A Digital Asset Protection Method Based on Digital Twin

By registering digital twin systems and data audit modules in the blockchain network, monitoring and verifying sensor data, identifying and isolating abnormal data, the risk of network attacks of industrial equipment when interconnecting with the outside world is solved, and data security and integrity are achieved.

CN118627133BActive Publication Date: 2025-06-24SHENZHEN TUOPU VIDEO TECH DEV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410827626.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-25
Publication Date
2025-06-24
Estimated Expiration
2044-06-25

AI Technical Summary

Technical Problem

Industrial equipment is vulnerable to cyber attacks when interconnecting with the outside world, resulting in data security threats and limited computing power, making it impossible to deploy powerful security protection solutions.

Method used

Using a digital asset protection method based on digital twins, a digital twin system and data audit module are registered in the blockchain network, a digital twin system is built at the edge layer of the IoT cluster, monitoring and verification of sensor data, identifying abnormal data, and isolating abnormal digital twin system.

Benefits of technology

Effectively prevent malicious nodes from tampering with data, prevent attacks from intermediate nodes, ensure data integrity and security, and avoid the drag on overall network performance by network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118627133B_ABST
    Figure CN118627133B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of digital asset protection, and provides a digital asset protection method based on digital twin. The method includes: registering a digital twin system and a data audit module in a blockchain network; when synchronizing sensor data between the digital twin system and Internet of Things devices, enabling the data audit module to monitor and verify the sensor data to ensure that the sensor data has not been tampered with or intercepted; based on a pre-trained detection model distributed in the edge layer of the Internet of Things cluster, analyzing the timestamp, device ID, data source, and IP address of the destination of the sensor data synchronized to the digital twin system to identify abnormal data; when detecting abnormal data, isolating and restricting the communication between the abnormal digital twin system and other digital twin systems; the present invention can solve the problem that industrial devices are vulnerable to attacks when interconnected with the outside world in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital asset protection, and in particular, to a digital asset protection method based on digital twin. Background Art

[0002] Devices such as industrial equipment and office equipment are important fixed assets of enterprises, and the data stored in industrial equipment and office equipment are important digital assets of enterprises, such as production materials, production records, equipment software, etc. In the era of Internet of Everything in Industry 4.0, the network connection between office equipment and industrial equipment enables office equipment to monitor and analyze various data of industrial equipment in real time, greatly improving production efficiency and quality. However, the accompanying risks are as follows: the heterogeneity of implementing industrial Internet of Things in a single smart factory limits the implementation of a general security protocol for the system-wide network, which is likely to become a springboard for network attacks and pose a threat to data security; the computing power of industrial equipment is limited and it is impossible to deploy a powerful security protection scheme on itself. Once attacked, it will drag down the overall network performance, resulting in failures in device data calculation, data modeling, and operation performance analysis. Summary of the Invention

[0003] In view of the above technical problems, the present invention provides a digital asset protection method based on digital twin to solve the problem that industrial equipment is vulnerable to attacks when interconnected with the outside world in the prior art.

[0004] Other features and advantages of the present invention will become apparent through the following detailed description, or be partially learned through the practice of the present invention.

[0005] According to one aspect of the present invention, a digital asset protection method based on digital twin is disclosed, and the method includes:

[0006] Register a digital twin system and a data audit module in a blockchain network, where the digital twin system is built on the edge layer of each Internet of Things cluster, the Internet of Things cluster includes multiple Internet of Things devices for reading sensor data of each protected device in the cluster, and the data audit module is set on the transmission path of the Internet of Things devices between virtual entities in the digital twin system;

[0007] When synchronizing the sensor data between the digital twin system and the Internet of Things devices, enable the data audit module to monitor and verify the sensor data to ensure that the sensor data has not been tampered with or intercepted;

[0008] Based on a pre-trained detection model distributed on the edge layer of the Internet of Things cluster, analyze the timestamp, device ID, data source, and destination IP address of the sensor data synchronized to the digital twin system to identify abnormal data;

[0009] When the abnormal data is detected, isolate and restrict the communication between the digital twin system with the anomaly and other digital twin systems.

