Industrial data trusted sharing method, device, equipment and storage medium

Through industrial Internet identification resolution and blockchain evidence storage technology, the problem of difficult to balance data value and security in industrial data sharing is solved, real, trustworthy, timely, effective and secure sharing of data is achieved, and governance processes are optimized and operational costs are reduced.

CN117573632BActive Publication Date: 2025-08-15CHINA MOBILE ZIJIN INNOVATION INST CO LTD +2
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202311518495.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-14
Publication Date
2025-08-15
Estimated Expiration
2043-11-14

AI Technical Summary

Technical Problem

The existing industrial data sharing methods cannot balance the release of data value and data security needs, and there are risks such as poor data circulation, information leakage, and excessive utilization. Moreover, traditional data sharing methods are difficult to protect the interests of data owners and the feasibility of data value integration.

Method used

The industrial Internet identification resolution system is adopted to identify business data on terminal industrial equipment through active identification carriers, and after the data user signs an electronic contract with the provider, the data usage log is recorded using blockchain evidence storage technology to ensure data security and traceability.

Benefits of technology

It realizes the authenticity, trustworthiness, timely and effective data sharing, solves the concerns of data abuse, improves the release and security of data value, optimizes governance processes and reduces operating costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117573632B_ABST
    Figure CN117573632B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of industrial Internet technology, and discloses a method, device, equipment and storage medium for trusted sharing of industrial data. The method comprises: upon receiving a data usage request initiated by a data user, sending a business data demand order to a data provider; after the data provider and the data user sign an electronic contract, obtaining target business data based on a data identifier and sending the target business data to the data user; after the data user obtains the target business data, storing the usage log of the target business data on a blockchain; the present invention ensures data security through identification technology and blockchain technology, and data access and use can be log-stored and traced, thereby resolving enterprises' concerns about data abuse during data transactions, thereby achieving a balance between data value release and data security requirements, and further realizing authentic, reliable, timely, effective and secure sharing of data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial Internet technology, and in particular to a method, device, equipment and storage medium for trusted sharing of industrial data. Background Art

[0002] With the deepening development of the digital economy, the supporting role of data has become increasingly important. In the industrial sector, industrial data is gradually transforming from a byproduct of the manufacturing process into a strategic resource that brings new value to enterprises and supply chains, becoming a key factor in enhancing manufacturing productivity, competitiveness, and innovation. However, while significantly promoting the networked sharing, intensive integration, collaborative development, and efficient utilization of social factor resources, industrial data also faces risks such as poor circulation, information leakage, and overuse.

[0003] Traditional data circulation methods can no longer fully meet the needs of industrial applications. Currently, data sharing and circulation are mostly centralized bilateral information transmission models. One method is to share and circulate through data trading platforms, and the parties to the transaction reach a transaction through data packet transmission. However, for industrial data with complex sources, it is difficult to protect the interests of data owners, which can easily lead to the exposure of information involving the core competitiveness of the enterprise and the secondary use or even abuse of data by users, making it less applicable. The other method is to circulate based on a plaintext data API interface, outputting the processed unilateral result data in the form of an API, which protects user privacy information to a certain extent and reduces the possibility of secondary use, but also reduces the feasibility of data value integration, making it difficult to release the application value of data collaborative sharing. Therefore, there is an urgent need to find a new data sharing and circulation solution suitable for industrial scenarios to strike a balance between data value release and data security requirements. Summary of the Invention

[0004] The main purpose of the present invention is to provide a method, device, equipment and storage medium for trusted sharing of industrial data, aiming to solve the technical problem that existing industrial data sharing methods cannot achieve a balance between data value release and data security requirements.

[0005] To achieve the above objectives, the present invention provides a method for trusted sharing of industrial data, which includes:

[0006] Upon receiving a data usage request from a data user, the service provider sends a business data demand order to the data provider;

[0007] After the data provider and the data user sign an electronic contract, the target business data is obtained based on the data identifier, which is obtained by identifying the business data uploaded by the terminal industrial device corresponding to the data provider using an active identification carrier, and the active identification carrier is set on the terminal industrial device;

[0008] Sending the target business data to the data user;

[0009] After the data user obtains the target business data, the usage log of the target business data is stored on the blockchain.

[0010] Optionally, the sending the target business data to the data user includes:

[0011] Desensitizing the target business data while preserving the original data information of the target business data;

[0012] The desensitized target business data is sent to the data user.

[0013] Optionally, upon receiving a data use request initiated by a data user, before sending a business data demand order to a data provider, the process further includes:

[0014] Upon receiving a first power-on verification request sent by the terminal industrial device via the active identification carrier, verifying the unique identification of the terminal industrial device;

[0015] After verification, the active identification carrier, the terminal industrial device and the enterprise identification of the data user are associated so that after the association is completed, the active identification carrier identifies the business data uploaded by the terminal industrial device through the association relationship.

[0016] Optionally, after the verification is passed, associating the active identification carrier, the terminal industrial device, and the enterprise identification of the data user includes:

[0017] After verification, the entities and relationships of the active identification carrier, the terminal industrial equipment, and the data user are determined, and a knowledge graph is constructed based on the entities and the relationships;

[0018] An entity relationship is established in the knowledge graph, and an attribute relationship is added in the knowledge graph to associate the active identification carrier, the terminal industrial equipment, and the corporate identity of the data user.

[0019] Optionally, upon receiving the first power-on verification request sent by the terminal industrial device via the active identification carrier, before verifying the unique identification of the terminal industrial device, the method further includes:

[0020] Upon receiving a registration request initiated by a data provider, registering the data provider;

[0021] After registration is completed, the enterprise identity of the data provider is applied for from the Industrial Internet Identity Resolution Top-Level Node through the Industrial Internet Identity Resolution Second-Level Node.

