Chemical industrial park operation data protection method and system based on industrial internet
By generating and managing temporary credentials to dynamically adjust data access permissions, the problem of excessive data exposure in the intelligent operation of chemical industrial parks is solved, achieving refined and context-aware data protection, and improving security and flexibility.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING ARK INTELLIGENT GARDEN INFORMATION TECHNOLOGY CO LTD
- Filing Date
- 2026-03-18
- Publication Date
- 2026-06-23
AI Technical Summary
The existing static data protection mechanism cannot dynamically adjust permissions according to the intelligent operation needs of the chemical industrial park, resulting in the excessive exposure of sensitive data when it is not necessary. It lacks context awareness and cannot distinguish between authorized access and the actual access required at present.
By receiving task information from the analysis module, a temporary credential for the main task with a limited validity period and data access permissions is generated. The credential is verified and automatically expires when the task is completed or expires, thus realizing dynamic and contextualized data access control.
It effectively solves the limitations of traditional static permission management in intelligent operation scenarios, improves the flexibility and security of data protection, prevents unauthorized or out-of-task data access, and reduces security risks.
Smart Images

Figure CN122263156A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the technical field of industrial internet data protection, specifically to a method and system for protecting operational data of chemical industrial parks based on the industrial internet. Background Technology
[0002] In modern industrial operations, especially in large chemical industrial parks, the application of industrial internet technology is crucial for improving efficiency and ensuring safety. These parks typically employ a multi-tiered structure, comprising a central control center and multiple independent sub-parks, each equipped with specialized production and monitoring systems. While this architecture facilitates comprehensive management, it also presents significant challenges in data protection. Traditional data security methods rely on static access control rules based on pre-defined data sensitivity and user roles, performing well when handling routine, stable operational tasks.
[0003] The intelligent operations analysis system has continuously gained access to large amounts of sensitive data without necessary intervention. If the system itself has vulnerabilities or its service accounts are maliciously exploited, this sensitive data, which should only be accessed in specific contexts, may face unnecessary exposure risks. The park's data protection system, due to its static rules and lack of context awareness, considers this continuous and broad data access "compliant" because it conforms to the initially manually configured permission list. The system cannot issue alerts or automatically block this "unreasonable" data flow in the current operational context because it cannot distinguish between "authorized access" and "currently needed access." This risk of "compliant but unreasonable" data exposure is a serious challenge faced by existing static data protection mechanisms in dealing with the increasingly complex needs of intelligent operations.
[0004] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention
[0005] This application discloses a method and system for protecting operational data in chemical industrial parks based on the Industrial Internet. It aims to address the problems of existing static data protection mechanisms failing to dynamically adjust permissions according to constantly changing operational scenarios when facing increasingly complex intelligent operation needs. This results in data access being technically "compliant" but "unreasonable" in terms of actual necessity, thus posing a continuous risk of excessive exposure of sensitive data. Furthermore, the system lacks a mechanism to understand contextual logic, failing to distinguish between "authorized access" and "currently needed access," leading to the risk of "compliant but unreasonable" data exposure.
[0006] The technical solution of this application is as follows: Firstly, this application discloses a method for protecting operational data of chemical industrial parks based on the Industrial Internet, including: Receive task information from the analysis module; the task information includes the purpose of the analysis work, the scope of required data resources, and the expected duration. Based on the task information and in conjunction with the access rule base, generate temporary credentials for the main task with a limited valid time period and data access permissions. When the analysis module initiates a data acquisition request, it performs a voucher verification judgment on the validity of the temporary voucher information of the main task, the limited validity period, and the data access permissions, obtains the verification pass judgment result, and allows the analysis module to acquire the corresponding data resources when the verification pass judgment result is passed; When the analysis module completes its analysis or the validity period of the temporary voucher information for the main task expires, the corresponding temporary voucher information for the main task becomes invalid to protect operational data.
[0007] Through this technical solution, this application can dynamically generate temporary credentials with limited validity periods and data access permissions based on the task information of the analysis module, and invalidate them when the task is completed or the credentials expire. This effectively solves the problem that traditional static permission management cannot adapt to the dynamic data access needs of intelligent operation analysis systems, avoids the risk of excessive exposure of sensitive data, and realizes refined and context-aware operation data protection.
[0008] Secondly, this application also discloses a chemical industrial park operation data protection system based on the Industrial Internet, used to perform operation data protection for chemical industrial parks based on the Industrial Internet, including: The task information receiving module is used to receive task information from the analysis module; the task information includes the purpose of the analysis work, the scope of required data resources, and the expected duration. The temporary credential generation module is used to generate temporary credential information for the main task with limited validity period and data access permissions based on task information and in conjunction with the access rule base. The voucher verification and judgment module is used to perform voucher verification and judgment on the validity, limited validity period and data access permissions of the temporary voucher information of the main task when the analysis module initiates a data acquisition request, obtain the verification pass judgment result, and allow the analysis module to acquire the corresponding data resources when the verification pass judgment result is pass; The data protection execution module is used to invalidate the corresponding temporary voucher information of the main task when the analysis module completes the analysis work or when the limited validity period of the temporary voucher information of the main task expires, so as to realize the protection of operational data.
[0009] This application provides a system-level solution through this technical solution. Through modular design, it realizes the reception of task information, generation of temporary vouchers, verification and judgment of vouchers, and execution of data protection. This enables efficient and automated management of access permissions for chemical industrial park operation data, effectively solving the limitations of traditional static permission management in intelligent operation scenarios and improving the flexibility and security of data protection.
[0010] Beneficial Effects: This application discloses a method for protecting operational data in chemical industrial parks based on the Industrial Internet. It receives task information from an analysis module, including the purpose of the analysis, the required data resource scope, and the expected duration. Based on this task information and an access rule base, a temporary credential with a limited validity period and data access permissions is generated. When the analysis module initiates a data acquisition request, it verifies the validity, limited validity period, and data access permissions of the temporary credential. If the verification is successful, the analysis module is allowed to acquire the corresponding data resources. When the analysis module completes its analysis or the limited validity period of the temporary credential expires, the temporary credential becomes invalid, thus achieving operational data protection.
[0011] This method introduces the concepts of "task information" and "temporary credential information for the main task" to achieve dynamic and contextualized management of data access permissions. Compared with the shortcomings of existing technologies that rely on static and broad permissions, this application can accurately generate temporary credentials with time-limited validity and scope restrictions based on the specific purpose of the analysis work, the required data resources, and the expected duration. This means that the data access permissions of the intelligent operation analysis system will be dynamically adjusted when performing different tasks, and access will only be granted to necessary data resources within the necessary timeframe. Once the task is completed or the credential expires, the permissions will automatically become invalid, thereby fundamentally solving the risk of "compliant but unreasonable" excessive data exposure.
[0012] Specifically, this method, through a credential verification mechanism, ensures that each data retrieval request matches the currently active temporary credential, effectively preventing unauthorized or out-of-task data access. This fine-grained control ensures that even if the intelligent operation analysis system itself has potential vulnerabilities or its service account is exploited, the scope of exploitable data access is limited to what is needed for the current task, significantly reducing the potential attack surface. Furthermore, the automatic credential expiration mechanism avoids the security risks that may arise from long-term broad permissions, improving the flexibility, security, and responsiveness of the entire chemical industrial park's operational data protection system. Therefore, this application effectively solves the problem that existing static data protection mechanisms cannot adapt to the dynamic data access needs of intelligent operation analysis systems, significantly improving the security of chemical industrial park operational data. Attached Figure Description
[0013] Figure 1 This is a flowchart of a method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in one embodiment of the present invention. Figure 2 This is a flowchart of a method for protecting operational data of a chemical industrial park based on the Industrial Internet, as shown in another embodiment of the present invention. Figure 3 This is a system block diagram of a chemical industrial park operation data protection system based on the Industrial Internet, according to another embodiment of the present invention. Explanation of reference numerals in the attached figures: 1. Industrial Internet-based chemical industrial park operation data protection system; 11. Task information receiving module; 12. Temporary voucher generation module; 13. Voucher verification and judgment module; 14. Data protection execution module. Detailed Implementation
[0014] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. The components of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.
[0015] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0016] This application discloses a method for protecting operational data of chemical industrial parks based on the Industrial Internet, combined with... Figure 1 As shown, it includes: S1 receives task information from the analysis module; the task information includes the purpose of the analysis work, the required data resource scope, and the expected duration. S2, Based on the task information and in conjunction with the access rule base, generate temporary credential information for the main task with a limited valid time period and data access permissions; S3, when the analysis module initiates a data acquisition request, it performs a voucher verification judgment on the validity of the temporary voucher information of the main task, the limited validity period, and the data access permissions, obtains the verification pass judgment result, and allows the analysis module to acquire the corresponding data resources when the verification pass judgment result is pass; S4. When the analysis module completes the analysis work or the limited validity period of the main task temporary voucher information expires, the corresponding main task temporary voucher information is invalidated to achieve operational data protection.
[0017] To better understand the method proposed in this application, we will first explain some key terms and their application environments. The "analysis module" refers to a computing unit within the industrial internet system of a chemical industrial park that undertakes data processing and analysis tasks. This unit can be a software service deployed on a cloud platform, edge server, or local control system, or it can be a dedicated data processing device. The main function of the analysis module is to process and analyze park operational data. Its application scenarios include production process optimization, predictive maintenance of equipment, energy management, safety risk assessment, and production efficiency analysis. When performing the above analysis tasks, the analysis module typically needs to access data resources from multiple production systems; therefore, its access permissions need to be strictly managed through security control mechanisms.
[0018] "Task Information" refers to a set of data submitted by the analysis module when initiating a data analysis request, describing the requirements of the analysis task. Task information explains key aspects such as the purpose of the analysis, the required data range, and the expected task duration. Specifically, "Purpose of Analysis" indicates the specific objective of the task, such as fault diagnosis, energy consumption optimization, or production forecasting; "Required Data Resource Range" describes the data types, sources, and time ranges required for access, such as historical operating data of a device, real-time temperature data, or pressure monitoring data for a specific time period; and "Expected Duration" indicates the expected execution time of the analysis task, such as two hours, half a day, or a full day. This task information allows the data protection system to accurately understand the data access requirements of the analysis module, providing a basis for subsequent dynamic authorization.
[0019] An "access rule base" is a database system used to store data access policies. It predefines access control rules for different task types, data resources, and security levels. The access rule base can record various rules, such as the data types allowed for access under a specific analytical purpose, the allowed time range for access, and the corresponding permission levels. Through the rule matching mechanism of the access rule base, necessary data access permissions can be provided for analytical tasks while ensuring data security.
[0020] "Temporary credential information for the main task" is a key data object in the dynamic authorization mechanism proposed in this application. This credential is an access token valid during task execution, with its access permissions and validity period dynamically generated based on specific task requirements. Unlike traditional static permission management methods, the temporary credential information for the main task explicitly specifies the scope of allowed data resources and the allowed time interval during its generation, thereby achieving on-demand authorization and least privilege control. This approach avoids the security risks associated with long-term authorization.
[0021] "Data resources" refer to various types of data generated or stored during the production and operation of chemical industrial parks, such as equipment operating parameters, production process data, environmental monitoring data, safety monitoring data, and personnel activity records. These data are typically distributed across different information systems or databases and serve as crucial foundational resources for intelligent analysis by analytical modules.
[0022] This application provides a method for protecting operational data of chemical industrial parks based on the Industrial Internet. Its core idea is to use a task-driven dynamic authorization mechanism to finely manage the data access behavior of the analysis module, thereby improving data security while ensuring data availability.
[0023] In the implementation process, the system first receives task information from the analysis module. When the analysis module needs to execute a new data analysis task, it sends the corresponding task information to the data protection system. For example, when the analysis module prepares to execute a predictive maintenance analysis task for a production unit, its task information may include the analysis purpose being predictive maintenance, the required data resources being the unit's historical operating data and real-time vibration monitoring data, and the expected duration being four hours. Task information can be transmitted through standardized interfaces, such as submitting it in a structured data format via a REST API interface, or publishing it through a message queue service, enabling the data protection system to receive and process this task information in real time.
[0024] Upon receiving the task information, the system generates a temporary credential with limited validity periods and data access permissions based on the task information and an access rule base. Specifically, the data protection system first parses the analysis purpose, data requirement scope, and expected execution time from the task information, and then matches these details against rules in the access rule base. For example, the access rule base might contain a rule: when the analysis task's purpose is predictive maintenance and involves a specific device, access to the device's historical operating data and real-time vibration monitoring data is permitted, with a default validity period of four hours. Based on the matched rule and the time parameters in the task information, the system generates the corresponding temporary credential for the main task. This credential contains permission information such as limited validity periods and the scope of permitted data resources, and can be protected using digital signatures or encryption technology to ensure the security and integrity of the credential during transmission and use.
[0025] When the analysis module subsequently initiates a data acquisition request, it needs to submit the temporary credential information for the main task along with it. Upon receiving the data acquisition request, the data access proxy service first verifies the credential, including checking the digital signature to confirm it hasn't been tampered with. The system then checks the valid time period in the credential to determine if the current time is within the credential's allowed access time range. Simultaneously, the system performs permission matching on the data resource requested by the analysis module to determine if it falls within the credential's authorized access range. If the credential verification is successful, the valid time period hasn't expired, and the accessed data resource is within the authorized range, the credential verification result is considered passed, and the data access proxy service allows the analysis module to acquire the corresponding data resource. If any condition is not met, the verification result is considered failed, thus rejecting the data access request.
[0026] To prevent prolonged access permissions after task completion, this method also includes a credential expiration mechanism. Once the analysis module finishes its data analysis, it can report the task completion status to the system via an interface. At this point, the system will immediately invalidate the corresponding temporary credential information for the main task. Furthermore, when the system detects that the limited validity period of the temporary credential information for the main task has expired, it will also automatically mark the credential as invalid. Expired credentials can no longer be used for data access requests, thus achieving timely revocation of data access permissions.
[0027] Through the aforementioned mechanism, this application implements a task-driven data access control method, ensuring that the analysis module can only access necessary data resources during task execution and automatically revokes access permissions after the task ends. This dynamic authorization and automatic expiration mechanism effectively reduces the security risks associated with long-term authorizations, prevents excessive data access or abuse, and thus improves the overall security level of operational data while ensuring the efficiency of industrial internet data sharing in chemical industrial parks.
[0028] Optionally, the step of generating temporary credentials for the main task with limited validity periods and data access permissions based on task information and in conjunction with the access rule base further includes: emergency permission extension processing, which includes: Pre-identify threshold exceedance risk anomalies within the park, and for each threshold exceedance risk anomaly, determine the data set required for emergency analysis; threshold exceedance risk anomalies are anomalies that characterize the occurrence of threshold exceedance of monitoring indicators; For each threshold exceedance risk event, generate and digitally sign emergency extension credential template information; the emergency extension credential template information includes default validity period information, authorized access data resource list information, and allowed operation type information; Emergency extended credential template information is distributed and stored in the local storage area of the data access agent service to form an emergency template library; When the analysis module detects an event that matches the predefined threshold risk abnormality during the execution of the main task, it sends an emergency permission extension request to the corresponding data access proxy service. The emergency permission extension request includes the main task identification code, the abnormal event identifier, the extension reason, and carries the temporary credential information of the currently active main task as authentication information. After verifying the validity of the temporary credential information for the main task, the data access proxy service matches the information in the emergency template library based on the abnormal event identifier information to obtain the matched emergency extended credential template information. The data access proxy service instantiates and digitally signs temporary extended credential information based on the matched emergency extended credential template information and the current time. The extended authorization scope of the temporary extended credential information is limited to the data set predefined by the emergency extended credential template information, and the temporary extended credential information is returned to the analysis module. The analysis module stores temporary extended credentials and main task temporary credentials, and sends a data request to the data access proxy service with the temporary extended credentials and main task temporary credentials when accessing emergency data. The data access proxy service performs credential verification and judgment on both the temporary extended credential information and the main task temporary credential information, and merges the authorization scope information of the temporary extended credential information and the main task temporary credential information to form combined authorization scope information; When the data requested and the operation fall within the scope of the combined authorization information, the analysis module is allowed to obtain the data; When the temporary extended credential information expires, the data access proxy service will refuse to use the temporary extended credential information in subsequent credential verification and judgment.
[0029] Specifically, pre-identifying threshold-exceeding risk anomalies within the industrial park refers to identifying and defining critical operational states that may trigger safety accidents, environmental pollution incidents, or production anomalies before or during the operation of the chemical industrial park system. This is achieved through safety risk assessments, expert experience analysis, and historical operational data statistics. For example, when key process parameters such as reactor temperature, pipeline pressure, material flow rate, or storage tank level exceed preset safety thresholds, specific risk anomalies may be triggered. For these identified anomalies, the system needs to pre-define the range of data resources that the analysis module needs to access when an anomaly occurs, thus forming a data set required for emergency analysis. This allows for the rapid acquisition of necessary data for diagnosis and handling in emergency situations.
[0030] Specifically, an emergency extended credential template is generated and digitally signed for each threshold-exceeding risk event. This template predefines the list of data resources allowed to be accessed, the types of operations allowed to be performed, and the default validity period under the corresponding emergency scenario. For example, in some emergency analysis tasks, only reading real-time monitoring data and historical operation records of relevant devices is permitted, while modification operations are not allowed. By digitally signing the emergency extended credential template, it is ensured that the template is not tampered with during distribution and use, and the credibility of the template's source is guaranteed, thereby improving the overall security of the system.
[0031] In practical applications, emergency extended credential template information is distributed and stored in the local storage area of the data access agent service to form an emergency template library. By storing this template information locally in the data access agent service, the system can quickly generate temporary extended credentials and authorize the analysis module to access emergency data resources without waiting for a response from the central authorization system in the event of an emergency. This local template mechanism can significantly improve the system's response efficiency in the event of an emergency, while also enhancing the system's robustness in the event of network anomalies or the unavailability of the central system.
[0032] When the analysis module detects an event that matches a predefined threshold exceeding risk during the execution of its main task—for example, if real-time monitoring data indicates that a key indicator exceeds a security threshold—the analysis module sends an emergency permission extension request to the corresponding data access proxy service. This request typically includes the main task identifier, the abnormal event identifier, and the reason for the extension. It also carries currently valid temporary credentials for the main task as authentication information to prove that the request originates from a legitimate task.
[0033] Upon receiving an emergency permission extension request, the data access proxy service first verifies the validity of the primary task's temporary credential information, including verifying the digital signature, checking the validity period, and confirming that the credential has not been revoked. Once the verification is successful, the data access proxy service searches for the corresponding emergency extension credential template information in the local emergency template library based on the exception event identifier information provided in the request, to determine the scope of permissions allowed for extension in the current emergency scenario.
[0034] Once a suitable emergency extended credential template is matched, the data access agent service generates a corresponding temporary extended credential based on the template and the current time. This credential is then digitally signed to ensure its integrity and reliability. The extended authorization scope of this temporary extended credential is strictly limited to the predefined set of data resources in the template, adhering to the principle of least privilege and granting access only to the extent required for emergency analysis. The generated temporary extended credential is then returned to the analysis module for use during emergency data access.
[0035] Upon receiving the temporary extended credential information, the analysis module stores and manages it together with the original main task temporary credential information. When access to data resources required for urgent analysis is needed, the analysis module will send a data access request to the data access proxy service, carrying both the main task temporary credential information and the temporary extended credential information.
[0036] Upon receiving a request containing both types of credentials, the data access proxy service performs credential verification on the primary task's temporary credential information and the temporary extended credential information separately. If both credentials are valid, the system merges the authorization scope information from the two credentials to generate combined authorization scope information. This merged authorization mechanism allows the analysis module to continue executing its original analysis tasks in emergency situations while also accessing additional emergency data resources within a limited scope.
[0037] When the data resources and operation types requested by the analysis module both fall within the scope permitted by the combined authorization range information, the data access proxy service will allow the data access request to be executed, thereby enabling the analysis module to obtain the necessary data resources and continue emergency analysis. This mechanism ensures both efficient emergency response while strictly controlling data access behavior.
[0038] To prevent the long-term abuse of permissions, when the temporary extended credential information reaches its expiration date, the data access proxy service will automatically refuse to use the credential for data access during subsequent credential verification processes, thereby revoking the emergency extended permissions and restoring the system to the original primary task permission scope. This automatic expiration mechanism ensures that emergency permissions are only valid for the necessary time, thus further strengthening the system's data security protection capabilities.
[0039] In some preferred embodiments, the operation of the above mechanism can be illustrated through specific scenarios. For example, in a chemical industrial park, the temperature sensor of a critical reactor detects a rapid temperature rise exceeding a preset red alert threshold. The system identifies this situation as an "over-temperature reactor" threshold violation risk anomaly. Before this event occurs, the park's safety management system has pre-identified the "over-temperature reactor" anomaly and determined the data set required for emergency analysis, including the reactor's historical operating data, cooling system status data, relevant material flow data, and emergency shutdown operation records. Simultaneously, a corresponding emergency extended credential template is generated for this anomaly and protected by a digital signature. This template specifies that access to the aforementioned data resources is permitted, but only read operations are allowed, and a default validity period of thirty minutes is set. This template information has been distributed and stored in the local storage area of the data access proxy service responsible for the reactor area.
[0040] When the real-time risk assessment and analysis module detects that the reactor temperature exceeds a threshold during its daily monitoring tasks, it immediately sends an emergency permission extension request to the corresponding data access proxy service. This request includes the current main task identifier, the abnormal event identifier, the reason for the extension, and temporary credentials for authentication. After verifying the validity of the main task credentials, the data access proxy service locates the corresponding "reactor over-temperature" emergency extension credential template in its local emergency template library based on the abnormal event identifier and generates temporary extension credential information. This credential allows the analysis module to access reactor-related data such as temperature, pressure, and coolant flow rate for thirty minutes.
[0041] Upon receiving the temporary extended credential, the analysis module saves it along with the existing primary task temporary credential. When accessing additional data, it sends a request to the data access proxy service with both credentials. After verifying the validity of both credentials, the data access proxy service merges their authorization scopes and allows access to the requested urgent data resource. For example, when the analysis module requests to read the status data of the reactor cooling system, access is granted because this data falls within the authorization scope of the temporary extended credential.
[0042] If extended permissions are not requested again after the 30-minute validity period, the temporary extended credential will automatically expire. At this time, the data access proxy service will refuse to use the credential for data access during subsequent credential verification, thereby automatically revoking the emergency extended permissions and restoring the user to the original main task permission scope, thus ensuring the timeliness of permission use and data security.
