Power station intelligent terminal trusted identity authentication method, system and device, and medium

CN122802233APending Publication Date: 2026-09-22GUANGXI GUIGUAN KAITOU ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611026971.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-10
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0004]有鉴于此,本公开实施例提供了一种电站智能终端可信身份认证方法及系统、装置、介质,能够解决现有接入认证方法无法精准识别电站智能终端的身份,无法实现电站现场数据源的有效安全防护等问题

Benefits of technology

[0010]本公开实施例提供的电站智能终端可信身份认证方法,基于芯片固有工艺偏差生成不可复制、不可篡改的硬件物理指纹向量,从硬件源头阻断仿冒终端入网风险;会话密钥结合专属硬件指纹向量与本次接入请求的时间戳共同进行哈希扰动动态生成,实现一次接入对应一组独立会话密钥,大幅缩减密钥泄露带来的攻击范围;将会话密钥、硬件物理指纹向量、接入时间戳、设备唯一标识以及工控业务数据多类安全关联要素生成可信凭证数据包上传,工控主站对数据包进行多维校验,任一维度校验不通过即确定发起接入请求的电站智能终端的身份不可信,拒绝接入,能够精确、快速地进行电站智能终端的可信身份认证,能够实现电站现场数据源的有效安全防护。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802233A_ABST
    Figure CN122802233A_ABST
Patent Text Reader

Abstract

The application discloses a power station intelligent terminal trusted identity authentication method and system, device and medium. The method comprises the following steps: in response to an access request initiated by a power station intelligent terminal, collecting multi-dimensional physical characteristics corresponding to a physical hardware layer, and generating a hardware physical fingerprint vector accordingly; performing hash disturbance processing on the timestamp of the access request and the hardware physical fingerprint vector, and dynamically generating a session key corresponding to the current session; generating a trusted credential data packet according to the session key, the hardware physical fingerprint vector, the timestamp corresponding to the access request, the device identifier of the power station intelligent terminal and the industrial control data corresponding to the access request; uploading the trusted credential data packet to an industrial control master station, and performing multi-dimensional information verification on the trusted credential data packet by the industrial control master station; and when all the multi-dimensional information passes the verification, generating an instruction allowing the power station intelligent terminal to access. The method can accurately identify the identity of the power station intelligent terminal to be accessed, and effectively and safely protect the data source of the power station site.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of power plant field data protection technology, and in particular to a trusted identity authentication method, system, device, and medium for power plant smart terminals. Background Technology

[0002] As new power systems are undergoing comprehensive upgrades towards intelligence and networking, various intelligent terminal devices such as RTUs and PLCs have become the core basic units of power plant industrial control networks. They are widely deployed at various field locations in power plants and are fully responsible for key tasks such as collecting equipment operation data and executing dispatch instructions. The authenticity of the identity of these terminal devices and the security of data transmission directly determine the operational stability of the power plant industrial control system and are key links to ensure the safety of power production and the accuracy of dispatch.

[0003] Currently, most power plants in China use traditional pure software protection solutions for intelligent terminal access control, such as account password authentication, fixed key verification, and IP address binding. These solutions are widely used due to their simple architecture and low deployment cost. However, they only achieve the most basic access control and prevent crude unauthorized network access. Since core data such as terminal identity information, authentication keys, and binding configurations are stored in the software firmware, unauthorized personnel can easily forge legitimate terminal identities through simple operations such as flashing the firmware, tampering with the program, and copying / cloning configurations. Once a counterfeit terminal successfully accesses the power plant's industrial control network, the counterfeit device can remain hidden within the internal network for a long time. The system cannot distinguish between genuine and counterfeit devices based solely on IP address and key, making it difficult for inspection and monitoring to detect, thus forming a concealed and persistent attack channel. It is understood that counterfeit terminals can intercept and steal core operational data such as voltage, current, switch status, and protection actions in batches, causing data leaks. They can also intercept control commands, replay messages, tamper with operating parameters, and upload false operating information to the main station. Attackers can also issue false opening and closing and power adjustment commands through counterfeit devices, causing unplanned unit shutdowns, line trips, and transformer overloads. This can result in minor issues such as partial power outages and unstable plant power, or even damage to large high-voltage power equipment, leading to high maintenance and power outage losses. After false data is uploaded to the regional dispatch platform, it will interfere with load forecasting, power flow calculation, and stability control strategy formulation, causing the dispatcher to make incorrect control decisions, resulting in power grid imbalance, and even triggering cascading trips and large-scale power outages. Summary of the Invention

[0004] In view of this, the present disclosure provides a trusted identity authentication method, system, device, and medium for power plant smart terminals, which can solve the problems that existing access authentication methods cannot accurately identify the identity of power plant smart terminals and cannot achieve effective security protection of power plant field data sources.

[0005] In a first aspect, embodiments of this disclosure provide a trusted identity authentication method for a power plant smart terminal, including: In response to the access request initiated by the power station intelligent terminal, the system collects the multi-dimensional physical features corresponding to the physical hardware layer of the power station intelligent terminal device, and generates a hardware physical fingerprint vector based on the multi-dimensional physical features. The timestamp of the access request and the hardware physical fingerprint vector are hashed and perturbed to dynamically generate the session key corresponding to this session. A trusted credential data packet is generated based on the session key, the hardware physical fingerprint vector, the timestamp corresponding to the access request, the device identifier of the power station smart terminal, and the industrial control data corresponding to the access request. The trusted credential data packet is uploaded to the industrial control master station. The industrial control master station performs multi-dimensional information verification on the trusted credential data packet. When all multi-dimensional information passes the verification, an instruction is generated to allow the power station smart terminal to access.

[0006] Secondly, this disclosure also provides a trusted identity authentication system for power plant smart terminals, comprising: The hardware physical fingerprint vector generation unit is used to respond to the access request initiated by the power station smart terminal, collect the multi-dimensional physical features corresponding to the physical hardware layer of the power station smart terminal device, and generate a hardware physical fingerprint vector based on the multi-dimensional physical features. The perturbation unit is used to perform hash perturbation processing on the timestamp of the access request and the hardware physical fingerprint vector to dynamically generate the session key corresponding to this session. The trusted credential data packet generation unit is used to generate a trusted credential data packet based on the session key, the hardware physical fingerprint vector, the timestamp corresponding to the access request, the device identifier of the power station smart terminal, and the industrial control data corresponding to the access request. The analysis unit is used to upload the trusted credential data packet to the industrial control master station. The industrial control master station performs multi-dimensional information verification on the trusted credential data packet. When all multi-dimensional information passes the verification, an instruction is generated to allow the power station smart terminal to access.

[0007] Thirdly, this disclosure also provides a computer device, which adopts the following technical solution: The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor; the instructions are executed by the at least one processor to enable the at least one processor to execute any of the above-described power station smart terminal trusted identity authentication methods.

[0008] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing computer instructions; the computer instructions are used to cause a computer to execute any of the above-described power plant smart terminal trusted identity authentication methods.

[0009] Fifthly, embodiments of this disclosure also provide a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of any of the methods described above.

[0010] The power plant smart terminal trusted identity authentication method provided in this disclosure generates an uncopyable and tamper-proof hardware physical fingerprint vector based on inherent chip process deviations, blocking the risk of counterfeit terminals entering the network from the hardware source. The session key is dynamically generated by hashing and perturbation together with the exclusive hardware fingerprint vector and the timestamp of the current access request, so that each access corresponds to a set of independent session keys, which greatly reduces the attack scope caused by key leakage. The session key, hardware physical fingerprint vector, access timestamp, device unique identifier and industrial control business data are used to generate a trusted credential data packet and uploaded. The industrial control master station performs multi-dimensional verification on the data packet. If any dimension verification fails, the identity of the power plant smart terminal that initiated the access request is determined to be untrustworthy and access is rejected. It can accurately and quickly perform trusted identity authentication of power plant smart terminals and can effectively protect the data source of the power plant site.

[0011] The above description is merely an overview of the technical solution disclosed herein. In order to better understand the technical means of this disclosure and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description

[0012] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart illustrating the trusted identity authentication method for power plant smart terminals provided in this embodiment of the disclosure.

[0014] Figure 2 This is a flowchart illustrating the method for generating hardware physical fingerprint vectors provided in this embodiment of the disclosure.

[0015] Figure 3 This is a flowchart illustrating the method for dynamically generating the session key corresponding to the current session provided in this embodiment of the disclosure.

[0016] Figure 4 This is a flowchart illustrating the method for generating a trusted credential data packet provided in an embodiment of this disclosure.

[0017] Figure 5 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. Detailed Implementation

[0018] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.

[0019] It should be understood that the following specific examples illustrate the implementation of this disclosure, and those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0020] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.

[0021] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this disclosure. The drawings only show the components related to this disclosure and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0022] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0023] Reference Figure 1 This application discloses a trusted identity authentication method for a power plant smart terminal, comprising: S100, in response to the access request initiated by the power station smart terminal, collects the multi-dimensional physical features corresponding to the physical hardware layer of the power station smart terminal device, and generates a hardware physical fingerprint vector based on the multi-dimensional physical features.

[0024] S200 performs hash perturbation processing on the timestamp of the access request and the hardware physical fingerprint vector to dynamically generate the session key corresponding to this session.

[0025] The session key contains device hardware characteristics and timing constraints, enabling the key and the terminal device to form an inseparable binding relationship at the physical layer.

[0026] S300 generates a trusted credential data packet based on the session key, hardware physical fingerprint vector, timestamp corresponding to the access request, device identifier of the power station smart terminal, and industrial control data corresponding to the access request.

