A dynamic security protection method, device and medium for data collection
Through the dynamic security protection system, the address conversion and writable permission control of Modbus communication packets is solved, and the security problems of the Modbus TCP protocol are effectively protected and production safely is achieved.
Patent Information
- Application Number
- CN202211719504.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2042-12-30
AI Technical Summary
In the existing industrial data acquisition solutions, the Modbus TCP protocol is insecure and has no protocol encryption, resulting in data assets being unable to be effectively protected. Any device or machine can obtain the data of the logical controller through the network, which poses the risk of data leakage and production accidents.
The dynamic security protection system is adopted to process Modbus communication messages through switches and dynamic security protection servers, realizing address transformation and writeable permission control, dynamically transform address correspondence, temporary authorization of write operations, and prevent third-party devices from obtaining data.
It realizes that third-party devices other than the host computer and the on-site logic controller cannot obtain the correspondence between data tags and protocol addresses, improves the availability, confidentiality, integrity and controllability of information security, reduces hardware resource requirements, and realizes lightweight deployment.
Smart Images

Figure CN116260623B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security, and in particular to a dynamic security protection method, device and medium for data acquisition. Background Art
[0002] Data collection at industrial sites is typically performed by a built-in industrial protocol driver within the host computer (configuration software). This driver sends addressing commands to the on-site logic controller (PLC, DCS), receives feedback frames from the logic controller, and then performs protocol parsing to obtain real-time data from the logic controller. Modbus TCP is a commonly used industrial communication protocol. While it offers advantages such as simplicity and ubiquity, it also suffers from insecurity, lacks protocol encryption, and is fully open within the network. This means that any device or machine on the same network as the logic controller can collect data from the logic controller via the Modbus driver, leaving users' data assets unprotected. Summary of the Invention
[0003] In order to solve the above problems, the present application proposes a dynamic security protection method for data acquisition, which is applied in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, and the method includes: the switch receives an address request message from the host computer, and sends the address request message to the dynamic security protection server, so as to determine the message address of the host computer and the transformation scheme of the message address through the dynamic security protection server, and determine the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message; the switch receives an address request message from the host computer, and sends the address request message to the dynamic security protection server, so as to determine the writable permission of the message address through the dynamic security protection server, so as to enable the host computer to perform a write operation on the message address according to the writable permission, thereby obtaining a data request message; the switch receives an address request message from the host computer, and sends the address request message to the dynamic security protection server, so as to determine the writable permission of the message address The data request message of the upper computer is received, and the data request message is sent to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, and performs address conversion on the exposed address according to the transformation scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so as to determine the response message corresponding to the data request message through the logic controller; the dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the transformation scheme, and sends the response message after address inverse conversion to the upper computer through the switch.
[0004] In one example, before the switch receives the address request message from the host computer, the method further includes: the host computer determining the message address of the data request message, and determining the exposed address corresponding to the message address through the first address list library of the host computer; determining the transformation scheme based on the message address and the exposed address, and generating the address request message based on the message address and the transformation scheme.
[0005] In one example, the message address of the host computer and the transformation scheme of the message address are determined by the dynamic security protection server, specifically including: parsing the address request message through the address transformation service of the dynamic security protection server to obtain the message address and the transformation scheme; comparing the message address through the second address list library of the dynamic security protection server according to the transformation scheme to determine the exposed address.
[0006] In one example, the writable permission of the message address is determined by the dynamic security protection server, specifically including: parsing the address request message through the writable restriction service of the dynamic security protection server to obtain the write request of the host computer; determining the permission address and address value according to the write request, and determining the permission exposure address and writable address according to the address value, and determining the writable exposure address corresponding to the writable address; determining the writable permission according to the permission address, the permission exposure address, the writable address and the writable exposure address, and generating an address response message according to the writable permission, and sending the address response message to the host computer through the switch.
