Industrial database protection method based on multi-mode authentication and encryption
By adopting multimodal authentication and adaptive encryption technology in industrial databases and combining in-depth analysis of industrial protocols, the contradiction between real-time and security caused by traditional security measures is solved, and high-accurate identity authentication and data encryption are achieved, ensuring the security of industrial data and the real-time system.
Patent Information
- Application Number
- CN202510525344.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the industrial Internet environment, traditional security protection measures often introduce additional delays, affecting the real-time response capabilities of industrial control systems, while simply reducing security standards will put the system at a serious security threat.
The industrial database protection method based on multimodal authentication and encryption is adopted, and the user identity information is checked through a multimodal authentication gateway. Combined with the sensitivity level of the industrial data transmitted in real time and the system load status, the encryption algorithm of the adaptive encryption engine is determined, the industrial data is encrypted, and the Modbus message is parsed through the industrial protocol in-depth analysis module, a whitelist instruction set is established, and industrial data with functional codes not in the whitelist instruction set is intercepted.
It improves the accuracy of identity authentication, cracks the defect that traditional static keys are easily copied, balances security with real-time requirements of industrial systems, blocks protocol abuse attacks, and ensures data security.
Smart Images

Figure CN120050122A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular to an industrial database protection method based on multimodal authentication and encryption. Background Art
[0002] In the industrial Internet environment, there is a fundamental contradiction between data security and system real-time performance. Traditional security protection measures often introduce additional delays, affecting the real-time response capabilities of industrial control systems, which may lead to reduced production efficiency or even safety accidents. However, simply lowering safety standards will expose the system to serious security threats. This contradiction is particularly prominent in highly automated modern industrial scenarios, such as smart manufacturing production lines and power dispatching systems.
[0003] At the same time, the diversity and complexity of industrial data further exacerbate this problem. Different types of industrial data, such as production parameters, equipment status, quality inspection results, etc., have different requirements for industrial data security and system real-time response capabilities. Therefore, how to formulate differentiated protection strategies for different data characteristics while ensuring the security of industrial data has become a major challenge. Summary of the invention
[0004] In order to overcome the defects of the prior art, the present invention provides an industrial database protection method based on multimodal authentication and encryption to solve the above-mentioned problems.
[0005] The technical solution adopted by the present invention to solve the technical problem is: an industrial database protection method based on multimodal authentication and encryption, comprising the following steps: S1: obtaining input data to be input into an industrial database, wherein the input data includes user identity information and industrial data transmitted in real time; S2: using a multimodal authentication gateway to verify the user identity information, the verification process is to generate a three-level identity verification mark by integrating biometrics, dynamic device fingerprints and quantum random number tokens; S3: After passing the three-level identity verification, the encryption algorithm of the adaptive encryption engine is determined according to the sensitivity level of the industrial data transmitted in real time and the system load status, and the industrial data transmitted in real time is encrypted by the encryption algorithm; S4: For the encrypted real-time transmitted industrial data, the industrial protocol deep analysis module is used to parse the function code of the Modbus message of the real-time transmitted industrial data, establish a whitelist instruction set, and intercept the industrial data with function codes that are not in the whitelist instruction set.
[0006] Specifically, in step S2, the biometric feature is a voiceprint or an iris feature; Obtain device hardware features and network behavior data, and obtain dynamic device fingerprints through fuzzy hash calculation; A random number sequence is generated by a quantum random number generator and combined with a timestamp to generate a unique one-time authentication key as a quantum random number token.
[0007] Specifically, in step S3, the system CPU load is monitored in real time by a load monitoring unit to obtain the system load status, the sensitivity level is determined according to the data category of the industrial data transmitted in real time by a data classification table, and the encryption algorithm is determined by the sensitivity level and the system load status.
