A smart pipe network data security and credibility architecture method and system
By constructing a smart pipeline network data domain and data item classification list database, a data security and trustworthy architecture is generated, which solves the security risks and trustworthiness issues in the data flow process and realizes the secure and trustworthy circulation and sharing of data inside and outside.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-03
- Publication Date
- 2026-03-24
AI Technical Summary
Existing technologies face challenges such as difficulties in data flow and application between internal and external entities, security risks during data transfer, and the inability to guarantee the reliability and security of pipeline data itself.
By constructing a smart pipeline network data domain, performing circulation attribute analysis to generate the first and second circulation dimensions, constructing a two-dimensional data partitioning coordinate system, dividing the data domain, and generating a data security and trustworthy architecture through a data item classification list database and a pipeline data authentication and certification center, the secure and trustworthy flow of data is achieved.
It enables the circulation and sharing of smart pipeline data within an internal and external data security and trustworthy architecture, improving the security and trustworthiness of smart pipeline data at each stage and avoiding security risks and resource waste during data flow.
Smart Images

Figure CN114491614B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of artificial intelligence, in particular to a smart pipe network data security and trust architecture method and system. BACKGROUND
[0002] With the development of Internet of Things, communication, artificial intelligence, big data, industrial control and cloud computing technology, a large number of pipeline key information infrastructures and intelligent devices have been created and developed, making smart pipe network a reality. Under the background of rapid development of pipeline construction, a large number of new and old pipelines coexist. The old pipeline construction period is limited by the level of technology, and the degree of informatization and automation is low, and the degree of manual maintenance and management is high. The newly built pipeline adopts certain Internet of Things and artificial intelligence devices, but still needs to invest personnel for management and control.
[0003] However, the present application inventors found at least the following technical problems in the process of implementing the technical solutions of the present application embodiments:
[0004] The prior art has the technical problems that data flow application between internal and external is difficult, there is a security risk in the data flow process, and the pipeline data itself cannot be trusted and the data security cannot be guaranteed. SUMMARY
[0005] The present application embodiments provide a smart pipe network data security and trust architecture method and system, which solves the technical problems of data flow application between internal and external, security risk in the data flow process, and inability to guarantee the trustworthiness and data security of pipeline data in the prior art. By constructing a smart pipe network data domain and a data item grading inventory database and a pipeline data authentication center, the technical effects of circulating and sharing smart pipeline data in the internal and external data security and trust architecture, and improving the security and trustworthiness of each link of smart pipeline data are achieved.
[0006] In view of the above problems, the present application embodiments provide a smart pipe network data security and trust architecture method and system.
[0007] A first aspect of the embodiments of the present application provides a method of a smart pipe network data security and trust architecture, wherein the method is applied to a smart pipe network data security and trust architecture system, the system is in communication connection with a pipe data authentication center, and the method comprises: constructing a smart pipe network data domain; generating a first flow dimension and a second flow dimension by analyzing the flow attribute of the smart pipe network data domain; constructing a two-dimensional data division coordinate system by taking the first flow dimension and the second flow dimension as the horizontal axis and the vertical axis, respectively; inputting the smart pipe network data domain into the two-dimensional data division coordinate system for data domain division to obtain a first divided data domain, wherein the first divided data domain comprises four data domains; obtaining a preset level coordinate domain, wherein the preset level coordinate domain is used for grading the data environment; grading and quality cleaning all divided data items in the first divided data domain according to the preset level coordinate domain to construct a data item grading list database; generating a data security and trust architecture according to the data item grading list database and the pipe data authentication center; and realizing the secure and trustworthy flow of the smart pipe network data domain according to the data security and trust architecture.
[0008] A second aspect of the embodiments of the present application provides a smart pipe network data security and trust architecture system, which comprises: a first construction unit, configured to construct a smart pipe network data domain; a first generation unit, configured to generate a first flow dimension and a second flow dimension by analyzing the flow attribute of the smart pipe network data domain; a second construction unit, configured to construct a two-dimensional data division coordinate system by taking the first flow dimension and the second flow dimension as the horizontal axis and the vertical axis, respectively; a first input unit, configured to input the smart pipe network data domain into the two-dimensional data division coordinate system for data domain division to obtain a first divided data domain, wherein the first divided data domain comprises four data domains; a first obtaining unit, configured to obtain a preset level coordinate domain, wherein the preset level coordinate domain is used for grading the data environment; a third construction unit, configured to grade and quality clean all divided data items in the first divided data domain according to the preset level coordinate domain to construct a data item grading list database; a second generation unit, configured to generate a data security and trust architecture according to the data item grading list database and a pipe data authentication center; and a first flow unit, configured to realize the secure and trustworthy flow of the smart pipe network data domain according to the data security and trust architecture.
[0009] The third aspect of the embodiment of the application provides a smart pipe network data security and credibility architecture system, wherein the device comprises a processor coupled with a memory, the memory is used to store a program, and when the program is executed by the processor, the device is caused to perform the steps of the method according to the first aspect.
[0010] The one or more technical solutions provided in the embodiment of the application have at least the following technical effects or advantages:
[0011] The embodiment of the application builds a smart pipe network data domain, analyzes the flow attribute of the smart pipe network data domain, generates a first flow dimension and a second flow dimension, constructs a two-dimensional data division coordinate system by taking the first flow dimension and the second flow dimension as the horizontal axis and the vertical axis respectively, inputs the smart pipe network data domain into the two-dimensional data division coordinate system for data domain division, and obtains a first division data domain, wherein the first division data domain comprises four data domains, a preset level coordinate domain is obtained, wherein the preset level coordinate domain is used for grading the data environment, all division data items in the first division data domain are graded and quality cleaned according to the preset level coordinate domain, a data item grading list database is constructed, a data security and credibility architecture is generated according to the data item grading list database and the pipe data authentication center, and the security and credibility flow of the smart pipe network data domain is realized according to the data security and credibility architecture. The technical problems in the prior art that data is difficult to flow between the internal and external data in the flow process, there is a security risk in the data flow process, data is easy to be copied, leaked, destroyed, hijacked and tampered with, the pipe data itself cannot be guaranteed to be credible and safe, and the data security technology problem are solved. By constructing the smart pipe network data domain, the data item grading list database and the pipe data authentication center, the technical effect of the security and credibility flow of the smart pipe network data domain in the data security and credibility architecture is achieved.
