Blockchain-based industrial internet device instruction operation security method
By quantifying the value of equipment instructions and utilizing blockchain technology, an instruction assetization and quota mechanism is constructed, which solves the problem of low security in the operation of equipment instructions in the industrial internet and realizes secure access and traceability of equipment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SICHUAN NORMAL UNIV
- Filing Date
- 2022-08-10
- Publication Date
- 2026-04-17
AI Technical Summary
Existing industrial internet device command operation methods have low security, are easily attacked and tampered with, leading to equipment damage and difficulty in tracing responsibility.
By quantifying the assets of industrial enterprises, an IIoT equipment instruction value model is constructed. Based on the decentralized and immutable characteristics of blockchain, an instruction assetization and quota mechanism is designed to control users' access permissions to the equipment.
It improves the security of industrial internet device command operations, prevents unauthorized modification and deletion, protects equipment from damage, and enables traceable operation records.
Smart Images

Figure CN115952553B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a blockchain-based method for ensuring secure operation of industrial internet equipment commands. Background Technology
[0002] The Industrial Internet of Things (IIoT) adds more endpoints than traditional consumer IoT. To manage all devices in an industrial production environment in a unified manner, a distributed cloud platform is needed to integrate and manage smart terminals and field devices within the industrial production environment. During automated industrial production, user control and management of all smart terminals and field devices in the production environment are based on commands issued through this IoT cloud platform.
[0003] Using the methods described above, whether it's a company-owned IoT cloud platform or a public one, the way users manage equipment by issuing commands to production site devices or smart terminals through the IoT cloud platform is not a completely secure management method. First, the industrial internet cloud platform uses traditional access control methods, i.e., gateway control, to manage production site devices and smart terminals. As long as a user has command permissions, they can repeatedly use those commands to control production site devices without restriction. However, repeated operation of certain commands, such as turning devices on / off, or accelerating / decelerating, can at least affect production efficiency, and at worst, cause equipment damage. Second, for ease of tracking and auditing, user commands issued remotely through the industrial internet cloud platform are recorded in detail in the platform's log system database. However, this centralized log system is vulnerable to attack. On the one hand, attackers, once they gain read / write access to the log system, can easily modify or delete information related to device operation commands to evade tracking; on the other hand, dishonest industrial internet cloud administrators, because they have management permissions for the log system, can also modify or delete information related to device operation commands to evade supervisory responsibility. Therefore, whether it is an attacker or a dishonest industrial internet cloud administrator, modifying or deleting information related to device command operations in the log system will cause irreversible physical damage to equipment or smart terminals on the production site, and it will be difficult to detect, thus reducing security. Summary of the Invention
[0004] The purpose of this invention is to provide a blockchain-based secure method for industrial internet device command operation, aiming to solve the problem of low security in existing industrial network device command operation methods.
[0005] To achieve the above objectives, this invention provides a blockchain-based method for secure operation of industrial internet device commands, comprising the following steps:
[0006] The value of an IIoT device instruction is calculated using a quantitative calculation method for industrial enterprise assets, and an IIoT device instruction value model is constructed.
[0007] The initial value of the instruction is calculated based on the IIoT device instruction value model.
[0008] Based on the risk level of equipment instructions, the risk level of operation instructions, and the initial value of the instructions, an instruction assetization model is constructed.
[0009] Calculate user instruction asset quotas based on the instruction assetization model.
[0010] Access to field devices and smart terminals is initiated based on blockchain and command asset quotas.
[0011] The specific method for constructing the IIoT equipment instruction value model by converting industrial internet equipment instructions into quantitative calculations of industrial enterprise assets is as follows:
[0012] Define device operation instructions;
[0013] The type of operation instruction used to obtain device operation commands;
[0014] IIIOT equipment instruction value models are constructed based on operation instruction types and production parameters.
[0015] The specific method for constructing the instruction assetization model based on the risk level of the equipment instruction, the risk level of the operation instruction, and the initial value of the instruction is as follows:
[0016] Define the risk level of device operation instructions and instruction operands.
[0017] The instruction consumption amount is calculated based on the device instruction risk level, the instruction operand risk level, and the instruction initial value.
