综合智慧能源 ›› 2024, Vol. 46 ›› Issue (5): 81-90.doi: 10.3969/j.issn.2097-0706.2024.05.010

• 网络安全防护 • 上一篇    

综合智慧能源系统典型构架网络安全防护研究

刘涛(), 李伟华(), 汤熠()   

  1. 深圳供电局有限公司,广东 深圳 518133
  • 收稿日期:2023-04-03 修回日期:2023-06-29 出版日期:2024-05-25
  • 作者简介:刘涛(1980),男,高级工程师,博士,从事电能计量工作,512474@qq.com
    李伟华(1975),男,高级工程师,从事电能计量工作,13602585342@139.com
    汤熠(1990),男,工程师,硕士,从事电能计量工作,tangyi@csg.cn
  • 基金资助:
    南方电网公司重点科技项目(090000KK52210170)

Security protection of typical networks for integrated smart energy systems

LIU Tao(), LI Weihua(), TANG Yi()   

  1. Shenzhen Power Supply Bureau Company Limited,Shenzhen 518133,China
  • Received:2023-04-03 Revised:2023-06-29 Published:2024-05-25
  • Supported by:
    Key Technology Project of China Southern Power Grid Company Limited(090000KK52210170)

摘要:

构建综合智慧能源系统及其网络安全防护架构,为实现安全的电力一体化基础设施提供了理论依据。首先,通过分析变电站、光伏发电站、储能站、充电站、数据中心站等各子站的特点,提出综合智慧能源系统架构,并在此架构下设计信息服务系统和分层体系结构。其次,对不同子站数据交互需求进行分析,提出综合智慧能源系统的数据交互模型,在此基础上根据五大安全目标,将综合智慧能源系统各子站分成3个类别,分别分析其面临的网络安全威胁。再次,立足于系统网络安全防护原则,构建综合智慧能源系统网络安全防护架构,并在该架构下提出具体的综合智慧能源系统安全分区和隔离方案。最后,结合等保2.0的相关评估指标,对综合智慧能源系统网络安全防护架构及系统安全分区和隔离方案的可行性进行评估,结果表明该架构符合等保2.0的标准。

关键词: 综合智慧能源系统, 网络安全威胁分析, 网络安全防护架构, 多站融合, 数据交互

Abstract:

Integrated infrastructure,represented by multi-station integrated intelligent energy systems,is a main form of new power systems.Based on the analysis on characteristics of different components,including substations,photovoltaic stations,and data center stations,a proper structure for integrated smart energy systems is constructed,and the information service system and hierarchical structure under this framework are designed.A data interaction model for the integrated smart energy system is proposed,considering the needs of data interaction between different substations.To achieve five major security goals,components of this system is divided into three categories in view of different threats to network security.Based on the principles of network security protection for the system,zoning and isolation plans for the integrated smart energy system are proposed under this protection architecture.Finally,the feasibility of the network security protection architecture for integrated intelligent energy systems and its zoning and isolation schemes are evaluated in accordance with relevant evaluation indicators in Equal Protection 2.0.The results show that the architecture meets the standards of Equal Protection 2.0.

Key words: integrated intelligent energy system, network security threat analysis, network security protection architecture, multi-station integration, data interaction

中图分类号: