Industrial personal computer data security backup method and system based on encryption algorithm
By adaptively calculating backup time intervals and employing differentiated encryption strategies, the problems of wasted industrial control computer data backup resources and real-time performance are solved, enabling flexible and efficient data security backup and monitoring, and supporting the security and traceability of critical data.
Patent Information
- Application Number
- CN202511058283.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-30
- Publication Date
- 2025-11-14
Smart Images

Figure CN120950304A_ABST
Abstract
Description
Technical Field
[0001] This invention proposes a method and system for secure data backup of industrial control computers based on encryption algorithms, which relates to the field of data analysis encryption and backup technology. Background Technology
[0002] In industrial automation systems, industrial control computers (ICCs) are responsible for real-time monitoring and processing of relevant status data. Timely backup of this data is crucial for preventing production interruptions and analyzing equipment damage. Traditional technologies often involve periodic or quantitative data collection and archiving, relying on timed backups or triggering thresholds. This approach fails to meet the actual needs of periods of high and low volatility. During stable periods, frequent backups lead to significant redundancy and wasted storage resources. During periods of rapid change, the inability to fine-grained backup intervals can result in critical information being overlooked or obscured, making accident tracing and detailed analysis difficult (e.g., changes within 5 seconds before and after an accident are often overlooked due to the large granularity of the archive). Furthermore, there is a lack of adaptive archiving mechanisms to adapt to data change frequencies. Existing methods often employ uniform algorithms (e.g., all using high-strength encryption), resulting in significant CPU and storage overhead under high concurrency and high data volumes, impacting real-time performance. Summary of the Invention
[0003] This invention provides a method and system for secure data backup of industrial control computers based on encryption algorithms, in order to solve the problems mentioned above:
[0004] This invention proposes a method for secure data backup of industrial control computers based on encryption algorithms, the method comprising:
[0005] The operating parameters of the production process stored in the industrial control computer are obtained to form original backup data blocks. The original backup data blocks are numbered, and the operating parameters are obtained at preset time intervals.
[0006] The original data blocks are encrypted, and time blocks with time intervals greater than a first preset threshold are encrypted using a low-strength encryption algorithm, while time blocks with time intervals less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm.
[0007] After encryption, an encrypted data block is formed. Security and integrity verification information is generated for the encrypted data block to achieve tamper detection and traceability.
[0008] Furthermore, the operating parameters of the production process stored in the industrial control computer are acquired to form an original backup data block. These operating parameters are acquired at preset time intervals, including:
[0009] Set and acquire the operating parameters of the production process stored in the industrial control computer. The operating parameters include: temperature, pressure, speed, current and valve opening.
[0010] The acquisition service is started according to a preset time period by the operating system timer. The acquisition service sends a read command to the target field device and calls the corresponding communication interface to obtain the acquired values of the operating parameters.
[0011] The system uses an industrial control protocol to poll and read the collected values of operating parameters according to a set address, and performs preliminary verification on the collected values of operating parameters. The preliminary verification includes: range detection, parity check, breakpoint supplementation sampling, and exclusion of abnormal sampling.
[0012] The collected values of the verified operating parameters are formed into a data sampling stream D = {d1, d2, ..., d...} n};
[0013] The backup time interval is calculated based on the data sampling stream. Original backup data blocks are formed according to the backup time interval, and these original backup data blocks are numbered. The calculation of the backup time interval includes:
[0014] Periodic calculation of the change index:
[0015]
[0016] Where Δ(t) represents the exponent of change, d i (t) represents the value of the i-th data point at time t, d i (t-1) represents the value of the i-th data point at time t-1, and N represents the total number of operating parameters;
[0017] Adaptive calculation of backup time interval:
[0018] T next =min{T max ,max{T min ,ɑ·e -β·Δ(t)}};
[0019] Among them, T next T represents the time window for backing up the next data block. min T represents the minimum backup time interval. max This represents the maximum backup time interval, and α and β represent sensitivity coefficients.
[0020] Furthermore, the original data blocks are encrypted based on the acquisition time interval of the original data blocks. Time blocks with a time interval greater than a first preset threshold are encrypted using a low-strength encryption algorithm, and time blocks with a time interval less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm, including:
[0021] The acquisition time interval of the original data block is obtained, and the acquisition time interval of the original data block is compared with a first preset threshold. If the acquisition time interval is greater than the first preset threshold, the original data block is encrypted by a low-strength encryption algorithm, including AES-128 and SM4-128, and random perturbation is added to the low-strength encryption algorithm.
[0022] If the acquisition time interval is less than or equal to a first preset threshold, the original data block is encrypted using a high-strength encryption algorithm, including AES-256 and SM4-256.
[0023] Furthermore, the low-strength encryption algorithm incorporates random perturbations, including:
[0024] For each data block encrypted using a low-strength encryption algorithm, the system master key K is used. master Partition block number j and timestamp T j Derived independent subkey:
[0025] K j =KDF(K master ,j,T j );
[0026] Wherein, KDF represents the key derivation function, which includes PBKDF2, HKDF, and SM3-HMAC, j represents the partition block number, and T... j Represents a timestamp;
[0027] Then through the system master key K master Partition block number j and timestamp T j Block-specific perturbation salt:
[0028] Salt j =PRF(K master ,j||T j );
[0029] Salt j This represents the block-specific perturbation salt for the j-th partition, PRF represents a pseudo-random function, and || represents a join operation.
[0030] First, connect the data block to Salt. j Perform XOR masking:
[0031]
[0032] Then, perform hierarchical encryption using an automatic allocation algorithm (such as AES-128 or AES-256) to obtain the final ciphertext C. j :
[0033]
[0034] Furthermore, after encryption, encrypted data blocks are formed. Security and integrity verification information is generated for these encrypted data blocks to enable backup data tampering detection and traceability, including:
[0035] A hash chain is constructed by calculating a separate hash value for each encrypted data block using a hash algorithm. j =H(C j ||hash j-1 );
[0036] hash j With backup data encrypted C j They are stored together, and before decryption, the hash value is compared to verify whether the backup data has been tampered with.
[0037] This invention proposes a data security backup system for industrial control computers based on encryption algorithms, the system comprising:
[0038] The module for acquiring operating parameters is used to acquire the operating parameters of the production process stored in the industrial control computer, form original backup data blocks, number the original backup data blocks, and acquire the operating parameters at preset time intervals.
[0039] An encryption module is used to encrypt the original data blocks. Time blocks with a time interval greater than a first preset threshold are encrypted using a low-strength encryption algorithm, and time blocks with a time interval less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm.
[0040] The verification module encrypts data to form encrypted data blocks and generates security and integrity verification information for these encrypted data blocks, enabling tamper detection and traceability.
[0041] Furthermore, the module for obtaining operating parameters includes:
[0042] The parameter acquisition module is used to set and acquire the operating parameters of the production process stored in the industrial control computer. The operating parameters include: temperature, pressure, speed, current and valve opening.
[0043] The calling module is used to schedule the start of the acquisition service according to a preset time period through the operating system timer. The acquisition service sends a read command to the target field device and calls the corresponding communication interface to obtain the acquired values of the operating parameters.
[0044] The preliminary verification module is used to poll and read the collected values of the operating parameters according to the set address through the industrial control protocol, and to perform preliminary verification on the collected values of the operating parameters. The preliminary verification includes: range detection, parity check, breakpoint supplementation and elimination of abnormal sampling.
[0045] The data sampling stream module is used to form a data sampling stream D = {d1, d2, ..., d...} from the collected values of the verified operating parameters. n};
[0046] The backup time interval calculation module is used to calculate the backup time interval based on the data sampling stream, form raw backup data blocks according to the backup time interval, and number the raw backup data blocks. The calculation of the backup time interval includes:
[0047] Periodic calculation of the change index:
[0048]
[0049] Where Δ(t) represents the exponent of change, d i (t) represents the value of the i-th data point at time t, d i (t-1) represents the value of the i-th data point at time t-1, and N represents the total number of operating parameters;
[0050] Adaptive calculation of backup time interval:
[0051] T next =min{T max ,max{T min ,α·e -β·Δ(t)}};
[0052] Among them, T next T represents the time window for backing up the next data block. min T represents the minimum backup time interval. max This represents the maximum backup time interval, and α and β represent sensitivity coefficients.
[0053] Furthermore, the encryption module includes:
[0054] A low-strength encryption module is used to obtain the acquisition time interval of the original data block, compare the acquisition time interval of the original data block with a first preset threshold, and if the acquisition time interval is greater than the first preset threshold, then the original data block is encrypted by a low-strength encryption algorithm. The low-strength encryption algorithm includes AES-128 and SM4-128, and the low-strength encryption algorithm incorporates random perturbation.
[0055] A high-strength encryption module is used to encrypt the original data block using a high-strength encryption algorithm if the acquisition time interval is less than or equal to a first preset threshold. The high-strength encryption algorithm includes AES-256 and SM4-256.
[0056] Furthermore, the low-strength encryption module includes:
[0057] The derived independent subkey module, for each data block encrypted using a low-strength encryption algorithm, uses the system master key K. master Partition block number j and timestamp T j Derived independent subkey:
[0058] K j =KDF(K master ,j,T j );
[0059] Wherein, KDF represents the key derivation function, which includes PBKDF2, HKDF, and SM3-HMAC, j represents the partition block number, and T... j Represents a timestamp;
[0060] A dedicated perturbation salt module for generating blocks is used to further process the system master key K. master Partition block number j and timestamp T j Block-specific perturbation salt:
[0061] Salt j =PRF(K master ,j||T j );
[0062] Salt j This represents the block-specific perturbation salt for the j-th partition, PRF represents a pseudo-random function, and || represents a join operation.
[0063] The mask module is used to first mask the data block with Salt. j Perform XOR masking:
[0064]
[0065] The final ciphertext generation module is used to further encrypt the final ciphertext C using an automatic allocation algorithm (such as AES-128 or AES-256). j :
[0066]
[0067] Furthermore, the verification module includes:
[0068] The module for calculating individual hash values is used to compute an individual hash value for each encrypted data block using a hash algorithm, thus constructing a hash chain: hash j =H(C j ||hash j-1 );
[0069] The comparison module is used to compare the hash. j With backup data encrypted C jThey are stored together, and before decryption, the hash value is compared to verify whether the backup data has been tampered with.
[0070] The beneficial effects of this invention are as follows: By setting different encryption strengths for data blocks of varying importance, it balances computational efficiency with data protection, thereby improving the overall level of data security. High-strength encryption is used for data during critical periods (such as anomalies or important process nodes) to ensure that critical data is not illegally accessed or leaked. Low-strength encryption is used for data during ordinary periods, improving data processing and storage efficiency and reducing resource consumption. By generating and saving security and integrity verification information for data blocks, it is possible to detect whether data has been tampered with in a timely manner. Furthermore, in the event of a security incident, data can be traced back to its source using the block number and verification information, ensuring traceability throughout the entire production process. The data acquisition time interval and encryption threshold can be adjusted according to actual production needs, flexibly adapting to data management requirements in different scenarios. By segmenting, numbering, encrypting, and verifying the integrity of industrial control computer production data, an efficient, flexible, and secure data backup and monitoring system is achieved, effectively preventing unauthorized data reading and tampering, while also facilitating event tracing and data management. Attached Figure Description
[0071] Figure 1 This is a schematic diagram of a data security backup method for industrial control computers based on encryption algorithms, as described in this invention. Detailed Implementation
[0072] To better understand the above-mentioned objectives, features, and advantages of the present invention, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be combined with each other.
[0073] Numerous specific details are set forth in the following description to provide a thorough understanding of the invention. The described embodiments are only a part of, and not all, of the embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.
[0074] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. The terminology used herein in the description of the invention is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention.
[0075] One embodiment of the present invention provides a method for secure data backup of an industrial control computer based on an encryption algorithm, the method comprising:
[0076] The operating parameters of the production process stored in the industrial control computer are obtained to form original backup data blocks. The original backup data blocks are numbered, and the operating parameters are obtained at preset time intervals.
[0077] The original data blocks are encrypted, and time blocks with time intervals greater than a first preset threshold are encrypted using a low-strength encryption algorithm, while time blocks with time intervals less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm.
[0078] After encryption, an encrypted data block is formed. Security and integrity verification information is generated for the encrypted data block to achieve tamper detection and traceability.
[0079] The working principle and effect of the above technical solution are as follows: The industrial control computer (ICC) collects and stores the operating parameters of the production process at preset time intervals, and organizes these parameters into raw backup data blocks. Each raw data block is assigned a unique number for subsequent management and retrieval. The collected raw data blocks are encrypted, and the strength of the encryption algorithm is differentiated according to the different data collection cycles (i.e., the time intervals covered by the data blocks). For data blocks with time intervals greater than a first preset threshold, their importance or sensitivity is considered relatively low, and a low-strength encryption algorithm is used to encrypt them, balancing security and efficiency. For data blocks with time intervals less than or equal to the first preset threshold, their importance or sensitivity is considered high, and a high-strength encryption algorithm is used to encrypt them to enhance their security and prevent data leakage or tampering. After the data blocks are encrypted, secure integrity verification information (such as hash values, digital signatures, etc.) is generated for the encrypted data blocks. This verification information is stored along with the data blocks for subsequent tampering detection and data traceability. By setting different encryption strengths for data blocks of varying importance, a balance is struck between computational efficiency and data protection, thereby enhancing the overall level of data security. High-strength encryption is used for data during critical periods (such as anomalies or important process nodes) to ensure that critical data is not illegally accessed or leaked. Low-strength encryption is used for data during ordinary periods, improving data processing and storage efficiency and reducing resource consumption. By generating and saving security and integrity verification information for data blocks, it is possible to detect data tampering in a timely manner. Furthermore, in the event of a security incident, data can be traced back to its source using the block number and verification information, ensuring traceability throughout the entire production process. The data collection time interval and encryption threshold can be adjusted according to actual production needs, flexibly adapting to data management requirements in different scenarios. Through block numbering, differentiated encryption, and integrity verification of industrial control computer production data, an efficient, flexible, and secure data backup and monitoring system is achieved, effectively preventing unauthorized data reading and tampering, while facilitating event tracing and data management.
[0080] In one embodiment of the present invention, operating parameters of a production process stored in an industrial control computer are acquired to form an original backup data block. The operating parameters are acquired at preset time intervals, including:
[0081] Set and acquire the operating parameters of the production process stored in the industrial control computer. The operating parameters include: temperature, pressure, speed, current and valve opening.
[0082] The acquisition service is started according to a preset time period by the operating system timer. The acquisition service sends a read command to the target field device and calls the corresponding communication interface to obtain the acquired values of the operating parameters.
[0083] The system uses an industrial control protocol to poll and read the collected values of operating parameters according to a set address, and performs preliminary verification on the collected values of operating parameters. The preliminary verification includes: range detection, parity check, breakpoint supplementation sampling, and exclusion of abnormal sampling.
[0084] The collected values of the verified operating parameters are formed into a data sampling stream D = {d1, d2, ..., d...} n};
[0085] The backup time interval is calculated based on the data sampling stream. Original backup data blocks are formed according to the backup time interval, and these original backup data blocks are numbered. The calculation of the backup time interval includes:
[0086] Periodic calculation of the change index:
[0087]
[0088] Where Δ(t) represents the exponent of change, d i (t) represents the value of the i-th data point at time t, d i (t-1) represents the value of the i-th data point at time t-1, and N represents the total number of operating parameters;
[0089] Adaptive calculation of backup time interval:
[0090] T next =min{T max ,max{T min ,α·e -β·Δ(t)}};
[0091] Among them, T next T represents the time window for backing up the next data block. min T represents the minimum backup time interval. max This represents the maximum backup time interval, and α and β represent sensitivity coefficients.
[0092] The working principle and effect of the above technical solution are as follows: The industrial control computer periodically collects key operating parameters such as temperature, pressure, speed, current, and valve opening. This collection is achieved through periodic calls to services via the operating system's timer. The services communicate with the corresponding field devices through the industrial control protocol to obtain the collected values. Preliminary verification of the collected parameter values is performed, including range checking, parity checking, re-collection in case of breakpoints, and removal of abnormal samples, ensuring data quality and continuity. The verified data parameters are sequentially arranged into a data sampling stream D = {d1, d2, ..., d...}. n This lays the foundation for subsequent analysis and storage. The time interval is calculated, and the original data blocks are packaged and numbered according to the calculated time interval for use in secure encryption, archiving, and other processes. The change index Δ(t) is essentially a measure of the "energy of time series fluctuations." The squared difference between the current and previous periods for each parameter is taken, and the summation is applied to the mean of all parameters. This ensures that the index increases significantly when fluctuations surge (such as accidents or changes in operating conditions). Using the square avoids the cancellation of positive and negative changes, while using the mean is suitable for systems with multiple parameters changing collaboratively. Backup interval t next Using exponential decay: a slight change in Δ(t) will cause T to... next Significantly reduces (speeds up backup) and improves responsiveness; for periods with small data fluctuations, the exponential function decreases T. next Increased efficiency effectively reduces the frequency of invalid data backups; the α and β sensitivity adjustment coefficients ensure that the response speed can be adjusted according to specific industrial control scenarios; T min and T max It enforces boundary protection to prevent excessively frequent or sparse backups due to extreme fluctuations or static stability; it adaptively adjusts, is intelligent and efficient, and dynamically adjusts backup timing according to real-time field fluctuations, with high backup frequency during periods of high volatility to meet security and anomaly tracking requirements; it reduces backup frequency during stable operation, saving storage and resources; multiple parameter changes jointly reflect operating conditions, ensuring no systemic risks caused by single parameter anomalies are overlooked; anomaly detection and historical tracing, with automatic intensive backup collection during drastic changes, greatly enhances the ability to detect and trace abnormal events; it saves resources and is easy to manage, with effective sampling reducing redundant data storage, facilitating subsequent archiving, analysis, and encryption, allowing resources to be invested in the most critical aspects; it is highly scalable and adjustable, with sensitivity and interval upper and lower limits that can be flexibly adjusted to adapt to the needs of different industrial processes and risk levels.
