Industrial data secure storage method and system based on block chain
By adopting a blockchain-based method in industrial data storage, the problems of data security and credibility in traditional storage architectures are solved, and the intelligent and secure management of industrial data is realized, reducing the risk of data leakage.
Patent Information
- Application Number
- CN202510148106.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-11
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-02-11
AI Technical Summary
Industrial data has a single point of failure risk in traditional centralized storage architecture and faces threats from internal overriding access and external cyber attacks. The integrity and confidentiality of data are difficult to guarantee.
The industrial data security storage method based on blockchain is adopted, and industrial data is clustered in department types, assigned exclusive blockchain networks and servers, hash processing and hash slot partitioning, smart contract algorithms are designed, data historical versions are automatically traced back, dynamic permission update frequency is set, and blockchain network server clusters are formed through distributed coordination algorithms.
It enhances the security and credibility of data, optimizes the data sharing process, realizes intelligent and secure management of industrial data, and reduces the risk of data leakage and system damage.
Smart Images

Figure CN120012134A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security and privacy protection, and in particular to a blockchain-based industrial data security storage method and system. Background Art
[0002] In the industrial field, with the acceleration of digital transformation, data is growing explosively and comes from a wide range of sources, covering various aspects such as production equipment operating parameters, process information, quality inspection data, etc. However, the current secure storage of industrial data faces many severe challenges.
[0003] On the one hand, the traditional centralized storage architecture has the risk of single point failure. Once the server is attacked or hardware failure occurs, a large amount of data may be lost or leaked, seriously affecting the production and operation of the enterprise. On the other hand, during the circulation and storage of industrial data, it faces the threat of unauthorized access from internal personnel and external network attacks, and the integrity and confidentiality of the data are difficult to guarantee. At the same time, the lack of efficient and reliable data sharing mechanism between different industrial departments has hindered the improvement of the overall production efficiency of enterprises.
[0004] Blockchain technology provides a solution with its decentralized, tamper-proof, and traceable characteristics. A blockchain-based industrial data security storage method and system can enhance the security and credibility of data, optimize the data sharing process, and help achieve intelligent and secure management of industrial data. Summary of the invention
[0005] The purpose of the present invention is to provide a method and system for secure storage of industrial data based on blockchain.
[0006] To achieve the above object, the present invention is implemented according to the following technical solutions: The first aspect of the present invention provides a blockchain-based industrial data security storage method, comprising: S100 clusters industrial data based on department type, assigns a blockchain network to each cluster, and configures servers for each blockchain network; S200 hashes the key fields of the industrial data to be operated, partitions each hash into hash slots, and maps them to the corresponding hash ring of the blockchain network to obtain an operation sequence; S300 eliminates invalid historical operations in the operation sequence and retains operation records within the life cycle; S400 designs a smart contract algorithm, which uses the hash value information in the operation record to automatically trace back to the historical version of the data for recovery when data is missing, and obtains complete data; S500 sets the permission update frequency based on the difference in key space between the same permission levels in the integrity data; S600 performs permission updates according to the permission update frequency, and based on data security assessment, applies a distributed coordination algorithm to servers of different blockchain networks to form a blockchain network server cluster; S700 If the blockchain server cluster is in an abnormal state, data access is interrupted and a dynamic key update mechanism is immediately triggered to achieve data security protection.
[0007] As a further method, the method of assigning a blockchain network to each cluster and configuring a server for each blockchain network includes: Asymmetric encryption is used to generate a public-private key pair for the industrial data in each cluster. The private key is stored locally, and the public key is used for communication encryption and identity authentication between nodes to generate a blockchain network. Determine the permissions of each node in the blockchain network based on job roles and data access requirements within the department; For each allocated blockchain network, configure the server resource size according to the amount of data it carries, including the number of servers, performance parameters, and storage capacity; During the server configuration process, critical server components are backed up through redundant backup technology, and a dynamic adjustment mechanism for server resources is established based on actual data growth and processing load.
[0008] As a further method, the method of hashing the key fields of the industrial data to be operated includes: Obtain industrial data that needs to be operated; For the industrial data to be operated, select key fields based on the departmental relevance of the data. Specifically, analyze the business processes of each department and use the fields that reflect the departmental business information as key fields; Perform hash processing on the key fields, where the expression of the hash function is: , Among them, x represents the key field, n and m are the total number of key fields and the number of iterations, respectively. is the weight coefficient of the data sensitivity of the i-th key field, for Hash algorithm, is the data value of the i-th key field, is the circular right shift function, r is the displacement value of the circular right shift, k is the security key, s is the random salt value, j is the current iteration number, represents the modulo operation, and p is a large prime number that ensures that the function results are evenly distributed.
