A Blockchain-Based Industrial Data Secure Transmission Method

By adopting a blockchain-based secure transmission method in industrial data transmission, using dynamic permission verification and multiple encryption technologies, the problem of insufficient security in industrial data transmission in the existing technology is solved, and the efficiency and reliability of data transmission are achieved.

CN119628974BActive Publication Date: 2025-06-27JIANGSU IDEABANK MICROELECTRONICS TECH

Patent Information

Application Number
CN202510162110.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-06-27
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

Existing industrial data transmission methods cannot effectively prevent the risk of illegal acquisition and tampering during data transmission, resulting in insufficient security of industrial data transmission.

Method used

The industrial data security transmission method based on blockchain is adopted, and the transmission request of the user's device is received through the server, the user behavior feature vector is obtained, and the dynamic permission verification model is used to classify and predict the legality probability, and multiple encryption and decryption are carried out through the blockchain verification information and proxy nodes to ensure the security of data transmission.

Benefits of technology

Effectively prevent the risk of illegal acquisition and tampering during data transmission, ensure the security of industrial data transmission, and improve the reliability and integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119628974B_ABST
    Figure CN119628974B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of industrial data secure transmission, and discloses an industrial data secure transmission method based on blockchain. The method includes that the server receives an industrial data request, obtains a user behavior feature vector, classifies and predicts it, and calculates a legitimacy probability; the server sends a data key and encrypted industrial data to a client device to generate a user key, combines the two to obtain a combined key, and then uses a second key to perform secondary encryption on the encrypted data to generate second encrypted industrial data; the requester and the proxy node verify information through the blockchain. After passing the verification, the combined key and the second encrypted data are queried at the proxy node; the requester and the client device obtain the data key through permission information authentication, then use the combined key to decrypt the second encrypted data to obtain first decrypted data, and then use the data key to decrypt to obtain the original industrial data. This method has the following effects: effectively preventing the risk of being tampered with during the data transmission process and ensuring the security of industrial data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial data secure transmission, and particularly to an industrial data secure transmission method based on blockchain. Background Art

[0002] At present, there is a risk of passive leakage in the process of industrial data transmission. For example, industrial data may be intercepted by hackers during transmission. Secondly, there is a risk of active tampering in the process of industrial data transmission. In response to various data transmission security problems existing in industrial data transmission, many security methods have been proposed, including differential privacy protection, proxy re-encryption, proxy obfuscated circuits, etc.

[0003] In the existing industrial data transmission process, if symmetric encryption is adopted, there are risks of privacy leakage and proxy attacks. Because the key of symmetric encryption is transmitted to the proxy, and the proxy has strong autonomy, it cannot be guaranteed that the proxy is honest and trustworthy. If public key encryption is adopted, there are problems of large computational amount and large communication volume. Because the key of public key encryption is encrypted by the user's public key, and the user's public key is very long, resulting in large computational and communication overheads. Moreover, the proxy cannot decrypt the data, and the data is directly decrypted by the user, while the industrial site generally does not have rich computing resources.

[0004] In summary, the existing industrial data transmission methods cannot effectively prevent the risks of illegal acquisition and tampering during data transmission, which is not conducive to ensuring the security of industrial data transmission. Summary of the Invention

[0005] The present invention provides an industrial data secure transmission method based on blockchain to effectively prevent the risks of illegal acquisition and tampering during data transmission and ensure the security of industrial data transmission.

[0006] In a first aspect, to solve the above technical problems, the present invention provides an industrial data secure transmission method based on blockchain, including:

[0007] The server receives a transmission request of industrial data sent by the user terminal device and obtains a user behavior feature vector;

[0008] The server classifies and predicts the user behavior feature vector based on a preset dynamic permission verification model to obtain the legitimacy probability of the user request;

[0009] The server judges the legitimacy probability. When the legitimacy probability is greater than or equal to a preset probability threshold, the data key and the first encrypted industrial data are sent to the user terminal device;

[0010] The client device generates a user key, combines the data key and the user key to obtain a combined key, and sends the combined key and the first encrypted industrial data to the proxy node; the proxy node performs secondary encryption on the combined key and the first encrypted industrial data to obtain second encrypted industrial data;

[0011] After obtaining the blockchain verification information and the industrial data source device permission information from the proxy node, the industrial data requester verifies through the blockchain verification information between the industrial data requester and the proxy node. After passing the verification, the combined key and the second encrypted industrial data are queried on the proxy node; wherein, the blockchain verification information and the industrial data source device permission information are stored on the blockchain through a blockchain smart contract;

[0012] Authenticate between the industrial data requester and the client device through the industrial data source device permission information. When the authentication is passed, obtain the data key stored in the client device;

[0013] The industrial data requester decrypts the second encrypted industrial data according to the combined key to obtain first decrypted data, and uses the data key to decrypt the first decrypted data again to obtain the decrypted industrial data.

