A method and device for secure access to industrial Internet data based on cloud-edge collaboration
By analyzing the industrial Internet access log and generating policy optimization signals, and optimizing the access control policy, the unauthorized access problem caused by the lack of flexibility in access control policies in the existing technology is solved, and more efficient and secure data access is achieved.
Patent Information
- Application Number
- CN202510168868.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-02-17
AI Technical Summary
The industrial Internet access control strategy based on cloud-edge collaboration in the prior art lacks flexibility and is difficult to adapt to changing access needs and potential security threats, resulting in high frequency of unauthorized access to data, which may lead to industrial Internet data leakage.
The data access information during the historical cycle is obtained through the industrial Internet access log, and unauthorized valid access is analyzed and evaluated to generate policy optimization signals. Based on this signal, access information within multiple historical periods of the user is obtained, local open data is analyzed, and access control policies are optimized through policy optimization values, access permission forms are generated, and access permissions are adjusted to reduce unauthorized access.
It improves the security and efficiency of industrial Internet data access, reduces the frequency of unauthorized access to data, reduces the risk of industrial Internet data leakage, and improves the access efficiency of users under the secure access policy, solving the network lag caused by a large number of users when accessing simultaneously.
Smart Images

Figure CN119628976B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data access security protection, and specifically, relates to an industrial Internet data security access method and device based on cloud-edge collaboration. Background Art
[0002] The Industrial Internet is the product of the deep integration of industrial manufacturing technology and Internet technology. Therefore, by utilizing the advantages of cloud-edge coordination technology: reducing data transmission delays, improving data processing efficiency, while reducing the load pressure of cloud computing centers and optimizing resource allocation, it can achieve interconnection between devices, real-time transmission and sharing of information, and promote the intelligent and digital transformation of industrial production.
[0003] The existing application number is 202310132155X, which is an industrial Internet security detection method and system based on cloud-edge collaboration. It generates security threat logs based on network attack behaviors, thereby realizing local and efficient detection of security threats. The security detection equipment has the characteristics of flexible deployment and low cost. The cloud computing module deployed in the cloud is used to receive, store and analyze security threat logs, thereby realizing centralized and unified management of the cloud.
[0004] In the existing technology, the industrial Internet access control strategy based on cloud-edge coordination technology lacks flexibility and is difficult to adapt to the ever-changing access needs and potential security threats. Therefore, unauthorized effective access is obtained through the industrial Internet access log, and it is analyzed to evaluate the security level of the industrial Internet access control strategy in the historical period. At the same time, the data access value is obtained to evaluate the degree of openness of the industrial Internet data and determine the local open data. Then, the local open data is analyzed to obtain the policy optimization value. Based on the policy optimization value, the access permission table is obtained to optimize the access control strategy to avoid the high frequency of unauthorized access to data, which leads to the security problem of industrial Internet data leakage. Finally, by testing the optimized access control strategy, the priority access table is obtained, thereby improving the user's access efficiency under the security access strategy and solving the security problem of network jams caused by a large number of users accessing at the same time.
[0005] To this end, the present invention provides a method and device for secure access to industrial Internet data based on cloud-edge collaboration. Summary of the invention
[0006] In order to make up for the deficiencies of the prior art, at least one technical problem raised in the background technology is solved.
[0007] The technical solution adopted by the present invention to solve the technical problem is: in the first aspect, a method for secure access to industrial Internet data based on cloud-edge collaboration, comprising:
[0008] Step 1: Obtain data access information in the historical period through the industrial Internet access log, analyze and process the data access information, obtain unauthorized valid access, and evaluate the industrial Internet access control strategy based on the unauthorized valid access to obtain the evaluation result;
[0009] Step 2: If the evaluation result is a strategy optimization signal, the user's access information in multiple historical periods of the historical cycle is obtained, and the access information in multiple historical periods is analyzed to obtain local open data;
[0010] Step 3: Analyze local open data in multiple historical periods within the historical cycle, output the policy optimization value, and generate an access permission table. Based on the access permission table, optimize the access control policy for the industrial Internet.
[0011] Step 4: Based on the access control strategy optimized by the Industrial Internet, obtain the user access decryption information within the test period through the Industrial Internet access log, process the user access decryption information, obtain the priority access table, and based on the priority access table, improve the access efficiency of users when accessing data.