[0009] As a further method, the method of mapping each hash to the corresponding hash ring of the blockchain network after hash slot partitioning includes: The total number of hash slots is determined based on the transaction processing efficiency of the blockchain network. The expression is: , in, and They are the average transaction volume per second and the standard deviation of transaction volume per second of the blockchain network, is the volatility coefficient, is the redundancy coefficient, The expected average number of transactions per second that can be processed by a single hash slot; Divide the hash value range evenly into hash slots to obtain hash slot partitions, and map each hash slot partition to the hash ring, where the expression of the mapping function is: , in, is the starting mapping position of the i-th partition on the hash ring, t is the current timestamp, T is the time window length, is the number of hash slots contained in the i-th partition, is the data feature hash value of the i-th partition, is the risk weight coefficient of the ith partition, is the coefficient used to adjust the overall scaling and offset of the mapping, M is the total number of partitions, L is the number of equally spaced points on the hash ring, and C is the circumference of the hash ring.
[0010] As a further method, the method of eliminating invalid historical operations in the operation sequence and retaining operation records within the life cycle includes: Set the life cycle for each operation record in the operation sequence. The expression is: , in, and They are time weight parameters used to adjust the impact of creation time and last access time on the life cycle. is the current time, and They are the creation time and last access time of the operation record, is the normalization factor, H is the number of active factors in the operation record, and are the weight and value of the hth activity factor, U is the total number of risk factors in the operation record, and are the weight and value of the jth risk factor, respectively, and S is the total risk score of the operation record; Traverse each operation record in the operation sequence, obtain its timestamp, and compare it with the life cycle of the operation record. If the life cycle of the operation record is exceeded, the operation record is judged to be an invalid operation; The operation records that are judged to be invalid are deleted from the operation sequence, and only the operation records within the valid life cycle are retained.
[0011] As a further method, the method of designing a smart contract algorithm and automatically tracing back to the historical version of the data for recovery when data is missing by using the hash value information in the operation record includes: If data is found to be missing, the smart contract will start the backtracking mechanism, which is as follows: by traversing the stored operation records, comparing the hash values before and after the data modification, locating the most recent historical version record with complete data, and extracting its corresponding data hash value; According to the located hash value of the historical version data, the complete data of the historical version is retrieved and obtained from the storage layer in the blockchain network, and restored to the storage location of the current data to complete the data backtracking recovery operation.
[0012] As a further method, the method for setting the permission update frequency based on the difference in key space between the same permission levels in the integrity data includes: Calculate the key space of each node in the blockchain network, the expression is: , in, is the key space of the nth node, The number of data categories that the nth node is responsible for, is the business weight of the nth node for the i-th type of data, is the amount of data stored in the nth node for the i-th type of data, is the data sensitivity of the i-th type of data on the n-th node, is the data operation frequency of the i-th type of data on the n-th node, is the balance constant of the key space, is the number of external factors that affect the node key space, is the degree to which the i-th type of data on the n-th node is affected by the j-th external factor; Get the key space difference between nodes of the same permission level, combine it with the activity of the node, and calculate the permission update frequency. The expression is: , in, is the permission update frequency of the nth node, The frequency of updating the basic permissions of the node. is the average value of the key space difference between the nth node and other nodes with the same permission level, is the sum of the average values of the key space differences between all nodes and other nodes of the same permission level, is the data interaction activity of the nth node, It is the sum of the data interaction activity of all nodes.
[0013] As a further method, the method of applying a distributed coordination algorithm to servers of different blockchain networks based on data security assessment to form a blockchain network server cluster includes: Perform data security assessment on servers of different blockchain networks, aggregate servers whose data security assessment value differences are less than a preset threshold, and obtain multiple security groups; A distributed coordination algorithm is used to establish secure associations within and between groups. Specifically, for servers within a group, encrypted communication connections are established through a secure channel protocol; a secure isolation mechanism is set up between groups to allow only authorized secure data interactions; a response and collaboration mechanism is established between groups so that when a security incident occurs in one group, the other groups can assist in restoring data or providing resources; Multi-layer security protection layers are set up at the entrance and exit of the cluster, including firewalls, intrusion detection and data encryption gateways, to safely filter and encrypt data entering and leaving the cluster.
[0014] As a further method, if the blockchain server cluster is in an abnormal state, the method of interrupting data access and immediately triggering a dynamic key update mechanism includes: Deploy a monitoring program in each security group in the blockchain server cluster. When the monitoring security group detects an abnormal situation locally, it encapsulates the abnormal signal and broadcasts it to the other security groups in the cluster. The abnormal signal includes the abnormal type, node identifier and timestamp. After the other security groups receive the abnormal signal, the nodes in the blockchain network within the security group interact with each other and start the consensus algorithm based on Byzantine fault tolerance. The expression of the consensus algorithm is: , Among them, C is the consensus result, N is the number of nodes in the blockchain network within the security group, is the signature of the abnormal state by the i-th node, M is the number of nodes that receive the abnormal signal, The vote of the jth node on the abnormal state; After reaching an abnormal consensus, all security groups in the cluster perform data access interruption operations, and the leader node elected by the consensus algorithm initiates a proposal for dynamic key update, including new key generation parameters and update plan, and broadcasts it to the remaining nodes for consensus; After reaching a consensus on key update, all nodes update keys according to the update plan based on the new key generation parameters, restore normal access to cluster data, and distribute new keys to authorized users.
