A power distribution terminal layered security management and control method and system based on trusted computing
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HEFEI ZHONGNENG POWER TECH
- Filing Date
- 2026-03-17
- Publication Date
- 2026-08-07
AI Technical Summary
现有可信计算方案已实现基础的分层防护及集中管理功能,但在实际工程应用中,仍存在诸多设计层面的缺陷,导致安全防护的适配性、运维效率及协同性有待进一步提升
1、通过动态角色切换机制与弹性验证规则,使防护策略能够精准匹配配电终端的动态业务场景,普通层终端临时承担核心业务时可快速启用高强度防护,核心层终端维护期间可切换至轻量化防护模式,既避免了固定防护策略导致的防护缺位或冗余,又有效协调了可信验证与终端业务运行的资源冲突,保障核心业务连续稳定运行。
Smart Images

Figure CN122533244A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power distribution safety management and control technology, and in particular to a hierarchical safety management and control method and system for power distribution terminals based on trusted computing. Background Technology
[0002] With the advancement of the informatization and intelligent transformation of power systems, distribution terminals have become core support equipment for power production dispatching. Currently, trusted computing technology has been widely applied in the field of power system security protection. Existing trusted computing solutions have achieved basic layered protection and centralized management functions, but in practical engineering applications, there are still many design-level defects, resulting in the need for further improvement in the adaptability, operation and maintenance efficiency, and collaboration of security protection.
[0003] Specifically, the existing solution adopts a fixed layering and protection mode based on terminal type, that is, core terminals use a forced mode and ordinary terminals use an alarm mode. However, the business roles of distribution terminals are dynamic and change, and the fixed protection strategy leads to a mismatch between protection strength and business needs. Moreover, policy switching requires manual intervention and modification, resulting in low response efficiency. At the same time, the legal procedures of terminals of the same type are completely consistent, but the existing solution requires a separate pre-configured benchmark library for each terminal. Repeated configuration is not only time-consuming and labor-intensive, but also prone to manual input errors, which can lead to false judgments in verification. In addition, the provincial dispatch master station uses a generalized distribution mode when issuing policies, which does not fully consider the differences in network environment and terminal hardware capabilities of different substations, which can easily lead to policy adaptation failures or waste of system resources.
[0004] There are currently no relevant technical solutions to the above-mentioned technical problems. Summary of the Invention
[0005] Therefore, it is necessary to provide a hierarchical security management method and system for power distribution terminals based on trusted computing to address the aforementioned technical problems.
[0006] In a first aspect, the present invention provides a hierarchical security management method for power distribution terminals based on trusted computing, comprising: S1. Classify and categorize the power distribution terminals according to the preset equipment information, establish a basic information ledger for the power distribution terminals, add a strategy adaptation layer, and build a communication link between the master station and the power distribution terminals. S2. Based on the basic information ledger of power distribution terminals, configure the default protection strategy and flexible verification rule list, and perform dynamic role switching and flexible verification to generate role switching audit logs. S3. Based on the preset trusted benchmark library module, batch derive and add trusted benchmark libraries dedicated to power distribution terminals, and update the trusted benchmark library template synchronously, generating template update audit logs. S4. In the policy adaptation layer, a policy adaptation rule list is constructed, the received master station general policy is converted into terminal protection instructions, and after being issued, a policy adaptation log is generated and the execution status is reported to realize the cascade control between the master station and the power distribution terminal. S5. Organize role switching audit logs, template update audit logs, and policy adaptation logs to build a hierarchical and categorized log system, and collect terminal operation data to achieve dynamic optimization of cascading control.
[0007] Furthermore, based on preset equipment information, the power distribution terminals are categorized and layered, a basic information ledger for the power distribution terminals is established, and a strategy adaptation layer is added. The communication link between the master station and the power distribution terminals is established, including: S11. Divide the power distribution terminals into core layer terminals and ordinary layer terminals, and uniformly enter the equipment information of all power distribution terminals into the trusted verification management center to establish a basic information ledger for power distribution terminals. S12. Pre-set temporary role tags for different identities and bind exclusive protection strategies to each type of temporary role tag to form a list of temporary roles and protection strategies; temporary roles include temporary core roles, maintenance status roles, and standby status roles; S13. Create corresponding trusted benchmark library templates for power distribution terminals according to the power distribution terminal manufacturer, equipment model and business type, and pre-set the general program expected value of the corresponding power distribution terminal in each trusted benchmark library template. S14. Add a policy adaptation layer within the trusted verification management center to establish a communication link between the master station and each power distribution terminal, enabling the master station to issue instructions and report operating status in real time.
