电力业务场景下用户特征安全认证模型研究
2021-07-28郭晶焦艳斌张晓韬
郭晶 焦艳斌 张晓韬



DOI:10.16661/j.cnki.1672-3791.2103-5042-5017
摘 要:国网公司的身份安全认证存在认证方式单一、安全隐患排查困难、用户体验不够友好等问题,难以有效支撑能源互联网的建设。提出基于时间、空间、行为等多维度的用户特征安全认证模型,面对电力业务场景设计动态身份安全认证系统,通过特征选择算法进行一致性检测,确保系统能够准确对用戶进行身份认证。该模型在某省公司进行实际应用,首次实现信息系统账号关联到实人,更便捷的是实现用户身份全生命周期管控。该文形成的研究成果也将适用于其他大型企业动态身份认证工作,具备很强的应用价值。
关键词:身份特征 身份安全认证 权限管理平台 电力业务
中图分类号:TP311.5 文献标识码:A文章编号:1672-3791(2021)03(b)-0028-04
Research on User Characteristic Security Authentication Model in Power Business Scenarios
GUO Jing1 JIAO Yanbin2 ZHANG Xiaotao1
(1.Aostar Information Technologies Co., Ltd., Chengdu, Sichuan Province, 610041 China; 2.State Grid Information and Communication Co., Ltd., Beijing, 102211 China)
Abstract: The identity security authentication of State Grid has prob:lems such as single authentication method, difficulty in troubleshooting hidden dangers, and unfriendly user experience, which is difficult to effectively support the construction of the energy Internet. Propose a multi-dimensional user characteristic security authentication model based on time, space, behavior, etc., design a dynamic identity security authentication system for power business scenarios, and perform consistency detection through feature selection algorithms to ensure that the system can accurately authenticate users. This model was actually applied in a provincial company. For the first time, the information system account was linked to a real person. It is more convenient to realize the full life cycle control of user identity. The research results formed in the article are also applicable to other large-scale enterprise dynamic identity authentication work, and have strong application value.
Key Words: Identity characteristics; Identity security certification; Authority management platform; Electricity business
随着能源互联网发展战略的逐步实施以及智能电网建设进程的快速推进,电力系统业务规模爆发式增长,种类也不断增多,信息安全防护工作的难度逐渐增加。身份认证作为信息安全防护基础,国家电网公司、南方电网等在近10年不断建设和完善统一身份认证及授权管理基础系统,应用了证书认证、扫码认证、多因子认证等多种技术。
经过SG186、SGERP建设,国家电网公司以统一权限平台为主的身份管理体系,其重点在于支撑“账号”“业务应用”,必然存在身份信息缺失、认证形式缺乏多样性、用户获得感较低等不足;同时,系统主要应用范围是信息内网,环境相对简单,采用的身份认证技术较为传统。但……