[0015] The second aspect of the present invention provides an industrial data security storage system based on blockchain, comprising: The blockchain configuration module is used to cluster industrial data based on department type, assign a blockchain network to each cluster, and configure servers for each blockchain network; A hash slot mapping module is used to hash the key fields of the industrial data to be operated, and after hash slot partitioning each hash, map it to the corresponding hash ring of the blockchain network to obtain an operation sequence; An operation record cleaning module is used to eliminate invalid historical operations in the operation sequence and retain operation records within the life cycle; A smart contract recovery module is used to design a smart contract algorithm, and to use the hash value information in the operation record to automatically trace back to the historical version of the data for recovery when data is missing to obtain complete data; An authority frequency setting module, used to set the authority update frequency based on the difference in key space between the same authority levels in the integrity data; A security assessment cluster module is used to apply a distributed coordination algorithm to servers of different blockchain networks based on data security assessment after updating permissions according to the permission update frequency to form a blockchain network server cluster; The abnormal security protection module is used to interrupt data access if the blockchain server cluster is in an abnormal state, and immediately trigger the dynamic key update mechanism to achieve data security protection.
[0016] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects: (1) The present invention clusters industrial data based on department type and allocates a dedicated blockchain network and server to each cluster. This can optimize resource allocation and data management according to the specific characteristics and usage frequency of different departments and avoid mutual interference between different types of data. (2) The present invention sets the permission update frequency based on the difference in the key space between the same permission levels of the integrity data, and can dynamically adjust permissions according to the actual use of the data and security requirements, respond to data changes in a timely manner, and effectively prevent security vulnerabilities caused by fixed permissions; (3) By building a server cluster, the present invention can achieve reasonable configuration of server resources, form an efficient, stable and secure storage architecture, enhance the ability of the entire blockchain network to cope with various security threats, and ensure reliable storage and access of industrial data in complex environments; (4) The present invention immediately interrupts data access and triggers a dynamic key update mechanism when an abnormal state occurs in the blockchain server cluster. This rapid response mechanism can prevent potential data leakage risks in the first place, thereby further enhancing the security of industrial data. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 This is a flowchart of the steps of a blockchain-based industrial data security storage method in an embodiment of the present invention. DETAILED DESCRIPTION
[0018] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0019] Reference Figure 1 As shown, the present invention provides a blockchain-based industrial data security storage method, comprising: S100 clusters industrial data based on department type, assigns a blockchain network to each cluster, and configures servers for each blockchain network; Take a large steel production enterprise as an example, which includes multiple production departments such as ironmaking, steelmaking, and steel rolling, as well as multiple business links such as procurement, sales, quality control, equipment maintenance, and financial management; It should be explained that this step is to classify and cluster industrial data according to the departmental sources, allocate independent blockchain networks to each cluster, and then configure servers, so that data from different departments can be stored and processed in a dedicated network and server environment to avoid data confusion and chaotic access. At the same time, resources are configured according to the characteristics of departmental data and usage requirements, which can improve data processing efficiency, enhance data security and privacy, and lay the foundation for subsequent data operations; In the actual evaluation, for the ironmaking workshop, blast furnace operation data, hot blast furnace data, raw material batching data, etc. are clustered together to generate a public-private key pair. The private key is stored in a local encrypted storage device, and the public key is used for encrypted communication and identity authentication between nodes. An ironmaking workshop blockchain network is built, and node permissions are set according to positions. Specifically, blast furnace operators can read real-time data such as blast furnace temperature and pressure, foremen can read and write some process parameter adjustment data, and workshop directors have higher management authority and can view all data and perform audit operations. Seven high-performance servers are configured, each server is equipped with a 32-core CPU, 64GB memory and 4TB storage capacity. RAID 5 redundancy technology is used to back up hard disk data, and a dynamic resource adjustment mechanism is set. When the data volume increases by more than 10% within 3 days or the CPU usage rate exceeds 85% for 4 consecutive hours, 2 servers are automatically added for load balancing and the storage capacity is expanded to 6TB.
[0020] S200 hashes the key fields of the industrial data to be operated, partitions each hash into hash slots, and maps them to the corresponding hash ring of the blockchain network to obtain an operation sequence; It needs to be explained that partitioning and mapping hash slots to hash rings helps to evenly distribute data storage and processing loads, improve the operational efficiency of the blockchain network, and enable subsequent data operations to be carried out in an orderly and efficient manner in the blockchain environment; In the actual evaluation, for the ironmaking workshop, eight key fields were selected for the blast furnace operation data, including "blast furnace number", "molten iron temperature", "furnace top pressure", "coke addition amount", "ore grade", "limestone addition amount", "hot air temperature" and "blast temperature". The random salt value was 256 bits, the cyclic right shift value was 32, and the large prime number was 3001. The key fields were hashed through the hash function to obtain the hash value. In the actual evaluation, the total number of hash slots was determined according to the transaction processing efficiency of the blockchain network in the ironmaking workshop. The average transaction processing volume per second was 47, and the average number of transactions processed per second for each hash slot was expected to be 12. The total number of hash slots was calculated to be 64. The hash values were evenly divided into hash slots and then mapped to the hash ring to complete the mapping and obtain the operation sequence.