[0043] Optional, combined Figure 2 As shown, after the data access proxy service verifies the validity of the temporary credential information for the main task, it matches the information in the emergency template library based on the abnormal event identifier to obtain the matched emergency extended credential template information. The steps include: A1, parse the text content of the abnormal event identifier information in the emergency permission extension request information, and identify the corresponding key attribute information; A2. Structure the information of each emergency extended voucher template in the emergency template library to extract the associated key attribute information; A3. Compare the key attribute information of the abnormal event identifier information with the key attribute information of each template one by one, and calculate the matching degree value. A4. Based on the matching degree value, filter the single emergency extended certificate template information or multiple related emergency extended certificate template information with the highest matching degree; A5. When multiple associated emergency extended certificate templates are selected, the authorization scope information corresponding to the multiple associated emergency extended certificate templates is logically merged to generate combined authorization scope information. A6 will use the selected single emergency extended credential template information or combined authorization scope information as the matched emergency extended credential template information.
[0044] Specifically, parsing the text content of the abnormal event identifier information in the emergency permission extension request information to identify the corresponding key attribute information refers to using Natural Language Processing (NLP) technology, keyword extraction algorithms, or predefined parsing rules to extract core elements such as event type, occurrence time, involved equipment, scope of impact, and risk level from unstructured or semi-structured abnormal event identifier information. For example, if the abnormal event identifier information is "The temperature of the reactor in Unit A exceeds the limit, which may cause a leak in Area B," then key attributes such as "Unit A," "reactor," "temperature exceeds the limit," "Area B," and "leak" can be identified. The purpose is to transform the raw, potentially ambiguous event description into structured data that can be accurately matched and processed by the system.
[0045] The process involves structuring each emergency extended voucher template in the emergency template library to extract associated key attribute information. This can be understood as preprocessing the emergency extended voucher template information when it is created or stored, or dynamically processing it during matching. Each template pre-defines key attributes such as the applicable abnormal event type, the equipment involved, and the required data type. For example, one template might be associated with the key attribute "abnormal reaction vessel temperature," while another might be associated with the attribute "excessively high storage tank level." The aim is to provide a unified and standardized data foundation for subsequent matching and comparison.
[0046] In practical applications, the key attributes of the abnormal event identifier are compared one by one with the key attributes of each template to calculate the degree of matching. This is done using similarity algorithms, such as cosine similarity, Jaccard similarity, or rule-based scoring mechanisms. For example, if the key attributes of an abnormal event overlap with multiple key attributes of a template, the degree of matching will be higher. The purpose is to quantify the correlation between abnormal events and various emergency templates, providing a basis for intelligent screening.
[0047] Furthermore, based on the matching score, the system filters for the single emergency extended credential template information or multiple related emergency extended credential template information with the highest matching score. This may include setting a matching score threshold, where only templates with a matching score higher than the threshold are considered. When multiple templates have the highest matching score, or when an abnormal event requires multiple different but related permission templates to fully cover it, the system will filter out multiple related emergency extended credential template information.
[0048] When multiple related emergency extended credential templates are selected, the authorization scope information corresponding to these templates is logically merged to generate combined authorization scope information. This logical merging can be a union operation on the data resource list information and permitted operation type information from different templates, ensuring that all necessary emergency data access permissions are included. For example, one template may authorize access to "temperature sensor data," and another to "pressure sensor data," but after merging, it will authorize access to both "temperature sensor data" and "pressure sensor data." The purpose is to ensure that in complex emergency situations, the analysis module obtains comprehensive and complete access to all necessary data.
[0049] Finally, the selected single emergency extended credential template information or combined authorization scope information will be used as the matched emergency extended credential template information for subsequent temporary extended credential instantiation.
[0050] Optionally, the steps for filtering the single emergency extended certificate template information or multiple related emergency extended certificate template information with the highest matching degree based on the matching degree value include: When there are multiple emergency extended voucher templates with matching scores higher than a preset threshold, analyze the key attribute information of the abnormal events associated with each emergency extended voucher template. Based on key attribute information and in conjunction with a priority rule base, the existing emergency extended certificate template information is sorted to obtain the priority of each emergency extended certificate template information. Prioritize the emergency extended credential template information with the highest priority, or logically merge the authorization scope information of multiple associated emergency extended credential template information with the highest priority to generate combined authorization scope information.
[0051] Specifically, when multiple emergency extended certificate templates have matching scores exceeding a preset threshold, it means that during the initial matching process, the system has identified several emergency authorization templates highly relevant to the current abnormal event. At this point, to make more accurate decisions, further detailed analysis of these templates is needed. Analyzing the key attribute information of the abnormal event associated with each emergency extended certificate template involves in-depth analysis of the abnormal event corresponding to each high-matching template, extracting its core characteristics, such as the event type, severity, scope of impact, involved equipment or processes, potential secondary risks, and time urgency. This key attribute information helps the system more comprehensively understand the actual applicable scenarios and importance of each template.
[0052] The system sorts existing emergency extended credential templates based on key attribute information and a priority rule base to determine their priorities. The priority rule base is a predefined knowledge base containing priority assessment criteria and rules for different types, severity levels, or impact ranges of abnormal events. For example, the rule base can specify that events involving personal safety have the highest priority, followed by events that may cause significant environmental pollution, and then equipment failure events affecting production continuity. By comparing and calculating the analyzed key attribute information with the rules in the priority rule base, the system can assign a priority value or level to each emergency extended credential template, thus forming an ordered list.
[0053] In practical applications, prioritizing the highest-priority emergency extension credential template means that after sorting, if only one template is determined to have the highest priority, that template will be automatically selected by the system as the basis for this emergency permission extension. Alternatively, when multiple emergency extension credential templates have the same highest priority, and these templates are logically related or complementary (for example, an emergency event may require access to both production process data and environmental monitoring data), the system will logically merge the authorization scope information of these multiple related emergency extension credential templates with the highest priority to generate a combined authorization scope. This logical merging typically means taking the union of the authorization scopes of all highest-priority templates to ensure that the most comprehensive and necessary authorization is provided without introducing conflicts, thereby supporting the analysis module in performing comprehensive emergency processing.
[0054] Optionally, when multiple associated emergency extended certificate templates are selected, the step of logically merging the authorization scope information corresponding to the multiple associated emergency extended certificate templates to generate combined authorization scope information includes: Analyze the authorization scope information corresponding to each emergency extended credential template to identify conflicting and redundant authorization scope information; Conflict handling is performed on conflicting authorization scope information based on the security policy library to generate conflict-free authorization scope information; Perform deduplication processing on redundant authorization scope information; Based on the business association rule base, the redundant authorization scope information after deduplication is finely coordinated to generate finely defined authorization scope information; By merging the conflict-free authorization scope information with the refined authorization scope information, the corresponding combined authorization scope information is obtained.
[0055] Specifically, when identifying conflicting and redundant authorization scope information, the data resource list information and permitted operation type information contained in each emergency extended credential template can be cross-checked. For example, if two templates both authorize access to "temperature data of device A," but one template allows "reading" and the other allows "writing," this may constitute conflicting authorization scope information. If multiple templates authorize access to "pressure data of device B" and all allow "reading," this constitutes redundant authorization scope information. The identification process can be implemented using techniques such as set operations, rule engines, or semantic analysis.
[0056] Specifically, conflict resolution based on a security policy library involves arbitrating identified conflicting authorizations according to predefined security policies and priority rules. For example, the security policy library can stipulate that when write and read permissions conflict, read permissions are prioritized to ensure data integrity, or that when different operation permissions conflict, the more restrictive operation is selected to ensure system security. This step aims to eliminate inconsistent or contradictory authorizations, ensuring the security and compliance of the final authorization.