[0014] In an alternative embodiment, the training process of the dynamic permission verification model includes:

[0015] Obtain the historical access data and historical behavior characteristics of the user;

[0016] Preprocess the historical access data and the historical behavior characteristics, and divide them into β non-overlapping subsets, where β is a preset number;

[0017] Divide all the subsets into training set data and validation set data;

[0018] Use the training set data as input data, construct an initial dynamic permission verification model based on the random forest algorithm, and perform permission dynamic adjustment on the initial dynamic permission verification model according to the validation set data to obtain a dynamic permission verification model;

[0019] Perform permission dynamic adjustment through the following formula:

[0020]

[0021] where, represents the feature value of the validation set data, and represent the adjustment parameters of the validation set data, represents the permission verification threshold for dynamic adjustment.

[0022] In an alternative embodiment, the server classifies and predicts the user behavior feature vector based on a preset dynamic permission verification model to obtain the legitimacy probability of the user request, including:

[0023] Obtain the output value of the user behavior feature vector;

[0024] If the output value is less than then it is determined as an illegal behavior;

[0025] If the output value is greater than or equal to then it is determined as a legal behavior;

[0026] For the output value determined as a legal behavior, calculate the legitimacy probability of the user request using a credibility algorithm;

[0027] Wherein, represents a dynamically adjusted permission verification threshold.

[0028] In an alternative embodiment, the server judges the legitimacy probability. When the legitimacy probability is greater than or equal to a preset probability threshold, the data key and the first encrypted industrial data are sent to the user terminal device, including:

[0029] The server judges the legitimacy probability:

[0030] When the legitimacy probability is less than the preset probability threshold, the user's request is rejected;

[0031] When the legitimacy probability is greater than or equal to the preset probability threshold, the user's verification information and the industrial data source device permission information are stored on the blockchain to generate a data key;

[0032] Perform preliminary encryption on the pre-obtained original industrial data and the data key using an encryption algorithm to obtain the first encrypted industrial data;

[0033] Send the data key and the first encrypted industrial data to the user terminal device.

[0034] In an alternative embodiment, the user terminal device generates a user key and combines the data key and the user key to obtain a combined key, including:

[0035] The user terminal device takes the user key as plaintext input and the data key as the encryption key;

[0036] Encrypt the user key using the data key through the SM4 encryption algorithm to obtain the combined key.

[0037] In an alternative embodiment, after the industrial data requester obtains the blockchain verification information and the industrial data source device permission information from the proxy node, the industrial data requester verifies with the proxy node through the blockchain verification information. After the verification passes, the combined key and the second encrypted industrial data are obtained by querying on the proxy node, including:

[0038] Obtain the blockchain verification information and the industrial data source device permission information;

[0039] The industrial data requester verifies with the proxy node through the blockchain verification information:

[0040] If the permission information provided by the industrial data requester matches the blockchain verification information, the combined key can be obtained by querying on the proxy node;

[0041] If the permission information provided by the industrial data requester does not match the blockchain verification information, obtain the blockchain verification information and the industrial data source device permission information again;

[0042] Query the second encrypted industrial data according to the combined key.

[0043] In an alternative embodiment, the industrial data requester authenticates with the client device through the industrial data source device permission information. After the authentication passes, the data key stored in the client device is obtained, including:

[0044] If the identity information and permission information provided by the industrial data requester match the permission information stored in the client device, obtain the data key stored in the client device;

[0045] If the identity information and permission information provided by the industrial data requester do not match the permission information stored in the client device, obtain the blockchain verification information and the industrial data source device permission information again.

[0046] In an alternative embodiment, the industrial data requester decrypts the second encrypted industrial data according to the combined key and the second encrypted industrial data, and decrypts the first decrypted data again with the data key to obtain the decrypted industrial data, including:

[0047] The industrial data requester obtains the combined key and the data key through the proxy node;

[0048] Query the second encrypted industrial data on the proxy node through the combined key;

[0049] Decrypt the second encrypted industrial data to obtain the first decrypted data;

[0050] Decrypt the first decrypted data with the data key to obtain the decrypted industrial data.

[0051] In a second aspect, the present invention further provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the method for secure transmission of industrial data based on blockchain described in any one of the above is implemented.

[0052] In a third aspect, the present invention further provides a computer-readable storage medium, which includes a stored computer program. When the computer program runs, it controls the device where the computer-readable storage medium is located to execute the method for secure transmission of industrial data based on blockchain described in any one of the above.

[0053] Compared with the prior art, the present invention has the following beneficial effects:

[0054] The present invention discloses a method for secure transmission of industrial data based on blockchain. The method includes: the server receives a transmission request of industrial data sent by a client device and obtains a user behavior feature vector; the server performs classification prediction on the user behavior feature vector based on a preset dynamic permission verification model to obtain the legitimacy probability of the user request. When the legitimacy probability is greater than or equal to a preset probability threshold, the data key and the first encrypted industrial data are sent to the client device; the client device generates a user key, combines the data key and the user key to obtain a combined key, and sends the combined key and the first encrypted industrial data to a proxy node; the proxy node performs secondary encryption on the combined key and the first encrypted industrial data to obtain second encrypted industrial data; after obtaining blockchain verification information and industrial data source device permission information from the proxy node, the industrial data requester verifies through the blockchain verification information between the industrial data requester and the proxy node. After passing the verification, the combined key and the second encrypted industrial data are obtained by querying on the proxy node; the industrial data requester authenticates through the industrial data source device permission information between the industrial data requester and the client device. When the authentication is passed, the data key stored in the client device is obtained; the industrial data requester decrypts the combined key and the second encrypted industrial data to obtain first decrypted data, and decrypts the first decrypted data again with the data key to obtain the decrypted industrial data. In summary, the present invention can effectively prevent the risk of being illegally obtained and tampered with during the data transmission process and ensure the security of industrial data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 is a schematic flowchart of the method for secure transmission of industrial data based on blockchain provided in the first embodiment of the present invention. Specific implementation manners

