CN115733684A - Industrial communication information security gateway system - Google Patents

Industrial communication information security gateway system Download PDF

Info

Publication number
CN115733684A
CN115733684A CN202211428035.6A CN202211428035A CN115733684A CN 115733684 A CN115733684 A CN 115733684A CN 202211428035 A CN202211428035 A CN 202211428035A CN 115733684 A CN115733684 A CN 115733684A
Authority
CN
China
Prior art keywords
data
module
gateway
communication information
industrial communication
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202211428035.6A
Other languages
Chinese (zh)
Inventor
蔡翔
汪文杰
王涛
许凡强
牟树贞
徐玲
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Tongling Power Supply Co of State Grid Anhui Electric Power Co Ltd
Original Assignee
Tongling Power Supply Co of State Grid Anhui Electric Power Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Tongling Power Supply Co of State Grid Anhui Electric Power Co Ltd filed Critical Tongling Power Supply Co of State Grid Anhui Electric Power Co Ltd
Priority to CN202211428035.6A priority Critical patent/CN115733684A/en
Publication of CN115733684A publication Critical patent/CN115733684A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Abstract

The application discloses an industrial communication information security gateway system, which comprises a data acquisition gateway device, an application server and a response device which are in communication connection with each other, wherein the data acquisition gateway device comprises a shell and an ARM processor arranged in the shell, and the ARM processor is provided with a data acquisition storage module, an equipment management module, a data processing and forwarding module, an Ethernet card, a serial port, an encryption module, a decryption module and a data security detection module; in order to prevent data from being stolen or lost, the data acquisition and storage module does not open any port to an external network when the system is in online operation, and sensitive information is encrypted and stored by the encryption module, plaintext is not directly stored, and only encrypted ciphertext is stored. The method and the device use corresponding encryption protocols and authentication modes to ensure the safety and integrity of data in the transmission process, reduce the probability of industrial communication information leakage and ensure the rights and interests of users.