[0012] The above description is only a summary of the technical solutions of the application. In order to enable the technical means of the application to be more clearly understood, the application can be implemented according to the content of the description, and in order to enable the above and other purposes, characteristics and advantages of the application to be more obvious and easy to understand, the following specific embodiments of the application are described. BRIEF DESCRIPTION OF DRAWINGS
[0013] Figure 1 A smart pipe network data security and credibility architecture method flowchart is provided for the embodiment of the application.
[0014] Figure 2 A smart pipe network data security and credibility architecture method flowchart is provided for the embodiment of the application.
[0015] Figure 3A flowchart of a process of generating the secure and trusted execution environment in a smart pipe network data security and trusted architecture method provided by an embodiment of the present application is provided.
[0016] Figure 4 A flowchart of a process of collaborative computing and circulation by a third data collaborative party in a smart pipe network data security and trusted architecture method provided by an embodiment of the present application is provided.
[0017] Figure 5 A schematic diagram of a structure of a smart pipe network data security and trusted architecture device provided by an embodiment of the present application is provided.
[0018] Figure 6 A schematic diagram of a structure of an exemplary electronic device of an embodiment of the present application is provided.
[0019] Legend: first obtaining unit 11, second obtaining unit 12, first identification unit 13, third obtaining unit 14, first sending unit 15, fourth obtaining unit 16, first processing unit 17, first sending unit 18, bus architecture 300, receiver 301, processor 302, transmitter 303, memory 304, bus interface 305. DETAILED DESCRIPTION
[0020] The embodiments of the present application provide a smart pipe network data security and trusted architecture method and system, which solve the technical problems of data circulation application difficulty between internal and external data, security risk in data circulation process, and inability to guarantee the trustworthiness and data security of pipe data in the prior art. By constructing a smart pipe network data domain, a data item grading inventory database, and a pipe data authentication and certification center, the technical effects of circulation and sharing of smart pipe data in the internal and external data security and trusted architecture, and improvement of the security and trustworthiness of each link of smart pipe data are achieved.
[0021] In the following, example embodiments according to the present application will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application, and it should be understood that the present application is not limited to the example embodiments described herein.
[0022] SUMMARY
[0023] With the development of IoT, communication, AI, big data, industrial control, and cloud computing technologies, a large number of critical pipeline information infrastructures and intelligent devices have been created and developed, making smart pipeline networks a reality. Against the backdrop of rapid pipeline construction, a large number of old and new pipelines coexist. Old pipelines, limited by technological levels during their construction, have lower levels of informatization and automation, and rely heavily on manual maintenance and management. New pipelines have adopted some IoT and AI equipment, but still require personnel for management and control. This technology addresses existing challenges such as difficulties in data flow and application between internal and external systems, security risks during data transfer, and the inability to guarantee the reliability of pipeline data itself, as well as data security issues. To address the aforementioned technical issues, the overall approach of the technical solution provided in this application is as follows: Constructing a smart pipeline network data domain; generating a first circulation dimension and a second circulation dimension by analyzing the circulation attributes of the smart pipeline network data domain; constructing a two-dimensional data partitioning coordinate system using the first circulation dimension and the second circulation dimension as the horizontal and vertical axes, respectively; inputting the smart pipeline network data domain into the two-dimensional data partitioning coordinate system for data domain partitioning to obtain a first partitioned data domain, wherein the first partitioned data domain includes four data domains; obtaining a preset classification coordinate domain, wherein the preset classification coordinate domain is used to classify the data environment; classifying and quality-cleaning all partitioned data items in the first partitioned data domain according to the preset classification coordinate domain, and constructing a data item classification list database; generating a data security and trustworthy architecture based on the data item classification list database and the pipeline data authentication and certification center; realizing secure and trustworthy circulation of the smart pipeline network data domain based on the data security and trustworthy architecture, achieving the technical effect of sharing and circulating smart pipeline data within the internal and external data security and trustworthy architecture, and improving the security and trustworthiness of each link of smart pipeline data.
[0024] To better understand the above technical solutions, the following will provide a detailed explanation of the technical solutions in conjunction with the accompanying drawings and specific implementation methods.
[0025] Example One
[0026] like Figure 1 As shown in the figure, this application provides a method and system for a secure and trusted architecture for smart pipeline network data. The method is applied to a secure and trusted architecture system for smart pipeline network data, and the system is communicatively connected to a pipeline data authentication and authorization center. The method includes:
[0027] Step S100: Construct the smart pipeline network data domain;
[0028] Specifically, for each type of data generated by the smart pipeline, all data in the smart pipeline network can be divided into non-secure data environment, secure data environment, and trusted data environment according to the data attributes. Some data naturally needs to be publicly shared and belongs to publicly accessible data. For this part of data, it can be divided into non-secure data environment and does not need to emphasize the security attribute of the data. The data that needs to be collected, queried, stored, processed and applied in a secure environment is divided into a secure environment. The constructed secure environment should meet the security requirements of the data environment within the security boundary. The data included in the secure data environment should be strictly managed in accordance with the laws and regulations of the national and enterprise internal network and data security levels. For example, according to the requirements of network security protection, security level evaluation, data security laws and regulations, technical control is implemented through asset investigation, permission management, security scanning, attack and defense drilling, monitoring and auditing and other technical means; a network security protection system is established to protect the data security of the secure environment. Further, within the secure data environment, a trusted data environment is further distinguished, and a trusted attribute requirement is added. The data in this boundary area needs to build a secure and trusted computing environment under the premise of security, and collect, query, store, analyze and apply in the trusted environment. Through the division of the application environment of each type of data generated by the smart pipeline, the positioning and marking of each type of data in the above data application environment quadrant are achieved, and the technical effect of giving the appropriate level of protection to the data item in this position is achieved.
