A data management method and system based on the OPC UA information model
Through the data management method based on the OPC UA information model, asymmetric encryption and blockchain technology are adopted to solve the security, efficiency and reliability problems in industrial automated data management, and the secure transmission, standardized processing and efficient storage of data are realized, thereby improving the reliability and user experience of the system.
Patent Information
- Application Number
- CN202411671889.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-21
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-11-21
AI Technical Summary
In the prior art, industrial automation data management has problems such as poor data transmission security, low processing efficiency and low storage reliability, especially in the process of data transmission, easy to be intercepted or tampered, inconsistent data formats lead to low processing efficiency, and centralized storage is prone to single point failure.
Using the data management method based on the OPC UA information model, by constructing OPC UA information model instances, using asymmetric encryption algorithms and digital identity authentication technology to ensure data security, and using blockchain technology to perform distributed storage and abnormal analysis, realizing standardized conversion and decentralized storage of data.
It improves the security of data transmission and storage, simplifies the data processing process, meets real-time requirements, reduces the risk of single point of failure, has good scalability and user experience, and provides intelligent abnormality analysis support.
Smart Images

Figure CN119628886B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data management, and particularly relates to a data management method and system based on the OPC UA information model. Background Art
[0002] With the development of industrialization and the digital transformation of production, it is necessary to standardize the data collection and access in industrial automation systems to achieve standardized and open data interaction for industrial intelligent manufacturing. The Object Linking and Embedding for Process Control Unified Architecture (OPC UA) information model is an open, cross-platform, and standardized data exchange framework, which is widely used in the field of industrial automation. The OPC UA information model defines how to represent, organize, access, and control the data in industrial automation systems.
[0003] The existing data management technologies have the following defects:
[0004] 1) Poor data transmission security: In the existing industrial automation data management, data is easily intercepted or tampered with during the transmission process, and there is a lack of a strict identity authentication mechanism, which cannot ensure that only authorized users can access and operate the data;
[0005] 2) Low data processing efficiency: The data formats between different physical entities are not unified, resulting in a large amount of conversion work during the data integration and exchange process, reducing the processing efficiency. The processing of real-time data is not fast enough to meet the high requirements for data real-time performance in some application scenarios;
[0006] 3) Low data storage reliability: The traditional centralized storage method is prone to single-point failures. Once the data center has problems, it may lead to data loss or service interruption. The centralized storage system often has problems with insufficient scalability when dealing with large-scale data and is difficult to adapt to the rapid growth of data volume. Summary of the Invention
[0007] In order to solve the problems of poor data transmission security, low data processing efficiency, and low data storage reliability existing in the prior art, the purpose of the present invention is to provide a data management method and system based on the OPC UA information model.
[0008] The technical solution adopted by the present invention is as follows:
[0009] A data management method based on the OPC UA information model includes the following steps:
[0010] Construct a corresponding OPC UA information model based on the historical physical data of a physical entity, and create a corresponding OPC UA information model instance in the address space of the OPC UA server;
[0011] Use a data acquisition device to collect real-time physical data according to the OPC UA information model of the physical entity, and send the real-time physical data to the OPC UA server;
[0012] Write the real-time physical data into the corresponding OPC UA information model instance in the OPC UA server, and extract the real-time OPC UA information data of the OPC UA information model instance;
[0013] Convert the real-time OPC UA information data into a real-time data standard file in a common format for the cloud data center and the OPC UA client, and upload it to the cloud data center;
[0014] Use the cloud data center to perform anomaly analysis on the real-time data standard file to obtain real-time anomaly analysis results, and perform distributed storage on the real-time data standard file and the real-time anomaly analysis results;
[0015] Use a terminal device to perform data query in the OPC UA server and / or the cloud data center through the OPC UA client.
[0016] Furthermore, constructing a corresponding OPC UA information model based on the historical physical data of a physical entity, and creating a corresponding OPC UA information model instance in the address space of the OPC UA server includes the following steps:
[0017] Use a data acquisition device to collect the historical physical data of the physical entity, and set corresponding nodes, node attributes, and node relationships according to the physical parameters and physical parameter relationships in the historical physical data;
[0018] Construct the OPC UA information model of the physical entity according to the nodes, node attributes, and node relationships, extract the model metadata of the OPC UA information model, and send it to the OPC UA server;
[0019] Use the OPC UA server to create a corresponding OPC UA information model instance in the address space according to the model metadata.
