Encryption access control method and platform for industrial security data

By classifying industrial data by attribute, dividing it into security levels, and configuring multi-level encryption algorithms, the problem of mismatch between data security requirements in existing technologies is solved. This enables refined encrypted storage and access control of industrial data, improving the confidentiality, controllability, and auditability of the data.

CN120880809AActive Publication Date: 2025-10-31BEIJING RONGSHUAN TECH CO LTD

Patent Information

Application Number
CN202511403203.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2025-10-31
Estimated Expiration
2045-09-29

AI Technical Summary

Technical Problem

Existing technologies lack sophisticated identification and hierarchical encryption mechanisms for the sensitivity levels of industrial data, resulting in a mismatch between encryption strategies and data security requirements. This affects data security and precise access control during dynamic access by multiple roles in industrial systems.

Method used

By collecting industrial system datasets, classifying and encoding attributes, establishing a data security quantitative indicator system for security level classification, constructing a multi-level data encryption algorithm list, and configuring fine-grained access and decryption interaction mechanisms, we can achieve refined encrypted storage and access control of data.

Benefits of technology

It enhances the confidentiality, controllability, and auditability of industrial data storage and access, ensuring that data is encrypted as needed, used according to permissions, and is traceable throughout the entire process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880809A_ABST
    Figure CN120880809A_ABST
Patent Text Reader

Abstract

The invention provides an encryption access control method and platform for industrial security data, and relates to the technical field of data encryption access, and the method comprises the steps: carrying out the attribute classification and code identification of an industrial system data set; performing security level division on the industrial system data set according to the data security quantitative index system; performing matching analysis on the multi-level industrial security data set based on the data encryption algorithm list; encrypting and storing the industrial system data set based on the industrial data identification code set by adopting a multi-stage data encryption algorithm to generate an industrial encrypted data warehouse; and establishing a fine-grained access mechanism and a decryption interaction mechanism according to the user role library, and performing access authority distribution and encryption access control on the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism. According to the invention, the technical problem that the comprehensive requirements of high safety, high precision and high flexibility in a modern industrial system are difficult to meet in the prior art can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data encryption access technology, and in particular to a method and platform for encrypted access control of industrial security data. Background Technology

[0002] With the rapid development of industrial informatization, massive amounts of industrial data are collected and stored in real time through automated acquisition systems and industrial Internet of Things (IoT) platforms, exhibiting characteristics of density, continuity, and high sensitivity. Therefore, ensuring the security and proper use of industrial data has become a crucial prerequisite for the operation of industrial systems.

[0003] Currently, most existing industrial data protection solutions rely on traditional static encryption methods and coarse-grained access control mechanisms, such as unified key encryption and simple role-based permission allocation. While these methods are feasible in small-scale or closed environments, they exhibit numerous shortcomings when faced with concurrent access from multiple roles, large-scale distributed data storage, multi-layered security requirements, and frequently changing access scenarios.

[0004] In summary, existing technologies suffer from a lack of sophisticated identification and hierarchical encryption mechanisms for the sensitivity levels of industrial data. This leads to a mismatch between encryption strategies and data security requirements, further impacting data security and precise access control during dynamic multi-role access in industrial systems. Summary of the Invention

[0005] The purpose of this application is to provide an encrypted access control method and platform for industrial security data, in order to solve the technical problem in the prior art that the lack of a fine identification and hierarchical encryption mechanism for the sensitivity level of industrial data leads to a mismatch between encryption strategies and data security requirements, which further affects the data security guarantee and precise access control during the dynamic access process of multiple roles in industrial systems.

[0006] In view of the above problems, this application provides an encrypted access control method and platform for industrial security data.

[0007] Firstly, this application provides an encrypted access control method for industrial security data, implemented through an encrypted access control platform for industrial security data. The method includes: collecting an industrial system dataset; classifying and encoding the industrial system dataset to obtain an industrial data identifier code set; establishing a data security quantitative index system; classifying the industrial system dataset into security levels according to the data security quantitative index system to obtain a multi-level industrial security dataset; constructing a data encryption algorithm list; performing matching analysis on the multi-level industrial security dataset based on the data encryption algorithm list; configuring multi-level data encryption algorithms; using the multi-level data encryption algorithms to encrypt and store the industrial system dataset based on the industrial data identifier code set to generate an industrial encrypted data warehouse; and establishing a fine-grained access mechanism and a decryption interaction mechanism based on a user role library; and allocating access permissions and implementing encrypted access control for the industrial encrypted data warehouse based on the fine-grained access mechanism and decryption interaction mechanism.

[0008] Preferably, the encrypted access control method for industrial security data further includes: constructing data attribute classification elements, wherein the data attribute classification elements include data source, data type, business requirements, and collection time; performing data cleaning and attribute classification on the industrial system dataset based on the data attribute classification elements to obtain an industrial data attribute parameter set; designing an attribute coding mapping table according to the data attribute classification elements, wherein the attribute coding mapping table includes coding method, coding order, and coding length; and encoding and identifying the industrial data attribute parameter set according to the attribute coding mapping table to obtain the industrial data identification code set.

[0009] Preferably, the encrypted access control method for industrial security data further includes: assessing the security requirements of the industrial system dataset according to the data security quantification index system to generate a data index quantification coefficient matrix set; analyzing the influence degree of each index information in the data security quantification index system to obtain a security index influence factor matrix; weighting and fusing the data index quantification coefficient matrix set based on the security index influence factor matrix to obtain an industrial data security coefficient set; and classifying the industrial system dataset into security levels according to the industrial data security coefficient set to obtain the multi-level industrial security dataset.

[0010] Preferably, the method for encrypted access control of industrial security data further includes: using the multi-level data encryption algorithm to perform hierarchical encryption on the industrial system dataset based on the industrial data identifier code set to obtain an industrial encrypted dataset; identifying the collection time of the industrial encrypted dataset and designing a hierarchical storage structure according to the data collection time, the hierarchical storage structure including a hot data layer and a cold data layer, wherein the collection time of the hot data layer is after that of the cold data layer; mapping the industrial encrypted dataset to the hierarchical storage structure for hierarchical encrypted storage to generate the industrial encrypted data warehouse.

[0011] Preferably, the encrypted access control method for industrial security data further includes: setting data access permission allocation rules, the data access permission allocation rules including role access control and dynamic attribute access control; performing permission allocation and parsing on the user role library based on the role access control and dynamic attribute access control to construct a fine-grained access mechanism; constructing an authentication policy, performing permission verification and key interaction on the user role library based on the authentication policy to establish a decryption interaction mechanism.

[0012] Preferably, the encrypted access control method for industrial security data further includes: performing access permission analysis on each role in the user role library based on the multi-level industrial security dataset according to the role access control to obtain role access level data; performing dynamic condition judgment on the access environment attributes of the user role library based on the dynamic attribute access control to obtain the dynamic access range of the role; and using the intersection of the role access level data and the dynamic access range of the role as role access permission data to construct the fine-grained access mechanism.

[0013] Preferably, the encrypted access control method for industrial security data further includes: obtaining a combination of authentication methods; matching and parsing the combination of authentication methods with the role access permissions of the user role library to determine a role identity hierarchical verification procedure; and performing full-line verification of the user role library based on the role identity hierarchical verification procedure to construct the authentication strategy.

[0014] Preferably, the method for encrypted access control of industrial security data further includes: acquiring a target access user; dynamically allocating permissions and calling industrial data for the target access user and the industrial encrypted data warehouse based on the fine-grained access mechanism to obtain target access permission data; using the decryption interaction mechanism to verify the permissions of the target access user and issue a key to obtain a target decryption key; and performing decryption access control on the target access permission data based on the target decryption key.

[0015] Preferably, the encrypted access control method for industrial security data further includes: recording access operations to the industrial encrypted data warehouse to obtain an industrial data access log, and performing data auditing and tracking based on the industrial data access log.

[0016] Secondly, this application also provides an encrypted access control platform for industrial security data, used to execute an encrypted access control method for industrial security data as described in the first aspect, comprising: an encoding and identification module, used to collect industrial system datasets, classify and encode the industrial system datasets according to their attributes to obtain an industrial data identification code set; a security level classification module, used to build a data security quantitative index system, classify the industrial system datasets according to the data security quantitative index system to obtain a multi-level industrial security dataset; a matching analysis module, used to construct a data encryption algorithm list, perform matching analysis on the multi-level industrial security datasets based on the data encryption algorithm list, and configure multi-level data encryption algorithms; an encrypted storage module, used to encrypt and store the industrial system datasets based on the industrial data identification code set using the multi-level data encryption algorithms to generate an industrial encrypted data warehouse; and an encrypted access control module, used to establish a fine-grained access mechanism and a decryption interaction mechanism according to a user role library, and allocate access permissions and perform encrypted access control on the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

[0017] The technical solution provided in this application has at least the following technical effects or advantages: by achieving the technical goal of multi-dimensional correlation analysis and dynamic encrypted access collaborative management based on data attributes, security levels and user roles, it can improve the confidentiality, controllability and auditability of industrial data storage and access, and ensure that data is encrypted on demand, used according to rights and traceable throughout the process.

[0018] The above description is merely an overview of the technical solution of this application. To better understand the technical means of this application and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of this application more apparent, specific embodiments of this application are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent through the following description. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0020] Figure 1 This is a flowchart illustrating an encrypted access control method for industrial security data according to this application.

[0021] Figure 2 This is a schematic diagram of the structure of an encrypted access control platform for industrial security data according to this application.

[0022] Explanation of reference numerals in the attached diagram: Encoding identification module 11, Security level classification module 12, Matching analysis module 13, Encrypted storage module 14, Encrypted access control module 15. Detailed Implementation

[0023] This application provides an encrypted access control method and platform for industrial security data, solving the technical problem in existing technologies where the lack of a fine-grained identification and hierarchical encryption mechanism for the sensitivity level of industrial data leads to a mismatch between encryption strategies and data security requirements, further affecting data security and precise access control during multi-role dynamic access in industrial systems. It achieves the technical goal of multi-dimensional correlation analysis and dynamic encrypted access collaborative management based on data attributes, security levels, and user roles, thereby improving the confidentiality, controllability, and auditability of industrial data storage and access, ensuring data is encrypted on demand, used according to permissions, and is fully traceable.

[0024] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. It should be understood that this application is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application. It should also be noted that, for ease of description, only the parts related to this application are shown in the accompanying drawings, not all of them.

[0025] Example 1, please refer to the appendix. Figure 1 This application provides a method for encrypted access control of industrial security data, applied to an encrypted access control platform for industrial security data, specifically including the following steps:

[0026] S1: Collect industrial system datasets, classify and encode the industrial system datasets according to their attributes, and obtain industrial data identification code sets.