[0093] In one embodiment of the present invention, the original data block is encrypted based on the acquisition time interval of the original data block. Time blocks with a time interval greater than a first preset threshold are encrypted using a low-strength encryption algorithm, while time blocks with a time interval less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm. This includes:
[0094] The acquisition time interval of the original data block is obtained, and the acquisition time interval of the original data block is compared with a first preset threshold. If the acquisition time interval is greater than the first preset threshold, the original data block is encrypted by a low-strength encryption algorithm, including AES-128 and SM4-128, and random perturbation is added to the low-strength encryption algorithm.
[0095] If the acquisition time interval is less than or equal to a first preset threshold, the original data block is encrypted using a high-strength encryption algorithm, including AES-256 and SM4-256.
[0096] In one embodiment of the present invention, the low-strength encryption algorithm incorporates random perturbations, including:
[0097] For each data block encrypted using a low-strength encryption algorithm, the system master key K is used. master Partition block number j and timestamp T j Derived independent subkey:
[0098] K j =KDF(K master ,j,T j );
[0099] Wherein, KDF represents the key derivation function, which includes PBKDF2, HKDF, and SM3-HMAC, j represents the partition block number, and T... j Represents a timestamp;
[0100] Then through the system master key K master Partition block number j and timestamp T j Block-specific perturbation salt:
[0101] Salt j =PRF(K master ,j||T j );
[0102] Salt j This represents the block-specific perturbation salt for the j-th partition, PRF represents a pseudo-random function, and || represents a join operation.
[0103] First, connect the data block to Salt. j Perform XOR masking:
[0104]
[0105] Then, perform hierarchical encryption using an automatic allocation algorithm (such as AES-128 or AES-256) to obtain the final ciphertext C. j :
[0106]
[0107] The working principle and effect of the above technical solution are as follows: The system obtains the acquisition time interval of each raw data block and compares it with a preset threshold. Low-strength encryption is triggered. If the interval is greater than the threshold, low-strength encryption algorithms such as AES-128 or SM4-128 are used, and random perturbation is superimposed to enhance security. If the interval is less than or equal to the threshold, high-strength encryption algorithms such as AES-256 or SM4-256 are used to improve the encryption strength of critical data. Using the system master key, partition block number and timestamp, a unique subkey K is derived through key derivation functions (KDF, such as PBKDF2, HKDF, SM3-HMAC). j —This way, even if the master key is the same, the password for each data block is different, improving resistance to attacks; by combining the master key, block number j, and timestamp with a pseudo-random function (PRF), a unique perturbation salt (Salt) is generated for each block. j (In reality, it's a unique random number based on the block number and collection time); using Salt j By XORing the original data block and applying a perturbation mask, even if the plaintext or encrypted password has been leaked, the uniqueness of each perturbation salt increases the security level; the perturbed B' j Using an automatically assigned encryption algorithm (such as AES-128 or AES-256) with K j The key is then finally encrypted to obtain ciphertext C. j Ordinary data is encrypted with low strength but with superimposed strong scrambling and block-derived keys to prevent mass decryption and key reuse attacks. Since the ordinary data in this application is measured by its degree of variability, and because it is encrypted using a low-strength encryption algorithm, a scrambling salt design is incorporated to prevent attackers from deducing other ordinary data after corrupting one block. This ensures that even if an attacker cracks one block of ordinary data, they cannot recover the other blocks. Each block's subkey derivation and unique scrambling salt design prevent attackers from deducing other block keys even if a partition or part of the subkeys are leaked, enhancing defense-in-depth and distributed storage security. After data block scrambling, it is difficult to establish a direct relationship between the original data and the ciphertext, reducing the plaintext attack surface. Because each scrambling salt is different, even if an attacker obtains multiple ciphertexts, they cannot extract usable information through comparison. This scheme, with "hierarchical, random, and block-based" as its core, achieves agile, efficient, and in-depth industrial control data security protection. It not only prevents the risk of mass decryption due to key reuse but also effectively resists ciphertext analysis and known-plaintext attacks.
