Cross-security-partition data import and export system for power plant

By setting up an isolation module data import and export system between different safe partitions of the power plant, the problem of data transmission security across safe partitions is solved, safe and reliable data transmission is achieved, and production management is facilitated.

CN222928408UActive Publication Date: 2025-05-30SHANGHAI YIKONG ELECTRIC POWER TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202421909637.8
Authority / Receiving Office
CN · China
Patent Type
Utility models(China)
Current Assignee / Owner
Filing Date
2024-08-07
Publication Date
2025-05-30
Estimated Expiration
2034-08-07

AI Technical Summary

Technical Problem

The prior art is difficult to safely import and export data between different safe partitions of power plants, resulting in inconvenient production management and affecting the safety and reliability of the power system.

Method used

A data import and export system across secure partitions is designed, and the isolation module is set up between the I-zone host, the II-zone host and the information management host, including a forward security isolation device, a longitudinal encryption device and an intrusion detection system, to ensure the security of data during transmission.

Benefits of technology

It realizes data transmission across safe partitions under the premise of safety, facilitates production management, and improves the safety and reliability of the power system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN222928408U_ABST
    Figure CN222928408U_ABST
Patent Text Reader

Abstract

The utility model relates to a cross-safety-zone data import and export system for a power plant, which comprises an I-zone host, an II-zone host and an information management host positioned in a management zone III, the I area host and the II area host are respectively in communication connection with a first communication interface and a second communication interface, the first communication interface is in communication connection with a first transmission machine, the second communication interface is in communication connection with a firewall, the firewall is in communication connection with a safe area switch, and the safe area switch is in communication connection with the first transmission machine; the first transmission machine is connected with an isolation module, the information management host is in communication connection with a third communication interface, and the third communication interface is in communication connection with a second transmission machine. The utility model relates to the technical field of power plant data. According to the utility model, the cross-safety-partition data transmission of the power plant is realized on the premise of safety, the production management is facilitated, and the operation of an electric power system is safer and more reliable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The utility model relates to the technical field of power plant data, and in particular to a data import and export system for cross-security zones in a power plant. Background Art

[0002] In consideration of power production safety, power generation enterprises need to establish a secondary power security zone, dividing the entire internal network into a production control zone (Security Zone I), a non-control zone (Security Zone II), and a management information zone (Management Zone III).

[0003] After the network zoning is established, due to confidentiality and security issues, the production data of many production control systems and advanced application systems covering production, management, water regime, monitoring, etc. cannot be directly copied, which brings inconvenience to production management. Therefore, necessary technical measures need to be taken to achieve secure access from Management Zone III to Security Zone I and Security Zone II, and to achieve the import and export of data in Security Zone I and Security Zone II. Content of the Utility Model

[0004] Aiming at the deficiencies of the existing technology, the purpose of the utility model is to provide a data import and export system for cross-security zones in a power plant, so as to solve the technical problems mentioned in the above background art.

[0005] The above technical purpose of the utility model is achieved through the following technical solutions:

[0006] A data import and export system for cross-security zones in a power plant includes a host in Zone I and a host in Zone II, and also includes an information management host located in Management Zone III;

[0007] The host in Zone I and the host in Zone II are respectively communicatively connected to a first communication interface and a second communication interface. The first communication interface is communicatively connected to a first transmitter, the second communication interface is communicatively connected to a firewall, the firewall is communicatively connected to a security zone switch, and the security zone switch is communicatively connected to the first transmitter;

[0008] The first transmitter is connected to an isolation module. The information management host is communicatively connected to a third communication interface. The third communication interface is communicatively connected to a second transmitter. The second transmitter is communicatively connected to the isolation module. The information management host includes a USB transmission interface.

[0009] By adopting the above technical solution, an isolation module is set between the host in Zone I, the host in Zone II and the information management host, so that data can be safely imported from the host in Zone I and the host in Zone II into the information management host, or the data of an external storage device can be safely imported into the host in Zone I and the host in Zone II through the USB transmission interface, realizing the cross-security-zone data transmission in a power plant on the premise of security, facilitating production management, and making the power system operate more safely and reliably.

[0010] Further, the first communication interface uses the RS232 protocol for transmission.

