Information technology-side network security system suitable for the complex network environment of new energy power plants

By constructing a network security system in the isolation zone and information technology zone of the new energy power plant, and combining firewalls and various hardware and software devices, the network security problem when the new energy power plant interacts with external systems has been solved, and an effective protection effect has been achieved.

CN122137561APending Publication Date: 2026-06-02POWERCHINA HUADONG ENG CORP LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
POWERCHINA HUADONG ENG CORP LTD
Filing Date
2024-11-29
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

When new energy power plants interact with external energy dispatch and management systems, they face cybersecurity issues, including risks such as network intrusion and data leakage, which are difficult to effectively prevent with existing technologies.

Method used

A cybersecurity system for the information technology side of new energy power plants is constructed, which is divided into an isolation zone and an information technology zone, with firewalls deployed between the zones. Combined with hardware and software devices, including control modules, backup and recovery modules, log management modules, network monitoring modules, etc., security measures such as real-time traffic monitoring, packet filtering, and deep packet inspection are implemented.

Benefits of technology

It effectively prevents network intrusion and data leakage, reduces security risks, and has low construction costs, making it suitable for network security protection in new energy power plants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137561A_ABST
    Figure CN122137561A_ABST
Patent Text Reader

Abstract

This invention provides an information technology-side network security system suitable for the complex network environment of new energy power plants. The network security system is divided into an isolation zone and an information technology zone, and firewalls are set up at the communication boundaries of each zone. The network security structure includes software and hardware devices such as application control, antivirus, patch management, device control, integrity control, system backup and recovery, security events and event management, network monitor, jump server, firewall, and network attached storage. It meets the basic functions of network security protection with minimal software and hardware configuration, effectively avoids network intrusion, hacker theft, data leakage and other problems, and has low construction cost, making it suitable for new energy power plants.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information technology and network security, and specifically relates to an information technology-side network security system architecture suitable for the complex network environment of new energy power plants. Background Technology

[0002] With the continuous development of my country's social economy, the demand for electricity from all sectors is constantly increasing. To meet this growing demand, my country has been increasing its efforts to develop new energy power generation models. In recent years, a large number of new energy power plants have been put into operation. In the face of today's complex and ever-changing network environment, improving the network security protection capabilities of new energy power plants plays a vital role in their safe and stable operation.

[0003] To meet peak-shaving and valley-filling demands, new energy power plants inevitably need to connect to the energy management and dispatch system. This necessitates a significant exchange of information with the energy management and dispatch system, raising cybersecurity concerns for the energy management and monitoring system. These issues should be addressed and mitigated by constructing a cybersecurity system architecture based on cybersecurity protection mechanisms. For new energy power plants, while ensuring network security functions and considering economic efficiency, building an information technology-side cybersecurity system based on isolation zones and information technology zones between the power plant's internal control system and the external energy dispatch and monitoring system plays a crucial role in preventing network intrusion, hacker theft, and data leakage. Summary of the Invention

[0004] The purpose of this invention is to address the network security protection issues that may arise when new energy power plants transmit and interact with external energy dispatch and management systems, and to provide an information technology-side network security system architecture suitable for the complex network environment of new energy power plants.

[0005] Therefore, the above-mentioned objective of the present invention is achieved through the following technical solution: Information technology-side network security systems suitable for the complex network environments of new energy power plants, including: The structure of the network security system includes an information technology zone and an isolation zone; The network security system includes firewalls and hardware / software devices that connect to the internal network and switches of the new energy power plant. The isolation zone is connected to the power plant's internal network, the power plant's internal monitoring system, and the information technology zone via firewalls. The information technology zone is also connected to the isolation zone and the external energy dispatch and management system via firewalls.

[0006] Furthermore, the hardware and software devices of the network security system are deployed in a distributed and modular manner through multiple rack servers, and the modules work together. The modules include: a control module, a backup and recovery module, a log management module, a network monitoring module, a jump server module, and a network attached storage module.

[0007] Furthermore, the firewall, by combining various hardware and software devices in the network security system, performs security management and data filtering between the new energy power plant and the external energy dispatch and management system to create a secure isolation layer for network access. The security management and data filtering mechanisms include: real-time traffic monitoring, packet filtering, access control lists, and deep packet inspection.

[0008] Furthermore, the information technology area of ​​the network security system includes the following hardware and software devices: a control module, a backup and recovery module, a log management module, a network monitoring module, a jump server module, and a network additional storage module.

[0009] Furthermore, the isolated zone of the network security system includes the following hardware and software devices: a control module, a backup and recovery module, a log management module, and a network-attached storage module.