[0027] Specifically, collecting industrial system datasets refers to gathering various forms of data from multiple subsystems or equipment sources during industrial production or operation through sensors, controllers, monitoring systems, etc., such as temperature, current, equipment operating status, and fault alarm records. Industrial system datasets are then categorized based on attributes such as source, type, purpose, and time. For example, temperature sensor data from the same production line can be grouped into one category, while electricity consumption data used for energy consumption statistics can be grouped into another. Different classifications help clarify the functional attributes and business relationships of each data category. Encoding and identification refers to generating a unique identifier for each data entry based on the classification results, resulting in an industrial data identifier code set. This assigns a clear identity to all collected and classified data, facilitating subsequent operations such as retrieval, encryption, and access control. Through the continuous process of collection, classification, and encoding, raw, scattered data can be transformed into a well-structured and traceable dataset.

[0028] S2: Establish a data security quantitative indicator system, and classify the industrial system dataset into security levels according to the data security quantitative indicator system to obtain a multi-level industrial security dataset.

[0029] Specifically, establishing a data security quantitative indicator system refers to creating a standardized evaluation system for assessing the security importance of different types of data in industrial systems. This system comprises multiple quantifiable security indicators, such as data sensitivity, business dependence, access frequency, modification risk, and historical leakage records. Each indicator is assigned a specific numerical value to measure its impact on data security. For example, sensitivity can be scored on a ten-level scale from 0 to 10, with higher scores indicating greater sensitivity. Classifying industrial system datasets according to this data security quantitative indicator system involves scoring each piece or category of data based on these indicators, calculating its comprehensive security score, and then dividing the data into different security levels based on the score range. This grouping of data according to security requirements from high to low results in a multi-level industrial security dataset. This helps to identify data requiring strong encryption and strict access control, thereby improving processing efficiency while ensuring security.

[0030] S3: Construct a list of data encryption algorithms, perform matching analysis on the multi-level industrial security dataset based on the list of data encryption algorithms, and configure multi-level data encryption algorithms.

[0031] Specifically, a data encryption algorithm list is constructed, pre-selecting a set of encryption algorithms suitable for different security levels. This can include symmetric encryption, asymmetric encryption, hash algorithms, and hybrid encryption techniques. Symmetric encryption, such as AES, is suitable for data processing with high efficiency requirements; asymmetric encryption, such as RSA, is suitable for critical data transmission; hash algorithms, such as SHA, are used for data integrity verification; and hybrid encryption combines symmetric and asymmetric algorithms to balance security and performance. Based on the data encryption algorithm list, a matching analysis is performed on multi-level industrial security datasets. According to the security requirements of different data levels, the specific requirements for encryption strength, encryption speed, key length, etc., are analyzed, and the most suitable encryption algorithm is selected for adaptation. For example, Level 1 highly sensitive data may require asymmetric encryption combined with dynamic keys, while Level 3 low-sensitivity data may only require basic symmetric encryption. The matching results are then implemented, specifying the corresponding encryption method and parameters for each security level of data, i.e., configuring multi-level data encryption algorithms. This not only ensures the confidentiality and integrity of data at different levels but also avoids the resource waste caused by uniformly using high-strength encryption for all data.

[0032] S4: The multi-level data encryption algorithm is used to encrypt and store the industrial system dataset based on the industrial data identification code set, thereby generating an industrial encrypted data warehouse.

[0033] Specifically, a multi-level data encryption algorithm is adopted to encrypt and store industrial system datasets based on an industrial data identifier code set. This involves selecting the appropriate encryption method according to the security level of each data type, based on a list of encryption algorithms. For example, highly sensitive, moderately sensitive, and low-sensitivity data are encrypted using different methods, thus achieving targeted configuration of encryption methods. By utilizing the classification and security level information contained in the identifier code of each data item, the corresponding encryption algorithm is automatically matched and the original data is encrypted. The encrypted data is then stored in an orderly manner according to the identifier code structure, forming an identifiable, decryptable, and manageable data set. All data that has undergone hierarchical encryption processing is organized into a structured storage platform to generate an industrial encrypted data warehouse. This industrial encrypted data warehouse not only has a high level of security but also supports efficient retrieval and scheduling management based on multiple dimensions such as data level, time, or source.

[0034] S5: Based on the user role library, establish a fine-grained access mechanism and a decryption interaction mechanism, and allocate access permissions and perform encrypted access control for the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

[0035] Specifically, the user role database is a pre-established collection of user information, where each user has a unique identifier and is associated with their role, responsibilities, permission level, and usage environment. For example, an administrator, equipment engineer, and security auditor in a company may have different data access permissions in the role database. Based on the user role database, a fine-grained access mechanism is established to further refine the granularity of access control, considering not only user identity and role permissions but also dynamic factors such as data security level, access time, operation type, and usage scenario.

[0036] The decryption interaction mechanism refers to the process where, when a user requests access to controlled data, after verifying their identity, the data is decrypted through key distribution and permission verification. For example, a two-factor authentication encryption method can be used to distribute a temporary key to a qualified user and verify whether their identity matches their permission level. Based on fine-grained access mechanisms and decryption interaction mechanisms, access permissions and encrypted access control are implemented for industrial encrypted data warehouses. This allows for full-process management of whether a user can access data, what data they can access, how they can access it, and whether the access process triggers dynamic key negotiation. A user role library provides the identity foundation, the fine-grained access mechanism provides precise control conditions, and the decryption interaction mechanism ensures key security. These three elements work together to build a rigorous and dynamically adjustable encrypted access control system that can effectively address the industrial security access needs of different users, different scenarios, and different data sensitivities.

