Industrial Control Host-based Encrypted Information Storage System and Its Method

By implementing a multi-level hardware and software verification mechanism on the industrial control host, the problem of the encryption system collapse after the key is stolen is solved, and high-security storage and access of encrypted information in the industrial control host is realized.

CN119783139BActive Publication Date: 2025-06-27TIANJIN ZHONGHUAN HENGDA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510264913.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-27
Estimated Expiration
2045-03-07

AI Technical Summary

Technical Problem

In the prior art, the encrypted information storage system of industrial control hosts has the problem that the encryption system collapses after the key is stolen and the attacker can easily obtain and tamper with sensitive information, which in turn causes serious damage to the industrial production process.

Method used

An encrypted information storage system based on an industrial control host is adopted, which includes a solid-state storage unit, an interactive signal unit, a hardware verification unit, a software verification unit and a storage information management unit. Through a multi-level hardware and software verification mechanism, secure storage and access of encrypted information is ensured.

Benefits of technology

Through a multi-level verification mechanism, it greatly increases the difficulty of illegal access, reduces the risk of data leakage and malicious attacks, and ensures the security of encrypted information in the industrial control host.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119783139B_ABST
    Figure CN119783139B_ABST
Patent Text Reader

Abstract

The present invention discloses an encrypted information storage system and method based on an industrial control host. The system includes a solid-state storage unit, an interaction signal unit, a hardware verification unit, a software verification unit, and a storage information management unit. The method is applicable to the above-mentioned encrypted information storage system based on an industrial control host to implement access rights to the industrial control host. The present invention greatly increases the difficulty of illegal access through a multi-level verification mechanism, reducing the risks of data leakage and malicious attacks. The interlock mechanism ensures that the system can maintain a high level of security under any circumstances. Even if a vulnerability occurs in a certain verification link, due to the existence of the interlock mechanism, illegal access cannot succeed. Encryption technology can effectively prevent data from being stolen or tampered with during storage and transmission. Even if an attacker obtains the encrypted conversion data, without the correct decryption key and verification information, the original data cannot be restored, thus protecting the security of the encrypted information in the industrial control host.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to an encrypted information storage system and method based on an industrial control host. Background Art

[0002] Security problems brought about by the development of the industrial Internet: The development of the industrial Internet has transformed the original discrete and isolated manufacturing equipment into interconnected intelligent equipment, but it has also brought a series of information security problems. The data of devices such as industrial control hosts connected to the industrial Internet is at risk of external attacks and internal snooping.

[0003] The following are the current situations and risks in the data storage of the existing industrial control systems:

[0004] 1. There are security hazards in the storage medium: When using mobile storage media such as USB flash drives to install software or store data, the information is stored naked, which is easily maliciously modified and may become a springboard for attacks, introducing the attacks into the industrial control host.

[0005] 2. The permission management method is not secure: Using the username / password method for permission management has a low security level, there is a risk of password leakage, and it is impossible to bind the operator's identity to the actual user.

[0006] 3. The data storage location is vulnerable to attacks: The permission data and sensitive data are directly stored in a general database, the attack target is clear, and there is a risk of data leakage after a long-term attack.

[0007] 4. Limitations of traditional encryption methods: For example, using the Basic Input / Output System (BIOS) to set a password for the hard disk has problems such as the password being easy to forget, the password being too simple, the need to input the password every time the computer is turned on, which is cumbersome, the data can still be recognized after the hard disk is transferred, and the password is easily cracked by hackers. Summary of the Invention

[0008] The purpose of the present invention is to solve the information security technical problem that if only a simple symmetric encryption algorithm is used, once the key is stolen, the entire encryption system will collapse instantly, and the attacker can easily obtain and tamper with sensitive information in the industrial control host, such as production process data, equipment operation parameters, etc., thereby causing serious damage to the industrial production process.

[0009] To achieve the above purpose, one of the technical solutions adopted by the present invention is: An encrypted information storage system based on an industrial control host, the system includes:

[0010] A solid-state storage unit, storing a solid-state PIN initial code set;

[0011] An interactive signal unit, used for communicating with a request end;

[0012] A hardware verification unit, configured with a preset hardware verification policy, the hardware verification policy responding to verification information input by a request end, the hardware verification policy including a number of hardware verification instructions and corresponding hardware verification conditions, the hardware verification unit determining corresponding hardware verification instructions according to the verification information, and sending the hardware verification instructions to the request end through an interaction signal unit to obtain hardware verification data, the hardware verification policy verifying the hardware verification data through corresponding hardware verification conditions, and generating first verification information according to the verification result;

[0013] A software verification unit, the software verification unit being configured with a preset software verification policy, the software verification policy being used to assign corresponding permission characteristics to the request end according to the first verification information;

[0014] A storage information management unit, the storage information management unit being configured with a number of encrypted information, different encrypted information being configured with corresponding permission characteristics, the storage information management unit configuring the access permission of the corresponding request end to the encrypted information according to the permission characteristics.

[0015] Further, the hardware verification conditions include a communication verification condition, a level verification condition, and a data verification condition. The communication verification condition is configured with a corresponding communication standard. If the feedback hardware verification data conforms to the communication representation, it is considered to meet the corresponding communication verification condition. The level verification condition is configured with a level mapping feature. If the feedback hardware verification data conforms to the level verification feature, it is considered to meet the corresponding level verification condition. The data verification condition includes a content recognition range and a corresponding verification calculation algorithm. The corresponding hardware verification data is calculated through the verification calculation algorithm to obtain a corresponding actual recognition value. If the actual recognition value falls within the corresponding content recognition range, it is considered to conform to the corresponding data verification condition.

[0016] Further, the hardware verification unit further includes a data conversion policy, the data conversion policy being configured with a number of data conversion conditions, each data conversion condition being indexed by a first conversion index value, retrieving the corresponding data conversion condition according to the first conversion index value, and processing the verification information according to the data conversion condition to generate conversion information.

