Design and Implementation of an Adaptive RBAC Model with Dynamic Permission Allocation for Industrial Control Systems in Smart Power Plants
DOI:
https://doi.org/10.66069/ojspub.26820706Keywords:
RBAC, Smart power plant, Dynamic permission configurationAbstract
Amidst escalating global energy demand and the accelerating deployment of renewable energy technologies, smart power plants have emerged as indispensable pillars of modern power systems, integrating distributed energy resources, advanced metering infrastructure, and real-time supervisory control and data acquisition (SCADA) networks. However, this digital transformation concurrently exposes these critical infrastructures to unprecedented cybersecurity vulnerabilities—including data tampering, unauthorized access, advanced persistent threats (APTs), and insider data breaches—which, if exploited, could trigger cascading failures or inflict substantial economic losses. Consequently, information security and permission management have become paramount concerns for plant operators and regulators alike. The conventional Role-Based Access Control (RBAC) model, while widely adopted for its stability and interpretability, exhibits inherent limitations in the dynamically evolving operational environment of smart power plants. Static role-to-permission mappings cannot adapt to fluctuating operational contexts, evolving user behaviors, or real-time risk postures—a shortcoming that grows increasingly critical as plants incorporate remote operations, multi-stakeholder coordination, and dynamic grid conditions. Recognizing this gap, researchers have pursued enhanced RBAC methodologies that decouple data logic control from business code, enabling the dynamic creation and modification of data logic during system runtime without service interruption. This approach, as demonstrated in practical implementations, effectively accommodates the fluid permission requirements inherent in smart power plant environments. Empirical validation of such dynamic frameworks is emerging across multiple domains: a 2024 study introduced a distributed smart power plant access control mechanism based on blockchain and ciphertext updatable functional encryption, leveraging decentralized, tamper-proof features to ensure data integrity and transparency while enabling fine-grained, dynamic authorization; experimental results confirmed that blockchain transaction latency remained under 5 milliseconds for typical operations, underscoring the practicality of such approaches for time-sensitive industrial control. Similarly, a context-aware framework integrating large language models with retrieval-augmented generation on an RBAC backbone has demonstrated the ability to infer implicit behavioral semantics from unstructured access logs, thereby refining authorization decisions beyond static policies. In substation automation, the combination of RBAC with mandatory access control has enabled hierarchical, sub-authorized access to IEC 61850 communications, substantially improving the controllability of remote equipment operations. Furthermore, a zero-trust security model for power plants and substations—comprising identity authentication, dynamic access control, and trust evaluation modules—has been proposed to address the complexity of modern communication networks, while attribute-based access control models integrated with variational autoencoders have achieved anomaly detection accuracies as high as 97.2% in power grid IoT terminal access management. The efficacy and feasibility of these enhanced, dynamically configurable permission management approaches are thus validated through their successful application in real-world smart power plant scenarios, offering a viable pathway toward securing critical energy infrastructure against evolving cyber threats while maintaining operational agility and regulatory compliance.
References
Wang Shudong. Safeguarding National Energy Security, Promoting Green and Low-Carbon Transformation, and High-Quality Assistance in Building Chinese-Style Modernization [N]. China Electric Power News, 2024-06-27 (001).
Wang Tao, Shan Zhengtao, Du Jingang, et al. Research and Development of an Intelligent Power Plant Production Management Development Platform [J]. Thermal Power Generation, 2019, 48(09):115-119. DOI: 10.19666/j.rlfd.201906129.
Zhao Jinsong, Zhang Chaoyang, Gu Weifeng, et al. Platform Architecture of Smart Power Plant Based on Industrial Internet [J]. Thermal Power Generation, 2019, 48(09): 101-107. DOI: 10.19666/j.rlfd.201906114.
Yu Yangkui. Research on Role-Based Access Control Model (RBAC) [J]. Computer Technology and Development, 2019, 29(01): 198-201.
Sun Hengyi. Design and Implementation of an Extended RBAC Permission Model for Power Trading Systems [J]. Network Security Technology and Application, 2018, (03): 42-43.
Hu Wenyu, Chen Jinbo. Research on Dynamic Access Control Model Oriented to Access Process [J]. Computer Technology and Development, 2022, 32(04): 92-96+108.