[0037] Furthermore, this application also includes: constructing data attribute classification elements, wherein the data attribute classification elements include data source, data type, business requirements, and collection time; performing data cleaning and attribute classification on the industrial system dataset based on the data attribute classification elements to obtain an industrial data attribute parameter set; designing an attribute coding mapping table according to the data attribute classification elements, wherein the attribute coding mapping table includes coding method, coding order, and coding length; and encoding and identifying the industrial data attribute parameter set according to the attribute coding mapping table to obtain the industrial data identification code set.

[0038] Specifically, constructing data attribute classification elements refers to dividing industrial system datasets into different attribute dimensions to describe the basic characteristics of the data. Data attribute classification elements include data source, data type, business requirements, and collection time. Data source refers to the equipment, system, or platform from which the industrial system dataset was collected, such as from sensors, control systems, or databases. Data type distinguishes the format of the industrial system dataset, such as numerical, text, image, or state variables. Business requirements indicate the purpose of the industrial system dataset in business processes, such as alarm detection, predictive maintenance, or energy consumption analysis. Collection time refers to the specific timestamp when the industrial system dataset was collected, used for subsequent sorting, synchronization, and analysis.

[0039] Subsequently, the industrial system dataset is cleaned and its attributes are classified based on data attribute classification elements. The raw data is cleaned by removing noise, deduplication, and format standardization to improve data quality and consistency. The data is then classified according to dimensions such as data source, data type, business needs, and collection time. For example, multiple data from the same device within the same time period can be grouped together and assigned to the same category, which allows for clearer organization and querying of the data, resulting in a structured set of industrial data attribute parameters.

[0040] Further, based on the data attribute classification elements, an attribute coding mapping table is designed to specify how to convert different data attributes into standardized codes. The attribute coding mapping table includes the coding method, coding order, and coding length. The coding method may use Arabic numerals, letters, or hash algorithms; the coding order determines the order in which each attribute appears in the final identifier code, for example, source first then type; the coding length indicates the fixed or variable number of bytes in each coding segment, for example, data source may be represented by four digits.

[0041] Finally, according to the attribute coding mapping table, each industrial data attribute parameter in the industrial data attribute parameter set is converted into a unique identifier, forming an industrial data identifier code set. Each identifier code is equivalent to tagging the raw data, facilitating subsequent data classification, security control, or index access.

[0042] Furthermore, this application also includes: conducting a security requirement assessment of the industrial system dataset according to the data security quantification index system, generating a data index quantification coefficient matrix set; analyzing the degree of influence of each index information in the data security quantification index system to obtain a security index influence factor matrix; weighting and fusing the data index quantification coefficient matrix set based on the security index influence factor matrix to obtain an industrial data security coefficient set; and classifying the industrial system dataset into security levels according to the industrial data security coefficient set to obtain the multi-level industrial security dataset.

[0043] Specifically, a security requirements assessment of industrial system datasets is conducted according to a data security quantitative indicator system. Based on a pre-established standard system for measuring data security, each piece of industrial data is analyzed to determine its security requirements in dimensions such as confidentiality, integrity, and availability. The data security quantitative indicator system includes multiple specific indicators, such as sensitivity level, business dependency, access frequency, and data granularity. By scoring different types of data in the industrial system item by item, multiple quantitative values ​​can be generated, ultimately forming a data indicator quantitative coefficient matrix set. Each row corresponds to one data point, and each column corresponds to a security indicator item. The values ​​in the matrix represent the quantitative score of each row of data under each column's indicator.

[0044] Next, we will analyze the impact of each indicator in the data security quantitative indicator system to assess the weight and contribution of each security indicator in the overall data security assessment. Different indicators have different degrees of impact on security; for example, the sensitivity level of data may be more critical to security than the access frequency. Through expert experience, statistical analysis, or regression algorithms, we can quantify the impact of each indicator, generate a security indicator impact factor matrix, and record the weight value of each indicator in the overall security scoring system.

[0045] Based on the safety indicator impact factor matrix, the data indicator quantification coefficient matrix set is then weighted and fused. The quantification score of each indicator is multiplied by the corresponding impact factor, and then the results are summed to obtain a set of comprehensive scores, namely the industrial data security coefficient set, which represents the security coefficient of each data under the comprehensive security assessment. The higher the value, the more strictly the data needs to be protected.

[0046] Finally, the industrial system dataset is classified into security levels according to the industrial data security coefficient set, and all data is then assigned to different security levels. Typically, this can be divided into three or five security levels, such as low, medium, and high, or levels one to five, corresponding to different encryption strategies and access permissions. The result is a multi-level industrial security dataset, and different levels of data will employ different encryption and access control methods in subsequent processes.

[0047] Furthermore, this application also includes: using the multi-level data encryption algorithm to perform hierarchical encryption on the industrial system dataset based on the industrial data identifier code set to obtain an industrial encrypted dataset; identifying the collection time of the industrial encrypted dataset and designing a hierarchical storage structure according to the data collection time, the hierarchical storage structure including a hot data layer and a cold data layer, wherein the collection time of the hot data layer is after that of the cold data layer; mapping the industrial encrypted dataset to the hierarchical storage structure for hierarchical encrypted storage to generate the industrial encrypted data warehouse.