[0017] Further, the first conversion index value is calculated through a verification index formula, and the verification index formula is configured as , , , ,wherein, is the first conversion index value, is the first communication factor, is the first level factor, is the first data factor, is the preset communication type weight, is the preset weight of the level type, is the preset weight of the data type, and there are , is the condition weight value of the th communication verification condition, is the verification result value of the th communication verification condition, is the total number of communication verification conditions corresponding to the hardware verification instruction, is the level weight value of the th level verification condition, is the level deviation function of the th level verification condition, is the feedback level value during the verification process, is the total number of level verification conditions corresponding to the hardware verification instruction, is the data weight value of the th data verification condition, is the data content similarity of the th data verification condition, is the data format similarity of the th data verification condition, is the total number of data verification conditions corresponding to the hardware verification instruction.

[0018] Furthermore, the hardware verification unit further includes an encryption configuration policy, the encryption configuration policy includes an encryption algorithm, the encryption configuration policy generates an encryption factor according to a first communication factor, a first level factor, and a first data factor, and configures the encryption factor in the encryption algorithm to process the conversion information to generate encrypted conversion data.

[0019] Furthermore, the hardware verification unit further includes a position generation policy and a window generation policy. The position generation policy is used to generate a verification position, and the window generation policy is used to generate a verification window. The verification position points to the initial position of the solid-state PIN initial code set during verification. The verification window is used to determine a verification PIN code as a reference from the solid-state PIN initial code set during verification. The hardware verification unit compares the encrypted conversion data with the verification PIN code used as a reference to generate a verification result.

[0020] Furthermore, the position generation policy includes initial position starting point data of a plurality of solid-state PIN initial code sets and corresponding position generation conditions;

[0021] The position generation condition is configured with a corresponding secure transmission standard. If the transmission data of the solid-state storage unit conforms to the secure transmission characterization, it is regarded as meeting the corresponding secure transmission verification condition, and then the corresponding verification position starting data is generated. Compare the verification position starting data with the initial position starting data of the solid-state PIN initial code set. If the comparison is consistent, the initial position of the solid-state PIN initial code set is successfully determined;

[0022] The window generation strategy retrieves the initial verification window from a preset window information table according to the initial position of the solid-state PIN initial code set, and extracts the conversion index condition in the conversion information through the verification feature extraction sub-algorithm. Process the initial verification window according to the conversion index condition to generate a conversion verification window, and send the conversion verification window to a pre-configured window mirror to determine the verification window in the solid-state PIN initial code set.

[0023] Further, when the generation of the first verification information needs to meet the first verification information generation condition, the first verification information is obtained through the first verification information calculation formula;

[0024] The first verification information generation condition includes a verification times condition and a verification matching degree condition;

[0025] The verification times condition is: the verification times of the communication verification condition is not greater than the preset times, the verification times of the level verification condition is not greater than the preset times, and the verification times of the data verification condition is not greater than the preset times;

[0026] The verification matching degree condition is: for the communication verification condition, if the communication encryption conversion data completely conforms to the communication characterization, the matching degree is 100%; if there is a deviation in the communication encryption conversion data format or communication protocol that exceeds the preset deviation range, the matching degree is set according to the deviation degree, and the matching degree is 90%;

[0027] For the level verification condition: if the level encryption conversion data completely conforms to the level verification feature, the matching degree is 100%; if the level encryption conversion data fluctuates within the allowable error range, the matching degree is determined according to the fluctuation degree, and the matching degree is 90%;

[0028] For the data verification condition, compare according to the proximity of the encryption conversion data to the central value of the content recognition range. If the encryption conversion data is within ±5% of the central value of the preset content recognition range, the matching degree is 90%; if it is close to the boundary but still within the range, the matching degree is 90%;

[0029] The first verification information calculation formula is:

[0030] ,

[0031] Among them, is the first verification information; is the verification times; is the maximum allowable verification times; is the weight of the verification times; is the verification matching degree; is the weight of the verification matching degree.

[0032] Further, the software verification strategy includes several software verification data and their corresponding software verification conditions;

[0033] The software verification conditions include the first verification information verification condition and the software input window verification condition;

[0034] The first verification information verification condition is configured with a corresponding first verification information verification standard. If the data of the first verification information conforms to the information verification characterization, it is regarded as meeting the corresponding first verification information verification condition;

[0035] The first verification information verification standard is ;

[0036] The software input window verification condition is configured with a corresponding window verification standard. If the PIN input code data input in the software input window conforms to the window verification characterization, it is regarded as meeting the corresponding software input window verification condition;

[0037] The software input window verification standard is to perform a preset hash operation on the PIN input code and the verification PIN code to obtain the PIN input code hash value and the verification PIN code hash value, and the PIN input code hash value and the verification PIN code hash value need to be compared and consistent.

[0038] Another technical solution adopted by the present invention is: an encrypted information storage method, which is applicable to the above-mentioned encrypted information storage system based on an industrial control host to implement the access right to the industrial control host. The method includes:

[0039] S1. The user connects the solid-state storage unit to the industrial control host through an interface to complete the storage of the solid-state PIN initial code set, and the solid-state PIN initial code set is stored in the storage information management unit;

[0040] Through the position generation strategy, if the secure transmission is completed, the initial position of the solid-state PIN initial code set is successfully determined;

[0041] If the secure transmission is not completed, a reminder page pops up on the external display of the industrial control host;

[0042] S2. Through the window generation strategy, based on the initial position of the solid-state PIN initial code set in S1, search for the corresponding initial verification window in the preset window information table, and use the verification feature extraction sub-algorithm to process the conversion information. Process the initial verification window according to the extracted conversion index conditions, and send the conversion verification window to a pre-configured window mirror. The window mirror will match the conversion verification window with the solid-state PIN initial code set to determine the verification window. Then, the solid-state PIN initial code within the verification window area serves as the reference verification PIN code;

[0043] S3. Obtain encrypted conversion data through the data conversion strategy and the encryption configuration strategy;

[0044] S4. Use the hardware verification unit to compare the encrypted conversion data in S3 with the reference verification PIN code in S2 for data integrity. When the encrypted conversion data and the reference verification PIN code match, the verification result passes;

[0045] S5. Substitute the encrypted conversion data in S3 into the first verification information generation condition, calculate the first verification information, and send it to the software verification unit;

[0046] S6. If the first verification information meets the first verification information verification standard then trigger the software input window verification condition in the software verification;

[0047] S7. Enter the PIN input code in the software input window. Perform a preset hash operation on the PIN input code and the verification PIN code according to the software input window verification standard to obtain the PIN input code hash value and the verification PIN code hash value. When the PIN input code hash value and the verification PIN code hash value match, the verification result passes;

[0048] S8. According to the verification results of S4 and S7, control the access permission to the encrypted information through the storage information management unit;

[0049] If the verification results of S4 and S7 both pass, grant the access permission to the industrial control host;

[0050] Otherwise, reject the access to complete the dynamic interlock of the hardware verification unit and the software verification unit for the encrypted information.