[0056] Currently, there is a risk of passive leakage during the industrial data transmission process. For example, industrial data may be intercepted by hackers during transmission. Secondly, there is a risk of active tampering during the industrial data transmission process. In response to various data transmission security problems existing in industrial data transmission, many security methods have been proposed, including differential privacy protection, proxy re-encryption, proxy obfuscated circuits, etc.

[0057] In the existing industrial data transmission process, if symmetric encryption is adopted, there are risks of privacy leakage and proxy attacks. Because the key of symmetric encryption is transmitted to the proxy, and the proxy has strong autonomy, it cannot be guaranteed that the proxy is honest and trustworthy. If public key encryption is adopted, there are problems of large computational amount and large communication volume. Because the key of public key encryption is encrypted by the user's public key, and the user's public key is very long, the computational and communication overheads are very large. Moreover, the proxy cannot decrypt the data, and the data is directly decrypted by the user, while the industrial site generally does not have rich computing resources. However, the existing industrial data transmission methods cannot effectively prevent the risks of illegal acquisition and tampering during the data transmission process, which is not conducive to ensuring the security of industrial data transmission.

[0058] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts shall fall within the protection scope of the present invention.

[0059] To solve the above problems, referring to Figure 1 , the first embodiment of the present invention provides an industrial data secure transmission method based on blockchain, including the following steps:

[0060] S11, the server receives a transmission request of industrial data sent by the user terminal device and obtains a user behavior feature vector;

[0061] S12, the server classifies and predicts the user behavior feature vector based on a preset dynamic permission verification model to obtain the legality probability of the user request;

[0062] S13, the server judges the legality probability. When the legality probability is greater than or equal to a preset probability threshold, the data key and the first encrypted industrial data are sent to the user terminal device;

[0063] S14. The client device generates a user key, combines the data key and the user key to obtain a combined key, and sends the combined key and the first encrypted industrial data to the proxy node. The proxy node performs secondary encryption on the basis of the combined key and the first encrypted industrial data to obtain second encrypted industrial data;

[0064] S15. After obtaining the blockchain verification information and the industrial data source device permission information from the proxy node, the industrial data requester verifies through the blockchain verification information between the industrial data requester and the proxy node. After the verification is passed, the combined key and the second encrypted industrial data are obtained by querying on the proxy node. Among them, the blockchain verification information and the industrial data source device permission information are stored on the blockchain through a blockchain smart contract;

[0065] S16. The industrial data requester and the client device are authenticated through the industrial data source device permission information. After the authentication is passed, the data key stored in the client device is obtained;

[0066] S17. The industrial data requester decrypts the second encrypted industrial data according to the combined key to obtain first decrypted data, and uses the data key to decrypt the first decrypted data again to obtain the decrypted industrial data.

[0067] The present invention discloses an industrial data secure transmission method based on blockchain. The method includes that the server receives a transmission request of industrial data sent by a client device and obtains a user behavior feature vector; the server classifies and predicts the user behavior feature vector based on a preset dynamic permission verification model to obtain the legality probability of the user request. When the legality probability is greater than or equal to a preset probability threshold, the data key and the first encrypted industrial data are sent to the client device; the client device generates a user key, combines the data key and the user key to obtain a combined key, and sends the combined key and the first encrypted industrial data to a proxy node; the proxy node performs secondary encryption according to the combined key and the first encrypted industrial data to obtain second encrypted industrial data; after an industrial data requester obtains blockchain verification information and industrial data source device permission information from the proxy node, the industrial data requester and the proxy node are verified through the blockchain verification information. After the verification is passed, the combined key and the second encrypted industrial data are obtained by querying on the proxy node; the industrial data requester and the client device are authenticated through the industrial data source device permission information. When the authentication is passed, the data key stored in the client device is obtained; the industrial data requester decrypts the second encrypted industrial data according to the combined key to obtain first decrypted data, and decrypts the first decrypted data again by using the data key to obtain the decrypted industrial data. In summary, the present invention can effectively prevent the risk of being illegally obtained and tampered during the data transmission process and ensure the security of industrial data transmission.

[0068] In step S11, the server receives a transmission request of industrial data sent by a client device and obtains a user behavior feature vector.

[0069] It should be noted that the data sources of industrial data transmission requests include sensors, PLCs, CNC machine tools, industrial robots, etc. The industrial data transmission request is obtained through physical connection and network configuration: a data acquisition device, such as an industrial intelligent gateway, is physically connected to industrial devices, and data transmission is realized through communication interfaces such as Ethernet and serial ports.