[0027] The S400 uploads the trusted credential data packet to the industrial control master station. The industrial control master station performs multi-dimensional information verification on the trusted credential data packet. When all multi-dimensional information passes the verification, it generates an instruction to allow the power station's intelligent terminal to access the network.

[0028] The power plant intelligent terminal trusted identity authentication method disclosed in this application generates an uncopyable and tamper-proof hardware physical fingerprint vector based on the inherent process deviation of the chip, blocking the risk of counterfeit terminals entering the network from the hardware source. The session key abandons the static pre-setting mode and dynamically generates it by combining the exclusive hardware fingerprint vector and the timestamp of the current access request through hash perturbation, so that each access corresponds to a set of independent session keys, which greatly reduces the attack scope caused by key leakage. At the same time, it deeply binds the inherent physical identity of the device with the timeliness of communication, avoiding the security vulnerability of old key reuse to forge messages. The session key, hardware physical fingerprint vector, access timestamp, device unique identifier and industrial control business data are uniformly encapsulated into a single trusted credential data packet for uploading. All kinds of information are mutually constrained and bound. Tampering with any data will cause the overall verification to fail. It can also reduce the number of multi-round interaction messages, adapt to industrial narrowband communication, reduce transmission latency, and take into account the security strength and industrial control real-time requirements. The industrial control master station performs multi-dimensional verification on data packets. If any dimension fails the verification, the identity of the power plant smart terminal that initiated the access request is determined to be untrustworthy, and access is rejected. This method can accurately and quickly authenticate the trusted identity of the power plant smart terminal. This method strengthens the trustworthiness of the terminal identity at the hardware level and can effectively resist replay and spoofing attacks.

[0029] Reference Figure 2 The method for generating the physical fingerprint vector of the S100 hardware specifically includes: S110, in response to the access request initiated by the power station smart terminal, issues an authentication restart command to the power station smart terminal.

[0030] Specifically, in response to the access request initiated by the power station intelligent terminal to the industrial control master station, the industrial control master station issues an authentication restart command to the power station intelligent terminal. After verifying the validity of the command, the power station intelligent terminal performs a controlled soft restart.

[0031] S120 controls the power station's intelligent terminal to execute authentication and restart commands, and collects the transient current waveform characteristics of the chip's core power supply circuit within the first preset window after power-on, the dynamic drift characteristics of the crystal oscillator frequency within the second preset window after power-on, and the random state characteristics of the SRAM power-on within the third preset window before the power-on initialization and clearing operation.

[0032] In this embodiment, the multidimensional physical characteristics include transient current waveform characteristics caused by chip manufacturing process deviations, dynamic drift characteristics of crystal oscillator frequency, and power-on random state characteristics of SRAM.

[0033] The method for obtaining transient current waveform characteristics includes: using a current sensor connected in series on the main power supply circuit of the chip core to collect the entire transient current waveform within a time window of 0~500μs after the chip core power supply circuit is powered on.

[0034] Specifically, within the first preset window period of 0~500μs after the terminal device is powered on, the chip core power rail gradually rises from 0V to the rated voltage, and the transistors are turned on and charged and discharged in sequence. The transient current in the circuit is formed by the superposition of the simultaneous working states of all transistors. The process deviation is directly mapped to the amplitude, fluctuation frequency and zero-crossing distribution difference of the transient current waveform. This waveform has uniqueness that cannot be replicated by the device. Specifically, it is preferable to use a high-precision current sensor with a sampling rate of not less than 100MHz connected in series in the main power supply circuit of the chip core to collect the entire transient current waveform within the 0~500μs time window after the chip core power supply circuit is powered on.

[0035] The method for obtaining the dynamic drift characteristics of crystal oscillator frequency includes: taking a high-stability reference clock as a reference, acquiring the instantaneous frequency of the main crystal oscillator at intervals within a window of 500μs~5ms after power-on, and recording all the dynamic drift characteristics of crystal oscillator frequency as the dynamic drift characteristics of crystal oscillator frequency.

[0036] Specifically, within the stable window period of 500μs to 5ms after the terminal device is powered on during a cold start, two independent counters are simultaneously activated from the 500μs moment. The first counter is driven by a highly stable reference clock and is used to accurately time the standard duration of 1μs. Whenever the reference clock accumulates to the 1μs timing threshold, the pulse count value of the second main crystal oscillator counter is immediately latched and reset to zero. Then, the next round of 1μs timing and main crystal oscillator pulse statistics is restarted. This acquisition logic is executed cyclically until the total power-on time reaches 5ms, at which point the acquisition process stops.

[0037] The total number of main crystal oscillator pulses obtained within each 1μs standard duration is combined with the standard frequency of the reference clock and converted into the instantaneous actual oscillation frequency of the main crystal oscillator at the current moment through hardware fixed-point calculation, i.e., the instantaneous frequency of the main crystal oscillator. The instantaneous frequencies corresponding to each sampling moment are cached into the on-chip high-speed storage in the order of acquisition. The entire array of values ​​arranged by time is the original crystal oscillator frequency sequence, which serves as the dynamic drift feature of the crystal oscillator frequency.