[0051] Compared with the prior art, the present invention has the following beneficial effects:

[0052] 1. From the secure transmission verification of the solid-state PIN initial code set, to the data integrity comparison of the encrypted conversion data and the verification PIN code of the benchmark, and then to the calculation of the first verification information and the hash operation comparison of the window verification conditions, each step provides security for the system. This multi-level verification mechanism greatly increases the difficulty of illegal access and reduces the risks of data leakage and malicious attacks. For an attacker to break through the multiple layers of verification, they need to master the PIN code, crack the hash operation, and bypass multiple verification conditions simultaneously, which is almost impossible in actual operation.

[0053] 2. The dynamic interlock mechanism of the hardware verification unit and the software verification unit further enhances the security of the system. Access permissions are only granted when all conditions of the hardware verification and software verification are met. This interlock mechanism ensures that the system can maintain a high level of security under any circumstances. Even if there is a vulnerability in a certain verification link, due to the existence of the interlock mechanism, illegal access will not succeed. If an attacker attempts to obtain access permissions by tampering with the software verification result, but the hardware verification unit fails, the system will still deny access.

[0054] 3. The encrypted conversion data is obtained through the data conversion strategy and the encryption configuration strategy, which enables the information stored in the system to exist in an encrypted form. Encryption technology can effectively prevent data from being stolen or tampered with during storage and transmission. Even if an attacker obtains the encrypted conversion data, without the correct decryption key and verification information, they cannot restore the original data, thus protecting the security of the encrypted information in the industrial control host. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 It is a schematic flowchart of the method for storing encrypted information based on an industrial control host according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] Next, the technical solutions in the embodiments of the encrypted information storage system and method based on an industrial control host provided by the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0057] Embodiment 1

[0058] An encrypted information storage system based on an industrial control host, the system includes: a solid-state storage unit storing a solid-state PIN initial code set.

[0059] Specifically, compared with traditional storage methods, the solid-state storage unit itself has better physical stability and is not easily disturbed by external environments such as magnetic fields and vibrations. It can effectively reduce the risk of leakage of the PIN initial code set due to physical damage. At the same time, its internal storage structure is relatively closed and difficult to be directly accessed illegally from the outside, providing a reliable physical isolation protection barrier for the PIN initial code set. At the same time, when the system performs the verification process, it can quickly retrieve the solid-state PIN initial code set, reduce the verification waiting time caused by data reading delays, make the entire hardware verification link more efficient and smooth, and improve the timeliness of the system response request end, especially in the scenario where the industrial control host has high real-time requirements, fast PIN code set acquisition can ensure business continuity and avoid system freezes or delays caused by slow verification. Solid-state storage units usually have high error correction capabilities. Even in the case of a certain degree of data error or slight damage, the stored PIN initial code set can still be accurately restored to ensure that the verification process is not disturbed by data integrity issues, and ensure that the basic code values ​​relied on by subsequent links such as hardware verification units and software verification units are accurate and correct, thereby maintaining the stable operation of the entire encrypted information storage system. As an independent storage module, the solid-state storage unit can be easily integrated into the industrial control host architecture and work closely with the hardware verification unit, interactive signal unit, etc. During system design and upgrade, it is convenient to uniformly plan and maintain the storage strategy of the PIN initial code set, update the code set, optimize the storage layout and other operations, thereby reducing system complexity and improving maintainability.

[0060] The system also includes an interactive signal unit for communicating with the requesting end.

[0061] Specifically, the interactive signal unit ensures that all kinds of instructions and data can be transmitted accurately and timely between the system and the requesting end. Whether it is the verification information required by the hardware verification unit or the permission granting result fed back by the software verification unit, it relies on the stable transmission of the interactive signal unit to avoid information blocking and make the entire verification and authorization process seamless. When the requesting end initiates an access request, the interactive signal unit can quickly deliver the request to each key unit of the system, and at the same time immediately transmit the system's processing progress and results back to the requesting end. For example, when the hardware verification fails, the requesting end is informed of the cause of the error in a timely manner, so that the operator can quickly adjust the strategy and improve the overall real-time interactive experience of the system. With its communication function, users can monitor the interactive data between the requesting end and the system in real time. When a fault or abnormality occurs, by analyzing the communication log recorded by the interactive signal unit, the root cause of the problem can be accurately located, whether it is a network connection failure, data transmission error, or a requesting end compatibility problem, etc., greatly improving the efficiency of system debugging and maintenance.

[0062] The system further includes a hardware verification unit configured with a preset hardware verification policy. The hardware verification policy responds to verification information input by a requesting end. The hardware verification policy includes a number of hardware verification instructions and corresponding hardware verification conditions. The hardware verification unit determines the corresponding hardware verification instruction according to the verification information, and sends the hardware verification instruction to the requesting end through an interaction signal unit to obtain hardware verification data. The hardware verification policy verifies the hardware verification data through the corresponding hardware verification conditions and generates first verification information according to the verification result.

[0063] Specifically, the hardware verification unit can quickly determine the corresponding hardware verification instruction according to the input verification information. Different verification instructions can be generated for different verification information, avoiding blind attempts of various instructions, saving verification time, and ensuring verification efficiency. The first verification information generated by the hardware verification unit can provide an accurate hardware verification result for the software verification unit, ensuring that the continuous input of verification information is not allowed, obtaining the solid-state PIN initial code set, isolating the verification information and the solid-state PIN initial code set through the hardware verification instruction, verifying the trust level of the requesting end, and preventing external attack devices from accessing to obtain key information. At the same time, it enables the software verification unit to conduct more in-depth verification and analysis on this basis, realizing the collaborative work and comprehensive verification of software and hardware.