[0007] In one example, the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a request message, specifically including: performing a write operation on the writable address through the host computer, and performing an address inverse conversion on the writable address after the write operation through the address inverse conversion service of the host computer to convert the writable address after the write operation into a writable exposed address; performing an address inverse conversion on the permission address through the address inverse conversion service of the host computer to convert the permission address into a permission exposed address; determining the request content according to the writable exposed address and the permission exposed address, and determining the data request message according to the request content and the exposed address.
[0008] In one example, after the host computer performs a write operation on the writable address, the method further includes: sending a write signal to the dynamic security protection server through the host computer, and closing the writable permission through the dynamic security protection server to close the write operation on the writable address.
[0009] In one example, the exposed address is converted according to the transformation scheme, specifically including: determining a second address list library through the address transformation service of the dynamic security protection server, wherein the second address list library includes a server address list and a client address list; querying the server address list according to the transformation scheme to obtain the list position of the exposed address, and searching the client address list according to the list position to obtain the message address corresponding to the exposed address.
[0010] In one example, the host computer includes a first address list library, the dynamic security protection server includes a second address list library, and the contents of the first address list library are consistent with those of the second address list library.
[0011] On the other hand, the present application also proposes a dynamic security protection device for data acquisition, which is used in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the dynamic security protection device for data acquisition to execute: the switch receives an address request message from the host computer, and sends the address request message to the dynamic security protection server, so as to determine the message address of the host computer and the transformation scheme of the message address through the dynamic security protection server, and determine the writable permission of the message address through the dynamic security protection server, so that the The host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message; the switch receives the data request message from the host computer, and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, and performs address conversion on the exposed address according to the transformation scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so as to determine the response message corresponding to the data request message through the logic controller; the dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the transformation scheme, and sends the response message after address inverse conversion to the host computer through the switch.
[0012] On the other hand, the present application also proposes a non-volatile computer storage medium storing computer executable instructions, which is applied in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, and the computer executable instructions are configured as follows: the switch receives an address request message from the host computer, and sends the address request message to the dynamic security protection server, so as to determine the message address of the host computer and the transformation scheme of the message address through the dynamic security protection server, and determine the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message; the switch receives an address request message from the host computer, and sends the address request message to the dynamic security protection server, so as to determine the writable permission of the message address through the dynamic security protection server, and The switch receives the data request message from the host computer and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, and performs address conversion on the exposed address according to the transformation scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so as to determine the response message corresponding to the data request message through the logic controller; the dynamic security protection server receives the response message returned from the logic controller, performs address reverse conversion on the response message according to the transformation scheme, and sends the response message after address reverse conversion to the host computer through the switch.
[0013] This application processes Modbus communication messages through Modbus related services, writable restriction services and address transformation services, and adds a solution of custom addressing mixing to achieve the effect that no third party other than the host computer and the field logic controller can obtain the correspondence between the data label and the protocol address. This application runs through the concept of zero trust, and both reading and writing are controlled by the legitimate requester. The instantaneous nature of write operations and the changeability of addresses greatly improve the availability, confidentiality, integrity and controllability of information security. Through dynamic addressing transformation, the solution is invisible to the host computer and equivalent network nodes, achieving lightweight deployment, low hardware resource requirements, strong confidentiality and high controllability. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0015] Figure 1 A flow chart of a dynamic security protection method for data collection in an embodiment of the present application;
[0016] Figure 2This is a structural diagram of industrial data collection in an embodiment of the present application;
[0017] Figure 3 This is a schematic diagram of the structure of a third-party device capturing industrial data in an embodiment of the present application;
[0018] Figure 4 This is a schematic diagram of the structure of the dynamic safety protection system in an embodiment of the present application;
[0019] Figure 5 This is a schematic diagram of the address protocol for industrial data collection in an embodiment of the present application;
[0020] Figure 6 This is a schematic diagram of the address protocol of the dynamic security protection method in the embodiment of the present application;
[0021] Figure 7 This is a schematic diagram of a writable address protocol for a dynamic security protection method according to an embodiment of the present application;
[0022] Figure 8 This is a schematic diagram of a dynamic safety protection device for data collection in an embodiment of the present application. DETAILED DESCRIPTION
[0023] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0024] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.