[0018] A command assetization model is constructed based on the number of times an command can be operated and the amount of command consumption.
[0019] The specific method for initiating access to field devices and smart terminals based on blockchain and instruction asset quotas is as follows:
[0020] The system evaluates user-initiated transaction requests and obtains a decision result.
[0021] The blockchain queries the determination result to obtain transaction details;
[0022] The execution point determines the query result. If the result is true, access can be sent to the field equipment and smart terminal; if the result is false, access is canceled.
[0023] The specific method for judging the transaction request initiated by the user and obtaining the judgment result is as follows:
[0024] The user sends a command request to the command value execution point;
[0025] The instruction execution point sends user information and instruction information to the instruction execution decision point;
[0026] After receiving user information and instruction information, the instruction execution determination point queries the instruction execution permissions of the user in the instruction permission information database to obtain the determination result.
[0027] The specific method for querying the judgment result based on the blockchain to obtain transaction details is as follows:
[0028] The instruction asset determination line sends a query request to the blockchain;
[0029] The blockchain queries the determination result to obtain transaction details.
[0030] The operation instruction parameters include the target equipment location, target object, target data, time duration, and impact on equipment production output.
[0031] The instruction types include switch instructions, equipment status adjustment instructions, raw material input instructions, and read instructions.
[0032] The device status adjustment instructions include sequential control, positioning control, and analog quantity control.
[0033] The asset quantification cost of the industrial enterprise includes direct raw material costs, equipment depreciation costs, and directly involved labor costs.
[0034] This invention presents a blockchain-based secure operation method for industrial internet (IIoT) equipment commands. It calculates the value of individual IIoT equipment commands using a quantitative calculation method for industrial enterprise assets, constructing an IIoT equipment command value model. Based on this model, the initial value of the command is calculated. Then, based on the risk level of the equipment command, the risk level of the operation command, and the initial value of the command, a command assetization model is constructed. Command asset quotas are calculated based on this model. Access to field devices and smart terminals is initiated based on the blockchain and command asset quotas. Leveraging the decentralized, immutable, traceable, and digital asset issuance capabilities of blockchain, this invention designs a secure operation scheme for industrial internet commands. First, the operation commands of smart terminals or field devices are assetized. Then, command operation quotas are allocated according to the user's actual needs for smart terminals or field devices. Finally, user access to devices is controlled simultaneously through command permissions and quota mechanisms. In this scheme, command assetization, quotas, and access to field devices are all published on the blockchain, thereby solving the problem of low security in existing industrial network equipment command operation methods. Attached Figure Description
[0035] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0036] Figure 1 This is a flowchart of a blockchain-based industrial internet device instruction operation security method provided by the present invention.
[0037] Figure 2 This is a flowchart for constructing an IIoT device instruction value model by calculating the instruction value of a single industrial internet device through a quantitative calculation method for industrial enterprise assets.
[0038] Figure 3 It is a device operation command security control model based on blockchain and asset quotas.
[0039] Figure 4 This is a flowchart of the blockchain platform initialization process.
[0040] Figure 5 This is a UML timing diagram of the instruction issuance process. Detailed Implementation
[0041] Embodiments of the present invention are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain the present invention, and should not be construed as limiting the present invention.
[0042] Please see Figures 1 to 5 This invention provides a blockchain-based method for securing instructions and operations of industrial internet devices, comprising the following steps:
[0043] S1 constructs an IIoT equipment instruction value model by converting IIoT equipment instructions into quantitative calculation methods for industrial enterprise assets.
[0044] IIoT (Industrial Internet of Things) is short for Industrial Internet of Things.
[0045] S11 defines the device operation instructions;
[0046] The operation command parameters include the target equipment location, target object, target data, time duration, and impact on equipment production output.
[0047] Specifically, in a single instruction, Operator represents the instruction name, also called the opcode; Address represents the target device location; Object represents the specific target object of the instruction operation; Data represents the target data accessed during the instruction operation; Time represents the specific duration of the instruction's operation, specifically the time period to which the target data belongs in a read instruction; and Yield represents the impact of the instruction on the equipment's production output per unit time. For a specific instruction, Data, Time, and Yield are optional.
