A data acquisition method, device and electronic equipment
By introducing management orchestration and network management modules into the digital twin network, and combining and orchestrating target security schemes based on data characteristic information, the problem of data leakage in the digital twin network is solved, and the secure and unified collection and management of different types of physical network data is realized.
Patent Information
- Application Number
- CN202310825513.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-06
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2043-07-06
AI Technical Summary
Existing digital twin networks pose a security risk of data leakage when collecting different types of physical network data, and cannot achieve unified management and security assurance for different types of data.
By working together with the management orchestration module and the network management module, a target security scheme matching the data collection request is orchestrated based on data characteristic information, and an adaptive and dynamic security collection scheme is configured to achieve unified collection and management of physical network data.
It maximizes the security of physical network data collection, meets the security collection needs of different types of data, and avoids data leakage.
Smart Images

Figure CN119276522B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of the combination of security technology, core network technology and digital twin network technology, and particularly relates to a data collection method and device and electronic equipment. BACKGROUND
[0002] A digital twin network is a network system that creates a virtual twin of a physical network in a digital manner and can interact with the physical network in real time. In order to realize real-time interaction mapping between the physical network and the digital twin network, the digital twin network requires accurate, real-time and secure collection of physical network data.
[0003] The existing digital twin network usually collects physical network data by directly transmitting the data to be collected by the physical network to the mapped digital twin network. However, due to the dispersion of nodes in the physical network, it is difficult to manage the physical network data uniformly, which may cause data leakage when collecting physical network data. At the same time, the existing digital twin network uses a unified security scheme to collect physical network data. However, the digital twin network needs to collect many types of physical network data, such as user data, network device data, network performance data, network traffic data, etc. Different types of physical network data have different data collection security requirements during the collection process. If a unified security scheme is used for physical network data collection, some confidential data may be leaked, which poses a security risk. SUMMARY
[0004] The present application provides a data collection method, device and electronic equipment, which can solve the problem of data leakage and security risk when the existing digital twin network collects different types of physical network data.
[0005] In a first aspect, the present application provides a data collection method, which is applied to a digital twin network including a management and arrangement module, and the method comprises:
[0006] The management and arrangement module sends a data collection request to a communication core network, wherein the data collection request is used to request to collect target physical network data;
[0007] The management and arrangement module receives a data feature information combination fed back by the communication core network, and arranges a target security scheme matched with the data collection request according to the data feature information combination, wherein the data feature information combination is obtained by the communication core network based on the data collection request, the request identification information is obtained by analyzing the data collection request, and the request identification information is obtained by converting the request identification information;
[0008] The management and arrangement module sends the target security scheme to the communication core network, so that the communication core network performs a collection operation of the target physical network data based on the target security scheme.
[0009] Through the above method, the management and arrangement module of the digital twin network combines and arranges a target security scheme matched with the data collection request according to data characteristic information, so that an adaptive and dynamic security collection scheme can be configured for different types of physical network data, the diversity of security collection schemes is met, and the security of physical network data collection is maximized.
[0010] In a possible design, the combining and arranging of the target security scheme matched with the data collection request according to the data characteristic information includes:
[0011] The management and arrangement module verifies the data characteristic information combination.
[0012] When the management and arrangement module verifies that the data characteristic information combination is not abnormal, the management and arrangement module combines and arranges the target security scheme according to the data characteristic information combination.
[0013] In a possible design, the combining and arranging of the target security scheme according to the data characteristic information combination includes:
[0014] The management and arrangement module calculates a security level to which the data characteristic information combination belongs.
[0015] The management and arrangement module combines and arranges the target security scheme according to the security level to which the data characteristic information combination belongs.
[0016] Through the above method, the management and arrangement module of the digital twin network combines and arranges a target security scheme according to data characteristic information, so that an adaptive and dynamic security scheme can be configured for different types of physical network data.
[0017] In a possible design, the digital twin network includes a digital twin body.
[0018] After the sending of the target security scheme to the communication core network, the method further includes:
[0019] The management and arrangement module receives the target physical network data transmitted by the communication core network, and sends the target physical network data to the digital twin body.
[0020] Through the above method, the target physical network data is stored in the digital twin body of the digital twin network, and real-time interaction and mapping of data between the physical network and the digital twin network is realized.
[0021] Secondly, this application also provides a data acquisition method, which is applied to a communication core network, the communication core network including a network management module, the method comprising:
[0022] The network management module parses the data collection request from the digital twin network to obtain request identification information, wherein the data collection request is used to request the collection of target physical network data;
[0023] The network management module converts the request identification information to obtain a combination of data feature information, and feeds back the combination of data feature information to the digital twin network. The combination of data feature information is used to assist the digital twin network in developing a target security scheme that matches the data collection request.
[0024] The network management module receives the target security scheme sent by the digital twin network and performs the collection operation of the target physical network data based on the target security scheme.
[0025] By using the above methods, the network management module based on the core communication network can uniformly collect and manage physical network data, thus ensuring the security of physical network data collection.
[0026] In one possible design, the transformation of the request identification information to obtain a combination of data feature information includes:
[0027] The network management module determines the data feature information corresponding to the request identification information;
[0028] The network management module assigns values to the data feature information to form the data feature information combination.
[0029] Using the above method, the network management module based on the core communication network uniformly collects and manages physical network data, converts the parsed request identification information to obtain the corresponding data feature information combination, and then the management and orchestration module of the digital twin network orchestrates the target security scheme that matches the data collection request based on the data feature information combination. It can configure adaptive and dynamic security schemes for different types of physical network data.
[0030] In one possible design, the data characteristic information includes at least one of the following: data type, data distribution, data real-time performance, data acquisition frequency, data confidentiality, data privacy level, data volume, and twin business graph.
[0031] By using the methods described above to obtain data feature information from multiple dimensions, we can better meet the security collection needs of different types of physical network data.
[0032] In one possible design, the operation of collecting the target physical network data based on the target security scheme includes:
[0033] The network management module parses the target security scheme to obtain M target security acquisition countermeasures and N target security transmission countermeasures, where M and N are integers greater than 0;
[0034] The network management module collects target physical network data from the physical network based on the M target security collection countermeasures;
[0035] When the network management module collects the target physical network data, it transmits the target physical network data to the digital twin network based on the N target security transmission countermeasures.
[0036] By using the methods described above, the target physical network data can be collected securely by performing the target physical network data collection operation based on the target security scheme.
[0037] Thirdly, this application provides a data acquisition device, which includes a management and orchestration module, a transmission module, and an orchestration module;
[0038] The management orchestration module is used to instruct the sending module to send a data acquisition request to the communication core network, and when instructing the orchestration module to receive the combination of data feature information fed back by the communication core network, and to orchestrate a target security scheme that matches the data acquisition request based on the combination of data feature information, the sending module is instructed to send the target security scheme to the communication core network.
[0039] The sending module is configured to send the data acquisition request and the target security scheme to the communication core network according to the instructions of the management and orchestration module, so that the communication core network performs the acquisition operation of target physical network data based on the target security scheme, wherein the data acquisition request is used to request the acquisition of the target physical network data;
[0040] The orchestration module is used to receive a combination of data feature information fed back by the communication core network according to the instructions of the management orchestration module, and to orchestrate a target security scheme that matches the data acquisition request based on the combination of data feature information. The combination of data feature information is obtained by the communication core network parsing the data acquisition request to obtain request identification information and then converting the request identification information.
[0041] In one possible design, the orchestration module is specifically used for:
[0042] When the management and orchestration module verifies that there are no anomalies in the combination of data feature information, the target security scheme is orchestrated according to the instructions of the management and orchestration module based on the combination of data feature information.
[0043] In one possible design, the orchestration module is further used for:
[0044] According to the instructions of the management and orchestration module, calculate the security level to which the data feature information combination belongs;
[0045] Following the instructions of the management and orchestration module, the target security scheme is orchestrated based on the security level to which the data feature information combination belongs.
[0046] In one possible design, the device also includes a digital twin:
[0047] A digital twin is used to receive the target physical network data sent by the management and orchestration module when the management and orchestration module receives the target physical network data transmitted by the communication core network.
[0048] Fourthly, this application also provides a data acquisition device, which includes a network management module, a conversion module, and an execution module;
[0049] The network management module is configured to instruct the conversion module to parse the data acquisition request from the digital twin network to obtain request identification information, and to instruct the conversion module to convert the request identification information to obtain a combination of data feature information, and to feed back the combination of data feature information to the digital twin network, wherein the combination of data feature information is used to assist the digital twin network in developing a target security scheme that matches the data acquisition request; and to instruct the execution module to receive the target security scheme sent by the digital twin network, and to perform the acquisition operation of the target physical network data based on the target security scheme;
[0050] The conversion module is used to parse the data collection request from the digital twin network according to the instructions of the network management module, obtain request identification information, convert the request identification information to obtain a combination of data feature information, and feed the combination of data feature information back to the digital twin network, wherein the data collection request is used to request the collection of data from the target physical network.