Description

Industrial communication information security gateway system
Technical Field
The invention relates to the technical field of gateway systems, in particular to an industrial communication information security gateway system.
Background
With the continuous development of the internet of things, more frequent man-machine interaction, exponentially increased data traffic, continuously increased terminal types and continuously emerging service scenes put higher requirements on transmission bandwidth, timeliness, heterogeneous access and the like. The edge calculation is on the side close to the object or data source, providing near-end network, data, calculation, and storage services nearby. The internet of things is generally a three-layer architecture of 'end, network and cloud': the terminal comprises a sensing device, an executing device and a communication control gateway, and realizes data acquisition and device control; the network comprises a ubiquitous connection network of technologies such as 2/3/4G, wiFi, NB-loT, optical bandwidth and the like and is responsible for data transmission; the cloud comprises a cloud host, a load, cloud services and the like, is responsible for data storage and processing, and provides application services.
The essence of the industrial information safety is to ensure that the flow for completing the industrial production task is not tampered or damaged, the normal production process is realized, the established production target is completed, and the element flow of the production execution process is not monitored or stolen; the industrial information security protection aims at ensuring that communication networks and internet services required by the production of industrial enterprises are uninterrupted, industrial production equipment, a control system and an information system reliably and normally operate, data penetrating through the industrial information security protection system is not damaged, changed and leaked due to accidental or malicious reasons, and the continuity of industrial production and business is ensured.
Computers and computer networks have become important information carriers and transmission channels for enterprises, governments and other various confidential companies, however, while enjoying the convenience offered by computers and computer networks, internal and external network security issues have arisen. Although the prior art has protection and security technologies for data files, such as firewall and intranet and extranet isolation, these technologies still cannot solve the problem of security inside an enterprise.
Disclosure of Invention
In order to solve the above problems, the present invention provides an industrial communication information security gateway system.
The technical purpose of the invention is realized by the following technical scheme: an industrial communication information security gateway system comprises a data acquisition gateway device, an application server and a response device which are in communication connection with each other, wherein the data acquisition gateway device comprises a shell and an ARM processor arranged in the shell, and the ARM processor is provided with a data acquisition storage module, an equipment management module, a data processing and forwarding module, an Ethernet card, a serial port, an encryption module, a decryption module and a data security detection module;
in order to prevent data from being stolen or lost, the data acquisition and storage module does not open any port to an external network when the system is in on-line operation, some sensitive information is encrypted and stored by an encryption module, plaintext is not directly stored, and only encrypted ciphertext is stored;
in the data transmission process, the IoT equipment, the gateway and the middleware interact through data transmission, and corresponding encryption protocols and authentication modes are used to ensure the security and integrity of data in the transmission process and the legality of the access equipment and the gateway.
By adopting the technical scheme, the data acquisition and storage module does not open any port to the external network when the system is in online operation, some sensitive information is encrypted and stored by the encryption module, plaintext is not directly stored, only encrypted ciphertext is stored, and the safety of industrial communication information is enhanced. The gateway and the middleware are interacted through data transmission, and use corresponding encryption protocol and authentication mode to ensure the security and integrity of data in the transmission process, reduce the probability of industrial communication information leakage and ensure the user rights and interests.
Furthermore, a remote debugging module and a remote control module are further arranged on the ARM processor.
By adopting the technical scheme, a user of the security gateway system can carry out system debugging operation through the remote debugging module and carry out corresponding control through the remote control module.
Further, in the device management module, a main user of the function is an administrator, and through the device management function, the administrator can manage information of the IoT device and the gateway, perform addition and deletion investigation on the information, or manage a mounting relationship between the IoT device and the gateway and an authorization relationship between the gateway and an operator.
By adopting the technical scheme, the administrator is the main user of the security gateway system, and the convenience in the process of using the gateway system is enhanced.
Furthermore, the data processing and forwarding module is the most important function of the system, and the user using the function is mainly an operator, and is responsible for docking with the middleware module to push the state information of the remote IoT device and the gateway, the real-time data of the IoT device, the alarm data and the like to the user.
By adopting the technical scheme, the user can master the state information of the security gateway system in real time through the remote control module and the data processing and forwarding module, so that the user can make a control instruction in time, and the use safety of the system is improved.
Further, in the data processing and forwarding module, the industrial internet of things gateway can upload the acquired and packaged data to the cloud platform through the 4G network, and the security mechanism of the data needs to be considered in the process; meanwhile, in order to be compatible with the former local manufacturing execution system of the enterprise, the gateway needs to provide data forwarding support for the local manufacturing execution system.
By adopting the technical scheme, the data processing and forwarding module uploads the acquired data information to the cloud platform, so that the data loss is avoided.
Furthermore, the remote debugging module is connected with the PLC remotely through the cloud platform, an engineer can carry out program monitoring and downloading of firmware, when equipment breaks down, the engineer is remotely matched with field personnel, and the problem can be solved in a shorter time.
Further, the remote control module captures data frame data on a network card of the monitoring server by adopting a Winpcap technology, wherein the data frame data comprises source and destination MAC, IP, port number and transport layer protocol data, fingerprint information such as connection and communication frequency established between the monitoring client and the gateway server is analyzed by a communication frequency threshold value, the fingerprint information is compared with data in a white list base line library, if the fingerprint information is inconsistent or non-white list fingerprint data, a black list library is updated, an alarm is notified, and a main thread program discards corresponding received data and carries out alarm processing.
Further, the encryption module checks the login account of the client device connected to the gateway server, if the login account fails for three times continuously, the client device can be logged in within the delay time, and after the login is accumulated for more than 3 times, the client device is refused to log in, and the client device is added into the blacklist library and gives an alarm through the alarm module.
By adopting the technical scheme, the setting of the encryption module enhances the safety of the user in using the security gateway system, and after the verification fails for three times, the alarm information is transmitted to the terminal equipment of the administrator so as to perform corresponding processing to prevent data loss.
In conclusion, the invention has the following beneficial effects:
1. in the application, when the system is in on-line operation, the data acquisition and storage module does not open any port to the external network, some sensitive information is encrypted and stored by the encryption module, plaintext is not directly stored, only encrypted ciphertext is stored, and the safety of industrial communication information is enhanced. The gateway and the middleware are interacted through data transmission, and use corresponding encryption protocol and authentication mode to ensure the security and integrity of data in the transmission process, reduce the probability of industrial communication information leakage and ensure the user rights and interests;
2. in the application, a user can master the state information of the security gateway system in real time through the remote control module and the data processing and forwarding module, so that the user can make a control instruction in time, and the use safety of the system is improved;