[0025] Current industrial data acquisition solutions typically connect a hardware device between the logic controller and the host computer. This hardware features built-in encryption and decryption software or an encryption chip, which encrypts messages sent and received by the host computer, preventing third-party devices or organizations from accessing the information. Alternatively, this hardware may include a program that deeply analyzes Modbus protocol requests from the host computer. Based on the parsed requests, Modbus addresses and commands are parsed and filtered. Read / write address permissions can be configured on the hardware, allowing for individual access permissions for each instruction and address. This type of hardware is generally categorized as an industrial firewall or industrial gateway, based on security levels, from low to high. Alternatively, this hardware may include built-in TCP / IP protocol parsing capabilities, restricting data flow by source IP, destination IP, source port, destination port, and protocol number, limiting access to only the host computer and thus limiting the purpose of third-party requests.
[0026] The three technologies mentioned above can either be implemented as a single piece of hardware or integrated into a multifunctional hardware package. However, all three share a common problem: high hardware computing performance is required for operations such as encryption, decryption, and protocol parsing. For typical small-scale industrial applications, the data volume and production capacity required are not suitable for these hardware devices, resulting in a low cost-performance ratio.
[0027] Usually the form of industrial data collection is that the host computer and the field logic controller are connected through a switch, and both are in the same network. Figure 2 As shown in the figure, the host computer sends a Modbus request message in the network. After receiving the request message, the logic controller identifies the semantics of the message, the requested command, address, verification, etc. After verification, the required address data is placed in the cache, packaged and processed using the Modbus protocol, and a Modbus response message is sent on the network. According to the above communication mechanism, when there is a third-party illegal device or organization connected to the network, the sent and received messages can be intercepted and then parsed to obtain data, or the request command sent by the host computer can be directly imitated to obtain data. Figure 3 As shown, the third-party device is on the same network as the host computer and logic controller, allowing it to capture all network data flows at zero cost, including Modbus request messages from the host computer and Modbus response messages from the logic controller. Without any additional equipment, the third-party device can easily obtain data through these two methods. Furthermore, the third-party device can send illegal commands to the logic controller, resulting in third-party request messages and the potential for production accidents.
[0028] like Figure 1As shown, in order to solve the above problems, an embodiment of the present application provides a dynamic security protection method for data acquisition, which is applied in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, and the method includes:
[0029] S101. The switch receives an address request message from the host computer and sends the address request message to the dynamic security protection server, so as to determine the message address of the host computer and the transformation scheme of the message address through the dynamic security protection server, and determine the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message.
[0030] like Figure 4 As shown, a dynamic security server is installed on the logic controller to implement Modbus addressing transformation, preventing third-party devices from parsing the correspondence between address variable labels and values. First, the host computer sends an address request message, writing different values to a specific address in the Modbus server service. These correspond to different relationships in the address mapping table. Different values correspond to different relationships, and on-site maintenance personnel are free to choose which address mapping table to use. This allows for pre-determined resolution of the corresponding address. For service write operations, based on the selected address mapping table, each actual pre-write address must be paired with a special address that allows write permissions. The switch receives the address request message and sends it to the dynamic security server. The address transformation service in the dynamic security server receives the value of the special address, parses it, queries the mapping table in the address mapping table, and performs the address-value transformation between the Modbus server and Modbus client services. The host computer sends an address request message in order to agree with the dynamic security protection server on a message address transformation scheme. The dynamic security protection device retains the host computer's message address and the message address transformation scheme. When the host computer sends a formal data request message based on the transformation scheme, the dynamic security protection server can obtain the actual message address based on the transformation scheme. In addition, the address request message sent by the host computer also includes a request for write permission for the message address content. The dynamic security protection server determines the write permission for the message address and feeds this write permission back to the host computer, allowing the host computer to perform a write operation on the message address based on the write permission, thereby obtaining a data request message. This write operation is a one-time operation. After the host computer completes the write operation, the dynamic security protection server disables the write permission, thereby preventing external devices from sending illegal instructions to the logic controller.