[0010] Furthermore, when registering the digital twin system and the data audit module, it includes:

[0011] Create a unique identifier based on a one-time random number and the first five characters of the hash value generated based on the number of protected devices paired with the digital twin system;

[0012] Encrypt the identifier using the public key, use the encrypted identifier as the transaction content, and create a first transaction on the blockchain network;

[0013] Verify whether the identifier exists in the nodes of the blockchain network. When the identifier exists, the first transaction will not be executed. When it does not exist, use a smart contract to register the new identifier on the blockchain network and create a new block;

[0014] After the identifier is registered, generate a certificate for each digital twin system associated with the data audit module, create a second transaction to register the new certificate, and encrypt it using the private key of the data audit module;

[0015] Encrypt the second transaction using the public key of the digital twin system. After the second transaction is confirmed in the blockchain network, the subsequent corresponding digital twin system uses its private key to obtain the certificate of the second transaction;

[0016] Distribute the certificate of the second transaction to the corresponding digital twin system, and generate a new transaction for each digital twin system using the private key of the data audit module;

[0017] Store the public key of the digital twin system in the blockchain network;

[0018] Use the data audit module to record the IP addresses of the IoT devices in each digital twin system and register them in the blockchain.

[0019] Furthermore, when synchronizing the sensor data between the digital twin system and the IoT device, and the data audit module monitors and verifies the sensor data, the method includes:

[0020] Based on the sensor data, the data audit module generates a configuration file for the digital twin system, and the configuration file at least includes a timestamp, a device ID, and the IP addresses of the data source and the destination;

[0021] Establish a time boundary for data synchronization between the data audit module and the digital twin system, and assign the time boundary to the configuration file;

[0022] When the digital twin system initiates a synchronization request, encrypt its certificate using the private key of the digital twin system, send the encrypted certificate to the blockchain network, and decrypt and verify the certificate in the blockchain network to verify the identity of the digital twin system;

[0023] After the identity verification of the digital twin system is successful, start the smart contract between the digital twin system and the data audit module, encrypt its identifier using the private key of the data audit module, send the encrypted identifier to the blockchain network, and decrypt and verify the identifier in the blockchain network;

[0024] After the identifier verification is successful and the security conditions of the smart contract are established, verify whether the configuration file of the digital twin system matches the configuration file stored in the data audit module.

[0025] Further, when verifying whether the configuration files match, it includes:

[0026] Check whether the information of the configuration file sent by the digital twin system is consistent with the information of the data packet received by the data audit module. When checking, verify whether the timestamp, device ID, and IP address match, and verify whether the configuration file falls within the time boundary, and perform integrity verification on the configuration file. The integrity verification is completed based on the hash value of the data packet or by using the immutable record on the blockchain. After the verification is successful, synchronize the configuration file between the data audit module and the digital twin system, and record the synchronization result on the blockchain network.

[0027] Further, when the configuration file verification is abnormal, store the configuration file in the blockchain network.

[0028] Further, the detection model is a model based on a long short-term memory network. When analyzing, the detection model performs the following operations:

[0029] Detect TCP and UDP data packets and extract unencrypted features;

[0030] Analyze the data packets of abnormal IP addresses;

[0031] Focus on analyzing the data packets of random IP addresses with high traffic;

[0032] Monitor the half-open connections between the protected devices;

[0033] Analyze the maximum, minimum, and average sizes of data packets;

[0034] Monitor the time difference between data packets;

[0035] Identify the behavior of abnormal networks maintaining TCP connections by exchanging PUSH and ACK messages with CnC servers.

[0036] Furthermore, the isolation restricts the communication of the abnormal digital twin system with other digital twin systems, including:

[0037] Record the IP address of the protected device with anomalies and its associated digital twin system in the blockchain network, revoke the certificate of the digital twin system with anomalies, and record the revoked certificate and updated policies in the blockchain network;

[0038] Interact with all digital twin systems through smart contracts, requiring valid certificates to prove their identities;

[0039] Verify the certificates provided by each digital twin system in the blockchain network. If the certificate is invalid, terminate the connection of the digital twin system with the invalid certificate, so that it is isolated.

[0040] The technical solution of the present invention has the following beneficial effects:

[0041] Using blockchain to register digital twin systems as transactions in blocks can prevent malicious nodes from injecting damaged data into the data stream and avoid affecting data integrity; register a data audit module in the blockchain to detect attacks on digital twin systems and detect whether there are data packet losses between IoT devices and virtual twins to prevent intermediate node attacks. Brief Description of the Drawings

[0042] Figure 1 It is a flowchart of a digital asset protection method based on digital twins in the embodiments of this specification;

[0043] Figure 2 It is a computer-readable storage medium storing a digital asset protection system based on digital twins in the embodiments of this specification. Detailed Embodiments

[0044] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present invention. However, those skilled in the art will recognize that the technical solutions of the present invention may be practiced without one or more of the specific details, or may be implemented using other methods, components, systems, steps, etc. In other cases, well-known technical solutions are not shown or described in detail to avoid obscuring the various aspects of the present invention.

[0045] In addition, the accompanying drawings are only schematic illustrations of the present invention. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, or in one or more hardware modules or integrated circuits, or in different networks and / or processor systems and / or microcontroller systems.

[0046] As Figure 1 shown, the embodiments of this specification provide a digital asset protection method based on digital twins. The execution subject of this method can be a terminal device such as a computer or a server. This method may specifically include the following steps S101 to S104:

[0047] In step S101, a digital twin system and a data audit module are registered in the blockchain network. The digital twin system is built on the edge layer of each Internet of Things (IoT) cluster. The IoT cluster includes multiple IoT devices for reading the sensor data of each protected device within the cluster. The data audit module is set on the transmission path between the virtual entities in the digital twin system and the IoT devices.

[0048] Among them, the digital twin system can be a system built based on a five-dimensional architecture. It is built on the edge layer of industrial devices and maps all interconnected industrial devices within a cluster. The Internet of Things devices play a connecting role, and the sensor data represents various states of the industrial devices. The data audit module is a virtual node that registers in the blockchain network and participates in the security protocol together with the digital twin system to prevent man-in-the-middle attacks and other network threats; the data audit module synchronizes data with the digital twin system to ensure that the transmitted data has not been modified, thereby guaranteeing the integrity and security of the data. At the same time, it is responsible for capturing and analyzing the network traffic of the Internet of Things devices, including TCP / UDP data headers, to monitor and analyze network activities, and records the collected data and analysis results in the blockchain network to provide tamper-proof evidence for subsequent network security analysis.

[0049] Specifically, registering the digital twin system and the data audit module in the blockchain network can ensure that only authorized virtual entities can receive data from the Internet of Things devices to prevent unauthorized network access and avoid network attacks. Specifically, the registration process includes steps S1011 - 1017:

[0050] In step S1011, a unique identifier is created based on a one-time random number and the first five characters of the hash value generated based on the number of protected devices paired with the digital twin system.

[0051] In step S1012, the identifier is encrypted using the public key, and the encrypted identifier is used as the transaction content to create a first transaction on the blockchain network.

[0052] Among them, encrypting the identifier using the public key ensures that only the participating party holding the corresponding private key can decrypt and verify the content of the identifier; using the encrypted identifier as the transaction content to create a new transaction on the blockchain network, this transaction will contain the encrypted identifier. In this way, the security of the transaction can be ensured because the identifier has been securely encrypted before being recorded in the blockchain.

[0053] In step S1013, it is verified whether the identifier exists in the nodes of the blockchain network. When the identifier exists, the first transaction will not be executed. When it does not exist, the new identifier is registered on the blockchain network using a smart contract, and a new block is created.

[0054] In step S1014, after the identifier is registered, a certificate is generated for each digital twin system associated with the data audit module, a second transaction is created to register the new certificate, and it is encrypted using the private key of the data audit module.

[0055] Among them, the certificate generated by the digital twin system contains identity information and other relevant data, and the private key of the data audit module is used to encrypt the certificate of the digital twin system. In this way, only the data audit module or an entity that knows the private key of the data audit module can decrypt this certificate. The encrypted certificate is used as the transaction content to create a second transaction, which will be sent to the blockchain network.

[0056] In step S1015, the public key of the digital twin system is used to encrypt the second transaction. After the second transaction is confirmed in the blockchain network, the subsequent corresponding digital twin system uses its private key to obtain the certificate of the second transaction.

[0057] Among them, in the blockchain network, in order to ensure the security of the transaction, it is necessary to encrypt the second transaction with the public key of the digital twin system again. In this way, only the digital twin system holding the corresponding private key can decrypt and access the transaction content. When the second transaction is confirmed on the blockchain, the corresponding digital twin system will use its private key to decrypt the encrypted certificate in the second transaction. Once the certificate is decrypted, the digital twin system can obtain and use this certificate to verify its identity and secure communication with other digital twin systems or network entities.

[0058] In step S1016, the certificate of the second transaction is distributed to the corresponding digital twin system, and a new transaction is generated for each digital twin system using the private key of the data audit module; the public key of the digital twin system is stored in the blockchain network.