3. in the application, the setting of the encryption module strengthens the safety of the user using the security gateway system, and after the three times of verification fail, the alarm information is transmitted to the terminal equipment of the administrator so as to perform corresponding processing to prevent data loss.
Drawings
FIG. 1 is a schematic diagram of the overall structure of an embodiment of the present invention;
fig. 2 is a system architecture diagram of an industrial communication information security gateway of an embodiment of the present invention.
In the figure: 1. a data acquisition gateway device; 2. an application server; 3. a response device; 4. an ARM processor; 5. a data acquisition and storage module; 6. a device management module; 7. a data processing and forwarding module; 8. an Ethernet card; 9. a serial port; 10. an encryption module; 11. a decryption module; 12. a data security detection module; 13. a remote debugging module; 14. a remote control module; 15. an IoT device; 16. and (4) a cloud platform.
Detailed Description
The technical solution in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application; it is obvious that the embodiments described are only a part of the embodiments of the present application, and not all embodiments, and all other embodiments obtained by a person of ordinary skill in the art without making creative efforts based on the embodiments in the present application belong to the protection scope of the present application.
It should be noted that the terms "first," "second," and the like in the description and claims of this application and in the accompanying drawings are used for distinguishing between similar elements and not necessarily for describing a particular sequential or chronological order. It should be understood that the data so used may be interchanged under appropriate circumstances in order to facilitate the description of the embodiments of the application herein. Moreover, the terms "comprises," "comprising," and "having," and any variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, system, article, or apparatus that comprises a list of steps or elements is not necessarily limited to those steps or elements expressly listed, but may include other steps or elements not expressly listed or inherent to such process, method, article, or apparatus.
In this application, the terms "upper", "lower", "left", "right", "front", "rear", "top", "bottom", "inner", "outer", "middle", "vertical", "horizontal", "lateral", "longitudinal", and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the drawings. These terms are used primarily to better describe the invention and its embodiments and are not intended to limit the indicated devices, elements or components to a particular orientation or to be constructed and operated in a particular orientation.
Moreover, some of the above terms may be used to indicate other meanings besides the orientation or positional relationship, for example, the term "on" may also be used to indicate some kind of attachment or connection relationship in some cases. The specific meanings of these terms in the present invention can be understood by those skilled in the art as appropriate.
Furthermore, the terms "mounted," "disposed," "provided," "connected," and "coupled" are to be construed broadly. For example, it may be a fixed connection, a removable connection, or a unitary construction; and may be a mechanical connection, or an electrical connection. The specific meanings of the above terms in the present invention can be understood according to specific situations by those of ordinary skill in the art.
As shown in fig. 1 and fig. 2, an embodiment of the present application discloses an industrial communication information security gateway system, which includes a data acquisition gateway device 1, an application server 2, and a response device 3, which are communicatively connected to each other. The data acquisition gateway device 1 comprises a shell and an ARM processor 4 arranged in the shell, wherein a data acquisition storage module 5, a device management module 6, a data processing forwarding module 7, an Ethernet card 8, a serial port 9, an encryption module 10, a decryption module 11, a data security detection module 12, a remote debugging module 13 and a remote control module 14 are arranged on the ARM processor 4.
In order to prevent data from being stolen or lost, the data acquisition and storage module 5 does not open any port to an external network when the system is in on-line operation, some sensitive information is encrypted and stored by the encryption module 10 and does not directly store plaintext, only encrypted ciphertext is stored, in the data transmission process, the IoT equipment 15, the gateway and the middleware interact through data transmission, and the security and the integrity of the data in the transmission process are ensured by using corresponding encryption protocols and authentication modes, so that the legality of the access equipment and the gateway is enhanced, the security of industrial communication information is enhanced, the security and the integrity of the data in the transmission process are ensured, the probability of industrial communication information leakage is reduced, and the user rights and interests are guaranteed.
In the device management module 6, a main user of this function is an administrator, and through the device management function, the administrator can manage information of the IoT device 15 and the gateway, perform addition, deletion, modification, and check on the information, or manage a mounting relationship between the IoT device 15 and the gateway, and an authorization relationship between the gateway and an operator. The data processing and forwarding module 7 is the most important function of the system, and the user using the function is mainly an operator, and is responsible for being in butt joint with the middleware module, and pushing the state information of the remote IoT device 15 and the gateway, the real-time data of the IoT device 15, the alarm data and the like to the user.
In the data processing and forwarding module 7, the industrial internet of things gateway can upload the acquired and packaged data to the cloud platform 16 through the 4G network, and the security mechanism of the data needs to be considered in the process; meanwhile, in order to be compatible with the former local manufacturing execution system of the enterprise, the gateway needs to provide data forwarding support for the local manufacturing execution system, and the gateway system is connected with the cloud platform 16, so that the probability of data loss is reduced.
The remote debugging module 13 is through cloud platform 16, and the engineer can remote connection equipment PLC carry out program monitoring and the download of firmware, and when equipment broke down, the engineer long-range and on-the-spot personnel cooperation can solve the problem in shorter time. The remote control module 14 captures data frame data on a network card of the monitoring server by adopting a Winpcap technology, wherein the data frame data comprises source and destination MAC, IP, a port number and transport layer protocol data, fingerprint information such as connection and communication frequency between the monitoring client and the gateway server is established, communication frequency threshold value analysis is carried out, the fingerprint information is compared with data in a white list base line library, and if the fingerprint information is inconsistent or non-white list fingerprint data, a black list library is updated and an alarm is notified, so that a main thread program discards corresponding received data and carries out alarm processing.
The encryption module 10 checks the login account of the client device connected to the gateway server, if the login account fails for three times continuously, the client device can be logged in within a delay time, and after the login account is accumulated for more than 3 times, the client device is refused to log in, and is added into the blacklist library, and an alarm is given through the alarm module. The setting of the encryption module 10 enhances the security of the user using the security gateway system, and after the three times of verification fails, the alarm information is transmitted to the terminal device of the administrator so as to perform corresponding processing to prevent data loss.
The application principle of an industrial communication information security gateway system in the embodiment is as follows: when the system is in on-line operation, the data acquisition and storage module 5 does not open any port to the external network, some sensitive information is encrypted and stored by the encryption module 10, plaintext is not directly stored, only encrypted ciphertext is stored, and the safety of industrial communication information is enhanced. The gateway and the middleware are interacted through data transmission, and use corresponding encryption protocol and authentication mode to ensure the security and integrity of data in the transmission process, reduce the probability of industrial communication information leakage and ensure the user rights and interests.
The above description is only a preferred embodiment of the present invention, and the scope of the present invention is not limited to the above embodiments, and all technical solutions that belong to the idea of the present invention belong to the scope of the present invention. It should be noted that modifications and adaptations to those skilled in the art without departing from the principles of the present invention should also be considered as within the scope of the present invention.