[0048] S12 obtains the operation instruction type of the device operation instruction;
[0049] The instruction types include switch instructions, equipment status adjustment instructions, raw material input instructions, and read instructions.
[0050] The equipment status adjustment commands include sequential control, positioning control, and analog quantity control.
[0051] Specifically, based on the operator's function, equipment commands can be divided into four categories: equipment switch commands, raw material input commands, equipment status read commands, and equipment status adjustment commands. Equipment switch commands control the on / off, pause, or resume of equipment. By controlling the timing of equipment switching, they typically affect equipment operation and production output. The main operands involved are Address, Object, Time, and Yield. Raw material input commands control the input of raw materials during equipment production. For example, if raw materials are input during the production process and processed to form finished products or intermediate products, they typically affect equipment operation and production. The main operands involved are Address, Object, Yield, and Time. Equipment status read commands control the user's acquisition of equipment status data. By accessing status data at different time periods, different information about the equipment can be obtained, including operational status data such as voltage, current, power consumption, time, and other relevant parameters during the production process, as well as production summary data and production decision data for specific time periods, such as annual and monthly production data. Generally, these commands do not affect the normal operation and production of the equipment. The main operands involved are Address, Object, Data, and Time; equipment status adjustment instructions control the user's setting and modification of equipment-related parameters, generally controlling production speed, which usually affects the normal operation of the equipment and production output. The main operands involved are Address, Object, Time, and Yield. The specific classification of equipment instructions is shown in Table 1.
[0052] Table 1 Classification of Equipment Instructions
[0053]
[0054] Equipment status adjustment commands are instructions that modify the production process and procedures of field equipment. They are categorized into three types: sequential control, positioning control, and analog control. The value of these commands is the sum of their impact on direct raw material costs, equipment depreciation costs, and directly involved labor costs during the production time they are in effect. (Using Val...) adjust This means that adjust = {speedUp, speedDown}. The Time parameter specifies the duration for which the adjusted device state is maintained.
[0055] Raw material input instructions are instructions that input raw materials during the production process. The value of such instructions should be the sum of the direct raw material costs and the directly involved labor costs affected during their effective time period, expressed as Val. input The specific calculation formula is as follows:
[0056] Valinput =Time Yeild C r (7)
[0057] Read commands are instructions to view on-site production processes or monitoring data. The value of such commands should be the monitoring costs incurred during the data collection period. For example, if a user reads a week's worth of production data, the value of the command should be the total monitoring cost for that week. (Using Val...) read The specific calculation formula is as follows:
[0058] Val read =C rg Time (8)
[0059] S13 constructs IIIOT equipment instruction value models based on operation instruction types and production parameters.
[0060] The production parameters include direct raw material costs, equipment depreciation costs, and directly involved labor costs.
[0061] Specifically, the value of instructions will be used as the primary basis for the assetization of industrial internet equipment instructions. Currently, industrial production follows specific production processes. Each instruction in these processes corresponds to a specific production step, which inevitably involves raw material consumption, direct labor input, and associated manufacturing costs. Therefore, when calculating the value of instructions, the raw material consumption portion focuses on direct raw material consumption and equipment depreciation; the direct labor input portion focuses on production labor costs and regulatory labor costs; and the associated manufacturing costs are not considered because different industrial production processes have completely different associated manufacturing processes, making a unified calculation impossible. The following section details the product manufacturing costs affected by equipment instructions and the estimation of equipment instruction value. The product manufacturing costs affected by equipment instructions will primarily focus on the calculation methods for direct raw material costs, equipment depreciation costs, and direct labor costs.