[0022] Optionally, upon receiving a data usage request initiated by a data user, before sending a business data demand order to a data provider, the process further includes:

[0023] receiving a data reporting request sent by the terminal industrial device via the active identification carrier;

[0024] Verifying the signature of the data reporting request, and after verifying the signature, authenticating the data reporting request;

[0025] After the authentication is passed, the business data uploaded by the terminal industrial equipment through the active identification carrier is received.

[0026] Optionally, the receiving a data reporting request sent by the terminal industrial device through the active identification carrier includes:

[0027] Assess the sensitivity level of the business data and analyze the scenario requirements of industrial scenarios;

[0028] Determine the data type of the business data according to the scenario requirements, and obtain the device type of the terminal industrial device;

[0029] Determining a data collection level for the business data based on the sensitivity level, the scenario requirements, the data type, and the device type;

[0030] Setting the frequency of uploading business data by the active identification carrier according to the data collection level;

[0031] The business data uploaded by the terminal industrial equipment through the active identification carrier is received at the interval of the frequency.

[0032] In addition, to achieve the above-mentioned purpose, the present invention further proposes an industrial data trusted sharing device, which includes:

[0033] The order sending module is used to send a business data demand order to the data provider upon receiving a data use request initiated by the data user;

[0034] A data acquisition module is configured to acquire target business data based on a data identifier after the data provider and the data user sign an electronic contract. The data identifier is obtained by identifying the business data uploaded by the terminal industrial device corresponding to the data provider using an active identification carrier, which is provided on the terminal industrial device.

[0035] A data sending module, configured to send the target service data to the data user;

[0036] The log evidence module is used to store the usage log of the target business data on the blockchain after the data user obtains the target business data.

[0037] In addition, to achieve the above-mentioned purpose, the present invention also proposes an industrial data trusted sharing device, which includes a memory, a processor, and an industrial data trusted sharing program stored on the memory and runnable on the processor, and the industrial data trusted sharing program is configured to implement the industrial data trusted sharing method as described above.

[0038] In addition, to achieve the above-mentioned purpose, the present invention also proposes a storage medium, on which an industrial data trusted sharing program is stored. When the industrial data trusted sharing program is executed by a processor, the industrial data trusted sharing method as described above is implemented.

[0039] The present invention discloses that upon receiving a data usage request initiated by a data user, a business data demand order is sent to a data provider. After the data provider and the data user sign an electronic contract, the target business data is obtained according to the data identifier. The data identifier is obtained by an active identification carrier identifying the business data uploaded by the terminal industrial equipment corresponding to the data provider. The active identification carrier is set on the terminal industrial equipment, and the target business data is sent to the data user. After the data user obtains the target business data, the usage log of the target business data is stored on the blockchain. The present invention ensures data security through identification technology and blockchain technology. Data access and use can be logged and traced, which solves the concerns of enterprises about data abuse in the data transaction process, so as to achieve a balance between data value release and data security needs, and further realize the authenticity, credibility, timeliness, effectiveness and secure sharing of data. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 It is a structural diagram of an industrial data trusted sharing device in a hardware operating environment involved in an embodiment of the present invention;

[0041] Figure 2 This is a flow chart of the first embodiment of the industrial data trusted sharing method of the present invention;

[0042] Figure 3 This is a diagram showing the overall architecture of a trusted data sharing platform according to an embodiment of the industrial data trusted sharing method of the present invention;

[0043] Figure 4 This is an interactive diagram of an embodiment of the industrial data trusted sharing method of the present invention;

[0044] Figure 5 This is a flow chart of a second embodiment of the industrial data trusted sharing method of the present invention;

[0045] Figure 6 This is a flow chart of a third embodiment of the industrial data trusted sharing method of the present invention;

[0046] Figure 7 This is a structural block diagram of the first embodiment of the industrial data trusted sharing device of the present invention.

[0047] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0048] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0049] Reference Figure 1 , Figure 1 This is a schematic diagram of the structure of an industrial data trusted sharing device in the hardware operating environment involved in the embodiment of the present invention.

[0050] like Figure 1 As shown, the industrial data trusted sharing device may include: a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to implement connection and communication between these components. The user interface 1003 may include a display screen. Optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. In the present invention, the wired interface of the user interface 1003 may be a USB interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a wireless fidelity (Wi-Fi) interface). The memory 1005 may be a high-speed random access memory (RAM) or a non-volatile memory (NVM), such as a disk storage device. The memory 1005 may also be a storage device independent of the aforementioned processor 1001.

[0051] Those skilled in the art will understand that Figure 1 The structure shown in the figure does not constitute a limitation on the industrial data trusted sharing device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0052] like Figure 1As shown, the memory 1005 identified as a computer storage medium may include an operating system, a network communication module, a user interface module, and an industrial data trusted sharing program.

[0053] exist Figure 1 In the industrial data trusted sharing device shown, the network interface 1004 is mainly used to connect to the background server and communicate data with the background server; the user interface 1003 is mainly used to connect to the user device; the industrial data trusted sharing device calls the industrial data trusted sharing program stored in the memory 1005 through the processor 1001, and executes the industrial data trusted sharing method provided by the embodiment of the present invention.

[0054] Based on the above hardware structure, an embodiment of the industrial data trusted sharing method of the present invention is proposed.

[0055] Reference Figure 2 , Figure 2 This is a flow chart of the first embodiment of the industrial data trusted sharing method of the present invention, and proposes the first embodiment of the industrial data trusted sharing method of the present invention.