[0021] S300 eliminates invalid historical operations in the operation sequence and retains operation records within the life cycle; It should be explained that as time goes by and business develops, the operation sequence will accumulate a large number of historical operations. Eliminating invalid operations and retaining records within the life cycle can, on the one hand, avoid redundant invalid data occupying storage resources, and on the other hand, ensure the timeliness and effectiveness of operation records, providing an accurate and reliable basis for subsequent analysis, tracing and decision-making based on valid data; In the actual evaluation, for the blockchain network of the ironmaking workshop, the operation records of the molten iron composition were calculated to have a life cycle of 5400 seconds. The operation sequence was traversed regularly, the timestamp and the life cycle were compared, the invalid records were deleted, and the valid records were retained to ensure the timeliness and efficiency of the data. Finally, the operation records within the life cycle were obtained as follows: Operation record 1: Operation content: Adjust the silicon content in the molten iron to 1.2%, creation time: 1630000000 seconds, last access time: 1630003600 seconds; Operation record 2: Increase the manganese content in the molten iron to 0.8%, creation time: 1630000000 seconds, last access timestamp: 1630003600 seconds; Operation record 3: Adjust the process parameters of molten iron desulfurization and increase the amount of lime added by 10%, creation time: 1630004200 seconds, last access time: 1630007000 seconds.
[0022] S400 designs a smart contract algorithm, which uses the hash value information in the operation record to automatically trace back to the historical version of the data for recovery when data is missing, and obtains complete data; It is important to explain that, through the uniqueness and relevance of the hash value, the historical version of the data can be accurately located and then restored to ensure the integrity of the data. This process effectively addresses the risks of data loss, damage or tampering, maintains the reliability and availability of industrial data in the blockchain storage environment, and ensures that the entire system can still operate stably in the face of data anomalies without affecting the continuity and accuracy of related businesses. In the actual assessment, due to a server failure in the ironmaking workshop, some blast furnace operation data was lost. The smart contract initiated backtracking, and by comparing the hash values before and after the data modification, the hash value of the complete data version of the previous day was located, and the data was retrieved and restored from the storage layer to ensure that production was not affected.
[0023] S500 sets the permission update frequency based on the difference in key space between the same permission levels in the integrity data; It should be explained that by analyzing the difference, the imbalance of data between nodes can be measured, and the permission update frequency can be set based on this difference. By using dynamic permission management strategies, node permissions can be adjusted in a timely manner to prevent potential security vulnerabilities caused by long-term fixed permissions, such as permission abuse and data leakage risks, thereby enhancing the security and compliance of data access and adapting to the ever-changing industrial data security needs; In the actual evaluation, for a process engineer node in the ironmaking workshop, he is responsible for 5 types of data, namely: , with business weights of 0.3, 0.2, 0.15, 0.15 and 0.2, respectively, and storage capacities of 714MB, 540MB, 500MB, 861MB and 200MB, respectively, and operation frequencies of 12 times / day, 8 times / day, 20 times / day, 6 times / day and 15 times / day, respectively. The key space of the node is calculated to be 520; there are 8 nodes with the same authority level as the engineer, and the authority update frequency is calculated to be 1.3 times / day. The authority is updated to ensure data security.
[0024] S600 performs permission updates according to the permission update frequency, and based on data security assessment, applies a distributed coordination algorithm to servers of different blockchain networks to form a blockchain network server cluster; It needs to be explained that the data security assessment based on , comprehensively considers all aspects of the server's security indicators, and uses distributed coordination algorithms to integrate servers of different blockchain networks, which can effectively coordinate resource allocation, optimize communication links, etc., prompting them to form clusters, enhance the overall fault tolerance, scalability and ability to resist external attacks, and build a more stable and efficient data storage architecture; In the actual assessment, a security assessment was conducted on the blockchain servers of each department, with indicators including encryption, network protection, storage stability and backup capabilities. Servers with an assessment similarity of less than 24%, that is, an assessment value difference of less than 30 points, were grouped. Specifically, the ironmaking and steelmaking workshop servers were divided into one group, the quality control and equipment maintenance department servers were divided into one group, and the financial department was divided into a separate group. The groups communicated using an encrypted channel protocol, and an isolation mechanism was set up between groups, allowing only authorized interactions. A response and collaboration mechanism was established. When the ironmaking workshop group was attacked, the quality control group assisted in recovering data or providing resources. Multi-layer protection was set up at the entrance and exit of the cluster, including a high-performance firewall (with an intrusion defense accuracy of 98%), an intelligent intrusion detection system (with a false negative rate of 1%), and a data encryption gateway (using AES-512 encryption) to ensure data security.
[0025] S700 If the blockchain server cluster is in an abnormal state, data access is interrupted and a dynamic key update mechanism is immediately triggered to achieve data security protection.