[0062] Direct raw material consumption costs include essential material costs and process loss costs. Essential materials are the minimum requirements to ensure the product can be processed. Process losses include material losses incurred during processing due to final product requirements, processing technology requirements, clamping, process features, and quality inspection. Additionally, raw material consumption needs to consider recycling and reuse. However, because these raw materials require additional processing before reuse, their unit recycling price is usually lower than the original price. Therefore, the formula for calculating direct raw material costs is as follows:
[0063]
[0064] Among them, Cr —Raw material consumption cost for producing a single product[$]
[0065] W r —Raw material consumption per unit of production [kg]
[0066] P r —Unit price of raw materials for producing a single product [$ / kg]
[0067] K r ——Raw material yield [%)
[0068] W w —Recyclable raw materials portion [kg]
[0069] P w —Unit price of recyclable raw materials [$ / kg]
[0070] There are various methods for calculating equipment depreciation expenses, and different methods yield different depreciation costs for the current period. Even within the same manufacturing company, the calculation method for depreciation expenses can differ due to variations in the use and operation of fixed assets. Depreciation expenses can be primarily calculated using three methods: the straight-line method, the units-of-production method, and the accelerated depreciation method. All three methods are used in manufacturing companies, but the straight-line method is the simplest and most widely applied. This article also uses the straight-line method to calculate equipment depreciation expenses, and the calculation formula is as follows:
[0071] D m =(P0-S) / L (2)
[0072] Among them, D m —Annual depreciation expense for fixed assets [$ / Year]
[0073] P0 – Initial value of fixed assets [$]
[0074] S — The value of fixed assets at the end of the depreciation period [$]
[0075] L – Depreciation period for fixed assets [Year]
[0076] In actual production processes, the directly involved labor costs typically consist of two parts: one is the production labor cost required for all processes, i.e., the real-time operation of equipment by personnel according to the production process instructions; the other is the monitoring labor cost required for all processes, i.e., the monitoring of the production process by personnel according to the process monitoring procedures and by reading on-site data according to instructions. Therefore, the directly involved production labor cost = labor production cost + labor monitoring cost, expressed by the following formula:
[0077] C a =Cpa +C la (3)
[0079] Among them, C a —Unit cost of labor directly involved [$ / Hr]
[0080] C pa —Unit cost of labor directly involved in production [$ / Hr]
[0081] C la —Unit cost of direct labor oversight [$ / Hr]
[0082] Both labor production costs and regulatory costs typically consist of two parts: the average number of workers assigned to the process and the wage per worker per unit of time. Therefore, in equation (3.3), the labor production cost per unit of time = average wage per production worker × number of workers, calculated as follows:
[0083] C pa =C tp N rp (4)
[0084] Among them, C pa —Production cost per unit of time for directly involved labor [$ / Part]
[0085] C tp —Average hourly wage for production workers [$ / Hr / Worker]
[0086] N rp —Number of workers required for each production process [Worker]
[0087] (3) The labor supervision cost in the formula = average wage income per supervised worker × number of workers, and the calculation formula is as follows:
[0088] C la =C td N rg (5)
[0089] Among them, C la —Direct manual supervision cost of a certain process[$ / Part]
[0090] C td — Average hourly wage for regulatory personnel [$ / Hr / Worker]
[0091] N rg —Number of workers required for supervision [Worker]
[0092] S2 calculates the initial value of the instruction based on the IIIOT device instruction value model;
[0093] Specifically, the process of returning the value of an instruction based on the operational cost affected by the instruction is defined as the algorithm operatorVal, as shown in Table 2.
[0094] Table 2 Algorithm operatorVal
[0095]
[0096]
[0097] Algorithm 1 first verifies that the published Operator is not empty, and also checks other parameters such as raw material cost C. r Equipment depreciation cost D m Production labor cost C pa ,Regulating labor costs C la It is not 0. Then, determine the Operator type and calculate the initial value of the instruction according to the formula.
[0098] S3 calculates and constructs an instruction assetization model based on the risk level of the equipment instruction, the risk level of the operation instruction, and the initial value of the instruction.
[0099] S31 defines the risk levels of device operation instructions and instruction operands.
[0100] Specifically, the risk of the instruction is first assessed as shown in Table 3.
[0101] Table 3 Risks of Equipment Directives
[0102]
[0103] The operands of the instructions are categorized into four types: OpParam, Address, object, Data, and Time, and Yield. Address refers to the location of the device, with risk levels of 3, 2, and 1 depending on the sensitivity of the device location (high, medium, or low). Object represents the specific target object of the instruction operation, also with risk levels of 3, 2, and 1 depending on the sensitivity of the target object. Data represents the specific data of the instruction operation, with risk levels of 4, 3, 2, and 1 depending on the sensitivity of the data (top secret, secret, confidential, or public). Time represents the specific time period of the instruction operation, with risk levels of 2 and 1 depending on the sensitivity of the time period. The operands OpParam and Yield, i.e., the instruction parameters and device productivity, are determined by the instruction and device capacity themselves and their risk levels are not considered. The specific risk levels of the device instruction operands are shown in Table 4.