[0057] In practical applications, deduplication of redundant authorization scope information means merging authorizations that appear repeatedly in multiple templates and have the same data resources and operation types, retaining only one copy. This helps simplify the authorization structure, improve the efficiency of authorization management, and avoid unnecessary duplicate authorization checks.
[0058] Furthermore, the refined coordination of redundant authorization scope information after deduplication based on the business association rule base can be understood as further optimizing and adjusting the authorization scope according to business logic and relevance, building upon deduplication. For example, if an anomaly requires access to "reactor temperature" and "feed flow rate" data, the business association rule base may indicate that, for a comprehensive analysis of the anomaly, access to "stirring speed" data is also necessary, even if this data was not explicitly authorized or was redundantly processed in the original template. This step aims to ensure that the generated authorization scope is not only safe and conflict-free but also fully meets the business needs of urgent analysis, providing a more comprehensive data view.
[0059] Finally, the conflict-free authorization scope information and the refined authorization scope information are merged to obtain the corresponding combined authorization scope information. This merging process ensures that the final authorization scope not only eliminates internal conflicts but also includes the necessary data optimized by business logic, thereby forming a secure and efficient emergency data access credential.
[0060] Optionally, the step of performing conflict processing on conflicting authorization scope information based on the security policy library to generate conflict-free authorization scope information includes: Obtain information on the operating status of the equipment involved in the conflict authorization scope, environmental monitoring data, and historical abnormal event handling records. Risk assessment is conducted based on equipment operating status information, environmental monitoring data, and historical abnormal event handling records to obtain potential risk level information. Based on potential risk level information and risk handling rule base, adjust the priority of each authorized operation in the conflict authorization scope information; Based on the adjusted priorities of each authorization operation in the conflict authorization scope information, the authorization operation with the highest priority is selected as the corresponding conflict-free authorization scope information, or the scope constraints of multiple authorization operations with the same highest priority are merged according to the risk handling rule base to generate the corresponding conflict-free authorization scope information; wherein, the scope constraint merging is performed by pruning multiple authorization scopes under preset security constraints before merging.
[0061] Specifically, acquiring information on the equipment operating status, environmental monitoring data, and historical anomaly handling records related to conflict authorization scope refers to the system proactively collecting real-time and historical operational data directly related to these conflicting authorization operations when it detects an authorization scope conflict. For example, equipment operating status information may include sensor readings, equipment start / stop status, and load conditions; environmental monitoring data may include temperature, pressure, and gas concentration; and historical anomaly handling records document the occurrence time, handling process, results, and responsible parties for similar past events. The purpose is to provide comprehensive and objective contextual information for subsequent risk assessment.
[0062] This process involves risk assessment based on equipment operating status information, environmental monitoring data, and historical anomaly handling records to obtain potential risk level information. This can be understood as using collected multi-dimensional data and a pre-defined risk assessment model or algorithm to quantitatively analyze the potential risks of a current conflict authorization operation. For example, if an authorization operation involves the control of high-risk equipment, and the current equipment operating status shows abnormalities, and environmental monitoring data also indicates potential danger, then the potential risk level of this operation will be assessed as high. The aim is to provide a scientific risk basis for conflict resolution.
[0063] In practical applications, adjusting the priority of authorized operations within the conflict authorization scope information based on potential risk level information and a risk handling rule base means that the system dynamically adjusts the execution priority of each authorized operation within the conflict authorization scope based on risk assessment results and a predefined risk handling rule base. For example, the risk handling rule base might stipulate that, in the event of a gas leak, operations related to emergency shut-off valves have a higher priority than operations related to data queries. The purpose is to ensure that, in emergency situations, the most critical and effective risk-controlling operations are executed first.
[0064] Furthermore, based on the adjusted priorities of each authorized operation in the conflict authorization scope information, the authorized operation with the highest priority is selected as the corresponding conflict-free authorization scope information. Alternatively, based on the risk handling rule base, the scope constraints of multiple authorized operations with the same highest priority are merged to generate the corresponding conflict-free authorization scope information. This means that after priority adjustment, the system will prioritize the operation with the lowest risk or the most critical operation as the final authorization scheme. If multiple operations have the same highest priority, and there is a certain correlation or complementarity between these operations, the system will, based on the risk handling rule base and under preset security constraints, trim and merge these authorization scopes to form a combined authorization scope that meets both emergency needs and security specifications. Specifically, scope constraint merging refers to a detailed review and adjustment of each authorization scope before merging, such as restricting the granularity of data access, the type of operation (read-only, partial write, etc.), or the validity period, to ensure that the merged authorization scope does not introduce new security risks. Its purpose is to maximize the satisfaction of data access needs in emergency situations while ensuring security.
[0065] Optionally, the step of performing fine-grained coordination on the deduplicated redundant authorization scope information based on the business association rule base to generate fine-grained authorization scope information includes: Acquire equipment operating parameters, process status information, and safety instrumented system data associated with abnormal event identification information; Based on equipment operating parameter information, process flow status information, and safety instrument system data information, identify corresponding secondary risk scenario information; Based on the secondary risk scenario information, determine the set of data resources that need to be accessed additionally; The additional data resource set is merged with the existing authorization scope information to generate refined authorization scope information that includes business-related data.
[0066] Specifically, when performing refined coordination on the deduplicated redundant authorization scope information, it is first necessary to acquire equipment operating parameter information, process status information, and safety instrumented system (SIS) data information directly associated with the current abnormal event identification information. Equipment operating parameter information may include, but is not limited to, real-time monitoring data such as temperature, pressure, flow rate, and liquid level, which directly reflect the current operating status of the equipment. Process status information may include production stage, batch information, valve opening / closing status, etc., used to understand the specific process context of the abnormal event. Safety instrumented system (SIS) data information covers the status of safety interlocks, emergency shutdown (ESD) systems, alarm records, etc., which are crucial for assessing safety risks. Acquiring this information aims to provide a comprehensive real-time context for subsequent risk identification.
[0067] Furthermore, based on the acquired equipment operating parameters, process status information, and safety instrumented system data, the system will identify corresponding secondary risk scenarios. Secondary risk scenarios refer to chain reactions or derivative risks triggered by an initial abnormal event that may lead to more serious consequences. For example, a simple pump failure may cause a localized temperature increase, subsequently triggering secondary risks such as material decomposition and a sudden increase in pressure. Through comprehensive analysis of multi-source heterogeneous data, combined with a pre-set risk model or expert knowledge base, the system can accurately determine the type of secondary risk that the current abnormal event may induce and its potential impact range.
[0068] Based on this, and according to the identified secondary risk scenario information, the system will determine the set of data resources that require additional access. This means that, in addition to the regular data within the initial authorized scope, access permissions need to be dynamically supplemented according to the characteristics of the secondary risk. For example, if a secondary risk of a toxic gas leak is identified, additional access to air quality data, wind direction and speed data, and population distribution information in the surrounding area from environmental monitoring stations is required. These additional data resources are crucial for comprehensively assessing risks, developing emergency plans, and taking effective measures.
[0069] Finally, the identified set of additional access data resources is logically merged with the existing authorization scope information to generate refined authorization scope information that includes business-related data. This merging process ensures that the final authorization scope not only covers the data required for the initial anomaly analysis but also fully considers the secondary risks that may be caused by the anomaly and the data support required, enabling the analysis module to obtain more comprehensive and accurate data to deal with complex emergency situations.
