Trusted execution environment dynamic construction method and system for localized application operation

By collecting and verifying data in real time on domestic chemical industrial equipment and coupling it with multi-dimensionally with real-time operation parameter flow, a trusted execution environment is dynamically built, and the problems of low data credibility and insufficient security in complex operating environments of domestic chemical industrial equipment are solved, achieving high dynamic trustworthiness guarantees.

CN120185941AActive Publication Date: 2025-06-20CHINA COLOR BLUEPRINT TECH CO LTD

Patent Information

Application Number
CN202510659994.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-06-20
Estimated Expiration
2045-05-22

AI Technical Summary

Technical Problem

Domestic chemical industrial equipment has low data credibility and poor dynamic collaborative guarantee capabilities in complex operating environments.

Method used

The data collection is generated by collecting mechanical operation data in real time on domestic industrial equipment and irreversibly binding it with the equipment's unique identifier and timestamp. Then, the data collection is input into the blockchain network for segmentation processing and cross-verification to generate verification information. Couple verification information with real-time running parameter flows in multiple dimensions to dynamically build a trusted execution environment.

Benefits of technology

It realizes a comprehensive perception of the operating status of industrial equipment, ensures that the data source is traceable and tamper-free, improves verification reliability through the distributed node consensus mechanism, dynamically adjusts security policies to match the operating status of equipment, and meets the trustworthy guarantee requirements in high-dynamic industrial scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185941A_ABST
    Figure CN120185941A_ABST
Patent Text Reader

Abstract

The invention provides a trusted execution environment dynamic construction method and system for localized application operation, and the method comprises the steps: collecting mechanical data in real time during the operation of localized industrial equipment, carrying out the irreversible binding of the mechanical data with an equipment unique identifier and a timestamp to form a data set, and storing the data set in a database; after block chain network segmentation, cross validation is carried out among multiple nodes to generate verification information; performing multi-dimensional coupling on the verification information and the real-time operation parameter stream, and extracting associated characteristics of the equipment state and the data credibility; and dynamically constructing a trusted execution environment adaptive to the current security requirement in combination with domestic application operation data. According to the method, the dynamic collaborative guarantee capability of data credibility and execution environment security of the domestic industrial equipment in a complex operation environment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of industrial Internet of Things security technology, and in particular to a method and system for dynamically constructing a trusted execution environment for domestic applications to run. Background Art

[0002] During the operation of domestic industrial equipment, it is necessary to ensure that critical applications are executed in a trusted environment to prevent data tampering and malicious attacks. Due to the complex and ever-changing operating states of the equipment and the involvement of multi-source heterogeneous data interaction, traditional static security protection is difficult to meet the real-time trusted requirements in a dynamic environment. There is an urgent need for a method that can combine the real-time operating state of the equipment and automatically construct a trusted execution environment.

[0003] Currently, existing solutions adopt a static trusted execution environment construction technology based on hardware trusted modules. By presetting security policies at the device end and combining hardware encryption modules to perform fixed isolation on the operating environment. This solution relies on a predefined rule library and uses a hardware security chip to sign and verify key data to ensure the trustworthiness of the execution environment.

[0004] This solution cannot adapt to the dynamically changing operating states of domestic industrial equipment. The preset security policies are difficult to cover the real-time working condition adjustment requirements, and it has strong hardware dependence, making it difficult to achieve flexible trusted consensus among distributed nodes. In addition, the static isolation mechanism cannot effectively integrate real-time operation data, resulting in a disconnection between the environment construction and the actual security requirements, and it is difficult to meet the trusted guarantee requirements in a highly dynamic industrial scenario. Summary of the Invention

[0005] This application provides a method and system for dynamically constructing a trusted execution environment for domestic applications to run, aiming to solve the problems of low data trustworthiness and poor dynamic collaborative guarantee ability of the execution environment security of domestic industrial equipment in a complex operating environment in the prior art.

[0006] In a first aspect, this application provides a method for dynamically constructing a trusted execution environment for domestic applications to run, including: During the continuous operation cycle of domestic industrial equipment, collect mechanical operation data in real time; Irreversibly bind the mechanical operation data, the unique identifier of the domestic industrial equipment, and the collection timestamp to generate a data set; Input the data set into a preset blockchain network. The blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information; Perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics; According to the multi-dimensional coupling characteristics, combined with the domestic application operation data of domestic industrial equipment, a trusted execution environment is dynamically constructed.

[0007] Optionally, the inputting the data set into a preset blockchain network, the blockchain network performing segmentation processing on the data set to obtain a segmentation result, and performing cross-verification on the segmentation result among multiple independent nodes, and outputting verification information, includes: Inputting the data set into a preset blockchain network, and through a segmentation module of the blockchain network, segmenting the mechanical operation data in the data set into multiple data segments according to the continuous time stamp order; Through a distribution module of the blockchain network, respectively distributing each data segment to an independent node in the blockchain network, so that each independent node generates a verification identification code corresponding to the data segment; Combining the verification identification codes corresponding to all the data segments in the time order of the data segments to generate a global verification identification code sequence corresponding to the data set; In the blockchain network, according to the global verification identification code sequence, initiating a consistency confirmation request to the independent nodes assigned with the corresponding data segments, and when more than a preset number threshold of independent nodes confirm the verification identification codes of the same data segment to be consistent, generating verification information.

[0008] Optionally, the in the blockchain network, according to the global verification identification code sequence, initiating a consistency confirmation request to the independent nodes assigned with the corresponding data segments, and when more than a preset number threshold of independent nodes confirm the verification identification codes of the same data segment to be consistent, generating verification information, includes: In the blockchain network, establishing a verification task queue corresponding to the global verification identification code sequence, where each verification task corresponds to a data segment and includes the identification information of the corresponding data segment and a list of independent nodes; For each verification task in the verification task queue, sending a confirmation request to all independent nodes in the list of independent nodes corresponding to the verification task, the confirmation request including the verification identification code of the data segment to be confirmed; Receiving confirmation response information returned by each independent node in the list of independent nodes for the same data segment to be confirmed, the confirmation response information including an approval or rejection mark for the verification identification code of the data segment to be confirmed; According to the confirmation response information, counting the number of independent nodes that approve the verification identification code of the data segment to be confirmed; When the number exceeds a preset number threshold, marking the verification identification code of the data segment to be confirmed as an approved state; Recombine the verification identification codes of all data segments in the confirmed state in the original order in the global verification identification code sequence; Generate verification information based on the recombined verification identification code sequence.

[0009] Optionally, the multi-dimensional coupling of the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics includes: Extract a set of continuous period parameters matching the timestamp traceability chain of the verification information from the real-time operation parameter stream of the domestic industrial equipment; Divide the set of continuous period parameters and the verification information into multiple parameter association groups according to the equipment operation stage, and each parameter association group contains real-time operation parameters synchronized in time within the same equipment operation stage and the recombined verified identification codes; Perform multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling characteristics.

[0010] Optionally, the multi-dimensional coupling processing of each parameter association group to generate multi-dimensional coupling characteristics includes: Extract the dynamic change characteristics of the real-time operation parameters and calculate the credibility weight according to the confirmation status of the verified identification code; Superimpose the dynamic change characteristics and the credibility weight according to the preset weight relationship to generate a feature vector; Calculate the inter-stage transition probability and the parameter change gradient according to the enhanced feature vectors of adjacent parameter association groups, and construct an inter-stage continuity association matrix; Combine the feature vectors of all parameter association groups and the inter-stage continuity association matrix to generate multi-dimensional coupling characteristics.