[0011] Further, the second transmitter includes a format detection module and a data conversion module. The format detection module is used to judge whether the received data format meets the requirements. If it meets the requirements, it is transmitted to the data conversion module; otherwise, the transmission is not continued. The data conversion module is used to convert and process the data that meets the requirements, which is beneficial to the display of production system data.

[0012] Further, the isolation module includes a forward security isolation device, a longitudinal encryption device and an intrusion detection system. The input end of the forward security isolation device is electrically connected to the first transmitter to detect and kill all malicious codes. The password in the longitudinal encryption device includes one or more of a symmetric encryption algorithm, an asymmetric encryption algorithm and a random number generation algorithm to achieve the security protection of the data network. The intrusion detection system is electrically connected to the first transmitter and the second transmitter to detect devices that violate the security policy in the computer network.

[0013] Further, the information management host is connected to the power management informatization system through a wireless signal.

[0014] Further, the information management host includes a data permission module and a face recognition module. The data permission module classifies production data according to different permissions. The face recognition module is used to identify the identity and permissions of the user of the information management host and allows the transmission of production data corresponding to the permissions according to the permissions.

[0015] In summary, the present utility model includes at least one of the following beneficial technical effects:

[0016] The data import / export system for cross-security-zone in a power plant, by setting an isolation module between the host in Zone I, the host in Zone II and the information management host, enables data to be safely imported from the host in Zone I and the host in Zone II into the information management host, or enables the data of an external storage device to be safely imported into the host in Zone I and the host in Zone II through the USB transmission interface, realizing the cross-security-zone data transmission in a power plant on the premise of security, facilitating production management, and making the power system operate more safely and reliably. Description of the Drawings

[0017] To more clearly illustrate the technical solutions of the embodiments of the present utility model, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present utility model. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0018] Figure 1 It is a system diagram of a data import / export system for a power plant that crosses security zones in this embodiment. Specific Embodiments

[0019] The following further elaborates on the present utility model in conjunction with the drawings.

[0020] Embodiment:

[0021] Referring to Figure 1 A data import / export system for a power plant that crosses security zones disclosed by the present utility model includes a host in Zone I and a host in Zone II, and also includes an information management host located in Management Zone III;

[0022] The host in Zone I and the host in Zone II are respectively communicatively connected to a first communication interface and a second communication interface. The first communication interface is communicatively connected to a first transmitter. The second communication interface is communicatively connected to a firewall, the firewall is communicatively connected to a security zone switch, and the security zone switch is communicatively connected to the first transmitter.

[0023] The first transmitter is connected to an isolation module. The information management host is communicatively connected to a third communication interface, the third communication interface is communicatively connected to a second transmitter, the second transmitter is communicatively connected to the isolation module, and the information management host includes a USB transmission interface.

[0024] The first communication interface uses the RS232 protocol for transmission. In serial communication, it is required that both communication parties adopt a standard interface so that different devices can be conveniently connected for communication. The RS-232 bus stipulates 25 lines, including two signal channels, namely the first channel and the second channel. Using three signal lines (receiving line, sending line, and signal line) can achieve a simple full-duplex communication process, with fewer signal lines required.

[0025] RS-232 stipulates a relatively large number of standard transmission rates, which can flexibly adapt to devices with different rates. For slow peripherals, a lower transmission rate can be selected; conversely, a higher transmission rate can be selected.

[0026] Since RS-232 uses a serial transmission method and converts the TTL level of a microcomputer into the RS-232C level, its transmission distance can generally reach 30m. If an optoelectronic isolation 20mA current loop is used for transmission, its transmission distance can reach 1000m. Additionally, if a Modem is added to the RS-232 bus interface and the data is transmitted via wire, wireless, or optical fiber, the transmission distance can be even farther.

[0027] The second transmitter includes a format detection module and a data conversion module. The format detection module is used to determine whether the received data format meets the requirements. If it meets the requirements, the data is transmitted to the data conversion module; otherwise, the transmission is not continued. The data conversion module is used to convert and process the data with a compliant format, facilitating the display of production system data.

[0028] The isolation module includes a forward security isolation device, a longitudinal encryption device, and an intrusion detection system.