[0008] Furthermore, based on the basic information ledger of power distribution terminals, a default protection strategy and a list of flexible verification rules are configured, and dynamic role switching and flexible verification are performed, generating role switching audit logs including: S21. Based on the basic information ledger of power distribution terminals, configure default protection strategies for power distribution terminals at different levels to achieve layered basic protection; S22. Based on the temporary role and protection strategy list, configure a dual role triggering method that combines manual triggering and scenario linkage triggering, and preset multiple scenario linkage conditions. When the scenario linkage conditions are met, the role switch is automatically triggered, and a role switch audit log is generated in real time. S23. Allocate power distribution terminal service periods and configure corresponding verification rules for each type of service period to form a flexible verification rule list. Service periods include peak service periods, idle periods, and downtime periods.
[0009] Furthermore, based on the preset trusted benchmark library module, new trusted benchmark libraries specifically for power distribution terminals are generated in batches, and the trusted benchmark library template is updated synchronously, generating template update audit logs including: S31. When a new power distribution terminal is connected, select the corresponding type of trusted benchmark library template for the new power distribution terminal in the trusted verification management center, and generate an exclusive trusted benchmark library through content configuration. S32. When a new power distribution terminal has personalized requirements, modify the differentiated parameters in the dedicated trusted reference library, and keep the unmodified general parameters consistent with the trusted reference library of the corresponding type. S33. When the general program of any type of power distribution terminal is updated, modify the trusted benchmark library template and the expected value of the general program of the corresponding type of power distribution terminal, and after the trusted benchmark library template is updated, synchronize the template update content to the dedicated trusted benchmark library and generate a template update audit log.
[0010] Furthermore, a policy adaptation rule list is constructed in the policy adaptation layer, which converts the received master station general policy into terminal protection instructions. After issuance, policy adaptation logs are generated and the execution status is reported, realizing cascaded control between the master station and the power distribution terminal, including: S41. Multiple types of adaptation rules are preset in the policy adaptation layer to form a policy adaptation rule list, which fully covers the differences in different network environments, terminal types and hardware capabilities. S42. The policy adaptation layer receives the general policy issued by the master station in real time through the communication link. After receiving the policy, it automatically matches the adaptation rules in the policy adaptation rule list and, in combination with the actual environment of each power distribution terminal in the plant, converts the general policy of the master station into the terminal protection instructions of each power distribution terminal. S43. Send terminal protection instructions in batches to the corresponding power distribution terminals through the communication link. The power distribution terminals take effect immediately upon receiving the instructions and perform the corresponding protection operations and generate policy adaptation logs.
[0011] Furthermore, the adaptation rules include access method adaptation rules, terminal type adaptation rules, and hardware capability adaptation rules; Among them, the access method adaptation rules stipulate that power distribution terminals accessed through private networks should prioritize hardware trusted root verification, while power distribution terminals accessed through dispatch data networks should prioritize software trusted root verification. The terminal type adaptation rule means that core layer terminals will directly convert the main station's general policy into a forced mode for execution, while ordinary layer terminals will convert the main station's general policy into an alarm mode for execution. The hardware capability adaptation rules stipulate that power distribution terminals that support hardware trusted roots enable full-process verification at the bootstrap layer, system layer, and application layer, while power distribution terminals that do not support hardware trusted roots disable real-time measurement of resource consumption and only retain bootstrap layer and core application layer verification.
[0012] Furthermore, the system organizes role switching audit logs, template update audit logs, and policy adaptation logs, establishes a hierarchical and categorized log system, and collects terminal operation data to achieve dynamic optimization of cascading control, including: S51. Organize role switching audit logs, template update audit logs, and policy adaptation logs, and classify and store them according to two dimensions to form a hierarchical classification log system; the first dimension is the hierarchical index, and the second dimension is the verification type index. S52. Utilize the Trusted Verification Management Center to collect the terminal operation status of each power distribution terminal in real time, generate a visual operation status dashboard, and display the control status of each power distribution terminal and each level. S53. Based on the log data and terminal operation data in the hierarchical classification log system, regularly analyze the operation status of the power distribution terminal and the execution effect of the protection strategy. When any power distribution terminal is abnormal, automatically trigger fault location and emergency response measures.