Claims (8)

1. An industrial communication information security gateway system, which comprises a data acquisition gateway device (1), an application server (2) and a response device (3) which are in communication connection with each other, and is characterized in that: the data acquisition gateway device (1) comprises a shell and an ARM processor (4) arranged in the shell, wherein a data acquisition storage module (5), a device management module (6), a data processing forwarding module (7), an Ethernet card (8), a serial port (9), an encryption module (10), a decryption module (11) and a data security detection module (12) are arranged on the ARM processor (4);
data of the system are stored in the data acquisition and storage module (5), in order to prevent the data from being stolen or lost, the data acquisition and storage module (5) does not open any port to an external network when the system is in online operation, some sensitive information is encrypted and stored by the encryption module (10), plaintext is not directly stored, and only encrypted ciphertext is stored;
in the data transmission process, the IoT equipment (15) interacts with the gateway, the gateway and the middleware through data transmission, and corresponding encryption protocols and authentication modes are used to ensure the safety and integrity of data in the transmission process and the legality of the access equipment and the gateway.
2. The industrial communication information security gateway system according to claim 1, wherein: and the ARM processor (4) is also provided with a remote debugging module (13) and a remote control module (14).
3. An industrial communication information security gateway system according to claim 2, characterized in that: in the device management module (6), the main user of the function is an administrator, and through the device management function, the administrator can manage the information of the IoT device (15) and the gateway, perform an add-delete check on the information, or manage the mounting relationship between the IoT device (15) and the gateway and the authorization relationship between the gateway and the operator.
4. An industrial communication information security gateway system according to claim 3, wherein: the data processing and forwarding module (7) is the most important function of the system, the user using the function is mainly an operator, and is responsible for being in butt joint with the middleware module, and pushing state information of the remote IoT device (15) and the gateway, real-time data of the IoT device (15), alarm data and the like to the user.
5. The industrial communication information security gateway system of claim 4, wherein: in the data processing and forwarding module (7), the industrial internet of things gateway can upload the acquired and packaged data to the cloud platform (16) through the 4G network, and the security mechanism of the data needs to be considered in the process; meanwhile, in order to be compatible with the former local manufacturing execution system of the enterprise, the gateway needs to provide data forwarding support for the local manufacturing execution system.
6. An industrial communication information security gateway system according to claim 5, wherein: the remote debugging module (13) is through cloud platform (16), and the engineer can remote connection equipment PLC carry out the program monitoring and download of firmware, and when equipment broke down, the engineer was long-range to cooperate with on-the-spot personnel, can solve the problem in shorter time.
7. An industrial communication information security gateway system as claimed in claim 6, wherein: the remote control module (14) captures data frame data on a network card of the monitoring server by adopting a Winpcap technology, wherein the data frame data comprises source and destination MAC, IP, port number and transport layer protocol data, fingerprint information such as connection and communication frequency established between the monitoring client and the gateway server is analyzed by a communication frequency threshold value, the fingerprint information is compared with data in a white list base line library, and if the fingerprint information is inconsistent or not, a black list library is updated, an alarm is notified, and a main thread program discards corresponding received data and carries out alarm processing.
8. An industrial communication information security gateway system as claimed in claim 7, wherein: the encryption module (10) checks the login account of the client device connected to the gateway server, if the login account fails for three times continuously, the client device can be logged in within the delay time, if the login account fails for more than 3 times, the client device is refused to log in, and the client device is added into the blacklist library and alarms through the alarm module.
CN202211428035.6A 2022-11-15 2022-11-15 Industrial communication information security gateway system Pending CN115733684A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202211428035.6A CN115733684A (en) 2022-11-15 2022-11-15 Industrial communication information security gateway system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202211428035.6A CN115733684A (en) 2022-11-15 2022-11-15 Industrial communication information security gateway system

