A nuclear power plant information security management method, system, device and medium

CN122741101APending Publication Date: 2026-09-11华能海南昌江核电有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610657290.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-13
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

[0005]因此,本发明解决的技术问题是:现有核电站信息安全管理方法采用集中式访问控制部署,对进入控制体系的数据缺乏基于安全属性的差异化标识与两级验证机制,攻击数据能够通过伪造标识或混入传输数据流的方式绕过访问控制进入核心存储区域,且在攻击发生后防御策略固定无法依据实际威胁等级动态调整,网络受损后依赖人工介入修复响应滞后

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122741101A_ABST
    Figure CN122741101A_ABST
Patent Text Reader

Abstract

This invention discloses a method, system, equipment, and medium for information security management in nuclear power plants, belonging to the field of nuclear power plant information security management technology. It includes: attaching identification codes to nuclear power plant operating status data and storing it in a first storage area; deploying access control logic on multiple independent nodes; synchronizing node control states through a consensus algorithm to establish a distributed access control system; performing two-level verification on data to be verified; classifying data that fails decryption verification as attack data; quantitatively assessing the risk level based on threat levels and switching security defense modes; and performing real-time analysis of network attacks, updating security protocols, and hierarchically reconstructing network paths and information security protocol logic according to the degree of damage. This invention eliminates the risk of single-point failure through distributed node deployment and achieves precise matching of defense strategies with actual threats through dynamic switching of defense modes driven by threat levels.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of nuclear power plant information security management technology, specifically to a method, system, equipment, and medium for nuclear power plant information security management. Background Technology

[0002] As the level of informatization in nuclear power plants continues to improve, the types of data generated during the operation of nuclear power plants are becoming increasingly complex, covering multiple dimensions such as equipment operating parameters, nuclear safety boundary data, environmental monitoring data, and personnel operation records. The above data have significant differences in access permissions and security attributes, which constitute the basic data environment that nuclear power plant information security protection needs to address.

[0003] For information security management in nuclear power plants, a centralized access control deployment approach is generally adopted, concentrating access control logic on a single control node. However, this centralized deployment approach inherently carries the risk of a single point of failure. When the control node suffers a targeted cyberattack, the entire access control system fails, and data interaction between the various subsystems of the nuclear power plant will continue without security control, allowing attack data to spread unchecked among the subsystems during this period. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention provides a method, system, equipment and medium for information security management of nuclear power plants.

[0005] Therefore, the technical problem solved by this invention is that the existing nuclear power plant information security management method adopts a centralized access control deployment, which lacks differentiated identification and two-level verification mechanism based on security attributes for data entering the control system. Attack data can bypass access control and enter the core storage area by forging identification or mixing into the transmission data stream. Moreover, after an attack occurs, the defense strategy is fixed and cannot be dynamically adjusted according to the actual threat level. After the network is damaged, it relies on manual intervention for repair and response is delayed.

[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: a method for information security management in nuclear power plants, comprising, Based on access permission levels, nuclear power plant operation status data is divided into access data and non-access data. Based on the access permission levels, the access data and non-access data are respectively assigned identification codes and stored in the first storage area. Based on the access permission levels, access control logic is deployed on multiple independent nodes. The control status of the multiple independent nodes is synchronized through a consensus algorithm to establish a distributed access control system. Based on the distributed access control system, the received data to be verified is identified and encoded. Data that fails the identification and encoding verification is stored in the second storage area. The data in the second storage area is decrypted and verified. Data that passes the decryption verification is stored in the first storage area. Data that fails the decryption verification is determined to be attack data. The risk level is quantitatively assessed based on the threat level of the attack data. The security defense mode is switched according to the quantitative assessment result to obtain the target security defense mode. Under the target security defense mode, network attacks are analyzed in real time, security protocols are updated based on the analysis results, damaged areas caused by network attacks are isolated, and network paths and information security protocol logic of the damaged areas are reconstructed in a hierarchical manner based on the degree of damage to the damaged areas.

[0007] As a preferred embodiment of the nuclear power plant information security management method described in this invention, the additional identification code includes: An access identity code is attached to the access-type data, and the access-type data is stored in the first storage unit of the first storage area; The non-accessible data is encrypted, and a key identifier is added to the non-accessible data based on the key generated by the encryption process. The non-accessible data is then stored in a second storage unit in the first storage area.

[0008] As a preferred embodiment of the nuclear power plant information security management method described in this invention, the identification coding verification includes: Check whether the data to be verified carries the access identity identifier code, the key identifier code, or the employee permission identifier code; The data to be verified, carrying the access identity identifier code, the key identifier code, or the employee permission identifier code, is allowed to access the first storage area; Data to be verified that does not include the access identity identifier code, the key identifier code, and the employee permission identifier code is stored in the second storage area.

[0009] As a preferred embodiment of the nuclear power plant information security management method described in this invention, the decryption verification includes: The data in the second storage area is decrypted, and data that fails to be decrypted is identified as attack data. For data that has been successfully decrypted, perform permission identification verification. Re-encrypt the data that has passed the permission identification verification and store it in the first storage area. Data that fails the permission identifier verification is verified by the transmission protocol encoding. Data that passes the transmission protocol encoding verification is re-encrypted and stored in the first storage area. Data that fails the transmission protocol encoding verification is identified as attack data.

[0010] As a preferred embodiment of the nuclear power plant information security management method described in this invention, the quantitative assessment includes: The threat level of the attack data is classified according to the access permission level of the data attacked. A risk assessment function is constructed based on the threat level, the attack intensity of the attack data, and the vulnerability of the system to quantify the risk level and obtain a risk assessment value.

[0011] As a preferred embodiment of the nuclear power plant information security management method described in this invention, the switching of the security defense mode includes: When the risk assessment value is less than or equal to the first preset threshold, the targeted mode is maintained, and targeted defense measures are invoked and executed in the targeted mode. When the risk assessment value is greater than the first preset threshold and less than or equal to the second preset threshold, switch to the merging mode. In the merging mode, calculate the correlation between each defense measure in the security protocol and the attack data, and select the defense measure with the highest correlation to merge and execute. When the risk assessment value exceeds the second preset threshold, the system switches to integrated mode, triggers the nuclear power plant integrated defense mechanism in integrated mode, repairs the damaged area, and synchronizes the status of the multiple independent nodes through a consensus algorithm.

