Power industrial control terminal network isolation method and system based on process security label binding

By constructing a network isolation mechanism that binds process security tags within the power industrial control terminal, strong logical network partitioning within the host is achieved. This solves the security and real-time issues of existing network isolation schemes, improves system security and reliability, and reduces the risk of fault propagation and maintenance costs.

CN122179215APending Publication Date: 2026-06-09NARI INFORMATION & COMM TECH

Patent Information

Authority / Receiving Office
CN Β· China
Patent Type
Applications(China)
Current Assignee / Owner
NARI INFORMATION & COMM TECH
Filing Date
2026-03-30
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

Existing network isolation schemes for power industry control systems suffer from several problems, including the potential for vertical privilege escalation and horizontal penetration due to multiple services sharing the same kernel network protocol stack, the difficulty in strongly constraining network isolation at the logic layer, and the potential for faults to escalate.

Method used

By building a network processing path isolation mechanism centered on process identity within the host and using process security label binding, network security partitioning is achieved, breaking the centralized model of shared protocol stacks, and sinking network processing capabilities to independent user-space instances, thereby enabling resource decoupling, traffic redirection, identity binding, and controlled switching.

Benefits of technology

It achieves strong logical network partitioning within the host, eliminates cross-regional penetration paths, reduces the risk of fault propagation, improves system security and real-time performance, reduces dependence on external devices, and lowers deployment and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122179215A_ABST
    Figure CN122179215A_ABST
Patent Text Reader

Abstract

The application discloses a kind of power industrial control terminal network isolation method and system based on process security label binding;Belong to the technical field of power system network security, its operating steps include: decoupling physical network resources into independent partitions and mapping to independent user-mode network protocol stack instances;Through the bottom flow direction rule, the in-bound traffic is accurately delivered to the corresponding partition;Identify process security label at the application layer, establish the forced mapping of process and specific protocol stack instance and link;Through the controlled shared memory channel, realize the safe data interaction between partitions.The application realizes strong logical isolation on unified hardware, through the forced binding of process identity and network link, reduces the privilege promotion and horizontal penetration risk caused by traditional protocol stack sharing, while limiting the scope of failure impact, without relying on external physical isolation equipment, significantly improves the endogenous security protection capability of industrial control system network boundary.
Need to check novelty before this filing date? Find Prior Art