首页 | 本学科首页   官方微博 | 高级检索  
     

配电物联网边缘物联代理网络安全防护研究
引用本文:何连杰,亢超群,孙志达,李二霞,李玉凌.配电物联网边缘物联代理网络安全防护研究[J].供用电,2021,38(2).
作者姓名:何连杰  亢超群  孙志达  李二霞  李玉凌
作者单位:中国电力科学研究院有限公司,北京 100192;国网浙江省电力有限公司电力科学研究院,浙江杭州 310014
基金项目:国家电网有限公司科技项目“终端智能化技术研究”(5400-201955454A-0-0-00)。
摘    要:配电物联网是配电监控系统向物联网模式演进的结果,边缘物联代理是连接物联网终端与云端的重要感知层设备。通过分析边缘物联代理自身及交互面临的安全风险和安全需求,研究了可信启动、身份认证、密钥协商、数据机密性保护、数据完整性保护、安全监测等技术,构建了基于可信启动的设备本体安全、基于身份认证和数据保护的交互安全以及基于日志、流量信息实时采集的安全监测于一体的安全防护架构,有效避免了因边缘物联代理遭受恶意攻击而导致整个系统瘫痪事件发生,有助于提升配电物联网在新的网络安全形势下抵御恶意攻击的能力。

关 键 词:配电物联网  网络安全  边缘物联代理  可信启动  身份认证  数据保护  安全监测

Research on Security Protection of Edge IoT Agent on the Power Distribution IoT
HE Lianjie,KANG Chaoqun,SUN Zhida,LI Erxia,LI Yuling.Research on Security Protection of Edge IoT Agent on the Power Distribution IoT[J].Distribution & Utilization,2021,38(2).
Authors:HE Lianjie  KANG Chaoqun  SUN Zhida  LI Erxia  LI Yuling
Affiliation:(China Electric Power Research Institute,Beijing 100192,China;State Grid Zhejiang Electric Power Research Institute,Hangzhou 310014,China)
Abstract:Power distribution IoT is the evolution result of distribution monitoring system to the Internet of things.Edge IOT agent is an important perceptual layer device connecting IOT terminal and cloud.By analyzing the security risks and security requirements faced by the edge IoT agent and its interaction,the technologies of trusted start,identity authentication,key agreement,data confidentiality protection,data integrity protection,security monitoring are studied.And an integrated security protection structure of device ontology security based on trusted start,interactive security based on identity authentication and data protection,and security monitoring based on real-time collection of log and traffic information are constructed.The whole system paralysis event caused by malicious attacks on the edge IoT agent is avoided effectively.It helps to improve the ability of power distribution IoT resisting malicious attacks in the new network security situation.
Keywords:power distribution IoT  network security  edge IoT agent  trusted start  identity authentication  data protection  security monitoring
本文献已被 CNKI 维普 万方数据 等数据库收录!
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号