[0013] Secondly, a hierarchical security management and control system for power distribution terminals based on trusted computing is provided, the system comprising: The basic configuration building module is used to classify and categorize power distribution terminals according to preset equipment information, establish a basic information ledger for power distribution terminals, add a strategy adaptation layer, and build a communication link between the master station and the power distribution terminals. The dynamic adaptation protection module is used to configure default protection policies and a list of flexible verification rules based on the basic information ledger of power distribution terminals, and to perform dynamic role switching and flexible verification, and generate role switching audit logs. The benchmark library management module is used to batch derive new trusted benchmark libraries for power distribution terminals based on the preset trusted benchmark library module, and synchronously update the trusted benchmark library template and generate template update audit logs. The policy localization and adaptation module is used to build a policy adaptation rule list in the policy adaptation layer, convert the received master station general policy into terminal protection instructions, generate policy adaptation logs after issuance and report the execution status, so as to realize the cascaded control between the master station and the power distribution terminal. The log tracing and optimization module is used to organize role switching audit logs, template update audit logs, and policy adaptation logs, build a hierarchical and classified log system, and collect terminal operation data to achieve dynamic optimization of cascading control.
[0014] Thirdly, the present invention provides an electronic device, which includes a processor, a storage medium and a computer program, wherein the computer program is stored in the storage medium, and when the computer program is executed by the processor, it implements the above-mentioned hierarchical security management method for power distribution terminals based on trusted computing.
[0015] Fourthly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the above-described method for hierarchical security management of power distribution terminals based on trusted computing.
[0016] The beneficial effects of this invention are as follows: 1. Through a dynamic role switching mechanism and flexible verification rules, the protection strategy can accurately match the dynamic business scenarios of the power distribution terminal. When the ordinary layer terminal temporarily undertakes the core business, high-intensity protection can be quickly activated. During the maintenance of the core layer terminal, it can be switched to lightweight protection mode. This not only avoids the protection gaps or redundancies caused by fixed protection strategies, but also effectively coordinates the resource conflicts between trusted verification and terminal business operation, ensuring the continuous and stable operation of core business.
[0017] 2. Based on the template-based management logic, similar power distribution terminals can directly reuse trusted benchmark library templates to complete batch configuration. Personalized terminals only need to modify the differentiated parameters. After the template is updated, it can be quickly synchronized to all associated terminals, which greatly reduces the workload of repetitive configuration, reduces the risk of manual input errors, realizes the standardized process of benchmark library configuration and update, and improves the convenience and standardization of operation and maintenance management.
[0018] 3. Through the multi-dimensional adaptation rules preset in the policy adaptation layer, the general policy of the main station can be transformed into a specific protection policy for the terminal with precise adaptation based on the actual environment such as the network access method, hardware capabilities, and terminal type of the factory terminal. This effectively solves the problem of policy adaptation for different factory environments and terminals with different configurations, avoids the adaptation failure or waste of resources caused by applying a one-size-fits-all general policy, and ensures the smooth implementation and effective execution of the cascaded control from the provincial dispatch center to the factory station. Attached Figure Description
[0019] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this invention, illustrate exemplary embodiments of the invention and are used to explain the invention, but do not constitute an undue limitation of the invention. In the drawings: Figure 1 This is a flowchart of a hierarchical security management method for power distribution terminals based on trusted computing, according to an embodiment of the present invention. Figure 2 This is a system principle block diagram of a hierarchical security management and control system for power distribution terminals based on trusted computing, according to an embodiment of the present invention. Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention.
[0020] The icons are labeled as follows: 1. Basic configuration setup module; 2. Dynamic adaptation protection module; 3. Baseline library management module; 4. Policy localization adaptation module; 5. Log tracing and optimization module. Detailed Implementation
[0021] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0022] Please see Figure 1 This paper provides a hierarchical security management method for power distribution terminals based on trusted computing, including: S1. Classify and categorize the power distribution terminals according to the preset equipment information, establish a basic information ledger for the power distribution terminals, add a strategy adaptation layer, and build a communication link between the master station and the power distribution terminals.
[0023] In the description of this invention, the power distribution terminals are classified and stratified according to preset equipment information, a basic information ledger of the power distribution terminals is established, a strategy adaptation layer is added, and a communication link between the master station and the power distribution terminals is established, including: S11. Divide the power distribution terminals into core layer terminals and ordinary layer terminals, and uniformly enter the equipment information of all power distribution terminals into the trusted verification management center to establish a basic information ledger for power distribution terminals.