[0104] Table 4 Risks of Device Command Operands
[0105]
[0106]
[0107] S32 calculates the instruction consumption amount based on the device instruction risk level, the instruction operand risk level, and the instruction initial value;
[0108] Specifically, when calculating the cost of a single instruction, in addition to the value of the instruction itself, the impact of the risk of the instruction and its operands should also be considered. That is, the higher the risk level of the instruction and its operands, the higher the quota consumed. For example, in a television production workshop, shutting down motherboard assembly equipment during a sensitive period should consume a higher quota than shutting down equipment that installs brand logos. Therefore, let the quota consumed by the instruction during a single execution be OnceQuo, and let r, rad, rob, rda, and rti represent the risk level of the instruction, the location risk level of the operating device, the object risk level of the operating device, the target data risk level, and the target device operation time risk level, respectively. According to Section 3.2, the corresponding value of this instruction is Val. operator .
[0109] The formula for calculating the quota consumption for a single instruction execution is as follows:
[0110] OnceQuo=(r 3 +r ad +r ob +r da +r ti (9)
[0111] *val operator
[0112] S33 constructs an instruction assetization model based on the number of times an instruction can be operated and the amount of instruction consumption.
[0113] Specifically, assuming the instruction can be operated on a number of times (n), the assetization calculation formula for this instruction is as follows:
[0114] Quo = n * OnceQuo (10)
[0115] Let Right be the set of instructions that a user can execute within their permission scope, where Right = {operator, n}. This includes permissions representing, in order: on / off permissions, I / O permissions, device status read permissions, and device status adjustment permissions.
[0116] S4 calculates the instruction asset quota based on the instruction assetization model;
[0117] S5 initiates access to field devices and smart terminals based on blockchain and command asset quotas.
[0118] S51 judges the transaction request initiated by the user and obtains the judgment result;
[0119] The S511 user sends an instruction request to the instruction value execution point;
[0120] Specifically, User: User entity: As the one who issues commands, it has the authority to issue commands and execute command control operations on field devices or smart terminals. User sends command issuance requests (and initiates transactions with AD).
[0121] The instruction execution point described in S512 sends user information and instruction information to the instruction execution decision point;
[0122] The specific command execution point (CEP) is where the command issued by the user is judged. If the judgment result is successful, the command is forwarded to the field equipment or smart terminal. After receiving the command request, the CEP sends a command execution judgment request to the IEDP with user information (transaction information) and command information.
[0123] After receiving user information and instruction information, the instruction execution determination point described in S513 queries the instruction execution permission information database for the user and obtains the determination result.
[0124] Specifically, the Command Execution Decision Point (CEDP) sends a decision request to the Command Authorization Decision Point, carrying the command forwarded by the CEP. If the authorization decision passes, it sends a decision request to the Command Asset Decision Point. Finally, it returns the decision result to the CEP.
[0125] S52 queries the judgment result based on the blockchain to obtain transaction details;
[0126] S521 describes an instruction asset determination line that sends a query request to the blockchain.
[0127] Specifically, the Command Assert Decision Point (CADP) queries the user's assets and the standard quota corresponding to the command, determines whether the user's assets exceed the standard quota of the command, and returns the decision result to the CEDP.
[0128] After receiving the CPDP's determination result, if the determination result is true, meaning the user has the authority to issue instructions, CEDP will send an instruction asset determination request to CADP, carrying user information, (user transaction information), and instruction information.
[0129] The blockchain described in S522 queries the determination result to obtain transaction details.
[0130] Specifically, blockchain, aimed at achieving information consensus for permissioned access in the Industrial Internet, begins with the initialization of the blockchain system. This includes building the blockchain, initializing quota standards, and initializing and allocating user quotas. These three processes will be explained in detail below.
