高级检索

基于国密算法的电力系统CMS协议双证书系统及其通信方法

A Dual-Certificate System and Communication Method for the CMS Protocol in Power Systems Based on National Cryptographic Algorithms

  • 摘要: 当今智能电网发展迅速,变电站内测控、保护装置与监控后台之间的数据通信安全已成为保障电力系统稳定运行的核心基石。传统的基于单证书的CMS(Communication Message Specification)通信协议存在密钥复用风险、性能瓶颈和证书管理策略冲突等问题。为解决上述问题,本文提出一种基于国密算法(SM2/SM3/SM4)的双证书实现方法及系统。该方法将加密证书与签名证书分离,加密证书专用于协商加密通信数据的会话密钥,签名证书则用于实现身份认证和数据完整性保护。文章详细阐述了双证书体系的架构设计、工作流程、密钥管理机制及抗重放攻击策略。实验与分析表明,相较于传统单证书方案,本方法在安全性、处理性能和管理灵活性方面均有显著提升,能够有效满足智能电网高安全、高可靠通信的需求。

     

    Abstract: The development of smart grids is rapid nowadays. The security of data communication between measurement and control devices, protection devices and monitoring backends in substations has become a core foundation for ensuring the stable operation of power systems. Traditional CMS(Communication Message Specification)communication protocols based on single certificates have problems such as key reuse risks, performance bottlenecks and conflicts in certificate management strategies. To address these issues, this paper proposes a dual-certificate implementation method and system based on national cryptographic algorithms (SM2/SM3/SM4). This method separates the encryption certificate from the signature certificate, with the encryption certificate dedicated to negotiating session keys for encrypted communication data, and the signature certificate used for identity authentication and data integrity protection. The paper elaborates in detail on the architecture design, workflow, key management mechanism and anti-replay attack strategy of the dual-certificate system. Experiments and analyses show that compared with the traditional single-certificate scheme, this method has significant improvements in security, processing performance and management flexibility, and can effectively meet the high-security and high-reliability communication requirements of smart grids.

     

/

返回文章
返回