[0024] Specifically, the core layer terminals include critical business support equipment such as NCS system servers, AGCAVC servers, and grid control platform servers, while the ordinary layer terminals include non-core business equipment such as desulfurization and denitrification workstations and auxiliary monitoring backup units. All terminal classification information and equipment parameters are uniformly entered into the trusted verification management center to establish a basic information ledger for power distribution terminals.
[0025] S12. Pre-define temporary role tags for different identities and bind exclusive protection strategies to each type of temporary role tag, forming a list of temporary roles and protection strategies. Temporary roles include temporary core roles, maintenance roles, and standby roles.
[0026] Specifically, the temporary core role binding forced mode is suitable for scenarios where ordinary layer terminals temporarily undertake core business; the maintenance status role binding alarm mode is suitable for scenarios where core layer terminals are shut down for maintenance; the standby status role disables application layer verification and retains only bootstrap layer verification, suitable for scenarios where power distribution terminals have no business operation.
[0027] S13. Create corresponding trusted benchmark library templates for power distribution terminals according to the power distribution terminal manufacturer, equipment model and business type, and pre-set the general program expected values for the corresponding power distribution terminals in each trusted benchmark library template.
[0028] Specifically, the expected values of the general program for each type of power distribution terminal are pre-set in the trusted benchmark library template, including developer signature information, hash values of core configuration parameters, common application paths and characteristics, and corresponding verification rules are associated. The core program uses dual signature verification, while the ordinary program uses single signature verification.
[0029] S14. Add a policy adaptation layer within the trusted verification management center to establish a communication link between the master station and each power distribution terminal, enabling the master station to issue instructions and report operating status in real time.
[0030] Specifically, a policy adaptation layer software module is added to the plant's trusted verification management center. No new hardware equipment is required. The policy adaptation layer establishes communication links with the trusted verification modules of the provincial dispatch master station and each distribution terminal. The communication stability is tested to ensure that the policies issued by the provincial dispatch master station can be smoothly transmitted to each distribution terminal and that the operating status of each distribution terminal can be reported to the provincial dispatch master station in real time, thus ensuring smooth policy flow.
[0031] S2. Based on the basic information ledger of power distribution terminals, configure the default protection strategy and flexible verification rule list, and perform dynamic role switching and flexible verification to generate role switching audit logs.
[0032] In the description of this invention, based on the basic information ledger of power distribution terminals, a default protection strategy and a list of flexible verification rules are configured, and dynamic role switching and flexible verification are performed to generate role switching audit logs, including: S21. Based on the basic information ledger of power distribution terminals, configure default protection strategies for power distribution terminals at different levels to achieve layered basic protection.
[0033] Specifically, default protection policies are configured for core layer terminals and ordinary layer terminals respectively, forming a list of default protection policies for terminals. Core layer terminals are enabled by default in forced mode, which performs full-process trusted verification of the boot layer, system layer, and application layer, and immediately blocks any abnormalities. Ordinary layer terminals are enabled by default in alarm mode, which only performs key verification on the boot layer and core application layer, and only generates audit logs for other links, without affecting the normal operation of the power distribution terminal, thus achieving layered basic protection.
[0034] S22. Based on the list of temporary roles and protection strategies, configure a dual role triggering method that combines manual triggering and scenario linkage triggering, and preset multiple scenario linkage conditions. When the scenario linkage conditions are met, the role switch is automatically triggered, and a role switch audit log is generated in real time.
[0035] Specifically, based on the temporary roles and protection strategy list, a dual-role triggering method is configured: manual triggering and scenario-linked triggering. Maintenance personnel can directly select the temporary role tag corresponding to the target power distribution terminal through the trusted verification management center interface. After triggering, the protection strategy takes effect immediately without restarting the power distribution terminal or re-issuing the configuration. Simultaneously, two types of scenario-linked conditions are preset: when the power distribution terminal accesses the core business partition of the dispatch data network or starts a core business process, the temporary core role is automatically triggered; when accessing the ordinary data network or shutting down the core business process, the basic level of protection is automatically restored. Temporary roles are set with selectable validity periods of 1-72 hours. After expiration, the system automatically restores the basic protection strategy for the power distribution terminal. A role switching audit log is generated throughout the role switching process, and this audit log is synchronously transmitted to the hierarchical and categorized log system.
[0036] S23. Allocate power distribution terminal service periods and configure corresponding verification rules for each type of service period to form a flexible verification rule list. Service periods include peak service periods, idle periods, and downtime periods.
[0037] Specifically, the system divides the power distribution terminal business time periods into three categories: peak business periods, idle periods, and downtime periods. Maintenance personnel can manually adjust the start and end times of each period based on on-site business patterns, or the system can automatically determine the time period by binding the power distribution terminal's business process status. Corresponding verification rules are configured for each type of time period, forming a flexible verification rule list. High protection intensity is maintained during peak periods, while verification frequency and steps are gradually reduced during idle and downtime periods. Exception rules are set for dispatch terminals directly connected to the provincial dispatch master station and critical power distribution terminals whose core business cannot be interrupted. Regardless of the time period, the verification intensity of the peak period is maintained to ensure the security of core business. Verification operation audit logs generated during the verification process are synchronously transmitted to a hierarchical and categorized log system.
[0038] S3. Based on the preset trusted benchmark library module, batch derive and add trusted benchmark libraries dedicated to power distribution terminals, and update the trusted benchmark library template synchronously, generating template update audit logs.
[0039] In the description of this invention, based on a preset trusted benchmark library module, a batch of newly added trusted benchmark libraries specific to power distribution terminals are derived, and the trusted benchmark library template is updated synchronously. The generated template update audit log includes: S31. When a new power distribution terminal is connected, select the corresponding type of trusted benchmark library template for the new power distribution terminal in the trusted verification management center, and generate a dedicated trusted benchmark library through content configuration.
[0040] S32. When a new power distribution terminal has personalized requirements, modify the differentiated parameters in the dedicated trusted reference library, while keeping the unmodified general parameters consistent with the trusted reference library of the corresponding type.
[0041] S33. When the general program of any type of power distribution terminal is updated, modify the trusted benchmark library template and the expected value of the general program of the corresponding type of power distribution terminal, and after the trusted benchmark library template is updated, synchronize the template update content to the dedicated trusted benchmark library and generate a template update audit log.
[0042] Specifically, when the general program of a certain type of power distribution terminal is updated, the operation and maintenance personnel only need to modify the corresponding type of power distribution terminal trusted benchmark library template and update the expected value of the general program. After the template is updated, the synchronization method is selected to synchronize the template update content to the relevant derived dedicated trusted benchmark library. After the synchronization is completed, the system automatically generates a template update audit log, which records the update time, template name, number of synchronized power distribution terminals and update content. This template update audit log is synchronously transmitted to the hierarchical classification log system.
[0043] S4. In the policy adaptation layer, a policy adaptation rule list is constructed, the received master station general policy is converted into terminal protection instructions, and after being issued, a policy adaptation log is generated and the execution status is reported to realize the cascaded control between the master station and the power distribution terminal.
[0044] In the description of this invention, a policy adaptation rule list is constructed in the policy adaptation layer, the received master station general policy is converted into terminal protection instructions, and after being issued, a policy adaptation log is generated and the execution status is reported, thereby realizing the cascaded control between the master station and the power distribution terminal, including: S41. Multiple types of adaptation rules are preset in the policy adaptation layer to form a policy adaptation rule list, which fully covers the differences in different network environments, terminal types and hardware capabilities.
[0045] In the description of this invention, the adaptation rules include access method adaptation rules, terminal type adaptation rules, and hardware capability adaptation rules.
[0046] Among them, the access method adaptation rules stipulate that power distribution terminals accessed through private networks should prioritize hardware trusted root verification, while power distribution terminals accessed through dispatch data networks should prioritize software trusted root verification.
[0047] The terminal type adaptation rule means that core layer terminals will directly convert the main station's general policy into a forced mode for execution, while ordinary layer terminals will convert the main station's general policy into an alarm mode for execution.
[0048] The hardware capability adaptation rules stipulate that power distribution terminals that support hardware trusted roots enable full-process verification at the bootstrap layer, system layer, and application layer, while power distribution terminals that do not support hardware trusted roots disable real-time measurement of resource consumption and only retain bootstrap layer and core application layer verification.
[0049] S42. The policy adaptation layer receives the general policy issued by the master station in real time through the communication link. After receiving the policy, it automatically matches the adaptation rules in the policy adaptation rule list and, in combination with the actual environment of each power distribution terminal in the plant, converts the general policy of the master station into the terminal protection instructions of each power distribution terminal.
[0050] S43. Send terminal protection instructions in batches to the corresponding power distribution terminals through the communication link. The power distribution terminals take effect immediately upon receiving the instructions and perform the corresponding protection operations and generate policy adaptation logs.
