Guide mechanism
Through the design of the guide mechanism and the IEC104 network access security audit device, the problems of inconvenience of one-hand operation and lack of safety audit in the prior art are solved, and the one-handed plug-in and unplugging of the network cable and the security audit of the IEC104 protocol are realized, improving user experience and grid safety.
Patent Information
- Application Number
- CN202322534564.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2023-09-19
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2033-09-19
AI Technical Summary
The existing IEC104 network-entry security audit device is not convenient for one-hand operation, and lacks audits for business interaction protocols and equipment's own security defense capabilities.
A guide mechanism is designed to realize the one-handed insertion and removal of the network cable through the cooperation of the limiting rod and the elastic member; at the same time, an IEC104 network access security audit device is provided, including a guide mechanism and control components, to audit business interaction protocols and security defense capabilities.
The one-handed plug-in and unplugging operation of the network cable is realized, improving the user's operation convenience and efficiency; at the same time, through in-depth audit of the IEC104 protocol, the safe and stable operation of the power grid equipment is ensured.
Smart Images

Figure CN222927861U_ABST
Abstract
Description
Technical Field
[0001] The utility model relates to the field of IEC104 network access security auditing devices, in particular to a guiding mechanism. Background Art
[0002] The IEC104 network access security audit device generally realizes data transmission with the outside world by plugging in a network cable. When plugging and unplugging the existing network cable with the audit device, it is usually necessary to use a two-handed operation method of one hand supporting the device and the other hand plugging and unplugging the network cable to realize the plugging and unplugging operation of the network cable, which is not convenient for users to operate with one hand. This on-off method brings inconvenience to users' daily use and affects the work efficiency of workers. Therefore, a guiding mechanism for facilitating the insertion and unplugging of network cables with one hand is proposed;
[0003] Moreover, most of the power-specific secondary equipment mainly enters the power system in the form of hardware + software. Such equipment has its own business capabilities and mostly uses power-specific protocols to conduct business interactions. However, the network access audit of such power equipment lacks protocol audits on business interactions, and also lacks audits on the security defense capabilities of the equipment itself. Therefore, an IEC104 network access security audit device is proposed. Utility Model Content
[0004] In view of the above existing technical problems, the present utility model is proposed.
[0005] The utility model aims to provide a guiding mechanism, which aims to solve the problem in the prior art that it is inconvenient to insert and remove the network cable with one hand.
[0006] To solve the above technical problems, the utility model provides the following technical solutions: a guide mechanism, comprising a guide assembly, including a shell, a mounting plate located on the outside of the shell, a mounting hole located on the side wall of the mounting plate, a network cable interface located on the side wall of the shell, an elastic member located on the inner wall of the network cable interface, and a limit member located on the outside of the network cable interface.
[0007] As a preferred solution of the guiding mechanism of the utility model, the elastic member includes a movable groove opened on the inner wall of the network cable interface, a fixed plate is provided at one end of the movable groove, a spring is provided at the other end of the movable groove, and an elastic block is embedded in the inner wall of the movable groove.
[0008] As a preferred embodiment of the guiding mechanism of the present utility model, wherein: the limiting member includes a rotating ring, a fixing member is fixedly arranged on the inner wall surface of the rotating ring, a boss is arranged on one side of the inner wall of the rotating ring, a rotating groove is formed on the surface of the boss, a limiting ring is arranged outside the boss, a limiting groove is arranged on the side wall of the limiting ring, a fixing ring is embedded outside the boss, a placing groove is formed on the surface of the fixing ring, a limiting rod is hingedly arranged on the inner wall of the placing groove, a guiding platform is arranged on the surface of the fixing ring, and a fixing column is arranged on the side wall of the fixing ring.
[0009] As a preferred embodiment of the guiding mechanism of the present utility model, wherein: the fixing member includes a limiting column fixed on the inner wall of the rotating ring, a elastic spring is fixedly arranged on the inner wall of the limiting column, and a pushing column is arranged at one end of the elastic spring.
