Abstract:
It is difficult to control the security of plants and stations whose assets are not belonged to the State Grid Corporation of China when they are connected to the power dispatching data network. If the attacked equipment is connected, the illegal traffic generated by them can attack any device node in the dispatching data network so long as knowing the destination IP, causing serious security risks. To solve this problem, an improved bidirectional forwarding detection (BFD) access authentication technology is proposed in this paper. The BFD protocol authentication results control the network equipment interface actions, and the isolation of risk equipment is realized at the physical layer. The method and the traditional authentication method are tested and verified in the laboratory environment. The results show that compared with the traditional authentication method, the method in this paper has higher security, more flexible concurrent processing mode, and reduced the business recovery time of link failure while reducing the hardware cost. This method has been deployed and applied in the high-speed synchronous network of State Grid Corporation of China, and its effectiveness has also been proved.