An industrial internet of things collaborative method, device and medium for improving data security
By leveraging the security mechanisms and blockchain authentication of industrial interconnection collaborative devices and platforms, device data is directly transmitted, solving the problem of balancing data timeliness and security, and achieving high-security and high-timeliness data transmission.
Patent Information
- Application Number
- CN202211581200.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2042-12-09
AI Technical Summary
Existing technologies cannot simultaneously ensure both data security and data timeliness in industrial data application scenarios where high data timeliness is required.
By using industrial interconnection to coordinate devices and platforms, data is collected and encrypted using a preset security mechanism, and enterprise identity is authenticated using blockchain technology. Designated connection relationships are established, and data is transmitted directly through the devices, avoiding platform forwarding.
It achieves a balance between data security and timeliness in scenarios with high data timeliness requirements, thereby improving the security and timeliness of data transmission.
Smart Images

Figure CN116318788B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of industrial information technology, and in particular to an industrial interconnection and collaboration method, device and medium for improving data security. Background Technology
[0002] The core of building an industrial internet system architecture lies in eliminating information silos and creating a global data resource pool. Traditional industries, currently operating in an information silo phase, face precarious data security. To build a distributed industrial internet system, industrial data security must be seriously addressed and resolved. Considering the requirements of enterprise digital transformation, current industrial security issues manifest in two main aspects: First, internal enterprise security is difficult to guarantee effectively. Whether through hacker attacks or internal personnel errors or violations, data loss or damage can occur, leading to service interruptions, asset losses, and in severe cases, legal risks. Second, the security of partner enterprises is difficult to guarantee effectively. The industrial internet architecture not only includes companies within the same industry and field but also expands to include various upstream and downstream enterprises across different industrial chains, aiming to create a unified and complete supply chain structure. As the coverage of enterprises within the industrial internet system continues to expand, the risk of data leakage also increases, inevitably becoming a major concern for enterprise data security. Therefore, as the industrial internet system continues to expand and improve, industrial security has gradually become a crucial aspect.
[0003] Typically, data transmission between enterprises and their partners is achieved through the construction of interconnected platforms to realize industrial interconnection among multiple parties. However, this data transmission process involves multiple forwardings, impacting both data timeliness and security risks. Therefore, in application scenarios with high requirements for data timeliness, it is impossible to simultaneously guarantee both data security and timeliness in industrial data. Summary of the Invention
[0004] This specification provides one or more embodiments of an industrial interconnection collaboration method, device, and medium for improving data security, addressing the following technical problem: in application scenarios with high requirements for data timeliness, it is impossible to simultaneously ensure the data security and data timeliness of industrial data.
[0005] One or more embodiments of this specification employ the following technical solutions:
[0006] This specification provides one or more embodiments of an industrial interconnection collaboration method for improving data security. The method is characterized by its application to an industrial interconnection collaboration system, which includes industrial interconnection collaboration devices and an industrial interconnection collaboration platform. The industrial interconnection collaboration devices and the industrial interconnection collaboration platform are connected. The method includes: collecting device data through the industrial interconnection collaboration devices; performing secure operations on the device data according to a preset security mechanism to generate designated device data; receiving a data acquisition request from a partner enterprise through the industrial interconnection collaboration platform; authenticating the partner enterprise's identity based on the data acquisition request and pre-stored enterprise identity authentication information, wherein the enterprise identity authentication information represents the identity information of the enterprise to which the industrial interconnection collaboration devices belong; establishing a designated connection relationship between the partner enterprise and the industrial interconnection collaboration devices through the industrial interconnection collaboration platform after successful authentication; verifying the connection relationship through the industrial interconnection collaboration devices; and sending the designated device data to the partner enterprise through the industrial interconnection collaboration devices after successful connection verification, thereby realizing industrial interconnection collaboration between the enterprise to which the industrial interconnection collaboration devices belong and the partner enterprise.
[0007] Furthermore, according to a preset security mechanism, secure operations are performed on the device data to generate designated device data, specifically including: obtaining a pre-set device identifier of the industrial interconnection collaborative device; adding the device identifier to the device data through the industrial interconnection collaborative device to generate identified device data; encrypting the identified device data to generate the designated device data.
[0008] Furthermore, before collecting device data through industrial internet collaborative devices, the method further includes: obtaining enterprise information pre-set on the industrial internet collaborative platform, wherein the enterprise information includes a data signature of the enterprise's real-name information and the enterprise's public key; authenticating the enterprise's identity based on the enterprise information through the industrial internet collaborative platform, and obtaining the enterprise's real-name information; after the enterprise's identity authentication is successful, generating a signature of the enterprise's real-name information through the industrial internet collaborative platform, and generating enterprise-specific card information based on the signature, the enterprise's public key, and the enterprise's real-name information; digesting the enterprise-specific card information through the industrial internet collaborative platform to generate a plaintext digest of the card, encrypting the enterprise-specific card information using the pre-obtained platform public key to generate encrypted enterprise-specific card information; and publishing the plaintext digest of the card and the encrypted enterprise-specific card information to the blockchain through the industrial internet collaborative platform.