[0070] A user behavior feature vector is a mathematical tool for representing user behavior features. It combines multiple user behavior features into a vector form, and these features include the user's historical access data and historical behavior features. The user's historical access data refers to the access records of the user on a website or application, including

[0071] access time, accessed page, access duration, access path, and access frequency, etc.; the user's historical behavior features refer to various behavior performances of the user on a website or application, including browsing behavior, interaction behavior, search behavior, and retention behavior, etc.

[0072] Obtaining the user behavior feature vector requires collecting various types of user behavior data, such as the user's historical access data and historical behavior characteristics, etc. Then, the extracted features are converted into numerical form and combined into a vector. For example, the user's historical access data and historical behavior characteristics can be represented as a vector. Finally, the obtained user behavior feature vector is normalized to improve accuracy.

[0073] In step S12, the server classifies and predicts the user behavior feature vector based on a preset dynamic permission verification model to obtain the legitimacy probability of the user request.

[0074] Obtain the output value of the user behavior feature vector;

[0075] If the output value is less than , it is determined as an illegal behavior;

[0076] If the output value is greater than or equal to , it is determined as a legal behavior;

[0077] For the output value determined as a legal behavior, use the credibility algorithm to calculate the legitimacy probability of the user request;

[0078] Among them, represents the dynamically adjusted permission verification threshold.

[0079] It should be noted that the output value of the user behavior feature vector is a multi-dimensional numerical vector used to represent the user's behavior characteristics. This vector can include the user's historical access data and historical behavior characteristics, etc., and is converted into numerical form after processing.

[0080] The credibility algorithm is a method for evaluating the degree to which a certain hypothesis or conclusion is true. It is used in uncertain reasoning and determines the credibility of a hypothesis by calculating the trust growth degree and the disbelief growth degree.

[0081] Calculate the credibility through the following formula:

[0082]

[0083] Among them, represents the credibility of the current user behavior, represents the trust growth degree, represents the disbelief growth degree.

[0084] Using the credibility algorithm to calculate the legitimacy probability of the user request requires first obtaining the output value of the user behavior feature vector determined as a legal behavior, and then using similarity calculation methods such as cosine similarity and Euclidean distance to calculate the similarity between the current user's behavior feature vector and the legal behavior; then determine the trust growth degree and the disbelief growth degree:

[0085] Degree of trust growth ( ): When the behavior feature vector of the current user has a high similarity with the legal behavior, the degree of trust growth is large, indicating that the current user's behavior is closer to the legal behavior.

[0086] Degree of distrust growth ( ): When the similarity is low, the degree of distrust growth is large, indicating that the current user's behavior is quite different from the legal behavior.

[0087] Finally, calculate the credibility result using the above formula. When , it indicates that the probability of the current user's behavior being legal is high; when , it indicates that the probability of the current user's behavior being legal is low; when , it indicates that the probability of the current user's behavior being legal is neutral.

[0088] According to the credibility and the set threshold, calculate the probability of the user request being legal. For example, when , the probability of legality can be set to 80%.

[0089] Furthermore, the training process of the dynamic permission verification model includes:

[0090] Obtain the historical access data and historical behavior characteristics of the user;

[0091] Preprocess the historical access data and the historical behavior characteristics, and divide them into β non-overlapping subsets, where β is a preset quantity;

[0092] Divide all the subsets into training set data and validation set data;

[0093] Use the training set data as input data, construct an initial dynamic permission verification model based on the random forest algorithm, and perform dynamic permission adjustment on the initial dynamic permission verification model according to the validation set data to obtain the dynamic permission verification model;

[0094] Perform dynamic permission adjustment through the following formula:

[0095]

[0096] Among them, represents the feature value of the validation set data, and represent the adjustment parameters of the validation set data, represents the dynamically adjusted permission verification threshold.

[0097] It should be noted that the selection of the number of subsets is usually based on the size of the dataset and computing resources. The cross-validation method can be used. Exemplarily, the selection in this method is 10. The historical access data of users refers to the access records of users on websites or applications, including access time, accessed pages, access duration, access paths, and access frequencies, etc. The historical behavior characteristics of users refer to various behavior performances of users on websites or applications, including browsing behaviors, interaction behaviors, search behaviors, and retention behaviors, etc. The adjustment parameters of the validation set data are obtained through parameter tuning in the model training process and the analysis of the expected eigenvalue of the validation set data.

[0098] The training set data and the validation set data are two parts of the dataset used to evaluate the model performance. The training set is the dataset used to train the model, that is, the model learns and adjusts parameters through these data to minimize the prediction error. The validation set is the dataset used to verify the generalization ability of the model, that is, to evaluate the performance of the model on unseen data to prevent overfitting of the model. The training set is used to train the model to help the model learn the mapping relationship from input to output. The validation set is used to evaluate the generalization ability of the model, that is, the prediction ability of the model for new data.