[0026] It needs to be explained that when the blockchain server cluster is in an abnormal state, such as being attacked by a network, hardware failure or software vulnerability being exploited, interrupting data access can quickly cut off the potential path for the spread of security risks, prevent data in abnormal states from being stolen, tampered with or destroyed, and immediately trigger the dynamic key update mechanism. By replacing the encryption key, the key obtained by the attacker will be invalidated, the confidentiality and integrity of the data will be enhanced, and possible subsequent attacks will be effectively resisted, thereby ensuring that the industrial data security protection in the entire system can be continuously maintained at a reliable level, reducing the risk of data leakage and system damage, and ensuring that the continuity and stability of industrial production are not seriously affected; In the actual evaluation, for the ironmaking workshop, the security group monitored and found that the server CPU usage rate exceeded 98% for 20 minutes and a large amount of suspicious traffic appeared in the network. The abnormal signal (including type, node ID, and timestamp) was encapsulated and broadcast to other groups; after other groups received the signal, the nodes in the group interacted and started the Byzantine fault-tolerant consensus algorithm. Among the 12 nodes in the group, 10 or more nodes received the signal, and more than 2 / 3 of the nodes voted in favor. The consensus result calculated by the consensus algorithm was an abnormal consensus; after reaching a consensus, all groups interrupted data access, and the leading node initiated a key update proposal (generating a 2048-bit key pair using the elliptic curve cryptography system, updated in stages within 40 minutes), broadcasted it to other nodes, and then the nodes updated the keys as planned. After the update was completed, data access was restored, and the new keys were distributed to authorized users.
[0027] In this embodiment, the method of allocating a blockchain network to each cluster and configuring a server for each blockchain network includes: Asymmetric encryption is used to generate a public-private key pair for the industrial data in each cluster. The private key is stored locally, and the public key is used for communication encryption and identity authentication between nodes to generate a blockchain network. Determine the permissions of each node in the blockchain network based on job roles and data access requirements within the department; For each allocated blockchain network, configure the server resource size according to the amount of data it carries, including the number of servers, performance parameters, and storage capacity; During the server configuration process, critical server components are backed up through redundant backup technology, and a dynamic adjustment mechanism for server resources is established based on actual data growth and processing load.
[0028] In this embodiment, the method for hashing the key fields of the industrial data to be operated includes: Obtain industrial data that needs to be operated; For the industrial data to be operated, select key fields based on the departmental relevance of the data. Specifically, analyze the business processes of each department and use the fields that reflect the departmental business information as key fields; Perform hash processing on the key fields, where the expression of the hash function is: , Among them, x represents the key field, n and m are the total number of key fields and the number of iterations, respectively. is the weight coefficient of the data sensitivity of the i-th key field, for Hash algorithm, is the data value of the i-th key field, is the circular right shift function, r is the displacement value of the circular right shift, k is the security key, s is the random salt value, j is the current iteration number, represents the modulo operation, and p is a large prime number that ensures that the function results are evenly distributed.
[0029] In this embodiment, the method of mapping each hash to the corresponding hash ring of the blockchain network after performing hash slot partitioning on each hash includes: The total number of hash slots is determined based on the transaction processing efficiency of the blockchain network. The expression is: , in, and They are the average transaction volume per second and the standard deviation of transaction volume per second of the blockchain network, is the volatility coefficient, is the redundancy coefficient, The expected average number of transactions per second that can be processed by a single hash slot; Divide the hash value range evenly into hash slots to obtain hash slot partitions, and map each hash slot partition to the hash ring, where the expression of the mapping function is: , in, is the starting mapping position of the i-th partition on the hash ring, t is the current timestamp, T is the time window length, is the number of hash slots contained in the i-th partition, is the data feature hash value of the i-th partition, is the risk weight coefficient of the ith partition, is the coefficient used to adjust the overall scaling and offset of the mapping, M is the total number of partitions, L is the number of equally spaced points on the hash ring, and C is the circumference of the hash ring.
[0030] In this embodiment, the method of eliminating invalid historical operations in the operation sequence and retaining operation records within the life cycle includes: Set the life cycle for each operation record in the operation sequence. The expression is: , in, and They are time weight parameters used to adjust the impact of creation time and last access time on the life cycle. is the current time, and They are the creation time and last access time of the operation record, is the normalization factor, H is the number of active factors in the operation record, and are the weight and value of the hth activity factor, U is the total number of risk factors in the operation record, and are the weight and value of the jth risk factor, respectively, and S is the total risk score of the operation record; Traverse each operation record in the operation sequence, obtain its timestamp, and compare it with the life cycle of the operation record. If the life cycle of the operation record is exceeded, the operation record is judged to be an invalid operation; The operation records that are judged to be invalid are deleted from the operation sequence, and only the operation records within the valid life cycle are retained.
[0031] In this embodiment, the method of designing a smart contract algorithm and automatically tracing back to the historical version of the data for recovery when data is missing by using the hash value information in the operation record includes: If data is found to be missing, the smart contract will start the backtracking mechanism, which is as follows: by traversing the stored operation records, comparing the hash values before and after the data modification, locating the most recent historical version record with complete data, and extracting its corresponding data hash value; According to the located hash value of the historical version data, the complete data of the historical version is retrieved and obtained from the storage layer in the blockchain network, and restored to the storage location of the current data to complete the data backtracking recovery operation.
[0032] In this embodiment, the method for setting the permission update frequency based on the difference in key spaces between the same permission levels in the integrity data includes: Calculate the key space of each node in the blockchain network, the expression is: , in, is the key space of the nth node, The number of data categories that the nth node is responsible for, is the business weight of the nth node for the i-th type of data, is the amount of data stored in the nth node for the i-th type of data, is the data sensitivity of the i-th type of data on the n-th node, is the data operation frequency of the i-th type of data on the n-th node, is the balance constant of the key space, is the number of external factors that affect the node key space, is the degree to which the i-th type of data on the n-th node is affected by the j-th external factor; Get the key space difference between nodes of the same permission level, combine it with the activity of the node, and calculate the permission update frequency. The expression is: , in, is the permission update frequency of the nth node, The frequency of updating the basic permissions of the node. is the average value of the key space difference between the nth node and other nodes with the same permission level, is the sum of the average values of the key space differences between all nodes and other nodes of the same permission level, is the data interaction activity of the nth node, It is the sum of the data interaction activity of all nodes.
[0033] In this embodiment, the method of forming a blockchain network server cluster by applying a distributed coordination algorithm to servers of different blockchain networks based on data security assessment includes: Perform data security assessment on servers of different blockchain networks, aggregate servers whose data security assessment value differences are less than a preset threshold, and obtain multiple security groups; A distributed coordination algorithm is used to establish secure associations within and between groups. Specifically, for servers within a group, encrypted communication connections are established through a secure channel protocol; a secure isolation mechanism is set up between groups to allow only authorized secure data interactions; a response and collaboration mechanism is established between groups so that when a security incident occurs in one group, the other groups can assist in restoring data or providing resources; Multi-layer security protection layers are set up at the entrance and exit of the cluster, including firewalls, intrusion detection and data encryption gateways, to safely filter and encrypt data entering and leaving the cluster.
[0034] In this embodiment, if the blockchain server cluster is in an abnormal state, the method of interrupting data access and immediately triggering a dynamic key update mechanism includes: Deploy a monitoring program in each security group in the blockchain server cluster. When the monitoring security group detects an abnormal situation locally, it encapsulates the abnormal signal and broadcasts it to the other security groups in the cluster. The abnormal signal includes the abnormal type, node identifier and timestamp. After the other security groups receive the abnormal signal, the nodes in the blockchain network within the security group interact with each other and start the consensus algorithm based on Byzantine fault tolerance. The expression of the consensus algorithm is: , Among them, C is the consensus result, N is the number of nodes in the blockchain network within the security group, is the signature of the abnormal state by the i-th node, M is the number of nodes that receive the abnormal signal, The vote of the jth node on the abnormal state; After reaching an abnormal consensus, all security groups in the cluster perform data access interruption operations, and the leader node elected by the consensus algorithm initiates a proposal for dynamic key update, including new key generation parameters and update plan, and broadcasts it to the remaining nodes for consensus; After reaching a consensus on key update, all nodes update keys according to the update plan based on the new key generation parameters, restore normal access to cluster data, and distribute new keys to authorized users.
[0035] The second aspect of the present invention also provides an industrial data security storage system based on blockchain, comprising: The blockchain configuration module is used to cluster industrial data based on department type, assign a blockchain network to each cluster, and configure servers for each blockchain network; A hash slot mapping module is used to hash the key fields of the industrial data to be operated, and after hash slot partitioning each hash, map it to the corresponding hash ring of the blockchain network to obtain an operation sequence; An operation record cleaning module is used to eliminate invalid historical operations in the operation sequence and retain operation records within the life cycle; A smart contract recovery module is used to design a smart contract algorithm, and to use the hash value information in the operation record to automatically trace back to the historical version of the data for recovery when data is missing to obtain complete data; An authority frequency setting module, used to set the authority update frequency based on the difference in key space between the same authority levels in the integrity data; A security assessment cluster module is used to apply a distributed coordination algorithm to servers of different blockchain networks based on data security assessment after updating permissions according to the permission update frequency to form a blockchain network server cluster; The abnormal security protection module is used to interrupt data access if the blockchain server cluster is in an abnormal state, and immediately trigger the dynamic key update mechanism to achieve data security protection.
[0036] The above contents are merely examples and explanations of the structure of the present invention. The technicians in this technical field may make various modifications or additions to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the structure of the invention or exceed the scope defined by the claims, they should all fall within the protection scope of the present invention.
Claims
1. A blockchain-based industrial data security storage method, characterized in that: The following steps are involved: Cluster industrial data based on department type, assign a blockchain network to each cluster, and configure servers for each blockchain network; Hash the key fields of the industrial data to be operated, partition each hash into hash slots, and map them to the corresponding hash ring of the blockchain network to obtain an operation sequence; Eliminate invalid historical operations in the operation sequence and retain operation records within the life cycle; Design a smart contract algorithm to use the hash value information in the operation record to automatically trace back to the historical version of the data for recovery when data is missing to obtain complete data; Setting the permission update frequency based on the difference in key space between the same permission levels in the integrity data; After updating permissions according to the permission update frequency, based on data security assessment, a distributed coordination algorithm is applied to servers of different blockchain networks to form a blockchain network server cluster; If the blockchain server cluster is in an abnormal state, data access will be interrupted and the dynamic key update mechanism will be triggered immediately to achieve data security protection.
2. According to the blockchain-based industrial data security storage method of claim 1, it is characterized in that: The method of allocating a blockchain network to each cluster and configuring a server for each blockchain network includes: Asymmetric encryption is used to generate a public-private key pair for the industrial data in each cluster. The private key is stored locally, and the public key is used for communication encryption and identity authentication between nodes to generate a blockchain network. Determine the permissions of each node in the blockchain network based on job roles and data access requirements within the department; For each allocated blockchain network, configure the server resource size according to the amount of data it carries, including the number of servers, performance parameters, and storage capacity; During the server configuration process, critical server components are backed up through redundant backup technology, and a dynamic adjustment mechanism for server resources is established based on actual data growth and processing load.
3. According to the blockchain-based industrial data security storage method of claim 1, it is characterized in that: The method for hashing the key fields of the industrial data to be operated includes: Obtain industrial data that needs to be operated; For the industrial data to be operated, select key fields based on the departmental relevance of the data. Specifically, analyze the business processes of each department and use the fields that reflect the departmental business information as key fields; Perform hash processing on the key fields, where the expression of the hash function is: , Among them, x represents the key field, n and m are the total number of key fields and the number of iterations, respectively. is the weight coefficient of the data sensitivity of the i-th key field, for Hash algorithm, is the data value of the i-th key field, is the circular right shift function, r is the displacement value of the circular right shift, k is the security key, s is the random salt value, j is the current iteration number, represents the modulo operation, and p is a large prime number that ensures that the function results are evenly distributed.
4. According to the blockchain-based industrial data security storage method of claim 1, it is characterized in that: The method of mapping each hash to the corresponding hash ring of the blockchain network after performing hash slot partitioning on each hash includes: The total number of hash slots is determined based on the transaction processing efficiency of the blockchain network. The expression is: , in, and They are the average transaction volume per second and the standard deviation of transaction volume per second of the blockchain network, is the volatility coefficient, is the redundancy coefficient, The expected average number of transactions per second that can be processed by a single hash slot; Divide the hash value range evenly into hash slots to obtain hash slot partitions, and map each hash slot partition to the hash ring, where the expression of the mapping function is: , in, is the starting mapping position of the i-th partition on the hash ring, t is the current timestamp, T is the time window length, is the number of hash slots contained in the i-th partition, is the data feature hash value of the i-th partition, is the risk weight coefficient of the ith partition, is the coefficient used to adjust the overall scaling and offset of the mapping, M is the total number of partitions, L is the number of equally spaced points on the hash ring, and C is the circumference of the hash ring.
5. According to the blockchain-based industrial data security storage method of claim 1, it is characterized in that: The method of eliminating invalid historical operations in the operation sequence and retaining operation records within the life cycle includes: Set the life cycle for each operation record in the operation sequence. The expression is: , in, and They are time weight parameters used to adjust the impact of creation time and last access time on the life cycle. is the current time, and They are the creation time and last access time of the operation record, is the normalization factor, H is the number of active factors in the operation record, and are the weight and value of the hth activity factor, U is the total number of risk factors in the operation record, and are the weight and value of the jth risk factor, respectively, and S is the total risk score of the operation record; Traverse each operation record in the operation sequence, obtain its timestamp, and compare it with the life cycle of the operation record. If the life cycle of the operation record is exceeded, the operation record is judged to be an invalid operation; The operation records that are judged to be invalid are deleted from the operation sequence, and only the operation records within the valid life cycle are retained.
6. According to the blockchain-based industrial data security storage method of claim 1, it is characterized in that: The method of designing a smart contract algorithm and automatically tracing back to the historical version of the data for recovery when data is missing by using the hash value information in the operation record includes: If data is found to be missing, the smart contract will start the backtracking mechanism, which is as follows: by traversing the stored operation records, comparing the hash values before and after the data modification, locating the most recent historical version record with complete data, and extracting its corresponding data hash value; According to the located hash value of the historical version data, the complete data of the historical version is retrieved and obtained from the storage layer in the blockchain network, and restored to the storage location of the current data to complete the data backtracking recovery operation.