[0010] As a preferred embodiment of the guiding mechanism of the present utility model, wherein: the elastic block is slidably matched with the moving groove;
[0011] The elastic members are symmetrically arranged on the side wall surfaces of both sides of the network cable interface.
[0012] As a preferred embodiment of the guiding mechanism of the present utility model, wherein: the pushing column and the limiting column form an elastic telescopic structure through the elastic spring;
[0013] The front end of the pushing column abuts against the surface of the guiding platform.
[0014] As a preferred embodiment of the guiding mechanism of the present utility model, wherein: the fixing column is integrally arranged with the outer shell, and the fixing column is slidably matched with the rotating groove.
[0015] As a preferred embodiment of the guiding mechanism of the present utility model, wherein: the fixing ring can be embedded in the groove formed by the rotating ring, the boss and the limiting ring;
[0016] The limiting groove is arranged in cooperation with the limiting rod.
[0017] The beneficial effect of the guiding mechanism of the present utility model is that: the connection between the device and the network cable is realized by pressing the card on the network cable by the limiting rod. At the same time, when the network cable is inserted, the elastic block can slide in the moving groove and squeeze the spring to make it in a compressed state. When the network cable needs to be pulled out, rotating the rotating ring can cancel the restriction on the network cable, and at the same time, the network cable can pop out under the elastic force of the spring, realizing the single-handed plugging and unplugging operation of the network cable, liberating the user's hands, bringing convenience to the user's daily use, and making the plugging and unplugging of the network cable more accurate and efficient.
[0018] Another object of the present utility model is to provide an IEC104 network access security audit device, aiming to solve the problem that the existing network access devices lack the audit of the protocols of service interactions and the audit of their own security defense capabilities.
[0019] To solve the above technical problems, the present utility model further provides the following technical solution: an IEC104 network access security auditing device, which includes a guiding mechanism; and a control component, and the control component includes a device connection module, a network link, a link auditing module, a message anti-loss auditing module, a message anti-replay auditing module, a heartbeat auditing module, a core parameter auditing and auditing report module.
[0020] As a preferred solution of the IEC104 network access security auditing device of the present utility model, the device connection module is arranged in cooperation with a network cable interface.
[0021] The beneficial effects of the IEC104 network access security auditing device of the present utility model are as follows: This device deeply implements security protection from a vertical business perspective, deeply explores the security protection of dedicated protocols, and provides a new perspective for the safe and stable operation of the power grid. Before the device accesses the network and before the new version of the software is launched, by testing the device with a security auditing tool, the compliance, reasonableness, and robustness of the IEC104 protocol are ensured. This patent can not only be applied to the device access of the power grid, but also improve the robustness and stability of the business procedures for power industry practitioners. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present utility model, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present utility model. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them:
[0023] Figure 1 It is a schematic diagram of the overall structure of a guiding mechanism in the present utility model;
[0024] Figure 2 It is a schematic diagram of the overall structure of an elastic member of a guiding mechanism in the present utility model;
[0025] Figure 3 It is an exploded view of the overall structure of a limiting member of a guiding mechanism in the present utility model;
[0026] Figure 4 It is a schematic diagram of the overall structure of the use state of a limiting member of a guiding mechanism in the present utility model;
[0027] Figure 5 It is a schematic diagram of the overall structure of a fixing member of a guiding mechanism in the present utility model;
[0028] Figure 6 It is a rear view of the overall structure of a limiting member of a guiding mechanism in the present utility model;
[0029] Figure 7 This is the system block diagram of an IEC104 network access security audit device in the present utility model;
[0030] Figure 8 This is the detailed diagram of step three of the system of an IEC104 network access security audit device in the present utility model. Specific embodiments
[0031] To make the above objects, features, and advantages of the present utility model more apparent and understandable, the following detailed description of the specific embodiments of the present utility model will be made in conjunction with the accompanying drawings of the specification.
[0032] In the following description, many specific details are set forth in order to fully understand the present utility model. However, the present utility model can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present utility model. Therefore, the present utility model is not limited by the specific embodiments disclosed below.