[0031] In one embodiment, before a switch receives an address request message from a host computer, the host computer selects the message address of the data request message from an address list library (herein referred to as a first address list library) and determines the exposed address corresponding to the message address from the first address list library. The host computer determines a transformation scheme based on the message address and the exposed address, and packages the message address and the transformation scheme to generate an address request message.
[0032] In one embodiment, the address transformation service of the dynamic security protection server parses the received address request message to obtain the message address and the transformation scheme. According to the transformation scheme, the message address is compared with the address list library of the dynamic security protection server (herein referred to as the second address list library) to determine the exposed address corresponding to the message address. This enables the dynamic security protection server to have the ability to find the original message address based on the exposed address. In this way, when a message with an exposed address is sent by the host computer, the dynamic security protection server can convert the exposed address into the actual message address and send the actual message address to the logic controller, thereby preventing a third-party device from capturing the correct message. Even if the third-party device can steal the address data, it cannot recognize it without the corresponding list library.
[0033] In one embodiment, Figure 5 As shown, the addressing of the communication protocols currently used in industrial control sites on the market is mostly fixed, that is, the Modbus address request required by the host computer remains unchanged in the next training cycle. Within a certain period, no matter how many data messages are sent or received, the data request message is always repeated periodically, and the address field of the response message is also unchanged. The only thing that changes is the real-time data stored at each address. Therefore, a third party can parse the real-time message by learning the Modbus protocol corresponding to the message, and then obtain the data on the address. If a fixed address and semantic correspondence table is obtained, such as "40001 address, corresponding to pressure parameter", then the pressure parameter value can be obtained in real time. As Figure 6As shown, in this embodiment, the correspondence between the address and the semantics is dynamically transformed. If the host computer wants to write to a certain address, it can directly write the converted address. After the writing is completed, it will be immediately closed by the writable restriction service. Before the host computer sends a formal data request message, the writable restriction service of the dynamic security protection server parses the received address request message to obtain the write request of the host computer. The dynamic security protection server has a writable restriction service, which can determine the corresponding permission address and address value according to the write request, and can match the permission exposure address and the writable address according to the address value, and match the writable address with the corresponding writable exposure address. The writable restriction service provides the host computer with a selection table of the above addresses, and the host computer can make a selection according to the actual situation. The host computer can define the semantics of the actual permission address. For example, the corresponding relationship of "40001 address, corresponding to pressure parameter" only exists in this communication process. In the next communication, it can be determined by the host computer and the logic controller through negotiation. The writable restriction service provides the corresponding permission exposure address for the permission address. For example, the host computer sends a write request command of "49999 address, corresponding to semantic table". The value is 1, which means that the corresponding relationship shown in Table 1 is adopted.
[0034] Semantics Permission Address Permission exposure address pressure 40001 40003 temperature 40002 40004 …… …… ……
[0035] Table 1
[0036] If the value is 2, it means that the corresponding relationship shown in Table 2 is adopted, and so on.
[0037] Semantics Permission Address Permission exposure address pressure 40001 41003 temperature 40002 41004 …… …… ……
[0038] Table 2
[0039] The above correspondence table between permission addresses and permission exposure addresses is stored in the address reversal service of the dynamic security protection server and the address reversal service of the host computer. When the value of 49999 is written as "1", the address reversal service of the dynamic security protection server and the host computer are both packaged and parsed according to the correspondence in Table 1. That is, the actual address of the permission address of the pressure is 40001, and the address exposed on the network is 40003. When the value of 49999 is written as "2", the address reversal service of the dynamic security protection server and the host computer are both packaged and parsed according to the correspondence in Table 2. That is, the actual address of the permission address of the pressure is 40001, and the address exposed on the network is 41003. Third-party devices may obtain data at either 40003 or 41003, but do not know whether it corresponds to the semantics of "pressure". This semantic correspondence table is manually set by operation and maintenance personnel, or a program automatically sets random numbers to increase undecipherability.