[0008] It is worth noting that in step S4, the Modbus message of the industrial data transmitted in real time is parsed by the industrial protocol deep analysis module to extract the function code and data address; the extracted function code is compared with the whitelist instruction set, and if the function code is in the whitelist instruction set, it is detected whether the data address is in the permitted range. If the data address is in the permitted range, the transmission of the industrial data to the industrial database is allowed. If the data address is not in the permitted range, the transmission of the industrial data is blocked and an alarm message is generated; in addition, if the function code is not in the whitelist instruction set, the transmission of the industrial data is blocked and an alarm message is generated.
[0009] Specifically, in step S2, for the network behavior in the dynamic device fingerprint, an anomaly detection model is deployed on the edge node. The anomaly detection model predicts the network behavior of the next cycle through LSTM time series prediction analysis based on the historical network behavior.
[0010] Optionally, in step S2, a threshold is preset, and an anomaly detection model is used to determine whether the predicted network behavior exceeds the preset threshold. When the predicted network behavior exceeds the preset threshold, an alarm is triggered.
[0011] Specifically, in step S2, the network behavior exceeding a preset threshold is used as an abnormal data feature, and the abnormal data feature is transmitted to a deep reinforcement learning model in the cloud for deep reinforcement learning training to update the rule base of the edge node.
[0012] It is worth noting that, in step S2, the adjusted rule base of the edge node is used to adjust the preset threshold of the anomaly detection model.
[0013] The beneficial effects of the present invention are as follows: the industrial database protection method based on multimodal authentication and encryption performs identity authentication through a multimodal authentication gateway, integrates biometrics and dynamic device fingerprints, improves the accuracy of identity authentication, and overcomes the defect that traditional static keys are easily copied. For real-time industrial data, an adaptive encryption engine is used to balance security and real-time requirements of industrial systems. In-depth analysis of industrial protocols is used to block protocol abuse attacks and ensure data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 It is a flow chart of an industrial database protection method based on multimodal authentication and encryption in one embodiment of the present invention; Figure 2 A flowchart of adaptive encryption in one embodiment of the present invention; Figure 3 The present invention is a flowchart of in-depth analysis of industrial protocols in one embodiment of the present invention. DETAILED DESCRIPTION
[0015] The specific embodiments of the present invention are further described below in conjunction with the accompanying drawings. It should be noted that the description of these embodiments is used to help understand the present invention, but does not constitute a limitation of the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0016] like Figure 1-3 As shown, an industrial database protection method based on multimodal authentication and encryption includes the following steps: S1: obtaining input data to be input into an industrial database, wherein the input data includes user identity information and industrial data transmitted in real time; S2: Use a multimodal authentication gateway to verify the user's identity information. The verification process is to generate a three-level identity verification mark by integrating biometrics, dynamic device fingerprints and quantum random number tokens; combine the quantum random number token, biometric mark and dynamic device fingerprint to determine the three-level identity verification result. Specifically, the three-level identity verification is verified separately, that is, the biometrics, dynamic device fingerprint and dynamic device fingerprint are verified separately. When all three pass, it means that the three-level identity verification is passed. Specifically, the user's voiceprint data is collected through the multimodal authentication gateway, such as extracting voiceprint features through a voiceprint recognition algorithm to generate a 128-dimensional voiceprint feature vector. At the same time, the user's iris image is collected, and the texture features are extracted using a Gabor filter to generate a 512-dimensional iris feature vector, which is fused to generate a biometric mark.
[0017] The hardware characteristics of the device, including the CPU serial number and MAC address, are obtained, combined with network behavior data, such as a request frequency of 5 times per second and a data packet size distribution of 100 bytes to 500 bytes, and a dynamic device fingerprint is generated through a fuzzy hash algorithm.