[0038] The method for obtaining the power-on random state characteristics of SRAM includes: obtaining the initial bit state of the SRAM storage array before system initialization and clearing, and retaining stable bits that meet the preset consistency conditions after multiple rounds of power-on screening as the power-on random state characteristics of SRAM.

[0039] Specifically, before the terminal device powers on and the system initialization program executes the SRAM clearing operation, the underlying firmware driver is called to directly read the uninitialized original bit state of the on-chip SRAM storage array upon power-on. Based on the inherent manufacturing process mismatch of the CMOS storage cell bistable circuit, each storage cell automatically and randomly locks logic 0 or logic 1 upon power-on, generating an original PUF bit array with chip-unique randomness. Multiple rounds of repeated power-on consistency screening are performed on all SRAM bits, and only high-stability bits with a consistency rate of not less than 95% after multiple power-on reads are retained as the SRAM power-on random state characteristics.

[0040] The complete power-on process of the terminal has a clear timing sequence. The entire power-on process covers multiple stages, including chip power supply conduction, hardware circuit stabilization, firmware low-level initialization, and system service initialization. The original random bits of SRAM power-on only exist in an extremely narrow intermediate timing window when power-on is completed but the system initialization program has not yet executed the memory cell clearing. This window is within the 0~5ms overall power-on acquisition interval, and together with the 0~500μs current acquisition window and the 500μs~5ms crystal oscillator drift acquisition window, they belong to the continuous power-on cycle of one authentication restart.

[0041] During the 0-500μs power-on phase, the power supply circuit is established and transient current waveforms are acquired synchronously. From 500μs to 5ms after power-on, the hardware clock stabilizes and crystal oscillator frequency drift data is continuously acquired. Before the 5ms window ends and the system is officially initialized and the memory is erased, the firmware driver prioritizes reading the original bits of the SRAM. Once the clear operation is performed, the original random state will be completely overwritten and destroyed, and this set of physical characteristics cannot be reproduced during normal operation.

[0042] In this embodiment, the generation mechanisms of the three types of physical features—power-on transient current waveform, crystal oscillator frequency drift characteristics, and SRAM power-on random state—are independent of each other. They originate from chip transistor manufacturing deviations, crystal oscillator component process differences, and CMOS memory cell microcircuit mismatches, respectively. They belong to three completely isolated hardware dimensions: circuit power consumption, external clock, and memory cell, which can form multiple independent verification barriers. Even if one type of feature information is leaked, attackers cannot piece together a complete and legitimate device fingerprint, significantly increasing the difficulty of terminal counterfeiting.

[0043] S130 generates a hardware physical fingerprint vector based on transient current waveform characteristics, crystal oscillator frequency dynamic drift characteristics, and SRAM power-on random state characteristics.

[0044] This step specifically includes: S131, obtaining mean, peak, and zero-crossing features based on all transient current waveforms, and generating current waveform feature sub-vectors. Specifically, the mean, peak, and zero-crossing features are extracted from all transient current waveforms, and then the current waveform feature sub-vectors are generated based on the extracted information. The method for extracting the zero-crossing frequency features includes: using the change in the sign of the current values ​​at adjacent sampling points as the criterion for zero-crossing determination, traversing the normalized current waveform sequence point by point, and determining that a current zero-crossing exists at the current position when the product of the currents at two adjacent points is less than zero, and simultaneously counting the total number of zero-crossings within the entire 0~500μs acquisition window as the global zero-crossing feature.

[0045] S132: Based on the dynamic drift characteristics of all crystal oscillator frequencies, the mean deviation and variance are obtained, and a crystal oscillator drift feature sub-vector is generated. Specifically, based on the individual uniqueness of the drift trajectory caused by the differences in the quartz cutting angle and electrode coating thickness of different crystal oscillators, the mean deviation, variance, and autocorrelation coefficient statistical features of the frequency drift characteristics, i.e., the sequence, are extracted to generate a crystal oscillator drift feature sub-vector.

[0046] S133: Concatenate all SRAM power-on random state features in a fixed address order to obtain the original bit string, and normalize the original bit string to obtain the SRAM random state feature sub-vector.

[0047] The highly stable bits obtained through multiple power-on screenings are distributed across different memory address units in the SRAM. Since a single bit cannot carry unique identification information, all valid bits are sequentially concatenated into a complete original bit string according to a fixed address order. This approach relies on multiple bit combinations to achieve sufficient distinguishability while also unifying the bit arrangement rules.

[0048] Among them, Hamming weight normalization is preferred for normalization processing. The original bit string consists only of 0 and 1, which is easily affected by the overall process bias of chip batch and temperature and pressure disturbance, resulting in feature deviation. Through Hamming weight normalization processing, the bit distribution offset caused by the global process can be eliminated, the binary bit information can be converted into a standardized value with a unified value range, the error caused by a small number of bit flips can be weakened, and a stable SRAM random state feature subvector adapted to encryption and identity comparison scenarios can be output.