[0051] The execution module is configured to receive the target security scheme sent by the digital twin network according to the instructions of the network management module, and perform the collection operation of the target physical network data based on the target security scheme.
[0052] In one possible design, the conversion module is specifically used for:
[0053] According to the instructions of the network management module, determine the data feature information corresponding to the request identification information;
[0054] As instructed by the network management module, the data feature information is assigned values to form the data feature information combination.
[0055] In one possible design, the data characteristic information includes at least one of the following: data type, data distribution, data real-time performance, data acquisition frequency, data confidentiality, data privacy level, data volume, and twin business graph.
[0056] In one possible design, the execution module is specifically used for:
[0057] According to the instructions of the network management module, the target security scheme is parsed to obtain M target security acquisition countermeasures and N target security transmission countermeasures, where M and N are integers greater than 0;
[0058] As instructed by the network management module, target physical network data is collected from the physical network based on the M target security collection countermeasures;
[0059] As instructed by the network management module, when the target physical network data is collected, the target physical network data is transmitted to the digital twin network based on the N target security transmission countermeasures.
[0060] Fifthly, this application provides a data acquisition system, which includes a digital twin network and a communication core network;
[0061] The digital twin network is used to perform the data acquisition method steps described in the first aspect above;
[0062] The communication core network is used to execute the data acquisition method steps described in the second aspect above.
[0063] Sixthly, this application provides an electronic device, comprising:
[0064] Memory, used to store computer programs;
[0065] When the processor executes the computer program stored in the memory, it implements the data acquisition method steps of the first or second aspect described above.
[0066] In a seventh aspect, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the data acquisition method steps described in the first or second aspect.
[0067] Based on the above data acquisition methods, physical network data can be uniformly collected and managed through the network management module. Adaptive and dynamic security schemes can be configured for different types of physical network data, which can meet the diverse needs of security schemes and maximize the security of physical network data collection. Attached Figure Description
[0068] Figure 1 This is a schematic diagram illustrating the applicable scenarios for the embodiments of this application;
[0069] Figure 2 A flowchart illustrating a data acquisition method for a communication core network provided in this application embodiment;
[0070] Figure 3 A flowchart illustrating a data acquisition method for a digital twin network provided in this application embodiment;
[0071] Figure 4 This application provides a schematic diagram of signaling interaction for data acquisition in an embodiment.
[0072] Figure 5 A schematic diagram of the structure of a data acquisition device corresponding to a digital twin network provided in this application embodiment;
[0073] Figure 6 A schematic diagram of the structure of a data acquisition device corresponding to another digital twin network provided in an embodiment of this application;
[0074] Figure 7 This application provides a schematic diagram of the structure of a data acquisition device corresponding to a core communication network.
[0075] Figure 8 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. Detailed Implementation
[0076] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operational methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "multiple" is understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing together, or B existing alone. A connected to B can represent: A and B directly connected, or A and B connected through C. Furthermore, in the description of this application, terms such as "first" and "second" are used only for distinguishing the purpose of description and should not be construed as indicating or implying relative importance or order.
[0077] To facilitate understanding by those skilled in the art, the technical terms involved in the embodiments of this application will first be explained.
[0078] (1) Virtual Private Network (VPN) is a remote access technology that mainly establishes a private network on a physical network for encrypted communication.
[0079] The following is a brief introduction to the application scenarios to which the technical solutions of the embodiments of this application are applicable. It should be noted that the application scenarios described below are only for illustrating the embodiments of this application and are not intended to limit the scope. In specific implementation, the technical solutions provided by the embodiments of this application can be flexibly applied according to actual needs.
[0080] Figure 1 This is a schematic diagram illustrating an application scenario applicable to the embodiments of this application. The scenario mainly includes a communication core network 101, a digital twin network 102, and a physical network 103, wherein the digital twin network 102 and the physical network 103 are connected through the communication core network 101.
[0081] For example, the communication core network 101 can be an International Mobile Telecommunications (IMT)-2020 network, i.e., a 5G network, or an Internet of Things (IoT) network; no limitation is made here. The communication core network 101 includes a network management module, used to convert request identification information to obtain a combination of data feature information, and feed this combination of data feature information back to the digital twin network 102. The request identification information is obtained by the network management module parsing the data collection request from the digital twin network 102. Simultaneously, according to the target security scheme sent by the digital twin network 102, the target physical network data collection operation is performed. The target physical network data can be any type of physical network data, such as user data, network device data, network performance data, and network traffic data.
[0082] For example, the digital twin network 102 includes a management orchestration module 102a and a digital twin 102b. The management orchestration module 102a is used to orchestrate a target security scheme that matches the data acquisition request based on the combination of data feature information sent by the communication core network 101, and send the target security scheme to the communication core network 101; the digital twin 102b is used to store the acquired target physical network data.
[0083] For example, physical network 103 is used to upload target physical network data to the network management module of communication core network 101.
[0084] Based on the above application scenarios, this application provides a data acquisition method that uses a network management module to uniformly collect and manage physical network data. It also configures adaptive and dynamic security schemes for different types of physical network data, meeting the diverse needs of security schemes and maximizing the security of physical network data acquisition. The methods and apparatus described in this application are based on the same technical concept. Since the principles by which the methods and apparatus solve the problems are similar, embodiments of the apparatus and methods can be referred to interchangeably, and repeated details will not be elaborated further.
[0085] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, the method may include more or fewer operation steps based on conventional or non-inventive methods. In steps where there is no logically necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application. In actual processing or when the device executes the method, it may be executed in the order shown in the embodiments or drawings, or in combination.
[0086] Example 1:
[0087] Figure 2 This application provides a flowchart of a data acquisition method for a digital twin network, which can be executed by a data acquisition device corresponding to the digital twin network. This device can be implemented in software, hardware, or a combination of both to ensure normal system operation. Figure 2 As shown, the process includes the following steps:
[0088] S21, the management and orchestration module sends a data acquisition request to the communication core network;
[0089] In this embodiment of the application, in order to achieve such Figure 1 The digital twin network 102 shown collects physical network data. The digital twin network 102 first needs to send a data collection request to the communication core network 101. The data collection request is used to request the collection of target physical network data.
[0090] S22, the management and orchestration module receives the combination of data feature information fed back from the core communication network, and orchestrates the target security scheme that matches the data acquisition request based on the combination of data feature information.
[0091] Optional, such as Figure 1After receiving a data acquisition request, the network management module of the communication core network 101 shown parses the data acquisition request to obtain request identification information, and then converts the request identification information to obtain a combination of data feature information X. D Then, combine the data feature information X D Feedback is sent to the management and orchestration module 102a of the digital twin network 102.
[0092] Furthermore, the management and orchestration module 102a combines X based on the data feature information. D Compile a target security scheme S that matches the data acquisition request. D (t). Specifically, the management orchestration module 102a receives X from the communication core network 101. D When, verify X D For example, verifying X D Check if the non-zero bits in X are zero; if so, then verify X. D If an anomaly is detected, the data acquisition request is resent to the communication core network 101; otherwise, X is verified. D There is no anomaly, therefore, according to X D Compile a target security scheme that matches the aforementioned data collection request.
[0093] Optionally, the target security scheme S D The arrangement method for (t) can be: combining the above data feature information X D Input the network model and calculate X D The security level to which it belongs, and then based on X D The security scheme for this target is determined by its corresponding security level. in, For target secure data acquisition solutions, A secure transmission scheme for the target. and For safety measures m i The set of m i ∈M={m1, m2, ..., m j Let M be the set of all security measures. D (t) The specific calculation formula can be:
[0094] S D (t)=f(X D ,t) (1)
[0095] In formula (1), f represents the arrangement of the target security scheme, which can be implemented using machine learning network models or neural network models, without specific limitations here. t indicates that the target security scheme will be updated over time or in different stages.
[0096] S23, the management and orchestration module sends the target security scheme to the communication core network.
[0097] Optionally, the management orchestration module 102a sends the orchestrated target security scheme to the communication core network 101, so that the communication core network 101 performs the target physical network data acquisition operation according to the target security scheme and transmits the target physical network data to the management orchestration module 102a.
[0098] Furthermore, the management orchestration module 102a receives the target physical network data transmitted by the communication core network 101 and sends the target physical network data to the digital twin 102b.
[0099] Through the above data acquisition methods, the management and orchestration module of the digital twin network combines and orchestrates target security schemes that match the data acquisition requests based on data feature information. This allows for the configuration of adaptive and dynamic security schemes for different types of physical network data, meeting the diverse needs of security schemes and maximizing the security of physical network data acquisition.
[0100] Example 2:
[0101] Figure 3 This application provides a flowchart of a data acquisition method for a communication core network. This process can be executed by a data acquisition device corresponding to the communication core network. This device can be implemented in software, hardware, or a combination of both, to ensure the normal operation of the system. Figure 3 As shown, the process includes the following steps:
[0102] S31, the network management module parses the data collection request from the digital twin network to obtain the request identification information;
[0103] In this embodiment of the application, to ensure the security of physical network data collection, it is possible to use methods such as Figure 1 The network management module of the communication core network 101 shown performs unified collection and management of physical network data.
