信息网络安全 ›› 2022, Vol. 22 ›› Issue (2): 32-38.doi: 10.3969/j.issn.1671-1122.2022.02.004

• 技术研究 • 上一篇    下一篇

基于SDP的电力物联网安全防护方案

吴克河, 程瑞(), 姜啸晨, 张继宇   

  1. 华北电力大学控制与计算机工程学院,北京 102206
  • 收稿日期:2021-11-14 出版日期:2022-02-10 发布日期:2022-02-16
  • 通讯作者: 程瑞 E-mail:chengrui@ncepu.edu.cn
  • 作者简介:吴克河(1962—),男,江苏,教授,博士,主要研究方向为电力信息安全|程瑞(1989—),男,安徽,博士研究生,主要研究方向为电力信息安全|姜啸晨(1999—),男,北京,硕士研究生,主要研究方向为网络信息安全|张继宇(1998—),男,山东,硕士研究生,主要研究方向为网络信息安全
  • 基金资助:
    国家重点研发计划(2020YFB0905900);国家电网公司总部科技项目(5700-202124182A-0-0-00)

Security Protection Scheme of Power IoT Based on SDP

WU Kehe, CHENG Rui(), JIANG Xiaochen, ZHANG Jiyu   

  1. School of Control and Computer Engineering, North China Electric Power University, Beijing 102206, China
  • Received:2021-11-14 Online:2022-02-10 Published:2022-02-16
  • Contact: CHENG Rui E-mail:chengrui@ncepu.edu.cn

摘要:

电力物联网的快速发展及海量终端的泛在连接和智能交互使得电力物联网的网络边界变得模糊,网络安全风险点和暴露面显著增多。文章摒弃传统的先连接后认证的安全认证措施,结合零信任安全机制提出一种基于软件定义边界的电力物联网安全防护方案,该方案利用改进的单包授权技术解决电力物联终端接入过程中存在的身份认证、电力物联系统资源隐藏及访问控制等问题,并从安全和性能两方面对方案进行分析。实验结果表明,该方案能有效抵御多类网络攻击,节省了电力物联终端的计算和通信资源,有效解决了电力物联网存在的安全认证等问题。

关键词: 电力物联网, 软件定义边界, 单包授权, 安全接入, 身份认证

Abstract:

The rapid development of the IoT and the ubiquitous connection and intelligent interaction of a large number of heterogeneous terminals have made the network boundaries of the power IoT blurred, and the network structure is more complex, and the security risk points and exposed areas have increased significantly. This paper abandoned the traditional security mechanism of connection before authentication and put forward a kind of security protection scheme for the power IoT with the zero trust security mechanism, while applying the SPA to effectively solve the problems of identity authentication, resource hiding, and access control of power IoT terminals. Finally, the scheme was compared and analyzed from security and communication performance. The results show that the proposed scheme can effectively resist multiple types of network attacks, and save computing and communication resources, and effectively solve the problems of identify authentication existing in the power IoT.

Key words: power IoT, SDP, SPA, secure access, identity authentication

中图分类号: