人民长江 ›› 2025, Vol. 56 ›› Issue (5): 210-215.doi: 10.16232/j.cnki.1001-4179.2025.05.029

• • 上一篇    

基于商用密码算法的水利工控协议安全加固技术

葛创杰,荆芳,王戈飞,袁世冲   

  • 收稿日期:2024-05-28 出版日期:2025-05-28 发布日期:2025-05-28

Security reinforcement technology for water conservancy industrial control protocol based on commercial cryptographic algorithm

GE Chuangjie,JING Fang,WANG Gefei,YUAN Shichong   

  • Received:2024-05-28 Online:2025-05-28 Published:2025-05-28

摘要: 针对水利工控系统面临的数据监听、数据篡改、数据伪造等安全风险,基于商用密码算法,开展数据安全传输技术研究,确保水利系统中工业以太网数据和现场总线数据传输的机密性、完整性和真实性。在分析当前水利工控系统面临的数据传输风险的基础上,针对工业以太网和现场总线 2 类通信协议进行安全加固设计,完成了密码模块设计,开展了多场景安全性测试与分析。经某水务基地水利一体化闸门现场测试,2 类协议下各通讯主体间分别收发数据 10000 次,其中工业以太网层共计成功收发数据 10000 次,失败 0 次,加密前后平均延时 0.25 ms;现场总线层共计成功收发数据 9977 次,失败 23 次,加密前后平均延时 269.28ms。另外,开展了身份仿冒、数据窃取、数据篡改攻击测试。结果表明:该方法加解密成功率高,时延低,运行稳定,能够抵御外部攻击,在不影响业务运转前提下,可有效保障水利工控场景下的数据通信安全。

关键词: 水利工控系统;数据传输风险;数据加解密;协议加固;商用密码算法;通信安全

Abstract: Given the security risks such as data monitoring, data tampering, and data forgery in water conservancy industrial control systems, research on data security transmission technology based on commercial cryptographic algorithms is carried out to ensure the confidentiality, integrity, and authenticity of industrial Ethernet data and fieldbus data transmission in water conservancy systems. We analyzed the data transmission risks faced by the current water conservancy industrial control system. Then we designed the security reinforcement for the 2 major types of communication protocols for industrial control, completed the design of the cryptographic module, and carried out multi-scenario security testing and analysis. Field tests were carried out at an integrated gate of a water conservancy base. Each communication device sent and received data 10 000 times in the two modes, of which the industrial Ethernet layer successfully sent and received data 10 000 times, with 0 failures. The average delay before and after encryption was 0.25 ms. And the fieldbus layer successfully sent and received data 9977 times, with 23 failures. The average delay before and after encryption was 269.28 ms. In addition, identity impersonation, data theft, and data tampering attacks were tested. The experimental results show that the method has a high success rate of encryption and decryption, a low delay, a very stable operation, and can resist external attacks. It can effectively guarantee the data communication process security in the water conservancy industrial control scenario without affecting the business operation.

Key words: water conservancy industrial control system;data transmission risk;data encryption and decryption;protocol reinforcement;commercial cryptographic algorithm;communication security