[0009] Furthermore, based on the data acquisition request of the cooperating enterprise and the enterprise identity authentication information pre-stored in the industrial internet collaboration platform, the cooperating enterprise is authenticated. Specifically, this includes: obtaining the cooperating enterprise information in the data acquisition request and the source enterprise information of the data source enterprise from which the data to be acquired is obtained; obtaining encrypted source enterprise special card information based on the source enterprise information and the plaintext digest of the special card in the blockchain, and decrypting the encrypted source enterprise special card information to obtain the source enterprise real name information in the source enterprise special card information; determining the potential cooperating enterprise identifiers of multiple potential cooperating enterprises corresponding to the source enterprise in a pre-established cooperation relationship data table based on the source enterprise real name information; and authenticating the cooperating enterprise based on the cooperating enterprise identifiers in the cooperating enterprise information and the multiple potential cooperating enterprise identifiers.
[0010] Furthermore, establishing a designated connection relationship between the cooperating enterprise and the industrial interconnected collaborative device through the industrial interconnected collaborative platform specifically includes: obtaining the data type to be acquired in the data acquisition request through the industrial interconnected collaborative platform, so as to determine the designated device identifier of the industrial interconnected collaborative device based on the data type to be acquired; obtaining the designated device data through the industrial interconnected collaborative platform, so as to determine the preset device identifier of the preset industrial interconnected collaborative device corresponding to the device data through the designated device data; verifying the preset industrial interconnected collaborative device through the industrial interconnected collaborative platform according to the designated device identifier and the preset device identifier; after successful verification, establishing a communication relationship between the cooperating enterprise and the industrial interconnected collaborative device through the industrial interconnected collaborative platform according to the preset device identifier and the cooperating enterprise information in the data acquisition request of the cooperating enterprise.
[0011] Furthermore, the connection verification of the designated connection relationship is performed through the industrial interconnection and collaboration device, specifically including: determining the connection type of the designated connection relationship through the industrial interconnection and collaboration device, wherein the connection type includes normal connection and illegal connection; when the designated connection relationship is a normal connection, the connection verification of the designated connection relationship is determined to be successful; when the designated connection relationship is an illegal connection, the designated connection relationship is blocked according to a pre-set illegal connection blocking scheduling strategy.
[0012] Furthermore, based on the cooperative enterprise identifier in the cooperative enterprise information and the multiple potential cooperative enterprise identifiers, the identity of the cooperative enterprise is authenticated, specifically including: when there is a designated enterprise identifier among the multiple potential cooperative enterprise identifiers that is consistent with the cooperative enterprise identifier, the identity of the cooperative enterprise is authenticated.
[0013] Furthermore, after sending the designated device data to the cooperating enterprise through the industrial interconnection collaborative device, the method further includes: parsing the designated device data to obtain device data and device identifier in the designated device data; verifying the device identifier, and obtaining the device data after successful verification.
[0014] This specification provides one or more embodiments of an industrial interconnected collaborative device for improving data security, including:
[0015] At least one processor; and,
[0016] A memory communicatively connected to the at least one processor; wherein,
[0017] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:
[0018] Data is collected from industrial interconnected collaborative devices, and the data is processed securely according to a preset security mechanism to generate specified device data.
[0019] Through the industrial internet collaboration platform, data acquisition requests from partner companies are received. Based on the data acquisition requests from partner companies and pre-stored enterprise identity authentication information, the identity of the partner companies is authenticated. The enterprise identity authentication information is used to represent the identity information of the enterprise to which the industrial internet collaboration device belongs.
[0020] After the identity of the cooperating enterprise is verified, a designated connection relationship is established between the cooperating enterprise and the industrial interconnection collaboration device through the industrial interconnection collaboration platform;
[0021] The industrial interconnection and collaboration device is used to verify the connection of the specified connection relationship;
[0022] After the connection verification of the specified connection relationship is successful, the specified device data is sent to the cooperating enterprise through the industrial interconnection collaboration device, so as to realize industrial interconnection collaboration between the enterprise to which the industrial interconnection collaboration device belongs and the cooperating enterprise.
[0023] This specification provides one or more embodiments of a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured as follows:
[0024] Data is collected from industrial interconnected collaborative devices, and the data is processed securely according to a preset security mechanism to generate specified device data.
[0025] Through the industrial internet collaboration platform, data acquisition requests from partner companies are received. Based on the data acquisition requests from partner companies and pre-stored enterprise identity authentication information, the identity of the partner companies is authenticated. The enterprise identity authentication information is used to represent the identity information of the enterprise to which the industrial internet collaboration device belongs.
[0026] After the identity of the cooperating enterprise is verified, a designated connection relationship is established between the cooperating enterprise and the industrial interconnection collaboration device through the industrial interconnection collaboration platform;
[0027] The industrial interconnection and collaboration device is used to verify the connection of the specified connection relationship;
[0028] After the connection verification of the specified connection relationship is successful, the specified device data is sent to the cooperating enterprise through the industrial interconnection collaboration device, so as to realize industrial interconnection collaboration between the enterprise to which the industrial interconnection collaboration device belongs and the cooperating enterprise.