[0029] Step S200: generating a first flow dimension and a second flow dimension by analyzing the flow attribute of the smart pipeline data domain;
[0030] Specifically, the analysis of the flow attribute of the smart pipeline data domain is to analyze the data in the smart pipeline network according to the flow direction of the data. The data flow direction can be divided into internal and external. Specifically, the internal flow data is the data flowing within the department, and the external flow data is the data flowing outside the department. According to the attribute of whether the data is shared, the smart pipeline data can be divided into private data and shared data. Specifically, private data refers to data that is private to a department or an individual and cannot be shared with other departments or individuals. Shared data refers to data that can be shared between departments or individuals. The first flow dimension is the internal flow dimension and the external flow dimension, and the second flow dimension is the private data dimension and the shared data dimension. By analyzing the flow attribute of the smart pipeline data domain, the smart pipeline data is divided into internal flow data, external flow data, private data and shared data, which achieves the technical effect of precise control of smart pipeline data and saves data control cost.
[0031] Step S300: constructing a two-dimensional data division coordinate system with the first flow dimension and the second flow dimension as the horizontal and vertical axes, respectively;
[0032] Step S400: inputting the smart pipe network data domain into the two-dimensional data division coordinate system for data domain division to obtain a first division data domain, wherein the first division data domain includes four data domains;
[0033] Specifically, a two-dimensional data division coordinate system is constructed with the first flow dimension and the second flow dimension as the horizontal and vertical axes, i.e., the first flow dimension as the X-axis and the second flow dimension as the Y-axis. By constructing the two-dimensional data division coordinate system, the smart pipe network data domain is input into the two-dimensional data division coordinate system for data domain division. In the secure and trusted data domain, the data domain is further divided according to the internal and external attributes and the private and shared attributes of the data. Further, a first division data domain is obtained, which includes four data domains. Specifically, when the secure and trusted data domain is input into the two-dimensional data division coordinate system for data domain division, the secure and trusted data domain can be divided into four quadrants by the two-dimensional data division coordinate system. From the first quadrant to the fourth quadrant, they are: external private secure and trusted environment, external shared secure and trusted environment, internal shared secure and trusted environment, and internal private secure and trusted environment. By further dividing the secure and trusted data domain, the first division data domain is obtained, which achieves the technical effect of selecting different data security and trust technologies and methods according to different data regions to realize data security and trust in different scenarios.
[0034] Step S500: obtaining a preset level coordinate domain, wherein the preset level coordinate domain is used for grading the data environment;
[0035] Step S600: grading and quality cleaning all division data items in the first division data domain according to the preset level coordinate domain to construct a data item grading list database;
[0036] Specifically, according to the first division data domain obtained in step S400, a preset level coordinate domain is obtained, which is constructed according to the smart pipe network data domain and the two-dimensional data division coordinate system. Specifically, the preset level coordinate domain can be used for grading the data environment. The grading of the data environment is to divide the data environment into three levels of non-secure and trusted environment, secure and non-trusted environment, and secure and trusted environment by the preset level coordinate domain. For example, if a data environment is in a secure environment and a trusted environment, the security level of the data environment is secure and trusted environment,
[0037] According to the preset level coordinate domain, all divided data items in the first divided data domain are graded and quality cleaned. Specifically, the grading of all divided data items in the first divided data domain is to label each data with different data dimension labels such as "internal", "external", "private", "shared", etc. The marking fragment cannot be removed by conventional data transformation, processing, encryption, etc. Specifically, the quality cleaning is to provide a quality checking tool to clean the data quality before data inflow to avoid quality rectification in subsequent data flow and to avoid interference and resource waste caused by inflow of garbage data that does not meet the requirements. A data item grading list database is constructed, which facilitates quick retrieval and grading of data. By pre-setting the level coordinate domain, all divided data items are graded and quality cleaned, and a data item grading list database is constructed, which achieves the technical effects of facilitating quick retrieval of data and avoiding interference and resource waste caused by garbage data.
[0038] Step S700: generating a data security and trust architecture according to the data item grading list database and the pipeline data authentication and certification center;
[0039] Step S800: realizing the security and trust circulation of the smart pipe network data domain according to the data security and trust architecture.
[0040] Specifically, the pipeline data authentication and certification center is used for the registration, application and obtaining of unique keys and authorization certificates of internal and external devices, personnel and institutions involved in the smart pipeline. The center is technically implemented and managed and maintained by the smart pipeline data asset security and the competent department. External institutions can also directly register and authorize the authentication center as authorized objects to the internal authorization center. The authorization certificate, key algorithm, authorized object, etc. should be updated and maintained regularly. The whole process of data collection, flow and application should be recorded in the authentication and certification center. The generated data security and trust architecture is four kinds of data environments in the grading list database. When technically implemented, different technical implementation methods should be designed according to different scenes to realize different data security and trust requirements.