[0012] As a further solution of the present invention, the authorized access requests in the historical period are classified and divided into authorized access requests and unauthorized access requests;
[0013] Divide the historical period into several historical time periods, obtain the number of unauthorized valid accesses in the historical time period, calculate the ratio of the number of unauthorized valid accesses in the historical time period to the total number of authorized access requests in the historical time period, and obtain the number of unauthorized valid accesses;
[0014] The number of unauthorized valid times corresponding to all historical periods in the historical cycle is added and averaged to obtain the policy evaluation value;
[0015] If the strategy evaluation value is greater than the strategy evaluation threshold, a strategy optimization signal is generated;
[0016] If the policy evaluation value is less than or equal to the policy evaluation threshold, a policy normal signal is generated.
[0017] As a further solution of the present invention, the method for obtaining local open data is:
[0018] The number of visits Accessing consecutive values with Substituting into the formula: , calculate the data access value ,in, , is the preset proportional coefficient;
[0019] The data access value is compared with the data access threshold. If the data access value is less than the data access threshold, a local open signal is generated, and the industrial Internet data corresponding to the local open signal is marked as local open data.
[0020] As a further solution of the present invention, the access times are obtained as follows:
[0021] Extracting any one historical period from multiple historical periods within the historical cycle, and obtaining the user's access data through the user key token within the historical period;
[0022] Based on the access data, the number of accesses to the access data in the historical period is obtained, and the ratio is calculated with the total number of authorized access requests in the historical period to obtain the number of accesses in the period;
[0023] The number of visits corresponding to all historical periods in the historical cycle is summed up and averaged to obtain the number of visits, and ;
[0024] The way to access continuous values is:
[0025] In the historical period, the interval time of access data is counted, the average is added and calculated, and the ratio is calculated with the length of the historical period to obtain the continuous value of the period;
[0026] Add the corresponding time period continuous values of all historical periods in the historical cycle and take the average to obtain the access continuous value, which is marked as .
[0027] As a further solution of the present invention, based on the access permission table, the optimization of the industrial Internet access control strategy is completed, and the optimization process is as follows:
[0028] Compare the policy optimization values corresponding to the data in the industrial Internet and arrange them in descending order to obtain an access rights table;
[0029] Based on the sorting of the access permission table, the access permission of the local open data is adjusted accordingly by access decryption.
[0030] As a further solution of the present invention, the strategy optimization value is obtained by:
[0031] Will generate interval time , signal generation frequency and number of visits Substituting into the formula: , calculate the strategy optimization value ,in, , , is the preset scaling factor.
[0032] As a further solution of the present invention, the generation interval duration is obtained in the following manner:
[0033] Obtain the time point at which the local open signal is generated, make a difference between the adjacent local open signal generation time points, take the absolute value, and calculate the ratio with the historical time period to obtain the unit interval length;
[0034] Add up all the unit interval durations and take the average to get the generation interval duration, which is marked as ;
[0035] The signal generation frequency is obtained as follows:
[0036] Count the number of times the local open signal is generated, calculate the ratio of the number of times the local open signal is generated to the total number of times the signal is generated in the historical period, and get the signal generation frequency, which is marked as .
[0037] As a further solution of the present invention, the process of improving the access efficiency when a user accesses data is as follows:
[0038] The decryption fluency values corresponding to all decryption periods in the test cycle are added and averaged to obtain the access credit value;
[0039] Obtain the access credit values corresponding to all users in the test period, compare the access credit values corresponding to the users, sort them in ascending order of access credit values, and sort the users accordingly to obtain a priority access table;
[0040] Based on the priority access table, the number of key digits input by priority users in the priority access table is reduced, thereby improving the efficiency of user access to data and solving the security problem of network jams caused by a large number of users accessing the data at the same time.
[0041] As a further solution of the present invention, the access credit value is obtained by:
[0042] The test cycle is divided into several decryption periods. A decryption process is selected from multiple decryption periods in the test cycle for analysis. The analysis process is as follows:
[0043] During the decryption process, the time for each digit of the key input by the user is obtained, and the ratio of the time for each digit of the key input by the user to the decryption period is calculated to obtain the sub-bit decryption time;
[0044] The sub-bit decryption time corresponding to each digit of the key input by the user is added and averaged to obtain the decryption time;
[0045] During the decryption process, the interval time when the user inputs the adjacent digits of the key is obtained, and the ratio of the interval time when the user inputs the adjacent digits of the key is calculated with the decryption period to obtain the sub-digit interval time;
[0046] Add up all the sub-bit intervals and take the average to get the decryption interval value;
[0047] The decryption duration and the decryption interval value are added together to obtain the decryption fluency value;
[0048] The decryption fluency values corresponding to all decryption periods in the test cycle are added and averaged to obtain the access credit value. The decryption fluency value is obtained as follows:
[0049] The test cycle is divided into several decryption periods. A decryption process is selected from multiple decryption periods in the test cycle for analysis. The analysis process is as follows:
[0050] During the decryption process, the time for each digit of the key input by the user is obtained, and the ratio of the time for each digit of the key input by the user to the decryption period is calculated to obtain the sub-bit decryption time;
[0051] The sub-bit decryption time corresponding to each digit of the key input by the user is added and averaged to obtain the decryption time;
[0052] During the decryption process, the interval time when the user inputs the adjacent digits of the key is obtained, and the ratio of the interval time when the user inputs the adjacent digits of the key is calculated with the decryption period to obtain the sub-digit interval time;
[0053] Add up all the sub-bit intervals and take the average to get the decryption interval value;
[0054] The decryption duration is added to the decryption interval value to obtain the decryption smoothness value.
[0055] In the second aspect, an industrial Internet data security access device based on cloud-edge collaboration includes:
[0056] Access policy evaluation module: obtains access information in the historical period through the industrial Internet access log, analyzes and processes the access information, obtains unauthorized valid access, and evaluates the industrial Internet access control policy based on the unauthorized valid access to obtain the evaluation result;
[0057] Access data classification module: If the evaluation result is a strategy optimization signal, the user's access information in multiple historical periods of the historical cycle is obtained, and the access information in multiple historical periods is analyzed to obtain local open data;
[0058] Access policy optimization module: Analyze local open data in multiple historical periods within the historical cycle, output the policy optimization value, and generate an access permission table. Based on the access permission table, optimize the access control policy of the industrial Internet.
[0059] Optimize the test adjustment module: Based on the optimized access control strategy of the industrial Internet, obtain the user access decryption information within the test period through the industrial Internet access log, process the user access decryption information, obtain the priority access table, and based on the priority access table, improve the access efficiency of users when accessing data.
[0060] The beneficial effects of the present invention are as follows:
[0061] (1) The present invention obtains access information within a historical period through an industrial Internet access log, analyzes the access information within the historical period, determines invalid access in unauthorized access requests, and divides the historical period to obtain a historical period. By counting the number of invalid accesses corresponding to the historical period, the policy evaluation value of the industrial Internet access control policy within the historical period is calculated, thereby reflecting the security level of the industrial Internet access control policy within the historical period through the policy evaluation value;
[0062] (2) Based on the policy optimization signal, the present invention counts the access information of users in multiple historical periods of the historical cycle, and outputs the data access value, thereby evaluating the degree of openness of industrial Internet data through the data access value, completing the classification and identification of the degree of openness of industrial Internet data, obtaining local open data, analyzing and processing the access information of local open data in multiple historical periods of the historical cycle, and outputting the policy optimization value, thereby reflecting the degree of openness of local open data through the policy optimization value, comparing the policy optimization values, and obtaining the access permission table in descending order, and then using the access permission table as the basis for sorting, and adjusting the access permission of local open data accordingly by means of access decryption, so as to avoid the high frequency of unauthorized access to data, which leads to the security problem of industrial Internet data leakage;
[0063] (3) The present invention is based on the access control strategy optimized by the industrial Internet. It obtains the user access decryption information within the test period through the industrial Internet access log, analyzes and processes the user access decryption information within the test period, and outputs the access credit value, thereby comprehensively reflecting the overall smoothness and efficiency of the user's key input behavior during the entire test period, which is conducive to evaluating the user's access credit, and then based on the user's access credit, improves the user's access efficiency under the security access strategy, and solves the security problem of network jams caused by a large number of users accessing at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] The present invention will be further described below in conjunction with the accompanying drawings.
[0065] Figure 1 It is a flowchart of the steps of evaluating access control strategy of an industrial Internet data security access method based on cloud-edge collaboration of the present invention;
[0066] Figure 2 It is a flowchart of the steps of optimizing the access control strategy of an industrial Internet data security access method based on cloud-edge collaboration of the present invention;
[0067] Figure 3 It is a module diagram within an industrial Internet data security access system based on cloud-edge collaboration of the present invention. DETAILED DESCRIPTION
[0068] In order to make the technical means, creative features, objectives and effects achieved by the present invention easy to understand, the present invention is further explained below in conjunction with specific implementation methods.