[0048] Specifically, a multi-level data encryption algorithm is used to perform hierarchical encryption on the industrial system dataset based on the industrial data identifier code set. Combining the security level information contained in the identifier code corresponding to each piece of industrial data, a matching encryption method is selected to encrypt data at different levels. The multi-level data encryption algorithm represents a strategy of using different encryption strengths for data corresponding to different security levels. For example, level 1 data uses the RSA algorithm, level 2 data uses the AES algorithm, and level 3 data may only use lightweight hash encryption, thus forming an industrial encrypted dataset, which is the set of industrial data after hierarchical encryption processing. Table 1 shows a partial record of the most recent hierarchical encryption of industrial system data.

[0049] Table 1: Partial Records of the Most Recent Industrial System Data Hierarchical Encryption

[0050]

[0051] Next, after the data is encrypted, the industrial encrypted dataset is time-stamped, recording the acquisition time for each data entry. A hierarchical storage structure is designed based on the data acquisition time, dividing the data into different storage tiers. The hierarchical structure is mainly divided into a hot data layer and a cold data layer. The hot data layer contains recently acquired data with high access frequency, such as data from the last 7 days; while the cold data layer contains historical data with low access frequency, such as data older than 30 days. This allows for optimization between storage resource utilization and access speed.

[0052] Industrial encrypted datasets are mapped to a hierarchical storage structure for layered encrypted storage. Encrypted and time-identified data is allocated to either a hot or cold data layer based on its time period, and further organized and stored according to different security levels to generate an industrial encrypted data warehouse, thus constructing a unified and structured industrial encrypted data warehouse. This industrial encrypted data warehouse not only possesses high security but also excellent retrieval efficiency and scalability.

[0053] Furthermore, this application also includes: setting data access permission allocation rules, the data access permission allocation rules including role access control and dynamic attribute access control; performing permission allocation parsing on the user role library based on the role access control and dynamic attribute access control to construct a fine-grained access mechanism; constructing an authentication policy, performing permission verification and key interaction on the user role library based on the authentication policy to establish a decryption interaction mechanism.

[0054] Specifically, to ensure the security and compliance of industrial encrypted data use, a management mechanism is established to constrain the access permissions of different users. This involves setting data access permission allocation rules to control data access behavior based on user identity and usage environment, preventing unauthorized reading, modification, or leakage. Data access permission allocation rules include role-based access control and dynamic attribute access control. Role-based access control assigns corresponding data access scope and permission levels to different roles within the organizational structure, such as administrator, operator, or auditor. For example, administrators can access all data and have modification permissions, while operators can only read data related to their assigned work section, ensuring consistency with the organization's permission system. Dynamic attribute access control, based on role-based permissions, further incorporates dynamic environmental attributes such as user behavior, access time, access location, or device used for real-time judgment to determine whether access is authorized.

[0055] Based on role-based access control and dynamic attribute access control, the user role database is parsed and permissions are allocated. After clarifying the basic access permissions for each user role, real-time environmental factors, such as access time, geographical location, and terminal device type, are further considered to refine the permissions for each role. This allows for precise segmentation of the access scope for all users in the user role database. Role-based access control is an access policy based on the functions performed by a user's identity. For example, a dispatcher can view operational data but cannot modify device parameters. Dynamic attribute access control, on the other hand, is a method of dynamically assigning permissions based on the user's current state. For instance, a user with the same role can access the core system within the company's intranet environment, but can only read partial information when accessing from an external network. Based on these two dimensions of rules, permissions are broken down to the smallest granularity, ensuring that each user can only access data resources that perfectly match their role and environment. This constructs a sophisticated, fine-grained access mechanism, achieving a higher level of security management.

[0056] Based on the different user roles' permission levels, access frequencies, and business risk levels, corresponding combinations of authentication methods are designed. For example, ordinary monitoring users only require a username and password, while system maintenance personnel require dual authentication using biometrics and dynamic passwords, thus forming a set of differentiated verification specifications. Based on the authentication policy, permission verification and key exchange are performed on the user role database. When a user initiates an access request, the corresponding verification program is first invoked based on their identity information in the user role database. After successful verification, an access key is issued, thus completing the user identity confirmation and decryption process. After successful verification, the decryption key required for access is sent to the user through a secure channel, ensuring that the key is not exposed in an insecure network environment and guaranteeing data integrity and confidentiality. The organic integration of user authentication and key management processes enables a complete verification and authorization process to be executed before each data access operation, achieving full control over sensitive data access behavior and ultimately establishing a decryption interaction mechanism.

[0057] Furthermore, this application also includes: performing access permission analysis on each role in the user role library based on the multi-level industrial security dataset according to the role access control to obtain role access level data; performing dynamic condition judgment on the access environment attributes of the user role library based on the dynamic attribute access control to obtain the dynamic access range of the role; and using the intersection of the role access level data and the dynamic access range of the role as role access permission data to construct the fine-grained access mechanism.

[0058] Specifically, role-based access control analyzes the access permissions of each role in the user role library based on a multi-level industrial security dataset. This involves using established role access rules, combined with different security levels of industrial data, to systematically assess the permissions of all user roles and clarify the data content levels that each role can access under the security level system. The multi-level industrial security dataset refers to a collection of data divided into different levels according to data security. For example, level one is core sensitive data, level two is general business data, and level three is publicly accessible operational data. The user role library is a collection of all users and their responsibilities, such as maintenance personnel, dispatchers, and equipment administrators. By matching roles with data levels, a role access level dataset can be generated to define the theoretically permissible data range for each role.

