版权所有@2014 《油气储运》杂志社 冀ICP备号:0000000
地址:河北省廊坊市金光道51号(065000);电话:0316-2177193 / 0316-2176753; 传真:0316-2177392; 网址:yqcy.paperonce.org
技术支持:西安三才科技实业有限公司 029-89381847;029-88222991
油气管道SCADA系统分区分域安全防护方法
Safety protection of oil/gas pipeline SCADA system by partition
oil/gas pipeline
; safety partition; SCADA; longitudinal; encryption中国石油油气管道SCADA系统存在安全防护及管理相关标准缺失,安全防护技术措施不足等问题,严重威胁国家的能源安全.为此,在充分调研油气调控业务流程、油气管道SCADA系统建设现状的基础上,借鉴国内电力行业电力二次防护方案及美国石油协会(API)的相关安全标准,依据国家信息安全等级保护的相关标准要求,进一步细化了系统安全区域的划分,明确了各安全区域的防护方法,加强了重点安全区内的安全防护能力,形成了多层防护手段.提出了油气调控领域"分区分域,物理隔离,多层防护,纵向加密"的安全防护方针,从而强化了油气管道SCADA系统的边界安全,提升了系统内部的安全防护能力,确保了核心数据、控制指令、机密信息不被攻击者窃取或破坏.
For oil/gas pipeline SCADA system in China, some problems exist, such as absence of related safety protection and management standards and insufficient safety protection measures, which seriously threaten the country's energy security. Therefore, based on the comprehensive investigation of the oil and gas control processes and the current situation of the construction of oil/gas pipeline SCADA system, and according to China’s power industry power secondary protection scheme and the relevant safety standards of American Petroleum Institute as well as the related standards of national classified protection of information security, this paper provides a further partition of safety areas, specifies the protection of each safety area and strengthens the protection capability at key safety areas, which forms a multi-layer protection method. The policy of "partition, physical isolation, multi-layer protection, and longitudinal encryption" is proposed for the oil and gas control areas, which helps to strengthen the border security of oil/gas pipeline SCADA system, improve the safety protection capability inside the system and ensure that the core data, control instruction and confidential information not be stolen or destroyed by attackers.
[1]彭勇,江常青,谢丰,等.工业控制系统信息安全研究进展[J].清华大学学报 (自然科学版) , 2012 (10) : 1396-1408.
PENG Y,JIANG C Q,XIE F,et al. Industrial control system cybersecurity research[J]. Journal of Tsinghua University(Natural Science), 2012 (10):1396-1408.
[2]李玉敏. 工业控制网络信息安全的防护措施与应用[J]. 中国仪器仪表, 2012 (11) : 59-64.
LI Y M. Industrial control network information safety protection measures and application[J]. China Instrumentation, 2012 (11):59-64.
[3]魏钦志. 工业控制系统安全现状及安全策略分析[J]. 信息安全与技术, 2012 (2) : 23-26.
WEI Q Z. Industrial control system security situation and safety strategy analysis[J]. Information Security and Technology, 2012 (2):23-26.
[4]陈星,贾卓生. 工业控制网络的信息安全威胁与脆弱性分析与研究[J].计算机科学, 2012 (10) : 188-190.
CHEN X,JIA Z S. Industrial control network information security threats and vulnerability analysis and research[J]. Computer Science, 2012 (10):188-190.
[5]彭杰,刘力. 工业控制系统信息安全性分析[J]. 自动化仪表,2012 (12) : 36-39.
PENG J,LIU L. Analysis of information security for industrial control system[J]. Process Automation Instrumentation, 2012 (12):36-39.
[6]王浩,吴中福,王平. 工业控制网络安全模型研究[J]. 计算机科学, 2007 (5) : 96-98.
WANG H,WU Z F,WANG P. Research on security model for industrial control networks[J]. Computer Science, 2007 (5):96-98.
[7]郭春梅,毕学尧.对工业控制系统网络安全的思考[J].信息安全与通信保密, 2013 (3) : 42-44.
GUO C M,BI X Y. A Study on network security of industrial control system[J]. China Information Security, 2013 (3):42-44.
[8]田嘉. 电厂二次系统安全防护方案的设计与规划[J]. 电力信息化, 2011 (4) : 60-64.
TIAN J. Design and implementation of secondary system security protection scheme[J]. Electric Power Information Technology, 2011 (4):60-64.
[9]曾玉,马进霞,张立平. 某电厂二次系统安全防护方案的设计与实现[J].电力系统保护与控制, 2009 (8) : 72-78.
ZENG Y,MA J X,ZHANG L P. Design and implementation of secondary system security protection scheme of a power plant[J]. Power System Protection and Control, 2009 (8):72-78.
[10]李宏发. 物理隔离装置技术分析及其在电力系统中的应用[J].计算机应用, 2006 (6) : 328-330.
LI H F. Analysis of physical isolation device technology and application in power supply system [J]. Computer Applications, 2006 (6):328-330.