[0011] Optionally, the step of allocating each data segment to an independent node in the blockchain network so that each independent node generates a verification identification code corresponding to the data segment includes: Allocate multiple data segments to different independent nodes in the blockchain network; Based on each independent node's verification of the allocated data segment, verify the consistency of the device unique identifier of the data segment and the continuity of the timestamp interval of the data segment; Generate a verification identification code when both the consistency and the continuity are verified.

[0012] Optionally, the step of dynamically constructing a trusted execution environment according to the multi-dimensional coupling characteristics in combination with the domestic application operation data of the domestic industrial equipment includes: Based on the multi-dimensional coupling characteristics, determine the environmental security level requirements corresponding to the current equipment operation stage; Establish a trusted execution environment configuration template that matches the environmental security level requirements according to the device function module call relationship recorded in the domestic application operation data; Adapt the trusted execution environment configuration template to the real-time operation parameters to generate an environment construction instruction set; Execute the environment construction instruction set at the hardware layer of the domestic industrial device to construct a trusted execution environment.

[0013] In a second aspect, the present application provides a system for dynamically constructing a trusted execution environment for domestic application operation, including: An acquisition module, configured to acquire mechanical operation data in real time during the continuous operation cycle of the domestic industrial device; A generation module, configured to irreversibly bind the mechanical operation data, the unique identifier of the domestic industrial device, and the acquisition timestamp to generate a data set; An input module, configured to input the data set into a preset blockchain network, and the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information; A coupling module, configured to perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domestic industrial device to obtain multi-dimensional coupling features; A construction module, configured to dynamically construct a trusted execution environment according to the multi-dimensional coupling features, in combination with the domestic application operation data of the domestic industrial device.

[0014] In a third aspect, the present application provides a computing device, including a processor and a memory, where a computer program is stored in the memory, and the processor is configured to run the computer program to execute the method for dynamically constructing a trusted execution environment for domestic application operation according to any one of the first aspects.

[0015] In a fourth aspect, the present application provides a computer storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the method for dynamically constructing a trusted execution environment for domestic application operation according to any one of the first aspects is implemented.

[0016] In this application, a method for dynamically constructing a trusted execution environment for domestic application operation is provided. The method includes: during the continuous operation cycle of domestic industrial equipment, collecting mechanical operation data in real time; irreversibly binding the mechanical operation data, the unique identifier of the domestic industrial equipment, and the collection timestamp to generate a data set; inputting the data set into a preset blockchain network, where the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information; performing multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features; and dynamically constructing a trusted execution environment according to the multi-dimensional coupling features in combination with the domestic application operation data of the domestic industrial equipment.

[0017] The technical solution provided by this application has the following beneficial effects: This application realizes the comprehensive perception of the operation state of industrial equipment and provides an original data basis for the construction of a trusted environment. By binding the device identifier and timestamp, it ensures that the data source is traceable and tamper-proof, and establishes a trusted data basis. The use of a distributed node consensus mechanism realizes the verification of data authenticity, solves the single-point trust problem, and improves the reliability of verification. Deeply correlates the verified trusted data with the real-time operation parameters to form a feature expression reflecting the true state of the device. Based on the real-time state features, the security policy is adaptively adjusted to achieve an accurate match between the environment and the device operation state.

[0018] Furthermore, this application also divides the mechanical operation data into continuous data segments according to the timestamp through the blockchain network, distributes them to different independent nodes to generate verification identification codes, initiates multi-node consistency confirmation after global sequence recombination, and outputs verification information when a preset threshold is reached. This process realizes the segmented verification and distributed consensus of data.

[0019] Moreover, through data sharding verification and cross-node consensus mechanism, this solution realizes high-reliability authentication of large-scale industrial data while ensuring verification efficiency. It not only avoids the performance bottleneck of single-node verification but also ensures the tamper-proof nature of the verification result through multi-node cross-checking, providing a trusted data basis for subsequent dynamic environment construction.

[0020] These aspects or other aspects of this application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0022] Figure 1 It is a flowchart of a method for dynamically constructing a trusted execution environment for domestic application operation provided by an embodiment of the present application; Figure 2 It is a schematic structural diagram of a system for dynamically constructing a trusted execution environment for domestic application operation provided by an embodiment of the present application; Figure 3 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners

[0023] To enable those skilled in the art to better understand the solution of the present application, the following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application.

[0024] In some processes described in the specification, claims and the above accompanying drawings of the present application, multiple operations appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear herein or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.

[0025] Researchers have found that current domestic industrial equipment has problems such as insufficient verification of data credibility and static rigidity of the execution environment during operation, and it is difficult to meet the dynamic security requirements under complex working conditions. Based on this, a method for dynamically constructing a trusted execution environment for domestic application operation is provided. After irreversibly binding the device operation data with spatio-temporal information, the method uses a blockchain network to achieve distributed verification, and deeply couples the verification results with real-time parameters, and finally constructs a trusted execution environment that adapts to the device operation state. The technical solution of the present application is applicable to scenarios such as health monitoring of domestic industrial equipment and intelligent manufacturing that require high-dynamic trusted guarantee.

[0026] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0027] Figure 1 It is a flowchart of a method for dynamically constructing a trusted execution environment for domestic application operation provided by an embodiment of the present application. As Figure 1 shown, the method includes: Step 101: During the continuous operation cycle of the domestic industrial equipment, collect mechanical operation data in real time.

[0028] In this step, the domestic industrial equipment refers to industrial production equipment manufactured using domestic independent technologies. The continuous operation cycle represents the complete working process of the equipment from startup to shutdown. The mechanical operation data represents physical parameters such as vibration, temperature, and rotational speed generated during the operation of the equipment. It is the mechanical motion data of the domestic industrial equipment.

[0029] In the embodiments of the present application, various mechanical parameter data during the operation of the equipment are collected in real time through domestic sensors installed on the equipment. The collection process covers the entire working cycle of the equipment to ensure the continuity and integrity of the data. The sensors obtain data according to the preset sampling frequency and temporarily store the original data in the local buffer for subsequent processing. The types of collected data include but are not limited to key operation indicators such as vibration amplitude, bearing temperature, and motor rotational speed.

[0030] For example, taking a domestic numerical control machine tool as an example, during the processing, the vibration sensor and temperature sensor installed on the spindle collect the spindle vibration data and bearing temperature data once per second. These data, together with the time stamp of the collection moment, are recorded and transmitted to the data processing unit. For example, at exactly 8 am, the spindle vibration data is X units and the bearing temperature is Y degrees. These data are marked as the mechanical operation data at the same moment.

[0031] Step 102: Irreversibly bind the mechanical operation data, the unique identifier of the domestic industrial equipment, and the collection timestamp to generate a data set.

[0032] In this step, irreversible binding means an unmodifiable data association implemented by cryptographic methods. The data set represents a structured data combination.

[0033] In the embodiments of the present application, the collected mechanical operation data is bound with the unique identity code burned at the time of equipment factory and the timestamp information accurate to the millisecond level through a hash algorithm to generate a structured data packet with the characteristic of being tamper-proof. During the processing, the original data is first standardized and formatted, and then it is input into a hash function operation together with the device identifier and the timestamp. Finally, a data digest with a fixed length is output to form a complete data set.

[0034] For example, continuing with the previous example, the vibration data X and temperature data Y of the numerically controlled machine tool, together with the unique machine number Z and the acquisition time 8:00:00.000, are subjected to a hash operation to generate a 64-bit hexadecimal string as the data digest. This digest and the original data together form a complete data set unit. For example, if the data digest is A1B2C3..., a data packet containing the original data and the digest is formed.

[0035] Step 103: Input the data set into a preset blockchain network. The blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information.