[0070] Optionally, the steps for adjusting the priority of each authorized operation in the conflict authorization scope information based on potential risk level information and risk handling rule base include: The adjustment rules for each authorized operation in the conflict authorization scope information are structured and parsed to identify the data resource information, scope of impact information, and potential mutual exclusion or inclusion relationship information that each rule depends on. Based on data resource information, scope of impact information, and potential mutual exclusion or inclusion relationship information, the dependency or conflict relationship between each adjustment rule is determined to construct a rule dependency graph. In the graph, nodes represent adjustment rules, and edges represent dependency or conflict relationship information between rules. Traverse the rule dependency graph to identify circular dependency information or potential conflict path information; When circular dependency information is identified, the priority of relevant rules is re-evaluated and adjusted based on the conflict resolution strategy library; When identifying potential conflict path information, the rules on the conflict path are subject to constraint adjustments based on the security policy library. These constraint adjustments include restricting the applicable conditions, scope of influence, or order of action of the rules to ensure that the adjusted priorities do not introduce new security vulnerabilities. Based on the adjusted rules, the priority sequence of each authorized operation in the conflict authorization scope information is recalculated and output.
[0071] Specifically, when performing structured parsing of the adjustment rules for each authorized operation within the conflict authorization scope information, Natural Language Processing (NLP) techniques or predefined rule parsers can be used to convert unstructured rule descriptions into machine-readable structured data. This process aims to accurately identify the specific data resources upon which each adjustment rule depends, such as specific sensor data, device parameters, or historical records; simultaneously, it clarifies which data or operations are affected after the rule takes effect, i.e., its scope of influence. Furthermore, it is necessary to identify whether there are potential mutually exclusive relationships (i.e., two rules cannot be effective simultaneously) or inclusion relationships (i.e., the effectiveness of one rule depends on the effectiveness of another rule) between rules. These relationships are crucial for subsequently constructing a rule dependency graph.
[0072] Furthermore, based on the parsed data resource information, scope of influence information, and potential mutually exclusive or inclusive relationships, a rule dependency graph can be constructed. In this graph, each node represents a specific adjustment rule, and the edges between nodes represent dependencies or conflicts between rules. For example, if the execution of rule A requires data provided by rule B, a dependency edge can be established from rule B to rule A; if rules C and D produce contradictory authorization results under certain conditions, a conflict edge can be established between them. The construction of this graph helps to visualize and manage complex rule sets.
[0073] Building upon this, by traversing the rule dependency graph, potential circular dependencies or conflicting paths can be identified. A circular dependency refers to a set of rules that depend on each other, forming a closed loop, which may cause the system to be unable to determine the final priority or fall into deadlock. Potential conflicting paths refer to combinations of rules that may lead to inconsistent authorization results or security vulnerabilities. For example, one path might grant excessively high privileges in an emergency, while another path might impose strict restrictions; the two may conflict in specific situations.
[0074] When circular dependency information is detected, the system will re-evaluate the relevant rules involving circular dependencies and adjust their priorities based on a pre-defined conflict resolution strategy library. The conflict resolution strategy library can contain various strategies, such as the "principle of least privilege," the "principle of highest risk priority," or the "principle of manual intervention approval," to ensure that reasonable priority decisions can be made in circular dependency scenarios.
[0075] When potential conflict paths are identified, the system will adjust the rules on those paths according to the security policy library. These adjustments may include restricting the applicability of rules, such as specifying that a rule only applies under certain device conditions; adjusting its scope of influence to affect only certain data resources; or changing its order of application to ensure that high-risk operations are executed after low-risk operations. These adjustments aim to eliminate conflicts and ensure that the adjusted priorities do not introduce new security vulnerabilities, thereby maintaining the security and stability of the entire system.
[0076] Optionally, the step of selecting the highest-priority authorization operation as the corresponding conflict-free authorization scope information based on the adjusted priorities of each authorization operation in the conflict authorization scope information includes: After selecting the highest priority single authorized operation, obtain the equipment operating parameter information, environmental monitoring data information, and personnel activity information directly related to the corresponding authorized operation; Risk assessment is conducted based on equipment operating parameters, environmental monitoring data, and personnel activity information to obtain real-time risk values. The real-time risk value is compared with the preset safety threshold to obtain the risk comparison and judgment result; When the risk comparison results indicate that the real-time risk value exceeds the safety threshold, the backup authorization process is triggered. The backup authorization process includes re-evaluating the second-highest priority operation or initiating a manual approval process to output a supplementary or alternative authorization plan. When the risk comparison result indicates that the real-time risk value does not exceed the security threshold, the highest priority single authorized operation is allowed to be executed, and the judgment result of the allowed execution is written into the audit log.
[0077] Specifically, after the data access proxy service selects the highest-priority single authorized operation, it does not execute the operation immediately. Instead, it first acquires equipment operating parameters, environmental monitoring data, and personnel activity information directly related to the authorized operation. Equipment operating parameters may include, but are not limited to, real-time data such as temperature, pressure, flow rate, and liquid level, reflecting the current operating condition of the equipment. Environmental monitoring data may include gas concentration, smoke alarms, ambient temperature, and humidity, used to assess the environmental safety of the operating area. Personnel activity information may include personnel location, entry and exit records, and operation logs, used to confirm the compliance and safety of operators. Acquiring this information aims to provide comprehensive and dynamic data support for subsequent real-time risk assessments.
[0078] Furthermore, based on the acquired equipment operating parameters, environmental monitoring data, and personnel activity information, the system will perform a real-time risk assessment to obtain a real-time risk value. This risk assessment can employ various models and algorithms, such as risk matrix assessment based on expert experience, machine learning prediction models based on historical data, or anomaly detection algorithms based on real-time event streams. Its purpose is to quantify the potential risk level of the current operating environment. Subsequently, this real-time risk value is compared with a preset safety threshold to determine whether the current risk is within an acceptable range. The preset safety threshold is determined comprehensively based on the safety management regulations of the chemical industrial park, process characteristics, and historical accident experience, and is used to define acceptable and unacceptable risk levels.
[0079] When the risk comparison results indicate that the real-time risk value exceeds the preset safety threshold, the system will trigger a backup authorization process. This backup authorization process is a flexible risk response mechanism designed to avoid forcibly executing high-risk operations under unsafe conditions. Specifically, the backup authorization process may include re-evaluating the next highest priority operation; that is, the system will re-examine and evaluate other authorization options with a priority lower than the current highest priority operation to find a safer and more feasible alternative in the current risk situation. Alternatively, the system may initiate a manual approval process, submitting the current situation and risk assessment results to the security manager or relevant personnel for manual review and decision-making. The human manager will determine whether the original operation should be executed, the alternative operation should be executed, or the operation should be completely rejected, thereby outputting a supplementary or alternative authorization option.
[0080] Conversely, when the risk comparison result indicates that the real-time risk value does not exceed the preset security threshold, it signifies that the current operating environment is relatively safe, and the system will allow the execution of the highest-priority single authorized operation. Simultaneously, to ensure the traceability and compliance of the operation, the judgment result of the allowed execution and related operation information will be written into the audit log. The audit log may include the operation time, operator, operation content, risk assessment results, and the final execution decision, providing detailed evidence for subsequent security reviews and incident tracing.
[0081] This application also discloses a chemical industrial park operation data protection system based on the Industrial Internet, used to perform operation data protection for chemical industrial parks based on the Industrial Internet, combined with... Figure 3 As shown, the chemical industrial park operation data protection system 1 based on the Industrial Internet includes: The task information receiving module 11 is used to receive task information from the analysis module; the task information includes the purpose of the analysis work, the required data resource scope, and the expected duration. The temporary credential generation module 12 is used to generate temporary credential information for the main task with a limited validity period and data access permissions based on the task information and in conjunction with the access rule base. The voucher verification and judgment module 13 is used to perform voucher verification and judgment on the validity, limited validity period and data access permissions of the temporary voucher information of the main task when the analysis module initiates a data acquisition request, obtain the verification pass judgment result, and allow the analysis module to acquire the corresponding data resources when the verification pass judgment result is pass; The data protection execution module 14 is used to invalidate the corresponding temporary voucher information of the main task when the analysis module completes the analysis work or when the limited validity period of the temporary voucher information of the main task expires, so as to realize the protection of operational data.