[0029] The above-mentioned at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects: Through the above technical solutions, the industrial interconnection collaborative device collects equipment data and performs secure operations on the equipment data, ensuring secure data collection and improving data security in the collection process; the industrial interconnection collaborative platform verifies the identity of the cooperating enterprise, and after successful verification, establishes a connection relationship between the industrial interconnection collaborative device and the cooperating enterprise, ensuring the security of the data acquisition party's identity and the security of the connection relationship, thus improving data security in data transmission; after the connection relationship is established, the industrial interconnection collaborative device verifies the connection relationship, and after successful verification, the device data is transmitted, further improving the security of data transmission. Moreover, the device data is sent directly to the cooperating enterprise by the industrial interconnection collaborative device without being forwarded by the industrial interconnection collaborative platform, which can ensure data timeliness and meet the needs of application scenarios with high requirements for data timeliness, balancing the data security and data timeliness of industrial data. Attached Figure Description
[0030] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0031] Figure 1 A flowchart illustrating an industrial interconnection collaboration method for improving data security, provided as an embodiment of this specification;
[0032] Figure 2 A schematic diagram of the hardware structure of an industrial interconnection and collaboration device provided in the embodiments of this specification;
[0033] Figure 3 A schematic diagram of the structure of a specified chip for an industrial interconnection system device provided in the embodiments of this specification;
[0034] Figure 4 A schematic diagram of the architecture of a secure operating system provided in the embodiments of this specification;
[0035] Figure 5 This is a schematic diagram of the structure of an industrial interconnection and collaboration device for improving data security, provided as an embodiment of this specification. Detailed Implementation
[0036] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0037] The core of building an industrial internet system architecture lies in eliminating information silos and creating a global data resource pool. Traditional industries, currently operating in an information silo phase, face precarious data security. To build a distributed industrial internet system, industrial data security must be seriously addressed and resolved. Considering the requirements of enterprise digital transformation, current industrial security issues manifest in two main aspects: First, internal enterprise security is difficult to guarantee effectively. Whether through hacker attacks or internal personnel errors or violations, data loss or damage can occur, leading to service interruptions, asset losses, and in severe cases, legal risks. Second, the security of partner enterprises is difficult to guarantee effectively. The industrial internet architecture not only includes companies within the same industry and field but also expands to include various upstream and downstream enterprises across different industrial chains, aiming to create a unified and complete supply chain structure. As the coverage of enterprises within the industrial internet system continues to expand, the risk of data leakage also increases, inevitably becoming a major concern for enterprise data security. Therefore, as the industrial internet system continues to expand and improve, industrial security has gradually become a crucial aspect.
[0038] Typically, data transmission between enterprises and their partners is achieved through the construction of interconnected platforms to realize industrial interconnection among multiple parties. However, this data transmission process involves multiple forwardings, impacting both data timeliness and security risks. Therefore, in application scenarios with high requirements for data timeliness, it is impossible to simultaneously guarantee both data security and timeliness in industrial data.
[0039] This specification provides an industrial interconnection collaboration method for improving data security. It should be noted that the execution subject in this specification embodiment can be a server or any device with data processing capabilities. Figure 1 This specification provides a flowchart illustrating an industrial interconnection collaboration method for improving data security, as illustrated in the embodiments of this specification. Figure 1 As shown, the main steps include the following:
[0040] Step S101: Collect device data through industrial interconnection collaborative devices, perform secure operations on the device data according to the preset security mechanism, and generate specified device data.
[0041] In one embodiment of this specification, equipment data is collected through an industrial interconnection and collaboration device. This industrial interconnection and collaboration device integrates multiple sensors to meet the data collection needs of various types of industrial equipment. Furthermore, the industrial interconnection and collaboration device integrates multiple sensor types and possesses data transmission and processing capabilities.
[0042] It should be noted that the methods in the embodiments of this specification are applied to an industrial interconnection and collaboration system. The industrial interconnection and collaboration system includes industrial interconnection and collaboration devices and an industrial interconnection and collaboration platform, which are connected. It should also be noted that the hardware components of the industrial interconnection and collaboration device include: a top cover, a power module, a data acquisition and processing module, a wireless transceiver module, a built-in accelerometer sensor module, and a base. Figure 2 This is a schematic diagram of the hardware structure of an industrial interconnection and collaboration device provided in the embodiments of this specification, such as... Figure 2As shown, the industrial interconnected collaborative device includes a cover, battery, battery compartment, base, and circuit board. It should be noted that the circuit board here can also be called a functional module, with the core circuit sensing components soldered into it. This includes the core board circuit, main power supply circuit, WIFI module circuit, vibration sensor interface circuit, infrared sensor interface circuit, and battery detection circuit. The base internally connects to the circuit board and externally mounts a magnetic connector. The cover is made of explosion-proof material and isolates the device from the internal and external environments when screwed onto the base, ensuring the core circuit board is not damaged. The industrial interconnected collaborative device is designed wirelessly, eliminating wired constraints and avoiding environmental limitations. Furthermore, the device uses a magnetic attachment method, offering advantages such as immediate installation and adaptability to any scale of equipment to be tested. It also breaks down the barriers to key data acquisition between domestic and international equipment, achieving a technological advantage in obtaining key production data. The table below shows the hardware technical specifications of an industrial interconnected collaborative device provided in this embodiment:
[0043]
[0044]
[0045] In one embodiment of this specification, the industrial interconnected collaborative device includes a designated chip. Figure 3 This is a schematic diagram of the structure of a designated chip for an industrial interconnection system device provided in an embodiment of this specification; furthermore, the industrial interconnection collaborative device also includes a security operation module, which embeds a security operating system. Figure 4 This is a schematic diagram of the architecture of a secure operating system provided in an embodiment of this specification. Figure 4 As shown, the secure operating system is based on the open-source Linux kernel and features deep industrial capability customization and security reconstruction. It instantly builds a universal, high-performance, secure, and trustworthy privacy computing environment for sensitive applications within the operating system kernel, effectively protecting the keys, cryptography, sensitive data, and sensitive algorithms of both the user and partners. It effectively prevents theft or damage caused by malicious external hacking and internal misoperations and violations. It possesses multiple security mechanisms, supporting multi-party co-governance authorization mechanisms, universally efficient trusted computing mechanisms, and multi-party proof mechanisms for local or remote device status at the kernel level. This ensures non-bypass, non-tamperable access control that effectively prevents malicious external hacking and internal misoperations and violations. It ensures that sensitive data and algorithms of the user or clients are usable but not visible, and prevents vulnerable algorithms from damaging information infrastructure. The system status proof based on the multi-party co-governance authorization mechanism provides a remote trust foundation for data sharing and collaborative ecosystems.