[0059] Among them, in this step, each digital twin needs a certificate to prove its identity and allow it to communicate securely with other nodes on the blockchain network. The private key of the data audit module is used to encrypt the certificate of each digital twin system to ensure that only the corresponding digital twin system can decrypt and use the certificate. A new transaction is generated for each digital twin system, and this transaction contains the encrypted certificate. In this way, each digital twin system has its own unique transaction and certificate. To ensure network security, the public key of each DT is stored on the blockchain. The public key can be used to verify the authenticity of transactions or certificates signed with the corresponding private key. By storing the public key on the blockchain, malicious nodes can be prevented from impersonating legitimate digital twin systems. If someone attempts to communicate with a forged public key, other participants on the network can identify whether this node is legitimate by comparing the public key stored on the blockchain.

[0060] In step S1017, the data audit module is used to record the IP addresses of the IoT devices in each digital twin system and register them in the blockchain.

[0061] Among them, the data audit module is responsible for recording the IP addresses of each Internet of Things device. These Internet of Things devices are associated with a specific digital twin system and register this information on the blockchain. By doing so, it can ensure that each digital twin system only contains verified Internet of Things devices, preventing attackers from adding malicious Internet of Things devices they control to the digital twin system, thereby protecting the network from unauthorized access or attacks.

[0062] In step S102, when the sensor data is synchronized between the digital twin system and the Internet of Things device, the data audit module monitors and verifies the sensor data to ensure that the sensor data has not been tampered with or intercepted.

[0063] Among them, once the registration is completed, the data audit module is responsible for ensuring that the packet data of the Internet of Things device can be safely synchronized with the digital twin system. This means that the data audit module will monitor and verify the process of data transmission between the Internet of Things device and the digital twin system to ensure that the data has not been tampered with or intercepted during transmission, thereby ensuring the integrity and security of the data.

[0064] Specifically, when the sensor data is synchronized between the digital twin system and the Internet of Things device and the data audit module monitors and verifies the sensor data, the method includes:

[0065] Based on the sensor data, the data audit module generates a configuration file for the digital twin system. The configuration file at least includes a timestamp, a device ID, IP addresses of the data source and the destination;

[0066] Establish a time boundary for data synchronization between the data audit module and the digital twin system and assign the time boundary to the configuration file;

[0067] When the digital twin system initiates a synchronization request, encrypt its certificate using the private key of the digital twin system, send the encrypted certificate to the blockchain network, and decrypt and verify the certificate in the blockchain network to verify the identity of the digital twin system;

[0068] After the identity verification of the digital twin system is successful, start the smart contract between the digital twin system and the data audit module, encrypt its identifier using the private key of the data audit module, send the encrypted identifier to the blockchain network, and decrypt and verify the identifier in the blockchain network;

[0069] After the identifier verification is successful and the security conditions of the smart contract are established, verify whether the configuration file of the digital twin system matches the configuration file stored in the data audit module.

[0070] Supplementary to this, when verifying whether the configuration file matches, it includes: checking whether the information of the configuration file sent by the digital twin system is consistent with the data packet received by the data audit module, verifying whether the timestamp, the device ID, and the IP address match during the check, verifying whether the configuration file falls within the time boundary, and performing integrity verification on the configuration file. The integrity verification is completed based on the hash value of the data packet or by using the immutable record on the blockchain. After successful verification, the data audit module synchronizes the configuration file with the digital twin system and records the synchronization result on the blockchain network.

[0071] In step S103, based on the pre-trained detection model distributed in the edge layer of the IoT cluster, analyze the timestamp, device ID, data source, and the IP address of the destination of the sensor data synchronized to the digital twin system to identify abnormal data.

[0072] Among them, the timestamp records the exact time when the data packet is captured and is used to analyze the data stream and detect abnormal patterns. The device ID is a unique identifier for the device that generates the data and helps to track and identify the network behavior of a specific device. The IP addresses of the data source and the destination: identify the network locations where the data is sent and received and are used to detect possible malicious communications or sources of attacks. By analyzing the above information, the pre-trained model can identify data patterns that are significantly different from the normal behavior patterns, which may include unusual data packet sizes, frequencies, sources or destinations, and other signs that may indicate a network attack or system failure. Over time, the model will learn from new data and feedback and continuously optimize its detection capabilities to cope with evolving network threats.