[0040] In the Modbus protocol, writing a value to a control point address is a common operation, but it also carries certain risks. Third-party devices connected to the network can perform random batch write operations, causing all address data to be confused and causing the logic controller to execute incorrect execution instructions, thereby achieving the illegal purpose of undermining production safety. Figure 7 As shown, this embodiment enables a temporary authorization mechanism for write operations. When a numerical value needs to be written to a certain Modbus address, data needs to be written to the writable exposed address first. The numerical value represents a different address and is also the address to be written in the next step. For example, as shown in Table 3, 40011 is the writable exposed address of this write permission. When the written value is 1, the corresponding writable address is 41111. At this time, the dynamic security protection server can open the writable permission of 41111, and the host computer can perform a write value operation on 41111. After the operation is completed, the dynamic security protection server will close the write permission of the address 41111. When the written value is 2, the corresponding writable address is 41112. At this time, the dynamic security protection server can open the writable permission of 41112, and the host computer can perform a write value operation on 41112. After the operation is completed, the dynamic security protection server will close the write permission of the address 41112.
[0041] Numerical Writable address 1 41111 2 41112 …… ……
[0042] Table 3
[0043] The corresponding relationship between the above writable addresses is also stored in the address reversal service of the dynamic security protection server and the address reversal service of the host computer. The host computer can then perform a write operation on address 41111. After the write operation is completed, the write permission is immediately revoked.
[0044] This temporary write authorization technology, combined with the previously mentioned dynamic Modbus address mapping technology, provides dual protection against write operations. As shown in Table 4, the first layer is address transformation. The address that a third party can capture is the exposed 42222, not 41111.
[0045]
[0046]
[0047] Table 4
[0048] The dynamic security protection server packages the permission address, permission exposure address, writable address and writable exposure address in the above table into writable permission, and generates an address response message based on the writable permission, and sends the address response message to the host computer through the switch, so that the host computer writes a formal data request message based on the writable permission in the address response message.
[0049] In one embodiment, the host computer performs a write operation on the writable address and performs an address inverse conversion on the writable address after the write operation through the host computer's address inverse conversion service to convert the writable address after the write operation into a writable exposed address. The host computer's address inverse conversion service performs an address inverse conversion on the permission address to convert the permission address into a permission exposed address. Request content is generated based on the writable exposed address and the permission exposed address, and a data request message is determined based on the request content and the exposed address.
[0050] In one embodiment, after the write operation is performed on the writable address by the host computer, a write signal is sent to the dynamic security protection server through the host computer, and the write permission is closed by the dynamic security protection server, so that the write operation of the writable address is closed. In the dynamic security protection server, all Modbus addresses are taken to the network with zero trust measures, and all addresses are set to have no write operation permission. In this way, even if a third-party device adopts a blind broadcast write operation, there is no possibility of any change to the data of the Modbus address in the dynamic security protection server. At the same time, the write permission of the address is temporarily controlled by the host computer, and a third party cannot operate it.
[0051] S102. The switch receives the data request message from the host computer and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, and performs address conversion on the exposed address according to the transformation scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so that the logic controller determines the response message corresponding to the data request message.
[0052] The host computer sends a regular data request message, which the switch receives and forwards to the dynamic security protection server. The dynamic security protection server's address inversion service restores the true correspondence in the logic controller based on the transformation scheme, converting the exposed address into the actual message address. The data request message with this message address is then sent to the logic controller, which verifies the content of the data request message, collects the corresponding response data, and generates a response message.
[0053] In one embodiment, the host computer includes a first address list library, and the dynamic security protection server includes a second address list library. The contents of the first address list library and the second address list library are consistent. Therefore, the conversion schemes stored in the host computer and the dynamic security protection server are also consistent, thereby achieving dynamic conversion of Modbus address correspondences.