[0056] It should be understood that with the deepening development of the digital economy, the supporting role of data elements has become increasingly important. In the industrial sector, industrial data is gradually transforming from a byproduct of the manufacturing process into a strategic resource that brings new value to enterprises and supply chains, becoming a key factor in improving manufacturing productivity, competitiveness, and innovation. However, while greatly promoting the networked sharing, intensive integration, collaborative development, and efficient utilization of social factor resources, industrial data also faces risks such as poor circulation, information leakage, and over-exploitation.

[0057] Traditional data circulation methods can no longer fully meet the needs of industrial applications. Currently, data sharing and circulation are mostly centralized bilateral information transmission models. One method is to share and circulate through data trading platforms, and the parties to the transaction reach a transaction through data packet transmission. However, for industrial data with complex sources, it is difficult to protect the interests of data owners, which can easily lead to the exposure of information involving the core competitiveness of the enterprise and the secondary use or even abuse of data by users, making it less applicable. The other method is to circulate based on a plaintext data API interface, outputting the processed unilateral result data in the form of an API, which protects user privacy information to a certain extent and reduces the possibility of secondary use, but also reduces the feasibility of data value integration, making it difficult to release the application value of data collaborative sharing. Therefore, there is an urgent need to find a new data sharing and circulation solution suitable for industrial scenarios to strike a balance between data value release and data security requirements.

[0058] The development of information and communication technologies, represented by the Industrial Internet, is bringing tremendous opportunities for the transformation of traditional industries and becoming a key foundation for intelligent manufacturing. Identity resolution, a key infrastructure of the Industrial Internet, assigns globally unique identifiers to every object. Leveraging the Industrial Internet's identity resolution system, it enables cross-regional, cross-industry, and cross-enterprise information querying and sharing. Identity resolution can overcome technical barriers stemming from differences in communication protocols, software and hardware platforms, and data formats. It can also break down spatial barriers stemming from multiple data collection sources and storage locations. It can also break down barriers between different organizations, such as management agencies, security entities, and stakeholders.

[0059] Tags that carry identification code resources, or identification carriers, can be categorized as active or passive identification carriers, depending on whether they can actively communicate with identification data reading and writing devices, identification resolution service nodes, and identification data application platforms. Active identification carriers can be embedded within industrial equipment, carrying the Industrial Internet identification code and its necessary security certificates, algorithms, and keys. They also possess network communication capabilities and the ability to actively register and upload operational status information.

[0060] Therefore, it is possible to use identification coding resources and identification resolution systems to carry out industrial identification data management and data sharing and use across enterprises, industries, regions and countries.

[0061] The existing industrial data sharing methods have the following main shortcomings:

[0062] 1. When data is shared and circulated through existing data trading platforms, the parties involved in the transaction reach a deal through the transmission of data packets. For industrial data from complex sources, this can easily lead to the exposure of core information and the secondary use or even abuse of data.

[0063] 2. When data is shared and circulated based on the plaintext data API interface, the processed unilateral result data is output in the form of an API. This method reduces the feasibility of data value integration and makes it difficult to release the application value of collaborative sharing of industrial data.

[0064] 3. There are still many "information islands" within enterprises, upstream and downstream of the industrial chain, and between various production equipment and information systems across fields, which hinder the integrated sharing of manufacturing resources and data and affect further collaborative applications.

[0065] 4. Most existing industrial data platforms only display data on large screens, focusing on data visualization and lack sufficient application scenarios. Their efficiency and value to the production process are not high.

[0066] Therefore, in order to solve the above technical problems, the present invention is based on the industrial Internet identification resolution system, and through active identification of data, it can realize uninterrupted recording and supervision of the entire process of data production, transaction, and application. It can build a new trust system and value system for industrial data applications, solve the trust problems of data across fields, industries, systems, and platforms, realize penetrating supervision and traceability, ensure the integrity, confidentiality, and availability of industrial data as a production factor, and on this basis, it can carry out safe and effective collection, transmission, storage, use, and sharing, promote data sharing, optimize governance processes, reduce operating costs, and improve collaborative efficiency.

[0067] In a first embodiment, the industrial data trusted sharing method includes:

[0068] Step S10: upon receiving a data usage request initiated by a data user, a business data demand order is sent to a data provider.

[0069] It can be understood that the execution subject of this embodiment can be an industrial data trusted sharing device with data processing, network communication and program running functions, such as a trusted data sharing platform (hereinafter referred to as the platform), etc., or other electronic devices that can achieve the same or similar functions. This embodiment does not impose any restrictions on this.

[0070] For easier understanding, refer to Figure 3 This invention is described but not limited thereto. Figure 3 This is a diagram of the overall architecture of the trusted data sharing platform for an embodiment of the trusted industrial data sharing method of the present invention. In the diagram, the trusted industrial data sharing method designed in this proposal is based on industrial Internet identity resolution, connecting national top-level nodes and enterprise nodes. The middle platform implements the horizontal expansion capability of identity services and provides support for upper-level application services. Relying on technologies such as the Internet of Things, blockchain, and data analysis, the platform assigns industrial Internet identity resolution codes to dynamically collected industrial data, stores the data in the blockchain, and establishes a point-to-point data "transmission chain" between enterprises, third-party service agencies, and government regulatory departments, opening up the interconnection and interoperability of heterogeneous data and different master processes, and realizing authentic, reliable, timely, effective, and secure data sharing.

[0071] In this embodiment, the trusted identification carrier based on the security chip ensures the security of identification data and data communication. The active identification carrier is closely integrated with the device itself and embedded inside the industrial equipment, which is not easy to be stolen or installed by mistake. At the same time, it has network connection capability and can actively initiate identification resolution requests to the identification resolution server. It has the characteristics of active identification registration and active uploading of operation status information, and supports remote addition, deletion, modification and query of the identification and related information it carries. In addition to carrying industrial identifiers, the active identification carrier also carries necessary security certificates, algorithms and keys, and can provide encrypted transmission of industrial identifiers and related data, and can support access authentication and other trusted related functions. The functional modules involved in the platform are as follows:

[0072] 1. For industrial terminal devices, deploying active identification carriers and active identification carrier software development kits (SDKs) on the data provider's industrial terminals enables reporting of industrial internet identification data, active identification carrier data, and terminal-collected data. If the industrial terminal device does not support interaction between the active identification carrier SDK and the identification carrier management module, the technical requirements can be met by connecting the device to an industrial intelligent gateway.

[0073] 2. Trusted data sharing platform. The platform deploys basic function modules of enterprise nodes, identification carrier management modules and data acquisition and transmission modules to realize operations such as active identification carrier management and industrial terminal data collection. It has the capabilities of data desensitization, access control, evidence storage and traceability.

[0074] The basic functional module of the enterprise node has the ability to allocate industrial Internet identities to active identification carriers, connect with secondary nodes, and apply for enterprise CA from the top node through the secondary nodes.

[0075] The identification carrier management module has the ability to obtain industrial identification, active identification carrier identification, associate the above identifications, add, delete, modify and query industrial identifications, and perform security authentication and carrier management of active identification carriers.

[0076] The data acquisition and transmission module has the ability to initiate identity authentication for active identification carriers and receive business data from industrial terminals.

[0077] The platform uses data desensitization, a security technology, to whitewash data and remove sensitive content while preserving original data characteristics, business rules, and data relevance. This ensures that development, testing, training, and big data operations are not impacted by desensitization, ensuring data consistency and validity before and after desensitization.

[0078] Through data control technology - access control, the platform provides the ability to control the objects, scope, and methods of data use, meeting the needs of enterprises for industrial data to be available but not visible, available but not storable, controllable and measurable, and eliminating circulation concerns; at the same time, it provides data processors with log evidence of data circulation processing, internal and external compliance records, and realizes effective management of data resources; the platform can also provide intermediary services for both data supply and demand parties, facilitate supply and demand docking, and promote the value conversion of industrial data element resources.

[0079] The platform uses blockchain evidence storage and identification technology to track and record the circulation chain of tangible goods or intangible information, and adopts a distributed trust mechanism to establish a digital space trust chain, so as to ensure that the content on the chain is safe, controllable, tamper-proof and traceable, achieving the purpose of anti-tampering, traceability and trustworthy data sources.

[0080] Data providers and data users can also subscribe to services provided by third-party organizations through the platform, including algorithm services, model services, federated learning, etc.

[0081] 3. The top-level nodes and secondary nodes of the Industrial Internet have the ability to assign industrial identification prefixes, apply for registration, and issue enterprise CA.

[0082] Step S20: After the data provider and the data user sign an electronic contract, the target business data is obtained according to the data identifier. The data identifier is obtained by an active identification carrier identifying the business data uploaded by the terminal industrial equipment corresponding to the data provider, and the active identification carrier is set on the terminal industrial equipment.

[0083] It is understandable that the terminal industrial equipment can upload business data via the active identification carrier at preset intervals, and this embodiment does not limit this.

[0084] Step S30: Send the target business data to the data user.

[0085] Step S40: After the data user obtains the target business data, the usage log of the target business data is stored in the blockchain.

[0086] For easier understanding, refer to Figure 4 This invention is described but not limited thereto. Figure 4 This is an interactive diagram of an embodiment of the industrial data trusted sharing method of the present invention. In the figure, the industrial data trusted sharing method includes the following steps:

[0087] 11. Data users can view the partial business data opened by data providers and the corresponding complete data identifiers through platform keyword search, catalog push, etc., and place orders for the required data platforms through the platform;

[0088] 12. The data provider receives the business data demand order pushed by the platform and signs an electronic contract;

[0089] 13. Data users can obtain the required uniquely identified business data through the platform and obtain business data through the identification resolution system. The business data reporting process can be traced and the business data is authentic and reliable.

[0090] 14. After data users obtain business data, the platform uses access control and blockchain technology to store, identify, and upload data usage logs to the blockchain. Considering the sensitivity and importance of industrial data, the reliability of data on-chain storage is enhanced through various methods. These include using a multi-signature mechanism to disperse key storage across different nodes to improve key security, using SHA-256 to replace weaker hash algorithms, or adopting the more powerful symmetric encryption algorithm AES-256, using role-based access control (RBAC) authentication and authorization mechanisms to manage user permissions, and implementing zero-knowledge proofs (ZKPs) technology to achieve privacy protection, significantly enhancing existing blockchain encryption methods.

[0091] 15. If third-party services, such as model training, are required, the third-party service provider and the data user will sign an electronic contract through the platform. The third-party service provider will obtain business data, and the platform will store, identify, and upload the data usage log to the blockchain.

[0092] For example, to detect defects on the surface of products in manufacturing scenarios, convolutional neural networks (CNN) can be used for image classification and defect detection. The surface images of industrial accessories are acquired in real time, and the data is uploaded in real time. Third-party service agencies can obtain images in real time through the platform, and the processed images and defect detection results are returned to the data provider in real time.

[0093] For example, in the scenario of load forecasting in the energy industry, regression models or time series models can be used. The energy data collection level is regular collection, and the data is uploaded regularly. Third-party service agencies can regularly obtain images through the platform and use models such as the Autoregressive Integrated Moving Average Model (ARIMA) and Long Short Term Memory (LSTM) to predict power load demand. The processed prediction results are regularly returned to the data provider for power scheduling and optimization.

[0094] For example, in logistics and supply chain management scenarios, by monitoring order, inventory, and transportation data, data collection will be triggered when the order volume changes, inventory falls below a certain level, or the transportation route needs to be optimized. Data collection is divided into event-triggered collection levels. At this time, machine learning algorithms can be used to optimize logistics routes and transportation plans to reduce costs, improve efficiency, and shorten transportation time.

[0095] 16. The third-party service agency will output the processed data to the data user.

[0096] In this embodiment, it is disclosed that when a data usage request initiated by a data user is received, a business data demand order is sent to the data provider. After the data provider and the data user sign an electronic contract, the target business data is obtained according to the data identifier. The data identifier is obtained by an active identification carrier identifying the business data uploaded by the terminal industrial equipment corresponding to the data provider. The active identification carrier is set on the terminal industrial equipment, and the target business data is sent to the data user. After the data user obtains the target business data, the usage log of the target business data is stored on the blockchain. This embodiment uses identification technology and blockchain technology to ensure data security. Data access and use can be logged and traced, which solves the company's concerns about data abuse during data transactions, so that a balance can be achieved between data value release and data security needs, and thus data can be shared authentically, reliably, timely, effectively and securely.

[0097] Reference Figure 5 , Figure 5 This is a flow chart of the second embodiment of the industrial data trusted sharing method of the present invention, based on the above Figure 2 The first embodiment shown here proposes a second embodiment of the industrial data trusted sharing method of the present invention.

[0098] In the second embodiment, before step S10, the method further includes:

[0099] Step S01: upon receiving a registration request initiated by a data provider, register the data provider.

[0100] It should be understood that in order to facilitate subsequent information association and improve the security of trusted sharing of industrial data, in this embodiment, the data provider can also be registered and the corporate identity of the data provider can be applied for from the Industrial Internet Identity Resolution Top-level Node through the Industrial Internet Identity Resolution Second-level Node.

[0101] Of course, in this embodiment, it is also possible to register and apply for corporate identification for data users and third-party service providers, and this embodiment does not impose any restrictions on this.

[0102] Step S02: After the registration is completed, apply for the enterprise identity of the data provider from the Industrial Internet identity resolution top-level node through the Industrial Internet identity resolution secondary node.

[0103] For easier understanding, refer to Figure 4 This invention is described but not limited thereto. Figure 4 This is an interactive diagram of an embodiment of the industrial data trusted sharing method of the present invention. In the figure, the industrial data trusted sharing method further includes the following steps:

[0104] 1. Data providers, data users, and third-party service providers register and log in to the trusted data sharing platform to become platform users, automatically become enterprise nodes, and subscribe to enterprise node hosting services;

[0105] 2. The trusted data sharing platform obtains enterprise node capabilities through the enterprise node basic function module, realizes docking with the secondary node, and applies to the top node for the enterprise identification code and enterprise certificate authority (CA) of the registered enterprise through the secondary node;

[0106] 3. Enterprises need to upload equipment information and customized production data templates on the trusted data sharing platform. At this time, enterprises can preset the publicly visible and encrypted parts of the production data to achieve standardized identification of production data.

[0107] This embodiment registers the data provider and applies for the data provider's corporate identity from the Industrial Internet Identity Resolution Top-Level Node through the Industrial Internet Identity Resolution Second-Level Node, thereby facilitating subsequent information association and improving the security of trusted sharing of industrial data.

[0108] In the second embodiment, before step S10, the method further includes:

[0109] Step S03: upon receiving the first power-on verification request sent by the terminal industrial device via the active identification carrier, verifying the unique identification of the terminal industrial device.

[0110] It should be understood that in order to ensure the authenticity and legality of the terminal industrial equipment, in this embodiment, when the terminal industrial equipment is powered on for the first time, the unique identifier of the industrial equipment needs to be parsed and identified, and after verification, the active identification carrier, the terminal industrial equipment and the corporate identifier of the data user are associated.

[0111] Step S04: after verification, the active identification carrier, the terminal industrial device and the enterprise identification of the data user are associated, so that after the association is completed, the active identification carrier identifies the business data uploaded by the terminal industrial device through the association relationship.

[0112] For easier understanding, refer to Figure 4 This invention is described but not limited thereto. Figure 4 This is an interactive diagram of an embodiment of the industrial data trusted sharing method of the present invention. In the figure, the industrial data trusted sharing method further includes the following steps:

[0113] 4. The data provider embeds an active identification carrier in the terminal industrial equipment.

[0114] 5. When the device is powered on for the first time, it initiates verification to the identity carrier management module through the active identity carrier SDK.

[0115] The unique identifiers of industrial equipment must be parsed and identified to ensure their authenticity and legitimacy. First, register the device on the platform and upload relevant information, including the device's hardware serial number (UDID, etc.) and manufacturer. The Active Identification Carrier SDK supports authentication and authorization mechanisms using tokens and API keys to ensure that only authorized users can access and use the SDK's features. After the device is powered on, the Active Identification Carrier SDK identifies and compares the device's hardware serial number (IMEI, etc.), manufacturer, and other information to confirm its compliance and validity.

[0116] 6. After verification, the identification carrier management module requests the industrial identification from the enterprise node basic function module, and associates the active identification carrier with the equipment and enterprise (enterprise identification). The active identification carrier obtains the ability to identify business data and report it to the platform.