Publications (1)

Publication Number Publication Date
CN115733684A true CN115733684A (en) 2023-03-03

Family

ID=85295834

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202211428035.6A Pending CN115733684A (en) 2022-11-15 2022-11-15 Industrial communication information security gateway system

Country Status (1)

Country Link
CN (1) CN115733684A (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018136059A1 (en) * 2017-01-19 2018-07-26 Nokia Technologies Oy IoT GATEWAY AND DESTINATION CLOUD SERVER
CN209201106U (en) * 2018-11-26 2019-08-02 湖南节点新火信息安全有限公司 A kind of application gateway system of data chain type storage and access safety
CN110943913A (en) * 2019-07-31 2020-03-31 广东互动电子网络媒体有限公司 Industrial safety isolation gateway
CN111901360A (en) * 2020-08-10 2020-11-06 西安交通大学 Control system suitable for safe access of intranet data

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018136059A1 (en) * 2017-01-19 2018-07-26 Nokia Technologies Oy IoT GATEWAY AND DESTINATION CLOUD SERVER
CN209201106U (en) * 2018-11-26 2019-08-02 湖南节点新火信息安全有限公司 A kind of application gateway system of data chain type storage and access safety
CN110943913A (en) * 2019-07-31 2020-03-31 广东互动电子网络媒体有限公司 Industrial safety isolation gateway
CN111901360A (en) * 2020-08-10 2020-11-06 西安交通大学 Control system suitable for safe access of intranet data

Similar Documents

Publication Publication Date Title
EP2036305B1 (en) Communication network application activity monitoring and control
US20210194932A1 (en) Network asset characterization, classification, grouping and control
CN109479013B (en) Logging of traffic in a computer network
CN102857388A (en) Cloud detection safety management auditing system
CN112187491A (en) Server management method, device and equipment
CN116055254A (en) Safe and trusted gateway system, control method, medium, equipment and terminal
CN113645213A (en) Multi-terminal network management monitoring system based on VPN technology
CN112822146A (en) Network connection monitoring method, device, system and computer readable storage medium
CN102932811A (en) Method and system for detecting lost terminal
CN114268457A (en) Multi-protocol multi-service public network security access method
KR101881061B1 (en) 2-way communication apparatus capable of changing communication mode and method thereof
CN115733684A (en) Industrial communication information security gateway system
KR100503772B1 (en) A monitoring system and method of auditing performanced work connected to database server by utility method
CN112350939B (en) Bypass blocking method, system, device, computer equipment and storage medium
JP4039361B2 (en) Analysis system using network
KR102024148B1 (en) An access control system of monitoring the file data during file transferring
CN103078865A (en) Network server communication model based on transmission control protocol (TCP)
CN115378618A (en) Network security protection architecture, communication method and device and communication equipment
CN111371765A (en) Online heterogeneous communication method and system based on link blocking
US10742480B2 (en) Network management as a service (MaaS) using reverse session-origination (RSO) tunnel
CN113347022B (en) Civil aircraft airborne information system network security capability detection system and method
CN117041760B (en) Communication network switching device, system and method
US20230325478A1 (en) Instrumenting applications to prevent abuse by privileged users
US20220417268A1 (en) Transmission device for transmitting data
CN110572353A (en) Cloud computing network security service

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20230303

RJ01 Rejection of invention patent application after publication