[0069] Example 1
[0070] like Figure 1-2 As shown, a method for secure access to industrial Internet data based on cloud-edge collaboration according to an embodiment of the present invention includes:
[0071] Step 1: Obtain data access information in the historical period through the industrial Internet access log, where the data access information includes access requests, analyze and process the access requests, obtain unauthorized valid access and unauthorized invalid access, and evaluate the industrial Internet access control policy based on the unauthorized valid access to obtain the evaluation results;
[0072] The evaluation results include strategy optimization signals or strategy normal signals;
[0073] In some embodiments, authorized access requests in a historical period are classified and divided into authorized access requests and unauthorized access requests;
[0074] Divide the historical period into several historical time periods, obtain the number of unauthorized valid accesses in the historical time period, calculate the ratio of the number of unauthorized valid accesses in the historical time period to the total number of authorized access requests in the historical time period, and obtain the number of unauthorized valid accesses;
[0075] It should be noted that the total number of access requests in the historical period is obtained by adding the total number of authorized accesses and the total number of unauthorized accesses in the historical period;
[0076] The number of unauthorized valid times corresponding to all historical periods in the historical cycle is added and averaged to obtain the policy evaluation value;
[0077] It should be noted that the historical period division method is to divide the historical period into equal time intervals to obtain historical periods, and the duration of each historical period is equal;
[0078] The policy evaluation value is compared with the policy evaluation threshold. The process is as follows;
[0079] If the strategy evaluation value is greater than the strategy evaluation threshold, it means that there are many ineffective accesses in the historical period, and a strategy optimization signal is generated;
[0080] If the policy evaluation value is less than or equal to the policy evaluation threshold, it means that the number of ineffective accesses in the historical period is small, and a policy normal signal is generated;
[0081] The specific implementation plan of the embodiment of the present invention is: obtaining access information within a historical period through an industrial Internet access log, analyzing the access information within the historical period, determining ineffective access in unauthorized access requests, and dividing the historical period to obtain historical time periods, and calculating the policy evaluation value of the industrial Internet access control policy within the historical period by counting the number of ineffective accesses corresponding to the historical time periods, thereby reflecting the security level of the industrial Internet access control policy within the historical period through the policy evaluation value.
[0082] Example 2
[0083] like Figure 1-2 As shown, based on Example 1, a method for secure access to industrial Internet data based on cloud-edge collaboration described in an embodiment of the present invention includes:
[0084] Step 2: Based on the strategy optimization signal, the access information of users in multiple historical periods of the historical cycle is counted, wherein the access information includes access data, the access data is analyzed to obtain the number of accesses and the access continuity value, the number of accesses and the access continuity value are analyzed and processed, the data access value is output, and it is compared with the data access threshold to obtain the local open data;
[0085] In some embodiments, a historical period is arbitrarily extracted from a plurality of historical periods within the historical cycle, and access data of the user is obtained through the user key token within the historical period;
[0086] Based on the access data, the number of accesses to the access data in the historical period is obtained, and the ratio is calculated with the total number of authorized access requests in the historical period to obtain the number of accesses in the period;
[0087] The number of visits corresponding to all historical periods in the historical cycle is summed up and averaged to obtain the number of visits, and ;
[0088] For example, the historical period may be 7 days, 15 days or 30 days;
[0089] For example, if the historical period is 15 days long, the historical period is divided into five historical periods with equal time intervals, and each historical period is marked as historical period A, historical period B, historical period C, historical period D, and historical period E;
[0090] The number of accesses to the access data in the historical period A is 30 times, and the total number of authorized access requests in the historical period A is 150; the number of accesses to the access data in the historical period B is 28 times, and the total number of authorized access requests in the historical period B is 100; the number of accesses to the access data in the historical period C is 22 times, and the total number of authorized access requests in the historical period C is 200; the number of accesses to the access data in the historical period D is 45 times, and the total number of authorized access requests in the historical period D is 90; the number of accesses to the access data in the historical period E is 25 times, and the total number of authorized access requests in the historical period E is 180;
[0091] The number of visits in the historical period of A is 30, and the total number of authorized access requests in the historical period of A is 150. The number of visits in the period is 0.2. The number of visits in the historical period of B is 28, and the total number of authorized access requests in the historical period of B is 100. The number of visits in the period is 0.28. The number of visits in the historical period of C is 22, and the total number of authorized access requests in the historical period of C is 200. The number of visits in the period is 0.11. The number of visits in the historical period of D is 45, and the total number of authorized access requests in the historical period of D is 90. The number of visits in the period is 0.5. The number of visits in the historical period of E is 25, and the total number of authorized access requests in the historical period of E is 180. The number of visits in the period is 0.14 (rounded to two decimal places);
[0092] The average of the number of visits during the A historical period (0.2), the number of visits during the B historical period (0.28), the number of visits during the C historical period (0.11), the number of visits during the D historical period (0.5), and the number of visits during the E historical period (0.14) is calculated to be 0.246.