[0117] In this embodiment, when the terminal industrial equipment is powered on for the first time, the unique identification of the industrial equipment needs to be parsed and identified. After verification, the active identification carrier, the terminal industrial equipment and the corporate identification of the data user are associated to ensure the authenticity and legitimacy of the terminal industrial equipment.

[0118] Furthermore, for industrial scenarios, the number of devices may be huge. For the association between active identification carriers and devices and enterprises, the association relationship can be managed by constructing a knowledge graph structure. The step S04 includes: after verification, determining the entities and relationships of the active identification carrier, the terminal industrial equipment and the data user, and constructing a knowledge graph based on the entities and the relationships; establishing entity relationships in the knowledge graph, and adding attribute relationships in the knowledge graph to associate the active identification carrier, the terminal industrial equipment and the enterprise identification of the data user.

[0119] For easier understanding, refer to Figure 4 This invention is described but not limited thereto. Figure 4This is an interactive diagram of an embodiment of the industrial data trusted sharing method of the present invention. In the figure, the industrial data trusted sharing method further includes the following steps:

[0120] 7. In industrial scenarios, the number of devices may be huge. For the association between active identification carriers and devices and enterprises, the management of the association relationship can be achieved by building a knowledge graph structure:

[0121] (1) Identify entities and relationships: Entities include identification carriers, devices, and enterprises, and relationships include ownership relationships, connection relationships, etc. Based on the identified entities and relationships, use graph modeling tools to create and manage graphs to ensure that the graphs can accurately represent the connections between entities and relationships.

[0122] (2) Establishing entity relationships: Create entity and relationship nodes in the graph. Assign unique identifiers to each entity and relationship and connect them. Create nodes to identify the carrier, device, and enterprise, and connect them using relationship edges.

[0123] (3) Add attribute information: In addition to entities and relationships, add attribute information to them, including the name, description, type, industrial identification, etc. of enterprises, equipment, and identification carriers. These attribute information can help better understand and manage entities and relationships.

[0124] (4) Query and Analysis: By querying the graph, you can obtain information related to identity carriers, devices, and enterprises. You can use graph query languages (such as SPARQL, Cypher, etc.) to write query statements and perform analysis and reasoning as needed.

[0125] (5) Update and maintenance: As identification carriers, equipment, and enterprise information are updated, the map needs to be updated and maintained in a timely manner. Ensure the accuracy and completeness of the map, and perform regular data cleaning and verification.

[0126] In the second embodiment, before step S10, the method further includes:

[0127] Step S05: receiving a data reporting request sent by the terminal industrial device via the active identification carrier.

[0128] It should be understood that in order to improve the security of trusted sharing of industrial data, in this embodiment, the data reporting request sent by the receiving terminal industrial equipment through the active identification carrier will also be verified, signed and authenticated.

[0129] Step S06: Verify the signature of the data reporting request, and after verifying the signature, authenticate the data reporting request.

[0130] Step S07: After the authentication is passed, the business data uploaded by the terminal industrial device through the active identification carrier is received.

[0131] For easier understanding, refer to Figure 4 This invention is described but not limited thereto. Figure 4 This is an interactive diagram of an embodiment of the industrial data trusted sharing method of the present invention. In the figure, the industrial data trusted sharing method further includes the following steps:

[0132] 8. When the terminal device initiates data reporting, the data acquisition and transmission module receives the reporting request and collects the signature, and sends it to the identification carrier management module for authentication.

[0133] 9. After authentication is passed, the data acquisition and transmission module receives the reported business data.

[0134] Furthermore, in order to ensure the rationality of the upload frequency, the step S05 includes: evaluating the sensitivity level of the business data and analyzing the scenario requirements of the industrial scenario; determining the data type of the business data according to the scenario requirements, and obtaining the device type of the terminal industrial equipment; determining the data collection level of the business data according to the sensitivity level, the scenario requirements, the data type and the device type; setting the frequency of uploading business data by the active identification carrier according to the data collection level; and receiving the business data uploaded by the terminal industrial equipment through the active identification carrier at intervals of the frequency.

[0135] For easier understanding, refer to Figure 4 This invention is described but not limited thereto. Figure 4 This is an interactive diagram of an embodiment of the industrial data trusted sharing method of the present invention. In the figure, the industrial data trusted sharing method further includes the following steps:

[0136] 10. Data providers can set the frequency of uploading business data by active identification carriers through the platform, and can remotely add, delete, modify, and query the identification and related information carried by active identification carriers on the platform. The frequency of uploading business data is bound to the level of active identification carriers, and the level division is associated with indicators such as scenarios, data types, and device types. The specific steps are as follows:

[0137] (1) Determine data sensitivity: Evaluate the sensitivity level of the data. Based on the confidentiality, integrity, and availability of the data, the data is classified into different sensitivity levels, such as high, medium, and low.

[0138] Analyze scenario requirements: Determine the purpose and requirements of data collection based on specific industrial scenario needs. Consider factors such as data real-time, accuracy, and comprehensiveness, as well as the need for data processing and analysis.

[0139] (2) Determine the data type: Based on the industrial scenario and requirements, determine the type of data that needs to be collected. The data type may include sensor data, equipment status data, environmental data, etc. For each data type, assess its importance and urgency.

[0140] (3) Consider device type: Consider the type of device used and its data collection capabilities. Different types of devices may have different data collection frequencies and accuracies. Determine the appropriate data collection frequency based on the device characteristics and scenario requirements.

[0141] (4) Data collection levels: Data collection is divided into different levels based on factors such as data sensitivity, scenario requirements, data type, and device type. Data collection is divided into real-time collection, periodic collection, and event-triggered collection levels.