[0131] (1) Blockchain Construction: Each production department in the Industrial Internet installs all ledger information on the consortium blockchain as a department, becoming a non-malicious full node on the consortium blockchain. Then, users in each department of the Industrial Internet register blockchain accounts. Taking the LED packaging department as an example, the quota administrator AD and users with command operation permissions US, namely U1 and U2, download and install the blockchain client and connect to the blockchain service. Then, AD and US generate their respective key pairs and send the public keys to the blockchain to generate account addresses USAddr and ADAddr respectively. The account address generation process is as follows: Figure 2 As shown, finally, use a wallet program such as "Metamask" to manage all your account addresses.
[0132] (2) Quota standard initialization: The administrator AD calculates the value according to the instruction and stores the value corresponding to all instructions in this management domain on CQSB. This process is defined as the function initPublishStand.
[0133] Define `initPublishStand(ADaddr, OpTxStan)`, where the parameters include the administrator's AD account address and the command quota standard set. This function is executed by AD, returning "true" if the initial publication was successful, and "false" otherwise. The specific algorithm is shown in Table 5.
[0134] Table 5 shows the algorithm initPublishStand(ADAddr, OpTxStan).
[0135]
[0136] In Algorithm 2, we first need to verify whether the operator in the published OpTxStan is the instruction required by the specification. Then, AD uses its public key PKAD to encrypt the authorization function and the initialization timestamp initTime and assigns it to the data field. Finally, AD stores this OpTxStan to CQSB by executing the database processing function.
[0137] (3) User initial quota allocation: The administrator AD assigns initial quotas to each user based on their respective permission sets opRight, that is, the administrator's assets are transferred to users with command operation permissions according to their permissions. We define the process of the administrator issuing command quotas as the function initPublishQuo.
[0138] Define `initPublishQuo(ADAddr, U1Addr, USQuo)`. AD encrypts and publishes the quota `USQuo` owned by US onto the blockchain. The parameters include AD's account address `ADAddr`, US's account address `USAddr`, and the assigned quota `USQuo`. This function is executed by AD and returns "true" if the initialization and publication were successful, otherwise it returns "false". The specific algorithm is shown in Table 6.
[0139] Table 6 shows the algorithm initPublishRight(ADddr, USAddr, USQuo)
[0140]
[0141]
[0142] In Algorithm 3, we first need to verify that the beneficiary of this Quota is indeed this US. Then, AD uses its public key PKAD to encrypt the authorization function and the initialization timestamp initTime and assigns it to the data field. Finally, AD publishes this USQuo to the blockchain by executing the transaction function.
[0143] During the secure operation process in the command security control model, users who have successfully initialized their assets and obtained quotas can access and operate smart terminals or field devices. The specific access steps are as follows:
[0144] Request Initialization Transaction: The user US, who is instructing the operation, transfers the quota corresponding to the instruction value to AD. After the blockchain confirms the transaction, it returns the transaction number and sends an instruction execution request to CEP with the AccessRight.
[0145] CEP requests CPDP to determine whether the permissions meet the standards.
[0146] CPDP returns a determination result; if true, CEP requests CADP to determine whether the transaction complies with the standards.
[0147] CADP returns a judgment result. If the result is true, CEP forwards the instruction to the field equipment.
[0148] Next, we will define and describe the relevant steps in detail. Since the public key already exists in the blockchain system, we use an asymmetric encryption scheme to exchange information. Considering the efficiency of asymmetric encryption, we will only use the public key to protect the symmetric shared key ksi.
[0149] After successful initialization, the user begins command operations. The specific steps for issuing user commands are as follows:
[0150] U1, carrying the instructions to be issued and the "accessRight" permission, initiates a transaction with AD that conforms to the instruction value standard, and records the data.
[0151] data = Enc(PKU1,accessRight||operator||initTime); tx = sendTransaction(U1Addr,C EPddr,onceQuo,data); After completing the transaction, the transaction number tx is received from the blockchain and the operator instruction is forwarded to CEP with the number tx.
[0152] After receiving the instruction, CEP decrypts the information and requests authorization from CPDP. CPDP verifies whether the current trader has this authorization; this process is defined as the function accessVerify. CPDP then returns the authorization result to CEP.