[0054] In one embodiment, Figure 4As shown, the address list library (including the first address list library and the second address list library) includes a server address list and a client address list. Taking the second address list library as an example, the transformation scheme is queried in the server address list to obtain the list position of the exposed address. Based on the list position, the client address list is searched to obtain the message address corresponding to the exposed address.
[0055] S103. The dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the conversion scheme, and sends the response message after address inverse conversion to the host computer through the switch.
[0056] Compared with the traditional field data acquisition security protection technology, this application is to dynamically transform the address correspondence and the temporary authorization of the write operation, and it is only authorized once and revoked immediately. Although the Modbus message is still transmitted in plain text, the technical core of the protection lies in the dynamic definition of the message parsing, that is, the semantic definition is reconstructed, and the reconstruction method is not unique, and the master and slave ends of the Modbus negotiate to determine which definition rules are used for transmission and parsing. In addition, for the Modbus write value operation, in addition to the dynamic transformation of the semantic parsing table, the temporary authorization of the specific address write operation is also specified, and it is only authorized once. After the write operation is completed, the write permission is immediately blocked. In other words, all Modbus addresses do not have write permissions by default.
[0057] like Figure 8 As shown, the embodiment of the present application further provides a dynamic security protection device for data acquisition, which is applied in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, including:
[0058] at least one processor; and,
[0059] a memory communicatively connected to the at least one processor; wherein,
[0060] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the dynamic security protection device for data collection to perform:
[0061] The switch receives the address request message from the host computer and sends the address request message to the dynamic security protection server, so that the dynamic security protection server determines the message address of the host computer and the transformation scheme of the message address, and determines the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message;
[0062] The switch receives the data request message from the host computer and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, performs address conversion on the exposed address according to the conversion scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so that the logic controller determines a response message corresponding to the data request message;
[0063] The dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the conversion scheme, and sends the response message after address inverse conversion to the host computer through the switch.
[0064] The present application also provides a non-volatile computer storage medium for use in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch, and a dynamic security protection server, and stores computer-executable instructions, wherein the computer-executable instructions are configured as follows:
[0065] The switch receives the address request message from the host computer and sends the address request message to the dynamic security protection server, so that the dynamic security protection server determines the message address of the host computer and the transformation scheme of the message address, and determines the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message;
[0066] The switch receives the data request message from the host computer and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, performs address conversion on the exposed address according to the conversion scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so that the logic controller determines a response message corresponding to the data request message;
[0067] The dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the conversion scheme, and sends the response message after address inverse conversion to the host computer through the switch.
[0068] The various embodiments in this application are described in a progressive manner. Similar portions between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the device and medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simple. For relevant portions, refer to the descriptions of the method embodiments.
[0069] The devices and media provided in the embodiments of the present application correspond one-to-one to the methods. Therefore, the devices and media also have similar beneficial technical effects to their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.
[0070] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0071] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0072] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0073] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0074] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0075] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0076] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0077] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0078] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application should be included within the scope of the claims of the present application.
Claims
1. A dynamic security protection method for data collection, characterized in that: Applied in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, the method includes: The switch receives the address request message from the host computer and sends the address request message to the dynamic security protection server, so that the dynamic security protection server determines the message address of the host computer and the transformation scheme of the message address, and determines the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message; The switch receives the data request message from the host computer and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, performs address conversion on the exposed address according to the conversion scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so that the logic controller determines a response message corresponding to the data request message; The dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the conversion scheme, and sends the response message after address inverse conversion to the host computer through the switch.
2. The method according to claim 1, characterized in that Before the switch receives the address request message from the host computer, the method further includes: The host computer determines the message address of the data request message, and determines the exposed address corresponding to the message address through the first address list library of the host computer; The transformation scheme is determined according to the message address and the exposed address, and the address request message is generated according to the message address and the transformation scheme.