[0036] In this step, the blockchain network refers to a distributed verification system composed of multiple domestic independent nodes. Each node performs parallel verification on the segmented data segments through a consensus mechanism to ensure that the verification process is decentralized and tamper-proof. This network uses domestic encryption algorithms to achieve secure communication between nodes. Each node independently stores the complete verification records of the data segments, and ensures the credibility of the output verification information through cross-node consistency confirmation. The segmentation processing means decomposing a large data set into multiple small units that can be processed in parallel. The cross-verification means that multiple verification parties independently verify the same data. The verification information is information regarding the authenticity and chronological integrity of the data, which is used to prove that the source of the mechanical operation data is credible and has not been tampered with, and at the same time ensure that the data acquisition timestamps are continuous and conflict-free.

[0037] In the embodiments of the present application, the data set is sliced into several consecutive data segments in chronological order, and each data segment contains the data set within a fixed time duration. These data segments are distributed to different verification nodes in the blockchain network, and each node independently performs integrity verification on the received data segment, including verifying the hash value match, timestamp continuity, etc. After each node completes the verification, it generates a verification result with a digital signature. When a sufficient number of nodes pass the verification of the same data segment, the data segment is regarded as valid.

[0038] For example, all the data sets generated by the numerical control machine tool during 8:00 - 8:05 in the morning are packed into a data segment and assigned to three independent nodes in the blockchain network for verification. Node 1 verifies that the hash values of 30 data packets during this period are all correct and the timestamps are continuous; Nodes 2 and 3 also come to the same conclusion. When two of the three nodes confirm that the data is valid, the system generates the verification information for this period, including the time range and data characteristics for which the verification has passed.

[0039] Step 104: Perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics.

[0040] In this step, the real-time operation parameter stream represents the operation state data of the equipment at the current moment. Multi-dimensional coupling means the deep fusion of multiple data characteristics. The multi-dimensional coupling characteristics are composite feature vectors generated by fusing the credibility index in the verification information and the state index in the real-time operation parameters, which contain both the quantization values of the current physical states such as vibration and temperature of the equipment and integrate the data credibility scores generated in the blockchain verification link, and form a unified feature expression that can reflect both the actual operation of the equipment and the data reliability through weighted association.

[0041] In the embodiment of the present application, feature-level fusion processing is performed on the output verification information and the real-time sensor data stream of the equipment. First, the two types of data are aligned in time, and then the credibility features in the verification information and the state features in the real-time data are extracted, and a composite feature vector that can reflect both the actual state of the equipment and include credibility evaluation is generated through the feature weighted fusion algorithm. This process ensures that the output features include both real-time performance and credible guarantee.

[0042] For example, the vibration data of the numerical control machine tool at the current moment (8:06) is X', which is compared with the data characteristics verified in Step 103 during 8:00 - 8:05. The system calculates the deviation degree between the current vibration data and the verified data characteristics, and combines credibility indicators such as the number of verification nodes to generate a two-dimensional feature vector including the state value and credibility. For example, the feature vector is (0.85, 0.92), indicating normal state and high data credibility.

[0043] Step 105: Dynamically construct a trusted execution environment according to the multi-dimensional coupling characteristics, in combination with the domestic application operation data of the domestic industrial equipment.

[0044] In this step, the domestic application operation data refers to the real-time operation logs and status records generated by domestic control software, monitoring systems, etc. running on industrial equipment, including runtime information such as program call sequences and resource occupancy. These data, together with the device hardware status characteristics, serve as the basis for formulating policies for dynamically constructing a trusted execution environment, ensuring that the environment configuration precisely matches the actual needs of the domestic application. The trusted execution environment represents a secure operating space.

[0045] In the embodiment of this application, based on the generated multi-dimensional coupling features, the system dynamically evaluates the current required security protection level. According to the values of each dimension in the feature vector, a matching configuration scheme is selected from a predefined security policy library, including parameters such as memory isolation intensity and data encryption level. Then, the security instruction set at the device bottom layer is called to dynamically construct a trusted execution environment that matches the current device operating state.

[0046] For example, when the feature vector of a numerically controlled machine tool shows a status value of 0.85 (normal range 0.8 - 1.2) and a credibility of 0.92 (high credibility threshold 0.9), the system selects a medium security protection policy: enable memory isolation while maintaining high computing performance. The specific implementation is as follows: divide a dedicated memory area to run the machining program, and at the same time maintain the normal communication bandwidth with the sensor data channel.

[0047] This method realizes the dynamic trusted guarantee of the operating environment of domestic industrial equipment through the complete closed-loop processing from data collection to environment construction. It ensures the authenticity of data from the source, improves the credibility through distributed verification, and finally constructs a secure execution environment that precisely matches the real-time state of the device. The entire process requires no manual intervention, ensuring both security and operation efficiency, and is particularly suitable for industrial manufacturing scenarios with high requirements for both real-time and credibility.

[0048] To solve the integrity and credibility problems of industrial equipment data during the distributed verification process, in some embodiments, step 103: input the data set into a preset blockchain network, and the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information, including: Step 201: Input the data set into a preset blockchain network, and through the segmentation module of the blockchain network, segment the mechanical operation data in the data set into multiple data segments in the order of continuous timestamps.

[0049] In step 201, a data segment refers to a mechanical operation data unit divided according to time continuity, where each data segment contains continuous mechanical operation data associated with the unique identifier of the same device and the corresponding timestamp interval.

[0050] In the embodiment of the present application, the segmentation module of the blockchain network adopts the time-sliding window technology. Based on the device sampling period, the data set with continuous timestamps is segmented into several data segments of equal length. A segment identifier and start and end time marks are added to the head of each data segment to form an independently verifiable data unit.

[0051] Step 202: Through the distribution module of the blockchain network, each of the data segments is respectively distributed to an independent node in the blockchain network, so that each independent node generates a verification identification code corresponding to the data segment.

[0052] In step 202, the verification identification code is an anti-counterfeiting verification label generated by an independent node, and includes the data segment hash value, the node digital signature, and the verification timestamp.

[0053] In the embodiment of the present application, the distribution module adopts the round-robin scheduling algorithm to evenly distribute each data segment to the independent nodes in the network. After each node receives the data segment, it first verifies the continuity of the timestamp, then calculates the hash value of the data segment content, and finally signs the "hash value + timestamp" with the node private key to generate a unique verification identification code.

[0054] Step 203: Combine the verification identification codes corresponding to all the data segments in the time order of the data segments to generate a global verification identification code sequence corresponding to the data set.

[0055] In step 203, the global verification identification code sequence is a chained structure of verification identification codes arranged in time order, and each position corresponds to a specific time period in the original data set.

[0056] In the embodiment of the present application, after the system collects the verification identification codes returned by all nodes, it reorders them according to the start time of the data segments, and ensures the time continuity of the sequence by comparing the end time and start time of the front and back data segments. Finally, an identification code chain covering the complete time period is generated.

[0057] Step 204: In the blockchain network, according to the global verification identification code sequence, initiate a consistency confirmation request to the independent node that distributes the corresponding data segment. When more than a preset number threshold of independent nodes confirm the verification identification code of the same data segment to be consistent, verification information is generated.

[0058] In step 204, the preset number threshold refers to the minimum number of consensus nodes required to determine the data to be valid in the blockchain network, and is usually set to more than two-thirds of the total number of nodes.

[0059] In the embodiment of the present application, the network broadcasts a global sequence to each node participating in the verification, requiring the node to reconfirm the data segment identification code that it has verified. The node checks the validity of the digital signature of the identification code and the timestamp logic and returns the confirmation result. When the number of confirmations for a data segment reaches the threshold, the system generates a final verification report containing all verification information for that period.