[0020] Furthermore, using a data acquisition device to collect real-time physical data according to the OPC UA information model of the physical entity, and sending the real-time physical data to the OPC UA server includes the following steps:
[0021] Using a data acquisition device, according to the nodes, node attributes, and node relationships in the OPC UA information model of a physical entity, collect the real-time node values and real-time node attribute values of each dynamic node;
[0022] Integrate the real-time node values and real-time node attribute values of all dynamic nodes into real-time physical data in the format of the OPC UA information model;
[0023] Based on the OPC UA protocol, send the real-time physical data in OPC UA format to the OPC UA server through an OPC UA client.
[0024] Further, write the real-time physical data into the corresponding OPC UA information model instance in the OPC UA server, and extract the real-time OPC UA information data of the OPC UA information model instance, including the following steps:
[0025] Use an OPC UA client to access the address space of the OPC UA server and locate the target node in the OPC UA information model instance;
[0026] Package the real-time node values and real-time node attribute values of the dynamic nodes corresponding to the target node in the real-time physical data in OPC UA format to obtain the corresponding real-time node package data;
[0027] Use the write service of the OPC UA protocol to write the real-time node package data of the dynamic nodes into the target node of the OPC UA information model instance;
[0028] Traverse the real-time node package data of all dynamic nodes in the real-time physical data until all target nodes in the OPC UA information model instance are written;
[0029] According to the preset subscription service, extract the real-time node package data written by all monitoring nodes in the OPC UA information model instance and integrate them to obtain the real-time OPC UA information data.
[0030] Further, it also includes: Based on a trusted institution, perform key generation and identity registration on the OPC UA server, including the following steps:
[0031] Based on a trusted institution, perform key generation and identity registration on all OPC UA servers to obtain the public-private key pairs and signature information of each OPC UA server;
[0032] Return the private key and signature information in the public-private key pair to the corresponding OPC UA server, and store the public key in the public-private key pair and the cloud key in the controlled database of the cloud data center.
[0033] Further, convert the real-time OPC UA information data into a real-time data standard file in a common format for the cloud data center and the OPC UA client, and upload it to the cloud data center, including the following steps:
[0034] Set the common format for the cloud data center and the OPC UA client to XML format, and convert the real-time OPC UA information data into a real-time data standard file in XML format;
[0035] Encrypt the real-time data standard file according to the private key in the public-private key pair to obtain the encrypted real-time data standard file;
[0036] Sign the encrypted real-time data standard file according to the signature information to obtain the real-time signature data of the encrypted real-time data standard file;
[0037] Upload the encrypted real-time data standard file in XML format and the real-time signature data to the cloud data center.
[0038] Further, perform anomaly analysis on the real-time data standard file to obtain the real-time anomaly analysis result, and perform distributed storage on the real-time data standard file and the real-time anomaly analysis result, including the following steps:
[0039] Based on the cloud data center, call a trusted institution to verify the signature of the real-time signature data. If the signature verification passes, proceed to the next step; otherwise, end the data management;
[0040] Decrypt the encrypted real-time data standard file according to the public key of the OPC UA server stored in the controlled database to obtain the decrypted real-time data standard file;
[0041] Parse the decrypted real-time data standard file and construct a real-time OPC UA information graph corresponding to the real-time OPC UA information data;
[0042] Use a pre-trained anomaly analysis model to perform anomaly analysis on the real-time OPC UA information graph to obtain the real-time anomaly analysis result;
[0043] Use the blockchain network to perform distributed storage on the encrypted real-time data standard file and the real-time anomaly analysis result.
[0044] Further, use the blockchain network to perform distributed storage on the encrypted real-time data standard file and the real-time anomaly analysis result, including the following steps:
[0045] Generate a retrieval label according to the timestamp and physical entity ID corresponding to the encrypted real-time data standard file;
[0046] According to the replica mechanism, the encrypted real-time data standard file is sharded to obtain several data file shards containing replica shards;
[0047] Send several data file shards to several nodes in the blockchain network. Use the nodes to locally store the received data file shards and obtain the corresponding storage addresses;
[0048] Record the storage addresses of each data file shard in the blockchain network, as well as the corresponding retrieval tags and real-time anomaly analysis results in the distributed ledger.
[0049] Further, use the terminal device to query data in the OPC UA server and / or cloud data center through the OPC UA client, including the following steps:
[0050] If real-time data query is performed, use the terminal device to connect to the OPC UA server through the OPC UA client and send the real-time query information to the OPC UA server;
[0051] Based on the OPC UA server, obtain the matching encrypted real-time data standard file according to the real-time query information, and send the XML-formatted matching encrypted real-time data standard file and the public key to the terminal device;
[0052] If historical data query is performed, use the terminal device to connect to the cloud data center through the OPC UA client and send the real-time query information to the cloud data center;
[0053] Based on the cloud data center, retrieve in the distributed ledger according to the real-time query information to obtain the matching retrieval tags;
[0054] Extract several matching data file shards from the blockchain network according to the matching storage addresses corresponding to the matching retrieval tags and restore them to obtain the corresponding matching encrypted historical data standard file;
[0055] Send the XML-formatted matching encrypted historical data standard file and the public key to the terminal device;
[0056] Based on the terminal device, decrypt the matching encrypted real-time data standard file and / or the matching encrypted historical data standard file according to the public key to obtain the matching decrypted real-time data standard file and / or the matching decrypted historical data standard file;
[0057] Parse the matching decrypted real-time data standard file and / or the matching decrypted historical data standard file to obtain the corresponding matching real-time OPC UA information data and / or matching historical OPC UA information data.
[0058] A data management system based on the OPC UA information model for implementing a data management method. The system includes a cloud data center, a trusted institution, a number of OPC UA servers, a number of data collection devices, and a number of terminal devices. The trusted institution is communicatively connected to the number of OPC UA servers respectively. The cloud data center is communicatively connected to the trusted institution, the number of OPC UA servers, and the number of terminal devices respectively. Each OPC UA server is communicatively connected to the number of terminal devices and the number of data collection devices within its communication range.
[0059] The beneficial effects of the present invention are as follows:
[0060] The present invention discloses a data management method and system based on the OPC UA information model, which encrypts the transmitted data files by using an asymmetric encryption algorithm and digital identity authentication technology to ensure the security of the data files during transmission and storage, effectively preventing data file leakage and tampering; utilizes the immutability of blockchain technology to achieve data source verification and data operation auditing, improving the security and transparency of data management; realizes standardized conversion between different data sources by constructing a unified OPC UA information model, simplifies the data processing process, and improves the processing efficiency. Through the data interaction processing process between the data collection device and the OPC UA server, it can quickly respond to the writing and query of real-time data, meeting the real-time requirements; uses a blockchain network for data storage, achieving decentralization, reducing the risk of single-point failure, and improving the overall reliability of the system. Utilizing the distributed characteristics of blockchain, it can easily cope with the rapid growth of data volume and has good scalability; realizes efficient data query by providing real-time retrieval of real-time and historical data, enhancing the user experience; realizes intelligent and automated anomaly analysis of OPC UA information data through the constructed anomaly analysis model, providing valuable data insights and decision-making support.
[0061] Other beneficial effects of the present invention will be further described in the specific implementation manner. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 is a flowchart of the data management method based on the OPC UA information model in the present invention.
[0063] Figure 2 is a structural block diagram of the data management system based on the OPC UA information model in the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0064] The present invention will be further explained below with reference to the drawings and specific embodiments.