[0153] After receiving the CPDP's determination result, CEP requests CADP to determine the transaction amount. CADP determines whether the transaction amount is the same as the standard quota consumed in a single instruction. We define this process as the function assertVerify. CADP then returns the determination result to CEP.
[0154] After receiving the judgment results and finding them all satisfactory, the CEP will issue instructions to the field equipment.
[0155] The user command issuance is now complete. The "true" and "false" in the message indicate whether the operation was successful. In this scheme, when sharing the symmetric key ksi is involved, we use DH for key negotiation. To more clearly illustrate the U1 command issuance process, the UML sequence diagram is as follows: Figure 3 As shown,
[0156] Command Permission Information Base (CPIB): This is an access control list used to store user information and their permissions.
[0157] Command Quota Standard Base (CQSB): A two-dimensional table used to record commands and their calculated values. Upon receiving a command asset assessment request, CADP queries the CQSB for that command's quota standard base. The CQSB returns the query results to CADP. CADP then queries the Blockchain for user transactions. The Blockchain returns the user's transaction details.
[0158] The S53 decision execution point determines the query result. If the result is true, it can send an access request to the field equipment and smart terminal; if the result is false, it cancels the access request.
[0159] Specifically, CADP determines whether the transaction amount is the same as the quota standard of the instruction and returns the determination result to CEDP. After receiving the determination result from CADP, CEDP returns the instruction execution determination result to CEP. After receiving the instruction execution determination result, if the result is true, CEP initiates access to the field equipment and smart terminal.
[0160] Model Implementation Specific Operation Process
[0161] In implementation, we treat CEP and CEDP as a single entity. CEP submits instruction information to CADP and CPDP for evaluation; if the evaluation is successful, the instruction is sent to the field equipment. Administrators are divided into two categories: a permissions administrator, who controls user permissions through the industrial control software interface, and a quota administrator, who connects to the blockchain to manage user quotas. In practice, the permissions administrator and the quota administrator can be the same person.
[0162] In this invention, due to the different access control policies of different industrial internet platforms, the traditional access control process will not be described in detail. We will focus on the quota-based instruction issuance process, and then provide some relevant definitions to illustrate the model reference implementation process in detail.
[0163] Define 2ADset, the administrator information set is as follows:
[0164] ADset={ADAddr,PKAD,SKAD,Enc(),Dec(),Sign()};
[0165] This includes information that sequentially represents the administrator's account address, public key, private key, encryption method, decryption method, and signature method. It's important to note that since this article does not discuss traditional access control processes, the administrator referred to here is the administrator responsible for command quotas.
[0166] Define 3USset, a user information set, USset = {USAddr, PKUS, SKUS, Enc(), Dec(), Sign()}, which includes information representing the user's account address, public key, private key, encryption method, decryption and signing method in that order.
[0167] Define 4OpRight, the user instruction permission set. We use an eleven-bit binary number to sequentially represent the eleven formalized operators mentioned above. If a permission is not available, the bit is represented as "0". If the number of permissions is insufficient, it is reserved as an extension bit. The permission set for ordinary users is initialized to "00000000000". In this scenario, U1's OpRight for the die bonder is "111111111111", and its permission for the encapsulator is "00000000000". U2's OpRight for the die bonder is "00000000000", and its permission for the encapsulator is "11011111111". M's permissions for both the encapsulator and die bonder are both "11011111111".
[0168] Define 5PermiCap, an access permission set, PermiCap = {USAddr, device, opRight}, which includes information representing the visitor's address, the device being operated, and the permissions the visitor has.
[0169] Define 6OpTxStan, the instruction quota standard set, OpTxStan = {operator, onceQuo}, which includes the instruction itself and the instruction value calculated according to the instruction value function.
[0170] Define 7USQuo, a user quota information set, USQua = {ADaddr, USAddr, Quota}, which includes information representing the address information of the administrator AD, the account address and target data of the quota user US, and the quota that this user has.
[0171] Define `sendTransaction(from, to, value, data)` as a blockchain transaction interface, where `from` represents the transaction initiator's address, `to` represents the transaction recipient's address, `value` represents the transaction amount, and `data` represents additional information. In the scenario described in this article, we add specific access information to `data`. This function returns the transaction identifier `tx`.