[0093] In the historical period, the interval time of access data is counted, the average is added and calculated, and the ratio is calculated with the length of the historical period to obtain the continuous value of the period;
[0094] Add the corresponding time period continuous values of all historical periods in the historical cycle and take the average to obtain the access continuous value, which is marked as ;
[0095] The number of visits Accessing consecutive values with Substituting into the formula: , calculate the data access value ,in, , is the preset scaling factor, and The value is 1.328. The value is 3.164 and the value is 0.0364;
[0096] It can be understood that the meaning of the data access value is: the number of users' accesses in each historical period of the historical cycle and the continuity of access behavior, combined with the frequency and continuity of users' access to data, reflects the degree of openness of the data. Specifically, if this value is larger, the frequency of users' access to data is higher and the continuity is stronger. On the contrary, if this value is smaller, the frequency of users' access to data is lower and the continuity is weaker, which is conducive to identifying the degree of openness of industrial Internet data;
[0097] The data access value is compared with the data access threshold as follows:
[0098] If the data access value is greater than or equal to the data access threshold, it means that the user accesses the data frequently and continuously, and the degree of openness of the industrial Internet data is relatively high, and a fully open signal is generated. The industrial Internet data that generates a fully open signal is marked as fully open data;
[0099] If the data access value is less than the data access threshold, it means that the user accesses the data less frequently and with less continuity, and the degree of openness of industrial Internet data is relatively low, so a partial open signal is generated, and the industrial Internet data corresponding to the partial open signal is marked as partial open data;
[0100] Step 3: Based on the local open signal, analyze the industrial Internet data in multiple historical periods within the historical cycle to obtain the signal generation interval and signal generation frequency, process the generation interval, generation frequency and number of visits, output the policy optimization value, and generate an access permission table. Based on the access permission table, complete the optimization of the industrial Internet access control strategy;
[0101] In some embodiments, when a local open signal is generated, a local open signal generation time point is obtained, adjacent local open signal generation time points are subtracted, an absolute value is taken, and a ratio is calculated with the historical time period to obtain a unit interval time length;
[0102] Add up all the unit interval durations and take the average to get the generation interval duration, which is marked as ;
[0103] Count the number of times the local open signal is generated, calculate the ratio of the number of times the local open signal is generated to the total number of times the signal is generated in the historical period, and get the signal generation frequency, which is marked as ;
[0104] It should be noted that the total number of signal generation in the historical period is obtained by adding the total number of partial open signal generation and the total number of fully open signal generation in the historical period;
[0105] Will generate interval time , signal generation frequency and number of visits Substituting into the formula: , calculate the strategy optimization value ,in, , , is the preset scaling factor, and The value is 3.312 and the value is 0.312. The value is 1.615. The value is 3.163 and the value is 0.316;
[0106] It can be explained that the meaning of the strategy optimization value is: by comprehensively analyzing the interval length of the local open signal generation, the number of local open signal generation, and the number of accesses of the industrial Internet data in each period of the historical cycle, it reflects the degree of local openness of the industrial Internet data. Specifically, if this value is larger, it means that the interval length of the local open signal generation of the industrial Internet data in each period of the historical cycle is longer, the number of generation is smaller, and the number of accesses is smaller, that is, the local open scope of the industrial Internet data in each period of the historical cycle is smaller, which reflects that the access rights to the industrial Internet data are higher;
[0107] Compare the policy optimization values corresponding to the data in the industrial Internet and arrange them in descending order to obtain an access rights table;
[0108] Based on the sorting of the access permission table, the access permission of the local open data is adjusted accordingly by access decryption;
[0109] The specific implementation plan of the embodiment of the present invention is: based on the policy optimization signal, the access information of users in multiple historical time periods of the historical cycle is counted, and the data access value is output, so as to evaluate the degree of openness of the industrial Internet data through the data access value, complete the classification and identification of the degree of openness of the industrial Internet data, obtain local open data, analyze and process the access information of the local open data in multiple historical time periods of the historical cycle, and output the policy optimization value, so as to reflect the degree of openness of the local open data through the policy optimization value, compare the policy optimization values, and obtain the access permission table in order from large to small, and then use the access permission table as the basis for sorting, and adjust the access permission of the local open data accordingly by means of access decryption, so as to avoid the high frequency of unauthorized access to data and the security problem of industrial Internet data leakage.