[0060] Here is a specific example: Based on the case of CNC machine tools, the 30 data packets generated between 8:00 and 8:05 (6 per minute, each containing vibration data X, temperature data Y, machine tool number Z and timestamp) are divided into 5 data segments, each corresponding to 6 data packets within 1 minute. The allocation module of the blockchain network sends these 5 data segments to 3 independent verification nodes (nodes A, B, and C), where node A receives the 1st and 4th minute segments, node B receives the 2nd and 5th minute segments, and node C receives the 3rd minute segment. Each node verifies each received data segment: first check whether the timestamps of the 6 data packets are continuous (such as 8:00:00.000 to 8:00:59.999), then recalculate the hash value of each data packet and compare it with the original summary. After all pass, a verification identification code is generated (such as node A generates a verification identification code M1 for the 1st minute segment, including the node digital signature). The system combines the identification codes of the five time periods into a global sequence [M1, M2, M3, M4, M5] in chronological order, and initiates a confirmation request to each node. For example, for the first minute, nodes A and C (although not verified but with copies stored) are confirmed. When two nodes (more than half of the threshold of three nodes) return consistent confirmation, the verification of the time period is passed. The verification information finally generated includes: the validity status of each minute segment (such as "verified" in the first minute), characteristic statistics (such as vibration average value 0.85=ΣX / 6, temperature range 1.2=Ymax-Ymin) and the number of nodes participating in the verification.

[0061] In the embodiment of this application, the solution not only ensures the efficiency of large-scale industrial data verification through time-series data segmentation and distributed consensus verification, but also ensures data authenticity through multi-node cross-verification, providing a reliable data foundation guarantee for the dynamic trusted execution environment. The entire process does not need to rely on specific hardware and is fully adapted to the application scenario requirements of domestic industrial equipment.

[0062] In order to solve the coordination and efficiency problems of multi-node verification in the blockchain network, in some embodiments, step 204: in the blockchain network, according to the global verification identification code sequence, a consistency confirmation request is initiated to the independent node assigned the corresponding data segment, and when more than a preset number of independent nodes confirm that the verification identification code of the same data segment is consistent, verification information is generated, including: Step 301: In the blockchain network, establish a verification task queue corresponding to the global verification identification code sequence, where each verification task corresponds to a data segment and includes the identification information of the corresponding data segment and a list of independent nodes.

[0063] In Step 301, the verification task queue is a first-in-first-out list storing tasks of data segments to be verified. Each task includes the data segment number, time range, and a list of node IDs responsible for verification. Exemplarily, node A generates the identification code H1 of data segment 1. After nodes B and C receive the confirmation request, they need to calculate the hash value H1' of data segment 1 by themselves and compare it with H1. If H1' = H1, the identification code is recognized.

[0064] In the embodiment of the present application, the system parses the global verification identification code sequence, creates a verification task for each data segment, and records the position index of the data segment in the original sequence, the number of verification identification codes included (such as 6 per minute), and the node information that has participated in verification (such as nodes A and B) in the task. The queue is arranged in the time order of the data segments to ensure the timeliness of verification.

[0065] Step 302: For each verification task in the verification task queue, send a confirmation request to all independent nodes in the list of independent nodes corresponding to the verification task. The confirmation request includes the verification identification code of the data segment to be confirmed.

[0066] In Step 302, the confirmation request is an instruction message triggering the node to perform secondary verification. The data segment to be confirmed refers to each segmented data segment as the data segment to be confirmed.

[0067] In the embodiment of the present application, the network controller takes out the task from the head of the queue and sends a request message to each verified node on record. The message is signed using the domestic encryption algorithm SM2, and the content includes the ciphertext form of all verification identification codes of the data segment (such as M1 generated by node A, M1' generated by node C), and the system time when the request is initiated. Each node verifies the validity of the signature first after receiving it.

[0068] Step 303: Receive the confirmation response information returned by each independent node in the list of independent nodes for the same data segment to be confirmed. The confirmation response information includes an approval or rejection mark for the verification identification code of the data segment to be confirmed.

[0069] In Step 303, the confirmation response information is a simple reply returned by the node, including a binary judgment result (approval / rejection) and a response timestamp.

[0070] In the embodiments of the present application, after each node receives a request, it re-verifies the matching of the original data segment stored locally with the verification identification code (such as recalculating the hash), and checks whether the timestamp is within the valid window (such as ±5 seconds). After passing the verification, an approval mark (value 1) is generated, otherwise a rejection mark (value 0) is generated, and after appending the current time, it is signed with the node's private key and returned.

[0071] Step 304: According to the confirmation response information, count the number of independent nodes that approve the verification identification code of the data segment to be confirmed.

[0072] In step 304, the approval count is a process of summing up the response results of all nodes for a specific data segment.

[0073] In the embodiments of the present application, the system collects all node responses within a preset timeout period (such as 10 seconds), first verifies the digital signature of each response, and then accumulates the approval mark values. For example, if responses from node A (1), node B (1), and node C (0) are received, the approval count is 2. The statistical result is compared with the threshold required for this data segment (such as a 2 / 3 majority).

[0074] Step 305: When the number exceeds the preset quantity threshold, mark the verification identification code of the data segment to be confirmed as the confirmed state.

[0075] In step 305, the confirmed state is the marked state after the data segment passes the verification, including metadata such as the passing time and the number of participating nodes.

[0076] In the embodiments of the present application, when the approval count of a certain data segment reaches the threshold (such as 2 approvals out of 3 nodes), the system attaches a status mark to its verification identification code, and records the passing moment and the list of node IDs participating in the verification. Data segments that do not reach the threshold are marked as pending review status, triggering subsequent processing procedures.

[0077] Step 306: Reorganize the verification identification codes of all data segments in the confirmed state according to their original order in the global verification identification code sequence.

[0078] In step 306, the reorganization operation is a process of rearranging the data segments that have passed the decentralized verification according to the timeline.

[0079] In the embodiments of the present application, the system scans all data segments marked as the confirmed state and reconnects them in their original time order (such as 8:00, 8:01, 8:02...). For missing time periods (such as data segments that are not confirmed due to some nodes not responding), a supplementary verification process is automatically initiated to ensure the time continuity of the final sequence.

[0080] Step 307: Generate verification information based on the reorganized verification identification code sequence.

[0081] In the embodiment of the present application, the system generates a structured report based on the recombined sequence, including: verification status of each period (such as verified from 8:00 to 8:04), data characteristic values (such as vibration average value 0.85), number of participating nodes (such as 2 out of 3 nodes passed), etc. The report is encapsulated in a format and signed with a network root certificate to ensure integrity.

[0082] The following is a specific example: Based on the data verification scenario of the numerical control machine from 8:00 to 8:05, the system first establishes a queue containing 5 verification tasks (corresponding to 1 data segment per minute). Taking the 8:00 period as an example, this verification task records the data segment number DS001, time range 8:00:00.000 - 8:00:59.999, and the list of nodes that participated in the verification of this segment [Node A, Node C]. The system sends a confirmation request to these two nodes, and the request contains the verification identification code M1 generated by Node A before (calculated from the vibration data average value 0.85 = (0.84 + 0.86 + 0.83 + 0.87 + 0.85 + 0.85) / 6) and the temperature range difference 1.2 = 46.3 - 45.1. After receiving the request, Node A rechecks the 6 original data packets stored locally, confirms that the timestamps are continuous and the hash values match (such as the hash value of the first data packet at 8:00:00.000 is still A1B2C3...), and then returns an approval mark; although Node C did not participate in the initial verification, it also returns an approval after completing the same verification through the stored copy. The system receives 2 approval responses within 10 seconds (the preset threshold is 2), and then marks DS001 as the confirmed state, recording the passing time as 8:05:30.500. After processing the verification tasks of 5 periods in sequence, the system recombines the verification identification codes in the order of [DS001, DS002, DS003, DS004, DS005], and the generated final verification information includes: status of each period (such as DS003 initially had only 1 approval due to Node B being down, and passed after supplementary verification at 8:06:15.200), vibration characteristic value (overall average value of 5 minutes 0.86 = (0.85×1 + 0.87×1 + 0.84×1 + 0.88×1 + 0.86×1) / 5), and node participation situation (a total of 3 nodes were used to complete the verification).