3. The method according to claim 2, characterized in that Determining the message address of the host computer and the message address transformation scheme by the dynamic security protection server specifically includes: Parsing the address request message through the address conversion service of the dynamic security protection server to obtain the message address and the conversion scheme; The message address is compared with the second address list library of the dynamic security protection server according to the transformation scheme to determine the exposed address.
4. The method according to claim 1, wherein Determining the writable permission of the message address by the dynamic security protection server specifically includes: Parsing the address request message through the writable restriction service of the dynamic security protection server to obtain the write request of the host computer; Determine an authority address and an address value according to the write request, determine an authority exposure address and a writable address according to the address value, and determine a writable exposure address corresponding to the writable address; The writable permission is determined according to the permission address, the permission exposure address, the writable address and the writable exposure address, and an address response message is generated according to the writable permission, and the address response message is sent to the host computer through the switch.
5. The method according to claim 4, characterized in that The host computer performs a write operation on the message address according to the writable permission, thereby obtaining a request message, specifically including: Performing a write operation on the writable address through the host computer, and performing an address inverse conversion on the writable address after the write operation through the address inverse conversion service of the host computer, so as to convert the writable address after the write operation into a writable exposed address; Performing address inverse conversion on the permission address through the address inverse conversion service of the host computer to convert the permission address into a permission exposure address; The request content is determined according to the writable exposure address and the permission exposure address, and the data request message is determined according to the request content and the exposure address.
6. The method according to claim 5, characterized in that After the host computer performs a write operation on the writable address, the method further includes: A write signal is sent to the dynamic security protection server through the host computer, and the writable permission is closed through the dynamic security protection server, so that the writable address closes the write operation.
7. The method according to claim 1, characterized in that Performing address conversion on the exposed address according to the conversion scheme specifically includes: Determine a second address list library through the address transformation service of the dynamic security protection server, wherein the second address list library includes a server address list and a client address list; According to the transformation scheme, the server address list is queried to obtain the list position of the exposed address, and according to the list position, the client address list is searched to obtain the message address corresponding to the exposed address.
8. The method according to claim 1, characterized in that The host computer includes a first address list library, and the dynamic security protection server includes a second address list library. The contents of the first address list library are consistent with those of the second address list library.
9. A dynamic safety protection device for data collection, characterized in that: Applied in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, including: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the dynamic security protection device for data collection to perform: The switch receives the address request message from the host computer and sends the address request message to the dynamic security protection server, so that the dynamic security protection server determines the message address of the host computer and the transformation scheme of the message address, and determines the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message; The switch receives the data request message from the host computer and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, performs address conversion on the exposed address according to the conversion scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so that the logic controller determines a response message corresponding to the data request message; The dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the conversion scheme, and sends the response message after address inverse conversion to the host computer through the switch.
10. A non-volatile computer storage medium storing computer executable instructions, characterized in that: Applied in a dynamic security protection system, wherein the dynamic security protection system includes a host computer, a logic controller, a switch and a dynamic security protection server, and the computer executable instructions are set to: The switch receives the address request message from the host computer and sends the address request message to the dynamic security protection server, so that the dynamic security protection server determines the message address of the host computer and the transformation scheme of the message address, and determines the writable permission of the message address through the dynamic security protection server, so that the host computer performs a write operation on the message address according to the writable permission, thereby obtaining a data request message; The switch receives the data request message from the host computer and sends the data request message to the dynamic security protection server, so that the dynamic security protection server determines the exposed address of the data request message, performs address conversion on the exposed address according to the conversion scheme, thereby converting the exposed address into the message address, and sends the data request message to the logic controller according to the message address, so that the logic controller determines a response message corresponding to the data request message; The dynamic security protection server receives the response message returned from the logic controller, performs address inverse conversion on the response message according to the conversion scheme, and sends the response message after address inverse conversion to the host computer through the switch.
Citation Information
Patent Citations
Data transmission method and data transmission system based on distributed FTP
CN104519138A
Data processing method, device and system and data server
CN106790230A