[0059] Furthermore, environmental attributes during access are introduced. Based on dynamic attribute access control, the access environment attributes of the user role library are dynamically judged, such as whether the accessing device is registered with the company, whether the accessing location is in an allowed area, and whether the access time is on a weekday, to assess whether the access behavior complies with the security policy of the current environment. Access environment attributes have dynamic changing characteristics, and different times or devices may lead to different permission judgment results. Therefore, dynamic attribute judgment can improve the accuracy of access control.

[0060] The intersection of role access level data and role dynamic access scope is used as role access permission data. This means that final access rights are only granted within the statically permitted permissions of a role, and only when the current access environment meets the requirements. This intersection constitutes the role access permission data, ensuring that any access behavior simultaneously satisfies the security requirements of both role responsibilities and the real-time environment. This leads to the construction of a fine-grained access mechanism, which is applied to all data access processes, enabling precise management and dynamic adjustment of each access behavior.

[0061] Furthermore, this application also includes: obtaining a combination of authentication methods; matching and parsing the combination of authentication methods with the role access permissions of the user role library to determine a role identity hierarchical verification procedure; and performing full-line verification of the user role library based on the role identity hierarchical verification procedure to construct the authentication strategy.

[0062] Specifically, multiple authentication methods are preset, such as password verification, biometrics, dynamic tokens, and digital certificates. Combinations of these methods are then acquired and categorized according to security levels and application scenarios to create several verification schemes supporting varying levels of access control. These combinations provide multi-layered protection; for example, low-sensitivity data can use a single password, while high-sensitivity data requires both fingerprint recognition and hardware key matching, thus enhancing overall system security. The system matches and parses the user role access permissions against the authentication method combinations, analyzing the permission level of each role and the required security verification strength. The most suitable verification method is then selected from the combinations to generate a dedicated verification program for that role, thus defining a hierarchical verification procedure for each role. Different roles will execute verification processes of varying complexity. For instance, ordinary users only need to enter a password, while system administrators must complete three verification steps: facial recognition, USB encryption key, and mobile verification code synchronization, ensuring that role permissions match the verification strength.

[0063] The role-based identity tiered verification procedure verifies the entire user role database. The verification procedure is applied to all users in the user role database one by one. Only after a user successfully completes their respective verification process is they recognized as a trusted identity by the system. This ensures that visitors not only have logical role permissions, but also undergo security screening in actual authentication behavior. Finally, an identity verification strategy is constructed, and the tiered verification rules are solidified as a system to form a complete identity authentication system for continuous management and auditing of user identities.

[0064] Furthermore, this application also includes: obtaining a target access user; dynamically allocating permissions and calling industrial data for the target access user and the industrial encrypted data warehouse based on the fine-grained access mechanism to obtain target access permission data; using the decryption interaction mechanism to verify the permissions of the target access user and issue a key to obtain a target decryption key; and performing decryption access control on the target access permission data based on the target decryption key.

[0065] Specifically, upon receiving an access request, the system identifies the specific access subject and then obtains the target user, such as a device maintenance engineer or dispatcher. Based on the current user identity, access environment, and data security level, the system calculates the accessible resource range in real time and extracts the corresponding data from the encrypted repository according to the accessible resource range, ultimately obtaining the target access permission data.

[0066] Next, a decryption interaction mechanism is adopted, which combines the authentication policy and the key management process into a secure interaction process. The user's identity and environment attributes are verified to ensure that they still meet the access conditions. After the verification is successful, the session key or private key used to decrypt specific data is sent to the user's device through a secure channel. Finally, the user obtains the target decryption key, which is used for the current session and has an expiration time, thereby reducing the risk of key leakage.

[0067] Then, based on the target decryption key, decryption access control is performed on the target access permission data. The extracted encrypted data is decrypted on the user end or in a controlled environment, and integrity verification and access logging are performed during the decryption process. Decryption access control not only includes the restoration of data content, but also the auditing and usage restrictions on the decrypted data according to user permissions, so as to ensure that users can only view and operate data within their authorized scope.

[0068] Furthermore, this application also includes: recording access operations to the industrial encrypted data warehouse to obtain an industrial data access log, and performing data auditing and tracking based on the industrial data access log.

[0069] Specifically, access operation records are kept for the industrial encrypted data warehouse. When a user performs any operation such as reading, modifying, copying, or downloading encrypted data, corresponding record information is automatically generated, including fields such as user identity, access time, access path, access method, and operation type, thus obtaining an industrial data access log.

[0070] Fields that may appear in industrial data access logs include user ID, assigned role, IP address, accessed data item number, access start time, and access duration, recorded with second-level time precision. Data auditing and tracing are performed based on these industrial data access logs, allowing for retrospective analysis of the log content to determine whether user access behavior complies with access rules, and whether there are instances of frequent access to highly sensitive data, unauthorized behavior, or abnormal access. This analysis is used to identify long-term usage trends, access behavior patterns, and potential internal security risks.

[0071] In summary, the encrypted access control method for industrial security data provided in this application has the following technical effects: by achieving the technical goal of multi-dimensional correlation analysis and dynamic encrypted access collaborative management based on data attributes, security levels and user roles, it can improve the confidentiality, controllability and auditability of industrial data storage and access, and ensure that data is encrypted on demand, used according to rights, and traceable throughout the process.