[0046] A secure operating system is embedded in industrial interconnected collaborative devices, employing industrial security technologies for protection. Specifically, this includes: preventing the creation of unauthorized accounts by requiring each account's system configuration file to contain content signatures or public key certificates from multiple security administrators; protecting the operating system's core algorithm capabilities by setting up an authorized whitelist to prevent the superuser account from viewing or modifying certain critical kernel modules; and setting up a controlled operating environment around sensitive application modules to prevent unauthorized access by operating system administrators to sensitive application storage information via other application modules. When a sensitive application module starts running, the operation of other unauthorized application modules is temporarily suspended until the sensitive application module finishes running and clears its temporarily stored sensitive information, at which point the operating system automatically resumes the previously suspended unauthorized modules. Furthermore, the establishment and revocation of the controlled environment are controlled by multiple security administrators to prevent the superuser account from creating backdoors. These security strategies comprehensively ensure the information security and reliability of the industrial chip operating system.
[0047] In one embodiment of this specification, industrial interconnected collaborative devices are connected to an industrial interconnected collaborative platform. By building this platform, enterprises undergoing digital transformation are provided with a secure method for identifier resolution, secure storage of enterprise data, and intelligent analysis and prediction services for enterprise data. Enterprises register and apply for an enterprise identification code through the industrial interconnected collaborative platform, and similarly apply for unique equipment identification codes for their key production equipment. These codes are then written to a specific memory address on the industrial interconnected collaborative device. After the device connects to the cloud, proactive identification technology is used to schedule the device to periodically collect and upload equipment data while simultaneously uploading its unique equipment identification code. The industrial interconnected collaborative platform receives and breaks down the data, performs identifier resolution on the unique equipment identification code, and stores and analyzes the collected data.
[0048] The authentication process using proactive identification technology involves the following steps: First, enterprises fill in relevant registration information for their internal equipment through the Industrial Internet Collaboration Platform. The platform submits the equipment registration application to the identifier resolution platform node. The identifier resolution platform issues a unique identifier code for each application, which is received and returned to the enterprise, thus granting the enterprise its unique identifier code. Next, the unique identifier code is stored in a specific 60-bit encrypted storage space within the memory of the industrial internet collaborative device monitoring the specific equipment. The device is configured to simultaneously upload the unique identifier code contained in this specific 60-bit address when uploading collected equipment status monitoring data to the Industrial Internet Collaboration Platform. After monitoring and collecting equipment data, the industrial internet collaborative device periodically and proactively connects to the network and simultaneously uploads the collected equipment data information and the unique identifier code stored in the encrypted memory space to the Industrial Internet Collaboration Platform. Step 4: After receiving the uploaded data from the industrial interconnection collaborative device, the industrial interconnection collaborative platform separates the device status data information from the device's unique identification code. Using identification resolution technology, it uploads and submits the device's unique identification code to the identification resolution node platform for identity lookup. The identification resolution node platform compares the device's unique identification code to query the corresponding enterprise and related equipment information and feeds it back to the industrial interconnection collaborative platform. The industrial interconnection collaborative platform receives the device identification code and corresponding resolution information data, identifies and completes device positioning and enterprise and device identity authentication. After confirming the device's identity, it matches the corresponding device data information and summarizes and displays it.
[0049] According to the preset security mechanism, the device data is subjected to secure operations to generate specified device data. Specifically, this includes: obtaining the device identifier of the industrial interconnection collaborative device that has been preset; adding the device identifier to the device data through the industrial interconnection collaborative device to generate identified device data; and encrypting the identified device data to generate the specified device data.
[0050] In one embodiment of this specification, based on the device identifier applied for in advance by the enterprise to which the device belongs, after the industrial interconnection device collects device data, the device identifier is added to the device data to generate identified device data, and the identified device data is encrypted to generate designated device data, thereby ensuring the secure collection of device data and further improving the security of data collection.
[0051] Before collecting device data through industrial internet collaborative devices, the method further includes: obtaining enterprise information pre-set on the industrial internet collaborative platform, wherein the enterprise information includes a data signature of the enterprise's real-name information and the enterprise's public key; authenticating the enterprise's identity based on the enterprise information through the industrial internet collaborative platform and obtaining the enterprise's real-name information; after the enterprise's identity authentication is successful, generating a signature of the enterprise's real-name information through the industrial internet collaborative platform, and generating enterprise-specific card information based on the signature, the enterprise's public key, and the enterprise's real-name information; digesting the enterprise-specific card information through the industrial internet collaborative platform to generate a plaintext digest of the card, encrypting the enterprise-specific card information using the pre-obtained platform public key to generate encrypted enterprise-specific card information; and publishing the plaintext digest and the encrypted enterprise-specific card information to the blockchain through the industrial internet collaborative platform.