[0033] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present utility model. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that mutually excludes other embodiments.
[0034] Embodiment 1
[0035] Refer to Figures 1 to 2 , which is the first embodiment of the present utility model. This embodiment provides a guiding mechanism.
[0036] The guiding mechanism includes a guiding component 100.
[0037] Specifically, the guiding component 100 includes a housing 101 for placing the IEC104 network access security audit device. An installation plate 102 is provided on the outer side of the housing 101. Installation holes 103 are provided on the side wall of the installation plate 102. A network cable interface 104 is provided on the side wall of the housing 101. An elastic member 105 is provided on the inner wall of the network cable interface 104.
[0038] Furthermore, the elastic member 105 includes a movable groove 105a which is cylindrical and has a long rectangular opening at one end and is opened on the inner wall of the network cable interface 104. A fixed plate 105b matching the movable groove 105a is fixedly provided at one end of the movable groove 105a, and a spring 105c is fixedly provided at the other end of the movable groove 105a. An elastic block 105d is embedded on the inner wall of the movable groove 105a. The fixed plate 105b limits the elastic block 105d to prevent the elastic block 105d from moving out of the movable groove 105a when the spring 105a pops out the elastic block 105d. The elastic block 105d slides between the movable grooves 105a, so that the network cable can drive the elastic block 105d to move in the movable groove 105a, thereby achieving the purpose that the network cable pushes the elastic block 105d to squeeze the spring 105c when disassembling, and the network cable is popped out by the elastic force of the spring 105c when being removed.
[0039] Preferably, the elastic member 105 is symmetrically arranged on the two side wall surfaces of the network cable interface 104, and one end of the elastic block 105d is cylindrical, and the other end of the elastic block 105d is square, and the square surface of one end of the elastic block 105d can fit with the network cable, and a silicone anti-slip strip is arranged on the square surface of one end of the elastic block 105d, so that the elastic block 105d can always fit with the network cable, is not easy to slip, and the friction is increased.
[0040] When in use, the network cable is inserted into the network cable interface 104, and the side wall of the network cable pushes the elastic block 105d to squeeze the spring 105c. When pulling out, the limit piece 106 releases the restriction on the network cable. At this time, the spring 105c pushes the elastic block 105d through the elastic force, and the network cable can be ejected out of the device, thereby completing the purpose of pulling out the network cable. This process can avoid the disadvantages of manually pulling out the network cable through the cooperation between the limit piece 106 and the elastic piece 105, making it more convenient for manual use, reducing the time of inserting the network cable, and improving the efficiency of installing the network cable.
[0041] Example 2
[0042] Reference Figures 3 to 6 , which is the second embodiment of the utility model, and this embodiment further provides a guiding mechanism.
[0043] The guiding mechanism further includes a limiting member 106 .
[0044] Specifically, the limiting member 106 includes a rotating ring 106a. A fixing member 106b is fixedly arranged on the inner wall surface of the rotating ring 106a. A boss 106c is fixedly arranged on one side of the inner wall of the rotating ring 106a. An arc-shaped rotating groove 106d is formed on the surface of the boss 106c. A limiting ring 106e is fixedly arranged on the outer side of the boss 106c. A limiting groove 106f is arranged on the side wall of the limiting ring 106e. A fixing ring 106g is embedded on the outer side of the boss 106c. A placing groove 106h is formed on the surface of the fixing ring 106g. The placing groove 106h is concave and has an open end. A limiting rod 106i is hingedly arranged on the inner wall of the placing groove 106h, facilitating the rotation of the limiting rod 106i in the placing groove 106h. A guiding platform 106j with one end being annular and the other end being sloped is arranged on the surface of the fixing ring 106g. A fixing column 106k is fixedly arranged on the side wall of the fixing ring 106g;
[0045] The fixing member 106b includes a limiting column 106b-1 fixed to the inner wall of the rotating ring 106a. A spring 106b-2 is fixedly arranged on the inner wall of the limiting column 106b-1. A pushing column 106b-3 is fixedly arranged at one end of the spring 106b-2.