[0104] Optionally, a data acquisition request is used to request the acquisition of target physical network data.
[0105] S32, the network management module converts the request identification information to obtain a combination of data feature information, and feeds the combination of data feature information back to the digital twin network;
[0106] Optionally, the conversion process for the request identification information can be:
[0107] The network management module determines the data characteristic information corresponding to the request identifier information. This data characteristic information includes data type, data distribution, data real-time performance, data collection frequency, data confidentiality, data privacy level, data volume, and twin business graph, as shown in Table 1.
[0108]
[0109] Table 1. Data Feature Information Table
[0110] Furthermore, the network management module assigns values to the data feature information to form a data feature information combination. This data feature information combination is used to assist the digital twin network 102 in arranging a target security scheme that matches the data acquisition request.
[0111] For example, the request identifier information parsed by the network management module is 10001001. According to Table 1, the data characteristic information corresponding to this request identifier information can be determined as data type, data confidentiality, and twinned graph. Further, assigning the data type value to x1, the data confidentiality value to x5, and the twinned graph value to x8, the resulting data characteristic information combination is: X D ={x1, 0, 0, 0, x5, 0, 0, x8}.
[0112] S33, the network management module receives the target security scheme sent by the digital twin network and performs the target physical network data collection operation based on the target security scheme.
[0113] Optionally, the specific steps for collecting target physical network data based on the target security scheme can be:
[0114] First, when the network management module receives the target security scheme sent by the digital twin network 102, it parses the target security scheme to obtain M target security acquisition countermeasures and N target security transmission countermeasures, where M and N are integers greater than 0.
[0115] Then, based on the M target security collection countermeasures, target physical network data is collected from physical network 103. Specifically, the network management module configures the M target security collection countermeasures and distributes them to physical network 103. Physical network 103 deploys and configures the received M target security collection countermeasures, such as deploying and configuring encryption countermeasures, transmission paths, and VPNs for the target physical network data. Furthermore, after completing the deployment and configuration, the target physical network data is uploaded to the network management module.
[0116] Finally, when the network management module collects the target physical network data, it transmits the target physical network data to the digital twin network 102 based on N target security transmission countermeasures.
[0117] Through the above data acquisition method, the network management module based on the core communication network uniformly collects and manages physical network data, realizes the conversion of the parsed request identification information, obtains the corresponding data feature information combination, and then the management and orchestration module of the digital twin network orchestrates the target security scheme matching the data acquisition request according to the data feature information combination. It can configure adaptive and dynamic security schemes for different types of physical network data.
[0118] Based on the above Figure 2 , Figure 3 The data acquisition method shown is Figure 4 An exemplary diagram illustrating signaling interaction for data acquisition is shown, such as... Figure 4 As shown, it includes physical nodes, a network management module, and a digital twin network management and orchestration module. Specifically, the physical nodes can be as follows: Figure 1 The physical network 103 shown contains nodes that contain the target physical network data. Specifically, the network management module can be as follows: Figure 1 The network management module in the communication core network 101 shown, specifically the digital twin network management and orchestration module, can be as follows: Figure 1 The management and orchestration module 102a in the digital twin network 102 shown.
[0119] exist Figure 4 In the process, the digital twin network management and orchestration module first sends a data acquisition request to the network management module. The network management module parses the data acquisition request to obtain the request identification information, and then transforms the request identification information to obtain the data feature information combination X. D Furthermore, X D Feedback is sent to the digital twin network management and orchestration module.
[0120] Furthermore, the digital twin network management and orchestration module, based on the aforementioned X... D Compile a target security scheme that matches the data acquisition request, and send the compiled target security scheme to the network management module.
[0121] Next, the network management module parses the target security scheme to obtain M target security acquisition countermeasures and N target security transmission countermeasures. Then, it configures the M target security acquisition countermeasures and N target security transmission countermeasures, and distributes the M target security acquisition countermeasures to the physical nodes. This allows the physical nodes to complete the deployment and configuration of the target physical network data according to the M target security acquisition countermeasures, and then upload the target physical network data to the network management module.
[0122] Finally, the network management module transmits the target physical network data to the digital twin network management and orchestration module based on N target security transmission countermeasures, thereby sending the target physical network data to the digital twin through the digital twin network management and orchestration module.
[0123] Based on the above data acquisition methods, physical network data can be uniformly collected and managed through the network management module. Adaptive and dynamic security schemes can be configured for different types of physical network data, which can meet the diverse needs of security schemes and maximize the security of physical network data collection.
