Skip to main content
Top

2023 | OriginalPaper | Chapter

Research and Application of Endogenous Security Active Defense Technology for Domestic Nuclear Safety-Level Gateway Equipment

Authors : Yong Li, Ming-Xing Liu, Hao Peng, Rong-Bin Hou, Quan Ma, Ru-Qiao Wang, Gen-Hua Liang

Published in: New Energy Power Generation Automation and Intelligent Technology

Publisher: Springer Nature Singapore

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

Gateway is a protective equipment at the boundary of the nuclear safety-level I&C system. Aiming at the unknown threat across the boundary of information physical space, this paper studies several key technologies of active defense, and constructs the gateway deep secure architecture that can resist multilevel and multi-dimensional complex attacks. Firstly, the systematic control mechanism of the gateway is constructed, which mechanism includes access control for data flow, IP whitelist at network layer, function code whitelist at application layer, IP/MAC binding and the isolation mechanism of chip’s external ports. Secondly, based on the domestic trust root, the trusted chain from bootloader to the upper-layer application is built to guarantee the secure startup of the embedded system, and the key application processes are measured periodically and verified dynamically during the running process. Based on the above, from building equipment embedded trusted system environment to its security functions, a set of active security defense mechanisms of the gateway equipment sare formed, which enhances the security of the system and improves the information security protection n capability of the equipment.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literature
1.
go back to reference U.S. NRC. Cyber security programs for nuclear facilities: RG 5.71–2010[S]. Washington, DC: NRC, pp. 4–20 (2010) U.S. NRC. Cyber security programs for nuclear facilities: RG 5.71–2010[S]. Washington, DC: NRC, pp. 4–20 (2010)
2.
go back to reference International Electrotechnical Commission. Nuclear power plants Instrumentation and control systems Requirements for coordinating safety and cybersecurity:IEC 62859-2016. International Electrotechnical Commission, Geneva, pp. 18-20 (2016) International Electrotechnical Commission. Nuclear power plants Instrumentation and control systems Requirements for coordinating safety and cybersecurity:IEC 62859-2016. International Electrotechnical Commission, Geneva, pp. 18-20 (2016)
3.
go back to reference AVENT. A unified framework for risk and vulnerability analysis covering both safety and security. Reliab. Eng. Syst. Saf. 92(6), 745–54 (2007) AVENT. A unified framework for risk and vulnerability analysis covering both safety and security. Reliab. Eng. Syst. Saf. 92(6), 745–54 (2007)
4.
go back to reference IECTR 63069–2019 Industrial-process measurement, control and automation Framework for functional safety and security IECTR 63069–2019 Industrial-process measurement, control and automation Framework for functional safety and security
5.
go back to reference Miller, C Dr., Valasek, C.: Remote exploitation of an unaltered passenger vehicle, August 2015 Miller, C Dr., Valasek, C.: Remote exploitation of an unaltered passenger vehicle, August 2015
6.
go back to reference IEC 62859, Nuclear power plants Instrumentation and control systems Requirements for coordinating safety and cybersecurity IEC 62859, Nuclear power plants Instrumentation and control systems Requirements for coordinating safety and cybersecurity
7.
go back to reference IEC 62443-3-3, Industrial communication networks - Network and system security IEC 62443-3-3, Industrial communication networks - Network and system security
8.
go back to reference IEC62645, Nuclear power plants instrumentation and control systems requirements for security programmes for computer-based systems IEC62645, Nuclear power plants instrumentation and control systems requirements for security programmes for computer-based systems
9.
go back to reference IEC 61508-3, Functional safety of electrical/electronic/programmable electronic safety-related systems Part 3 IEC 61508-3, Functional safety of electrical/electronic/programmable electronic safety-related systems Part 3
10.
go back to reference International electro technical commission. Failure Modes and Effects Analysis (FMEA and FMECA) : IEC 60812–2018. International electro technical commission, Geneva, vol. 20 (2018) International electro technical commission. Failure Modes and Effects Analysis (FMEA and FMECA) : IEC 60812–2018. International electro technical commission, Geneva, vol. 20 (2018)
11.
go back to reference International Electro technical Commission. Functional safety of electrical/electronic/programmable electronic safety related systems-Part 1: General requirements: IEC 61508-1-2010. International Electro technical Commission, Geneva, vol. 55–56 (2010) International Electro technical Commission. Functional safety of electrical/electronic/programmable electronic safety related systems-Part 1: General requirements: IEC 61508-1-2010. International Electro technical Commission, Geneva, vol. 55–56 (2010)
12.
go back to reference International electro technical commission. Functional safety of electrical/electronic/programmable electronic safety related systems- Part 2: Requirements for electrical/electronic/programmable electronic safety related systems: IEC 61508-2-2010. International Electro technical Commission, Geneva, pp. 15-40 (2010) International electro technical commission. Functional safety of electrical/electronic/programmable electronic safety related systems- Part 2: Requirements for electrical/electronic/programmable electronic safety related systems: IEC 61508-2-2010. International Electro technical Commission, Geneva, pp. 15-40 (2010)
Metadata
Title
Research and Application of Endogenous Security Active Defense Technology for Domestic Nuclear Safety-Level Gateway Equipment
Authors
Yong Li
Ming-Xing Liu
Hao Peng
Rong-Bin Hou
Quan Ma
Ru-Qiao Wang
Gen-Hua Liang
Copyright Year
2023
Publisher
Springer Nature Singapore
DOI
https://doi.org/10.1007/978-981-99-3455-3_20