[0012] As a preferred embodiment of the nuclear power plant information security management method described in this invention, the hierarchical reconstruction includes: When the degree of damage to the damaged area is less than a first preset ratio, the network path and information security protocol logic of the damaged area are updated in a targeted manner, the update result is verified, and if the verification is successful, it is deployed to the damaged area. When the degree of damage to the damaged area is greater than or equal to a first preset ratio and less than a second preset ratio, security hardening is performed on the damaged area and related areas, network security policies are reviewed, and access restrictions are implemented on security vulnerabilities identified during the review. When the degree of damage to the damaged area is greater than or equal to the second preset ratio, the network connection is disconnected, the information security protocol logic is replaced, and the damaged network device is reconfigured.

[0013] This invention provides an information security management system for nuclear power plants.

[0014] To solve the above technical problems, the present invention provides the following technical solution: a nuclear power plant information security management system, comprising: a data management module, used to divide nuclear power plant operation status data into access data and non-access data based on access permission levels, to attach identification codes to the access data and the non-access data respectively according to the access permission levels, and store them in a first storage area, to deploy access control logic on multiple independent nodes based on the access permission levels, and to synchronize the control status of the multiple independent nodes through a consensus algorithm to establish a distributed access control system; The risk assessment module is used to perform identification and encoding verification on the received data to be verified based on the distributed access control system, store the data to be verified that fails the identification and encoding verification into the second storage area, perform decryption verification on the data in the second storage area, store the data that passes the decryption verification into the first storage area, determine the data that fails the decryption verification as attack data, quantify the risk level based on the threat level of the attack data, and switch the security defense mode according to the quantitative assessment result to obtain the target security defense mode. The emergency reconstruction module is used to perform real-time analysis of network attacks under the target security defense mode, update security protocols based on the analysis results, isolate damaged areas caused by network attacks, and perform hierarchical reconstruction of network paths and information security protocol logic of the damaged areas based on the degree of damage to the damaged areas.

[0015] The present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the nuclear power plant information security management method.

[0016] The present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the nuclear power plant information security management method.

[0017] The beneficial effects of this invention are as follows: This invention adds differentiated identification codes to nuclear power plant operation status data by means of access permission levels, and stores access-type data and non-access-type data in different storage units in the first storage area respectively. Combined with a two-level judgment mechanism that sequentially performs identification code verification and decryption verification on the data to be verified, this invention enables attack data that infiltrates by forging identifications or mixing into the transmission data stream to be identified and stored in the second storage area before entering the first storage area. This changes the passive situation in the prior art where there is no effective means to distinguish between attack data and legitimate data.

[0018] By deploying access control logic on multiple independent nodes and using a consensus algorithm to ensure the consistency of the control state of each node, when any independent node is attacked, the remaining nodes automatically take over the access control logic of the attacked node, thus solving the single point of failure problem caused by the centralized access control deployment method in the prior art.

[0019] By constructing a quantitative risk assessment model based on the threat level of attack data, and dynamically switching between targeted mode, combined mode and comprehensive mode according to the risk assessment value, the defense strength is adaptively adjusted according to the actual threat level, which solves the problem that fixed defense strategies in existing technologies cannot match multiple types and intensities of attacks. Attached Figure Description

[0020] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1 This is a general flowchart of a nuclear power plant information security management method provided in one embodiment of the present invention.

[0022] Figure 2 This is a flowchart illustrating the decryption and verification process of a nuclear power plant information security management method according to an embodiment of the present invention.

[0023] Figure 3 This is a flowchart illustrating the hierarchical reconstruction process of a nuclear power plant information security management method, as provided in one embodiment of the present invention. Detailed Implementation

[0024] To make the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0025] Example 1, referring to Figures 1-3 This is one embodiment of the present invention, which provides a method for information security management in nuclear power plants, comprising: S1. Based on access permission levels, the nuclear power plant operation status data is divided into access data and non-access data. Based on the access permission levels, the access data and the non-access data are respectively assigned identification codes and stored in the first storage area. Based on the access permission levels, the access control logic is deployed on multiple independent nodes. The control status of the multiple independent nodes is synchronized through a consensus algorithm to establish a distributed access control system.

[0026] In some embodiments, the nuclear power plant operating status data in step S1 includes equipment operating data, safety parameter data, environmental monitoring data, economic and financial data, and access data.

[0027] It is understood that the equipment operation data includes real-time operating parameters of the nuclear power plant reactor and its supporting equipment, such as temperature, pressure, flow rate, vibration, radiation, and humidity; the safety parameter data includes nuclear safety boundary parameters such as the radioactive dose in the nuclear power plant operating area and the concentration of radioactive materials in the coolant; the environmental monitoring data includes changes in current and voltage in the power grid, power grid frequency, and external environmental parameters such as air, water quality, and soil; the economic and financial data includes investment, operation, and maintenance cost data of the nuclear power plant; and the access data includes manually entered data, personnel access information, and emergency response data.

[0028] It should be noted that the access data involves records of personnel operation behavior and has identity authentication attributes, and is classified as access data; the equipment operation data, safety parameter data, environmental monitoring data, and economic and financial data are allowed to be exchanged and shared among the various subsystems of the nuclear power plant, and are classified as non-access data, and the data transmission time of the non-access data is not allowed to exceed one minute.

[0029] Furthermore, after data classification is completed, based on pre-set access permission levels, corresponding identifier codes are added to the access-class data and the non-access-class data respectively. Specific implementation methods include steps S11-S12, wherein: S11, add an access identity identifier code to the access type data, and store the access type data in the first storage unit in the first storage area.