[0065] Embodiment 1:
[0066] AsFigure 1 As shown in the figure, this embodiment provides a data management method based on the OPC UA information model, including the following steps:
[0067] S0: Based on a trusted institution, perform key generation and identity registration on the OPC UA server, including the following steps:
[0068] S0-1: Based on a trusted institution, perform key generation and identity registration on all OPC UA servers to obtain the public-private key pairs and signature information of each OPC UA server;
[0069] S0-1-1: Based on a trusted institution, perform key initialization to obtain public parameters, a master key, and an initial key;
[0070] GP = {g, g1, g a , e(g, g) a , H1, H2, H3, H4, H5, H6}
[0071] PK = {g, g1, g a , e(g, g) a , H u}
[0072] MSK = {g a , a}
[0073] In the formula, GP is the public parameter; MSK is the master key; PK is the initial key; a is a random number in the integer domain Z p ; H1, H2, H3, H4, H5, H6, H u are all target hash functions; g, g1, g a are all random numbers of the generators of the cyclic group G; e(g, g) a is the bilinear mapping of the random number g;
[0074] S0-1-2: Collect the attribute information and server ID of the OPC UA server, and use the asymmetric encryption algorithm to generate keys for the OPC UA server based on the attribute information V u , public parameters, master key, and initial key to obtain the corresponding public-private key pairs;
[0075] The formula is:
[0076] SK u = {MSK, V u , K = g a g ab , L u = g b , (K' u = H3(V u )b )}
[0077]
[0078] Wherein, SK u is the private key of the OPC UA server u; b is a random number in the integer domain Z p ; L u , K' u are the second private key parameters of the OPC UA server u; H3 is the target hash function of the public parameter GP; u is the OPC UA server indicator; MSK is the master key; PK is the initial key; PK u is the public key of the OPC UA server u; g b , g a , g ab are random numbers of the generators of the cyclic group G; V u is the attribute information of the OPC UA server u;
[0079] S0-1-3: According to the public and private key pairs and the corresponding server ID, use the digital identity authentication method to perform identity registration to obtain the signature information of the corresponding OPC UA server;
[0080] The formula is:
[0081]
[0082] Wherein, k' is a random number; K u is the registration parameter of the OPC UA server u; KID u is the registration ID of the OPC UA server u; KID u and the corresponding K u constitute the signature information {K u , KID u}; H1 is the target hash function; ID u is the server ID of the OPC UA server u; is the prime order; P is the prime field base point; mod(*) is the remainder function;
[0083] S0-2: Return the private key in the public and private key pairs and the signature information to the corresponding OPC UA server, and store the public key in the public and private key pairs and the cloud key in the controlled database of the cloud data center;
[0084] S1: According to the historical physical data of the physical entity, construct the corresponding OPC UA information model, and create the corresponding OPC UA information model instance in the address space of the OPC UA server, including the following steps:
[0085] S1-1: Use a data acquisition device to collect historical physical data of a physical entity, and set corresponding nodes, node attributes, and node relationships according to the physical parameters and physical parameter relationships in the historical physical data;
[0086] Nodes are building blocks in the OPC UA information model, including but not limited to:
[0087] Object nodes: Represent objects in the real world, such as devices, systems, or processes;
[0088] Variable nodes: Represent data values, such as temperature, pressure, etc.;
[0089] Method nodes: Represent functions or operations that can be called;
[0090] View nodes: Represent a subset of the OPC UA information model and can be used to organize nodes or provide a specific perspective;
[0091] Node attributes are descriptive attributes that each node has, and these attributes define the characteristics of the node, including but not limited to:
[0092] NodeId: The unique identifier;
[0093] NodeClass: The type of the node (such as object, variable, method, etc.);
[0094] BrowseName: The name used for browsing;
[0095] DisplayName: The name used for display;
[0096] Description: The text describing the purpose of the node;
[0097] References: The reference list pointing to other nodes;
[0098] Value: For variable nodes, this attribute contains the current value of the variable;
[0099] DataType: For variable nodes, this attribute defines the type of the value;
[0100] Node relationship references are associations between nodes, and they define the structure and relationship between nodes. References have types and directions; References allow the construction of a hierarchy and define how nodes are related to each other in the address space;
[0101] S1-2: Construct the OPC UA information model of the physical entity based on the nodes, node attributes, and node relationships, extract the model metadata of the OPC UA information model, which defines the structure of the information model, including objects, variables, methods, references, etc., and send it to the OPC UA server;
[0102] S1-3: Use the OPC UA server to create corresponding OPC UA information model instances in the address space according to the model metadata, which involves defining new nodes and their attributes in the server's address space;
[0103] The OPC UA information model instances usually include the following:
[0104] Object instances, such as devices, sensors, etc.;
[0105] Variable instances, such as measured values of temperature, pressure, speed, etc.;
[0106] Method instances, such as control commands or operations;