[0110] Example 3
[0111] like Figure 1-2 As shown, based on Example 1 and Example 2, an industrial Internet data security access method based on cloud-edge collaboration described in an embodiment of the present invention includes:
[0112] Step 4: Based on the access control strategy optimized by the Industrial Internet, obtain the user access decryption information within the test period through the Industrial Internet access log, where the user access decryption information includes the decryption duration and the decryption interval value. The decryption duration and the decryption interval value are processed and output to obtain the access credit value. Based on the access credit value, a priority access table is obtained, and based on the priority access table, the access efficiency of users accessing data is improved;
[0113] Specifically, the test cycle is divided into several decryption periods, and a decryption process is selected from multiple decryption periods in the test cycle for analysis. The analysis process is as follows:
[0114] Exemplarily, during the decryption process, the time for each digit of the key input by the user is obtained, and the ratio of the time for each digit of the key input by the user to the decryption period is calculated to obtain the sub-digit decryption period;
[0115] The sub-bit decryption time corresponding to each digit of the key input by the user is added and averaged to obtain the decryption time;
[0116] At the same time, during the decryption process, the interval time when the user inputs the adjacent digits of the key is obtained, and the ratio of the interval time when the user inputs the adjacent digits of the key is calculated with the decryption period to obtain the sub-digit interval time;
[0117] Add up all the sub-bit intervals and take the average to get the decryption interval value;
[0118] The decryption duration and the decryption interval value are added together to obtain the decryption fluency value;
[0119] The decryption fluency values corresponding to all decryption periods in the test cycle are added and averaged to obtain the access credit value;
[0120] It can be explained that the meaning of the access credit value is: the access credit value is obtained by summing up the decryption fluency values (obtained by adding the decryption duration and the decryption interval value) corresponding to all decryption periods in the test cycle and taking the average value. The decryption duration reflects the efficiency of the user in the process of decryption by inputting the key, and the decryption interval value reflects the pause time of the user in the process of decryption by inputting the key, which comprehensively reflects the overall fluency and efficiency of the user's key input behavior in the entire test cycle, which is conducive to evaluating the user's access credit, and then based on the user's access credit, improving the user's access efficiency under the security access policy;
[0121] Obtain the access credit values corresponding to all users in the test period, compare the access credit values corresponding to the users, sort them in ascending order of access credit values, and sort the users accordingly to obtain a priority access table;
[0122] Based on the priority access table, the number of key bits input by the priority users in the priority access table is reduced, the efficiency of user access to data is improved, and the security problem of network jamming caused by a large number of users accessing at the same time is solved;
[0123] The specific implementation method of the embodiment of the present invention is: based on the access control strategy optimized by the industrial Internet, the user access decryption information within the test period is obtained through the industrial Internet access log, and the user access decryption information within the test period is analyzed and processed to output an access credit value, thereby comprehensively reflecting the overall smoothness and efficiency of the user's key input behavior during the entire test period, which is conducive to evaluating the user's access credit, and then based on the user's access credit, improving the user's access efficiency under the security access policy, and solving the security problem of network jams caused by a large number of users accessing at the same time.
[0124] Example 4
[0125] like Figure 3 As shown, based on Example 1, Example 2 and Example 3, an industrial Internet data security access device based on cloud-edge collaboration described in an embodiment of the present invention includes:
[0126] Access policy evaluation module: obtains data access information in the historical period through the industrial Internet access log, analyzes and processes the data access information, obtains unauthorized valid access, and evaluates the industrial Internet access control policy based on the unauthorized valid access to obtain the evaluation result;
[0127] Access data classification module: If the evaluation result is a strategy optimization signal, the user's access information in multiple historical periods of the historical cycle is obtained, and the access information in multiple historical periods is analyzed to obtain local open data;
[0128] Access policy optimization module: Analyze local open data in multiple historical periods within the historical cycle, output the policy optimization value, and generate an access permission table. Based on the access permission table, optimize the access control policy of the industrial Internet.