[0046] Furthermore, the pushing column 106b-3 and the limiting column 106b-1 form an elastic telescopic structure through the spring 106b-2. When the pushing column 106b-3 moves to the guiding platform 106j, the spring 106b-2 is compressed by the pushing column 106b-3. At this time, the pushing column 106b-3 slides in cooperation between the limiting columns 106b-1, thereby achieving the purpose of the telescopic movement of the pushing column 106b-3. When the fixing member 106b moves to the placing groove 106h, the pushing column 106b-3 is pushed out by the elastic force of the spring 106b-2, thereby achieving the purpose of supporting the limiting rod 106i;
[0047] The fixing column 106k and the housing 101 are integrally arranged, and the fixing column 106k slides in cooperation between the rotating grooves 106d, enabling the synchronous rotation of the rotating ring 106a and the boss 106c through the fixing column 106k. The fixing ring 106g can be fitted into the groove formed by the rotating ring 106a, the boss 106c, and the limiting ring 106e. The limiting groove 106f and the limiting rod 106i are cooperatively arranged. Further, when the rotating ring 106a rotates, the limiting groove 106f pushes the limiting rod 106i, causing the limiting rod 106i to rotate to the placing groove 106h through the hinge point on the placing groove 106h, thereby achieving the purpose that the limiting rod 106i does not limit the network cable. At this time, the fixing member 106b follows the rotating ring 106a to rotate to the guiding platform 106j, and vice versa, achieving the purpose of the limiting rod 106i limiting the network cable.
[0048] Preferably, one end of the guiding platform 106j is provided in a slope shape, and the other end is provided in a circular shape, facilitating the movement of the fixing member 106b on the guiding platform 106j.
[0049] During use, the limiting rod 106i is fixed through the fixing member 106b. When inserting the network cable, the limiting rod 106i can press against the card on the network cable, enabling the network cable to be inserted into the network cable interface 104 more smoothly. When it is necessary to remove the network cable, by rotating the rotating ring 106a clockwise, the rotating ring 106a, the convex platform 106c, and the limiting ring 106e rotate synchronously, driving the fixing member 106b to move to the guiding platform 106j. At this time, the limiting groove 106f pushes the limiting rod 106i, causing the limiting rod 106i to rotate to the placement groove through the hinge point with the placement groove 106h. On the contrary, when it is necessary to limit the network cable, rotate the rotating ring 106a counterclockwise, so that the rotating ring 106a, the convex platform 106c, and the limiting ring 106e rotate synchronously, driving the fixing member 106b to move into the placement groove 106h and restricting the limiting rod 106i. At this time, the limiting rod 106i loses the restriction of the limiting groove 106f, and then the limiting rod 106i rotates to a vertical state through the hinge point, thereby achieving the purpose of limiting the card on the network cable, making the insertion of the network cable more convenient, without the need for manual assistance with both hands, and the single-handed operation steps are simpler and more convenient for users to use.
[0050] Embodiment 3
[0051] Refer to Figures 1 to 8 , which is the third embodiment of the present utility model. This embodiment further provides an IEC104 network access security audit device.
[0052] The IEC104 network access security audit device further includes a control component 200.
[0053] Specifically, the control component 200 includes a device connection module 201, a network link 202, an IEC link audit module 203, a message anti-loss audit module 204, a message anti-replay audit module 205, a heartbeat audit module 206, a core parameter audit module 207, and an audit report module 208 that are cooperatively set with the network cable interface 104.
[0054] Furthermore, Step 1. Prepare the network access connection device 201 and the design device. The audit device can be an ordinary server, workstation, or PC. Build a security audit program; the network access device is the object, and the audit device is the subject. The two are connected through the RJ45 interface 104 of the network cable.