[0051] S5. Organize role switching audit logs, template update audit logs, and policy adaptation logs to build a hierarchical and categorized log system, and collect terminal operation data to achieve dynamic optimization of cascading control.
[0052] In the description of this invention, the process of organizing role switching audit logs, template update audit logs, and policy adaptation logs, establishing a hierarchical and categorized log system, and collecting terminal operation data to achieve dynamic optimization of cascading control includes: S51. Organize role switching audit logs, template update audit logs, and policy adaptation logs, and classify and store them according to two dimensions to form a hierarchical classification log system. The first dimension is the hierarchical index, and the second dimension is the verification type index.
[0053] Specifically, a hierarchical and categorized log system is constructed. The first dimension is a hierarchical index, which classifies terminals according to the core layer terminals / ordinary layer terminals + distribution terminal type in the basic information ledger of distribution terminals. Each category corresponds to an independent log file directory. The second dimension is a verification type index, which subdivides log entries according to the verification stage (guided layer verification / system layer verification / application layer verification) and verification result (pass / alarm / block). Each log entry is labeled with key information such as distribution terminal IP, process name, file name, timestamp, and operation content. A multi-condition combined search function is configured to support quick queries by hierarchical type, verification stage, time range, and verification result. At the same time, log storage rules are set, adopting a daily partitioning + automatic archiving mechanism. Logs older than 3 months are automatically compressed and archived, and retained for 1 year for future reference. The search results can be exported to a format compatible with the power system safety management platform to meet the requirements of compliance auditing and fault tracing.
[0054] S52. Utilize the Trusted Verification Management Center to collect the terminal operation status of each power distribution terminal in real time, generate a visual operation status dashboard, and display the control status of each power distribution terminal and each level.
[0055] S53. Based on the log data and terminal operation data in the hierarchical classification log system, regularly analyze the operation status of the power distribution terminal and the execution effect of the protection strategy. When any power distribution terminal is abnormal, automatically trigger fault location and emergency response measures.
[0056] Specifically, based on log data in the hierarchical and categorized log system and monitoring data from the operational status dashboard, the operating data of power distribution terminals, various audit logs, and the execution effect of specific protection strategies for terminals are analyzed regularly. If it is found that a certain type of power distribution terminal adaptation rule leads to an increase in verification misjudgment rate, abnormal resource usage, or adjustments to the security requirements of the provincial dispatch master station, the relevant control rules in the temporary role and protection strategy list, the power distribution terminal trusted benchmark library template, the strategy adaptation rule list, and the flexible verification rule list are modified in a timely manner. When power distribution terminals experience verification anomalies or failures in the execution of specific protection strategies, maintenance personnel can quickly locate the cause of the fault through the hierarchical and categorized log system and take measures such as restoring the dedicated trusted benchmark library, switching protection modes, and updating adaptation rules. After the fault handling is completed, an emergency handling log is generated, forming a complete closed loop to ensure that the control system continuously adapts to actual application needs.
[0057] Please see Figure 2 This paper provides a hierarchical security management and control system for power distribution terminals based on trusted computing. The system includes: The basic configuration building module 1 is used to classify and categorize power distribution terminals according to preset equipment information, establish a basic information ledger for power distribution terminals, add a strategy adaptation layer, and build a communication link between the master station and the power distribution terminals.
[0058] The dynamic adaptation protection module 2 is used to configure default protection strategies and a list of flexible verification rules based on the basic information ledger of power distribution terminals, and to perform dynamic role switching and flexible verification, and generate role switching audit logs.
[0059] The benchmark library management module 3 is used to batch derive new trusted benchmark libraries for power distribution terminals based on the preset trusted benchmark library module, and synchronously update the trusted benchmark library template and generate template update audit logs.
[0060] The policy localization adaptation module 4 is used to build a policy adaptation rule list in the policy adaptation layer, convert the received master station general policy into terminal protection instructions, generate policy adaptation logs after issuance and report the execution status, so as to realize the cascaded control between the master station and the power distribution terminal.
[0061] Log tracing and optimization module 5 is used to organize role switching audit logs, template update audit logs, and policy adaptation logs, build a hierarchical and classified log system, and collect terminal operation data to achieve dynamic optimization of cascading control.
[0062] This application also provides an electronic device, such as... Figure 3As shown, it includes: a processor, and a memory coupled to the processor, the memory being used to store a computer program; the processor being used to execute the computer program stored in the memory, so that the electronic device performs the trusted computing-based hierarchical security management method for power distribution terminals as described in any of the above embodiments.