[0030] It is understood that the access data carries personnel identity information and operation records, and its source and permission ownership need to be marked by access identity identification code, and stored in a dedicated first storage unit for isolated management.

[0031] In some embodiments, the specific format of the access identity code is F-charkA-levelB, where A is the employee ID, which is unique for all employees, and B is the employee's access permission level. When a new employee is added, the user with the highest privileges directly sets the access permissions for the newly added employee according to the access permission level, and stores all information of the newly added employee in the access control list.

[0032] It should be noted that the access control list is a data structure that stores the correspondence between the identity information of all employees and their access permission levels, and is used to provide an identity authentication benchmark during the identification code verification process. Each record in the access control list contains an employee number, an access permission level, and a corresponding access identity identifier code, with the unique employee number ensuring the non-repeatability of the record.

[0033] S12, the non-accessible data is encrypted, a key identifier is added to the non-accessible data based on the key generated by the encryption process, and the non-accessible data is stored in the second storage unit in the first storage area.

[0034] It is understandable that the non-accessible data involves core operating parameters of the nuclear power plant and needs to be encrypted to ensure the security of data transmission and storage, preventing data from being intercepted or tampered with during the exchange between subsystems.

[0035] In some embodiments, the encryption process uses the AES encryption algorithm to encrypt the non-accessible data. During the encryption process, a random key is generated, and a key identifier code is added to the random key to mark the encryption status and key ownership of the data. The encrypted non-accessible data is then stored in a second storage unit for unified management.

[0036] It should be noted that the access-type data and the non-access-type data are stored in the first storage unit and the second storage unit respectively through differentiated identification and encoding methods, thereby achieving physical isolation between the two types of data in the first storage area.

[0037] Furthermore, after completing the identification encoding and classification storage, based on the access permission level, the access control logic is deployed on multiple independent nodes, and the control status of the multiple independent nodes is synchronized through a consensus algorithm. The specific implementation includes steps S13-S15, wherein: S13, check whether the data to be verified carries the access identity identifier code, the key identifier code, or the employee permission identifier code.

[0038] It is understood that the data to be verified is newly entered data into the control system. The access control list checks the identifier code of the data to be verified to determine whether it has legitimate access rights. The employee permission identifier code and the access identity identifier code together constitute the identity authentication benchmark for personnel access, and the key identifier code is a legitimate encryption mark for non-access-type data.

[0039] It should be noted that in the nuclear power plant information security management scenario, the access control logic is executed across multiple independent nodes. The various subsystems of the nuclear power plant are distributed across different physical areas, and each node in each area is responsible for access control of data within its designated area. The quality of control state synchronization between nodes directly determines the consistency of verification for cross-area data access requests. When a node in a certain physical area experiences control state deviations due to network fluctuations or load changes, if these deviations are not corrected in a timely manner, the same access request will generate different verification conclusions at different nodes, disrupting the overall consistency of nuclear power plant information security management. To quantitatively evaluate the synchronization effect of the control states of these multiple independent nodes, a comprehensive synchronization effect index is introduced, expressed as: in, This is a comprehensive indicator of the synchronization performance of the consensus algorithm. For the node state space; For the first The state values ​​of each node; The total number of independent nodes; This is the node state attenuation coefficient, reflecting the signal attenuation rate caused by physical distance and differences in network topology during the propagation of node control states in the nuclear power plant network. For integration variables; Used to describe the degree of decay of a node's control state as its location in the state space changes; For nodes The control logic functions; For nodes The synchronization state summation function; For node state values Let be the probability distribution function of the node states, which is the independent variable. It is a continuously variable representing the node's state.

[0040] Furthermore, Used to describe nodes Under the current control logic, the state The response characteristics of nodes in nuclear power plant access control scenarios are as follows: Each node needs to respond to access control commands from different subsystems and with different permission levels. These commands exhibit a periodic characteristic with multiple frequencies superimposed over time. A single function form cannot accurately characterize the state response patterns of nodes under complex command environments. Expressed as: in, For integration variables; The probability density function is Gaussian distributed, and probability weights are assigned to each state response value in the node control logic. This reduces the proportion of abnormal states that deviate from the normal access control response range in the overall evaluation, which is consistent with the actual characteristic of nuclear power plant access control command responses being mainly within the normal range. For the first The nth sine function is used to describe the node control logic in the nth... Periodic response characteristics under the frequency components of access control commands; For the first Frequency parameters of a sine function; The total number of sine functions; For the first The result of normalizing a sine function according to its frequency parameter eliminates the amplitude difference between access control command components of different frequencies, ensuring that the contribution of each frequency component to the node control logic description is balanced.

[0041] Furthermore, Used to measure nodes The overall degree of control state difference between nodes and other nodes. Due to the different access control responsibilities undertaken by the nodes in each subsystem of a nuclear power plant, there are inherent state differences between the nodes. While reflecting the overall differences in the states between nodes, it is necessary to assign less weight to the differences between nodes that are physically far apart and have low functional correlation. Expressed as: in, The summation index ranges from 1 to... The weighting coefficients vary with the summation index. The value decreases as the topological distance increases, reflecting the characteristic that the functional correlation between a node with a larger number and the current node decreases as the topological distance increases in the distributed node network of a nuclear power plant. For nodes The state value, For node indexing; For nodes The state value, For node indexing; It is an exponentially decaying function, passing through nodes With nodes The absolute value of the difference in state values ​​measures the degree of difference in control state between two nodes. The smaller the state difference, the more consistent the behavior of the corresponding nodes is when executing access control logic. With formula The attenuation coefficient in the text has the same meaning.

[0042] Furthermore, Used to describe the node's state value. Throughout the state space The probability distribution characteristics within the system. In nuclear power plant information security management, the overall distribution pattern of node states reflects the stability of the distributed access control system under the current operating environment. The more concentrated the node state distribution, the more consistent the execution of control logic across nodes. Expressed as: in, For the continuous value variable of the node state, and the formula middle The meaning is consistent; This is a normalization constant used to ensure... In state space The integral over the given value is 1, which satisfies the normalization condition of the probability distribution; The mean value of the node states reflects the expected level of control state of each node under normal operation of the distributed access control system. The standard deviation of the node state. The smaller the value, the lower the dispersion of the control state of each node relative to the mean, and the higher the consistency of the execution of the access control logic between nodes. For the first The frequency of a sine function; and middle The meaning is consistent, representing the total number of sine functions.