[0107] Event instances, such as alarms or notifications;
[0108] The current or historical values of variable nodes;
[0109] The timestamps and related information triggered by events;
[0110] The parameters and results of method calls;
[0111] S2: Use the data acquisition device to collect real-time physical data according to the OPC UA information model of the physical entity and send the real-time physical data to the OPC UA server, including the following steps:
[0112] S2-1: Use the data acquisition device to collect the real-time node values and real-time node attribute values of each dynamic node according to the nodes, node attributes, and node relationships in the OPC UA information model of the physical entity;
[0113] The real-time node values include: real-time node process values: This refers to the real-time data directly collected from physical devices or sensors, such as temperature, pressure, flow rate, etc.; real-time node variable values: If the data written is to a variable node, then these data can be called real-time node variable values;
[0114] Real-time node attribute values: Each node in OPC UA has attributes, such as value, quality, timestamp, etc., and the data input into these attributes is called real-time node attribute values;
[0115] S2-2: Integrate the real-time node values and real-time node attribute values of all dynamic nodes into real-time physical data in the OPC UA information model format;
[0116] S2-3: Based on the OPC UA protocol, send the real-time physical data in OPC UA format to the OPC UA server through the OPC UA client;
[0117] S3: Write the real-time physical data into the corresponding OPC UA information model instance in the OPC UA server, and extract the real-time OPC UA information data of the OPC UA information model instance, including the following steps:
[0118] S3-1: Use the OPC UA client to access the address space of the OPC UA server and locate the target node in the OPC UA information model instance;
[0119] S3-2: Package the real-time node value and real-time node attribute value of the dynamic node corresponding to the target node in the real-time physical data in OPC UA format to obtain the corresponding real-time node package data;
[0120] S3-3: Use the write service of the OPC UA protocol to write the real-time node package data of the dynamic node into the target node of the OPC UA information model instance;
[0121] S3-4: Traverse the real-time node package data of all dynamic nodes of the real-time physical data until all target nodes of the OPC UA information model instance are written;
[0122] S3-5: According to the preset subscription service, extract the real-time node package data written by all monitoring nodes in the OPC UA information model instance and integrate them to obtain the real-time OPC UA information data;
[0123] S4: Convert the real-time OPC UA information data into a real-time data standard file in a common format for the cloud data center and the OPC UA client, and upload it to the cloud data center, including the following steps:
[0124] S4-1: Set the common format for the cloud data center and the OPC UA client to XML format, and convert the real-time OPC UA information data into a real-time data standard file in XML format;
[0125] XML is a widely used format with many mature tools and libraries for processing XML data. The OPC UA client can parse the XML file and convert it back to the OPC UA information model for further processing or display;
[0126] S4-2: Encrypt the real-time data standard file according to the private key in the public-private key pair to obtain the encrypted real-time data standard file;
[0127] The formula is:
[0128] M u1 = E(SK u1 , m u1 )
[0129] Wherein, M u1 is the encrypted real-time data standard file; E(*) is the asymmetric encryption function; m u1 is the real-time data standard file; SK u1 is the private key of the OPC UA server u1; u1 is the OPC UA server indicator;
[0130] S4-3: According to the signature information, sign the encrypted real-time data standard file to obtain the real-time signature data of the encrypted real-time data standard file;
[0131] The formula is:
[0132]
[0133] Wherein, r' is a random number; is the prime order; P is the prime field base point; H2 is the target hash function; K u1 is the registration parameter of the OPC UA server u1 in the signature information {K u1 , KID u1}; KID u1 is the registration ID of the OPC UA server u1 in the signature information; ID u1 is the server ID of the OPC UA server u1; The composed real-time signature data is {ID u1 , γ' = {K u1 , R u1 , M u1 , B u1}}; R u1 , B u1 , γ' are all signature parameters of the OPC UA server u1;
[0134] S4-4: Upload the encrypted real-time data standard file in XML format and the real-time signature data to the cloud data center;
[0135] S5: Use the cloud data center to perform anomaly analysis on the real-time data standard file to obtain the real-time anomaly analysis result, and perform distributed storage on the real-time data standard file and the real-time anomaly analysis result, including the following steps:
[0136] S5-1: Based on the cloud data center, call a trusted institution to verify the signature of the real-time signature data. If the signature verification passes, proceed to the next step; otherwise, end the data management;
[0137] The formula is:
[0138] β u1 B u1 P = β u1 H2(R u1 ,ID u1 ,K u1 )R u1 +β u1 K u1 +β u1 H1(ID u1 ,K u1 )PK u1
[0139] If the left side is equal to the right side, the signature verification passes;
[0140] S5-2: According to the public key of the OPC UA server stored in the controlled database, decrypt the encrypted real-time data standard file to obtain the decrypted real-time data standard file;
[0141] The formula is:
[0142] m' u1 = E - (PK u1 |RR1,M u1 )
[0143] In the formula, m' u1 is the decrypted real-time data standard file; E - (*) is the asymmetric decryption function; M u1 is the encrypted real-time data standard file; PK u1 is the public key of the OPC UA server u1;