[0063] Electronic devices can be computing devices such as desktop computers, laptops, handheld computers, and cloud servers. These electronic devices may include, but are not limited to, processors and memory.
[0064] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the electronic device, connecting various parts of the device via various interfaces and lines.
[0065] The memory can be used to store the computer program, and the processor implements various functions of the electronic device by running or executing the computer program stored in the memory and calling the data stored in the memory.
[0066] The memory may primarily include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function, etc.; the data storage area may store data created based on the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0067] This application also provides a computer-readable storage medium. The computer program is stored in the computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium can include any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a flexible component distribution medium, etc.
[0068] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
Claims
1. A hierarchical security management method for power distribution terminals based on trusted computing, characterized in that, include: S1. Classify and categorize the power distribution terminals according to the preset equipment information, establish a basic information ledger for the power distribution terminals, add a strategy adaptation layer, and build a communication link between the master station and the power distribution terminals. S2. Based on the basic information ledger of power distribution terminals, configure the default protection strategy and flexible verification rule list, and perform dynamic role switching and flexible verification to generate role switching audit logs. S3. Based on the preset trusted benchmark library module, batch derive and add trusted benchmark libraries dedicated to power distribution terminals, and update the trusted benchmark library template synchronously, generating template update audit logs. S4. In the policy adaptation layer, a policy adaptation rule list is constructed, the received master station general policy is converted into terminal protection instructions, and after being issued, a policy adaptation log is generated and the execution status is reported to realize the cascade control between the master station and the power distribution terminal. S5. Organize role switching audit logs, template update audit logs, and policy adaptation logs to build a hierarchical and categorized log system, and collect terminal operation data to achieve dynamic optimization of cascading control.
2. The hierarchical security management method for distribution terminals based on trusted computing according to claim 1, characterized in that, The step of classifying and stratifying power distribution terminals according to preset equipment information, establishing a basic information ledger for power distribution terminals, adding a strategy adaptation layer, and building a communication link between the master station and the power distribution terminals includes: S11. Divide the power distribution terminals into core layer terminals and ordinary layer terminals, and uniformly enter the equipment information of all power distribution terminals into the trusted verification management center to establish a basic information ledger for power distribution terminals. S12. Pre-set temporary role tags for different identities, and bind exclusive protection strategies to each type of temporary role tag to form a list of temporary roles and protection strategies; the temporary roles include temporary core roles, maintenance status roles, and standby status roles; S13. Create corresponding trusted benchmark library templates for power distribution terminals according to the power distribution terminal manufacturer, equipment model and business type, and pre-set the general program expected value of the corresponding power distribution terminal in each trusted benchmark library template. S14. Add a policy adaptation layer within the trusted verification management center to establish a communication link between the master station and each power distribution terminal, enabling the master station to issue instructions and report operating status in real time.
3. The hierarchical security management method for power distribution terminals based on trusted computing according to claim 2, characterized in that, The process involves configuring default protection strategies and a list of flexible verification rules based on the basic information ledger of power distribution terminals, performing dynamic role switching and flexible verification, and generating role switching audit logs, including: S21. Based on the basic information ledger of power distribution terminals, configure default protection strategies for power distribution terminals at different levels to achieve layered basic protection; S22. Based on the temporary role and protection strategy list, configure a dual role triggering method that combines manual triggering and scenario linkage triggering, and preset multiple scenario linkage conditions. When the scenario linkage conditions are met, the role switch is automatically triggered, and a role switch audit log is generated in real time. S23. Allocate power distribution terminal service periods and configure corresponding verification rules for each type of service period to form a flexible verification rule list. The service periods include peak service periods, idle periods, and downtime periods.
4. The hierarchical security management method for distribution terminals based on trusted computing according to claim 1, characterized in that, The preset trusted benchmark library module batch-derives and adds new trusted benchmark libraries specific to power distribution terminals, and synchronously updates the trusted benchmark library template, generating template update audit logs including: S31. When a new power distribution terminal is connected, select the corresponding type of trusted benchmark library template for the new power distribution terminal in the trusted verification management center, and generate an exclusive trusted benchmark library through content configuration. S32. When a new power distribution terminal has personalized requirements, modify the differentiated parameters in the dedicated trusted reference library, and keep the unmodified general parameters consistent with the trusted reference library of the corresponding type. S33. When the general program of any type of power distribution terminal is updated, modify the trusted benchmark library template and the expected value of the general program of the corresponding type of power distribution terminal, and after the trusted benchmark library template is updated, synchronize the template update content to the dedicated trusted benchmark library and generate a template update audit log.