[0073] In step S104, when the abnormal data is detected, isolate and restrict the communication of the digital twin system with abnormal data from other digital twin systems.

[0074] In one embodiment, when the configuration file verification is abnormal, store the configuration file in the blockchain network to retain non-tamperable evidence.

[0075] In one embodiment, the detection model is a model based on a long short-term memory network. When analyzing, the detection model performs the following operations:

[0076] Detect TCP and UDP packets, extract unencrypted features; analyze packets of abnormal IP addresses; focus on analyzing packets of random IP addresses with high traffic; monitor half-open connections between the protected devices; analyze the maximum, minimum, and average sizes of packets; monitor the time difference between packets; identify the behavior of abnormal networks maintaining TCP connections by exchanging PUSH and ACK messages with CnC servers.

[0077] Among them, due to the large volume of traffic from IoT devices, the detection model adopts a long short-term memory network, which is a variant of the recurrent neural network and is very suitable for the aggregation of a large number of packet data, and the captured data has a high degree of similarity. The advantage of the long short-term memory network compared with other models is that it retains early sequential input data and manages long-term dependencies. The model composed of input, forget, and output gates collects long-term dependencies and filters data at each gate using the sigmoid function.

[0078] As a supplement, the isolation restricts the abnormal digital twin system from communicating with other digital twin systems, including:

[0079] Record the IP addresses of the abnormal protected devices and their associated digital twin systems in the blockchain network, revoke the certificates of the digital twin systems with anomalies, and record the revoked certificates and updated policies in the blockchain network; interact with all digital twin systems through a smart contract, requiring them to provide valid certificates to prove their identities; verify the certificates provided by each digital twin system in the blockchain network. If the certificate is invalid, terminate the connection of the digital twin system with the invalid certificate, so that it is isolated.

[0080] It can be seen from the above embodiments that the present invention uses the blockchain to register the digital twin system as a transaction in the block, which can prevent malicious nodes from injecting damaged data into the data stream and avoid affecting the integrity of the data; register a data audit module in the blockchain to detect attacks on the digital twin system and detect whether there is packet loss between IoT devices and virtual twins to prevent intermediate node attacks.

[0081] Based on the same idea, the exemplary embodiment of the present invention also provides a computer-readable storage medium, on which a program product capable of implementing the above method of this specification is stored. In some possible implementation manners, various aspects of the present invention can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to cause the terminal device to execute the steps according to various exemplary embodiments of the present invention described in the above "Digital Asset Protection System Based on Digital Twin" part of this specification.

[0082] Reference Figure 2As shown, a program product 200 for implementing the above method according to an exemplary embodiment of the present invention is described. It may be a portable compact disc read-only memory (CD-ROM), include program code, and can run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, a readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system, or device.

[0083] The program product may employ any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, but not be limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the foregoing. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0084] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, system, or device.

[0085] The program code contained on the readable medium may be transmitted by any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination of the foregoing.

[0086] The program code for performing the operations of the present invention can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computing device, partially on the user's device, executed as a stand-alone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).

[0087] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, server, terminal system, or network device, etc.) to execute the method according to the exemplary embodiments of the present invention.

[0088] In addition, the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present invention, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed, for example, synchronously or asynchronously in multiple modules.

[0089] It should be noted that although several modules or units of devices for performing actions are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the exemplary embodiments of the present invention, the features and functions of two or more of the above-described modules or units can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.

[0090] Other embodiments of the present invention will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the invention following the general principles of the invention and including known common general knowledge or conventional technical means in the technical field of the invention not disclosed herein. The specification and embodiments are to be considered as illustrative only, and the true scope and spirit of the invention are pointed out by the claims.