[0064] Further, the hardware verification conditions include a communication verification condition, a level verification condition, and a data verification condition. The communication verification condition is configured with a corresponding communication standard. If the feedback hardware verification data conforms to the communication representation, it is considered to meet the corresponding communication verification condition.

[0065] Specifically, the communication standard can be any one of the RS-232 or RS-485 communication standards. Among them, when the RS-232 communication standard is selected, it is used for communication between an industrial control host and external devices, specifying signal levels, data formats (start bit, data bit, parity bit, stop bit), transmission rate, etc. In this application, its signal level uses negative logic, -3V to -15V represents logic "1", and +3V to +15V represents logic "0".

[0066] When the RS-485 communication standard is selected, multiple devices are supported to communicate on the bus at this time. It has the advantages of strong anti-interference ability and long transmission distance. In this application, its signal level uses negative logic, -2V to -6V represents logic "1", and +2V to +6V represents logic "0". Its interface signal level is lower than that of RS-232-C, and it is not easy to damage the chips of the interface circuit.

[0067] By configuring the corresponding communication standards, it is possible to ensure that data transmission and interaction between hardware devices follow predetermined rules, reducing problems such as data transmission errors, loss, or out-of-order, and ensuring the accuracy of communication content. In network communication, following specific communication protocol standards can ensure that data packets are correctly sent, received, and parsed.

[0068] Furthermore, the level verification condition is configured with a level mapping feature. If the feedback hardware verification data conforms to the level verification feature, it is considered to meet the corresponding level verification condition. Implementing a clear level mapping relationship helps the receiving end accurately interpret the signal sent by the sending end, thus avoiding misjudgment or distortion of the signal during transmission.

[0069] Specifically, whether the feedback hardware verification data conforms to the level mapping feature can be determined by using a comparator, a gate circuit, or a processor.

[0070] When using a comparator, the level of the feedback hardware verification data is used as one input of the comparator, and the other input is connected to a known reference level. When the voltage difference between the two input ports exceeds the threshold voltage of the comparator, the output port will generate a high-level or low-level signal to determine whether the level of the verification data conforms to the expected level verification feature. For example, in this invention application, to detect whether a signal is high level, the signal can be connected to one input terminal of the comparator, and the other input terminal of the comparator is connected to a determined high-level reference voltage. If the output of the comparator is high level, it indicates that the feedback hardware verification data conforms to the high-level verification feature.

[0071] When using a gate circuit, the level signal to be detected is used as one input signal of the gate circuit, and the other input signal is connected to a known level signal or voltage reference source, and then judged according to the output signal of the gate circuit. For example, in this invention application, the AND gate circuit outputs a high level only when all input signals are high level; the OR gate circuit outputs a high level as long as one input signal is high level. Through this logical relationship, it can be judged whether the level of the hardware verification data meets the specific level verification feature.

[0072] When using a processor, the hardware system needs to include a microcontroller or a processor. The analog level signal can be converted into a digital value through its built-in analog-to-digital converter (ADC), and then in the software, it is judged whether the hardware verification data conforms to the level verification feature according to the preset level range or threshold. The industrial control main chip reads the voltage value through the GPIO pin and compares it with the internally set threshold. If it is higher than the threshold, it is judged as high level, and if it is lower than the threshold, it is judged as low level.

[0073] Further, the data verification conditions include a content recognition range and a corresponding verification calculation algorithm. The corresponding hardware verification data is calculated through the verification calculation algorithm to obtain the corresponding actual recognition value. If the actual recognition value falls within the corresponding content recognition range, it is considered to meet the corresponding data verification conditions.

[0074] If the actual recognition value does not fall within the corresponding content recognition range, it may mean that the data has been in error or tampered with during transmission or processing. Discover and take measures in a timely manner to ensure the authenticity and reliability of the data. In the encryption system of this application, the verification calculation algorithm can be used to detect whether the data has been illegally modified. Furthermore, it can check the accuracy and integrity of the data, ensure that the data is within a reasonable range and conforms to the expected format and logic, provide a reliable basis for the subsequent processing and decision-making of the system, and avoid system crashes or incorrect operations caused by data errors. The accurate verification of the data in the encryption system can ensure the safe and correct execution of the verification.

[0075] The present invention provides an accurate basis for judging whether the communication is normal through a clear communication representation. If the feedback hardware verification data conforms to the communication representation, it indicates that the communication process is stable and the data transmission is accurate, reducing system errors and data loss caused by communication failures; the level mapping feature defines the conversion relationship and standard between different levels, ensuring that the signal will not be distorted or lost due to level mismatch during transmission and processing; the content recognition range and the verification calculation algorithm provide a quantitative standard for judging the correctness of the data. Only when the actual recognition value falls within the corresponding content recognition range is the data considered to meet the requirements, effectively avoiding data errors and misjudgments. That is, the reliability of the device is further verified through these three dimensions of communication verification, level verification, and data verification, and external attack devices are prevented from accessing again.

[0076] Further, the hardware verification unit further includes a data conversion strategy. The data conversion strategy is configured with several data conversion conditions. Each data conversion condition is indexed by a first conversion index value. The corresponding data conversion condition is retrieved according to the first conversion index value, and the verification information is processed according to the data conversion condition to generate conversion information. By configuring the data conversion conditions and retrieving and applying them with the first conversion index value as the index, flexible and efficient data processing can be achieved, ensuring the accuracy and reliability of the hardware verification, completing the separation and protection of the verification information and the verification result inside the device again, preventing unexpected interactions and influences between them and other parts of the device; making them in a relatively independent and secure environment, reducing the risk of damage or leakage that may be caused by external attacks or internal failures, preventing attackers or unauthorized personnel from inferring the verification information from the known verification results, or calculating the verification results from the verification information, so as to obtain sensitive information inside the device or bypass the security verification mechanism.