[0043] Understandable Medium Gaussian distribution term Nodes that deviate significantly from the mean of normal access control status are assigned lower probability weights, enabling the statistical identification of nodes with abnormal control states; sine function square term The periodic distribution pattern of node status under different access control cycles in a nuclear power plant is described, and it is matched with the frequency characteristics of periodic access control operations such as regular inspections, shift handovers, and emergency responses. The distribution description is closer to the access control rhythm of actual nuclear power plant operation.

[0044] Based on the above comprehensive indicators of synchronization effect Dynamically evaluate the synchronization effect between nodes: when At this time, the consensus algorithm between nodes cannot function properly; when The value in At times, the consensus algorithm cannot adapt to the current data environment and needs to be optimized; when At that time, nodes operate efficiently through a consensus algorithm.

[0045] Furthermore, when any independent node detects a change in control state, it communicates with the other independent nodes through a consensus algorithm to achieve control state consistency through the consensus process; when any independent node receives attack data, the other independent nodes take over the access control logic of the attacked independent node and disconnect from the attacked independent node.

[0046] S14, carrying the verification data containing the access identity identifier code, the key identifier code, or the employee permission identifier code, allows access to the first storage area.

[0047] It is understandable that after the data to be verified carrying a valid identifier code is authenticated by the access control list, the corresponding access permissions are granted according to the type of the identifier code it carries, allowing access to or output of the data in the corresponding storage unit in the first storage area.

[0048] S15, the data to be verified without carrying the access identity identifier code, the key identifier code, and the employee permission identifier code is stored in the second storage area.

[0049] It is understandable that data to be verified without any legitimate identification code is of questionable origin and nature. It is stored in the second storage area for isolation to prevent potential attack data from directly infiltrating the first storage area and compromising the data security of the nuclear power plant.

[0050] S2, based on the distributed access control system, the received data to be verified is identified and encoded. Data that fails the identification and encoding verification is stored in the second storage area. Data in the second storage area is decrypted and verified. Data that passes the decryption verification is stored in the first storage area. Data that fails the decryption verification is determined to be attack data. The risk level is quantitatively assessed based on the threat level of the attack data. The security defense mode is switched according to the quantitative assessment result to obtain the target security defense mode.

[0051] In some embodiments, the specific implementation of the decryption verification in step S2 includes steps S21 to S23, wherein: S21, decrypt the data in the second storage area, and determine the data that fails to be decrypted as attack data.

[0052] It is understandable that the data stored in the second storage area is unverified data whose identification code verification failed, and its source is questionable. Further decryption is required to determine its nature. In the context of nuclear power plant information security management, legitimate data is encrypted and appended with corresponding identification codes before entering the control system. Therefore, data with a legitimate source should be able to be correctly decrypted during the decryption process.

[0053] It should be noted that when decryption fails, it indicates that the data has not undergone a legitimate encryption process and does not possess the basic characteristics of legitimate data. It is therefore identified as attack data and stored in the historical database for future optimization and iteration of the risk assessment model.

[0054] S22, perform permission identification verification on the data that has been successfully decrypted, re-encrypt the data that has passed the permission identification verification, and store it in the first storage area.

[0055] Understandably, data that has been successfully decrypted possesses basic legitimate encryption characteristics and needs further verification to determine whether it carries a valid employee access permission identifier code, in order to determine whether the data was initiated by an employee with legitimate permissions.

[0056] In some embodiments, the permission identifier verification includes checking whether the decrypted data carries an employee access permission identifier code that already exists in the access control list, and determining whether the employee has the corresponding data entry permission based on the employee's access permission level in the access control list and the storage address contained in the decrypted data. When the employee has the corresponding data entry permission, the data is re-encrypted and stored in the first storage area with a random key; when the employee does not have the corresponding data entry permission, the data is identified as attack data and stored in the historical database for recording.

[0057] S23, perform transmission protocol encoding verification on data that fails the permission identifier verification, re-encrypt data that passes the transmission protocol encoding verification, store it in the first storage area, and determine data that fails the transmission protocol encoding verification as attack data.

[0058] Understandably, data that fails access control verification does not carry a valid employee access permission code and requires further verification to determine if it is data normally transmitted between the various subsystems of the nuclear power plant. There is a large amount of data exchange between the various subsystems of the nuclear power plant. When transmitted data is first output at the sending end, a unique transmission protocol code is attached to it to identify the legitimate source of the data transmission.

[0059] In some embodiments, the transmission protocol encoding verification includes querying the control center for the output terminals and their respective secure file transfer protocols of all output data within one minute prior to receiving the data, decrypting the transmission protocol encoding carried in the data, and matching the decrypted and identified transmission protocol encoding with the output records returned by the control center. When the transmission protocol encoding exists in the output records, it is determined to be transmitted data, and the data is re-encrypted and stored in the first storage area along with a random key. When the following conditions occur, it is determined to be attack data: the transmission protocol encoding cannot be decrypted, the transmission protocol encoding does not exist, or the transmission protocol encoding does not exist in the output records returned by the control center within one minute, the attack data is stored in the historical database for recording and optimization of the risk assessment model.

[0060] Furthermore, after completing the decryption verification and identifying the attack data, the risk level is quantitatively assessed based on the threat level of the attack data. Specific implementation methods include steps S24-S25, wherein: S24. Based on the access permission level of the data attacked by the attack data, classify the threat level of the attack data.

[0061] Understandably, in the context of nuclear power plant information security management, the impact of data with different access levels on the operational safety of nuclear power plants varies significantly. The lower the access level of the data, the more sensitive the core operational information it involves, and the higher the threat to the information security of the nuclear power plant after being attacked.