[0052] To prevent the leakage of enterprise information and partner enterprise information on the platform, which could compromise the data security of industrial equipment, the enterprise owning the equipment needs to conduct enterprise identity authentication on the platform in advance and publish the enterprise information to the blockchain. By using blockchain technology to implement multi-party trusted identity authentication for data permission operations, the key passwords, sensitive data, and sensitive algorithms of the enterprise and its partners can be effectively protected, thus effectively preventing theft or damage caused by malicious external hacking and internal misoperation or violation.
[0053] In one embodiment of this specification, blockchain technology is used to achieve multi-party trusted identity authentication for data access control. First, the enterprise uploads its real-name information, public key, private key, and a signature generated by the enterprise based on the first three pieces of information to the industrial internet collaboration platform. The industrial internet collaboration platform will then perform real-name authentication on the enterprise through an authoritative identity authentication source. Second, the industrial internet collaboration platform calculates enterprise user-specific card information using the enterprise's real-name information, public key, and the platform's signature based on the first two pieces of information. It then digests this enterprise user-specific card information and recalculates the digest. Finally, the industrial internet collaboration platform encrypts the enterprise user-specific card information using its public key and publishes both the plaintext digest and the encrypted ciphertext of the enterprise user-specific card information to the blockchain, thus achieving a multi-party trusted identity authentication method. Step S102: The industrial internet collaboration platform receives data acquisition requests from partner enterprises and authenticates the partner enterprises based on their data acquisition requests and pre-stored enterprise identity authentication information.
[0054] The enterprise identity authentication information is used to represent the identity information of the enterprise to which the industrial interconnection collaborative device belongs.
[0055] In real-world applications, a company may have partnerships with multiple upstream and downstream enterprises across the entire industry chain. To achieve industrial interconnection between these companies, data interconnection and collaboration with multiple partners are necessary. When a partner company needs to access data from other companies, it must send a data acquisition request to the industrial interconnection collaboration platform. To ensure data security, the platform authenticates the partner company based on its data acquisition request and pre-stored company identity authentication information.
[0056] Based on the data acquisition request from the cooperating enterprise and the enterprise identity authentication information pre-stored in the industrial internet collaboration platform, the identity of the cooperating enterprise is authenticated. Specifically, this includes: obtaining the cooperating enterprise information in the data acquisition request and the source enterprise information of the data source enterprise to be acquired; obtaining the encrypted source enterprise special card information based on the source enterprise information and the plaintext digest of the special card in the blockchain, and decrypting the encrypted source enterprise special card information to obtain the source enterprise real name information in the source enterprise special card information; based on the source enterprise real name information, determining the potential cooperating enterprise identifiers of multiple potential cooperating enterprises corresponding to the source enterprise in the pre-established cooperation relationship data table; and authenticating the identity of the cooperating enterprise based on the cooperating enterprise identifier in the cooperating enterprise information and the multiple potential cooperating enterprise identifiers.
[0057] Based on the partner company identifier in the partner company information and the multiple potential partner company identifiers, the partner company is authenticated. Specifically, when there is a designated company identifier among the multiple potential partner company identifiers that matches the partner company identifier, the partner company's identity is authenticated.
[0058] In one embodiment of this specification, when obtaining the information of the cooperating enterprise in the data acquisition request and the source enterprise information of the data source enterprise to be acquired, and authenticating the user identity of the enterprise through the industrial internet collaborative platform, it is necessary to determine whether the cooperating enterprise is a partner of the enterprise to which the data to be acquired belongs. Based on the source enterprise information and the plaintext digest of the dedicated card in the blockchain, the encrypted source enterprise dedicated card information is obtained, and the encrypted source enterprise dedicated card information is decrypted to obtain the source enterprise real-name information in the source enterprise dedicated card information. Each enterprise corresponds to at least one cooperating enterprise, and the cooperation relationship between the enterprise and the cooperating enterprises is stored in a cooperation relationship data table. Based on the source enterprise real-name information, the identifiers of multiple potential cooperating enterprises corresponding to the source enterprise are determined in the pre-established cooperation relationship data table. The identity of the cooperating enterprise is authenticated based on the cooperating enterprise identifier in the cooperating enterprise information and the multiple potential cooperating enterprise identifiers. If a designated enterprise identifier that matches the cooperating enterprise identifier exists among the multiple potential cooperating enterprise identifiers, it indicates that the cooperating enterprise is a partner of the source enterprise and has data acquisition rights; therefore, the identity authentication of the cooperating enterprise is passed.
[0059] Step S103: After the identity authentication of the partner company is passed, a designated connection relationship is established between the partner company and the industrial interconnection collaborative device through the industrial interconnection collaborative platform.
[0060] In one embodiment of this specification, after the industrial internet collaboration platform verifies the identity of the cooperating enterprise, it indicates that the data acquisition request is permitted by the enterprise, and a designated connection relationship is established between the cooperating enterprise and the industrial internet collaboration device through the industrial internet collaboration platform.