[0144] S5-3: Parse the decrypted real-time data standard file and construct a real-time OPC UA information graph corresponding to the real-time OPC UA information data;
[0145] S5-4: Use the pre-trained anomaly analysis model to perform anomaly analysis on the real-time OPC UA information graph to obtain the real-time anomaly analysis result;
[0146] The anomaly analysis model is constructed based on the Graph Convolutional Network (GCN). The real-time OPC UA information graph includes the real-time node value features of each node in the OPC UA information model instance, the edge features of the node relationships, and the real-time node attribute value features, which constitute the real-time graph features of the real-time OPC UA information graph. Anomaly analysis is performed according to the real-time graph features to obtain the real-time anomaly analysis result;
[0147] S5-5: Use a blockchain network to perform distributed storage on the encrypted real-time data standard file and the real-time anomaly analysis result, including the following steps:
[0148] S5-5-1: Generate a retrieval tag based on the timestamp and physical entity ID corresponding to the encrypted real-time data standard file;
[0149] S5-5-2: Shard the encrypted real-time data standard file according to the replication mechanism to obtain a number of data file shards containing replica shards;
[0150] S5-5-3: Send the number of data file shards to a number of nodes in the blockchain network, use the nodes to locally store the received data file shards, and obtain the corresponding storage addresses;
[0151] S5-5-4: Record the storage addresses of each data file shard in the blockchain network, as well as the corresponding retrieval tags and real-time anomaly analysis results in the distributed ledger;
[0152] S6: Use a terminal device to perform data query in the OPC UA server and / or cloud data center through an OPC UA client, including the following steps:
[0153] S6-1: If performing real-time data query, use the terminal device to connect to the OPC UA server through the OPC UA client and send the real-time query information to the OPC UA server;
[0154] S6-2: Based on the OPC UA server, obtain the matching encrypted real-time data standard file according to the real-time query information, and send the matching encrypted real-time data standard file in XML format and the public key to the terminal device;
[0155] S6-3: If performing historical data query, use the terminal device to connect to the cloud data center through the OPC UA client and send the real-time query information to the cloud data center;
[0156] S6-4: Based on the cloud data center, retrieve in the distributed ledger according to the real-time query information to obtain the matching retrieval tag;
[0157] S6-5: Extract a number of matching data file shards from the blockchain network according to the matching storage address corresponding to the matching retrieval tag, and restore them to obtain the corresponding matching encrypted historical data standard file;
[0158] S6-6: Send the matching encrypted historical data standard file in XML format and the public key to the terminal device;
[0159] S6-7: Based on the terminal device, decrypt the matched encrypted real-time data standard file and / or the matched encrypted historical data standard file according to the public key to obtain the matched decrypted real-time data standard file and / or the matched decrypted historical data standard file;
[0160] S6-8: Analyze the matched decrypted real-time data standard file and / or the matched decrypted historical data standard file to obtain the corresponding matched real-time OPC UA information data and / or the matched historical OPC UA information data.
[0161] Embodiment 2:
[0162] As Figure 2 shown, this embodiment provides a data management system based on the OPC UA information model for implementing the data management method. The system includes a cloud data center, a trusted institution, several OPC UA servers, several data acquisition devices, and several terminal devices. The trusted institution is respectively communicatively connected to several OPC UA servers, the cloud data center is respectively communicatively connected to the trusted institution, several OPC UA servers, and several terminal devices, and each OPC UA server is respectively communicatively connected to several terminal devices and several data acquisition devices within the communication range;
[0163] The cloud data center is used to perform anomaly analysis on the real-time data standard file to obtain a real-time anomaly analysis result, and perform distributed storage on the real-time data standard file and the real-time anomaly analysis result;
[0164] The trusted institution is used to generate keys and register the identities of the OPC UA servers;
[0165] The data acquisition device constructs a corresponding OPC UA information model according to the historical physical data of the physical entity; collects real-time physical data according to the OPC UA information model of the physical entity, and sends the real-time physical data to the OPC UA server;
[0166] The OPC UA server is used to create a corresponding OPC UA information model instance in the address space; write the real-time physical data into the corresponding OPC UA information model instance, and extract the real-time OPC UA information data of the OPC UA information model instance; convert the real-time OPC UA information data into a real-time data standard file in a common format for the cloud data center and the OPC UA client, and upload it to the cloud data center;
[0167] The terminal device is used to query data on the OPC UA server and / or the cloud data center through the OPC UA client.