[0018] A quantum random number token is used to generate a 128-bit one-time authentication key, which is combined with biometric identification and dynamic device fingerprint to determine the user's identity through three-level identity verification; S3: After passing the three-level identity verification, the encryption algorithm of the adaptive encryption engine is determined according to the sensitivity level of the industrial data transmitted in real time and the system load status, and the industrial data transmitted in real time is encrypted by the encryption algorithm; S4: For the encrypted real-time transmitted industrial data, the industrial protocol deep analysis module is used to parse the function code of the Modbus message of the real-time transmitted industrial data, establish a whitelist instruction set, and intercept the industrial data with function codes not in the whitelist instruction set (i.e., with illegal function codes).
[0019] The industrial database protection method based on multimodal authentication and encryption performs identity authentication through a multimodal authentication gateway, integrates biometrics and dynamic device fingerprints, improves the accuracy of identity authentication, and overcomes the defect that traditional static keys are easily copied. For real-time industrial data, an adaptive encryption engine is used to balance security and real-time requirements of industrial systems. In-depth analysis of industrial protocols is used to block protocol abuse attacks and ensure data security.
[0020] It is worth noting that in step S2, the biometric feature is a voiceprint or an iris feature; Obtain device hardware features (CPU serial number, MAC address) and network behavior data (request frequency, data packet size distribution), and obtain a dynamic device fingerprint through fuzzy hash calculation. The dynamic device fingerprint is a unique device fingerprint and is updated every hour. A random number sequence is generated by a quantum random number generator and combined with a timestamp to generate a unique one-time authentication key as a quantum random number token.
[0021] In this embodiment, biometric verification: identity verification is performed through the user's voiceprint or iris, and matching is performed using a unique biometric feature.
[0022] The verification of dynamic device fingerprint is achieved through double comparison of the fuzzy hash value of the device hardware characteristics and the network behavior feature vector. The specific process is as follows: Fingerprint generation and storage: 1. Device hardware feature extraction: Collect static hardware information of the device (CPU serial number, MAC address, hard disk serial number, etc.); use fuzzy hash algorithm (such as SHA-3 with Salt) to hash the device hardware features to generate a fixed-length hardware feature hash value (for example, 256 bits).
[0023] 2. Network behavior extraction: monitor the network behavior of the device (such as traffic, CPU usage and other time series data); vectorize the network behavior data (for example, normalize it to the [0,1] interval) to generate a dynamic feature vector.
[0024] 3. Fingerprint synthesis: The hardware feature hash value (accounting for 60% of the weight) and the network behavior feature vector (accounting for 40% of the weight) are combined to generate a dynamic device fingerprint.
[0025] Comparison and verification logic: 1. Baseline fingerprint library: When a device is registered for the first time, its initial dynamic device fingerprint (including hardware hash value and network behavior baseline vector) is stored in the cloud.
[0026] 2. Real-time fingerprint comparison: For the matching of device hardware features, the edge node generates the current hardware hash value in real time and performs fuzzy matching with the cloud benchmark value (a certain error is allowed, such as Hamming distance ≤5%); hardware hash similarity ≥ 95% indicates that the hardware feature match is successful. For network behavior verification: compare the current network behavior vector with the network behavior baseline vector and calculate the dynamic similarity (such as cosine similarity); pass condition: similarity ≥ 90% is judged as normal behavior, indicating that the network behavior verification has passed, and similarity < 70% is judged as abnormal.
[0027] The verification pass conditions for dynamic device fingerprint verification are: hardware feature matching is successful and network behavior verification is passed.
[0028] The verification process of quantum random number token verification is as follows: the authentication server calls the quantum random number generator to generate a one-time quantum random number as a random number sequence; the random number sequence is bound to the current timestamp and device identifier to generate a unique one-time authentication key (i.e., challenge value) as a quantum random number token; the challenge value is sent to the user terminal through a secure communication channel; the user enters the challenge value and obtains the time when the user enters the challenge value; if the challenge value is correct and the time difference between the time when the user enters the challenge value and the current timestamp is less than the preset time interval, the verification is successful.