[0062] In some embodiments, the threat level classification rules are as follows: When the attack data originates from malicious data already recorded in a historical database, the threat level is classified as Level I, and the attack intensity is high; when the attacked data has the fewest access holders and is classified as top secret, the threat level is Level II, and the attack intensity is medium; when the number of access holders is large and the data is classified as confidential, the threat level is Level III, and the attack intensity is low; when anyone is allowed access and the data is classified as ordinary, the threat level is Level IV, and the attack intensity is ordinary. The attack intensity is deducted in descending order of threat level, with deductions of 10, 8, 6, and 2 points respectively.

[0063] S25. Based on the threat level, the attack intensity of the attack data, and the vulnerability of the system, a risk assessment function is constructed to quantify the risk level and obtain a risk assessment value.

[0064] Understandably, in the context of nuclear power plant information security management, simply relying on qualitative classification of threat levels cannot accurately reflect the actual risk level under different attack scenarios. It is necessary to comprehensively quantify threat levels, attack intensity, and system vulnerability to support precise decision-making regarding subsequent security defense mode switching. Therefore, a risk assessment value is introduced, expressed as: in, The overall level of risk; This represents the upper limit of the integration, indicating the probability that the attack will be detected. For the first The severity of the impact after a successful attack; This is a risk factor function that comprehensively describes the relationship between attack characteristics and system response; The attack intensity of the attack data corresponds to the comprehensive deduction result of the threat level classification in step S24; The threat level corresponds to levels I to IV as defined in step S24. The vulnerability level of the system reflects the exposed area of ​​the nuclear power plant's current information security protection system when facing attacks; This represents the probability of an attack occurring. This represents the total number of attack data points included in the assessment.

[0065] Furthermore, risk factor function Expressed as: Understandable The ratio of attack intensity to threat level is used as an index to describe the amplification effect of the excess of attack intensity relative to threat level on risk. In the context of nuclear power plant information security, when the attack intensity is significantly higher than the expected defense capability corresponding to the current threat level, the risk level increases exponentially, reflecting the breakthrough threat that high-intensity attacks pose to the information security protection system of nuclear power plants. This term uses the ratio of system vulnerability level to threat level as a parameter to describe the logarithmic gain effect of the excess of system exposure area relative to the current threat level on risk. When the system vulnerability level is high and the threat level is low, the logarithmic gain is limited, avoiding the over-amplification of the overall risk assessment by low-threat level attacks, which meets the actual needs of nuclear power plant information security management to maintain an appropriate response to low-threat attacks.

[0066] Furthermore, based on the aforementioned risk assessment value The decision to switch the security defense mode is made, and the specific implementation includes steps S26 to S28, wherein: S26, when the risk assessment value is less than or equal to the first preset threshold, maintain the targeted mode, and in the targeted mode, call up targeted defense measures to perform defense.

[0067] It is understood that in some embodiments, the first preset threshold is 0.5. When If the risk level is deemed low, it indicates that the threat level of the current attack data is within the range of Level I or below, and that existing targeted defense measures can effectively address the situation, thus maintaining the existing targeted defense model.

[0068] In some embodiments, the specific implementation of the targeted mode is as follows: When attack data or malicious data attacks the database for the first time, a security analysis report is generated based on the attack direction, attack intensity, and damage results. Nuclear power plant staff study targeted measures based on the security analysis report and input them into the security protocol. When subsequent attack data appears, the corresponding targeted measures in the security protocol are retrieved to perform defense, with the targeted mode being selected as the priority for defense.

[0069] S27. When the risk assessment value is greater than the first preset threshold and less than or equal to the second preset threshold, switch to the merging mode. In the merging mode, calculate the correlation between each defense measure in the security protocol and the attack data, and select the defense measure with the highest correlation to merge and execute.

[0070] It is understood that in some embodiments, the second preset threshold is 0.8. When If the attack is classified as medium risk, it indicates that the threat level of the current attack data is above Level II. The security protocol may not have any targeted measures that are completely matched with the current attack data. It is necessary to calculate the correlation of the defense measures through the merging mode and then carry out combined defense.

[0071] In some embodiments, the merging mode is activated when one of the following two triggering conditions is met: Condition 1 is that when the access control list determines that the data is attacking, the corresponding targeted measures cannot be retrieved or there are no corresponding targeted measures in the security protocol; Condition 2 is that after defending against the targeted mode, the network path or data information is still damaged or leaked.

[0072] It should be noted that the correlation between the various defensive measures and the attack data is determined by a correlation function. The calculation is performed and expressed as follows: in, A collection of targeted defense measures With attack data set The correlation between them; The number of targeted defensive measures; The amount of attack data; For the first A quantitative value for the effectiveness of a targeted defense measure; For the first A quantitative value representing the severity of an attack; This represents the probability that there are no corresponding specific measures in the security protocol. The probability of an access control list being identified as attack data; For The Gaussian weighted term for the standard deviation describes the first... The first defensive measure and the first The degree of matching of each attack data point along the index dimension; For The Gaussian weighted term for the standard deviation describes the first... The effectiveness quantification value of the first defensive measure and the first The degree of numerical matching between the quantified values ​​of the severity of each attack.

[0073] Understandable By performing a double Gaussian weighted summation on the product of the quantified value of the effectiveness of defensive measures and the quantified value of the severity of attack data, the correspondence between defensive measures and attack data in the index dimension is considered, as well as the degree of matching between the two in terms of the numerical values ​​of effectiveness and severity. In the context of information security management in nuclear power plants, the above-mentioned double Gaussian weighting mechanism can effectively screen out combinations of defensive measures that are highly matched in terms of both defensive effectiveness and attack severity, avoiding the problem of mismatch between defensive measures and attack data caused by simply selecting based on index order or a single numerical dimension.

[0074] Furthermore, the two most relevant defense measures are selected and merged to generate an attack report, which is sent to the control center. The control center adjusts the defense measures based on the attack report and returns the adjustment results. The returned defense measures are then used to defend against the attack. When the attack stops or the current attack data can no longer damage the database or network path, the system switches back to the targeted mode. When the attack intensity increases or the damage level increases, the system switches to the comprehensive mode, and all processing procedures and merging results are stored in the historical database.