[0168] The present invention discloses a data management method and system based on the OPC UA information model, which encrypts the transmitted data file by using an asymmetric encryption algorithm and digital identity authentication technology to ensure the security of the data file during transmission and storage, and effectively prevents the leakage and tampering of the data file; utilizes the immutability of blockchain technology to implement data source verification and data operation auditing, improving the security and transparency of data management; realizes the standardized conversion between different data sources by constructing a unified OPC UA information model, simplifies the data processing process, improves the processing efficiency, and can quickly respond to the writing and query of real-time data through the data interaction processing process between the data acquisition device and the OPC UA server, meeting the real-time requirements; uses a blockchain network for data storage, achieving decentralization, reducing the risk of single-point failure, and improving the overall reliability of the system. Utilizing the distributed characteristics of blockchain, it can easily cope with the rapid growth of data volume and has good scalability; realizes efficient data query by providing real-time retrieval of real-time and historical data, enhancing the user experience; realizes intelligent and automated anomaly analysis of OPC UA information data through the constructed anomaly analysis model, providing valuable data insights and decision-making support.
[0169] The specific embodiments described above further elaborate on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A data management method based on the OPC UA information model, characterized in that: Including the following steps: Based on the historical physical data of the physical entity, construct the corresponding OPC UA information model and create the corresponding OPC UA information model instance in the address space of the OPC UA server; Use the data acquisition device to collect real-time physical data according to the OPC UA information model of the physical entity and send the real-time physical data to the OPC UA server; Write the real-time physical data into the corresponding OPC UA information model instance in the OPC UA server and extract the real-time OPC UA information data of the OPC UA information model instance, including the following steps: Use the OPC UA client to access the address space of the OPC UA server and locate the target node in the OPC UA information model instance; Package the real-time node value and real-time node attribute value of the dynamic node corresponding to the target node in the real-time physical data in OPC UA format to obtain the corresponding real-time node packaged data; Use the write service of the OPC UA protocol to write the real-time node packaged data of the dynamic node into the target node of the OPC UA information model instance; Traverse the real-time node packaged data of all dynamic nodes of the real-time physical data until all target nodes of the OPC UA information model instance are written; According to the preset subscription service, extract the real-time node packaged data written by all monitoring nodes in the OPC UA information model instance and integrate them to obtain the real-time OPC UA information data; Convert the real-time OPC UA information data into a real-time data standard file in a common format for the cloud data center and the OPC UA client and upload it to the cloud data center; Use the cloud data center to perform anomaly analysis on the real-time data standard file to obtain the real-time anomaly analysis result and perform distributed storage on the real-time data standard file and the real-time anomaly analysis result, including the following steps: Based on the cloud data center, call a trusted institution to verify the signature of the real-time signature data. If the signature verification passes, proceed to the next step; otherwise, end the data management; According to the public key of the OPC UA server stored in the controlled database, decrypt the encrypted real-time data standard file to obtain the decrypted real-time data standard file; Parse the decrypted real-time data standard file and construct the real-time OPC UA information graph corresponding to the real-time OPC UA information data; Use the pre-trained anomaly analysis model to perform anomaly analysis on the real-time OPC UA information graph to obtain the real-time anomaly analysis result; The anomaly analysis model is constructed based on the GCN algorithm; Use the blockchain network to perform distributed storage on the encrypted real-time data standard file and the real-time anomaly analysis result; Use the terminal device to perform data query in the OPC UA server and / or the cloud data center through the OPC UA client, including the following steps: If real-time data query is to be performed, use the terminal device to connect to the OPC UA server through the OPC UA client and send the real-time query information to the OPC UA server; Based on the OPC UA server, according to the real-time query information, obtain the matching encrypted real-time data standard file, and send the matching encrypted real-time data standard file in XML format and the public key to the terminal device; If historical data query is performed, use the terminal device to connect to the cloud data center through the OPC UA client and send the real-time query information to the cloud data center; Based on the cloud data center, according to the real-time query information, retrieve in the distributed ledger to obtain the matching retrieval tags; According to the matching storage addresses corresponding to the matching retrieval tags, extract several matching data file shards in the blockchain network and restore them to obtain the corresponding matching encrypted historical data standard files; Send the matching encrypted historical data standard file in XML format and the public key to the terminal device; Based on the terminal device, decrypt the matching encrypted real-time data standard file and / or the matching encrypted historical data standard file according to the public key to obtain the matching decrypted real-time data standard file and / or the matching decrypted historical data standard file; Parse the matching decrypted real-time data standard file and / or the matching decrypted historical data standard file to obtain the corresponding matching real-time OPC UA information data and / or matching historical OPC UA information data.
