作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2026, Vol. 52 ›› Issue (10): 1-17. doi: 10.19678/j.issn.1000-3428.0260693

• 前沿观点与综述 • 上一篇    

面向智能电网的可部署内生安全技术研究综述

王鼎宇1, 张帆2, 王俊超2, 曹琰1   

  1. 1. 郑州大学网络空间安全学院, 河南 郑州 450002;
    2. 复旦大学大数据研究院, 上海 200433
  • 收稿日期:2026-05-13 修回日期:2026-08-24 发布日期:2026-09-29
  • 作者简介:王鼎宇(CCF学生会员),男,硕士,主研方向为软件多样化、编译安全,E-mail:wangjunchao11@126.com;张帆(CCF专业会员、共同一作),教授;王俊超(CCF杰出会员、通信作者),副教授;曹琰(CCF高级会员),教授。
  • 基金资助:
    国家电网有限公司总部管理科技项目(52130025002S-473-ZN)。

Review of Deployable Endogenous Security Technologies for Smart Grids

WANG Dingyu1, ZHANG Fan2, WANG Junchao2, CAO Yan1   

  1. 1. School of Cyber Science and Engineering, Zhengzhou University, Zhengzhou 450002, Henan, China;
    2. Institute of Big Data, Fudan University, Shanghai 200433, China
  • Received:2026-05-13 Revised:2026-08-24 Published:2026-09-29

摘要: 智能电网作为现代能源体系的关键基础设施,其网络空间与物理运行过程深度耦合,已成为国家能源安全的重要支撑。随着分布式能源、储能系统、智能电表等海量异构设备的大规模接入,"云-管-边-端"协同架构成为主流形态。然而,攻击手段的持续演进使针对数据采集与监视控制(SCADA)系统、智能终端和通信网络的网络攻击日益频发,传统"封门补漏"式被动防御固有的滞后性与对先验知识的依赖,使其难以有效应对深植于系统架构与运行过程的安全威胁。信息系统中由漏洞、后门等自身缺陷引发的内生安全问题,难以在设计与开发阶段被完全消除,成为制约电网安全防护能力提升的根本性瓶颈。针对上述问题,系统研究了可部署于智能电网的内生安全技术。首先,以智能电网面临的供应链攻击、漏洞利用攻击、分布式拒绝服务/拒绝服务(DDoS/DoS)攻击、数据篡改与伪造攻击、物理与侧信道攻击、高级持续性威胁(APT)6类主要威胁为研究切入点,结合智能电网架构模型(SGAM)与典型攻击案例,分析了各类攻击的典型入口、影响层级及传统防御的技术难点与局限,发现攻击的直接来源大多集中于组件层与通信层,且攻击影响可跨层级传播。其次,依据核心功能定位,将可部署的内生安全技术划分为抗攻击类与可信认证类两大类:前者包括软件多样化、动态异构冗余(DHR)、基于物理不可克隆函数(PUF)的认证机制和抗攻击路由,后者包括零信任架构、可信计算与量子安全可信认证技术,并从作用机理、适用威胁、部署层级、性能开销和工程条件等维度,系统梳理了7类技术的研究进展、防御目标、作用层级与验证结果,总结了各类技术的适用条件与主要局限。研究结果表明:其一,单项内生安全技术通常只作用于攻击过程的局部环节,难以独立应对APT等复合攻击,多技术协同的关键在于按照攻击阶段明确技术分工,并共享身份、设备状态、异常输出、网络状态等信息,后续研究应以攻击链阻断率、误判率、最坏时延、恢复时间等指标评价协同效果;其二,现有技术方案多处于原型、仿真或小规模验证阶段,缺乏智能电网真实场景下的大规模部署验证,性能开销与实时性约束是技术落地的关键障碍;其三,供应链安全是内生安全技术可靠运行的基础,软件多样化依赖可信编译链,DHR依赖执行体来源,零信任和可信计算依赖准确的资产及固件信息,应形成从组件识别、完整性验证到异常处置的闭环;其四,人工智能(AI)可辅助内生安全检测与认证,但需兼顾识别能力与模型安全,评价时应同时报告检测性能、推理时延、资源占用与更新方式;其五,量子安全技术应按当前发展状况渐进迁移,后量子密码(PQC)可优先通过纯软件方案部署并建立密码敏捷机制,量子密钥分发(QKD)宜优先用于固定的高价值链路。