[0099] The dynamic permission verification model is a permission management mechanism that allows the system to dynamically adjust the permissions of users according to the real-time behaviors of users, environmental conditions, or preset rules at runtime. Different from traditional static permission management, dynamic permission management does not rely on predefined roles and permissions, but can flexibly grant or revoke permissions according to real-time situations. The dynamic permission verification model has strong adaptability and can handle dynamic factors such as role changes and user behavior changes to adapt to changing business requirements. It can also dynamically adjust permissions according to real-time conditions to improve the responsiveness and user experience of the application.

[0100] The random forest algorithm is an ensemble learning method belonging to the supervised learning algorithm and is mainly used for classification and regression tasks. It improves the prediction accuracy and robustness by constructing multiple decision trees and integrating their results. The core idea of the random forest includes two "randomnesses". The first is to randomly select samples: during the training process, when training each decision tree, samples are randomly drawn from the training set by sampling with replacement. The second is to randomly select features: when splitting each node of the decision tree, a part of the features are randomly selected from all features for splitting instead of using all features. The random forest algorithm can effectively reduce the risk of overfitting by integrating the results of multiple decision trees and improve the prediction accuracy of the model. The random forest algorithm has strong robustness to noise and outliers: since it is an ensemble of multiple decision trees, even if some decision trees are affected by noise or outliers, the performance of the overall model will not be greatly affected.

[0101] In step S13, the server determines the legality probability. When the legality probability is greater than or equal to a preset probability threshold, the data key and the first encrypted industrial data are sent to the client device.

[0102] The server determines the legality probability:

[0103] When the legality probability is less than the preset probability threshold, the user's request is rejected;

[0104] When the legality probability is greater than or equal to the preset probability threshold, the user's verification information and the industrial data source device permission information are stored on the blockchain, and a data key is generated;

[0105] According to the pre-obtained original industrial data and the data key, a preliminary encryption is performed using an encryption algorithm to obtain the first encrypted industrial data;

[0106] The data key and the first encrypted industrial data are sent to the client device.

[0107] It should be noted that the data key refers to the key used to encrypt or decrypt data. In cryptography, the data key is specifically used to encrypt the data itself and not to encrypt other keys. The data key can be a key for symmetric encryption or a public key or private key in asymmetric encryption; in this embodiment, a key for symmetric encryption is selected. The data key can protect data security: The data key is the core of data encryption. Through it, the plaintext data is converted into ciphertext, thus preventing unauthorized access and data leakage. Only users holding the correct key can decrypt and access the original data. During data transmission and storage, the data key can prevent data from being tampered with, and the integrity and consistency of the data can be guaranteed through encryption. In this method, the preset probability threshold is exemplarily set to 80%.

[0108] A preliminary encryption is performed using an encryption algorithm to obtain the first encrypted industrial data. The industrial data source device can select a data key and save it in the device, and then generate verification information and send it to the user. The user fills in the verification information and returns it. If the verification is passed, the data key is used to encrypt the original industrial data to generate the first encrypted industrial data.

[0109] In step S14, the client device generates a user key, combines the data key and the user key to obtain a combined key, and sends the combined key and the first encrypted industrial data to the proxy node; the proxy node performs a secondary encryption based on the combined key and the first encrypted industrial data to obtain the second encrypted industrial data.

[0110] The client device takes the user key as the plaintext input and the data key as the encryption key;

[0111] Using the SM4 encryption algorithm, encrypt the user key with the data key to obtain the combined key.

[0112] It should be noted that the user key is a key used for encrypting and decrypting data and is used for authentication and data protection. It can be a key for symmetric encryption or a pair of public and private keys in asymmetric encryption. The user key is used in a security system to ensure that only authorized users can access or operate specific data or resources.

[0113] The SM4 encryption algorithm is a symmetric encryption algorithm used for encrypting and decrypting data. The key length of the SM4 encryption algorithm is 128 bits, and the data block size is 128 bits. The SM4 encryption algorithm has high security. It uses complex encryption algorithms and a relatively long key length, making it extremely difficult to crack and effectively protecting the confidentiality of data. In terms of design, the SM4 encryption algorithm can resist various known cryptographic attacks, such as differential cryptanalysis and linear cryptanalysis, and has high security.

[0114] The combined key refers to combining multiple keys or key fragments, such as a data key and a user key, to form a new key for encrypting or decrypting data. This combination can be achieved by splicing, mixing, or rules of multiple key fragments. By combining multiple keys, the difficulty of cracking can be increased because an attacker needs to crack multiple key fragments simultaneously to obtain the complete combined key; the combined key can utilize key fragments from different sources to provide a more complex encryption mechanism, thereby enhancing the security of the system.

[0115] In a specific application scenario, for example, in the KDC scheme, each user only stores their own private key and the public key of the KDC; when user A wants to have a session with user B, user A needs to send a request encrypted with their own private key to the KDC, indicating that user A wants to have a session with user B; after receiving the request, the KDC generates a key K of a symmetric cryptographic algorithm that can be used for a secret session between user A and user B, and then returns a response to user A, which contains the key K encrypted with user A's public key and the key K encrypted with user B's public key; user A sends the part encrypted with user B's public key to user B, and user B decrypts it to obtain the session key K, completing the automatic key distribution process. In this process, the data key (session key K) is generated by the KDC, the user keys (the user's private key and public key) are used for encrypting and decrypting requests and responses of industrial data, and the combined key (session key K) is used for subsequent encrypted communication.

[0116] In step S15, after the industrial data requester obtains the blockchain verification information and the industrial data source device permission information from the proxy node, the industrial data requester verifies with the proxy node through the blockchain verification information. After the verification passes, the combined key and the second encrypted industrial data are obtained by querying on the proxy node; wherein, the blockchain verification information and the industrial data source device permission information are stored on the blockchain through a blockchain smart contract.

[0117] Obtain blockchain verification information and industrial data source device permission information;

[0118] The industrial data requester verifies with the proxy node through the blockchain verification information:

[0119] If the permission information provided by the industrial data requester matches the blockchain verification information, the combined key can be obtained by querying on the proxy node;

[0120] If the permission information provided by the industrial data requester does not match the blockchain verification information, obtain the blockchain verification information and the industrial data source device permission information again;

[0121] Query the second encrypted industrial data according to the combined key.

[0122] It should be noted that the blockchain verification information refers to the information used to verify the integrity and authenticity of the data in the blockchain. This information includes transaction hashes, blockchain hashes, Merkle trees, etc., which are used to ensure the immutability and consistency of the blockchain data. The method of obtaining blockchain verification information can be through the use of a block explorer, which allows users to search and browse blockchain data. Through the block explorer, users can query information such as specific blocks, transactions, and addresses. For example, in a specific application scenario, users can obtain relevant verification information, such as the detailed content of the transaction and the hash value of the block, by inputting the transaction hash or block number.

[0123] A blockchain smart contract is a computer program that automatically executes, controls, or records legal events and actions on the blockchain. It is a self-executing contract, the terms of which are written in code on the blockchain and automatically executed when preset conditions are met. The code and execution results of the blockchain smart contract are publicly available on the blockchain, and all participants can verify the terms and execution of the contract, enhancing the transparency of the system; once the smart contract is deployed on the blockchain, its code and execution results will be permanently recorded and cannot be tampered with, ensuring the security and reliability of the contract.

[0124] Industrial data source device permission information refers to the permission settings for accessing and operating data source devices, such as sensors, PLCs, industrial robots, etc. in an industrial environment. These permission information define which users or systems can access the data of specific devices, what operations can be performed, such as reading, writing, modifying, etc., as well as the scope and limitations of access. Industrial data source device permission information can prevent unauthorized users from accessing sensitive data through strict permission management, thereby protecting the data security of enterprises and preventing data leakage; it can also ensure that only legitimate users or systems can access and operate data source devices, preventing data from being illegally tampered with or misused.

[0125] In step S16, authenticate between the industrial data requester and the client device through the industrial data source device permission information, and obtain the data key stored in the client device after successful authentication.

[0126] If the identity information and permission information provided by the industrial data requester match the permission information stored in the client device, obtain the data key stored in the client device;

[0127] If the identity information and permission information provided by the industrial data requester do not match the permission information stored in the client device, re-obtain the blockchain verification information and the industrial data source device permission information.

[0128] It should be noted that industrial data source device permission information refers to the permission settings for accessing and operating data source devices, such as sensors, PLCs, industrial robots, etc. in an industrial environment. These permission information define which users or systems can access the data of specific devices, what operations can be performed, such as reading, writing, modifying, etc., as well as the scope and limitations of access. Industrial data source device permission information can prevent unauthorized users from accessing sensitive data through strict permission management, thereby protecting the data security of enterprises and preventing data leakage; it can also ensure that only legitimate users or systems can access and operate data source devices, preventing data from being illegally tampered with or misused.

[0129] In step S17, the industrial data requester decrypts the second encrypted industrial data according to the combined key and the data key to obtain the first decrypted data, and then decrypts the first decrypted data again using the data key to obtain the decrypted industrial data.

[0130] The industrial data requester obtains the combined key and the data key through the proxy node;

[0131] Query the second encrypted industrial data on the proxy node through the combined key;

[0132] Decrypt the second encrypted industrial data to obtain the first decrypted data;

[0133] Decrypt the first decrypted data with the data key to obtain the decrypted industrial data.

[0134] It should be noted that decrypting the second encrypted industrial data to obtain the first decrypted data is the above-mentioned first encrypted industrial data; decrypting the first decrypted data with the data key to obtain the decrypted industrial data is the above-mentioned original industrial data.

[0135] A data key refers to a key used to encrypt or decrypt data. In cryptography, a data key is specifically used to encrypt the data itself and not other keys. A data key can be a key for symmetric encryption or a public key or private key in asymmetric encryption. A data key can protect data security: A data key is the core of data encryption. By using it, plaintext data is converted into ciphertext, thus preventing unauthorized access and data leakage. Only users with the correct key can decrypt and access the original data. During data transmission and storage, a data key can prevent data from being tampered with. Through encryption, the integrity and consistency of the data can be guaranteed.

[0136] A combined key refers to combining multiple keys or key fragments, such as a data key and a user key, to form a new key for encrypting or decrypting data. This combination can be achieved by splicing, mixing, or rules of multiple key fragments. By combining multiple keys, the difficulty of cracking can be increased because an attacker needs to crack multiple key fragments simultaneously to obtain the complete combined key; a combined key can utilize key fragments from different sources to provide a more complex encryption mechanism, thereby improving the security of the system.