[0010] Furthermore, the control module of the network security system is used to deploy application control software, antivirus software, patch management software, device control software, and integrity control software, and is responsible for the formulation and execution of security policies, wherein: The application control software is used to prevent the installation and updates of malicious software and to provide whitelist-based protection for the human-machine interface of multi-computer management equipment in new energy power plants. The antivirus software is used to scan the system in real time and update the virus database regularly to protect the computer system of the new energy power plant from known malware. The patch management software is used to centrally manage various software and systems in the multi-computer management equipment of new energy power plants, and to realize the automated deployment and updating of patches. The device control software is used to apply mobile media strategies to multi-computer management devices in new energy power plants, and supports granular access control for users, computers and devices. The integrity control software is used to provide automatic diagnostic functions for the monitoring system of new energy power plants and to continuously audit the integrity of database changes and log files.

[0011] Furthermore, the software module of the network security system further includes: The backup and recovery module provides disk-level and file-level backup functions through backup and recovery software based on image technology, supporting the backup and recovery of host operating system, application software, configuration files and data; The log management module, through log management software and in conjunction with the security information and event management system, collects and analyzes security events from multiple data sources in real time for threat detection and alerts. It also supports the generation of compliance reports and event investigations through historical data analysis. The network monitoring module uses network monitoring software to monitor network traffic in real time, accurately detect and quickly block advanced, targeted, and evasive attacks, thereby reducing system security risks.

[0012] Furthermore, the hardware module of the network security system includes: The jump server module manages and controls access permissions to multiple target servers, ensuring that only authorized users can access the target servers and preventing unauthorized logins and operations. The network-attached storage module provides efficient data storage and file sharing capabilities by deploying network-attached storage, while also supporting system backup and collaborative management of internal data.

[0013] Compared with the prior art, the present invention has the following beneficial effects: This invention divides the network security system structure into an isolation zone and an information technology zone, and deploys firewalls on the communication nodes of each zone. The isolation zone and the information technology zone include software and hardware such as application control, antivirus, patch management, device control, integrity control, system backup and recovery, security events and event management, network monitor, jump server, firewall, and network attached storage. It meets the basic functions of network security protection with the lowest software and hardware configuration, effectively avoiding network intrusion, hacker theft, data leakage and other problems. Moreover, the construction cost is low and it is suitable for new energy power plants. Attached Figure Description

[0014] Figure 1 This invention provides a network security system architecture diagram for the information technology side, suitable for complex network environments in new energy power plants. Detailed Implementation

[0015] The present invention will be described in further detail with reference to the accompanying drawings and specific embodiments.

[0016] An information technology-side network security system suitable for the complex network environment of new energy power plants, wherein: The structure of the network security system includes an information technology zone and an isolation zone; The network security system includes firewalls and hardware / software devices that connect to the internal network and switches of the new energy power plant. The isolation zone is connected to the power plant's internal network, the power plant's internal monitoring system, and the information technology zone via firewalls. The information technology zone is also connected to the isolation zone and the external energy dispatch and management system via firewalls.

[0017] like Figure 1 As shown, an information technology-side network security system suitable for the complex network environment of new energy power plants, for the isolation zone, firstly, consists of a redundant communication network composed of two core switches. Secondly, within the isolation zone, application control software, antivirus software, patch management software, device control software, and integrity control software are installed on the same rack-mounted server to form a control module, used for centralized management and execution of security policies. In the diagram, AC represents application control software, AV represents antivirus software, PM represents patch management software, DC represents device control software, and IC represents integrity control software. Next, system backup and recovery software is deployed separately on a rack-mounted server to form a backup and recovery module, providing disk-level and file-level backup and rapid recovery functions. Thirdly, log management software, combined with a security information and event management system, is deployed separately on a rack-mounted server to form a log management module, responsible for real-time collection and analysis of security events within the isolation zone. Simultaneously, a network-attached storage device is configured within the isolation zone as a storage module for storing and backing up data; a multi-computer management device is configured to provide human-machine interface interactive management functions. Firewalls are deployed along the communication links between the internal monitoring system of the new energy power plant and the isolation zone, and between the isolation zone and the information technology zone, to achieve secure isolation and access control between areas. All of the above hardware devices are housed in a single cabinet for centralized management and maintenance.

