摘要
为应对工业控制系统面临的外部网络攻击和内部数据泄露等安全挑战,本文提出了一种新型的面向工控编程平台整体的通用性安全增强框架。该框架有机集成了工控系统的核心功能模块,并综合运用安全隔离认证网关、国密算法、轻量级身份验证和密钥协商、动态细粒度访问控制等技术,解决了目前大多数工控系统共同存在的核心安全问题,包括远程访问及通信过程中缺少身份认证、主机和终端易被窃听和篡改、数据库信息易泄露、系统资源缺少细粒度访问控制等。此外,本文提出了两类常见应用系统-煤矿主通风可编程逻辑控制器(PLC)监控系统和己内酰胺生产分布式控制系统(DCS)的安全增强方案,并对其中安全技术集成度高的DCS系统进行了性能测试。测试结果表明该DCS系统安全认证时间约为2s,对于1000字节的数据通信,其加密或解密时间小于0.08ms,表明采用安全增强方案后系统性能较高,可满足实际应用需要。
In response to the security challenges faced by industrial control systems(Icss)such as external network attacks and internal data leaks,this paper proposes a novel general security framework for enhancing the overall security of industrial control programming platforms.The framework organically integrates the core functional modules of the industrial control system,and comprehensively uses technologies including security isolation authentication gateway,algorithms like SM2,SM3 and SM4,lightweight identity authentication and key agreement,dynamic fine-grained access control,trusted hardware and trusted computation,in order to solve the core security problems common to most industrial control systems,including:the lack of identity authentication in the process of remote access and communication of the industrial control system,eavesdropping on and tampering with hosts and terminals,leakage of database information,and the lack of fine-grained access control of system resources.In addition,security enhancement schemes were proposed for the two common applications of IcSs,coal mine main ventilation PLC monitoring system and caprolactam DCS production control system.A performance test of the DCS system which highly integrates the proposed security technologies is carried out.The results show that the security authentication time of the Dcs system is about 2s,the communication encryption and decryption time of 1000 bytes of data is less than 0.08ms,and the system also performs well in other aspects,such as remote access,which can meet the needs of actual industrial controlapplications.
出处
《自动化博览》
2025年第5期52-59,共8页
Automation Panorama
基金
国家重点研发计划资助项目(2021YFB3101601)
浙江农林大学科研发展基金(人才启动项目2024LFR126)。
关键词
工业控制系统
工控编程平台
可编程逻辑控制器
分布式控制系统
密码学
Industrial control system(ICS)
Industrial control programming platform
Programmable logic controller(PLC)
Distributed control system(DCS)
Cryptography
作者简介
高山(1980-),男,山东烟台人,高级工程师,硕士,现于浙江大学控制科学与工程学院博士在读,研究方向是工业信息安全;通信作者:胡爽(1993-),女,讲师,博士,现就职于浙江农林大学数学与计算机科学学院,研究方向是密码学与隐私保护;张秉晟(1984-),男,研究员,博士,现就职于浙江大学区块链与数据安全全国重点实验室、杭州高新区(滨江)区块链与数据安全研究院,研究方向是密码学与隐私保护。