[0049] Reference Figure 3 The method for dynamically generating the session key corresponding to this S200 session includes: S210 normalizes each component in the hardware physical fingerprint vector to obtain the initial chaotic value.

[0050] Specifically, a modulo 256 operation is performed on each component of the hardware physical fingerprint vector, and the result of the modulo operation is normalized and mapped to the open interval (0,1) to obtain a chaotic initial value, which is highly sensitive to minute differences in the fingerprint.

[0051] S220: Hash the timestamp corresponding to the access request to obtain the timestamp hash value, and XOR the timestamp hash value with the chaotic initial value to generate a composite initial value.

[0052] Specifically, the microsecond-level timestamp T corresponding to the time the access request was initiated is obtained, and a lightweight hash compression function H(·) is used to perform hash compression processing on the microsecond-level timestamp T, and the hash compressed output is then obtained. With the initial value of chaos Perform XOR perturbation fusion to generate composite initial values. , This ensures that the composite initial value corresponding to a single session is globally unique and unpredictable.

[0053] Furthermore, a hash compression function H(・) is constructed using the round function of the SPECK64 lightweight block cipher. When an access request is triggered, a 64-bit microsecond-level timer count value T is read as input, which is directly used as a 64-bit input block without additional block padding. A set of fixed 32-bit constants is preset as the built-in confusion key for each round of iteration. The SPECK native circular right shift and modulo 2 shift are executed sequentially. 6The three basic nonlinear operations of addition and bitwise XOR are performed. After running 22 rounds of standard confusion iteration, the lower 32 bits of the output result are extracted as the hash compression output H(T). The entire operation only includes shift, addition and XOR operations. No additional table lookup and complex calculation are required. Even a small change in timestamp can cause an overall change in the compression result. It is adapted to low-computing industrial control terminals to quickly complete the nonlinear disassembly of timing information.

[0054] S230: Perform chaotic iteration based on composite initial values, remove initial unstable data to obtain a random sequence; extract valid bits from the random sequence and concatenate them to form the session key corresponding to this session.

[0055] The iterative formula is: With a composite initial value of 0.6241, 3.96 Taking version 1.95 as an example, a lightweight chaotic iteration was carried out. The first round of iteration... Substituting 0.6241, we get a new value. Then start the second round of iterations to As Continue calculating, and so on. The cyclical process is called chaotic iteration. 128 rounds of preliminary iteration are executed in advance and all outputs are discarded to eliminate the regular deviation caused by the instability of the initial values. That is, the cycle is repeated 128 times and all results are discarded directly because the values ​​of the initial rounds have strong regularity and poor randomness and must be discarded.

[0056] After the initial iteration ends, the calculation continues in a loop. The result of each iteration is multiplied by 256 and rounded down to the nearest integer. The lowest bit of the binary number is truncated as the effective key bit. 128 bits are extracted and concatenated to generate a 128-bit session key. The iteration is extended to extract 256 bits to obtain a 256-bit key. After 128 rounds, the calculation continues in a loop. The decimal result calculated in each round is converted to an integer and 1 binary bit is extracted until 128 / 256 bits are concatenated to form the session key.

[0057] Chaotic iteration can amplify subtle differences in composite initial values, ensuring that each session key is unique. The iterative output sequence has strong randomness, resisting key reverse engineering. The operation only includes basic multiplication, subtraction, and XOR operations, making it suitable for fast computation in low-computing-power RTUs and PLCs. At the same time, it breaks down the linear correlation between hardware fingerprints and timestamps, preventing attackers from forging session keys based on timing or device characteristics.

[0058] Reference Figure 4 The methods for generating S300 trusted credential data packets include: S310 performs hash processing on the hardware physical fingerprint vector, and after concatenating it with the device identifier of the power station smart terminal, generates a trusted physical identity credential for the terminal.

[0059] Specifically, a hash calculation is performed on the hardware physical fingerprint vector to obtain a 64-bit hardware fingerprint hash digest. This hardware fingerprint hash digest is then linearly concatenated with the device unique identifier of the power station smart terminal in a preset order to obtain the first-level credential as a trusted physical identity credential for the terminal. This credential is mainly used for calculations within the local security chip and is not directly transmitted externally.

[0060] S320 concatenates the terminal's physical identity trusted credential with the session key and the timestamp corresponding to the access request to obtain the replay forgery identification credential.

[0061] Specifically, the terminal's physical identity trusted credential, session key, and timestamp corresponding to the access request are sequentially and linearly concatenated to obtain a continuous binary bit stream. This continuous binary bit stream is the replay forgery identification credential used to identify message replay attacks and device forgery attacks.

[0062] S330 obtains the industrial control data corresponding to the access request, performs hash encryption on the industrial control data, and obtains the ciphertext data frame.