[0041] The data security and trust architecture is used to realize the secure and trusted flow of the smart pipe network data domain. For different secure and trusted technical methods, the secure and trusted flow of the smart pipe data between different secure and trusted environments inside and outside is realized. For example, for the secure and trusted flow of internal private data, the trusted execution environment construction technology is used to realize the secure and trusted flow. For the secure and trusted flow of internal shared data, the secure and trusted flow is realized by limiting the internal trusted program read-only access, the secure and trusted sandbox read-only access, the file loading synchronous closed terminal external function, and the like. Through the data security and trust architecture, the secure and trusted flow of the smart pipe network data domain is realized, and the technical effect of generating corresponding data security and trust flow according to different flow dimensions and different security levels is achieved.
[0042] Further, as shown in Figure 2 The embodiment of the present application further includes the step S900:
[0043] Step S910: obtaining a first real-time flow data flow between two parties, wherein the data flow between two parties includes a first data flow party and a second data flow party;
[0044] Step S920: obtaining a first data domain label and a first classification environment of the first data flow party;
[0045] Step S930: obtaining a second data domain label and a second classification environment of the second data flow party;
[0046] Step S940: judging whether the first classification environment and the second classification environment are in the same preset classification environment;
[0047] Step S950: if the first classification environment and the second classification environment are in the same preset classification environment, generating a secure and trusted execution environment according to the first data domain label and the second data domain label.
[0048] Specifically, the first real-time data flow is the process of transmitting any real-time data from one party to another party. The first data flow party is the initiator of data transmission, and the second data flow party is the acceptor of data transmission. The first data domain label and the first classification environment of the first data flow party are obtained. Specifically, the first data domain label is the data domain label of the first data flow party, that is, any one of the external private secure and trusted environment, the external shared secure and trusted environment, the internal shared secure and trusted environment, and the internal private secure and trusted environment. The first classification environment is the classification environment of the first data flow party, that is, any one of the non-secure and trusted data domain, the secure data domain, and the secure and trusted data domain.
[0049] obtaining a second data domain label and a second classification environment of the second data flow party, wherein the second data domain label is a data domain label of the second data flow party, and the second classification environment is a classification environment of the second data flow party; further determining whether the first classification environment and the second classification environment are in a same preset classification environment; further, if the first classification environment and the second classification environment are in the same preset classification environment, generating a secure and trusted execution environment according to the first data domain label and the second data domain label, for example, if the first classification environment and the second classification environment are both secure and trusted environments, the first data domain label is an internal shared secure and trusted environment, and the second data domain label is an external shared secure and trusted environment, the secure and trusted execution environment is constituted by the internal secure and trusted environment to the external secure and trusted environment.
[0050] Further, as shown in Figure 3 According to the first data domain label and the second data domain label, the step S950 further includes:
[0051] Step S951: If the first classification environment and the second classification environment are in the preset classification environment, obtaining a first input instruction;
[0052] Step S952: Constructing an execution environment requirement analysis model;
[0053] Step S953: According to the first input instruction, inputting the first data domain label and the second data domain label into the execution environment requirement analysis model, and obtaining first output information according to the execution environment requirement analysis model, wherein the first output information is data security and trusted environment requirement information;
[0054] Step S954: Generating the secure and trusted execution environment based on the first output information and the data security and trusted architecture.
[0055] Specifically, the first input instruction is generated when the first classification environment and the second classification environment are in a safe and trusted environment, and the first input instruction is used to input the first data domain label and the second data domain label into an execution environment requirement analysis model. The execution environment requirement analysis model generates data security and trusted environment requirement information according to the input first data domain label and second data domain label. Specifically, the execution environment requirement analysis model can be one of a neural network model, a machine learning model, and a deep learning model. According to the execution environment requirement analysis model, first output information is obtained. Specifically, the first output information is security and trusted environment requirement information. The security and trusted environment requirement information refers to the requirement information of the classification environment and the data domain label of both parties for data circulation in order to ensure the security of data transmission. Based on the first output information and the data security and trusted architecture, the secure and trusted execution environment is generated. Specifically, the secure and trusted execution environment is generated by the secure and trusted environment requirement information and the data security and trusted architecture, and is used for data transmission between both parties for data circulation. Through the execution environment requirement analysis model, data security and trusted environment requirement information is generated, and the technical effect of further ensuring the security and trustworthiness of the execution environment is achieved.
[0056] Further, as Figure 4 The embodiments of the present application also include:
[0057] Step S931: determining whether the first data domain label and the second data domain label have a private label of the second circulation dimension.
[0058] Step S932: if the first data domain label and the second data domain label have a private label of the second circulation dimension, a first external private data environment and a second external private data environment corresponding to the first data circulation party and the second data circulation party are respectively constructed.
[0059] Step S933: according to the first external private data environment and the second external private data environment, a third data coordination party performs collaborative calculation and circulation.
[0060] Specifically, the private label of the second flow dimension refers to the private data dimension in the second flow dimension, and the judgment of whether the first data domain label and the second data domain label have the private label of the second flow dimension refers to whether the first data domain label and the second data domain label belong to the private data dimension label. If the first data domain label and the second data domain label have the private label of the second flow dimension, the first external private data environment and the second external private data environment corresponding to the first data flow party and the second data flow party are respectively constructed, and the third data collaborative party performs collaborative calculation and flow according to the first external private data environment and the second external private data environment. The third data collaborative party performs collaborative calculation and flow, which is to establish a calculation model by a third party as a collaborator to encrypt the data of the data flow parties on the basis of ensuring data privacy security and legal compliance, and feed back the calculation results to the data flow parties respectively, and the data flow parties will only get the calculation results and will not get the data of other data parties. Through the third data collaborative party for collaborative calculation and flow, the technical effect of ensuring that the data flow parties will not leak their respective data to the outside while exchanging data is achieved.