5. The hierarchical security management method for distribution terminals based on trusted computing according to claim 1, characterized in that, The step of constructing a policy adaptation rule list in the policy adaptation layer, converting the received master station general policy into terminal protection instructions, generating policy adaptation logs after issuance and reporting the execution status, and realizing cascaded control between the master station and the power distribution terminal includes: S41. Multiple types of adaptation rules are preset in the policy adaptation layer to form a policy adaptation rule list, which fully covers the differences in different network environments, terminal types and hardware capabilities. S42. The policy adaptation layer receives the general policy issued by the master station in real time through the communication link. After receiving the policy, it automatically matches the adaptation rules in the policy adaptation rule list and, in combination with the actual environment of each power distribution terminal in the plant, converts the general policy of the master station into the terminal protection instructions of each power distribution terminal. S43. Send terminal protection instructions in batches to the corresponding power distribution terminals through the communication link. The power distribution terminals take effect immediately upon receiving the instructions and perform the corresponding protection operations and generate policy adaptation logs.
6. The hierarchical security management method for distribution terminals based on trusted computing according to claim 4, characterized in that, The adaptation rules include access method adaptation rules, terminal type adaptation rules, and hardware capability adaptation rules; The access method adaptation rules stipulate that power distribution terminals accessed via private networks shall prioritize hardware root of trust verification, while power distribution terminals accessed via dispatch data networks shall prioritize software root of trust verification. The terminal type adaptation rule means that core layer terminals will directly convert the main station's general policy into a forced mode for execution, while ordinary layer terminals will convert the main station's general policy into an alarm mode for execution. The hardware capability adaptation rules stipulate that power distribution terminals that support hardware trusted roots enable full-process verification at the bootstrap layer, system layer, and application layer, while power distribution terminals that do not support hardware trusted roots disable real-time measurement of resource consumption and only retain bootstrap layer and core application layer verification.
7. A hierarchical security management method for distribution terminals based on trusted computing according to claim 1, characterized in that, The process of organizing role switching audit logs, template update audit logs, and policy adaptation logs, establishing a hierarchical and categorized log system, and collecting terminal operation data to achieve dynamic optimization of cascading control includes: S51. Organize role switching audit logs, template update audit logs, and policy adaptation logs, and classify and store them according to two dimensions to form a hierarchical classification log system; the first dimension is the hierarchical index, and the second dimension is the verification type index. S52. Utilize the Trusted Verification Management Center to collect the terminal operation status of each power distribution terminal in real time, generate a visual operation status dashboard, and display the control status of each power distribution terminal and each level. S53. Based on the log data and terminal operation data in the hierarchical classification log system, regularly analyze the operation status of the power distribution terminal and the execution effect of the protection strategy. When any power distribution terminal is abnormal, automatically trigger fault location and emergency response measures.
8. A hierarchical security management and control system for distribution terminals based on trusted computing, used to implement the hierarchical security management and control method for distribution terminals based on trusted computing as described in any one of claims 1-7, characterized in that, The system includes: The basic configuration building module is used to classify and categorize power distribution terminals according to preset equipment information, establish a basic information ledger for power distribution terminals, add a strategy adaptation layer, and build a communication link between the master station and the power distribution terminals. The dynamic adaptation protection module is used to configure default protection policies and a list of flexible verification rules based on the basic information ledger of power distribution terminals, and to perform dynamic role switching and flexible verification, and generate role switching audit logs. The benchmark library management module is used to batch derive new trusted benchmark libraries for power distribution terminals based on the preset trusted benchmark library module, and synchronously update the trusted benchmark library template and generate template update audit logs. The policy localization and adaptation module is used to build a policy adaptation rule list in the policy adaptation layer, convert the received master station general policy into terminal protection instructions, generate policy adaptation logs after issuance and report the execution status, so as to realize the cascaded control between the master station and the power distribution terminal. The log tracing and optimization module is used to organize role switching audit logs, template update audit logs, and policy adaptation logs, build a hierarchical and classified log system, and collect terminal operation data to achieve dynamic optimization of cascading control.
9. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor is used to implement the steps of the trusted computing-based hierarchical security management method for power distribution terminals as described in claims 1-7 when executing a computer program.
10. A computer-readable storage medium, characterized in that, A computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, it implements the hierarchical security management method for power distribution terminals based on trusted computing as described in any one of claims 1-7.