[0077] Further, the first conversion index value is calculated by a verification index formula, and the verification index formula is configured as , , , , where is the first conversion index value, is the first communication factor, is the first level factor, is the first data factor, is the preset communication type weight, is the preset level type weight, is the preset data type weight, and there is , is the condition weight value of the th communication verification condition, is the verification result value of the th communication verification condition, is the total number of communication verification conditions corresponding to the hardware verification instruction, is the level weight value of the th level verification condition, is the level deviation function of the th level verification condition, is the feedback level value during the verification process, is the total number of level verification conditions corresponding to the hardware verification instruction, is the data weight value of the th data verification condition, is the data content similarity of the th data verification condition, is the data format similarity of the th data verification condition, is the total number of data verification conditions corresponding to the hardware verification instruction.

[0078] Specifically, during the process of converting verification information into conversion information in other forms, the first conversion index value is calculated through the verification index formula, making the first conversion index value not deterministic and predictable, ensuring that the verification information and the conversion information are in a strictly isolated state within the device or system, preventing unnecessary interactions and interferences between them and with other irrelevant information. With a high degree of uncertainty, it increases the difficulty for attackers to obtain the original verification information. Also, ensuring that the verification information and the conversion information are in a strictly isolated state within the device or system, preventing unnecessary interactions and interferences between them and with other irrelevant information, and reducing information leakage and error propagation caused by incomplete or inaccurate isolation means that, on the premise of ensuring the above-mentioned uncertainty and isolation accuracy, the entire system can still effectively execute the verification process, that is, it can accurately determine whether the verification result meets the expectations based on the verification information and the conversion information, and stably and reliably complete the verification work of the hardware verification information.

[0079] Furthermore, the hardware verification unit further includes an encryption configuration policy. The encryption configuration policy includes an encryption algorithm. The encryption configuration policy generates an encryption factor based on a first communication factor, a first level factor, and a first data factor, and configures the encryption factor in the encryption algorithm to process the conversion information to generate encrypted conversion data. Through the encryption configuration policy, the generated encryption factor and the encryption algorithm encrypt the data, making it difficult for attackers to easily interpret the data content. Without the correct encryption factor and knowledge of the corresponding encryption algorithm, even if an attacker obtains the encrypted conversion data, it is difficult to restore the original conversion information, thus ensuring the integrity and authenticity of the data. At the same time, the encrypted conversion data can be effectively managed and verified within the storage information management unit, facilitating the integration of the system and the improvement of the overall security.

[0080] Furthermore, the hardware verification unit further includes a location generation policy and a window generation policy. The location generation policy is used to generate a verification location, and the window generation policy is used to generate a verification window. The verification location points to the initial position of the solid-state PIN initial code set during verification, and the verification window is used to determine the verification PIN code as a reference from the solid-state PIN initial code set during verification. The hardware verification unit compares the encrypted conversion data with the verification PIN code as a reference to generate a verification result.

[0081] Specifically, the position generation strategy defines the initial position of the solid-state PIN initial code set during verification. This is like determining from which page to start searching for a password in a password book, avoiding blindly searching through the entire code set. The obtained reference verification PIN code is uncertain, increasing the difficulty of reverse-obtaining the solid-state PIN initial code; at the same time, reducing the possibility of verification errors; the window generation strategy generates a verification window for determining the verification PIN code as a reference. This enables the verification process to focus within a specific and targeted code set range, ensuring that the selected verification PIN code is a valid code that meets the current verification requirements.

[0082] Specifically, the position generation strategy includes the initial position starting point data of several solid-state PIN initial code sets and the corresponding position generation conditions;

[0083] The position generation conditions are configured with corresponding secure transmission standards. If the transmission data of the solid-state storage unit conforms to the secure transmission representation, it is considered to meet the corresponding secure transmission verification conditions, and then the corresponding verification position starting point data is generated. Compare the verification position starting point data with the initial position starting point data of the solid-state PIN initial code set. If the comparison is consistent, the initial position of the solid-state PIN initial code set is successfully determined.

[0084] The window generation strategy retrieves the initial verification window from a preset window information table according to the initial position of the solid-state PIN initial code set, and extracts the conversion index condition in the conversion information through the verification feature extraction sub-algorithm. Process the initial verification window according to the conversion index condition to generate a conversion verification window, and send the conversion verification window to a pre-configured window mirror to determine the verification window in the solid-state PIN initial code set. Make the means of determining the initial position and the window different. The conversion verification window is generated according to the characteristics of the initial position and the conversion information, and has randomness. The window mirror makes the generated actual verification window unable to be known externally, and thus the solid-state PIN initial code set cannot be known.

[0085] Specifically, the preset window information table includes parameters such as the size and starting position of the window; the verification feature extraction sub-algorithm is used to extract the conversion index condition from the conversion information, and this conversion index condition will be used to process the initial verification window; the window mirror can be a pre-configured tool or module for determining the final verification window in the solid-state PIN initial code set according to the conversion verification window.

[0086] Furthermore, when the generation of the first verification information needs to meet the first verification information generation conditions, the first verification information is obtained through the first verification information calculation formula;

[0087] The first verification information generation conditions include verification times conditions and verification matching degree conditions;

[0088] The verification times condition is as follows: the verification times of the communication verification condition is not greater than the preset times, the verification times of the level verification condition is not greater than the preset times, and the verification times of the data verification condition is not greater than the preset times;

[0089] Specifically, the preset times can be set according to the user. For example, the preset times is 3 times.

[0090] The verification matching degree condition is as follows: for the communication verification condition, if the communication encryption conversion data completely conforms to the communication representation, the matching degree is 100%; if there is a deviation amplitude of the communication encryption conversion data format or communication protocol exceeding the preset deviation range, the matching degree is set according to the deviation degree, and the matching degree is 90%;

[0091] Specifically, the preset deviation range is set according to the user. For example, the preset deviation range is that the deviation range of data transmission delay is within ±10 milliseconds.

[0092] For the level verification condition: if the level encryption conversion data completely conforms to the level verification feature, the matching degree is 100%; if the level encryption conversion data fluctuates within the allowable error range, the matching degree is determined according to the fluctuation degree, and the matching degree is 90%;

[0093] For the data verification condition, it is compared according to the proximity of the encryption conversion data to the central value of the content recognition range. If the encryption conversion data is within ±5% of the central value of the preset content recognition range, the matching degree is 90%; if it is close to the boundary but still within the range, the matching degree is 90%;

[0094] The calculation formula of the first verification information is:

[0095] ,

[0096] where is the first verification information; is the verification times; is the maximum allowable verification times; is the weight of the verification times; is the verification matching degree; is the weight of the verification matching degree.