[0083] In the embodiment of the present application, this solution ensures the rigor of the verification process through task queue management and multi-round node confirmation mechanism, and can automatically handle node anomalies. Finally, it outputs a verification report with time continuity and complete credibility assessment, providing accurate data authenticity guarantee for the construction of the dynamic environment of industrial equipment.

[0084] To solve the problem of the integration of real-time data of industrial equipment and blockchain verification results, in some embodiments, step 104: The multi-dimensional coupling of the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features includes: Step 401: Extract a set of continuous period parameters matching the timestamp traceability chain of the verification information from the real-time operation parameter stream of the domestic industrial equipment.

[0085] In step 401, the timestamp interval of the global verification identification code sequence in the verification information; the timestamp interval is defined by the start point and end point of the timestamp of each data segment after being segmented by the blockchain network. Continuous means an uninterrupted and complete period that exactly matches the timestamp traceability chain in the verification information. Specific example: If the timestamp traceability chain of the verification information is [T1, T2, T3] (continuous from T1 to T2 to T3), then [T1 data, T2 data, T3 data] is extracted from the real-time parameter stream as the set of continuous period parameters, and the requirements are: the middle period cannot be missing (such as only extracting T1 and T3); the period interval needs to be equal to the device sampling period (for example, if it is collected once every 1 second, then T2 = T1 + 1 second). The set of continuous period parameters is a data segment intercepted from the real-time data stream and aligned with the verified period, containing a sequence of sensor readings with the same time span.

[0086] In the embodiments of the present application, the system extracts the parameter sequence of the corresponding period from the real-time data buffer according to the time range recorded in the verification information (such as 8:00 - 8:05). When extracting, the sliding window matching algorithm is used to ensure that the timestamps are completely aligned (for example, the data corresponding to 8:00:30.000 in the verification information must match the data with the same timestamp in the real-time stream), and linear interpolation is automatically performed to complete the missing data.

[0087] Step 402: Divide the set of continuous period parameters and the verification information into multiple parameter association groups according to the equipment operation stage, and each parameter association group contains real-time operation parameters synchronized in time within the same equipment operation stage and the recombined verified identification codes.

[0088] In step 402, in the scenario of health monitoring of domestic industrial equipment, the equipment operation stage includes the start-up stage, the stable operation stage, the load fluctuation stage, and the shutdown transition stage. The parameter association group is a data unit divided according to the equipment working state, containing the paired combination of verified data features and real-time parameters. The verified identification code is the state of the verification identification code after node consistency confirmation (that is, after being recognized by more than a preset number of independent nodes), and it is a verified and effective verification identification code.

[0089] In the embodiment of the present application, the system first identifies the device operation stage (such as startup, processing, idle), and then classifies and pairs the statistical values of each time period in the verification information (such as the average vibration per minute) with the real-time parameters according to the stage. Strict time synchronization is ensured within each group (for example, the average value of 0.87 at 8:01 in the verification is paired with 6 original readings in the real-time stream at 8:01), and the belonging operation stage is marked (such as "processing stage").

[0090] Step 403: Perform multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features.

[0091] In step 403, the multi-dimensional coupling processing is an analysis process of generating a composite index through feature weighted fusion.

[0092] In the embodiment of the present application, for each parameter association group, execute: calculate the deviation degree between the real-time parameter and the verification benchmark (such as the difference of 0.01 between the real-time vibration value of 0.88 at 8:01 and the verification average value of 0.87); calculate the weight coefficient (0.01×0.67 = 0.0067) in combination with the verification credibility (such as 2 / 3 nodes passing at this time period); generate a three-dimensional feature vector including the original value, deviation degree, and credibility. The vectors of all groups are arranged in chronological order to form the final feature matrix.

[0093] The following is a specific example: Based on the verification information of the CNC machine tool from 8:00 to 8:05 (including the average vibration per minute [0.85, 0.86, 0.84, 0.87, 0.85] and the temperature range [1.1, 1.2, 1.0, 1.3, 1.1]), the system first extracts the vibration and temperature data for 5 minutes starting from 8:06:00 from the real-time data stream (6 samples per minute, a total of 30 data points). After dividing these real-time parameters by minute, they are matched with the corresponding period average values in the verification information: for example, the real-time vibration data [0.83, 0.84, 0.85, 0.84, 0.86, 0.85] at 8:02 is compared with the verification average value of 0.84, and the current minute vibration average value 0.845 = (0.83 + 0.84 + 0.85 + 0.84 + 0.86 + 0.85) / 6 is calculated, and its deviation degree from the verification value is |0.845 - 0.84| / 0.84 = 0.006; at the same time, according to the number of verified passing nodes of 2 (a total of 3 nodes) in this time period, the credibility weight 0.67 = 2 / 3 is calculated. Finally, a multi-dimensional feature vector for this minute segment is generated (vibration average value 0.845, deviation degree 0.006, credibility 0.67). The feature vectors of the 5 time periods are combined in the order of [8:02, 8:03, 8:04, 8:05, 8:06], and the overall trend index such as the vibration change rate of 0.01 = (the current 8:06 average value of 0.85 - the earliest 8:02 average value of 0.845) / 4 is calculated to form a complete set of coupling features for environmental construction decision-making.

[0094] In the embodiments of the present application, this solution realizes multi-level feature fusion of the real-time state of the device and the blockchain verification result through spatio-temporal alignment data association and dynamic weighted fusion, which not only retains the detailed features of the original data but also integrates the credibility information of distributed verification, providing a decision-making basis that takes into account both accuracy and reliability for subsequent dynamic environment construction.

[0095] To solve the problem of the accuracy of multi-source data fusion of industrial devices, in some embodiments, step 403: performing multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features, including: Step 501: Extract the dynamic change features of the real-time operation parameters, and calculate the credibility weight according to the confirmation status of the verified identification code.

[0096] In step 501, the dynamic change feature is a quantization index reflecting the parameter fluctuation law, including statistics such as mean, variance, and range. The confirmed status refers to passing the node consistency verification by more than a preset number threshold. The unconfirmed status refers to not passing the threshold verification. The credibility weight is a confidence coefficient calculated according to the verification node ratio and the degree of consistency.

[0097] In the embodiments of the present application, the system calculates the third-order statistical features of the real-time operation parameters within each parameter association group: sliding mean (taking a 10-second window); sum of absolute differences of adjacent samples (fluctuation intensity); difference between peak and valley (dynamic range). At the same time, according to the number of node confirmations recorded in the verified identification code during this period (such as 2 confirmations out of 3 nodes), calculate the adjusted credibility coefficient according to the formula: weight = number of confirmations / total number of nodes × 0.8 + 0.2 (basic credibility).

[0098] Step 502: Superimpose the dynamic change features and the credibility weight according to a preset weight relationship to generate a feature vector.

[0099] In step 502, the feature vector is a composite data structure that fuses the original features and credibility, and there is a preset weighting relationship between each dimension.

[0100] In the embodiments of the present application, the dynamic weighting method is used for fusion: multiply the vibration-related features (mean, fluctuation intensity) by the credibility weight; multiply the temperature-related features (mean, dynamic range) by the square of the weight (highlighting highly credible data); splice the processed feature values to form a 6D vector (vibration processed value × 2, temperature processed value × 2, original weight, timestamp encoding).

[0101] Step 503: Calculate the inter-stage transition probability and parameter change gradient according to the enhanced feature vectors of adjacent parameter association groups, and construct an inter-stage continuity association matrix.