[0075] S28, when the risk assessment value is greater than the second preset threshold, switch to the comprehensive mode, trigger the nuclear power plant comprehensive defense mechanism in the comprehensive mode, repair the damaged area, and synchronize the status of the multiple independent nodes through the consensus algorithm.

[0076] It is understandable that, in some embodiments, when If the attack is deemed high-risk, it indicates that the threat level of the current attack data is above Level III, and the targeted and combined measures stored in the security protocol are unable to prevent the attack data or the attack data has directly caused information leakage and network path paralysis. It is necessary to switch to the comprehensive mode to activate the nuclear power plant's comprehensive defense mechanism for multi-layered defense.

[0077] In some embodiments, the integrated mode does not use the targeted measures and merging measures stored in the security protocol, but adopts the nuclear power plant integrated defense mechanism to carry out multi-layered defense of the entire network, repairs all damaged parts and then performs network-wide optimization and updates, and synchronizes the status of all network nodes through consensus algorithms to restore the overall consistency of the distributed access control system.

[0078] S3, under the target security defense mode, perform real-time analysis of network attacks, update security protocols based on the analysis results, isolate damaged areas caused by network attacks, and perform hierarchical reconstruction of network paths and information security protocol logic of the damaged areas based on the degree of damage to the damaged areas.

[0079] In some embodiments, the specific implementation of step S3 in the target security defense mode, which involves real-time analysis of network attacks, updating security protocols based on the analysis results, and isolating the damaged areas caused by network attacks, is as follows: Understandably, in the context of nuclear power plant information security management, when a cyberattack breaches the security defenses and causes actual damage, the affected area must be immediately isolated to prevent further penetration of attack data into normal network areas. Upon detecting a cyberattack, network segmentation technology is used to isolate the attacked physical or logical area, logically severing the connection between the damaged area and the normally operating nuclear power plant network area, thus preventing attack data from spreading to undamaged areas via data exchange channels between nuclear power plant subsystems.

[0080] It should be noted that after the damaged area is isolated, necessary communication between the various subsystems of the nuclear power plant is maintained through backup network links to ensure that the real-time transmission of critical operating data of the nuclear power plant is not interrupted due to network attack events, while waiting for the original link to be repaired.

[0081] Furthermore, while implementing the isolation of the damaged area, the security protocol is updated in real time based on the attack direction, attack methods, and damage caused by the network attack. The analysis results and countermeasures of this attack event are recorded in the security protocol for use in defense decisions against subsequent identical or similar attacks.

[0082] Furthermore, after completing the isolation of the damaged area and the update of the security protocol, based on the degree of damage to the damaged area, the network path and information security protocol logic of the damaged area are reconstructed in a hierarchical manner. The specific implementation includes steps S31-S33, wherein: S31, when the degree of damage to the damaged area is less than a first preset ratio, perform targeted updates to the network path and information security protocol logic of the damaged area, verify the update results, and if the verification is successful, deploy to the damaged area.

[0083] It is understood that in some embodiments, the first preset ratio is 10%. When the damage level of the damaged area is less than 10%, it indicates that the network attack only damages local nodes or local network paths, and the overall information security architecture of the nuclear power plant has not been fundamentally damaged. The damage can be repaired by updating the network paths and information security protocol logic at the damaged locations.

[0084] In some embodiments, the targeted update is implemented as follows: First, the specific attacked nodes and damaged network paths are identified, and the attack methods and entry points used in this attack are analyzed; further, the information security protocol logic of the damaged area is specifically revised in response to the identified attack methods to block the security vulnerabilities exploited by this attack; even further, the updated network paths and information security protocol logic are tested and verified in an isolated environment. After confirming that the updated protocol logic can effectively resist similar attacks and does not affect the normal data access process, the updated protocol logic is deployed to the damaged area to restore the normal operation of the area.

[0085] S32, when the degree of damage to the damaged area is greater than or equal to a first preset ratio and less than a second preset ratio, security hardening is performed on the damaged area and related areas, network security policy is reviewed, and access restrictions are implemented on the security vulnerabilities identified in the review.

[0086] It is understood that in some embodiments, the second preset ratio is 70%. When the damage level of the damaged area is greater than or equal to 10% and less than 70%, it indicates that the network attack has caused significant damage to the information security architecture of the nuclear power plant. The surrounding related areas also face the risk of being attacked and penetrated, and it is necessary to implement active defense reinforcement for the related areas while repairing the damaged area.

[0087] In some embodiments, the specific implementation of the security hardening is as follows: First, the network path and information security protocol logic of the damaged area are updated and repaired; further, security hardening is performed on associated areas that have data interaction relationships with the damaged area, the access control level of the associated areas is improved, and unnecessary cross-regional data transmission is restricted; even further, a comprehensive review of the security policy of the entire nuclear power plant information security network is carried out, focusing on investigating potential security vulnerabilities related to this attack method; access restrictions are implemented on the security vulnerabilities identified in the review, and before the formal repair plan is determined, temporary access restriction measures are used to block the attack path targeting the vulnerability, preventing attackers from using similar vulnerabilities to cause further damage to the information security of the nuclear power plant.

[0088] S33, when the degree of damage to the damaged area is greater than or equal to the second preset ratio, disconnect the network connection, replace the information security protocol logic, and reconfigure the damaged network device.

[0089] Understandably, when the damage level of the affected area is greater than or equal to 70%, it indicates that the cyberattack has severely damaged the information security architecture of the nuclear power plant. The existing information security protocol logic can no longer effectively support the information security management of the nuclear power plant under the current damaged state, and an emergency response plan needs to be initiated for a comprehensive reconstruction.