[0063] Specifically, the original industrial control business data bound to this access request can be captured by the local security coprocessor of the power station's intelligent terminal. The original data is in the power standard IEC 60870-5 or Modbus industrial control message format, preferably containing measurement and control information such as voltage, current, switch open / close positions, and protection action signals. Then, the original industrial control message is serialized, and redundant blank bytes are removed by segmenting the message header, data field, and checksum tail to obtain a standardized industrial control binary message. The standardized industrial control binary message is then merged with the device root salt value preset locally on the terminal. A lightweight hash algorithm such as SHA-256, adapted to embedded low-computing-power chips, is selected to perform hash encryption on the merged information, and finally a 256-bit digest is output. This digest is encapsulated into an independent transmission frame and defined as a ciphertext data frame, and the original industrial control plaintext is no longer carried during transmission.

[0064] In this step, the unique device root salt can completely negate the cracking effect of the hash rainbow table, greatly reducing the possibility of hash collisions between different industrial control messages, and effectively preventing attackers from reverse engineering sensitive measurement and control data such as voltage, switch status, and protection settings; subsequent transmission links only transmit hash digests without carrying plaintext industrial control data, avoiding the risk of data eavesdropping and leakage at the link level, and the binding characteristic of one device and one salt can also block the attack path of attackers using the digest of a single terminal to laterally impersonate other devices.

[0065] The device root salt value preset locally on the terminal is a randomly generated, binary-formatted fixed key string. It is written once to the chip's internal, non-erasable, and non-rewriteable OTP one-time programmable storage area. After writing, the storage area is locked, preventing upper-layer industrial control software and external debugging interfaces from reading, modifying, or overwriting the root salt. This hardware-level guarantee ensures the root salt's uniqueness and immutability. This root salt is not transmitted externally; it is permanently stored in the terminal's local secure storage unit and is only accessed when performing industrial control data hash operations within the terminal.

[0066] S340, concatenates the encrypted data frame with the replay forgery identification credential to generate a trusted credential data packet.

[0067] Specifically, linear concatenation is performed by first replaying the forged identification credential, followed by the encrypted data frame, in a fixed binary order. No delimiters, padding bytes, or length identifier fields are added during the concatenation process, directly forming a continuous and complete binary bitstream. This bitstream is the trusted credential data packet used for power station terminal access interaction. This concatenation method adopts a globally unified fixed arrangement rule. During gateway parsing, the data can be split into two segments according to a preset bit length boundary. First, the forged identification credential is extracted and replayed to verify device identity and message freshness. Then, the encrypted data frame is split to verify the integrity of industrial control data. The unified and non-redundant concatenation structure reduces the data packet transmission volume, adapting to industrial narrowband communication scenarios. Simultaneously, the two security credentials are bound together for overall transmission; any tampering with any segment will cause the gateway's layered verification to fail, simultaneously achieving multiple security verification capabilities against forgery, replay, and industrial control message tampering.

[0068] The method for S400 to perform multi-dimensional information verification on trusted credential data packets includes: after the terminal completes the generation of the trusted credential data packet, it uploads the complete trusted credential data packet to the industrial control master station through the power industry communication link; after receiving the data packet, the industrial control master station splits the data packet according to the preset fixed bit segmentation rules, and sequentially separates the replay forgery identification credential and the ciphertext data frame, and then performs hierarchical multi-dimensional verification logic on the two types of credentials obtained by splitting.

[0069] Specifically, the industrial control main station first splits the replay forged identification credentials a second time, extracting three types of information: the terminal's physical identity trusted credentials, the session key, and the access request timestamp, and then performs multi-dimensional verification on each of them.

[0070] Specifically, the hardware fingerprint hash digest and the device's unique identifier are extracted from the terminal's physical identity trusted certificate. The hardware fingerprint hash baseline value for the device registration and the whitelist of legitimate devices stored locally on the main station are retrieved. The hardware fingerprint hash is compared to see if they match and if the device identifier is registered, thus completing the verification of the authenticity of the terminal's hardware entity identity.

[0071] Extract the session key, match it with the temporary key used by the terminal and the master station to negotiate and establish the communication session, verify whether the session key is a valid session key, and exclude expired or stolen illegal session keys.

[0072] Extract the timestamp of the access request, compare it with the standard time of the local system of the industrial control master station, set a legal time offset threshold, and if the timestamp exceeds the threshold range, it is determined to be a replay message and directly intercepted, thereby completing the message freshness verification.

[0073] After completing all dimensions of the replay forged identification certificate verification and ensuring that all results are valid, the industrial control master station performs industrial control data integrity verification on the encrypted data frame. The master station retrieves the original standardized industrial control binary message corresponding to this access request, reads the exclusive device root salt value stored in the terminal's registration, concatenates the industrial control message with the device root salt, performs the same SHA-256 hash operation as the terminal, generates a standard verification hash digest, and compares the digest bit by bit with the encrypted data frame obtained by splitting the data packet. If the two are completely consistent, it is determined that the industrial control data transmission process has not been tampered with.

[0074] When all dimensions of hardware identity verification, session key validity verification, timestamp anti-replay verification, and industrial control data integrity verification pass the verification, the industrial control master station generates a standardized terminal access permission instruction and sends it to the power station's intelligent terminal through the communication link, allowing the terminal to access the industrial control master station to carry out subsequent measurement and control data interaction.

[0075] If any dimension fails the verification, the industrial control master station will directly discard the trusted credential data packet, lock the corresponding terminal communication channel, and prohibit unauthorized devices from reusing the leaked key to access the industrial control network.

[0076] In this embodiment, the industrial control master station performs hardware entity identity verification, session key validity verification, timestamp anti-replay detection, and salted hash integrity comparison of industrial control data for data packets. A single verification process can intercept three types of high-frequency industrial control attacks: spoofing terminals, message replay, and tampering with measurement and control data. This simplifies the architecture of the master station's security verification module and reduces computing power consumption and operation and maintenance development costs.

[0077] A computer device according to embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc.

[0078] The processor may be a central processing unit (CPU) or other processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of this disclosure, the processor is used to run computer-readable instructions stored in the memory, causing the computer device to perform all or part of the steps of the power plant smart terminal trusted identity authentication method described in the foregoing embodiments of this disclosure.

[0079] Those skilled in the art will understand that, in order to solve the technical problem of how to achieve a good user experience, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included within the protection scope of this disclosure.

[0080] like Figure 5 This is a schematic diagram of a computer device provided for an embodiment of the present disclosure. It illustrates a structural schematic diagram suitable for implementing the computer device in the embodiments of the present disclosure. Figure 5 The computer device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0081] like Figure 5 As shown, a computer device may include a processor (such as a central processing unit, graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) or programs loaded from storage devices into random access memory (RAM). The RAM also stores various programs and data required for the operation of the computer device. The processor, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.

[0082] Typically, the following devices can be connected to the I / O interface: input devices, such as sensors or visual information acquisition devices; output devices, such as displays; storage devices, such as magnetic tapes or hard drives; and communication devices. Communication devices allow the computer device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 5 A computer apparatus with various devices is shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or included alternatively.

[0083] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the power plant smart terminal trusted identity authentication method of embodiments of this disclosure are performed.

[0084] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0085] A computer-readable storage medium according to embodiments of the present disclosure stores non-transitory computer-readable instructions. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the power plant smart terminal trusted identity authentication method described in the foregoing embodiments of the present disclosure are performed.

[0086] The aforementioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or portable hard drive), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).

[0087] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.

[0088] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0089] In this disclosure, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, devices, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as "comprising," "including," "having," etc., are open-ended terms meaning "including but not limited to," and are used interchangeably with them. The terms "or" and "and" as used herein refer to the terms "and / or," and are used interchangeably with them unless the context clearly indicates otherwise. The term "such as" as used herein refers to the phrase "such as but not limited to," and is used interchangeably with it.

[0090] Additionally, as used herein, the "or" used in a list of items beginning with "at least one" indicates a separate list, such that a list of, for example, "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not imply that the described example is preferred or better than other examples.

[0091] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.

[0092] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.

[0093] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0094] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. A trusted identity authentication method for a power station intelligent terminal, characterized in that, include: In response to the access request initiated by the power station intelligent terminal, the system collects the multi-dimensional physical features corresponding to the physical hardware layer of the power station intelligent terminal device, and generates a hardware physical fingerprint vector based on the multi-dimensional physical features. The timestamp of the access request and the hardware physical fingerprint vector are hashed and perturbed to dynamically generate the session key corresponding to this session. A trusted credential data packet is generated based on the session key, the hardware physical fingerprint vector, the timestamp corresponding to the access request, the device identifier of the power station smart terminal, and the industrial control data corresponding to the access request. The trusted credential data packet is uploaded to the industrial control master station. The industrial control master station performs multi-dimensional information verification on the trusted credential data packet. When all multi-dimensional information passes the verification, an instruction is generated to allow the power station smart terminal to access.

2. The trusted identity authentication method for power plant intelligent terminals according to claim 1, characterized in that, In response to an access request initiated by the power station's intelligent terminal, the system collects multi-dimensional physical features corresponding to the physical hardware layer of the power station's intelligent terminal device, and generates a hardware physical fingerprint vector based on these multi-dimensional physical features, including: In response to the access request initiated by the power station smart terminal, an authentication restart command is sent to the power station smart terminal; The power station intelligent terminal is controlled to execute the authentication restart command, and the transient current waveform characteristics of the core power supply circuit of the chip are collected in the first preset window after power-on, the dynamic drift characteristics of the crystal oscillator frequency are collected in the second preset window after power-on, and the random state characteristics of the SRAM power-on are collected in the third preset window before the power-on initialization and clearing operation. Based on the transient current waveform characteristics, the crystal oscillator frequency dynamic drift characteristics, and the SRAM power-on random state characteristics, a hardware physical fingerprint vector is generated.