[0018] For the information technology zone, its network architecture also consists of a redundant communication network composed of two core switches to improve network reliability. In terms of functional deployment, firstly, application control software, antivirus software, patch management software, device control software, and integrity control software are installed on the same rack server to form a control module for centralized management and execution of security policies. In the diagram, AC represents application control software, AV represents antivirus software, PM represents patch management software, DC represents device control software, and IC represents integrity control software. Secondly, system backup and recovery software is deployed separately on a rack server to form a backup and recovery module, providing disk-level and file-level backup and rapid recovery capabilities. Thirdly, log management software, combined with the security information and event management system, is deployed separately on a rack server to form a log management module, responsible for real-time collection and analysis of security events within the quarantine area. Furthermore, network monitoring software (NM) is placed on a separate rack server to form a network monitoring module, used for real-time monitoring of network traffic and detection of potential network attacks. Within the information technology area, a network-attached storage device (NAT) is configured as a storage module for data storage, along with a multi-computer management device to provide a human-computer interface for interactive management. A firewall is deployed on the communication link between the information technology area and the external energy management and dispatch system to prevent external network threats and ensure the security and integrity of data exchange. All of the aforementioned hardware is housed in a single cabinet for centralized management and maintenance.

[0019] The above specific embodiments are used to explain and illustrate the present invention, and are only preferred embodiments of the present invention, not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made to the present invention within the spirit and scope of the claims shall fall within the protection scope of the present invention.

Claims

1. An information technology-side network security system applicable to the complex network environment of new energy power plants, characterized in that: The structure of the network security system includes an information technology zone and an isolation zone; The network security system includes firewalls and hardware / software devices that connect to the internal network and switches of the new energy power plant. The isolation zone is connected to the power plant's internal network, the power plant's internal monitoring system, and the information technology zone via firewalls. The information technology zone is also connected to the isolation zone and the external energy dispatch and management system via firewalls.

2. The information technology-side network security system applicable to the complex network environment of new energy power plants according to claim 1, characterized in that: The network security system's hardware and software devices are deployed in a distributed, modular manner through multiple rack-mounted servers, and the modules work collaboratively with each other. The modules include: a control module, a backup and recovery module, a log management module, a network monitoring module, a jump server module, and a network attached storage module.

3. The information technology-side network security system applicable to the complex network environment of new energy power plants according to claim 1, characterized in that: The firewall, by combining various hardware and software devices in the network security system, performs security management and data filtering between the new energy power plant and the external energy dispatch and management system to create a secure isolation layer for network access. The security management and data filtering mechanisms include: real-time traffic monitoring, packet filtering, access control lists, and deep packet inspection.

4. The information technology-side network security system applicable to the complex network environment of new energy power plants according to claim 1, characterized in that: The information technology area of ​​the network security system includes the following hardware and software devices: a control module, a backup and recovery module, a log management module, a network monitoring module, a jump server module, and a network additional storage module.

5. The information technology-side network security system applicable to the complex network environment of new energy power plants according to claim 1, characterized in that: The isolated zone of the network security system includes the following hardware and software devices: a control module, a backup and recovery module, a log management module, and a network-attached storage module.

6. The information technology-side network security system applicable to the complex network environment of new energy power plants according to claim 2, characterized in that: The control module of the network security system is used to deploy application control software, antivirus software, patch management software, device control software, and integrity control software, and is responsible for the formulation and execution of security policies, wherein: The application control software is used to prevent the installation and updates of malicious software and to provide whitelist-based protection for the human-machine interface of multi-computer management equipment in new energy power plants. The antivirus software is used to scan the system in real time and update the virus database regularly to protect the computer system of the new energy power plant from known malware. The patch management software is used to centrally manage various software and systems in the multi-computer management equipment of new energy power plants, and to realize the automated deployment and updating of patches. The device control software is used to apply mobile media strategies to multi-computer management devices in new energy power plants, and supports granular access control for users, computers and devices. The integrity control software is used to provide automatic diagnostic functions for the monitoring system of new energy power plants and to continuously audit the integrity of database changes and log files.

7. The information technology-side network security system applicable to the complex network environment of new energy power plants according to claim 2, characterized in that: The software modules of the network security system further include: The backup and recovery module provides disk-level and file-level backup functions through backup and recovery software based on image technology, supporting the backup and recovery of host operating system, application software, configuration files and data; The log management module, through log management software and in conjunction with the security information and event management system, collects and analyzes security events from multiple data sources in real time for threat detection and alerts. It also supports the generation of compliance reports and event investigations through historical data analysis. The network monitoring module uses network monitoring software to monitor network traffic in real time, accurately detect and quickly block advanced, targeted, and evasive attacks, thereby reducing system security risks.

8. The information technology-side network security system applicable to the complex network environment of new energy power plants according to claim 2, characterized in that: The hardware modules of the network security system include: The jump server module manages and controls access permissions to multiple target servers, ensuring that only authorized users can access the target servers and preventing unauthorized logins and operations. The network-attached storage module provides efficient data storage and file sharing capabilities by deploying network-attached storage, while also supporting system backup and collaborative management of internal data.