[0102] In step 503, the inter-stage transition probability is a quantitative index that quantifies the likelihood of a domestic industrial device switching from one operating stage (such as "start-up") to another stage (such as "processing"). Its calculation is based on the statistical frequency of stage transitions in historical operation data. Specifically, the system analyzes the operation stage markers of adjacent parameter correlation groups (such as stage codes 1 to 2), and calculates the proportion of the number of occurrences of a specific transition (such as "start-up to processing") in the total number of transitions starting from the "start-up" stage. For example, if the number of times the device transitions from "start-up" to "processing" in the historical data accounts for 80% of the total number of "start-up" times, the corresponding transition probability is recorded as 0.8. This probability is used to predict the evolution trend of the device operation state and provide a forward-looking basis for constructing a dynamic environment. The parameter change gradient is a directional index that describes the change rate of key operating parameters (such as vibration and temperature) between adjacent stages, reflecting the severity of the device state change. Its calculation method is: the change amount of the mean value of the same parameter (such as vibration value) between two stages divided by the stage time interval (unit: minute). For example, if the vibration mean value in the "start-up" stage is 0.5 and rises to 0.8 after transitioning to "processing", and it takes 2 minutes, then the gradient is (0.8 - 0.5) / 2 = 0.15 / minute. The gradient value can be positive or negative. A positive gradient indicates an upward trend of the parameter (such as the temperature gradually increasing), while a negative gradient indicates a downward trend (such as the rotational speed decreasing). This index is used to quantitatively evaluate the stability of the device state change and provide a quantitative basis for adjusting the environmental safety strategy. The cross-stage continuity correlation matrix is a transfer relationship table that describes the parameter evolution law between different operating stages.

[0103] In the embodiment of the present application, the system analyzes the difference in eigenvectors of adjacent parameter correlation groups in chronological order: calculates the vibration mean change rate = (post-group mean - pre-group mean) / time interval; statistically analyzes the temperature fluctuation correlation (covariance divided by the product of the standard deviations of the two groups); records the stage transition markers (such as "processing to idle"). Finally, a matrix containing 16 possible transition states is generated, and each element stores the probability and typical parameter gradient of the corresponding transition.

[0104] Step 504: Combine the eigenvectors of all parameter correlation groups and the cross-stage continuity correlation matrix to generate multi-dimensional coupled features.

[0105] In the embodiment of the present application, the 6-dimensional eigenvectors of each time period are arranged in chronological order to form an eigenmatrix, and at the same time, a compressed representation of the correlation matrix (taking the first 3 principal components) is added to the head of the matrix. Finally, a coupled feature package containing N×6 + 3 dimensions is generated, where N is the number of parameter correlation groups.

[0106] The following is a specific example: Based on 5 parameter correlation groups (1 group per minute) during the period from 8:02 to 8:06 on the CNC machine tool, the system first processes the group at 8:03: extracts the real-time vibration data [0.84, 0.85, 0.86, 0.85, 0.87, 0.86] to calculate dynamic features. Among them, the sliding mean 0.855 = (0.84 + 0.85 + 0.86 + 0.85 + 0.87 + 0.86) / 6, and the fluctuation intensity 0.03 = (|0.85 - 0.84| + |0.86 - 0.85| +...) / 5; combines the verification information (2 / 3 nodes passed) during this period to calculate the credibility weight 0.67 = 2 ÷ 3 × 0.8 + 0.2 (basic value), and generates the feature vector of the group at 8:03 [0.855 × 0.67, 0.03 × 0.67, 46.2 × 0.67², 1.2 × 0.67², 0.67, 3] (the temperature value 46.2 and the range 1.2 are from real-time data). Then analyzes the stage transition from 8:03 to 8:04: the vibration change rate (0.86 - 0.855) / 1 = 0.005 / minute (the mean value 0.86 at 8:04 is calculated from real-time data), the temperature correlation 0.92 (obtained by calculating covariance), and updates the statistical value of the "processing → processing" item in the association matrix (the historical probability 0.9 is superimposed with the current change rate of 0.005). Finally, combines the feature vectors of the 5 groups with the principal components [0.88, 0.09, 0.03] of the association matrix (obtained by matrix eigenvalue decomposition) to form a multi-dimensional coupling feature set including features such as vibration trend (rising by 0.02 in 5 minutes) and temperature stability (range fluctuation < 0.2) for use by the environment construction module.

[0107] In the embodiment of the present application, this solution realizes the refined characterization of the equipment operation state through dynamic weight adjustment and cross-stage association analysis, not only retains the detailed features of real-time parameters, but also improves the reliability of feature expression through credibility weighting and transfer law mining, providing a decision-making basis with both timeliness and accuracy for subsequent environment construction.

[0108] To solve the problem of efficient allocation of data verification tasks in the blockchain network, in some embodiments, step 202: the step of respectively allocating each of the data segments to an independent node in the blockchain network so that each of the independent nodes generates a verification identification code corresponding to the data segment includes: Step 601: Allocate multiple data segments to different independent nodes in the blockchain network.

[0109] In step 601, the data segment allocation refers to the process of distributing the cut data units to different verification nodes according to a preset strategy.

[0110] In the embodiment of the present application, the scheduling module of the blockchain network adopts a polling allocation algorithm to evenly distribute data segments to each independent node according to the current load condition of the node (such as the number of tasks to be verified) and the network topology distance. Each node receives at most 3 data segments each time, and the data segments of the same device need to be allocated to nodes in different physical regions (for example, node A is located in East China and node B is located in North China) to ensure regional disaster tolerance. The mapping relationship between the data segments and the nodes is recorded during allocation for subsequent traceability of verification results.

[0111] Step 602: Based on each independent node's verification of the allocated data segments, verify the consistency of the device unique identifiers of the data segments and the continuity of the timestamp intervals of the data segments.

[0112] In step 602, the identifier consistency verification is a process of checking whether the device IDs of all data packets in the data segment are exactly the same. The timestamp continuity verification is a judgment process of confirming whether the data packet timestamps are strictly increasing and uninterrupted.

[0113] In the embodiment of the present application, after receiving a data segment, the node performs double verification: extract the device identifier of the first data packet (such as the machine tool number Z001), and verify whether all subsequent data packets carry the same identifier; after sorting the data packets by timestamp, calculate the adjacent time differences and confirm that all differences are equal to the sampling interval (such as 1 second) and there are no duplicate or missing time points. If an abnormality is found during the verification process (such as a mutation of the device ID or a break in the timestamp), the processing is immediately terminated and an error code is returned.

[0114] Step 603: When both the consistency and continuity are verified to pass, generate a verification identification code.

[0115] In the embodiment of the present application, when the data segment passes the double verification, the node performs: calculate the combined hash value of all data packets in the data segment (hash again after concatenating the hash values of each packet in chronological order); use the node's private key to digitally sign the "combined hash + time interval"; generate a verification identification code containing the signature result, time interval, and node ID. This identification code is encrypted and stored using a domestic algorithm to ensure it cannot be forged.