[0108] In one embodiment of the present invention, encrypted data blocks are formed after encryption, and security and integrity verification information is generated for the encrypted data blocks to realize backup data tampering detection and traceability, including:
[0109] A hash chain is constructed by calculating a separate hash value for each encrypted data block using a hash algorithm. j =H(C j ||hash j-1 );
[0110] hash j With backup data encrypted C j They are stored together, and before decryption, the hash value is compared to verify whether the backup data has been tampered with.
[0111] One embodiment of the present invention provides a data security backup system for industrial control computers based on an encryption algorithm, the system comprising:
[0112] The module for acquiring operating parameters is used to acquire the operating parameters of the production process stored in the industrial control computer, form original backup data blocks, number the original backup data blocks, and acquire the operating parameters at preset time intervals.
[0113] An encryption module is used to encrypt the original data blocks. Time blocks with a time interval greater than a first preset threshold are encrypted using a low-strength encryption algorithm, and time blocks with a time interval less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm.
[0114] The verification module encrypts data to form encrypted data blocks and generates security and integrity verification information for these encrypted data blocks, enabling tamper detection and traceability.
[0115] In one embodiment of the present invention, the module for obtaining operating parameters includes:
[0116] The parameter acquisition module is used to set and acquire the operating parameters of the production process stored in the industrial control computer. The operating parameters include: temperature, pressure, speed, current and valve opening.
[0117] The calling module is used to schedule the start of the acquisition service according to a preset time period through the operating system timer. The acquisition service sends a read command to the target field device and calls the corresponding communication interface to obtain the acquired values of the operating parameters.
[0118] The preliminary verification module is used to poll and read the collected values of the operating parameters according to the set address through the industrial control protocol, and to perform preliminary verification on the collected values of the operating parameters. The preliminary verification includes: range detection, parity check, breakpoint supplementation and elimination of abnormal sampling.
[0119] The data sampling stream module is used to form a data sampling stream D = {d1, d2, ..., d...} from the collected values of the verified operating parameters. n};
[0120] The backup time interval calculation module is used to calculate the backup time interval based on the data sampling stream, form raw backup data blocks according to the backup time interval, and number the raw backup data blocks. The calculation of the backup time interval includes:
[0121] Periodic calculation of the change index:
[0122]
[0123] Where Δ(t) represents the exponent of change, d i (t) represents the value of the i-th data point at time t, d i (t-1) represents the value of the i-th data point at time t-1, and N represents the total number of operating parameters;
[0124] Adaptive calculation of backup time interval:
[0125] T next =min{T max ,max{T min ,α·e -β·Δ(t)}};
[0126] Among them, T next T represents the time window for backing up the next data block. min T represents the minimum backup time interval. max This represents the maximum backup time interval, and α and β represent sensitivity coefficients.
[0127] In one embodiment of the present invention, the encryption module includes:
[0128] A low-strength encryption module is used to obtain the acquisition time interval of the original data block, compare the acquisition time interval of the original data block with a first preset threshold, and if the acquisition time interval is greater than the first preset threshold, then the original data block is encrypted by a low-strength encryption algorithm. The low-strength encryption algorithm includes AES-128 and SM4-128, and the low-strength encryption algorithm incorporates random perturbation.
[0129] A high-strength encryption module is used to encrypt the original data block using a high-strength encryption algorithm if the acquisition time interval is less than or equal to a first preset threshold. The high-strength encryption algorithm includes AES-256 and SM4-256.
[0130] In one embodiment of the present invention, the low-strength encryption module includes:
[0131] The derived independent subkey module, for each data block encrypted using a low-strength encryption algorithm, uses the system master key K. master Partition block number j and timestamp T j Derived independent subkey:
[0132] K j =KDF(K master ,j,T j );
[0133] Wherein, KDF represents the key derivation function, which includes PBKDF2, HKDF, and SM3-HMAC, j represents the partition block number, and T... j Represents a timestamp;
[0134] A dedicated perturbation salt module for generating blocks is used to further process the system master key K. master Partition block number j and timestamp T j Block-specific perturbation salt:
[0135] Salt j =PRF(K master ,j||T j );
[0136] Salt j This represents the block-specific perturbation salt for the j-th partition, PRF represents a pseudo-random function, and || represents a join operation.
[0137] The mask module is used to first mask the data block with Salt. j Perform XOR masking:
[0138]
[0139] The final ciphertext generation module is used to further encrypt the final ciphertext C using an automatic allocation algorithm (such as AES-128 or AES-256). j :
[0140]
[0141] In one embodiment of the present invention, the verification module includes:
[0142] The module for calculating individual hash values is used to compute an individual hash value for each encrypted data block using a hash algorithm, thus constructing a hash chain: hash j =H(C j ||hash j-1 );
[0143] The comparison module is used to compare the hash. j With backup data encrypted C j They are stored together, and before decryption, the hash value is compared to verify whether the backup data has been tampered with.