3. The power station intelligent terminal trusted identity authentication method according to claim 2, characterized in that, The control power station intelligent terminal executes the authentication restart command, and collects the transient current waveform characteristics of the chip core power supply circuit within a first preset window after power-on, the dynamic drift characteristics of the crystal oscillator frequency within a second preset window after power-on, and the random state characteristics of the SRAM power-on within a third preset window before the power-on initialization and clearing operation, including: A current sensor connected in series with the main power supply circuit of the chip core is used to collect the transient current waveform of the entire process within a time window of 0~500μs after the chip core power supply circuit is powered on. The instantaneous frequency of the main crystal oscillator was acquired at intervals of 500μs to 5ms after power-on, and all the dynamic drift characteristics of the crystal oscillator frequency were recorded as the dynamic drift characteristics of the crystal oscillator frequency. Before system initialization and zeroing, the initial bit state of the SRAM storage array is obtained upon power-on. After multiple rounds of power-on screening, stable bits that meet the preset consistency conditions are retained as the random state characteristics of the SRAM upon power-on.

4. The trusted identity authentication method for power plant intelligent terminals according to claim 2, characterized in that, The generation of a hardware physical fingerprint vector based on the transient current waveform characteristics, the crystal oscillator frequency dynamic drift characteristics, and the SRAM power-on random state characteristics includes: Based on all the transient current waveforms, the mean, peak value, and zero-crossing features are obtained, and a current waveform feature sub-vector is generated. Based on all the aforementioned crystal oscillator frequency dynamic drift characteristics, the mean deviation and variance are obtained, and a crystal oscillator drift characteristic sub-vector is generated. All the power-on random state features of the SRAM are concatenated in a fixed address order to obtain the original bit string, and the original bit string is normalized to obtain the SRAM random state feature sub-vector. A hardware physical fingerprint vector is generated based on the current waveform feature vector, the crystal oscillator drift feature vector, and the SRAM random state feature vector.

5. The trusted identity authentication method for power station intelligent terminals according to claim 1, characterized in that, The process of hashing and perturbing the timestamp of the access request and the hardware physical fingerprint vector to dynamically generate the session key corresponding to this session includes: Each component in the hardware physical fingerprint vector is normalized to obtain the initial chaotic value; The timestamp corresponding to the access request is hashed to obtain a timestamp hash value. The timestamp hash value is then XORed and fused with the chaotic initial value to generate a composite initial value. Based on the composite initial value, chaotic iteration is performed to remove the initial unstable data and obtain a random sequence. Valid bits are extracted from the random sequence and concatenated to form the session key corresponding to this session.

6. The trusted identity authentication method for power plant intelligent terminals according to claim 1, characterized in that, The step of generating a trusted credential data packet based on the session key, the hardware physical fingerprint vector, the timestamp corresponding to the access request, the device identifier of the power station smart terminal, and the industrial control data corresponding to the access request includes: The hardware physical fingerprint vector is hashed and then concatenated with the device identifier of the power station smart terminal to generate a trusted physical identity credential for the terminal. By concatenating the terminal physical identity trusted credential with the session key and the timestamp corresponding to the access request, a replay forgery identification credential is obtained; Obtain the industrial control data corresponding to the access request, and perform hash encryption on the industrial control data to obtain a ciphertext data frame; The encrypted data frame is concatenated with the replay forgery identification credential to generate a trusted credential data packet.

7. A trusted identity authentication system for a power plant intelligent terminal, characterized in that, include: The hardware physical fingerprint vector generation unit is used to respond to the access request initiated by the power station smart terminal, collect the multi-dimensional physical features corresponding to the physical hardware layer of the power station smart terminal device, and generate a hardware physical fingerprint vector based on the multi-dimensional physical features. The perturbation unit is used to perform hash perturbation processing on the timestamp of the access request and the hardware physical fingerprint vector to dynamically generate the session key corresponding to this session. The trusted credential data packet generation unit is used to generate a trusted credential data packet based on the session key, the hardware physical fingerprint vector, the timestamp corresponding to the access request, the device identifier of the power station smart terminal, and the industrial control data corresponding to the access request. The analysis unit is used to upload the trusted credential data packet to the industrial control master station. The industrial control master station performs multi-dimensional information verification on the trusted credential data packet. When all multi-dimensional information passes the verification, an instruction is generated to allow the power station smart terminal to access.

8. A computer device, characterized in that, The computer device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor; the instructions are executed by the at least one processor to enable the at least one processor to perform the power station smart terminal trusted identity authentication method according to any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions; the computer instructions are used to cause the computer to execute the power plant smart terminal trusted identity authentication method according to any one of claims 1-6.

10. A computer program product comprising computer instructions, characterized in that, When executed by a processor, the computer instructions implement the steps of the method according to any one of claims 1-6.