[0116] The following is a specific example: Based on the data verification scenario of the CNC machine tool from 8:00 to 8:05, the system distributes 5 data segments (each segment contains 6 data packets) to 3 nodes: Node A receives the segments at 8:00 and 8:03, Node B receives the segments at 8:01 and 8:04, and Node C receives the segment at 8:02. When Node A processes the 8:00 segment, it first verifies that the device numbers of all 6 data packets are Z001, confirms that the timestamps are continuous from 8:00:00.000 to 8:00:50.000 (with an interval of 10 seconds because the sampling frequency is 0.1 Hz), then recalculates the hash value for each data packet (e.g., the hash value of the data packet at 8:00:00.000 = hash function(vibration value 0.84 || temperature 45.1 || Z001 || timestamp)). After comparing the recalculated hash values with the original digest and finding them consistent, it concatenates the 6 hash values in chronological order into a string H1 - H6, and then hashes again to obtain the combined hash value JH1 = hash function(H1 + H2 +... + H6). Finally, it signs "JH1 || 8:00:00.000 - 8:00:50.000" with the private key of Node A to generate the verification identification code M1 = {signature result, JH1, time interval, Node A number}. Similarly, when Node B generates M2 for the 8:01 segment, it finds that the vibration value of the 4th data packet (8:01:30.000) is 0.88, which does not match the original record of 0.87, and the hash comparison fails. So it aborts the processing and reports an exception. The system automatically redistributes the 8:01 segment to the standby Node D, and after verification, generates the corrected M2'. Finally, the 5 identification codes [M1, M2', M3, M4, M5] enter the subsequent consensus process. Among them, the verification information for the 8:01 segment is specifically marked as "verified and passed by Node D after re-verification". Its average vibration value is 0.865 = (0.86 + 0.85 + 0.87 + 0.86 + 0.88 + 0.87) / 6, and the temperature range is 1.1 = 46.0 - 44.9 (the maximum and minimum values come from the temperature data Y of the 6 data packets).

[0117] In the embodiments of the present application, through the intelligent allocation and double verification mechanism, this solution not only achieves the load balancing of the verification tasks, but also ensures the data authenticity through strict identity and timing checks, providing high-quality preliminary verification results for subsequent consensus verification, and overall improving the processing efficiency and reliability of the blockchain network in the industrial data verification scenario.

[0118] To solve the problem of dynamic adaptation of the security environment of domestic industrial equipment, in some embodiments, step 105: Dynamically constructing a trusted execution environment according to the multi-dimensional coupling characteristics and combining the domestic application operation data of domestic industrial equipment includes: Step 701: Based on the multi-dimensional coupling characteristics, determine the environmental security level requirements corresponding to the current device operation stage.

[0119] In step 701, the current device operation stage refers to the specific working state (such as startup, operation, shutdown, etc.) of domestic industrial equipment during real-time operation, which is the same concept as the same device operation stage, both referring to the time period division of the device under the same working state. The definition criteria of the operation stage in both expressions are exactly the same. The former emphasizes real-time, and the latter focuses on the stage matching during data grouping. The environmental security level requirement is the security protection intensity level divided according to the device operation state, including three levels: basic protection, enhanced protection, and strict protection.

[0120] In the embodiment of the present application, the system analyzes indicators such as vibration trend and temperature stability in multi-dimensional coupling features, and combines preset level mapping rules (such as triggering strict protection when the vibration change rate > 0.05 / minute and the temperature range > 2.0) to determine the current required security level. Among them, the vibration change rate = (current vibration mean - historical mean) / time interval, and the temperature range is directly taken from the temperature indicator in the coupling feature.

[0121] Step 702: Establish a trusted execution environment configuration template that matches the environmental security level requirement according to the device function module call relationship recorded in the domestic application operation data.

[0122] In step 702, the trusted execution environment configuration template is a predefined combination of security policies, including elements such as memory isolation schemes, data encryption methods, and access control lists.

[0123] In the embodiment of the present application, according to the program module call graph (such as the frequency of the main control module calling sensor reading and writing) recorded in the domestic application operation data, a matching template is selected from the policy library. For example, when the sensor is called frequently, the "memory partition isolation + lightweight encryption" template is used, and when it is called infrequently, the "full memory encryption + strict access control" template is used.

[0124] Step 703: Adapt the trusted execution environment configuration template to real-time operation parameters to generate an environment construction instruction set.

[0125] In step 703, the environment construction instruction set is intermediate code that converts template parameters into executable commands, including hardware operation instructions and resource allocation schemes.

[0126] In the embodiment of the present application, the system adjusts the template parameters according to real-time operation parameters (such as CPU load (CPU Load, CPU), memory margin): when the CPU load > 70%, the encryption intensity is reduced; the size of the memory isolation area is dynamically divided according to the current number of tasks. Finally, an instruction sequence containing parameters such as specific register configuration values and memory address ranges is generated.

[0127] Step 704: Execute the environment construction instruction set at the hardware layer of domestic industrial equipment to construct a trusted execution environment.

[0128] In step 704, the hardware layer execution refers to the process of directly loading the instruction set through a domestic security chip to reconstruct the computing environment at the physical level.

[0129] In the embodiment of the present application, after the domestic security coprocessor carried by the device receives the instruction set: it resets the isolation area configuration of the memory management unit; loads the specified encryption algorithm engine; and sets the hardware-level access control register. All operations are completed through the secure bus inside the chip to ensure that the execution process is not interfered by the main system.

[0130] The following is a specific example: Based on the multi-dimensional coupling characteristics of a CNC machine tool at 8:06 (including the vibration average value of 0.86, temperature range of 1.1, and credibility of 0.92 in the first 5 minutes), the system first determines that it is currently in the "precision machining" stage. According to the vibration volatility of 0.01 = (0.86 - 0.85) / 1 (the difference between the current average value of 0.86 and the average value of 0.85 in the previous minute) and the temperature stability index (the range of 1.1 is less than the threshold of 1.5), it is determined that "three-level security protection" needs to be adopted. Querying the domestic application operation data finds that the G-code machining program is currently being executed (the sensor module is called once every 10 milliseconds). Based on this, the pre-set "high-frequency sampling protection template" is selected (including: the memory is divided into three isolation areas - the core algorithm area of 1.5GB, the real-time data area of 0.8GB, and the communication buffer area of 0.2GB, using the national cipher SM4 encryption algorithm). Combining with the real-time monitored CPU load rate of 70% = (the current number of used cores 4 / the total number of cores 6) × 100%, the template parameters are adjusted to: the core algorithm area is reduced to 1.2GB, and the encryption rounds are reduced from 12 rounds to 8 rounds. The generated instruction set includes: [Configure 0x0000 - 0x4B000000 as the algorithm area, load the 8-round SM4 key, set the white list of sensor data channels...]. After being executed by the security chip built into the machine tool, the environment construction is completed at 8:06:30. At this time, the machining program runs in the protected algorithm area, the vibration data acquisition channel is isolated in the data area, and data is exchanged between the two areas through the encrypted buffer. Moreover, each sensor call needs to pass the security verification to ensure that the machining process not only meets the precision control requirements but also has the anti-tampering ability.

[0131] In the embodiment of the present application, this solution realizes the precise matching of the operating environment of domestic industrial equipment and the real-time working conditions through dynamic security level assessment and hardware-level environment reconstruction, which not only ensures the safe isolation of key operations but also maintains the system performance through elastic resource allocation, effectively solving the problem of insufficient adaptability of traditional static protection solutions in complex industrial scenarios.

[0132] Figure 2 This is a schematic structural diagram of a trusted execution environment dynamic construction system for domesticated application operation provided by an embodiment of the present application. As Figure 2 shown, the system includes: An acquisition module 21, configured to collect mechanical operation data in real time during the continuous operation cycle of a domesticated industrial device.

[0133] A generation module 22, configured to irreversibly bind the mechanical operation data, the unique identifier of the domesticated industrial device, and the acquisition timestamp to generate a data set.

[0134] An input module 23, configured to input the data set into a preset blockchain network, and the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information.

[0135] A coupling module 24, configured to perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domesticated industrial device to obtain multi-dimensional coupling features.

[0136] A construction module 25, configured to dynamically construct a trusted execution environment according to the multi-dimensional coupling features and in combination with the domesticated application operation data of the domestic industrial device.