[0029] The input end of the forward security isolation device is electrically connected to the first transmitter and kills all malicious codes. Safety Zone I and Safety Zone II cannot directly communicate with Management Zone III in a skip-level manner. A dedicated security isolation device is required. When transmitting information from Safety Zone I and Safety Zone II to Management Zone III, it must pass through the forward security isolation device. Access through the E-mail across the isolation device is prohibited, and all malicious codes will be killed during data transmission. To transfer data between different safety zones, a security isolation device is needed for data transmission to achieve the purpose of isolation.

[0030] The password in the longitudinal encryption device includes one or more of symmetric encryption algorithms, asymmetric encryption algorithms, and random number generation algorithms to achieve the security protection of the data network. The management system of the longitudinal encryption device can not only set and query the encryption authentication gateways across the network but also manage digital certificates and initialize keys, query and set the working modes, statuses, etc. of the encryption authentication gateways across the network, and effectively monitor and manage each encryption device across the network.

[0031] The intrusion detection system is electrically connected to the first transmitter and the second transmitter to detect devices that violate security policies in the computer network. The information management host is connected to the power management information system via a wireless signal, enabling users to directly access the data located in Management Zone III through the network.

[0032] The information management host includes a data permission module and a face recognition module. The data permission module classifies production data according to different permissions. The face recognition module is used to identify the identity and permissions of the user of the information management host and allows the transmission of production data corresponding to the permissions according to the permissions.

[0033] In this embodiment, by setting up isolation modules between the host in Zone I, the host in Zone II and the information management host, data can be safely imported from the host in Zone I and the host in Zone II into the information management host, or the data of external storage devices can be safely imported into the host in Zone I and the host in Zone II through the USB transmission interface. On the premise of security, cross-security zone data transmission in the power plant is realized, facilitating production management and making the operation of the power system safer and more reliable.

[0034] The embodiments of this specific implementation manner are all preferred embodiments of the present invention, and do not limit the protection scope of the present invention accordingly. Therefore, all equivalent changes made according to the structure, shape and principle of the present invention shall be covered within the protection scope of the present invention.

Claims

1. A data import and export system across security zones for a power plant, comprising a zone I host and a zone II host, characterized in that: Also included is an information management host located in management area III; The host in zone I and the host in zone II are respectively connected to a first communication interface and a second communication interface, the first communication interface is connected to a first transmission machine, the second communication interface is connected to a firewall, the firewall is connected to a safety zone switch, and the safety zone switch is connected to the first transmission machine; The first transmitter is connected to an isolation module, the information management host is communicatively connected to a third communication interface, the third communication interface is communicatively connected to a second transmitter, the second transmitter is communicatively connected to the isolation module, and the information management host includes a USB transmission interface.

2. A data import and export system across security zones for a power plant according to claim 1, characterized in that: The first communication interface adopts RS232 protocol transmission.

3. A data import and export system across security zones for a power plant according to claim 2, characterized in that: The second transmission machine includes a format detection module and a data conversion module. The format detection module is used to determine whether the format of the received data meets the requirements. If it meets the requirements, it is transmitted to the data conversion module, otherwise the transmission will not continue; the data conversion module is used to convert and process the format of the data that meets the requirements, so as to facilitate the display of the production system data.

4. A data import and export system across security zones for a power plant according to claim 3, characterized in that: The isolation module includes a forward security isolation device, a vertical encryption device and an intrusion detection system. The input end of the forward security isolation device is telecommunicationally connected to the first transmission machine to detect and kill all malicious codes. The password in the vertical encryption device includes one or more of a symmetric encryption algorithm, an asymmetric encryption algorithm and a random number generation algorithm to achieve security protection of the data network. The intrusion detection system is telecommunicationally connected to the first transmission machine and the second transmission machine to detect devices that violate security policies in the computer network.

5. A data import and export system across security zones for a power plant according to claim 4, characterized in that: The information management host is connected to the power management information system via wireless signals.

6. A data import and export system across security zones for a power plant according to claim 5, characterized in that: The information management host includes a data permission module and a face recognition module. The data permission module classifies production data according to different permissions. The face recognition module is used to identify the identity and permissions of the information management host user and allow the transmission of production data with corresponding permissions based on their permissions.