[0061] Further, the embodiments of the application also include:
[0062] Step S9531: Obtain the first data acquisition device information of the smart pipe network data domain;
[0063] Step S9532: Analyze the function and geometry of the data acquisition device according to the first data acquisition device information to obtain a first function index and a first geometry index;
[0064] Step S9533: Input the first function index and the first geometry index into a logistic regression model for logistic judgment to obtain a first judgment result, wherein the first judgment result includes a first result and a second result, the first result is a device embedded execution result, and the second result is a chip implanted execution result;
[0065] Step S9534: Add the first judgment result as first additional information to the first output information.
[0066] Specifically, the first data collection device information is any pipe network data collection device, which can be an Internet of Things sensing device or a manually operated collection device, for collecting parameter, material and function information. The first function index refers to the functional use of the first data collection device, which can be collecting humidity in a long-distance oil and gas pipeline or collecting temperature in a long-distance oil and gas pipeline. The first geometric index refers to the size information of the first data collection device, including length, width, width, etc. The logistic regression model is a linear regression analysis model that can predict the probability of data leakage occurrence according to risk factors. The first function index and the first geometric index can be obtained through the logistic regression model. The first judgment result includes a first result and a second result. The first result is a device embedding execution result. Specifically, for Internet of Things data collection devices with simple functions and weak processing capabilities, these collection devices can be directly embedded and run on an integrated secure and trusted execution environment hardware to complete security authentication functions such as data encryption and decryption. The second result is a chip implantation execution result. For collection devices with slightly complex functions or larger size, a secure and trusted chip product can be implanted to build a secure and trusted application runtime environment to achieve the purpose of secure and trusted private data protection. The first judgment result is added to the first output information as first additional information. The first additional information is a supplementary description of the first output information. The first function index and the first geometric index are calculated through the logistic regression model to obtain the first additional information of the first output information, thereby achieving the technical effect of perfecting the first output information.
[0067] Further, the embodiments of the application further include:
[0068] Step S610: constructing data quality verification rules, data standard verification rules and data conflict verification rules;
[0069] Step S620: generating first data verification rules according to the data quality verification rules, the data standard verification rules and the data conflict verification rules;
[0070] Step S630: performing data quality cleaning on the first real-time circulation data based on the first data verification rules to obtain second real-time circulation data;
[0071] Step S640: circulating in the secure and trusted execution environment according to the second real-time circulation data.
[0072] Specifically, the data quality checking rule can be used to check whether the input data is consistent with a unique and explicit data source, and whether the original data is consistent with the data collection specification; check whether the input data is consistent with the data application system data dictionary standard in the data scene; check whether the input data and other input data have conflicts, including time, place and content conflicts. According to the data quality checking rule, the data standard checking rule and the data conflict checking rule, a first data checking rule is generated, which can be used for data quality cleaning of the first flow data. The data quality cleaning refers to removing garbage data that does not meet the data collection specification, does not meet the data application system data dictionary standard in the data scene, and has conflicts with other input data in the first flow data through the first data checking rule. After the data quality cleaning of the first flow data, the second flow data is obtained, and further, the second real-time flow data is further circulated in the secure and trusted execution environment. Through the data quality cleaning of the first flow data by the first data checking rule, the technical effect of avoiding interference and resource waste caused by the flow of garbage data that does not meet the requirements is achieved.
[0073] Further, the embodiments of the application also include:
[0074] Step S1010: obtaining first monitoring data by performing data monitoring and tracking on the execution process of all secure and trusted environments of the data security and trusted architecture;
[0075] Step S1020: generating a first risk assessment coefficient by screening and evaluating abnormal data of the first monitoring data;
[0076] Step S1030: obtaining first reminder information if the first risk assessment coefficient is greater than a preset risk assessment coefficient;
[0077] Step S1040: optimizing the data security and trusted architecture according to the first reminder information.
[0078] Specifically, the data monitoring and tracking is to monitor and track the data in all life cycle of each link, mechanism and scene in the data security and trust architecture by establishing a data monitoring system and platform, the first monitoring data refers to all monitoring results of the data monitoring system and platform to the data security and trust architecture, the first risk assessment coefficient is generated by screening and evaluating the abnormal data of the first monitoring data, the abnormal data is the data interruption, unauthorized access, abnormal sending and the like in the first monitoring data, the first risk assessment coefficient is the influence coefficient of any abnormal data on data security, according to the influence and threat degree of the safe and reliable environment of the data security and trust architecture, the first risk assessment coefficient of the abnormal data is different, if the first risk assessment coefficient is greater than the preset risk assessment coefficient, the first prompt information is obtained, the preset risk assessment coefficient refers to the maximum value of the first risk assessment coefficient allowed by the data security and trust architecture, the first prompt information includes warning and interception, the optimization of the data security and trust architecture according to the first prompt information refers to the periodical rectification, replacement and upgrade of the found vulnerabilities and problems, and the verification effect. By establishing the data monitoring system and platform, the data monitoring and tracking of all safe and reliable environment execution processes of the data security and trust architecture are realized, and the technical effects of real-time protection of the data security and trust architecture and maintenance of the safe and reliable environment of the intelligent pipeline are achieved.