[0124] Based on the same inventive concept, this application also provides a data acquisition device, such as... Figure 5 The diagram shown is a structural schematic of a data acquisition device corresponding to a digital twin network provided in an embodiment of this application. The device includes a management and orchestration module 51, a transmission module 52, and an orchestration module 53.
[0125] The management orchestration module 51 is used to instruct the sending module 52 to send a data acquisition request to the communication core network, and when instructing the orchestration module 53 to receive the data feature information combination fed back by the communication core network, and to orchestrate a target security scheme that matches the data acquisition request based on the data feature information combination, the sending module instructs the sending module to send the target security scheme to the communication core network.
[0126] The sending module 52 is used to send the data acquisition request and the target security scheme to the communication core network according to the instructions of the management and orchestration module 51, so that the communication core network performs the acquisition operation of target physical network data based on the target security scheme, wherein the data acquisition request is used to request the acquisition of the target physical network data;
[0127] The orchestration module 53 is used to receive the combination of data feature information fed back by the communication core network according to the instructions of the management orchestration module 51, and to orchestrate a target security scheme that matches the data acquisition request based on the combination of data feature information. The combination of data feature information is obtained by the communication core network parsing the data acquisition request to obtain request identification information and converting the request identification information.
[0128] In one possible design, the orchestration module 53 is specifically used for:
[0129] When the management and orchestration module 51 verifies that there is no anomaly in the combination of data feature information, the target security scheme is orchestrated according to the instructions of the management and orchestration module 51 based on the combination of data feature information.
[0130] In one possible design, the orchestration module 53 is further configured to:
[0131] According to the instructions of the management and orchestration module 51, the security level to which the data feature information combination belongs is calculated;
[0132] According to the instructions of the management and orchestration module 51, the target security scheme is orchestrated based on the security level to which the data feature information combination belongs.
[0133] In other embodiments, in addition to the above... Figure 5 In addition to the modules shown, digital twins may be further included, such as Figure 6 As shown, an exemplary schematic diagram of a data acquisition device corresponding to another digital twin network provided in this application embodiment is illustrated. The device includes: a management and orchestration module 51, a transmission module 52, an orchestration module 53, and a digital twin 61.
[0134] The digital twin 61 is used to receive the target physical network data sent by the management and orchestration module 51 when the management and orchestration module 51 receives the target physical network data transmitted by the communication core network.
[0135] Through the aforementioned data acquisition device, the management and orchestration module of the digital twin network combines and orchestrates target security schemes that match the data acquisition requests based on data characteristic information. This allows for the configuration of adaptive and dynamic security schemes for different types of physical network data, meeting the diverse needs of security schemes and maximizing the security of physical network data acquisition.
[0136] This application also provides a data acquisition device, such as... Figure 7 The diagram shown is a structural schematic of a data acquisition device corresponding to a communication core network provided in an embodiment of this application. The device includes a network management module 71, a conversion module 72, and an execution module 73.
[0137] The network management module 71 is used to instruct the conversion module 72 to parse the data acquisition request from the digital twin network to obtain request identification information, and to instruct the conversion module 72 to convert the request identification information to obtain a combination of data feature information, and to feed the combination of data feature information back to the digital twin network, wherein the combination of data feature information is used to assist the digital twin network in arranging a target security scheme that matches the data acquisition request; and to instruct the execution module 73 to receive the target security scheme sent by the digital twin network, and to perform the acquisition operation of the target physical network data based on the target security scheme;
[0138] The conversion module 72 is used to parse the data acquisition request from the digital twin network according to the instructions of the network management module 71, obtain the request identification information, convert the request identification information to obtain the data feature information combination, and feed the data feature information combination back to the digital twin network, wherein the data acquisition request is used to request the acquisition of the target physical network data.
[0139] The execution module 73 is configured to receive the target security scheme sent by the digital twin network according to the instructions of the network management module 71, and perform the collection operation of the target physical network data based on the target security scheme.
[0140] In one possible design, the conversion module 72 is specifically used for:
[0141] According to the instructions of the network management module 71, the data feature information corresponding to the request identification information is determined;
[0142] As instructed by the network management module 71, the data feature information is assigned values to form the data feature information combination.
[0143] In one possible design, the data characteristic information includes at least one of the following: data type, data distribution, data real-time performance, data acquisition frequency, data confidentiality, data privacy level, data volume, and twin business graph.