[0129] Optimize the test adjustment module: Based on the optimized access control strategy of the industrial Internet, obtain the user access decryption information within the test period through the industrial Internet access log, process the user access decryption information, obtain the priority access table, and based on the priority access table, improve the access efficiency of users when accessing data.
[0130] The above shows and describes the basic principles, main features and advantages of the present invention. It should be understood by those skilled in the art that the present invention is not limited to the above embodiments. The above embodiments and descriptions are only for explaining the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention may have various changes and improvements, which fall within the scope of the present invention. The scope of protection of the present invention is defined by the attached claims and their equivalents.
Claims
1. A method for secure access to industrial Internet data based on cloud-edge collaboration, characterized in that: include: Step 1: Obtain data access information in the historical period through the industrial Internet access log, analyze and process the data access information, obtain unauthorized valid access, and evaluate the industrial Internet access control strategy based on the unauthorized valid access to obtain the evaluation result; Step 2: If the evaluation result is a strategy optimization signal, the user's access information in multiple historical periods of the historical cycle is obtained, and the access information in multiple historical periods is analyzed to obtain local open data; Step 3: Analyze local open data in multiple historical periods within the historical cycle, output the policy optimization value, and generate an access permission table. Based on the access permission table, optimize the access control policy for the industrial Internet. Step 4: Based on the access control strategy optimized by the Industrial Internet, obtain the user access decryption information within the test period through the Industrial Internet access log, process the user access decryption information, obtain the priority access table, and improve the access efficiency of users when accessing data based on the priority access table; The process of improving access efficiency when users access data is as follows: The decryption fluency values corresponding to all decryption periods in the test cycle are added and averaged to obtain the access credit value; Obtain the access credit values corresponding to all users in the test period, compare the access credit values corresponding to the users, sort them in ascending order of access credit values, and sort the users accordingly to obtain a priority access table; Based on the priority access table, reducing the number of key digits of the input key for the priority users in the priority access table; The test cycle is divided into several decryption periods. A decryption process is selected from multiple decryption periods in the test cycle for analysis. The analysis process is as follows: During the decryption process, the time for each digit of the key input by the user is obtained, and the ratio of the time for each digit of the key input by the user to the decryption period is calculated to obtain the sub-bit decryption time; The sub-bit decryption time corresponding to each digit of the key input by the user is added and averaged to obtain the decryption time; During the decryption process, the interval time when the user inputs the adjacent digits of the key is obtained, and the ratio of the interval time when the user inputs the adjacent digits of the key is calculated with the decryption period to obtain the sub-digit interval time; Add up all the sub-bit intervals and take the average to get the decryption interval value; The decryption duration and the decryption interval value are added together to obtain the decryption fluency value; The decryption fluency values corresponding to all decryption periods in the test cycle are added together and averaged to obtain the access credit value.
2. According to the method of secure access to industrial Internet data based on cloud-edge collaboration according to claim 1, it is characterized by: The evaluation results are obtained as follows: Classify the authorized access requests in the historical period into authorized access requests and unauthorized access requests; Divide the historical period into several historical time periods, obtain the number of unauthorized valid accesses in the historical time period, calculate the ratio of the number of unauthorized valid accesses in the historical time period to the total number of authorized access requests in the historical time period, and obtain the number of unauthorized valid accesses; The number of unauthorized valid times corresponding to all historical periods in the historical cycle is added and averaged to obtain the policy evaluation value; If the strategy evaluation value is greater than the strategy evaluation threshold, a strategy optimization signal is generated; If the policy evaluation value is less than or equal to the policy evaluation threshold, a policy normal signal is generated.
3. According to the method of secure access to industrial Internet data based on cloud-edge collaboration according to claim 1, it is characterized in that: The methods for obtaining local open data are: The number of visits Accessing consecutive values with Substituting into the formula: , calculate the data access value ,in, is the preset proportional coefficient; The data access value is compared with the data access threshold. If the data access value is less than the data access threshold, a local open signal is generated, and the industrial Internet data corresponding to the local open signal is marked as local open data.