[0090] In some embodiments, the emergency response plan is implemented as follows: immediately disconnect the entire network connection of the nuclear power plant to cut off all possible paths for the attack data to continue to penetrate; further, completely replace the information security protocol logic of the entire nuclear power plant information security network, and rebuild the information security protection system with a new security architecture and security strategy; even further, conduct a comprehensive inspection of the damaged network equipment, reconfigure the security of the repairable damaged network equipment, and replace the unrepairable damaged network equipment to ensure that there are no residual attack entry points or damaged nodes in the rebuilt nuclear power plant information security architecture.

[0091] It is easy to understand that after the above-mentioned hierarchical reconstruction is completed, the control state of the multiple independent nodes is resynchronized through a consensus algorithm, and the reconstructed information security protocol logic is synchronized to all independent nodes in the network.

[0092] Example 2, an embodiment of the present invention, provides a method for information security management in nuclear power plants. To verify the beneficial effects of the present invention, scientific demonstration is conducted through experiments: In some embodiments, a nuclear power plant information security management system is selected as the experimental environment. This nuclear power plant comprises four subsystems: a reactor control subsystem, a cooling system monitoring subsystem, a power grid monitoring subsystem, and a personnel access management subsystem. These subsystems interact with each other via the nuclear power plant's internal network. In the experiment, three typical attack scenarios—data leakage, malware attacks, and phishing—are simulated for the aforementioned nuclear power plant information security management system. For each scenario, existing technologies are compared with the method described in this invention. The evaluation dimensions include three indicators: risk score, attack success probability, and data leakage amount. The risk score is calculated based on the risk assessment value described in step S25.

[0093] It should be noted that the three attack scenarios differ fundamentally in their attack methods and targets: the data breach scenario simulates unauthorized access requests to both access-related and non-access-related data; the malware attack scenario simulates data packets carrying malicious code being infiltrated into the data interaction process between various subsystems of a nuclear power plant through forged key identifier encoding; and the phishing scenario simulates unauthorized access requests forged employee access permission identifier encoding. These three scenarios correspond to the core defense capabilities of the identifier encoding differentiation storage mechanism, transmission protocol encoding verification mechanism, and access control list permission verification mechanism in the method described in this invention. The experimental results are shown in Table 1 below. Table 1 Comparison of Experimental Analysis

[0094] Understandably, in a data breach scenario, the risk score of existing technologies is 8.5, while the risk score of the method described in this invention is 2.3. The probability of a successful attack is reduced from 0.71 to 0.15, and the amount of data leaked is reduced from 150MB to 10MB. Existing technologies lack a differentiated identification and encoding mechanism for access-related and non-access-related data. Attack data can directly infiltrate legitimate data streams during the identification and encoding check. However, the method described in this invention, through step S13's step-by-step verification of the access identity identifier, key identifier, and employee permission identifier, isolates data without a valid identifier to the second storage area. Combined with the mechanism in step S21 where decryption failure is identified as attack data, interception is completed before the data enters the first storage area, significantly narrowing the path for attack data to breach access control.

[0095] In a malware attack scenario, the existing technology has a risk score of 7.9, while the method described in this invention has a risk score of 1.8. The probability of successful attack is reduced from 0.63 to 0.08, and the amount of data leakage is reduced from 120MB to 5MB. Malware infiltrates the data interaction process between nuclear power plant subsystems by forging key identifier codes. Existing technologies lack timely verification methods for the legitimacy of transmitted data and cannot distinguish between normal transmitted data and malicious data packets with forged transmission identifiers. The method described in this invention, through the verification of transmission protocol codes matching in the output records within a one-minute time window in step S23, identifies transmission protocol codes not present in the output records as attack data, cutting off the path for malware to spread through the data interaction channel between subsystems. After the risk assessment value enters the medium-risk range, step S27, based on... The computational merging mode targets the multi-path composite attack characteristics of malware, selecting the defense measures with the highest match between the effectiveness quantification value and the degree of attack harm from security protocols and executing them in combination. Compared with the fixed defense strategy of existing technologies, the matching accuracy between defense measures and attack methods is improved.

[0096] In phishing scenarios, the risk score of existing technologies is 6.8, while the risk score of the method described in this invention is 1.2. The success rate of the attack is reduced from 0.54 to 0.03, and the amount of data leakage is reduced from 80MB to 2MB. Phishing attacks rely on forging employee access permission identifiers to bypass identity authentication. Existing technologies lack joint verification methods for employee permission levels and storage address access permissions, allowing forged identity data packets to pass single identity verification with a high probability. The method described in this invention, in step S22, jointly compares the storage address contained in the decrypted data with the employee permission level in the access control list. Provided the employee identity identifier is valid, it further verifies whether the employee has the entry permission for the corresponding storage address. This ensures that attack data with forged employee identities but mismatched permission levels is identified during the permission identifier verification stage, suppressing the success rate of the attack to 0.03, the lowest among the three scenarios, consistent with the attack pattern of phishing attacks being characterized by single features and relying on a single forgery method.

[0097] Example 3 is an embodiment of the present invention, which provides a nuclear power plant information security management system, including: The data management module is used to divide the nuclear power plant operation status data into access data and non-access data based on access permission levels. According to the access permission levels, the access data and the non-access data are respectively assigned identification codes and stored in the first storage area. Based on the access permission levels, the access control logic is deployed on multiple independent nodes. The control status of the multiple independent nodes is synchronized through a consensus algorithm to establish a distributed access control system. The risk assessment module is used to perform identification and encoding verification on the received data to be verified based on the distributed access control system, store the data to be verified that fails the identification and encoding verification into the second storage area, perform decryption verification on the data in the second storage area, store the data that passes the decryption verification into the first storage area, determine the data that fails the decryption verification as attack data, quantify the risk level based on the threat level of the attack data, and switch the security defense mode according to the quantitative assessment result to obtain the target security defense mode. The emergency reconstruction module is used to perform real-time analysis of network attacks under the target security defense mode, update security protocols based on the analysis results, isolate damaged areas caused by network attacks, and perform hierarchical reconstruction of network paths and information security protocol logic of the damaged areas based on the degree of damage to the damaged areas.