[0144] In one possible design, the execution module 73 is specifically used for:
[0145] According to the instructions of the network management module 71, the target security scheme is parsed to obtain M target security acquisition countermeasures and N target security transmission countermeasures, wherein M and N are integers greater than 0;
[0146] As instructed by the network management module 71, target physical network data is collected from the physical network based on the M target security collection countermeasures;
[0147] As instructed by the network management module 71, when the target physical network data is collected, the target physical network data is transmitted to the digital twin network based on the N target security transmission countermeasures.
[0148] Through the aforementioned device, the network management module based on the core communication network uniformly collects and manages physical network data, converts the parsed request identification information to obtain the corresponding data feature information combination, and then the management and orchestration module of the digital twin network orchestrates the target security scheme matching the data collection request based on the data feature information combination. It can configure adaptive and dynamic security schemes for different types of physical network data.
[0149] Based on the same inventive concept, this application also provides an electronic device that can realize the functions of the aforementioned data acquisition device, see reference. Figure 8 The electronic device includes:
[0150] At least one processor 81 and a memory 82 connected to the at least one processor 81. In this embodiment, the specific connection medium between the processor 81 and the memory 82 is not limited. Figure 8 The example shown is the connection between processor 81 and memory 82 via bus 80. Bus 80 is... Figure 8 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. Bus 80 can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 8 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, the processor 81 can also be called a controller; there is no restriction on the name.
[0151] In this embodiment, the memory 82 stores instructions executable by at least one processor 81. By executing the instructions stored in the memory 82, the at least one processor 81 can perform the data acquisition method described above. The processor 81 can implement... Figure 5 and / or Figure 6 and / or Figure 7 The functions of each module in the device shown.
[0152] The processor 81 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 82 and calling data stored in memory 82, the processor can perform various functions and process data, thereby monitoring the device as a whole.
[0153] In one possible design, processor 81 may include one or more processing units. Processor 81 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 81. In some embodiments, processor 81 and memory 82 may be implemented on the same chip; in some embodiments, they may also be implemented on separate chips.
[0154] Processor 81 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the data acquisition method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0155] Memory 82, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 82 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 82 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 82 may also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.
[0156] By designing and programming the processor 81, the code corresponding to the data acquisition method described in the foregoing embodiments can be embedded into the chip, enabling the chip to execute the code during operation. Figure 2 and / or Figure 3The steps of the data acquisition method in the illustrated embodiment are as follows. How to design and program the processor 81 is a technique well-known to those skilled in the art and will not be described further here.
[0157] Based on the same inventive concept, embodiments of this application also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform the data acquisition method described above.
[0158] In some possible implementations, various aspects of the data acquisition method provided in this application may also be implemented as a program product, which includes program code that, when the program product is run on a device, causes the control device to perform the steps in the data acquisition method according to the various exemplary embodiments of this application described above.
[0159] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0160] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0161] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0162] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0163] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A data acquisition method, characterized in that, The method is applied to a digital twin network, which includes a management and orchestration module. The method includes: The management orchestration module sends a data acquisition request to the communication core network, wherein the data acquisition request is used to request the acquisition of target physical network data; The management orchestration module receives a combination of data feature information fed back by the communication core network, and orchestrates a target security scheme that matches the data collection request based on the combination of data feature information. The combination of data feature information is obtained by the communication core network parsing the data collection request to obtain request identification information and then converting the request identification information. The management and orchestration module sends the target security scheme to the communication core network, so that the communication core network performs the acquisition operation of the target physical network data based on the target security scheme. The core communication network performs the acquisition operation of the target physical network data based on the target security scheme, including: The target security scheme is analyzed to obtain M target security acquisition countermeasures and N target security transmission countermeasures; After collecting target physical network data from the physical network based on the M target security acquisition countermeasures, the target physical network data is transmitted to the digital twin network based on the N target security transmission countermeasures.
2. The method as described in claim 1, characterized in that, The step of combining and arranging a target security scheme that matches the data collection request based on the data feature information includes: The management and orchestration module verifies the combination of data feature information; When the management and orchestration module verifies that there are no anomalies in the combination of data feature information, it orchestrates the target security scheme based on the combination of data feature information.
3. The method as described in claim 2, characterized in that, The step of combining and assembling the target security scheme based on the data feature information includes: The management orchestration module calculates the security level to which the combination of data feature information belongs; The management orchestration module orchestrates the target security scheme based on the security level associated with the data feature information combination.
4. The method as described in claim 1, characterized in that, The digital twin network includes digital twins; After sending the target security scheme to the communication core network, the method further includes: When the management and orchestration module receives the target physical network data transmitted by the communication core network, the digital twin receives the target physical network data sent by the management and orchestration module.
