Power industrial control terminal network isolation method and system based on process security label binding
By constructing a network isolation mechanism that binds process security tags within the power industrial control terminal, strong logical network partitioning within the host is achieved. This solves the security and real-time issues of existing network isolation schemes, improves system security and reliability, and reduces the risk of fault propagation and maintenance costs.
Patent Information
- Authority / Receiving Office
- CN Β· China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NARI INFORMATION & COMM TECH
- Filing Date
- 2026-03-30
- Publication Date
- 2026-06-09
AI Technical Summary
Existing network isolation schemes for power industry control systems suffer from several problems, including the potential for vertical privilege escalation and horizontal penetration due to multiple services sharing the same kernel network protocol stack, the difficulty in strongly constraining network isolation at the logic layer, and the potential for faults to escalate.
By building a network processing path isolation mechanism centered on process identity within the host and using process security label binding, network security partitioning is achieved, breaking the centralized model of shared protocol stacks, and sinking network processing capabilities to independent user-space instances, thereby enabling resource decoupling, traffic redirection, identity binding, and controlled switching.
It achieves strong logical network partitioning within the host, eliminates cross-regional penetration paths, reduces the risk of fault propagation, improves system security and real-time performance, reduces dependence on external devices, and lowers deployment and maintenance costs.
Smart Images

Figure CN122179215A_ABST