[0144] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A method for secure data backup of industrial control computers based on encryption algorithms, characterized in that, The method includes: The operating parameters of the production process stored in the industrial control computer are obtained to form original backup data blocks. The original backup data blocks are numbered, and the operating parameters are obtained at preset time intervals. The original data blocks are encrypted, and time blocks with time intervals greater than a first preset threshold are encrypted using a low-strength encryption algorithm, while time blocks with time intervals less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm. After encryption, an encrypted data block is formed. Security and integrity verification information is generated for the encrypted data block to achieve tamper detection and traceability.
2. The method for secure data backup of industrial control computers based on encryption algorithms according to claim 1, characterized in that, The system acquires the operating parameters of the production process stored in the industrial control computer to form a raw backup data block. These operating parameters are acquired at preset time intervals, including: Set and acquire the operating parameters of the production process stored in the industrial control computer. The operating parameters include: temperature, pressure, speed, current and valve opening. The acquisition service is started according to a preset time period by the operating system timer. The acquisition service sends a read command to the target field device and calls the corresponding communication interface to obtain the acquired values of the operating parameters. The system uses an industrial control protocol to poll and read the collected values of operating parameters according to a set address, and performs preliminary verification on the collected values of operating parameters. The preliminary verification includes: range detection, parity check, breakpoint supplementation sampling, and exclusion of abnormal sampling. The collected values of the verified operating parameters are formed into a data sampling stream D = {d1, d2, ..., d...} n }; The backup time interval is calculated based on the data sampling stream. Original backup data blocks are formed according to the backup time interval, and these original backup data blocks are numbered. The calculation of the backup time interval includes: Periodic calculation of the change index: Where Δ(t) represents the exponent of change, d i (t) represents the value of the i-th data point at time t, d i (t-1) represents the value of the i-th data point at time t-1, and N represents the total number of operating parameters; Adaptive calculation of backup time interval: T next =min{T max ,max{T min ,α·e -β·Δ(t) }}; Among them, T next T represents the time window for backing up the next data block. min T represents the minimum backup time interval. max This represents the maximum backup time interval, and α and β represent sensitivity coefficients.
3. The method for secure data backup of an industrial control computer based on an encryption algorithm according to claim 1, characterized in that, Encrypting the original data block based on the acquisition time interval of the original data block, wherein time blocks with a time interval greater than a first preset threshold are encrypted using a low-strength encryption algorithm, and time blocks with a time interval less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm, including: The acquisition time interval of the original data block is obtained, and the acquisition time interval of the original data block is compared with a first preset threshold. If the acquisition time interval is greater than the first preset threshold, the original data block is encrypted by a low-strength encryption algorithm, including AES-128 and SM4-128, and random perturbation is added to the low-strength encryption algorithm. If the acquisition time interval is less than or equal to a first preset threshold, the original data block is encrypted using a high-strength encryption algorithm, including AES-256 and SM4-256.
4. The method for secure data backup of an industrial control computer based on an encryption algorithm according to claim 3, characterized in that the low-strength encryption algorithm incorporates random perturbations, including: For each data block encrypted using a low-strength encryption algorithm, the system master key K is used. master Partition block number j and timestamp T j Derived independent subkey: K j =KDF(K master ,j,T j ); Wherein, KDF represents the key derivation function, which includes PBKDF2, HKDF, and SM3-HMAC, j represents the partition block number, and T... j Represents a timestamp; Then through the system master key K master Partition block number j and timestamp T j Dedicated perturbation salt for generating blocks: Salt j =PRF(K master ,j||T j ); Salt j This represents the block-specific perturbation salt for the j-th partition, PRF represents a pseudo-random function, and || represents a join operation. First, connect the data block to Salt. j Perform XOR masking: Then, perform hierarchical encryption using an automatic allocation algorithm (such as AES-128 or AES-256) to obtain the final ciphertext C. j :
5. The method for secure data backup of an industrial control computer based on an encryption algorithm according to claim 1, characterized in that, After encryption, encrypted data blocks are formed. Security and integrity verification information is generated for these encrypted data blocks to enable backup data tampering detection and traceability, including: A hash chain is constructed by calculating a separate hash value for each encrypted data block using a hash algorithm. j =H(C j ||hash j-1 ); hash j With backup data encrypted C j They are stored together, and before decryption, the hash value is compared to verify whether the backup data has been tampered with.