5. A data acquisition method, characterized in that, The method is applied to a communication core network, which includes a network management module, and the method includes: The network management module parses the data collection request from the digital twin network to obtain request identification information, wherein the data collection request is used to request the collection of target physical network data; The network management module converts the request identification information to obtain a combination of data feature information, and feeds back the combination of data feature information to the digital twin network. The combination of data feature information is used to assist the digital twin network in developing a target security scheme that matches the data collection request. The network management module receives the target security scheme sent by the digital twin network; parses the target security scheme to obtain M target security acquisition countermeasures and N target security transmission countermeasures; after acquiring target physical network data from the physical network based on the M target security acquisition countermeasures, it transmits the target physical network data to the digital twin network based on the N target security transmission countermeasures.
6. The method as described in claim 5, characterized in that, The process of converting the request identifier information to obtain a combination of data feature information includes: The network management module determines the data feature information corresponding to the request identification information; The network management module assigns values to the data feature information to form the data feature information combination.
7. The method as described in claim 6, characterized in that, The data characteristic information includes at least one of the following: data type, data distribution, data real-time performance, data acquisition frequency, data confidentiality, data privacy level, data volume, and twin business graph.
8. The method as described in claim 5, characterized in that, The step of collecting target physical network data based on the target security scheme includes: The network management module parses the target security scheme to obtain M target security acquisition countermeasures and N target security transmission countermeasures, where M and N are integers greater than 0; The network management module collects target physical network data from the physical network based on the M target security collection countermeasures; When the network management module collects the target physical network data, it transmits the target physical network data to the digital twin network based on the N target security transmission countermeasures.
9. A data acquisition device, characterized in that, The device includes a management and orchestration module, a transmission module, and an orchestration module; The management orchestration module is used to instruct the sending module to send a data acquisition request to the communication core network, and when instructing the orchestration module to receive the combination of data feature information fed back by the communication core network, and to orchestrate a target security scheme that matches the data acquisition request based on the combination of data feature information, the sending module is instructed to send the target security scheme to the communication core network. The sending module is configured to send the data acquisition request and the target security scheme to the communication core network according to the instructions of the management and orchestration module, so that the communication core network performs a target physical network data acquisition operation based on the target security scheme. The data acquisition request is used to request the acquisition of the target physical network data. The communication core network's execution of the target physical network data acquisition operation based on the target security scheme includes: parsing the target security scheme to obtain M target security acquisition countermeasures and N target security transmission countermeasures; acquiring the target physical network data from the physical network based on the M target security acquisition countermeasures; and transmitting the target physical network data to the digital twin network based on the N target security transmission countermeasures. The orchestration module is used to receive a combination of data feature information fed back by the communication core network according to the instructions of the management orchestration module, and to orchestrate a target security scheme that matches the data acquisition request based on the combination of data feature information. The combination of data feature information is obtained by the communication core network parsing the data acquisition request to obtain request identification information and then converting the request identification information.
10. A data acquisition device, characterized in that, The device includes a network management module, a parsing module, a conversion module, and an execution module; The network management module is configured to instruct the conversion module to parse the data acquisition request from the digital twin network to obtain request identification information, and to instruct the conversion module to convert the request identification information to obtain a combination of data feature information, and to feed back the combination of data feature information to the digital twin network, wherein the combination of data feature information is used to assist the digital twin network in developing a target security scheme that matches the data acquisition request; and to instruct the execution module to receive the target security scheme sent by the digital twin network, and to perform the acquisition operation of the target physical network data based on the target security scheme; The conversion module is used to parse the data collection request from the digital twin network according to the instructions of the network management module, obtain request identification information, convert the request identification information to obtain a combination of data feature information, and feed the combination of data feature information back to the digital twin network, wherein the data collection request is used to request the collection of data from the target physical network. The execution module is configured to receive the target security scheme sent by the digital twin network according to the instructions of the network management module, parse the target security scheme to obtain M target security acquisition countermeasures and N target security transmission countermeasures; collect target physical network data from the physical network based on the M target security acquisition countermeasures, and transmit the target physical network data to the digital twin network based on the N target security transmission countermeasures.
11. A data acquisition system, characterized in that, The system includes a digital twin network and a core communication network; The digital twin network is used to perform the method as described in any one of claims 1-4; The communication core network is used to perform the method as described in any one of claims 5-8.
12. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, when executing a computer program stored in the memory, implements the method steps of any one of claims 1-4 or 5-8.
13. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method steps of any one of claims 1-4 or 5-8.
Citation Information
Patent Citations
Data acquisition method and digital twin network
CN115473906A
Computing power network system based on digital twinning and computing power processing method
CN115622862A