[0137] The working process of the present invention is described below by taking a relatively common scenario as an example. Please also refer to Figure 1 the schematic diagram of the working scenario of the method.

[0138] In an intelligent manufacturing factory, the sensor devices of an automated production line need to transmit the collected industrial data to a central server for analysis. The sensor devices first send a data transmission request to the server and provide their operation behavior feature vectors. The server analyzes the feature vectors using a preset dynamic permission verification model and calculates the legitimacy probability of the request. When the probability reaches or exceeds the set threshold, the server sends the data key and the encrypted industrial data to the sensor devices. The sensor devices generate a user key and combine it with the data key to generate a combined key. Then, they send the combined key and the encrypted data to the proxy node, and the proxy node uses the combined key to perform secondary encryption on the data to generate more secure second-encrypted industrial data. After obtaining the blockchain verification information and device permission information, the industrial data requester conducts identity verification with the proxy node through blockchain verification. After the verification passes, the requester obtains the combined key and the second-encrypted data from the proxy node. Then, the requester and the sensor devices authenticate through the permission information. After the authentication passes, the requester obtains the data key. Finally, the requester decrypts the second-encrypted data with the combined key to obtain the first decrypted data, and then decrypts the first decrypted data with the data key to finally obtain the decrypted industrial data.

[0139] In summary, the present invention discloses a method for secure transmission of industrial data based on blockchain. The method includes the server receiving a transmission request for industrial data sent by a user terminal device and obtaining the user behavior feature vector. The server classifies and predicts the user behavior feature vector based on a preset dynamic permission verification model to obtain the legitimacy probability of the user request. When the legitimacy probability is greater than or equal to the preset probability threshold, the server sends the data key and the first-encrypted industrial data to the user terminal device. The user terminal device generates a user key, combines the data key and the user key to obtain a combined key, and sends the combined key and the first-encrypted industrial data to the proxy node. The proxy node performs secondary encryption on the basis of the combined key and the first-encrypted industrial data to obtain second-encrypted industrial data. After the industrial data requester obtains the blockchain verification information and the industrial data source device permission information from the proxy node, the industrial data requester and the proxy node are verified through the blockchain verification information. After the verification passes, the combined key and the second-encrypted data are obtained by querying on the proxy node. The industrial data requester and the user terminal device are authenticated through the industrial data source device permission information. When the authentication passes, the data key stored in the user terminal device is obtained. The industrial data requester decrypts the second-encrypted industrial data according to the combined key to obtain the first decrypted data, and decrypts the first decrypted data again using the data key to obtain the decrypted industrial data. In summary, the present invention can effectively prevent the risk of illegal acquisition and tampering during the data transmission process and ensure the security of industrial data transmission.

[0140] It should be noted that the embodiments of the present invention are used to execute all the process steps of the above-mentioned blockchain-based industrial data secure transmission method. The working principles and beneficial effects of the two correspond one by one, so they will not be elaborated here.

[0141] The embodiments of the present invention also provide an electronic device. The electronic device includes: a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a data processing terminal program. When the processor executes the computer program, the steps in the above-mentioned various embodiments of the blockchain-based industrial data secure transmission method are implemented, such as Figure 1 the step S11 shown.

[0142] Exemplarily, the computer program can be divided into one or more modules / units. The one or more modules / units are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units can be a series of computer program instruction segments capable of performing specific functions, and these instruction segments are used to describe the execution process of the computer program in the electronic device.

[0143] The electronic device can be a computing device such as a desktop computer, a notebook, a palm computer, and a smart tablet. The electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above components are only examples of the electronic device and do not constitute a limitation on the electronic device. It may include more or fewer components than the above, or combine certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, a bus, etc.

[0144] The so-called processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the electronic device and connects various parts of the entire electronic device through various interfaces and lines.