[0061] The industrial internet collaboration platform establishes a designated connection between the collaborating enterprise and the industrial internet collaboration device. Specifically, this includes: obtaining the data type to be acquired from the data acquisition request through the industrial internet collaboration platform, and determining the designated device identifier of the industrial internet collaboration device based on the data type; acquiring the designated device data through the industrial internet collaboration platform, and determining the preset device identifier of the preset industrial internet collaboration device corresponding to the device data; verifying the preset industrial internet collaboration device through the industrial internet collaboration platform based on the designated device identifier and the preset device identifier; and establishing a communication relationship between the collaborating enterprise and the industrial internet collaboration device through the industrial internet collaboration platform based on the preset device identifier and the collaborating enterprise information in the data acquisition request.
[0062] In practical application scenarios, in addition to verifying the identity of partner companies, it is also necessary to ensure the data security of partner companies. In order to avoid sending incorrect data to partner companies, it is necessary to verify the device data of industrial interconnection collaborative devices.
[0063] In one embodiment of this specification, the data type to be acquired in the data acquisition request is obtained through an industrial internet collaboration platform. Based on the data type, the industrial internet collaboration device collecting the data is determined, and a designated device identifier for that device is obtained. The designated device data sent by the industrial internet device is acquired through the industrial internet collaboration platform, and the designated device data is parsed to obtain the device data portion and the device identifier, which is referred to as the preset device identifier. The industrial internet collaboration platform determines whether the designated device identifier and the preset device identifier are consistent. If they are consistent, the device verification of the corresponding preset industrial internet collaboration device is passed. After successful verification, a communication relationship is established between the collaborating enterprise and the industrial internet collaboration device based on the preset device identifier and the collaborating enterprise information in the data acquisition request.
[0064] Step S104: Verify the connection of the specified connection relationship through the industrial interconnection collaborative device.
[0065] The industrial interconnection and collaboration device verifies the connection of the specified connection relationship, specifically including: determining the connection type of the specified connection relationship through the industrial interconnection and collaboration device, wherein the connection type includes normal connection and illegal connection; when the specified connection relationship is a normal connection, the connection verification of the specified connection relationship is deemed to be successful; when the specified connection relationship is an illegal connection, the specified connection relationship is blocked according to the pre-set illegal connection blocking scheduling policy.
[0066] In practical application scenarios, after the platform establishes a connection between the device and the partner company, there may be situations where someone impersonates the partner company to illegally connect to the device. In order to avoid data security threats in such cases, the embodiments in this specification also need to verify the connection relationship.
[0067] In one embodiment of this specification, the security operating system of the industrial interconnection collaborative device determines the connection type of a specified connection relationship between the collaborative service and the device. It should be noted that the connection type includes normal connections and illegal connections. When the specified connection relationship is a normal connection, the connection verification for that specified connection relationship is deemed successful. When the specified connection relationship is an illegal connection, the specified connection relationship is blocked according to the illegal connection blocking scheduling policy pre-set in the security operating system, preventing damage to the industrial interconnection collaborative device and avoiding data loss.
[0068] In one embodiment of this specification, an effective strategy for identifying illegal connections is designed. This involves analyzing the data connection state transition process, monitoring "masked frames," and employing a priority-based illegal connection blocking scheduling strategy. Illegal links are identified through key variable comparison tests and blocked immediately. The identification and immediate blocking of illegal connections includes the following steps: Step 1: During the compilation of the operating system kernel, the cryptographic public keys (or a certificate list containing cryptographic public keys) of all security administrators within the system are implanted. While setting up ordinary blacklist and whitelist mechanisms, a policy is implemented requiring signature authorization from a majority / all security administrators for certain critical kernel access programs to execute. Step 2: When an application is invoked for execution, the operating system kernel in this embodiment verifies whether the current valid account identity file corresponds to the content of the corresponding account authorization file. If the verification fails, execution is not allowed. Then, based on the operating system kernel in this embodiment, it checks whether the valid account identity has the execution authorization qualification to launch the application. If the verification fails, the application is not executed. Step 3: Based on the hardened operating system kernel of the embodiments in this specification, system calls are intercepted and the application's current valid account file is obtained during application startup and execution. This file is checked to ensure the validity of the account authorization file, the role authorization file, and the execution authorization file used when the application process is started and run. If any of these authorizations is deemed invalid, the startup and execution of the application process are terminated. Step 4: At the terminal access boundary switch, network access control measures can be used to block unauthorized terminals from accessing the intranet. Simultaneously, application access control is used on important background servers to block unauthorized terminals from accessing important servers and service resources. Step 5: Based on the terminal network behavior pattern, a proactive threat defense mechanism is implemented. By centrally controlling the network behavior of each computer terminal, limiting the subject, target, and service of network behavior, and combining this with the security status of the computer terminal to control network access, illegal connection pathways can be effectively cut off. Monitoring the number of concurrent TCP connections mitigates the damage caused by illegal connections to the network. Monitoring UDP packet sending behavior restricts network access for abnormal processes. Step 6: A powerful built-in enterprise-grade host firewall system employs access control, traffic control, ARP spoofing control, network behavior pattern control, and unauthorized external connection control to proactively defend against threats and control network behavior against computer terminals. Step 7: By monitoring ARP request or response packets, automatically binding gateway MAC addresses, and rejecting delayed ARP response packets, internal network ARP spoofing attacks are prevented.
[0069] Step S105: After the connection verification of the specified connection relationship is passed, the data of the specified device is sent to the partner company through the industrial interconnection collaboration device to realize industrial interconnection collaboration between the company to which the industrial interconnection collaboration device belongs and the partner company.