关键词: 智能电网, 内生安全, 网络威胁, 抗攻击技术, 可信认证

Abstract: The smart grid is a critical infrastructure in the modern energy system that couples cyberspace with physical operation processes, and it has become a key pillar of national energy security. With the widespread use of massive heterogeneous devices such as distributed energy resources, energy storage systems, and smart meters, the "cloud—network—edge—terminal" collaborative architecture has become the mainstream paradigm. However, the continuous evolution of attack techniques has led to increasingly frequent cyberattacks targeting Supervisory Control and Data Acquisition (SCADA) systems, intelligent terminals, and communication networks. The inherent lag of conventional ″patch-and-block″ passive defense techniques and their dependence on prior knowledge cause difficulty in effectively countering security threats deeply embedded in system architectures and operational processes. Endogenous security issues caused by inherent defects such as vulnerabilities and backdoors in information systems cannot easily be completely eliminated during the design and development phases; this creates a fundamental bottleneck that restricts the improvement of smart grid security protection capabilities. To address these issues, this paper systematically reviews endogenous security technologies that can be deployed in smart grids. First, the six major threats facing smart grids—supply-chain attacks, vulnerability exploit attacks, Distributed Denial of Service/Denial of Service (DDoS/DoS) attacks, data tampering and forgery attacks, physical and side-channel attacks, and Advanced Persistent Threats (APTs)—are considered as research entry points. Typical entry points, impact levels, and the technical difficulties and limitations of traditional defenses for each type of attack are analyzed, combined with the Smart Grid Architecture Model (SGAM) and typical attack cases. The analysis reveals that the direct sources of most attacks are concentrated at the component and communication layers, and that the attack impacts can propagate across layers. Second, according to core functional positioning, deployable endogenous security technologies are categorized into attack-resistant and trusted authentication technologies. Attack-resistant technologies include software diversification, Dynamic Heterogeneous Redundancy (DHR), Physical Unclonable Function (PUF)-based authentication mechanisms, and attack-resistant routing, while trusted authentication technologies include zero-trust architecture, trusted computing, and quantum-secure trusted authentication. This paper systematically reviews the research progress, defense objectives, operational layers, and verification results of these seven technologies based on their working mechanism, applicable threats, deployment layers, performance overhead, and engineering conditions. It also summarizes the applicable conditions and main limitations of each technology. The review reveals five key findings. First, a single endogenous security technology usually acts on only partial segments of an attack chain and cannot independently cope with composite attacks such as APTs. The key to multi-technology collaboration lies in clarifying the division of labor according to attack phases and the sharing of information such as identities, device statuses, abnormal outputs, and network statuses. Follow-up research should evaluate collaboration effectiveness using metrics such as attack chain blocking rate, false judgment rate, worst-case latency, and recovery time. Second, most existing technical solutions are still in the prototyping, simulation, or small-scale verification stages, and large-scale deployment verification has not been performed in real smart grid scenarios, where performance overhead and real-time constraints are key obstacles to technology implementation. Third, supply chain security is the foundation for the reliable operation of endogenous security technologies. Software diversification relies on a trusted compilation chain, while dynamic heterogeneous redundancy relies on trusted execution body sources, and zero-trust and trusted computing solutions rely on accurate asset and firmware information. Accordingly, a closed-loop process from component identification and integrity verification to anomaly response should be established. Fourth, Artificial Intelligence (AI) can assist endogenous security detection and authentication, but both recognition capability and model security must be considered. Evaluations should simultaneously report detection performance, inference latency, resource overhead, and update mechanisms. Fifth, quantum security technologies should be migrated progressively according to their current development status. Post-Quantum Cryptography (PQC) can be prioritized for deployment via pure software solutions with cryptographic agility mechanisms, while Quantum Key Distribution (QKD) can be used for priority application in fixed high-value links.

Key words: smart grid, endogenous security, cyber threats, attack-resistant technology, trusted authentication

中图分类号: