在分析变电站智能电子设备远程配置的底层安全机制如IP层协议安全结构(IPSec)、安全套接层协议(SSL)等方法局限性的基础上,提出了一种基于可扩展标记语言安全(XML Security)的变电站远程配置安全机制。该机制定义了变电站配置描述语言(SCL)的安全扩展,通过XML数字签名实现配置文档的完整性和通信双方实体的身份认证;通过XML加密实现对配置文档的多粒度安全保护。为验证安全机制的有效性,设计了远程安全配置仿真系统。对变电站实例配置文件的安全处理结果显示,该方法能有效满足SCL配置过程中的安全需求。
Based on the limitation analysis of security mechanisms at bottom layer for the remote configuration of substation IEDs(Intelligent Electronic Devices), such as IPSec(Security architecture for IP network) and SSL(Secure Socket Layer), a security communication mechanism based on XML(eXtensible Markup Language) Security is presented. An extended schema for SCL(Suhstation Configuration description Language) security is defined. The integrality of SCL files and the authentication of both communication ends are guaranteed by XMI. digital signature, and the multi-granularity confidentiality of SCL elements are protected by the symmetrical key encryption. A simulation system is designed and a remote configuration instance shows its validity.