[0079] Compared with the prior art, the present application has the following beneficial effects:
[0080] 1.The method for a smart pipe network data security and credibility architecture according to the present application, which constructs a smart pipe network data domain, analyzes the flow attribute of the smart pipe network data domain to generate a first flow dimension and a second flow dimension, constructs a two-dimensional data division coordinate system with the first flow dimension and the second flow dimension as the horizontal axis and the vertical axis respectively, inputs the smart pipe network data domain into the two-dimensional data division coordinate system to obtain a first division data domain, wherein the first division data domain includes four data domains, obtains a preset level coordinate domain, wherein the preset level coordinate domain is used for grading the data environment, grades and quality cleans all division data items in the first division data domain according to the preset level coordinate domain, and constructs a data item grading list database; generates a data security and credibility architecture according to the data item grading list database and the pipe data authentication center; and realizes the secure and credible flow of the smart pipe network data domain according to the data security and credibility architecture. The method solves the technical problems of the prior art, such as the difficulty of data flow application between the internal and external data in the flow process, the security risk in the data flow process, and the inability to guarantee the credibility and data security of the pipe data. By constructing the smart pipe network data domain, the data item grading list database, and the pipe data authentication center, the technical effects of the secure and credible flow of the smart pipe data in the internal and external data security and credibility architecture and the improvement of the security and credibility of the smart pipe data in each link are achieved.
[0081] 2.The method for a smart pipe network data security and credibility architecture according to the present application, which performs data quality cleaning on the first flow data according to the first data verification rule, so as to avoid the interference and resource waste caused by the flow of garbage data that does not meet the requirements. The technical effect of avoiding the interference and resource waste caused by the flow of garbage data that does not meet the requirements is achieved.
[0082] 3.The method for a smart pipe network data security and credibility architecture according to the present application, which performs data monitoring and tracking on the flow of all secure and credible environments of the data security and credibility architecture by establishing a data monitoring system and platform, so as to realize the real-time protection of the data security and credibility architecture and the maintenance of the secure and credible environment of the smart pipe. The technical effects of the real-time protection of the data security and credibility architecture and the maintenance of the secure and credible environment of the smart pipe are achieved.
[0083] Example Two
[0084] Based on the same inventive concept as the method for a smart pipe network data security and credibility architecture in the foregoing embodiment, the present application also provides a system for a smart pipe network data security and credibility architecture. Please refer to the accompanying drawings Figure 5 , which comprises:
[0085] A first construction unit 11 is configured to construct a smart pipe network data domain.
[0086] A first generation unit 12 is configured to analyze the flow attribute of the smart pipe network data domain to generate a first flow dimension and a second flow dimension.
[0087] The second construction unit 13 is configured to construct a two-dimensional data division coordinate system with the first flow dimension and the second flow dimension as the transverse axis and the longitudinal axis, respectively.
[0088] The first input unit 14 is configured to input the smart pipe network data domain into the two-dimensional data division coordinate system for data domain division to obtain a first divided data domain, wherein the first divided data domain includes four data domains.
[0089] The first obtaining unit 15 is configured to obtain a preset level coordinate domain, wherein the preset level coordinate domain is used for grading the data environment.
[0090] The third construction unit 16 is configured to grade and quality clean all divided data items in the first divided data domain according to the preset level coordinate domain, and construct a data item grading list database.
[0091] The second generation unit 17 is configured to generate a data security and trust architecture according to the data item grading list database and a pipeline data authentication center.
[0092] The first flow unit 18 is configured to realize the secure and trusted flow of the smart pipe network data domain according to the data security and trust architecture.
[0093] Further, the system further comprises:
[0094] The second obtaining unit is configured to obtain a first real-time flow data flow transaction party, wherein the data flow transaction party includes a first data flow transaction party and a second data flow transaction party.
[0095] The third obtaining unit is configured to obtain a first data domain label and a first grading environment of the first data flow transaction party.
[0096] The fourth obtaining unit is configured to obtain a second data domain label and a second grading environment of the second data flow transaction party.
[0097] The first judging unit is configured to judge whether the first grading environment and the second grading environment are in the same preset level environment.
[0098] The third generation unit is configured to generate a secure and trusted execution environment according to the first data domain label and the second data domain label if the first grading environment and the second grading environment are in the same preset level environment.
[0099] Further, the system further comprises:
[0100] a fifth obtaining unit, configured to obtain a first input instruction if the first rating environment and the second rating environment are the preset rating environment;
[0101] a fourth constructing unit, configured to construct an execution environment requirement analysis model;
[0102] a sixth obtaining unit, configured to input the first data domain label and the second data domain label into the execution environment requirement analysis model according to the first input instruction, and obtain first output information according to the execution environment requirement analysis model, wherein the first output information is data security and trusted environment requirement information;
[0103] a fourth generating unit, configured to generate the secure and trusted execution environment based on the first output information and the data security and trusted architecture.
[0104] Further, the system further comprises:
[0105] a second judging unit, configured to judge whether the first data domain label and the second data domain label have a private label of the second circulation dimension;
[0106] a fifth constructing unit, configured to construct a first external private data environment and a second external private data environment corresponding to the first data circulation party and the second data circulation party respectively if the first data domain label and the second data domain label have the private label of the second circulation dimension;
[0107] a first calculating unit, configured to perform collaborative calculation and circulation by a third data collaborative party according to the first external private data environment and the second external private data environment.
[0108] Further, the system further comprises:
[0109] a seventh obtaining unit, configured to obtain first data acquisition device information of the smart pipe network data domain;
[0110] an eighth obtaining unit, configured to analyze the data acquisition device in terms of function and geometry according to the first data acquisition device information, and obtain a first function index and a first geometry index;
[0111] The ninth obtaining unit is configured to input the first function index and the first geometry index into a logistic regression model to perform a logistic judgment and obtain a first judgment result, wherein the first judgment result includes a first result and a second result, the first result is a device embedding execution result, and the second result is a chip implantation execution result.
[0112] The first adding unit is configured to add the first judgment result as first additional information to the first output information.
[0113] Further, the system further includes:
[0114] The sixth constructing unit is configured to construct a data quality checking rule, a data standard checking rule and a data conflict checking rule.
[0115] The fifth generating unit is configured to generate a first data checking rule according to the data quality checking rule, the data standard checking rule and the data conflict checking rule.
[0116] The first cleaning unit is configured to perform data quality cleaning on the first real-time flow data based on the first data checking rule to obtain second real-time flow data.
[0117] The first flow unit is configured to flow in the secure and reliable execution environment according to the second real-time flow data.
[0118] Further, the system further includes:
[0119] The tenth obtaining unit is configured to obtain first monitoring data by performing data monitoring and tracking on all secure and reliable environments of the data security and reliability architecture.
[0120] The sixth generating unit is configured to generate a first risk assessment coefficient by screening and evaluating abnormal data of the first monitoring data.
[0121] The eleventh obtaining unit is configured to obtain first reminding information if the first risk assessment coefficient is greater than a preset risk assessment coefficient.
[0122] The first optimization unit is configured to optimize the data security and reliability architecture according to the first reminding information.
[0123] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments. Figure 1The method for a smart pipe network data security and trust architecture in embodiment one and the specific example are also applicable to the smart pipe network data security and trust architecture system in the present embodiment. Through the foregoing detailed description of the method for a smart pipe network data security and trust architecture, those skilled in the art can clearly understand the smart pipe network data security and trust architecture system in the present embodiment. Therefore, for the sake of brevity of the description, the smart pipe network data security and trust architecture system in the present embodiment will not be described in detail. As the device disclosed in the embodiment corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant part is described in the method part.
[0124] The above description of the disclosed embodiments enables a person skilled in the art to implement or use the present application. Various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
[0125] Exemplary Electronic Device
[0126] The electronic device of the embodiments of the present application will be described below with reference to Figure 6
[0127] Figure 6 FIG. 1 illustrates a structural schematic diagram of an electronic device according to an embodiment of the present application.
[0128] Based on the method for a smart pipe network data security and trust architecture in the foregoing embodiment, the present application further provides a method system for a smart pipe network data security and trust architecture, which has a computer program stored thereon, and the program is executed by a processor to implement the steps of any method of the method for a smart pipe network data security and trust architecture.
[0129] wherein, in Figure 6 In particular embodiments, a bus architecture (represented by bus 300) can include any number of interconnecting buses and bridges needed to link various circuitry from the one or more processors represented by processor 302 and memory represented by memory 304. Bus 300 can also link various other circuitry, such as peripheral devices, voltage regulators, and power management circuitry, all of which are well known in the art, and therefore, not described in more detail herein. Bus interface 305 provides an interface between bus 300 and receiver 301 and transmitter 303. Receiver 301 and transmitter 303 can be the same device, i.e., a transceiver, providing a unit for communicating with various other apparatus over the transmission medium. Processor 302 is responsible for managing the bus 300 and general processing, while the memory 304 can be used for storing data used by the processor 302 in executing operational processes.
[0130] The application provides a smart pipe network data security and credibility architecture method, wherein the method is applied to a smart pipe network data security and credibility architecture system, the system is in communication connection with a pipe data authentication center, and the method comprises the following steps: constructing a smart pipe network data field; generating a first flow dimension and a second flow dimension by analyzing the flow attribute of the smart pipe network data field; constructing a two-dimensional data division coordinate system by taking the first flow dimension and the second flow dimension as the horizontal axis and the vertical axis respectively; inputting the smart pipe network data field into the two-dimensional data division coordinate system to divide the data field and obtain a first division data field, wherein the first division data field comprises four data fields; obtaining a preset level coordinate field, wherein the preset level coordinate field is used for grading the data environment; grading and quality cleaning all division data items in the first division data field according to the preset level coordinate field, and constructing a data item grading list database; generating a data security and credibility architecture according to the data item grading list database and the pipe data authentication center; and realizing the secure and credible flow of the smart pipe network data field according to the data security and credibility architecture. The method solves the technical problems in the prior art that data flow application is difficult between the internal and external data in the flow process, there is a security risk in the data flow process, and the pipe data itself cannot be guaranteed to be credible and safe. By constructing the smart pipe network data field, the data item grading list database and the pipe data authentication center, the technical effects of the secure and credible flow of the smart pipe network data in the internal and external data security and credibility architecture and the improvement of the security and credibility of the smart pipe network data in each link are achieved.
[0131] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, apparatus, or computer program product. Accordingly, the present application can take the form of an entirely software embodiment, an entirely hardware embodiment or an embodiment combining software and hardware aspects all generally referred to herein as a "circuit" or "module." Furthermore, the present application can take the form of a computer program product on one or more computer readable storage media (media) having computer readable program code embodied, including but not limited to, semiconductor(s), magnetic disk(s), optical disk(s) such as CD-ROM, DVD, Blu-ray, or any combination thereof, encoded thereon.
[0132] The present application is described in reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks.
[0133] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart illustrations and / or block diagrams block or blocks. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks.
[0134] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure One one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure OneThe steps of a method, process, or algorithm described in connection with the present disclosure can be embodied directly in hardware, in a software module executed by a processor, or in a combination of the two. A software module can reside in RAM, flash memory, ROM, EEPROM, or any other form of non-transitory computer-readable storage medium known in the art. When the software module is inserted into the computer system, it can cause the computer system to be made to perform the steps of the method, process, or algorithm. Alternatively, the features and aspects of the present disclosure can be implemented in hardware, or a combination of hardware and software.
[0135] It will be apparent to those skilled in the art that various modifications and variations can be made to the present disclosure without departing from the spirit or scope of the disclosure. Thus, it is intended that the present disclosure cover the modifications and variations of this disclosure provided they come within the scope of the appended claims and their equivalents.