[0137] Figure 2 The above-mentioned trusted execution environment dynamic construction system for domesticated application operation can execute Figure 1 the trusted execution environment dynamic construction method described in the embodiment shown in

[0138] The implementation principle and technical effects will not be elaborated again. For the above-mentioned trusted execution environment dynamic construction system for domesticated application operation, the specific manners of operations performed by each module and unit have been described in detail in the embodiments related to the method, and will not be elaborated here. Figure 2 In a possible design, Figure 3 the trusted execution environment dynamic construction system described in the embodiment shown in can be implemented as a computing device. As

[0139] shown, the computing device may include a storage component 31 and a processing component 32; Figure 1 The storage component 31 stores one or more computer instructions, and among them, the one or more computer instructions are called and executed by the processing component 32.

[0140] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above-mentioned method. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components for executing the above-mentioned method.

[0141] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disc.

[0142] Of course, the computing device may necessarily also include other components, such as input / output interfaces, display components, communication components, etc.

[0143] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above-mentioned peripheral interface module may be an output device, an input device, etc.

[0144] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.

[0145] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, and the above-mentioned processing component, storage component, etc. may be basic server resources leased or purchased from a cloud computing platform.

[0146] The embodiments of the present application also provide a computer storage medium storing a computer program, and when the computer program is executed by a computer, it can implement the above-mentioned Figure 1 method for dynamically constructing a trusted execution environment for domestic application operation shown in the embodiments.

[0147] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0148] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0149] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0150] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, and are not intended to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of each embodiment of the present application.

Claims

1. A method for dynamically constructing a trusted execution environment for domestic application operation, characterized in that, Including: During the continuous operation cycle of domestic industrial equipment, mechanically operating data is collected in real time; The mechanically operating data, the unique identifier of the domestic industrial equipment, and the collection timestamp are irreversibly bound to generate a data set; The data set is input into a preset blockchain network, and the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information; The verification information is multi-dimensionally coupled with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics; According to the multi-dimensional coupling characteristics, combined with the domestic application operation data of the domestic industrial equipment, a trusted execution environment is dynamically constructed.

2. The method according to claim 1, characterized in that, The step of inputting the data set into a preset blockchain network, where the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information, includes: The data set is input into a preset blockchain network, and through the segmentation module of the blockchain network, the mechanically operating data in the data set is segmented into multiple data segments according to the continuous timestamp order; Through the distribution module of the blockchain network, each data segment is respectively allocated to an independent node in the blockchain network, so that each independent node generates a verification identification code corresponding to the data segment; The verification identification codes corresponding to all the data segments are combined according to the time order of the data segments to generate a global verification identification code sequence corresponding to the data set; In the blockchain network, according to the global verification identification code sequence, a consistency confirmation request is sent to the independent nodes allocated with the corresponding data segments. When the verification identification codes of the same data segment are confirmed to be consistent by more than a preset number threshold of independent nodes, verification information is generated.

3. The method according to claim 2, characterized in that, The step of, in the blockchain network, according to the global verification identification code sequence, sending a consistency confirmation request to the independent nodes allocated with the corresponding data segments, and when the verification identification codes of the same data segment are confirmed to be consistent by more than a preset number threshold of independent nodes, generating verification information, includes: In the blockchain network, a verification task queue corresponding to the global verification identification code sequence is established, where each verification task corresponds to a data segment and includes the identification information of the corresponding data segment and a list of independent nodes; For each verification task in the verification task queue, a confirmation request is sent to all the independent nodes in the list of independent nodes corresponding to the verification task, and the confirmation request includes the verification identification code of the data segment to be confirmed; Receiving the confirmation response information returned by each independent node in the list of independent nodes for the same data segment to be confirmed, where the confirmation response information includes an approval or rejection mark for the verification identification code of the data segment to be confirmed; According to the confirmation response information, the number of independent nodes that approve the verification identification code of the data segment to be confirmed is counted; When the number exceeds the preset number threshold, the verification identification code of the data segment to be confirmed is marked as the confirmed state; Recombine the verification identification codes of all data segments in the confirmed state in the original order in the global verification identification code sequence; Generate verification information based on the recombined verification identification code sequence.

4. The method according to claim 1, characterized in that, The multi-dimensional coupling of the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features includes: Extract a set of continuous period parameters in the real-time operation parameter stream of the domestic industrial equipment that match the timestamp traceability chain of the verification information; Divide the set of continuous period parameters and the verification information into multiple parameter association groups according to the equipment operation stage, and each parameter association group contains real-time operation parameters and the recombined verified identification codes that are time-synchronized within the same equipment operation stage; Perform multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features.

5. The method according to claim 4, characterized in that, The multi-dimensional coupling processing of each parameter association group to generate multi-dimensional coupling features includes: Extract the dynamic change features of the real-time operation parameters, and calculate the credibility weight according to the confirmation status of the verified identification code; Superimpose the dynamic change features and the credibility weight according to a preset weight relationship to generate a feature vector; Calculate the inter-stage transition probability and the parameter change gradient based on the enhanced feature vectors of adjacent parameter association groups, and construct an inter-stage continuity association matrix; Combine the feature vectors of all parameter association groups and the inter-stage continuity association matrix to generate multi-dimensional coupling features.

6. The method according to claim 2, characterized in that, The step of respectively allocating each data segment to an independent node in the blockchain network so that each independent node generates a verification identification code corresponding to the data segment includes: Allocate multiple data segments to different independent nodes in the blockchain network; Based on each independent node's verification of the allocated data segment, verify the consistency of the device unique identifier of the data segment and the continuity of the timestamp interval of the data segment; Generate a verification identification code when both the consistency and the continuity are verified.

7. The method according to claim 1, characterized in that,The step of dynamically constructing a trusted execution environment according to the multi-dimensional coupling features in combination with the domestic application operation data of the domestic industrial equipment includes: Based on the multi-dimensional coupling features, determine the environmental security level requirements corresponding to the current equipment operation stage; Establish a trusted execution environment configuration template that matches the environmental security level requirements according to the device function module call relationship recorded in the domestic application operation data; Adapt the trusted execution environment configuration template to the real-time operation parameters to generate an environment construction instruction set; Execute the environment construction instruction set at the hardware layer of the domestic industrial equipment to construct a trusted execution environment.

8. A dynamic construction system for a trusted execution environment for domestic application operation, characterized in that, Including: A collection module for real-time collecting mechanical operation data during the continuous operation cycle of the domestic industrial equipment; A generation module for irreversibly binding the mechanical operation data, the unique identifier of the domestic industrial equipment, and the collection timestamp to generate a data set; An input module, configured to input the data set into a preset blockchain network, where the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information; A coupling module, configured to perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features; A construction module, configured to dynamically construct a trusted execution environment according to the multi-dimensional coupling features in combination with the domestic application operation data of the domestic industrial equipment.

9. A computing device, characterized in that, It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a method for dynamically constructing a trusted execution environment for domestic application operation according to any one of claims 1 to 7.

10. A computer storage medium, characterized in that, A computer program is stored, and when the computer program is executed by a computer, it implements a method for dynamically constructing a trusted execution environment for domestic application operation according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and system for realizing trusted timestamp service based on block chain

    CN110535663A

  • Electric energy consumption monitoring method and system based on block chain

    CN113179309A

  • Data trusted processing method and system fusing trusted computing and block chain

    CN114499895A

  • Multi-source trusted data production method based on block chain, block chain node and system

    CN117171812A

  • Expandable block chain identity authentication method and system for distributed resource aggregation scene

    CN119675935A

Cited By

  • Power distribution intelligent gateway access detection system and method

    CN120528690A

  • Safe starting system and method based on dynamic environment binding and heterogeneous inspection

    CN121658088A

  • Remote attestation in network

    US12647450B2