[0070] In one embodiment of this specification, after the connection verification of the specified connection relationship is passed by the industrial interconnection collaborative device, a direct data transmission channel is established according to the specified connection relationship between the industrial interconnection collaborative device and the cooperative enterprise. The device data collected by the industrial interconnection collaborative device of the enterprise is directly sent to the cooperative enterprise, avoiding the problem of long forwarding time caused by the device data being forwarded through the industrial interconnection collaborative platform, and ensuring the timeliness of the data.
[0071] After sending the designated device data to the partner company through the industrial interconnection collaborative device, the method further includes: parsing the designated device data to obtain the device data and device identifier in the designated device data; verifying the device identifier, and obtaining the device data after successful verification.
[0072] In one embodiment of this specification, in order to ensure the data security of the cooperating enterprise, it is necessary to perform data verification on the received designated device data to determine whether the data was sent by the device of the enterprise to which the enterprise belongs. The designated device data is parsed to obtain the device data and device identifier in the designated device data. It is determined whether the device identifier in the actual received data is consistent with the device identifier corresponding to the data to be obtained. If they are consistent, the verification of the device identifier is deemed to be successful. After successful verification, the device data is obtained, thereby realizing industrial interconnection collaboration between the enterprise to which the industrial interconnection collaborative device belongs and the cooperating enterprise.
[0073] The above technical solution collects equipment data through industrial internet collaborative devices and performs secure operations on the data, ensuring secure data collection and improving data security. The industrial internet collaborative platform verifies the identity of partner companies; after successful verification, a connection is established between the industrial internet collaborative devices and the partner company, ensuring the security of the data acquisition party's identity and the connection itself, thus improving data security during data transmission. After the connection is established, the industrial internet collaborative devices verify the connection before transmitting data, further enhancing data transmission security. Moreover, since the equipment data is sent directly to the partner company by the industrial internet collaborative devices without being forwarded through the platform, data timeliness is guaranteed, meeting the needs of application scenarios with high data timeliness requirements, thus balancing data security and timeliness in industrial data.
[0074] This specification also provides an industrial interconnection and collaboration device for improving data security, such as... Figure 5 As shown, the device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to:
[0075] The system collects device data through industrial interconnection and collaboration devices, performs secure operations on the data according to a preset security mechanism, and generates designated device data. Through the industrial interconnection and collaboration platform, it receives data acquisition requests from partner companies. Based on the partner company's data acquisition request and pre-stored enterprise identity authentication information, it authenticates the partner company. This enterprise identity authentication information represents the identity information of the company to which the industrial interconnection and collaboration devices belong. After successful authentication, a designated connection relationship is established between the partner company and the industrial interconnection and collaboration devices through the industrial interconnection and collaboration platform. The industrial interconnection and collaboration devices verify this connection relationship. After successful connection verification, the designated device data is sent to the partner company through the industrial interconnection and collaboration devices, thus realizing industrial interconnection collaboration between the company to which the industrial interconnection and collaboration devices belong and the partner company.
[0076] This specification also provides a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured as follows:
[0077] The system collects device data through industrial interconnection and collaboration devices, performs secure operations on the data according to a preset security mechanism, and generates designated device data. Through the industrial interconnection and collaboration platform, it receives data acquisition requests from partner companies. Based on the partner company's data acquisition request and pre-stored enterprise identity authentication information, it authenticates the partner company. This enterprise identity authentication information represents the identity information of the company to which the industrial interconnection and collaboration devices belong. After successful authentication, a designated connection relationship is established between the partner company and the industrial interconnection and collaboration devices through the industrial interconnection and collaboration platform. The industrial interconnection and collaboration devices verify this connection relationship. After successful connection verification, the designated device data is sent to the partner company through the industrial interconnection and collaboration devices, thus realizing industrial interconnection collaboration between the company to which the industrial interconnection and collaboration devices belong and the partner company.
[0078] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for apparatus, devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0079] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0080] The devices, media, and methods provided in the embodiments of this specification are one-to-one correspondences. Therefore, the devices and media also have similar beneficial technical effects as their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.
[0081] Those skilled in the art will understand that embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0082] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0083] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0084] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0085] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0086] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0087] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0088] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0089] The above description is merely one or more embodiments of this specification and is not intended to limit this specification. Various modifications and variations can be made to the one or more embodiments of this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of one or more embodiments of this specification should be included within the scope of the claims of this specification.