[0142] (5) Determine the upload frequency: Determine the frequency of data upload based on the data collection level and scenario requirements. For the real-time collection level, data can be uploaded in real time; for the periodic collection level, data can be uploaded at predetermined time intervals; for the event-triggered collection level, data can be uploaded when an event occurs.

[0143] (6) Verification and Adjustment: In actual applications, verify the rationality of the data collection level and upload frequency. Make necessary adjustments and optimizations based on actual conditions and feedback.

[0144] Reference Figure 6 , Figure 6 This is a flow chart of the third embodiment of the industrial data trusted sharing method of the present invention, based on the above Figure 2 The first embodiment shown here proposes a third embodiment of the industrial data trusted sharing method of the present invention.

[0145] In the third embodiment, step S30 includes:

[0146] Step S301: Desensitizing the target business data while retaining the original data information of the target business data.

[0147] It should be understood that in order to whiten the data and erase the sensitive content in the data, the original data characteristics, business rules and data relevance are maintained. Development, testing, training and big data services are guaranteed not to be affected by desensitization, and the consistency and validity of the data before and after desensitization are achieved. In this embodiment, the target business data is desensitized while maintaining the original data information of the target business data, and the desensitized target business data is sent to the data user.

[0148] It can be understood that data desensitization includes but is not limited to any one of random replacement, desensitization rules, encryption processing, data masking and data desensitization algorithms, and this embodiment does not limit this.

[0149] Step S302: Send the desensitized target business data to the data user.

[0150] It is understandable that the target business data after data desensitization is sent to the data user so that the data user can carry out development, testing, training and big data business.

[0151] This embodiment desensitizes the target business data while maintaining the original data information of the target business data, and sends the desensitized target business data to the data user, thereby whitening the data and erasing sensitive content in the data while maintaining the original data characteristics, business rules and data relevance, ensuring that development, testing, training and big data businesses will not be affected by desensitization, and achieving data consistency and validity before and after desensitization.

[0152] In addition, refer to Figure 7 The embodiment of the present invention further provides an industrial data trusted sharing device, the industrial data trusted sharing device comprising:

[0153] The order sending module 10 is used to send a business data demand order to the data provider upon receiving a data use request initiated by the data user;

[0154] A data acquisition module 20 is configured to acquire target business data based on a data identifier after the data provider and the data user sign an electronic contract. The data identifier is obtained by identifying the business data uploaded by the terminal industrial device corresponding to the data provider using an active identification carrier, which is provided on the terminal industrial device.

[0155] A data sending module 30 is used to send the target business data to the data user;

[0156] The log evidence module 40 is used to store the usage log of the target business data in the blockchain after the data user obtains the target business data.

[0157] In this embodiment, it is disclosed that when a data usage request initiated by a data user is received, a business data demand order is sent to the data provider. After the data provider and the data user sign an electronic contract, the target business data is obtained according to the data identifier. The data identifier is obtained by an active identification carrier identifying the business data uploaded by the terminal industrial equipment corresponding to the data provider. The active identification carrier is set on the terminal industrial equipment, and the target business data is sent to the data user. After the data user obtains the target business data, the usage log of the target business data is stored on the blockchain. This embodiment uses identification technology and blockchain technology to ensure data security. Data access and use can be logged and traced, which solves the company's concerns about data abuse during data transactions, so that a balance can be achieved between data value release and data security needs, and thus data can be shared authentically, reliably, timely, effectively and securely.

[0158] In one embodiment, the data sending module 30 is further used to desensitize the target business data while maintaining the original data information of the target business data; and send the desensitized target business data to the data user.

[0159] In one embodiment, the industrial data trusted sharing device further includes:

[0160] The information association module is used to verify the unique identification of the terminal industrial device when receiving the first power-on verification request sent by the terminal industrial device through the active identification carrier; after the verification is passed, the active identification carrier, the terminal industrial device and the corporate identification of the data user are associated so that after the association is completed, the active identification carrier can identify the business data uploaded by the terminal industrial device through the association relationship.

[0161] In one embodiment, the information association module is further used to determine the entities and relationships of the active identification carrier, the terminal industrial equipment and the data user after verification, and construct a knowledge graph based on the entities and the relationships; establish entity relationships in the knowledge graph, and add attribute relationships in the knowledge graph to associate the active identification carrier, the terminal industrial equipment and the corporate identity of the data user.

[0162] In one embodiment, the industrial data trusted sharing device further includes:

[0163] The user registration module is used to register the data provider when receiving a registration request initiated by the data provider; after the registration is completed, apply for the enterprise identity of the data provider from the Industrial Internet Identity Resolution Top-Level Node through the Industrial Internet Identity Resolution Second-Level Node.

[0164] In one embodiment, the industrial data trusted sharing device further includes:

[0165] The data reporting module is used to receive the data reporting request sent by the terminal industrial equipment through the active identification carrier; verify the signature of the data reporting request, and after verifying the signature, authenticate the data reporting request; after the authentication is passed, receive the business data uploaded by the terminal industrial equipment through the active identification carrier.

[0166] In one embodiment, the data reporting module is also used to evaluate the sensitivity level of the business data and analyze the scenario requirements of the industrial scenario; determine the data type of the business data according to the scenario requirements, and obtain the device type of the terminal industrial equipment; determine the data collection level of the business data according to the sensitivity level, the scenario requirements, the data type and the device type; set the frequency of uploading business data by the active identification carrier according to the data collection level; and receive the business data uploaded by the terminal industrial equipment through the active identification carrier at intervals of the frequency.

[0167] Other embodiments or specific implementations of the industrial data trusted sharing device of the present invention can refer to the above-mentioned method embodiments and will not be repeated here.