[0072] Example 2: Based on the same inventive concept as the encrypted access control method for industrial security data in the foregoing examples, this application also provides an encrypted access control platform for industrial security data. Please refer to the appendix. Figure 2 The system includes: an encoding and identification module 11, used to collect industrial system datasets, classify and encode the industrial system datasets according to their attributes, and obtain an industrial data identification code set; a security level classification module 12, used to build a data security quantitative index system, classify the industrial system datasets according to the data security quantitative index system, and obtain a multi-level industrial security dataset; a matching analysis module 13, used to construct a data encryption algorithm list, perform matching analysis on the multi-level industrial security datasets based on the data encryption algorithm list, and configure multi-level data encryption algorithms; an encrypted storage module 14, used to encrypt and store the industrial system datasets based on the industrial data identification code set using the multi-level data encryption algorithms, and generate an industrial encrypted data warehouse; and an encrypted access control module 15, used to establish a fine-grained access mechanism and a decryption interaction mechanism based on a user role library, and allocate access permissions and perform encrypted access control on the industrial encrypted data warehouse based on the fine-grained access mechanism and decryption interaction mechanism.

[0073] Furthermore, the encrypted access control platform for industrial security data is also used for: constructing data attribute classification elements, which include data source, data type, business requirements, and collection time; performing data cleaning and attribute classification on the industrial system dataset based on the data attribute classification elements to obtain an industrial data attribute parameter set; designing an attribute coding mapping table according to the data attribute classification elements, which includes coding method, coding order, and coding length; and encoding and identifying the industrial data attribute parameter set according to the attribute coding mapping table to obtain the industrial data identification code set.

[0074] Furthermore, the encrypted access control platform for industrial security data is also used for: assessing the security requirements of the industrial system dataset according to the data security quantification index system, generating a set of data index quantification coefficient matrices; analyzing the degree of influence of each index information in the data security quantification index system to obtain a security index influence factor matrix; weighting and fusing the set of data index quantification coefficient matrices based on the security index influence factor matrix to obtain an industrial data security coefficient set; and classifying the industrial system dataset into security levels according to the industrial data security coefficient set to obtain the multi-level industrial security dataset.

[0075] Furthermore, the industrial security data encryption access control platform is also used for: employing the multi-level data encryption algorithm to perform hierarchical encryption on the industrial system dataset based on the industrial data identifier code set to obtain an industrial encrypted dataset; identifying the collection time of the industrial encrypted dataset and designing a hierarchical storage structure according to the data collection time, the hierarchical storage structure including a hot data layer and a cold data layer, wherein the collection time of the hot data layer is after that of the cold data layer; mapping the industrial encrypted dataset to the hierarchical storage structure for hierarchical encrypted storage to generate the industrial encrypted data warehouse.

[0076] Furthermore, the encrypted access control platform for industrial security data is also used for: setting data access permission allocation rules, the data access permission allocation rules including role access control and dynamic attribute access control; performing permission allocation and parsing on the user role library based on the role access control and dynamic attribute access control to construct a fine-grained access mechanism; constructing an authentication policy, performing permission verification and key interaction on the user role library based on the authentication policy to establish a decryption interaction mechanism.

[0077] Furthermore, the encrypted access control platform for industrial security data is also used to: perform access permission analysis on each role in the user role library based on the multi-level industrial security dataset according to the role access control, to obtain role access level data; perform dynamic condition judgment on the access environment attributes of the user role library based on the dynamic attribute access control, to obtain the dynamic access range of the role; and use the intersection of the role access level data and the dynamic access range of the role as role access permission data to construct the fine-grained access mechanism.

[0078] Furthermore, the encrypted access control platform for industrial security data is also used to: obtain a combination of authentication methods; match and parse the combination of authentication methods with the role access permissions of the user role library to determine a role identity hierarchical verification procedure; and perform full-line verification of the user role library based on the role identity hierarchical verification procedure to construct the authentication strategy.

[0079] Furthermore, the encrypted access control platform for industrial security data is also used for: acquiring target access users; dynamically allocating permissions and calling industrial data to the target access users and the industrial encrypted data warehouse based on the fine-grained access mechanism to obtain target access permission data; verifying the permissions of the target access users and issuing keys using the decryption interaction mechanism to obtain target decryption keys; and performing decryption access control on the target access permission data based on the target decryption keys.

[0080] Furthermore, the encrypted access control platform for industrial security data is also used to: record access operations to the industrial encrypted data warehouse, obtain industrial data access logs, and perform data auditing and tracking based on the industrial data access logs.

[0081] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The encryption access control method and specific examples for industrial security data in the aforementioned embodiment one are also applicable to the encryption access control platform for industrial security data in this embodiment. Through the foregoing detailed description of the encryption access control method for industrial security data, those skilled in the art can clearly understand the encryption access control platform for industrial security data in this embodiment. Therefore, for the sake of brevity, it will not be described in detail here.

[0082] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0083] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application also intends to include such modifications and variations.

Claims

1. A method for encrypted access control of industrial security data, characterized in that, The method includes: Collect industrial system datasets, classify and encode the industrial system datasets according to their attributes, and obtain an industrial data identifier code set; A data security quantitative indicator system is established, and the industrial system dataset is classified into security levels according to the data security quantitative indicator system to obtain a multi-level industrial security dataset. Construct a list of data encryption algorithms, perform matching analysis on the multi-level industrial security dataset based on the list of data encryption algorithms, and configure multi-level data encryption algorithms; The multi-level data encryption algorithm is used to encrypt and store the industrial system dataset based on the industrial data identifier code set, thereby generating an industrial encrypted data warehouse. Based on the user role library, a fine-grained access mechanism and a decryption interaction mechanism are established. Based on the fine-grained access mechanism and the decryption interaction mechanism, access permissions are allocated and encrypted access is controlled for the industrial encrypted data warehouse.

2. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The obtained industrial data identifier code set includes: Construct data attribute classification elements, which include data source, data type, business requirements, and collection time; Based on the data attribute classification elements, the industrial system dataset is cleaned and its attributes are classified to obtain an industrial data attribute parameter set. Based on the data attribute classification elements, an attribute coding mapping table is designed, which includes coding method, coding order and coding length. The industrial data attribute parameter set is encoded and identified according to the attribute encoding mapping table to obtain the industrial data identifier code set.

3. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The obtained multi-level industrial safety dataset includes: The security requirements of the industrial system dataset are assessed according to the data security quantification index system, and a set of data index quantification coefficient matrix is ​​generated. An impact analysis was performed on each indicator in the data security quantitative indicator system to obtain a security indicator impact factor matrix. Based on the safety index influence factor matrix, the data index quantification coefficient matrix set is weighted and fused to obtain the industrial data safety coefficient set. The industrial system dataset is classified into security levels according to the industrial data security coefficient set to obtain the multi-level industrial security dataset.

4. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The generation of the industrial encrypted data warehouse includes: The multi-level data encryption algorithm is used to perform hierarchical encryption on the industrial system dataset based on the industrial data identifier code set to obtain an industrial encrypted dataset. The industrial encrypted dataset is identified by its acquisition time, and a hierarchical storage structure is designed according to the data acquisition time. The hierarchical storage structure includes a hot data layer and a cold data layer, wherein the acquisition time of the hot data layer is after that of the cold data layer. The industrial encrypted dataset is mapped to the hierarchical storage structure for hierarchical encrypted storage, thereby generating the industrial encrypted data warehouse.

5. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The establishment of the fine-grained access mechanism and decryption interaction mechanism includes: Set data access permission allocation rules, which include role access control and dynamic attribute access control; Based on the aforementioned role-based access control and dynamic attribute-based access control, permission allocation and parsing are performed on the user role database to construct a fine-grained access mechanism; An authentication policy is constructed, and based on the authentication policy, permission verification and key exchange are performed on the user role library, and a decryption exchange mechanism is established.

6. The encrypted access control method for industrial security data as described in claim 5, characterized in that, The construction of the fine-grained access mechanism includes: Based on the multi-level industrial security dataset, the access control system performs access permission analysis on each role in the user role library according to the role access control, and obtains role access level data. Based on the dynamic attribute access control, the access environment attributes of the user role library are dynamically judged to obtain the dynamic access range of the role. The intersection of the character's accessibility level data and the character's dynamic accessibility range is used as the character's access permission data to construct the fine-grained access mechanism.

7. The encrypted access control method for industrial security data as described in claim 5, characterized in that, The authentication strategy includes: Obtain the combination of authentication methods, and match and parse the combination of authentication methods with the role access permissions in the user role database to determine the role identity hierarchical verification procedure; The user role database is fully verified based on the role identity classification verification procedure, and the identity verification strategy is constructed.

8. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The method of allocating access permissions and controlling encrypted access to the industrial encrypted data warehouse based on the fine-grained access mechanism and decryption interaction mechanism includes: The target access user is obtained, and dynamic permission allocation and industrial data retrieval are performed on the target access user and the industrial encrypted data warehouse based on the fine-grained access mechanism to obtain target access permission data; The decryption interaction mechanism is used to verify the access rights of the target user and issue a key to obtain the target decryption key; Access control is performed on the target access permission data based on the target decryption key.

9. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The method further includes: Access operations to the industrial encrypted data warehouse are recorded to obtain an industrial data access log, and data auditing and tracing are performed based on the industrial data access log.

10. An encrypted access control platform for industrial security data, characterized in that, The steps for implementing the encrypted access control method for industrial security data according to any one of claims 1 to 9 include: The encoding and identification module is used to collect industrial system datasets, classify and encode the industrial system datasets to obtain an industrial data identification code set. The security level classification module is used to build a data security quantitative indicator system, and classify the industrial system dataset into security levels according to the data security quantitative indicator system to obtain a multi-level industrial security dataset. The matching analysis module is used to construct a list of data encryption algorithms, perform matching analysis on the multi-level industrial security dataset based on the list of data encryption algorithms, and configure multi-level data encryption algorithms. An encrypted storage module is used to encrypt and store the industrial system dataset based on the industrial data identifier code set using the multi-level data encryption algorithm, thereby generating an industrial encrypted data warehouse. The encrypted access control module is used to establish a fine-grained access mechanism and a decryption interaction mechanism based on the user role library, and to allocate access permissions and perform encrypted access control for the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

Citation Information

Patent Citations

  • Enterprise-level data encryption and access control method and system

    CN118410505A

  • Enterprise internal software authority management method and device, equipment and storage medium

    CN118627100A

  • Enterprise sensitive data security access management method and system

    CN118656870A

  • Information data security management method, system, equipment and medium

    CN119046957A

  • Dynamic trusted edge gateway for industrial terminals based on classification and hierarchical management and its implementation method

    US20250280041A1

Cited By

  • Data security protection method, device and system based on anti-quantum cryptography algorithm

    CN121396456A

  • Data security protection method, device and system based on anti-quantum cryptography algorithm

    CN121396456B