Claims
1. An industrial interconnection collaborative method for improving data security, characterized in that, The application is applied to an industrial internet collaborative system, which comprises industrial internet collaborative devices and an industrial internet collaborative platform, and the method comprises the following steps: Collecting device data through the industrial internet collaborative device, performing security operations on the device data according to a preset security mechanism, and generating specified device data; Through the industrial internet collaborative platform, receiving a data acquisition request of a cooperative enterprise, performing identity authentication on the cooperative enterprise according to the data acquisition request of the cooperative enterprise and pre-stored enterprise identity authentication information, wherein the enterprise identity authentication information is used to represent the identity information of the enterprise to which the industrial internet collaborative device belongs; After the identity authentication of the cooperative enterprise is passed, establishing a specified connection relationship between the cooperative enterprise and the industrial internet collaborative device through the industrial internet collaborative platform; Through the industrial internet collaborative device, performing connection verification on the specified connection relationship; After the connection verification of the specified connection relationship is passed, sending the specified device data to the cooperative enterprise through the industrial internet collaborative device, and realizing the industrial internet collaboration between the enterprise to which the industrial internet collaborative device belongs and the cooperative enterprise; According to a preset security mechanism, performing security operations on the device data to generate specified device data, specifically comprising: Obtaining the device identifier of the industrial internet collaborative device pre-set; Through the industrial internet collaborative device, adding the device identifier in the device data to generate identified device data; Encrypting the identified device data to generate the specified device data; Through the industrial internet collaborative platform, establishing a specified connection relationship between the cooperative enterprise and the industrial internet collaborative device, specifically comprising: Through the industrial internet collaborative platform, obtaining the to-be-acquired data type in the data acquisition request, so as to determine the specified device identifier of the industrial internet collaborative device based on the to-be-acquired data type; Through the industrial internet collaborative platform, obtaining the specified device data, so as to determine the preset device identifier of the preset industrial internet collaborative device corresponding to the device data through the specified device data; Through the industrial internet collaborative platform, performing device verification on the preset industrial internet collaborative device according to the specified device identifier and the preset device identifier; After verification, through the industrial internet collaborative platform, establishing a communication relationship between the cooperative enterprise and the industrial internet collaborative device according to the preset device identifier and the cooperative enterprise information in the data acquisition request of the cooperative enterprise; Through the industrial internet collaborative device, performing connection verification on the specified connection relationship, specifically comprising: Through the industrial internet collaborative device, determining the connection type of the specified connection relationship, wherein the connection type comprises normal connection and illegal connection; When the specified connection relationship is normal connection, it is determined that the connection verification of the specified connection relationship is passed; When the specified connection relationship is illegal connection, setting a block according to a pre-set illegal connection blocking scheduling strategy. 2.The industrial internet of things collaborative method for improving data security of claim 1, wherein, Before collecting device data by the industrial internet of things collaborative device, the method further comprises: obtaining enterprise information of an enterprise to which the industrial internet of things collaborative platform belongs, wherein the enterprise information of the enterprise to which the industrial internet of things collaborative platform belongs comprises a data signature of enterprise real name information and a public key of the enterprise to which the industrial internet of things collaborative platform belongs; performing enterprise identity authentication on the enterprise to which the industrial internet of things collaborative platform belongs according to the enterprise information of the enterprise to which the industrial internet of things collaborative platform belongs, and obtaining enterprise real name information of the enterprise to which the industrial internet of things collaborative platform belongs; generating signature information of the enterprise real name information by the industrial internet of things collaborative platform when the enterprise identity authentication of the enterprise to which the industrial internet of things collaborative platform belongs is passed, and generating enterprise-specific card information according to the signature information, the public key of the enterprise to which the industrial internet of things collaborative platform belongs, and the enterprise real name information of the enterprise to which the industrial internet of things collaborative platform belongs; performing an abstract on the enterprise-specific card information by the industrial internet of things collaborative platform to generate a specific card plaintext abstract, encrypting the enterprise-specific card information using a platform public key obtained in advance to generate encrypted enterprise-specific card information; publishing the specific card plaintext abstract and the encrypted enterprise-specific card information to a block chain by the industrial internet of things collaborative platform. 3.The industrial internet of things collaborative method for improving data security of claim 2, wherein, According to the data acquisition request of the cooperative enterprise and the enterprise identity authentication information stored in the industrial internet of things collaborative platform in advance, performing identity authentication on the cooperative enterprise, specifically comprising: obtaining cooperative enterprise information in the data acquisition request and source enterprise information of a data source enterprise to be acquired; obtaining encrypted source enterprise-specific card information according to the source enterprise information and the specific card plaintext abstract in the block chain, and decrypting the encrypted source enterprise-specific card information to obtain source enterprise real name information in the source enterprise-specific card information; based on the source enterprise real name information, determining a plurality of to-be-cooperated enterprise identifiers of a plurality of to-be-cooperated enterprises corresponding to the source enterprise in a pre-established cooperation relationship data table; performing identity authentication on the cooperative enterprise according to the cooperative enterprise identifier in the cooperative enterprise information and the plurality of to-be-cooperated enterprise identifiers.
4. The industrial internet synergy method for improving data security according to claim 3, characterized in that, According to the cooperative enterprise identifier in the cooperative enterprise information and the plurality of to-be-cooperated enterprise identifiers, performing identity authentication on the cooperative enterprise, specifically comprising: when there is a specified enterprise identifier consistent with the cooperative enterprise identifier in the plurality of to-be-cooperated enterprise identifiers, performing identity authentication on the cooperative enterprise.
5. The industrial internet synergy method for improving data security according to claim 1, wherein, After sending the specified device data to the cooperative enterprise by the industrial internet of things collaborative device, the method further comprises: parsing the specified device data to obtain device data and a device identifier in the specified device data; verifying the device identifier, and obtaining the device data after verification.
6. An industrial interconnected collaborative device for improving data security, characterized by, The device comprises: at least one processor; and a memory in communication connection with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-5.
7. A non-transitory computer storage medium having stored thereon computer- executable instructions configured to perform the method of any one of claims 1-5.
Citation Information
Patent Citations
Industrial Internet identifier distribution and data management method based on block chain
CN112085417A
Data storage and calling method and device of industrial internet platform
CN114430417A