7. According to the blockchain-based industrial data security storage method of claim 1, it is characterized in that: The method for setting the permission update frequency based on the difference in key space between the same permission levels in the integrity data comprises: Calculate the key space of each node in the blockchain network, the expression is: , in, is the key space of the nth node, The number of data categories that the nth node is responsible for, is the business weight of the nth node for the i-th type of data, is the amount of data stored in the nth node for the i-th type of data, is the data sensitivity of the i-th type of data on the n-th node, is the data operation frequency of the i-th type of data on the n-th node, is the balance constant of the key space, is the number of external factors that affect the node key space, is the degree to which the i-th type of data on the n-th node is affected by the j-th external factor; Get the key space difference between nodes of the same permission level, combine it with the activity of the node, and calculate the permission update frequency. The expression is: , in, is the permission update frequency of the nth node, The frequency of updating the basic permissions of the node. is the average value of the key space difference between the nth node and other nodes with the same permission level, is the sum of the average values of the key space differences between all nodes and other nodes of the same permission level, is the data interaction activity of the nth node, It is the sum of the data interaction activity of all nodes.
8. According to the blockchain-based industrial data security storage method of claim 1, it is characterized in that: The method of forming a blockchain network server cluster by applying a distributed coordination algorithm to servers of different blockchain networks based on data security assessment includes: Perform data security assessment on servers of different blockchain networks, aggregate servers whose data security assessment value differences are less than a preset threshold, and obtain multiple security groups; A distributed coordination algorithm is used to establish secure associations within and between groups. Specifically, for servers within a group, encrypted communication connections are established through a secure channel protocol; a secure isolation mechanism is set up between groups to allow only authorized secure data interactions; a response and collaboration mechanism is established between groups so that when a security incident occurs in one group, the other groups can assist in restoring data or providing resources; Multi-layer security protection layers are set up at the entrance and exit of the cluster, including firewalls, intrusion detection and data encryption gateways, to safely filter and encrypt data entering and leaving the cluster.
9. The method for secure storage of industrial data based on blockchain according to claim 1, characterized in that: The method of interrupting data access and immediately triggering a dynamic key update mechanism if an abnormal state occurs in the blockchain server cluster includes: Deploy a monitoring program in each security group in the blockchain server cluster. When the monitoring security group detects an abnormal situation locally, it encapsulates the abnormal signal and broadcasts it to the other security groups in the cluster. The abnormal signal includes the abnormal type, node identifier and timestamp. After the other security groups receive the abnormal signal, the nodes in the blockchain network within the security group interact with each other and start the consensus algorithm based on Byzantine fault tolerance. The expression of the consensus algorithm is: , Among them, C is the consensus result, N is the number of nodes in the blockchain network within the security group, is the signature of the abnormal state by the i-th node, M is the number of nodes that receive the abnormal signal, The vote of the jth node on the abnormal state; After reaching an abnormal consensus, all security groups in the cluster perform data access interruption operations, and the leader node elected by the consensus algorithm initiates a proposal for dynamic key update, including new key generation parameters and update plan, and broadcasts it to the remaining nodes for consensus; After reaching a consensus on key update, all nodes update keys according to the update plan based on the new key generation parameters, restore normal access to cluster data, and distribute new keys to authorized users.
10. A blockchain-based industrial data security storage system, used to execute a blockchain-based industrial data security storage method according to any one of claims 1 to 9, characterized in that: The system comprises: The blockchain configuration module is used to cluster industrial data based on department type, assign a blockchain network to each cluster, and configure servers for each blockchain network; A hash slot mapping module is used to hash the key fields of the industrial data to be operated, and after hash slot partitioning each hash, map it to the corresponding hash ring of the blockchain network to obtain an operation sequence; An operation record cleaning module is used to eliminate invalid historical operations in the operation sequence and retain operation records within the life cycle; A smart contract recovery module is used to design a smart contract algorithm, and to use the hash value information in the operation record to automatically trace back to the historical version of the data for recovery when data is missing to obtain complete data; An authority frequency setting module, used to set the authority update frequency based on the difference in key space between the same authority levels in the integrity data; A security assessment cluster module is used to apply a distributed coordination algorithm to servers of different blockchain networks based on data security assessment after updating permissions according to the permission update frequency to form a blockchain network server cluster; The abnormal security protection module is used to interrupt data access if the blockchain server cluster is in an abnormal state, and immediately trigger the dynamic key update mechanism to achieve data security protection.
Citation Information
Patent Citations
Distributed account book security-oriented high-performance extensible system and cluster architecture thereof
CN113411344A
Block chain transaction processing method, storage medium and computer system
CN114095436A
Heterogeneous identity alliance risk assessment system and method based on block chain, and terminal
CN114139203A
Block chain storage method, system and device and storage medium
CN116049315A
Self-adaptive micro-energy driven passive sensing node security encryption architecture
CN119364348A
Cited By
Industrial control network data security sharing method and system based on block chain
CN120263396A
Private data protection method based on computer network
CN120474846A
Data security sharing method of standard digital knowledge base based on block chain
CN120498798A
Data security sharing method for standard digital knowledge base based on blockchain
CN120498798B
User data protection method and system for online promotion platform
CN120850336A