Claims
1. A method for a secure and reliable data architecture for smart pipeline networks, wherein, The method is applied to a smart pipeline network data security and trustworthy architecture system, the system being communicatively connected to a pipeline data authentication and authorization center, and the method includes: Constructing a smart pipeline network data domain; By performing flow attribute analysis on the smart pipeline network data domain, a first flow dimension and a second flow dimension are generated. A two-dimensional data partitioning coordinate system is constructed using the first circulation dimension and the second circulation dimension as the horizontal and vertical axes, respectively. The first circulation dimension refers to the internal circulation dimension and the external circulation dimension, and the second circulation dimension refers to the private data dimension and the shared data dimension. The smart pipeline network data domain is input into the two-dimensional data partitioning coordinate system to partition the data domain, thereby obtaining a first partitioned data domain, wherein the first partitioned data domain includes four data domains. Obtain a preset level coordinate domain, wherein the preset level coordinate domain is used to classify the data environment; Based on the preset grade coordinate domain, all partitioned data items in the first partitioned data domain are graded and quality cleaned to construct a data item graded list database. Based on the data item classification list database and the pipeline data authentication center, a data security and trustworthy architecture is generated. The secure and reliable flow of data in the smart pipeline network is achieved based on the aforementioned data security and trustworthy architecture.
2. The method as described in claim 1, wherein, The method further includes: The two parties that obtain the first real-time circulating data include the first data circulating party and the second data circulating party; Obtain the first data domain label and the first classification environment of the first data circulation party; Obtain the second data domain label and the second classification environment of the second data circulation party; Determine whether the first classification environment and the second classification environment are in the same preset classification environment; If the first rating environment and the second rating environment are in the same preset rating environment, a secure and trusted execution environment is generated based on the first data domain label and the second data domain label.
3. The method as described in claim 2, wherein, The method for generating a secure and trusted execution environment based on the first data field label and the second data field label further includes: If the first rating environment and the second rating environment are in the preset rating environment, a first input instruction is obtained; Construct an execution environment requirements analysis model; According to the first input instruction, the first data domain label and the second data domain label are input into the execution environment requirements analysis model. According to the execution environment requirements analysis model, the first output information is data security and trustworthy environment requirements information. Based on the first output information and the data security and trustworthy architecture, the secure and trustworthy execution environment is generated.
4. The method of claim 2, wherein, The method further includes: Determine whether the first data field label and the second data field label have a private label for the second circulation dimension; If the first data domain label and the second data domain label have private labels for the second circulation dimension, construct the first external private data environment and the second external private data environment corresponding to the first data circulation party and the second data circulation party, respectively. Based on the first external private data environment and the second external private data environment, collaborative computing and circulation are carried out by the third data collaborator.
5. The method of claim 3, wherein, The method further includes: Obtain information about the first data acquisition device in the smart pipeline network data domain; Based on the information from the first data acquisition device, the data acquisition device is analyzed functionally and geometrically to obtain a first functional index and a first geometric index. Logistic regression models are input based on the first functional index and the first geometric index to make logical judgments and obtain a first judgment result. The first judgment result includes a first result and a second result. The first result is the device embedding execution result, and the second result is the chip implantation execution result. The first judgment result is added as the first additional information to the first output information.
6. The method of claim 2, wherein, The method further includes: Construct data quality verification rules, data standard verification rules, and data conflict verification rules; Based on the data quality verification rule, the data standard verification rule, and the data conflict verification rule, a first data verification rule is generated; Based on the first data verification rule, the first real-time circulating data is cleaned to obtain the second real-time circulating data. The second real-time circulation data circulates within the secure and trusted execution environment.
7. The method of claim 1, wherein, The method further includes: The first monitoring data is obtained by monitoring and tracking the execution processes of all secure and trusted environments within the data security and trusted architecture. A first risk assessment coefficient is generated by screening and evaluating abnormal data from the first monitoring data. If the first risk assessment coefficient is greater than the preset risk assessment coefficient, a first alert message is received. The data security and trustworthy architecture is optimized based on the first reminder information.
8. A smart pipeline network data security and trustworthy architecture system, wherein, The system includes: First Construction Unit: The first construction unit is used to construct the smart pipeline network data domain; First generation unit: The first generation unit is used to generate a first circulation dimension and a second circulation dimension by performing circulation attribute analysis on the smart pipeline network data domain; Second construction unit: The second construction unit is used to construct a two-dimensional data partitioning coordinate system with the first circulation dimension and the second circulation dimension as the horizontal axis and the vertical axis, respectively. The first circulation dimension is the internal circulation dimension and the external circulation dimension, and the second circulation dimension refers to the private data dimension and the shared data dimension. First input unit: The first input unit is used to input the smart pipeline data domain into the two-dimensional data partitioning coordinate system to partition the data domain and obtain a first partitioned data domain, wherein the first partitioned data domain includes four data domains. First obtaining unit: The first obtaining unit is used to obtain a preset level coordinate domain, wherein the preset level coordinate domain is used to classify the data environment; Third construction unit: The third construction unit is used to classify and clean the quality of all partitioned data items in the first partitioned data domain according to the preset level coordinate domain, and to construct a data item classification list database. Second generation unit: The second generation unit is used to generate a data security and trustworthy architecture based on the data item classification list database and the pipeline data authentication center; First circulation unit: The first circulation unit is used to realize the secure and reliable circulation of the smart pipeline network data domain according to the data security and trustworthy architecture.
9. A smart pipeline network data security and trustworthy architecture system, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein, When the processor executes the program, it implements the steps of the method according to any one of claims 1-7.
Citation Information
Patent Citations
Systems and methods of data transmission and management
CA2770166A1
Operation service data access control based on grade and domain division and realization thereof
CN104113432A