[0145] The memory can be used to store the computer programs and / or modules. By running or executing the computer programs and / or modules stored in the memory, and invoking the data stored in the memory, the processor realizes various functions of the electronic device. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory can include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0146] Among them, if the modules / units integrated in the electronic device are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0147] The specific embodiments described above have further elaborated on the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above description is only the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. In particular, it is pointed out that for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A blockchain-based industrial data security transmission method, characterized in that: include: The server receives the transmission request of industrial data sent by the user terminal device and obtains the user behavior feature vector; The server classifies and predicts the user behavior feature vector based on a preset dynamic authority verification model to obtain the legitimacy probability of the user request; The server judges the legitimacy probability, and when the legitimacy probability is less than a preset probability threshold, rejects the user's request, and when the legitimacy probability is greater than or equal to the preset probability threshold, sends the data key and the first encrypted industrial data to the user terminal device; The user terminal device generates a user key, combines the data key and the user key to obtain a combined key, and sends the combined key and the first encrypted industrial data to the proxy node; The proxy node performs secondary encryption according to the combined key and the first encrypted industrial data to obtain second encrypted industrial data; After the industrial data requester obtains the blockchain verification information and the industrial data source device permission information from the proxy node, the industrial data requester and the proxy node are verified through the blockchain verification information. After the verification is passed, the combined key and the second encrypted industrial data are queried on the proxy node; wherein the blockchain verification information and the industrial data source device permission information are stored on the blockchain through a blockchain smart contract; Authenticate the industrial data requester and the user terminal device through the industrial data source device authority information, and obtain the data key stored in the user terminal device after the authentication is passed; The industrial data requester decrypts the first decrypted data according to the combined key and the second encrypted industrial data, and decrypts the first decrypted data again using the data key to obtain the decrypted industrial data; The server classifies and predicts the user behavior feature vector based on a preset dynamic authority verification model to obtain the legitimacy probability of the user request, including: Obtaining an output value of the user behavior feature vector; If the output value is less than the dynamically adjusted permission verification threshold, it is determined to be an illegal behavior; If the output value is greater than or equal to the dynamically adjusted permission verification threshold, it is determined to be a legal behavior; The output value determined as a legitimate behavior is used to calculate the legitimacy probability of the user's request using a credibility algorithm; The training process of the dynamic permission verification model includes: Obtain the user's historical access data and historical behavior characteristics; Preprocessing the historical access data and the historical behavior features, and dividing them into β non-overlapping subsets, where β is a preset number; Dividing all the subsets into training set data and validation set data; Using the training set data as input data, constructing an initial dynamic permission verification model based on a random forest algorithm, and dynamically adjusting permissions of the initial dynamic permission verification model according to the verification set data to obtain a dynamic permission verification model; The following formula is used to dynamically adjust permissions: in, represents the feature value of the validation set data, and represents the adjustment parameters of the validation set data, Indicates the dynamically adjusted permission verification threshold.

2. The method for secure transmission of industrial data based on blockchain according to claim 1 is characterized in that: The server judges the legitimacy probability, and when the legitimacy probability is less than a preset probability threshold, rejects the user's request, and when the legitimacy probability is greater than or equal to the preset probability threshold, sends the data key and the first encrypted industrial data to the user terminal device, including: The server determines the legitimacy probability: When the legitimacy probability is less than a preset probability threshold, the user's request is rejected; When the legitimacy probability is greater than or equal to a preset probability threshold, the user's verification information and industrial data source device permission information are stored on the blockchain to generate a data key; Performing preliminary encryption using an encryption algorithm based on the pre-acquired original industrial data and the data key to obtain first encrypted industrial data; The data key and the first encrypted industrial data are sent to a user terminal device.

3. The method for secure transmission of industrial data based on blockchain according to claim 1 is characterized in that: The user terminal device generates a user key, and combines the data key and the user key to obtain a combined key, including: The user terminal device inputs the user key as plain text and uses the data key as an encryption key; The user key is encrypted using the data key through the SM4 encryption algorithm to obtain the combined key.

4. The method for secure transmission of industrial data based on blockchain according to claim 1 is characterized in that: After the industrial data requester obtains the blockchain verification information and the industrial data source device authority information from the proxy node, the industrial data requester and the proxy node are verified through the blockchain verification information, and after the verification is passed, the combined key and the second encrypted industrial data are queried on the proxy node, including: Obtain blockchain verification information and industrial data source equipment permission information; The industrial data requester and the proxy node verify each other through the blockchain verification information: If the authority information provided by the industrial data requester is consistent with the blockchain verification information, the combined key is obtained by querying on the proxy node; If the authority information provided by the industrial data requester does not match the blockchain verification information, then re-acquire the blockchain verification information and the industrial data source device authority information; According to the combined key, the second encrypted industrial data is queried and obtained.

5. The method for secure transmission of industrial data based on blockchain according to claim 1 is characterized in that: The step of authenticating the industrial data requester and the user terminal device through the industrial data source device authority information, and obtaining the data key stored in the user terminal device after the authentication is passed, includes: If the identity information and permission information provided by the industrial data requester match the permission information stored in the user terminal device, then obtaining the data key stored in the user terminal device; If the identity information and permission information provided by the industrial data requester do not match the permission information stored in the user-end device, the blockchain verification information and industrial data source device permission information are re-obtained.

6. The method for secure transmission of industrial data based on blockchain according to claim 4 is characterized in that: The industrial data requester decrypts the first decrypted data according to the combined key and the second encrypted industrial data, and decrypts the first decrypted data again using the data key to obtain the decrypted industrial data, including: The industrial data requester obtains the combined key and the data key through the proxy node; Obtaining second encrypted industrial data by querying on the proxy node through the combined key; decrypting the second encrypted industrial data to obtain first decrypted data; The first decrypted data is decrypted again using the data key to obtain decrypted industrial data.

7. An electronic device, characterized in that: It includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the processor executes the computer program, it implements the blockchain-based industrial data security transmission method as described in any one of claims 1 to 6.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the blockchain-based industrial data security transmission method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Abnormal behavior information identification method, system and device, equipment and medium

    CN110602248A

  • Data security storage system based on block chain

    CN112150147A

Cited By

  • Industrial data secure transmission method based on block chain

    CN121750231A