2. The data management method based on the OPC UA information model according to claim 1, wherein: According to the historical physical data of the physical entity, construct the corresponding OPC UA information model and create the corresponding OPC UA information model instance in the address space of the OPC UA server, including the following steps: Use the data acquisition device to collect the historical physical data of the physical entity, and set the corresponding nodes, node attributes and node relationships according to the physical parameters and physical parameter relationships in the historical physical data; According to the nodes, node attributes and node relationships, construct the OPC UA information model of the physical entity, extract the model metadata of the OPC UA information model, and send it to the OPC UA server; Use the OPC UA server to create the corresponding OPC UA information model instance in the address space according to the model metadata.
3. The data management method based on the OPC UA information model according to claim 2, characterized in that: Use the data acquisition device to collect the real-time physical data according to the OPC UA information model of the physical entity and send the real-time physical data to the OPC UA server, including the following steps: Use the data acquisition device to collect the real-time node values and real-time node attribute values of each dynamic node according to the nodes, node attributes and node relationships in the OPC UA information model of the physical entity; Integrate the real-time node values and real-time node attribute values of all dynamic nodes into the real-time physical data in the OPC UA information model format; Based on the OPC UA protocol, send the real-time physical data in OPC UA format to the OPC UA server through the OPC UA client.
4. A data management method based on the OPC UA information model according to claim 1, characterized in that: It also includes: Based on the trusted institution, perform key generation and identity registration for the OPC UA server, including the following steps: Based on the trusted institution, perform key generation and identity registration for all OPC UA servers to obtain the public-private key pairs and signature information of each OPC UA server; Return the private key and signature information in the public-private key pair to the corresponding OPC UA server, and store the public key in the public-private key pair and the cloud key in the controlled database of the cloud data center.
5. A data management method based on the OPC UA information model according to claim 4, characterized in that: Convert the real-time OPC UA information data into a real-time data standard file in a common format for the cloud data center and the OPC UA client, and upload it to the cloud data center, including the following steps: Set the common format for the cloud data center and the OPC UA client to XML format, and convert the real-time OPC UA information data into a real-time data standard file in XML format; Encrypt the real-time data standard file according to the private key in the public-private key pair to obtain the encrypted real-time data standard file; Sign the encrypted real-time data standard file according to the signature information to obtain the real-time signature data of the encrypted real-time data standard file; Upload the encrypted real-time data standard file in XML format and the real-time signature data to the cloud data center.
6. The data management method based on the OPC UA information model according to claim 5, characterized in that: Use the blockchain network to perform distributed storage on the encrypted real-time data standard file and the real-time anomaly analysis result, including the following steps: Generate a retrieval label according to the timestamp and physical entity ID corresponding to the encrypted real-time data standard file; Slice the encrypted real-time data standard file according to the replication mechanism to obtain a number of data file slices including replica slices; Send the number of data file slices to a number of nodes in the blockchain network, use the nodes to locally store the received data file slices, and obtain the corresponding storage addresses; Record the storage address of each data file slice in the blockchain network, as well as the corresponding retrieval label and real-time anomaly analysis result in the distributed ledger.
7. A data management system based on the OPC UA information model for implementing the data management method according to any one of claims 1-6, characterized in that: The system described includes a cloud data center, a trusted institution, a number of OPC UA servers, a number of data collection devices, and a number of terminal devices. The trusted institution is respectively communicatively connected to the number of OPC UA servers. The cloud data center is respectively communicatively connected to the trusted institution, the number of OPC UA servers, and the number of terminal devices. Each OPC UA server is respectively communicatively connected to the number of terminal devices and a number of data collection devices within the communication range.
Citation Information
Patent Citations
Multi-transport protocol equipment monitoring system based on OPC UA
CN111556163A
Abnormity detection method and system based on mine real-time monitoring data
CN118484752A