4. According to the method of secure access to industrial Internet data based on cloud-edge collaboration according to claim 3, it is characterized in that: The number of visits is obtained as follows: Extracting any one historical period from multiple historical periods within the historical cycle, and obtaining the user's access data through the user key token within the historical period; Based on the access data, the number of accesses to the access data in the historical period is obtained, and the ratio is calculated with the total number of authorized access requests in the historical period to obtain the number of accesses in the period; The number of visits corresponding to all historical periods in the historical cycle is summed up and averaged to obtain the number of visits, and ; The way to access continuous values is: In the historical period, the interval time of access data is counted, the average is added and calculated, and the ratio is calculated with the length of the historical period to obtain the continuous value of the period; Add the corresponding time period continuous values of all historical periods in the historical cycle and take the average to obtain the access continuous value, which is marked as .
5. According to the method of secure access to industrial Internet data based on cloud-edge collaboration according to claim 1, it is characterized by: Based on the access rights table, the optimization of the industrial Internet access control strategy is completed. The optimization process is as follows: Compare the policy optimization values corresponding to the data in the industrial Internet and arrange them in descending order to obtain an access rights table; Based on the sorting of the access permission table, the access permission of the local open data is adjusted accordingly by access decryption.
6. According to the method of secure access to industrial Internet data based on cloud-edge collaboration according to claim 5, it is characterized in that: The strategy optimization value is obtained as follows: Will generate interval time , signal generation frequency and number of visits Substituting into the formula: , calculate the strategy optimization value ,in, is the preset scaling factor.
7. The method for secure access to industrial Internet data based on cloud-edge collaboration according to claim 6 is characterized in that: The generation interval duration is obtained as follows: Obtain the time point at which the local open signal is generated, make a difference between the adjacent local open signal generation time points, take the absolute value, and calculate the ratio with the historical time period to obtain the unit interval length; Add up all the unit interval durations and take the average to get the generation interval duration, which is marked as ; The signal generation frequency is obtained as follows: Count the number of times the local open signal is generated, calculate the ratio of the number of times the local open signal is generated to the total number of times the signal is generated in the historical period, and get the signal generation frequency, which is marked as .
8. An industrial Internet data security access device based on cloud-edge collaboration, characterized in that: The device comprises: Access policy evaluation module: obtains access information in the historical period through the industrial Internet access log, analyzes and processes the access information, obtains unauthorized valid access, and evaluates the industrial Internet access control policy based on the unauthorized valid access to obtain the evaluation result; Access data classification module: If the evaluation result is a strategy optimization signal, the user's access information in multiple historical periods of the historical cycle is obtained, and the access information in multiple historical periods is analyzed to obtain local open data; Access policy optimization module: Analyze local open data in multiple historical periods within the historical cycle, output the policy optimization value, and generate an access permission table. Based on the access permission table, optimize the access control policy of the industrial Internet. Optimize the test adjustment module: Based on the optimized access control strategy of the industrial Internet, obtain the user access decryption information within the test period through the industrial Internet access log, process the user access decryption information, obtain the priority access table, and improve the access efficiency of users when accessing data based on the priority access table; The process of improving access efficiency when users access data is as follows: The decryption fluency values corresponding to all decryption periods in the test cycle are added and averaged to obtain the access credit value; Obtain the access credit values corresponding to all users in the test period, compare the access credit values corresponding to the users, sort them in ascending order of access credit values, and sort the users accordingly to obtain a priority access table; Based on the priority access table, reducing the number of key digits of the input key for the priority users in the priority access table; The test cycle is divided into several decryption periods. A decryption process is selected from multiple decryption periods in the test cycle for analysis. The analysis process is as follows: During the decryption process, the time for each digit of the key input by the user is obtained, and the ratio of the time for each digit of the key input by the user to the decryption period is calculated to obtain the sub-bit decryption time; The sub-bit decryption time corresponding to each digit of the key input by the user is added and averaged to obtain the decryption time; During the decryption process, the interval time when the user inputs the adjacent digits of the key is obtained, and the ratio of the interval time when the user inputs the adjacent digits of the key is calculated with the decryption period to obtain the sub-digit interval time; Add up all the sub-bit intervals and take the average to get the decryption interval value; The decryption duration and the decryption interval value are added together to obtain the decryption fluency value; The decryption fluency values corresponding to all decryption periods in the test cycle are added together and averaged to obtain the access credit value.
Citation Information
Patent Citations
Safety access method and system based on industrial internet platform
CN118487847A
Systems And Methods Of Dynamically Adapting Security Certificate-Key Pair Generation
US20160099813A1