Claims

1. A digital asset protection method based on digital twins, characterized in that: The method comprises: Register a digital twin system and a data audit module in a blockchain network, wherein the digital twin system is constructed at the edge layer of each IoT cluster, wherein the IoT cluster includes a plurality of IoT devices for reading sensor data of each protected device in the cluster, and the data audit module is arranged on a transmission path of the IoT devices between virtual entities in the digital twin system; when registering the digital twin system and the data audit module, it includes: creating a unique identifier based on a one-time random number and the first five characters of a hash value generated based on the number of protected devices paired with the digital twin system; encrypting the identifier using a public key, using the encrypted identifier as transaction content, and creating a first transaction on the blockchain network; verifying whether the identifier exists on a node of the blockchain network, and when the identifier exists, the first transaction will not be executed, and when it does not exist, using a smart The contract can register a new identifier on the blockchain network and create a new block; after the identifier is registered, a certificate is generated for each digital twin system associated with the data audit module, a second transaction is created to register a new certificate, and the second transaction is encrypted using the private key of the data audit module; the second transaction is encrypted using the public key of the digital twin system, and after the second transaction is confirmed in the blockchain network, the corresponding digital twin system subsequently uses its private key to obtain the certificate of the second transaction; the certificate of the second transaction is distributed to the corresponding digital twin system, and a new transaction is generated for each digital twin system using the private key of the data audit module; the public key of the digital twin system is stored in the blockchain network; the IP address of the IoT device in each digital twin system is recorded using the data audit module, and registered in the blockchain; When the sensor data is synchronized between the digital twin system and the IoT device, the data audit module monitors and verifies the sensor data to ensure that the sensor data has not been tampered with or intercepted; Based on the pre-trained detection model distributed at the edge layer of the IoT cluster, the timestamp, device ID, data source and destination IP address of the sensor data synchronized to the digital twin system are analyzed to identify abnormal data; When the abnormal data is detected, the digital twin system that isolates and limits the abnormality communicates with other digital twin systems.

2. According to claim 1, a digital asset protection method based on digital twins is characterized in that: When the sensor data is synchronized between the digital twin system and the IoT device, and the data audit module monitors and verifies the sensor data, the method includes: Based on the sensor data, the data audit module generates a configuration file for the digital twin system, wherein the configuration file includes at least a timestamp, a device ID, and an IP address of a data source and a destination; Establishing a time boundary for data synchronization between the data audit module and the digital twin system, and assigning the time boundary to the configuration file; When the digital twin system initiates a synchronization request, the digital twin system's certificate is encrypted using its private key, the encrypted certificate is sent to the blockchain network, and the certificate is decrypted and verified in the blockchain network to verify the identity of the digital twin system; After the identity authentication of the digital twin system is successful, the smart contract is started between the digital twin system and the data audit module, the identifier thereof is encrypted using the private key of the data audit module, the encrypted identifier is sent to the blockchain network, and the identifier is decrypted and verified in the blockchain network; After the identifier is successfully verified, the security condition of the smart contract is met, and then it is verified whether the configuration file of the digital twin system matches the configuration file stored in the data audit module.

3. A digital asset protection method based on digital twins according to claim 2, characterized in that: When verifying whether the configuration file matches, including: Check whether the configuration file sent by the digital twin system is consistent with the information of the data packet received by the data audit module, verify whether the timestamp, the device ID, and the IP address match during the check, and verify whether the configuration file falls within the time boundary, and perform integrity verification on the configuration file, the integrity verification is based on the hash value of the data packet or is completed using the immutable record on the blockchain. After successful verification, the data audit module synchronizes the configuration file with the digital twin system and records the synchronization result on the blockchain network.

4. A digital asset protection method based on digital twins according to claim 2, characterized in that: When the configuration file is verified abnormally, the configuration file is stored in the blockchain network.

5. A digital asset protection method based on digital twins according to claim 1, characterized in that: The detection model is a model based on a long short-term memory network. During analysis, the detection model performs the following operations: Detect TCP and UDP packets and extract unencrypted features; Analyze data packets of abnormal IP addresses; Focus on analyzing random IP addresses with high traffic; monitoring half-open connections between the protected devices; Analyze the maximum, minimum and average size of packets; Monitor the time difference between packets; Identify abnormal network behavior of maintaining TCP connections by exchanging PUSH and ACK messages with the CnC server.

6. A digital asset protection method based on digital twins according to claim 1, characterized in that: The digital twin system with the isolation restriction exception communicates with other digital twin systems, including: Recording the IP address of the abnormal protected device and the digital twin system associated with it in the blockchain network, revoking the certificate of the abnormal digital twin system, and recording the revoked certificate and updated policy in the blockchain network; Interact with all of the digital twin systems through smart contracts, requiring valid certificates to prove their identity; The certificates provided by each of the digital twin systems are verified in the blockchain network. If the certificate is invalid, the connection of the digital twin system with the invalid certificate is terminated so that it is isolated.

Citation Information

Patent Citations

  • Construction method of energy storage twinborn digital model based on block chain and Internet of Things

    CN116090355A

  • Network security monitoring method and system based on user behavior analysis and digital twinning

    CN117914540A