首页|基于可信计算的电力系统软件供应链安全防护解决方案

基于可信计算的电力系统软件供应链安全防护解决方案

扫码查看
随着信息技术和物联网的快速发展,电力行业的信息化水平逐渐提高,电力供应链的数字化、智能化程度日益加深.然而,随之而来的安全问题也日益突出,尤其在电力系统软件供应链中,涉及供应商管理、研发生产、安全检测等多个环节,任何安全漏洞都可能导致严重的安全事故.为了提高电力系统软件供应链的安全性,本文先对电力系统供应链的业务特征进行了分析,并针对供应链管控缺失、终端接入安全风险增加和关键控制业务缺乏安全认证等问题,提出了基于可信计算的电力系统软件供应链安全防护解决方案,设计了从供应链源头到设备终端的全链条认证与安全防护架构,保障了关键业务数据的完整性、机密性和合规性,为电力系统的安全运行提供了强有力的保障.
With the rapid development of information technology and the Internet of Things,the informationalized level of the power industry is gradually improving,and the digitalization and intelligence of the power supply chain are deepening.However,the ensuing security problems are becoming increasingly prominent,especially in the power system software supply chain,involving supplier management,research and development,production,safety testing and other links,any security loopholes may lead to serious security accidents.In order to improve the security of the power system software supply chain,this paper first analyzes the business characteristics of the power system supply chain,and proposes a power system software supply chain security protection solution based on trusted computing in view of the problems such as lack of supply chain control,increased terminal access security risks and lack of security certification for key control services.The whole chain authentication and security protection architecture from the source of the supply chain to the terminal of the equipment is designed to ensure the integrity,confidentiality and compliance of key business data,and provide a strong guarantee for the safe operation of the power system.

Trusted computingPower system software supply chainWhole life cycle controlEnd-to-end authentication

张富川、吴金宇、陈树廷、王杨

展开 >

中国南方电网有限责任公司,广东 广州 510663

北京可信华泰信息技术有限公司,北京 100195

可信计算 电力系统软件供应链 全生命周期管控 端到端认证

2025

中国科技产业
科技部火炬高技术产业开发中心

中国科技产业

影响因子:0.181
ISSN:1002-0608
年,卷(期):2025.(1)