[0055] Step 2. The device connection module 202 sets corresponding IPs for the main body and the object. At the same time, the business program and the audit program are the client and the server respectively, and they can be interchanged with each other without affecting this process. The two parties establish a TCP connection. At this time, there are two situations: the main body is the active station and the object is the passive station, or the object is the active station and the main body is the passive station;
[0056] Step 3. The normal process of the link audit module 203 is that the main body sends a connection establishment notice, and the object sends a confirmation frame accordingly. The audit operation is that the active station sends an activation, and the passive station always refuses the message; when the object is the passive station, the active station sends an activation, and the passive station sends an error or other service message in response; the active station sends an activation, and after the passive station receives it, it sends an activation message and then sends a confirmation message; the overall operation checks the feedback of the active station. On the contrary, when the object is the active station, it sends other messages before the link is established, then sends an activation message, and then immediately sends a service message, and checks the feedback of the passive station;
[0057] Step 4. For the message loss prevention audit module 204, when the main body is the active station, it sends messages to the slave station in non - consecutive order (such as sequence number 135) and checks the feedback of the slave station. When the main body is the passive station, it randomly loses messages after receiving the messages from the other party and checks the feedback of the active station;
[0058] Step 5. For the message replay prevention audit module 205, when the main body is the active station or the passive station, it continuously sends confirmation frames with the same sequence number to the other party at random time intervals and checks the feedback of the other party;
[0059] Step 6. For the heartbeat audit module 206, when the main body is the active station or the passive station, there is no business interaction between the two parties. No matter what message the object sends, the main body does not give any feedback, so as to find out whether the passive station has a heartbeat mechanism and calculate whether the heartbeat of the passive station is sent periodically; if the sending period of the passive station mechanism is N, the main body continuously sends heartbeats to the passive station within a random time less than N and checks the feedback of the object;
[0060] Step 7. The core parameter audit module 207; continuously confirms whether the following parameters conform to the periodic law and whether they are out of bounds through exploratory messages.
[0061] T0: Connection establishment timeout. t0 stipulates the maximum allowable time for the master station and the slave RTU to establish a TCP connection once.
[0062] T1: t1 stipulates that after the sender sends an I - format message or a U - format message, it must get the recognition of the receiver within the time of t1, otherwise the sender considers that the TCP connection has a problem and should re - establish the connection;
[0063] T2 (T2 < T1): t2 specifies that after the receiving party receives an I-format message, if no new I-format message is received after t2 time, it must send an S-format frame to the sending party to acknowledge the received I-format message;
[0064] T3 (T3 > T1): t3 specifies that each time the dispatching end or the substation RTU end receives an I-frame, S-frame or U-frame, the timer t3 will be re-triggered. If no message is received within t3, a test link frame will be sent to the other party;
[0065] K: The maximum number of unacknowledged I-format APDUs (k);
[0066] W: The receiving party acknowledges after receiving w I-format APDUs.
[0067] Step 8. Audit Report Module 208. According to the feedback results of the previous steps 2-7, the device will form an audit report in the form of a report.
[0068] In use, when the power system adopts IEC104 as the secondary device for service interaction, before the network access trial operation, the network access test is first carried out through the security audit device. The main purposes of the test start from several aspects such as the compliance, security, and rationality of the IEC104 process.
[0069] Principle: The audit device has a complete mechanism for self-transmitting and receiving IEC104. The IEC104 implementation of the device to be audited needs to comply with the communication protocol requirements of IEC104; since the IEC104 protocol adopts a balanced communication method, the audit device has both the capabilities of a primary station and a secondary station.