[0172] Define the function `getPermiCap(USAddr)` to retrieve the latest permiCap. It retrieves the latest permiCap from the CPIB, where `USAddr` is the user account address. This function returns the permiCap for the corresponding user.
[0173] Define a function `getAmount(tx)` to retrieve the transaction amount. It uses the `getTransaction(tx)` function from the blockchain to obtain the latest transaction amount `Amount`, where `tx` represents the transaction identifier. This function returns `Amount`.
[0174] Definition 11 `getOnceQuo(operator)` is a function that retrieves the standard value of an instruction. It obtains the latest asset value of the operator from the CPIB. This function returns `onceQuo`.
[0175] The above-disclosed embodiments are merely preferred embodiments of the blockchain-based industrial internet device instruction operation security method of the present invention, and should not be construed as limiting the scope of the present invention. Those skilled in the art can understand that implementing all or part of the above embodiments and making equivalent changes in accordance with the claims of the present invention are still within the scope of the invention.
Claims
1. A blockchain-based method for secure operation of industrial internet equipment commands, characterized in that: Includes the following steps: The value of individual Industrial Internet of Things (IIoT) device instructions is calculated using quantitative methods for industrial enterprise assets, and an IIoT device instruction value model is constructed. Specific steps include... Define device instructions; The instruction types for obtaining equipment instructions include switch instructions, equipment status adjustment instructions, raw material input instructions, and read instructions; Based on the instruction type and production parameters, an IIIOT equipment instruction value model is constructed. The production parameters include direct raw material costs, equipment depreciation costs, and directly involved labor costs. The initial value of the instruction is calculated based on the IIoT device instruction value model. Based on the risk level of the device instruction, the risk level of the device instruction operands, and the initial value of the instruction, an instruction assetization model is constructed. Specific steps include... Define the risk level of device instructions and the risk level of device instruction operands; The instruction consumption amount is calculated based on the risk level of the equipment instruction, the risk level of the equipment instruction operands, and the initial value of the instruction. The equipment instruction operands include the location of the equipment, the specific target object, the specific data, the specific time period, the instruction parameters, and the equipment productivity. Construct an instruction assetization model based on the number of operable instructions and the cost of instruction consumption. Calculate the user instruction asset quota based on the instruction assetization model; Access to field devices and smart terminals is initiated based on blockchain and command asset quotas.
2. The blockchain-based industrial internet device instruction operation security method as described in claim 1, characterized in that, The steps for initiating access to field devices and smart terminals based on blockchain and instruction asset quotas include sending instruction issuance requests to users, initiating transactions on the blockchain, requesting judgment, and obtaining judgment results. The transaction details are obtained by querying the judgment result based on the blockchain and the permission information database; The execution point determines the query result. If the result is true, access can be sent to the field equipment and smart terminal; if the result is false, access is canceled.
3. The blockchain-based industrial internet device instruction operation security method as described in claim 2, characterized in that, The specific steps of sending an instruction request to the user, initiating a transaction on the blockchain, and simultaneously requesting a judgment to obtain a judgment result include: the user sending an instruction request to the instruction value execution point. The instruction execution point sends user information and instruction information to the instruction execution decision point; After receiving user information and instruction information, the instruction execution determination point queries the instruction execution permissions of the user in the instruction permission information database to obtain the determination result.
4. The blockchain-based industrial internet device instruction operation security method as described in claim 3, characterized in that, The steps for querying the judgment result based on the blockchain and permission information database to obtain transaction details include: The instruction asset determination point sends a query request to the blockchain; The blockchain queries the judgment result to obtain transaction details, and the asset judgment point determines whether the transaction amount is the same as the quota standard of the instruction, and obtains the judgment result.
5. The blockchain-based industrial internet device instruction operation security method as described in claim 1, characterized in that, The equipment instructions include the target equipment location, target object, target data, time duration, and impact on equipment production output.
6. The blockchain-based industrial internet device instruction operation security method as described in claim 5, characterized in that, The equipment status adjustment commands include sequential control, positioning control, and analog quantity control.
Citation Information
Patent Citations
Machine behavior identification method and device based on data analysis, equipment and medium
CN109657892A
Equipment control method and device based on blockchain, equipment and storage medium
CN112785432A