[0097] Specifically, the verification times, the maximum allowable verification times, the weight of the verification times, the verification matching degree, and the weight of the verification matching degree can all be set according to the user; for example is 5 times, is 0.5, is 0.5.

[0098] Specifically, by formulating detailed matching degree measurement criteria for communication verification conditions, level verification conditions, and data verification conditions respectively, the compliance degree of hardware verification data with preset conditions can be comprehensively and accurately evaluated. In communication verification, not only the ideal situation of complete compliance with communication representations is considered, but also the slight deviations in format or protocol are quantitatively evaluated. This refined approach helps to more accurately grasp the actual state of the hardware. For level verification, considering the situation where data fluctuates within the allowable error range, the matching degree is reasonably set to avoid over-negating the hardware performance due to minor fluctuations. In terms of data verification, determining the matching degree based on the proximity of the encrypted conversion data to the central value of the content recognition range can more precisely reflect the effectiveness of the data. At the same time, if only strict verification criteria are adopted, that is, as long as there is a little non-compliance with the preset conditions, the hardware verification is determined to fail, it may lead to misjudgment of some hardware that can actually still work properly. By setting different degrees of matching degrees and comprehensively considering the number of verification times, small defects of the hardware and accidental mistakes in the verification process can be tolerated to a certain extent, avoiding overly strict verification. For example, in data verification, when the encrypted conversion data is close to the boundary of the content recognition range but still within the range, a matching degree of 90% is given instead of directly determining it as unqualified, so as to avoid frequently rejecting the hardware due to minor fluctuations in the data.

[0099] The system further includes a software verification unit, and the software verification unit is configured with a preset software verification strategy, and the software verification strategy is used to assign corresponding permission characteristics to the requesting end according to the first verification information. The software verification conditions are divided into the first verification information verification condition and the window verification condition, and the hardware-related information is verified from different perspectives to achieve hierarchical verification guarantee.

[0100] Specifically, the software verification strategy includes a number of software verification data and their corresponding software verification conditions;

[0101] The software verification conditions include the first verification information verification condition and the software input window verification condition;

[0102] The first verification information verification condition is configured with a corresponding first verification information verification standard. If the data of the first verification information conforms to the information verification representation, it is considered to meet the corresponding first verification information verification condition;

[0103] The first verification information verification standard is 。

[0104] Specifically, a clear numerical range is set through the first verification information verification standard, avoiding overly loose or strict verification. By requiring the first verification information to be between 0.45 and 0.875, it is possible to screen out cases with good comprehensive performance in terms of matching degree and verification times during the hardware verification process. The setting of this range can effectively exclude cases with too low hardware verification matching degree or too many verification times, thereby improving the accuracy of software verification in judging the hardware state.

[0105] The software input window verification condition is configured with a corresponding window verification standard. If the PIN input code data entered in the software input window conforms to the window verification representation, it is considered to meet the corresponding software input window verification condition;

[0106] The software input window verification standard is to perform a preset hash operation on the PIN input code and the verification PIN code to obtain the PIN input code hash value and the verification PIN code hash value, and the PIN input code hash value and the verification PIN code hash value need to be compared and consistent.

[0107] Specifically, a hash operation is used in the software input window verification condition to compare the PIN input code and the verification PIN code. The hash operation has the characteristics of one-wayness and collision resistance, which means that it is difficult to reverse the original PIN code from the hash value, and the probability of different PIN codes generating the same hash value is extremely low. Therefore, by comparing the hash values to verify the PIN code, it can effectively prevent the PIN code from being stolen or tampered with during the verification process, greatly improving the security and accuracy of PIN code verification.

[0108] The system further includes a storage information management unit. The storage information management unit is configured with a number of encrypted information, and different encrypted information is configured with corresponding permission characteristics. The storage information management unit configures the access permission of the corresponding request end to the encrypted information according to the permission characteristics.

[0109] Specifically, by configuring permission characteristics for different encrypted information, the storage information management unit can achieve hierarchical access control. This means that only the request end with the corresponding permission can access specific encrypted information, thereby effectively preventing unauthorized access and data leakage. In an enterprise data storage system, highly confidential business secret files can be set to be accessible only by senior management, and ordinary employees cannot obtain these sensitive information, greatly reducing the risk of data leakage.

[0110] The information itself is already in an encrypted state, and combined with permission control, it provides double protection for the data. Even if an attacker manages to obtain the storage medium, without the correct access permission and decryption key, they cannot understand the content of the encrypted information.

[0111] Embodiment 2

[0112] Such asFigure 1 As shown in the figure, an encrypted information storage method, which is applicable to the encrypted information storage system based on an industrial control host described in the above-mentioned Embodiment 1 to implement the access permission to the industrial control host. The method includes:

[0113] S1. The user connects the solid-state storage unit to the industrial control host through an interface to complete the storage of the solid-state PIN initial code set, and the solid-state PIN initial code set is stored in the storage information management unit;

[0114] Through the position generation strategy, if the secure transmission is completed, the initial position of the solid-state PIN initial code set is successfully determined;

[0115] If the secure transmission is not completed, a reminder page pops up on the external display of the industrial control host;

[0116] S2. Through the window generation strategy, according to the initial position of the solid-state PIN initial code set in S1, find the corresponding initial verification window in the preset window information table, and use the verification feature extraction sub-algorithm to process the conversion information. According to the extracted conversion index condition, process the initial verification window, and send the conversion verification window to the pre-configured window mirror. The window mirror will match the conversion verification window with the solid-state PIN initial code set to determine the verification window, and the solid-state PIN initial code within the verification window area is used as the reference verification PIN code;

[0117] Specifically, if the solid-state PIN initial code set is stored in a certain area of the memory in a certain order, the initial position can be a memory address or an index value. Assume that the index corresponding to the initial position is i, and find the record corresponding to the index in the window information table, which contains the parameters of the initial verification window, such as the window size i (assumed to be m code elements) and the starting position, etc.