[0082] Specifically, the above embodiments have already described the methods and steps of receiving task information from the analysis module, generating temporary credential information for the main task based on the task information and in conjunction with the access rule base, performing credential verification and judgment on the temporary credential information for the main task, and invalidating the temporary credential information for the main task. The specific method flow will not be repeated here. It is important to emphasize that in the system embodiment, the above methods are implemented collaboratively by multiple functional modules, thereby constructing a data protection system architecture for the industrial internet environment.
[0083] The task information receiving module receives task information from the analysis module. This module can be implemented as a network service interface to receive data requests from different analysis modules. For example, this module can be deployed in an industrial internet platform. The analysis modules send data requests containing task information to this interface via HTTP or HTTPS protocols. The task information can be encapsulated in a structured data format for system parsing. In another implementation, the task information receiving module can act as a consumer node in a message queue system, subscribing to specific message topics to receive task information messages published by the analysis modules, thereby achieving asynchronous reception and processing of task information.
[0084] The temporary credential generation module generates temporary credential information for the main task, with limited validity periods and data access permissions, based on task information and an access rule base. This module can be implemented as a standalone microservice component. When the task information receiving module receives task information submitted by the analysis module, it passes the task information to the temporary credential generation module. The temporary credential generation module searches the access rule base for corresponding access policies based on the analysis purpose, required data resource scope, and task duration information in the task information, and generates the corresponding temporary credential information for the main task according to the matched access rules. In a specific implementation, this credential can be represented in the form of an encrypted token, such as JSONWebToken, which contains information such as the credential's validity period, a list of allowed data resources, and allowed operation types. Digital signatures are used to ensure the integrity and trustworthiness of the credential content during transmission and use.
[0085] The credential verification module verifies the validity, validity period, and data access permissions of the temporary credential information for the main task when the analysis module initiates a data acquisition request. This module is typically deployed within a data access proxy service, serving as the secure entry point for all data access requests. When the analysis module requests data resources from the system carrying the temporary credential information for the main task, the credential verification module first parses the credential and verifies its digital signature to confirm its legitimate origin and lack of tampering. Subsequently, the system checks the validity period recorded in the credential to determine if the current time is within the permitted access time range and compares the requested data resource with the data access permissions recorded in the credential. Only when the credential verification is successful, the credential is not expired, and the accessed data resource falls within the authorized scope will the system allow the corresponding data access request to proceed; otherwise, the request will be rejected.
[0086] The data protection execution module is used to invalidate the corresponding temporary credentials for main tasks when the analysis module completes its analysis task or when the validity period of the temporary credentials expires. This module can be implemented as a background management service, its main function being to periodically check all valid temporary credentials in the system. For example, this module can periodically scan all temporary credentials for main tasks in the credential database or cache storage area and check whether their validity period has ended. When a credential is detected to have expired, the system automatically marks it as invalid. Furthermore, this module can provide an interface for the analysis module to actively call after completing its analysis task, thereby immediately revoking the temporary credential corresponding to that task. Once a credential is marked as invalid, the credential verification module will refuse to use it when processing subsequent data access requests, thus ensuring that access permissions are promptly revoked.
[0087] Traditional data protection methods typically employ static access control policies based on data sensitivity levels and user roles. In normal, stable business environments, this approach can meet basic data security requirements. However, when an intelligent operations analysis system is deployed in an industrial internet environment within a chemical industrial park, and cross-system, cross-domain data analysis is required, the limitations of traditional static permission mechanisms become apparent. Since static permissions are usually pre-set during system deployment, it is difficult to dynamically adjust them based on the specific tasks being performed by the intelligent analysis system. In this situation, although the system technically still complies with the permission rules, in practical applications, the problem of over-authorization often arises, allowing the analysis module to continue to access large amounts of sensitive data unnecessarily.
[0088] Furthermore, traditional systems lack the ability to understand task context. For example, when an intelligent operations analysis system performs a task of predicting equipment failures, it may indeed need to access the process operation data of a specific sub-park; however, when the system performs an energy consumption optimization task, it may not need to access the same data. However, in traditional static permission mechanisms, the system cannot dynamically adjust access permissions based on the current task type, resulting in the analysis module holding data access permissions beyond the actual need for extended periods. This phenomenon poses a potential security risk in the industrial internet environment, meaning that the intelligent analysis system can still access sensitive production data when it is not necessary.
[0089] The chemical industrial park operation data protection system proposed in this application, based on the Industrial Internet, effectively solves the aforementioned problems by introducing a task-driven data access control mechanism and a modular system structure. This system uses a task information receiving module to perceive and analyze the true intent of the currently executing task, a temporary credential generation module to dynamically generate a main task temporary credential with a limited validity period and access permissions, a credential verification module to perform real-time verification for each data access request, and a data protection execution module to promptly revoke access permissions upon task completion or credential expiration.
[0090] Compared to existing static data protection mechanisms, this system can dynamically and on-demand allocate data access permissions based on the specific task scenario being executed by the intelligent operation analysis system. This task-driven authorization mechanism ensures that the analysis module only accesses the data resources necessary for completing the task during its execution and automatically revokes access permissions after the task ends, significantly reducing the risk of excessive access to sensitive data. Simultaneously, the system can fully record data access behavior, providing a basis for subsequent data auditing and security tracking. This enhances data security, controllability, and auditing capabilities within the industrial internet environment of the chemical industrial park, providing reliable data security guarantees for the park's intelligent operation.
[0091] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. A method for protecting operational data of a chemical industrial park based on the Industrial Internet, characterized in that, include: Receive task information from the analysis module; The task information includes the purpose of the analysis work, the scope of required data resources, and the expected duration. Based on the task information and in conjunction with the access rule base, generate temporary credential information for the main task with a limited valid time period and data access permissions; When the analysis module initiates a data acquisition request, it performs a credential verification judgment on the validity, limited validity period and data access permissions of the temporary credential information of the main task, obtains a verification pass judgment result, and allows the analysis module to acquire the corresponding data resources when the verification pass judgment result is pass; When the analysis module completes its analysis or the limited validity period of the temporary voucher information for the main task expires, the corresponding temporary voucher information for the main task becomes invalid to achieve operational data protection.
2. The method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 1, is characterized in that... The step of generating temporary credentials for the main task with limited validity periods and data access permissions based on the task information and in conjunction with the access rule base further includes: emergency permission extension processing, wherein the emergency permission extension processing includes: Pre-identify threshold exceedance risk anomalies within the park, and for each threshold exceedance risk anomaly, determine the data set required for emergency analysis; the threshold exceedance risk anomaly is an anomaly that characterizes the occurrence of threshold exceedance of the monitoring indicator; For each threshold exceedance risk event, generate and digitally sign emergency extension credential template information; the emergency extension credential template information includes default validity period information, authorized access data resource list information, and allowed operation type information; The emergency extended credential template information is distributed and stored in the local storage area of the data access agent service to form an emergency template library; When the analysis module detects an event that matches the abnormal scenario of exceeding the predefined threshold risk during the execution of the main task, it sends an emergency permission extension request to the corresponding data access proxy service. The emergency permission extension request includes the main task identification code, the abnormal event identifier, the extension reason, and carries the temporary credential information of the currently active main task as authentication information. After verifying the validity of the temporary credential information for the main task, the data access proxy service matches the abnormal event identifier information in the emergency template library to obtain the matched emergency extended credential template information. The data access proxy service instantiates and digitally signs temporary extended credential information based on the matched emergency extended credential template information and the current time. The extended authorization scope of the temporary extended credential information is limited to the data set predefined by the emergency extended credential template information, and the temporary extended credential information is returned to the analysis module. The analysis module stores the temporary extended credential information and the main task temporary credential information, and sends a data request to the data access proxy service with the temporary extended credential information and the main task temporary credential information when accessing emergency data; The data access proxy service performs credential verification and judgment on the temporary extended credential information and the main task temporary credential information simultaneously, and merges the authorization scope information of the temporary extended credential information and the main task temporary credential information to form combined authorization scope information; When the data and operation requested by the data request fall within the combined authorization scope information, the analysis module is allowed to obtain the data; When the temporary extended credential information expires, the data access proxy service will refuse to use the request for the temporary extended credential information in subsequent credential verification.
3. The method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 2, is characterized in that... After verifying the validity of the temporary credential information for the main task, the data access proxy service performs a matching process in the emergency template library based on the abnormal event identifier information to obtain the matched emergency extended credential template information. The steps include: The text content of the abnormal event identifier information in the emergency permission extension request information is parsed to identify the corresponding key attribute information; The information of each emergency extended voucher template in the emergency template library is structured to extract the associated key attribute information; Compare the key attribute information of the abnormal event identifier with the key attribute information of each template, and calculate the matching degree value; Based on the matching degree value, filter the single emergency extended certificate template information or multiple related emergency extended certificate template information with the highest matching degree; When multiple associated emergency extended certificate templates are selected, the authorization scope information corresponding to the multiple associated emergency extended certificate templates is logically merged to generate combined authorization scope information. The selected single emergency extended credential template information or the combined authorization scope information is used as the matched emergency extended credential template information.
4. A method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 3, is characterized in that... The step of filtering the single emergency extended certificate template information or multiple associated emergency extended certificate template information with the highest matching degree based on the matching degree value includes: When there are multiple emergency extended voucher templates with matching scores higher than a preset threshold, analyze the key attribute information of the abnormal events associated with each emergency extended voucher template. Based on the key attribute information and in conjunction with the priority rule base, the existing emergency extended certificate template information is sorted to obtain the priority of each emergency extended certificate template information. The highest priority emergency extended credential template information is selected first, or the authorization scope information of multiple associated emergency extended credential template information with the highest priority is logically merged to generate combined authorization scope information.
5. A method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 3, is characterized in that... When multiple related emergency extended certificate templates are selected, the steps to logically merge the authorization scope information corresponding to the multiple related emergency extended certificate templates to generate combined authorization scope information include: Analyze the authorization scope information corresponding to each of the aforementioned emergency extended credential templates to identify conflicting and redundant authorization scope information; Based on the security policy library, conflict processing is performed on the conflict authorization scope information to generate conflict-free authorization scope information; Perform deduplication processing on the redundant authorization range information; Based on the business association rule base, the redundant authorization scope information after deduplication is finely coordinated to generate finely defined authorization scope information; The conflict-free authorization scope information is combined with the refined authorization scope information to obtain the corresponding combined authorization scope information.
6. A method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 5, is characterized in that... The step of performing conflict processing on the conflict authorization scope information based on the security policy library to generate conflict-free authorization scope information includes: Obtain information on the operating status of the equipment involved in the conflict authorization scope, environmental monitoring data, and historical abnormal event handling records. Risk assessment is performed based on the equipment operating status information, the environmental monitoring data information, and the historical abnormal event handling record information to obtain potential risk level information; Based on the potential risk level information and the risk handling rule base, the priority of each authorized operation in the conflict authorization scope information is adjusted; Based on the adjusted priorities of each authorization operation in the conflict authorization scope information, the authorization operation with the highest priority is selected as the corresponding conflict-free authorization scope information, or the scope constraints of multiple authorization operations with the same highest priority are merged according to the risk handling rule base to generate the corresponding conflict-free authorization scope information; wherein, the scope constraint merging is performed by pruning multiple authorization scopes under preset security constraints before merging.
7. A method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 5, is characterized in that... The step of performing fine-grained coordination on the deduplicated redundant authorization scope information based on the business association rule base to generate fine-grained authorization scope information includes: Acquire equipment operating parameters, process status information, and safety instrumented system data associated with abnormal event identification information; Based on the equipment operating parameter information, the process flow status information, and the safety instrument system data information, the corresponding secondary risk scenario information is identified; Based on the secondary risk scenario information, determine the set of data resources that need to be accessed additionally; The additional access data resource set is merged with the existing authorization scope information to generate refined authorization scope information that includes business-related data.
8. A method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 6, is characterized in that... The step of adjusting the priority of each authorized operation in the conflict authorization scope information based on the potential risk level information and the risk handling rule base includes: The adjustment rules for each authorized operation in the conflict authorization scope information are structured and parsed to identify the data resource information, scope of impact information, and potential mutual exclusion or inclusion relationship information that each rule depends on. Based on the data resource information, scope of influence information, and potential mutual exclusion or inclusion relationship information, the dependency or conflict relationship between each adjustment rule is determined to construct a rule dependency graph, in which nodes represent adjustment rules and edges represent dependency or conflict relationship information between rules. Traverse the rule dependency graph to identify circular dependency information or potential conflict path information; When circular dependency information is identified, the priority of relevant rules is re-evaluated and adjusted based on the conflict resolution strategy library; When identifying potential conflict path information, the rules on the conflict path are adjusted according to the security policy library; wherein, the constraint adjustment includes restricting the applicable conditions, scope of influence or order of action of the rules, so as to ensure that the adjusted priority does not introduce new security vulnerabilities. Based on the adjusted rules, the priority sequence of each authorized operation in the conflict authorization scope information is recalculated and output.
9. A method for protecting operational data of a chemical industrial park based on the Industrial Internet, as described in claim 6, characterized in that, The step of selecting the authorization operation with the highest priority as the corresponding conflict-free authorization scope information based on the adjusted priorities of each authorization operation in the conflict authorization scope information includes: After selecting the highest priority single authorized operation, obtain the equipment operating parameter information, environmental monitoring data information, and personnel activity information directly related to the corresponding authorized operation; Risk assessment is performed based on the equipment operating parameters, environmental monitoring data, and personnel activity information to obtain a real-time risk value; The real-time risk value is compared with a preset safety threshold to obtain the risk comparison and judgment result; When the risk comparison and judgment result indicates that the real-time risk value exceeds the preset security threshold, the backup authorization process is triggered; the backup authorization process includes re-evaluating the second highest priority operation or initiating a manual approval process to output a supplementary or alternative authorization scheme; When the risk comparison judgment result indicates that the real-time risk value does not exceed the preset security threshold, the highest priority single authorized operation is allowed to be executed, and the judgment result of the allowed execution is written into the audit record.
10. A chemical industrial park operation data protection system based on the Industrial Internet, used to perform operation data protection for chemical industrial parks based on the Industrial Internet, characterized in that, include: The task information receiving module is used to receive task information from the analysis module; The task information includes the purpose of the analysis work, the scope of required data resources, and the expected duration. The temporary credential generation module is used to generate temporary credential information for the main task with a limited validity period and data access permissions based on the task information and in conjunction with the access rule base. The voucher verification and judgment module is used to perform voucher verification and judgment on the validity, limited validity period and data access permissions of the temporary voucher information of the main task when the analysis module initiates a data acquisition request, obtain the verification pass judgment result, and allow the analysis module to acquire the corresponding data resources when the verification pass judgment result is pass; The data protection execution module is used to invalidate the corresponding temporary credential information of the main task when the analysis module completes the analysis work or when the limited validity period of the temporary credential information of the main task expires, so as to realize the protection of operational data.