[0070] Importantly, it should be noted that the construction and arrangement of the present application shown in multiple different exemplary embodiments are merely illustrative. Although only a few embodiments are described in detail in this disclosure, those who refer to this disclosure should easily understand that many modifications are possible without materially departing from the novel teachings and advantages of the subject matter described in this application (e.g., changes in the dimensions, scales, structures, shapes and proportions of various elements, as well as parameter values (such as temperature, pressure, etc.), installation arrangements, use of materials, colors, orientations, etc.). For example, an element shown as integrally formed may be composed of multiple parts or elements, the position of the element may be inverted or otherwise changed, and the nature, number or position of discrete elements may be altered or changed. Accordingly, all such modifications are intended to be included within the scope of the present utility model. The order or sequence of any process or method steps may be changed or reordered according to alternative embodiments. In the claims, any "means-plus-function" clause is intended to cover the structures that perform the recited function herein, and not only structural equivalents but also equivalent structures. Other substitutions, modifications, changes and omissions may be made in the design, operating conditions and arrangement of the exemplary embodiments without departing from the scope of the present utility model. Therefore, the present utility model is not limited to a particular embodiment, but extends to various modifications that still fall within the scope of the appended claims.
[0071] In addition, in order to provide a concise description of the exemplary embodiments, all features of the actual embodiments may not be described (i.e., those features that are not relevant to the currently considered best mode of carrying out the present utility model or those features that are not relevant to the implementation of the present utility model).
[0072] It should be understood that in the development of any actual implementation, as in any engineering or design project, numerous specific implementation decisions may be made. Such development efforts may be complex and time-consuming, but for those of ordinary skill in the art who benefit from this disclosure, without undue experimentation, such development efforts will be a routine task of design, manufacture and production.
[0073] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present utility model and not to limit them. Although the present utility model has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present utility model may be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present utility model, and they should all be covered within the scope of the claims of the present utility model.
Claims
1. A guiding mechanism, Features: include, A guide assembly (100) comprises a housing (101), a mounting plate (102) located outside the housing (101), a mounting hole (103) located on a side wall of the mounting plate (102), a network cable interface (104) located on the side wall of the housing (101), an elastic member (105) located on an inner wall of the network cable interface (104), and a limiting member (106) located outside the network cable interface (104). The elastic member (105) comprises a movable groove (105a) provided on the inner wall of the network cable interface (104); a fixing plate (105b) is provided at one end of the movable groove (105a); a spring (105c) is provided at the other end of the movable groove (105a); and an elastic block (105d) is embedded in the inner wall of the movable groove (105a). The limiting member (106) comprises a rotating ring (106a), a fixing member (106b) is fixedly arranged on the inner wall surface of the rotating ring (106a), a boss (106c) is arranged on one side of the inner wall of the rotating ring (106a), a rotating groove (106d) is opened on the surface of the boss (106c), a limiting ring (106e) is arranged on the outer side of the boss (106c), and the side wall of the limiting ring (106e) is provided with a A limiting groove (106f) is provided, a fixing ring (106g) is embedded on the outer side of the boss (106c), a placement groove (106h) is opened on the surface of the fixing ring (106g), a limiting rod (106i) is hingedly provided on the inner wall of the placement groove (106h), a guide platform (106j) is provided on the surface of the fixing ring (106g), and a fixing column (106k) is provided on the side wall of the fixing ring (106g).
2. The guide mechanism according to claim 1, Features: The fixing member (106b) comprises a limiting column (106b-1) fixed on the inner wall of the rotating ring (106a), an elastic spring (106b-2) is fixedly arranged on the inner wall of the limiting column (106b-1), and a pushing column (106b-3) is arranged at one end of the elastic spring (106b-2).
3. The guide mechanism according to claim 2, Features: The elastic block (105d) is slidably matched with the movable groove (105a); The elastic member (105) is symmetrically arranged on the two side wall surfaces of the network cable interface (104).
4. The guide mechanism according to claim 3, Features: The pushing column (106b-3) and the limiting column (106b-1) form an elastic telescopic structure via an elastic spring (106b-2); The front end of the pushing column (106b-3) abuts against the surface of the guide platform (106j).
5. The guide mechanism according to claim 4, Features: The fixing column (106k) is integrally formed with the housing (101), and the fixing column (106k) is slidably matched with the rotating groove (106d).
6. The guide mechanism according to claim 5, Features: The fixed ring (106g) can be fitted into the groove formed by the rotating ring (106a), the boss (106c) and the limit ring (106e); The limit groove (106f) is arranged in cooperation with the limit rod (106i).