[0118] The conversion information can be a data packet containing the modified password and high security level. The algorithm extracts the conversion index condition that needs to shift the verification window to the left by m code elements from it.

[0119] When the conversion index condition is a translation operation, translate the initial verification window in the specified direction and distance. For example, if the starting position of the initial verification window is p and the size is n, and the conversion index condition is to shift to the left by m code elements, then the starting position of the conversion verification window becomes p - m, and the size remains n. That is, when the conversion index condition involves a change in the window size, such as expanding the window size to k times the original, then the new window size is n * k, and the starting position is adjusted as needed.

[0120] The window imager searches for a region in the solid-state PIN initial code set that corresponds to the start position and size of the conversion verification window, and this region is the finally determined verification window. It will be used for subsequent PIN code verification and other operations.

[0121] S3. Obtain encrypted conversion data through the data conversion strategy and the encryption configuration strategy;

[0122] S4. Use the hardware verification unit to compare the encrypted conversion data in S3 with the reference verification PIN code in S2. When the encrypted conversion data and the reference verification PIN code match, the verification result passes;

[0123] S5. Substitute the encrypted conversion data of S3 into the first verification information generation condition, calculate the first verification information, and send it to the software verification unit;

[0124] S6. If the first verification information meets the first verification information verification standard then trigger the software input window verification condition in the software verification;

[0125] S7. Input a PIN input code in the software input window, perform a preset hash operation on the PIN input code and the verification PIN code according to the software input window verification standard to obtain a PIN input code hash value and a verification PIN code hash value. When the PIN input code hash value and the verification PIN code hash value match, the verification result passes;

[0126] S8. According to the verification results of S4 and S7, control the access permission to the encrypted information through the storage information management unit;

[0127] If the verification results of S4 and S7 both pass, grant the access permission to the industrial control host;

[0128] Otherwise, reject the access to complete the dynamic interlock of the hardware verification unit and the software verification unit for the encrypted information.

[0129] The above has described an embodiment of the present invention in detail, but the content is only the preferred embodiment of the present invention and cannot be considered as limiting the implementation scope of the present invention. All equivalent changes and improvements made according to the scope of the present invention application should still fall within the patent coverage scope of the present invention.

Claims

1. An encrypted information storage system based on an industrial control host, characterized in that: The system includes: A solid-state storage unit storing a solid-state PIN initial code set; An interactive signal unit, used for communicating with the requesting end; A hardware verification unit is configured with a preset hardware verification strategy, the hardware verification strategy responds to the verification information input by the requesting end, the hardware verification strategy includes a plurality of hardware verification instructions and corresponding hardware verification conditions, the hardware verification unit determines the corresponding hardware verification instruction according to the verification information, and sends the hardware verification instruction to the requesting end through the interactive signal unit to obtain hardware verification data, the hardware verification strategy verifies the hardware verification data through the corresponding hardware verification condition, and generates first verification information according to the verification result; A software verification unit, wherein the software verification unit is configured with a preset software verification strategy, and the software verification strategy is used to assign corresponding authority characteristics to the requesting end according to the first verification information; A storage information management unit, wherein the storage information management unit is configured with a plurality of encryption information, different encryption information is configured with corresponding permission characteristics, and the storage information management unit configures the access rights of the corresponding requesting end to the encryption information according to the permission characteristics; The hardware verification unit further includes a position generation strategy and a window generation strategy, wherein the position generation strategy is used to generate a verification position, and the window generation strategy is used to generate a verification window, wherein the verification position points to an initial position of the solid-state PIN initial code set during verification, and the verification window is used to determine a verification PIN code as a reference from the solid-state PIN initial code set during verification, and the hardware verification unit compares the encrypted conversion data with the verification PIN code as a reference to generate a verification result; The position generation strategy includes initial position starting point data of a plurality of solid-state PIN initial code sets and corresponding position generation conditions; The position generation condition is configured with a corresponding security transmission standard. If the transmission data of the solid-state storage unit meets the security transmission characterization, it is deemed to meet the corresponding security transmission verification condition, and the corresponding verification position starting point data is generated. The verification position starting point data is compared with the initial position starting point data of the solid-state PIN initial code set. If the comparison is consistent, the initial position of the solid-state PIN initial code set is successfully determined; The window generation strategy retrieves an initial verification window from a preset window information table according to the initial position of the solid-state PIN initial code set, extracts a conversion index condition in the conversion information through a verification feature extraction sub-algorithm, processes the initial verification window according to the conversion index condition to generate a conversion verification window, and sends the conversion verification window to a pre-configured window mirror to determine a verification window in the solid-state PIN initial code set; The preset window information table includes parameters of the window size and starting position; the verification feature extraction sub-algorithm is used to extract the conversion index condition from the conversion information, and the conversion index condition is used to process the initial verification window; the window mirror is a pre-configured module used to determine the verification window according to the conversion verification window in the solid-state PIN initial code set; The conversion information is a data packet containing the modification password and the high security level, from which the verification feature extraction sub-algorithm extracts the conversion index condition that requires the verification window to be shifted to the left by m code elements; The conversion index condition is a translation operation, which translates the initial verification window in the specified direction and distance; the starting position of the initial verification window is p, and the size is n. The conversion index condition is to translate m code elements to the left, and the starting position of the conversion verification window is pm, and the size is n; The window mirror searches the solid-state PIN initial code set for an area corresponding to the starting position and size of the conversion verification window, and this area is the verification window.

2. The encrypted information storage system based on the industrial control host according to claim 1 is characterized in that: The hardware verification conditions include communication verification conditions, level verification conditions and data verification conditions. The communication verification conditions are configured with corresponding communication standards. If the fed-back hardware verification data conforms to the communication characterization, it is deemed to satisfy the corresponding communication verification conditions. The level verification conditions are configured with level mapping features. If the fed-back hardware verification data conforms to the level verification features, it is deemed to satisfy the corresponding level verification conditions. The data verification conditions include a content recognition range and a corresponding verification calculation algorithm. The corresponding hardware verification data is calculated by the verification calculation algorithm to obtain the corresponding actual recognition value. If the actual recognition value falls within the corresponding content recognition range, it is deemed to satisfy the corresponding data verification conditions.