[0098] This embodiment also provides an electronic device applicable to a nuclear power plant information security management method, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the nuclear power plant information security management method proposed in the above embodiment.

[0099] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements a nuclear power plant information security management method as proposed in the above embodiments.

[0100] The storage medium proposed in this embodiment belongs to the same inventive concept as the method for implementing information security management of nuclear power plants proposed in the above embodiments. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.

[0101] Based on the above description of the implementation methods, those skilled in the art can clearly understand that the present invention can be implemented using software and necessary general-purpose hardware, and of course, it can also be implemented using hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a computer floppy disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk, or optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0102] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for information security management in nuclear power plants, characterized in that, include: Based on access permission levels, nuclear power plant operation status data is divided into access data and non-access data. Based on the access permission levels, the access data and non-access data are respectively assigned identification codes and stored in the first storage area. Based on the access permission levels, access control logic is deployed on multiple independent nodes. The control status of the multiple independent nodes is synchronized through a consensus algorithm to establish a distributed access control system. Based on the distributed access control system, the received data to be verified is identified and encoded. Data that fails the identification and encoding verification is stored in the second storage area. The data in the second storage area is decrypted and verified. Data that passes the decryption verification is stored in the first storage area. Data that fails the decryption verification is determined to be attack data. The risk level is quantitatively assessed based on the threat level of the attack data. The security defense mode is switched according to the quantitative assessment result to obtain the target security defense mode. Under the target security defense mode, network attacks are analyzed in real time, security protocols are updated based on the analysis results, damaged areas caused by network attacks are isolated, and network paths and information security protocol logic of the damaged areas are reconstructed in a hierarchical manner based on the degree of damage to the damaged areas.

2. The nuclear power plant information security management method as described in claim 1, characterized in that, The additional identifier code includes: An access identity code is attached to the access-type data, and the access-type data is stored in the first storage unit of the first storage area; The non-accessible data is encrypted, and a key identifier is added to the non-accessible data based on the key generated by the encryption process. The non-accessible data is then stored in a second storage unit in the first storage area.

3. The nuclear power plant information security management method as described in claim 2, characterized in that, The identifier encoding verification includes: Check whether the data to be verified carries the access identity identifier code, the key identifier code, or the employee permission identifier code; The data to be verified, carrying the access identity identifier code, the key identifier code, or the employee permission identifier code, is allowed to access the first storage area; Data to be verified that does not include the access identity identifier code, the key identifier code, and the employee permission identifier code is stored in the second storage area.

4. The nuclear power plant information security management method as described in claim 3, characterized in that, The decryption verification includes: The data in the second storage area is decrypted, and data that fails to be decrypted is identified as attack data. For data that has been successfully decrypted, perform permission identification verification. Re-encrypt the data that has passed the permission identification verification and store it in the first storage area. Data that fails the permission identifier verification is verified by the transmission protocol encoding. Data that passes the transmission protocol encoding verification is re-encrypted and stored in the first storage area. Data that fails the transmission protocol encoding verification is identified as attack data.

5. The nuclear power plant information security management method as described in claim 4, characterized in that, The quantitative assessment includes: The threat level of the attack data is classified according to the access permission level of the data attacked. A risk assessment function is constructed based on the threat level, the attack intensity of the attack data, and the vulnerability of the system to quantify the risk level and obtain a risk assessment value.

6. The nuclear power plant information security management method as described in claim 5, characterized in that, The switching of security defense mode includes: When the risk assessment value is less than or equal to the first preset threshold, the targeted mode is maintained, and targeted defense measures are invoked and executed in the targeted mode. When the risk assessment value is greater than the first preset threshold and less than or equal to the second preset threshold, switch to the merging mode. In the merging mode, calculate the correlation between each defense measure in the security protocol and the attack data, and select the defense measure with the highest correlation to merge and execute. When the risk assessment value exceeds the second preset threshold, the system switches to integrated mode, triggers the nuclear power plant integrated defense mechanism in integrated mode, repairs the damaged area, and synchronizes the status of the multiple independent nodes through a consensus algorithm.

7. The nuclear power plant information security management method as described in claim 6, characterized in that, The hierarchical reconstruction includes: When the damage level of the damaged area is less than a first preset ratio, a targeted update is performed on the network path and information security protocol logic of the damaged area, the update result is verified, and if the verification is successful, it is deployed to the damaged area; When the degree of damage to the damaged area is greater than or equal to a first preset ratio and less than a second preset ratio, security hardening is performed on the damaged area and related areas, network security policies are reviewed, and access restrictions are implemented on security vulnerabilities identified during the review. When the degree of damage to the damaged area is greater than or equal to the second preset ratio, the network connection is disconnected, the information security protocol logic is replaced, and the damaged network device is reconfigured.

8. A nuclear power plant information security management system, employing the nuclear power plant information security management method as described in any one of claims 1 to 7, characterized in that, include: The data management module is used to divide the nuclear power plant operation status data into access data and non-access data based on access permission levels. According to the access permission levels, the access data and the non-access data are respectively assigned identification codes and stored in the first storage area. Based on the access permission levels, the access control logic is deployed on multiple independent nodes. The control status of the multiple independent nodes is synchronized through a consensus algorithm to establish a distributed access control system. The risk assessment module is used to perform identification and encoding verification on the received data to be verified based on the distributed access control system, store the data to be verified that fails the identification and encoding verification into the second storage area, perform decryption verification on the data in the second storage area, store the data that passes the decryption verification into the first storage area, determine the data that fails the decryption verification as attack data, quantify the risk level based on the threat level of the attack data, and switch the security defense mode according to the quantitative assessment result to obtain the target security defense mode. The emergency reconstruction module is used to perform real-time analysis of network attacks under the target security defense mode, update security protocols based on the analysis results, isolate damaged areas caused by network attacks, and perform hierarchical reconstruction of network paths and information security protocol logic of the damaged areas based on the degree of damage to the damaged areas.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the nuclear power plant information security management method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the nuclear power plant information security management method according to any one of claims 1 to 7.