[1]张宝强 焦如义 江勇 张倩.国内外长输油气管道顶管工程标准对比分析[J].油气储运,2016,35(预出版):1.
ZHANG Baoqiang,JIAO Ruyi,JIANG Yong,et al.Comparative analysis on the jacking engineering standards for long-distance oil and gas pipelines in China and abroad[J].Oil & Gas Storage and Transportation,2016,35(11):1.
[2]朱春靖 潘红丽.海外油气管道社会风险评估方法[J].油气储运,2016,35(预出版):1.
ZHU Chunjing,PAN Hongli.Assessment method of security risk of overseas oil and gas pipeline[J].Oil & Gas Storage and Transportation,2016,35(11):1.
[3]陈晓晖 王荣玖 许峻岭 李锋涛 樊明峰.管道悬索跨越大型主塔液压自爬模技术的工艺创新[J].油气储运,2016,35(预出版):1.
CHEN Xiaohui,WANG Rongjiu,XU Junling,et al.Improvement and innovation of hydraulic self-climbing formwork technology for large main tower of pipeline suspension crossingg[J].Oil & Gas Storage and Transportation,2016,35(11):1.
[4]谭东杰,李柏松,杨晓峥,等.中国石油油气管道设备国产化现状和展望[J].油气储运,2015,34(9):913.[doi:10.6047/j.issn.1000-8241.2015.09.001]
TAN Dongjie,LI Baisong,YANG Xiaozheng,et al.Development and prospect of PetroChinas pipeline equipment localization[J].Oil & Gas Storage and Transportation,2015,34(11):913.[doi:10.6047/j.issn.1000-8241.2015.09.001]
[5]张宝强,焦如义,江勇,等.国内外长输油气管道顶管工程标准对比分析[J].油气储运,2015,34(12):1345.[doi:10.6047/j.issn.1000-8241.2015.12.019]
ZHANG Baoqiang,JIAO Ruyi,JIANG Yong,et al.Comparative analysis on the jacking engineering standards for long-distance oil and gas pipelines in China and abroad[J].Oil & Gas Storage and Transportation,2015,34(11):1345.[doi:10.6047/j.issn.1000-8241.2015.12.019]
[6]祝悫智,段沛夏,王红菊,等.全球油气管道建设现状及发展趋势[J].油气储运,2015,34(12):1262.[doi:10.6047/j.issn.1000-8241.2015.12.002]
ZHU Quezhi,DUAN Peixia,WANG Hongju,et al.Current situations and future development of oil and gas pipelines in the world[J].Oil & Gas Storage and Transportation,2015,34(11):1262.[doi:10.6047/j.issn.1000-8241.2015.12.002]
[7]经建芳,李康春,邓富康,等.油气管道腐蚀的灰色线性回归组合预测模型[J].油气储运,2015,34(12):1300.[doi:10.6047/j.issn.1000-8241.2015.12.010]
JING Jianfang,LI Kangchun,DENG Fukang,et al.Prediction model of oil and gas pipeline corrosion based on grey-linear regression combination[J].Oil & Gas Storage and Transportation,2015,34(11):1300.[doi:10.6047/j.issn.1000-8241.2015.12.010]
[8]邓涛,肖斌涛,于达,等.油气管道试压水排放试验系统[J].油气储运,2015,34(12):1305.[doi:10.6047/j.issn.1000-8241.2015.12.011]
DENG Tao,XIAO Bintao,YU Da,et al.Test system for water draining after hydrotest of oil/gas pipelines[J].Oil & Gas Storage and Transportation,2015,34(11):1305.[doi:10.6047/j.issn.1000-8241.2015.12.011]
[9]陈晓晖,王荣玖,许峻岭,等.管道悬索跨越大型主塔液压自爬模技术的工艺创新[J].油气储运,2015,34(12):1333.[doi:10.6047/j.issn.1000-8241.2015.12.017]
CHEN Xiaohui,WANG Rongjiu,XU Junling,et al.Improvement and innovation of hydraulic self-climbing formwork technology for large main tower of pipeline suspension crossing[J].Oil & Gas Storage and Transportation,2015,34(11):1333.[doi:10.6047/j.issn.1000-8241.2015.12.017]
[10]钟威,高剑锋.油气管道典型地质灾害危险性评价[J].油气储运,2015,34(9):934.[doi:10.6047/j.issn.1000-8241.2015.09.004]
ZHONG Wei,GAO Jianfeng.Hazard assessment of typical geological disasters along oil and gas pipeline[J].Oil & Gas Storage and Transportation,2015,34(11):934.[doi:10.6047/j.issn.1000-8241.2015.09.004]
收稿日期:2013-10-31;改回日期:2014-8-22。
基金项目:西气东输二线关键技术研究重大科技专项(二期)"油气管道SCADA系统软件国产化研发",2009E-0102.
作者简介:陈鹏,工程师,1981年生,2003年毕业于中国石油大学(北京)计算机专业,现主要从事管道自动化技术的研究工作.Tel: 010-59983718, Email: scada_paper@163.com