策略动态更新的变电站安全通信体系研究OA
Research of substation communication security system based on dynamic negotiation of security policy
针对变电站单一固定的加解密算法应对第三方截取和暴力破解能力不足的问题,本文梳理变电站网络通信构架特点,提出动态更新安全策略的变电站安全体系方案:首先构建全站统一的安全策略库,通过证书授权机和密钥代理机进行管理,为每个设备建立与其通信能力匹配的策略库子集;通信设备在线动态选择适合自身能力的安全策略,并对当前安全策略进行时效管理,实现安全策略的自适应动态更新,提升变电站信息安全主动防护的能力.通过设计测试平台,对策略动态更新功能、通信性能及设备功能进行实测,证明策略动态更新机制不影响设备核心功能的正常运行,对设备通信实时性有轻微影响.
In view of the inadequate response of single fixed encryption and decryption algorithm in substations to third-party interceptions and brute-force attacks,this paper analyzes the characteristics of substation network and proposes a secure system scheme with dynamic negotiation of security policy.First,a unified security policy library is established,which is managed through certificate authority and secret key agent,and a subset of the policy library matching with each device is made.In the communication progress,the security policy that adapt to the communication devices is dynamically selected,the device characteristics information is added to the secret key data in the distribution process,and a time-effective management is performed.This mechanism can realize the adaptive select of the security policy,and improve the ability to cope with third-party interception and brute-force cracking.Through the design of a test platform,it is confirmed that the policy dynamic update mechanism does not affect the normal operation of the key functions of the equipments,and has a slight impact on the real-time communication of the equipment.
徐广辉;高诗航;马玉龙;滕春涛;刘汝华
国电南瑞科技股份有限公司,南京 211106||南瑞集团有限公司,南京 211106
变电站信息安全安全策略动态更新加解密算法证书授权机密钥代理机
substation information securitydynamic negotiation of security policyencryption and decryption algorithmcertificate authoritysecret key agent
《电气技术》 2024 (007)
32-38 / 7
国电南瑞/南瑞控制科技项目(524608210209)
评论