6. A data security backup system for industrial control computers based on encryption algorithms, characterized in that, The system includes: The module for acquiring operating parameters is used to acquire the operating parameters of the production process stored in the industrial control computer, form original backup data blocks, number the original backup data blocks, and acquire the operating parameters at preset time intervals. An encryption module is used to encrypt the original data blocks. Time blocks with a time interval greater than a first preset threshold are encrypted using a low-strength encryption algorithm, and time blocks with a time interval less than or equal to the first preset threshold are encrypted using a high-strength encryption algorithm. The verification module encrypts data to form encrypted data blocks and generates security and integrity verification information for these encrypted data blocks, enabling tamper detection and traceability.
7. The industrial control computer data security backup system based on encryption algorithm according to claim 6, characterized in that, The module for obtaining operating parameters includes: The parameter acquisition module is used to set and acquire the operating parameters of the production process stored in the industrial control computer. The operating parameters include: temperature, pressure, speed, current and valve opening. The calling module is used to schedule the start of the acquisition service according to a preset time period through the operating system timer. The acquisition service sends a read command to the target field device and calls the corresponding communication interface to obtain the acquired values of the operating parameters. The preliminary verification module is used to poll and read the collected values of the operating parameters according to the set address through the industrial control protocol, and to perform preliminary verification on the collected values of the operating parameters. The preliminary verification includes: range detection, parity check, breakpoint supplementation and elimination of abnormal sampling. The data sampling stream module is used to form a data sampling stream D = {d1, d2, ..., d...} from the collected values of the verified operating parameters. n }; The backup time interval calculation module is used to calculate the backup time interval based on the data sampling stream, form raw backup data blocks according to the backup time interval, and number the raw backup data blocks. The calculation of the backup time interval includes: Periodic calculation of the change index: Where Δ(t) represents the exponent of change, d i (t) represents the value of the i-th data point at time t, d i (t-1) represents the value of the i-th data point at time t-1, and N represents the total number of operating parameters; Adaptive calculation of backup time interval: T next =min{T max ,max{T min ,α·e -β·Δ(t) }}; Among them, T next T represents the time window for backing up the next data block. min T represents the minimum backup time interval. max This represents the maximum backup time interval, and α and β represent sensitivity coefficients.
8. The industrial control computer data security backup system based on encryption algorithm according to claim 6, characterized in that, The encryption module includes: A low-strength encryption module is used to obtain the acquisition time interval of the original data block, compare the acquisition time interval of the original data block with a first preset threshold, and if the acquisition time interval is greater than the first preset threshold, then the original data block is encrypted by a low-strength encryption algorithm. The low-strength encryption algorithm includes AES-128 and SM4-128, and the low-strength encryption algorithm incorporates random perturbation. A high-strength encryption module is used to encrypt the original data block using a high-strength encryption algorithm if the acquisition time interval is less than or equal to a first preset threshold. The high-strength encryption algorithm includes AES-256 and SM4-256.
9. The industrial control computer data security backup system based on encryption algorithm according to claim 8, characterized in that, The low-strength encryption module includes: The derived independent subkey module, for each data block encrypted using a low-strength encryption algorithm, uses the system master key K. master Partition block number j and timestamp T j Derived independent subkey: K j =KDF(K master ,j,T j ); Wherein, KDF represents the key derivation function, which includes PBKDF2, HKDF, and SM3-HMAC, j represents the partition block number, and T... j Represents a timestamp; A dedicated perturbation salt module for generating blocks is used to further process the system master key K. master Partition block number j and timestamp T j Dedicated perturbation salt for generating blocks: Salt j =PRF(K master ,j||T j ); Salt j This represents the block-specific perturbation salt for the j-th partition, PRF represents a pseudo-random function, and || represents a join operation. The mask module is used to first mask the data block with Salt. j Perform XOR masking: The final ciphertext generation module is used to further encrypt the final ciphertext C using an automatic allocation algorithm (such as AES-128 or AES-256). j :
10. The industrial control computer data security backup system based on encryption algorithm according to claim 6, characterized in that, The verification module includes: The module for calculating individual hash values is used to compute an individual hash value for each encrypted data block using a hash algorithm, thus constructing a hash chain: hash j =H(C j ||hash j-1 ); The comparison module is used to compare the hash. j With backup data encrypted C j They are stored together, and before decryption, the hash value is compared to verify whether the backup data has been tampered with.