[0168] In addition, an embodiment of the present invention further proposes a storage medium, on which an industrial data trusted sharing program is stored. When the industrial data trusted sharing program is executed by a processor, the industrial data trusted sharing method described above is implemented.

[0169] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or system. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or system comprising the element.

[0170] The serial numbers of the above embodiments of the present invention are for description only and do not represent the advantages or disadvantages of the embodiments.

[0171] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, or of course by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory image (ROM) / random access memory (RAM), a magnetic disk, or an optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in each embodiment of the present invention.

[0172] The above are only preferred embodiments of the present invention and are not intended to limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made using the contents of the present invention description and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present invention.

Claims

1. A trusted sharing method for industrial data, characterized in that: The industrial data trusted sharing method includes: Upon receiving a data usage request from a data user, the service provider sends a business data demand order to the data provider; After the data provider and the data user sign an electronic contract, the target business data is obtained based on the data identifier, which is obtained by identifying the business data uploaded by the terminal industrial device corresponding to the data provider using an active identification carrier, and the active identification carrier is set on the terminal industrial device; If third-party services are required, after the third-party service agency signs an electronic contract with the data user, the target business data will be sent to the third-party service provider, and the usage log of the target business data will be stored on the blockchain. The third-party service agency will then send the processed target business data to the data user. After the data user obtains the target business data, the usage log of the target business data is stored on the blockchain, where the usage log is used to store the usage of the data.

2. The industrial data trusted sharing method according to claim 1, characterized in that: Sending the target business data to the data user includes: Desensitizing the target business data while preserving the original data information of the target business data; The desensitized target business data is sent to the data user.

3. The industrial data trusted sharing method according to claim 1, characterized in that: Upon receiving a data use request initiated by a data user, before sending a business data demand order to a data provider, the method further includes: Upon receiving a first power-on verification request sent by the terminal industrial device via the active identification carrier, verifying the unique identification of the terminal industrial device; After verification, the active identification carrier, the terminal industrial device and the enterprise identification of the data user are associated so that after the association is completed, the active identification carrier identifies the business data uploaded by the terminal industrial device through the association relationship.

4. The industrial data trusted sharing method according to claim 3, characterized in that: After the verification is passed, associating the active identification carrier, the terminal industrial device, and the enterprise identification of the data user includes: After verification, the entities and relationships of the active identification carrier, the terminal industrial equipment, and the data user are determined, and a knowledge graph is constructed based on the entities and the relationships; An entity relationship is established in the knowledge graph, and an attribute relationship is added in the knowledge graph to associate the active identification carrier, the terminal industrial equipment, and the corporate identity of the data user.

5. The industrial data trusted sharing method according to claim 3, characterized in that: The method further includes: before verifying the unique identification of the terminal industrial device upon receiving the first power-on verification request sent by the terminal industrial device via the active identification carrier, Upon receiving a registration request initiated by a data provider, registering the data provider; After registration is completed, the enterprise identity of the data provider is applied for from the Industrial Internet Identity Resolution Top-Level Node through the Industrial Internet Identity Resolution Second-Level Node.

6. The industrial data trusted sharing method according to any one of claims 1 to 5, characterized in that: Upon receiving a data use request initiated by a data user, before sending a business data demand order to a data provider, the method further includes: receiving a data reporting request sent by the terminal industrial device via the active identification carrier; Verifying the signature of the data reporting request, and after verifying the signature, authenticating the data reporting request; After the authentication is passed, the business data uploaded by the terminal industrial equipment through the active identification carrier is received.

7. The industrial data trusted sharing method according to claim 6, characterized in that: The receiving the data reporting request sent by the terminal industrial device through the active identification carrier includes: Assess the sensitivity level of the business data and analyze the scenario requirements of industrial scenarios; Determine the data type of the business data according to the scenario requirements, and obtain the device type of the terminal industrial device; Determining a data collection level for the business data based on the sensitivity level, the scenario requirements, the data type, and the device type; Setting the frequency of uploading business data by the active identification carrier according to the data collection level; The business data uploaded by the terminal industrial equipment through the active identification carrier is received at the interval of the frequency.

8. An industrial data trusted sharing device, characterized in that: The industrial data trusted sharing device includes: The order sending module is used to send a business data demand order to the data provider upon receiving a data use request initiated by the data user; A data acquisition module is configured to acquire target business data based on a data identifier after the data provider and the data user sign an electronic contract. The data identifier is obtained by identifying the business data uploaded by the terminal industrial device corresponding to the data provider using an active identification carrier, which is provided on the terminal industrial device. The data sending module is used to send the target business data to the third-party service provider if third-party services are required, after the third-party service agency signs an electronic contract with the data user, and to store the target business data usage log on the blockchain. The third-party service agency will send the processed target business data to the data user; The log evidence module is used to store the usage log of the target business data on the blockchain after the data user obtains the target business data, wherein the usage log is used to store the usage of the data.

9. An industrial data trusted sharing device, characterized in that: The industrial data trusted sharing device includes: a memory, a processor, and an industrial data trusted sharing program stored in the memory and executable on the processor. When the industrial data trusted sharing program is executed by the processor, the industrial data trusted sharing method according to any one of claims 1 to 7 is implemented.

10. A storage medium, characterized in that: An industrial data trusted sharing program is stored on the storage medium, and when the industrial data trusted sharing program is executed by the processor, the industrial data trusted sharing method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Product tracing method and system based on industrial internet identification analysis technology

    CN114493627A

  • Block chain-based big data analysis method, device and system and medium

    CN115033367A

  • Block chain-based asset checking method, system and device, equipment and medium

    CN115309830A

  • Data sharing method and device based on block chain, equipment and storage medium

    CN116860866A