3. The encrypted information storage system based on the industrial control host according to claim 2 is characterized in that: The hardware verification unit further includes a data conversion strategy, wherein the data conversion strategy is configured with a plurality of data conversion conditions, each data conversion condition is indexed by a first conversion index value, a corresponding data conversion condition is retrieved according to the first conversion index value, and verification information is processed according to the data conversion condition to generate conversion information; The first conversion index value is calculated by a verification index formula, and the verification index formula is configured as follows: , , , ,in, is the first conversion index value, is the first communication factor, is the first level factor, is the first data factor, is the preset communication type weight, is the preset level type weight, is the preset data type weight, , For the The condition weights of the communication verification conditions, For the The verification result value of each communication verification condition, is the total number of communication verification conditions corresponding to the hardware verification instructions, For the The level weight of each level verification condition, For the The level deviation function of the level verification condition, is the feedback level value during the verification process, is the total number of level verification conditions corresponding to the hardware verification instruction, For the The data weight of each data verification condition, For the The data content similarity of the data verification conditions, For the The data format similarity of the data verification conditions, is the total number of data verification conditions corresponding to the hardware verification instructions; The hardware verification unit also includes an encryption configuration strategy, which includes an encryption algorithm. The encryption configuration strategy generates an encryption factor based on a first communication factor, a first level factor, and a first data factor, and configures the encryption factor in the encryption algorithm to process the conversion information to generate corresponding encrypted conversion data.

4. The encrypted information storage system based on the industrial control host according to claim 1 is characterized in that: When the generation of the first verification information needs to meet the first verification information generation condition, the first verification information is obtained by using the first verification information calculation formula; The first verification information generation condition includes a verification times condition and a verification matching degree condition; The verification times condition is: the verification times of the communication verification condition is not greater than the preset times, the verification times of the level verification condition is not greater than the preset times, and the verification times of the data verification condition is not greater than the preset times; The verification matching condition is as follows: for the communication verification condition, if the communication encryption conversion data completely conforms to the communication representation, the matching degree is 100%; if there is a deviation in the communication encryption conversion data format or the communication protocol that exceeds the preset deviation range, the matching degree is set according to the degree of deviation, and the matching degree is 90%; The level verification conditions are: if the level encrypted conversion data fully meets the level verification characteristics, the matching degree is 100%; if the level encrypted conversion data fluctuates within the allowable error range, the matching degree is determined according to the degree of fluctuation, and the matching degree is 90%; For the data verification condition, the encrypted conversion data is compared based on the closeness to the center value of the content recognition range. If the encrypted conversion data is within ±5% of the preset content recognition range center value, the match degree is 90%; if it is close to the boundary but still within the range, the match degree is 90%; The first verification information calculation formula is: , in, is the first verification information; is the number of verifications; is the maximum number of authentications allowed; is the weight of the number of verifications; To verify the matching; The weight for verifying the matching degree.

5. The encrypted information storage system based on the industrial control host according to claim 4 is characterized in that: The software verification strategy includes a number of software verification data and corresponding software verification conditions; The software verification condition includes a first verification information verification condition and a software input window verification condition; The first verification information verification condition is configured with a corresponding first verification information verification standard, and if the data of the first verification information meets the information verification representation, it is deemed to meet the corresponding first verification information verification condition; The first verification information verification standard is: ; The software input window verification condition is configured with a corresponding window verification standard. If the PIN input code data entered in the software input window meets the window verification characterization, it is deemed to meet the corresponding software input window verification condition; The software input window verification standard is to perform a preset hash operation on the PIN input code and the verification PIN code to obtain a PIN input code hash value and a verification PIN code hash value, and the PIN input code hash value and the verification PIN code hash value must be compared and consistent.

6. The encrypted information storage method is characterized in that: The method is applicable to the encrypted information storage system based on the industrial control host as described in claim 5 to implement access rights to the industrial control host. The method includes: S1. The user connects the solid-state storage unit to the industrial control host through an interface to complete the solid-state PIN initial code collection and storage. The solid-state PIN initial code set is stored in the storage information management unit; Through the position generation strategy, if the secure transmission is completed, the initial position of the solid-state PIN initial code set is successfully determined; If the secure transmission is not completed, a reminder page will pop up on the external monitor of the industrial control host; S2. Using the window generation strategy, according to the initial position of the solid-state PIN initial code set in S1, the corresponding initial verification window is searched in the preset window information table, and the conversion information is processed using the verification feature extraction sub-algorithm, and the initial verification window is processed according to the extracted conversion index condition, and the conversion verification window is sent to the pre-configured window mirrorer, and the window mirrorer matches the conversion verification window with the solid-state PIN initial code set to determine the verification window, and the solid-state PIN initial code in the verification window area is used as the reference verification PIN code; S3, obtaining encrypted conversion data through data conversion strategy and encryption configuration strategy; S4, using the hardware verification unit to compare the encrypted data in S3 with the reference verification PIN code in S2 for data integrity. When the encrypted data and the reference verification PIN code are consistent, the verification result is passed; S5, bringing the encrypted converted data of S3 into the first verification information generation condition, calculating and obtaining the first verification information and sending it to the software verification unit; S6. If the first verification information meets the first verification information verification standard , the software input window verification condition in the software verification is triggered; S7. Enter the PIN input code in the software input window, perform a preset hash operation on the PIN input code and the verification PIN code according to the software input window verification standard, obtain the PIN input code hash value and the verification PIN code hash value, and when the PIN input code hash value and the verification PIN code hash value are consistent, the verification result is passed; S8, controlling access rights to the encrypted information through the storage information management unit according to the verification results of S4 and S7; If the verification results of S4 and S7 are both passed, access to the industrial control host is granted; Otherwise, access is denied, completing the dynamic interlocking of the hardware verification unit and the software verification unit for the encrypted information.

Citation Information

Patent Citations

  • Identity authentication method and protection method for ensuring security of encryption device

    CN112257119A

  • Method, device and system for classifying, grading and protecting sensitive data of multiple password modules

    CN116232593A