[0029] In this embodiment, the device hardware features are usually fixed, but in some cases, the device hardware features may be affected by forgery or changes (such as through virtualization technology, anonymization tools, etc.). Network behavior, as a dynamic feature, helps to increase the diversity and accuracy of fingerprints. Network behavior can reflect the behavior pattern of the device during actual use, not just static hardware properties. Network behavior, such as request frequency, data packet size distribution, accessed services, etc., is relatively difficult to forge, especially in large-scale attacks or malicious activities. This makes the generation of fingerprints through network behavior highly secure.
[0030] Network behavior changes over time and with usage patterns, and can reflect device usage habits or network connection methods. By updating network behavior data every hour, the timeliness and accuracy of fingerprints can be improved, ensuring that device fingerprints remain valid over a long period of time, making them highly adaptable.
[0031] Combining network behavior with hardware features helps identify devices more accurately. For example, if a device's hardware fingerprint changes (such as a MAC address change), but the network behavior pattern remains the same, the identity of the device can still be confirmed, achieving collaborative verification of device identity.
[0032] Furthermore, network behavior verification is performed by comparing with historical data: historical network data of the current device within a preset time period is obtained; the network behavior of the current device within the corresponding time period is compared with the historical network behavior of the device to check whether it conforms to the normal pattern. If the behavior pattern of the current device is generally consistent with the previous one within the same time period, it means that the network behavior is normal; if the abnormal behavior fluctuates greatly, further inspection may be required. In this embodiment, the historical network data within the same time period has more similar behavior patterns, which reduces the data processing steps and ensures a high accuracy of verification.
[0033] Specifically, the calculation process of fuzzy hash is as follows: for example, the CPU serial number "1234-5678-ABCD" and the MAC address "00-1A-2B-3C-4D-5E", network behavior data is obtained at the same time, including the request frequency "10 times per second" and the data packet size distribution "100 bytes to 500 bytes". The collected hardware feature data is preprocessed, and the CPU serial number and MAC address are converted into a unified coding format using a standardized algorithm to obtain "CPU: 12345678ABCD" and "MAC: 001A2B3C4D5E". Feature extraction is performed on the network behavior data, and the mean request frequency "10 times per second" and the standard deviation of the data packet size distribution "150 bytes" are calculated to obtain the behavior pattern parameters "frequency mean: 10, standard deviation: 150". The unified coding result and the behavior pattern parameters are applied to the fuzzy hash algorithm, and the local sensitive hash calculation is used to generate the preliminary hash value "a1b2c3d4e5f6". Get the current timestamp "2023-10-01 12:00:00" and the device's historical behavior data, extract the network behavior trend in the last hour, and get the dynamic adjustment factor "0.95". Correct the initial hash value according to the dynamic adjustment factor, update the fuzzy hash result through weighted calculation, and get the dynamic device fingerprint "a1b2c3d4e5f6*0.95".
[0034] Preferably, in step S3, the system CPU load is monitored in real time by a load monitoring unit to obtain the system load status, the sensitivity level is determined according to the data category of the industrial data transmitted in real time by a data classification table, and the encryption algorithm is determined by the sensitivity level and the system load status.
[0035] The encryption algorithm is selected from a preset data classification table; the adaptive encryption engine uses the data classification table to classify sensor flow data, process parameters and alarm logs, and determine the sensitivity level of each data category. By real-time monitoring of the CPU load (lightweight encryption is enabled when the threshold is ≥80%) and the sensitivity level, the encryption algorithm is dynamically switched to encrypt industrial data, that is, when the CPU load is less than 80%, the encryption algorithm is selected through the data classification table, and when the CPU load is greater than or equal to 80%, the selected encryption algorithm is downgraded to start lightweight encryption. LBlock encryption is used for real-time transmission of sensor data (pressure / temperature), with a delay of less than 2ms. The encryption level is determined based on the sensitivity of the data. The sensor data is encrypted using the lightweight LBlock algorithm, and the high-level national encryption SM4 is used for some core data.
[0036] The data classification table is as follows: Optionally, in step S4, the Modbus message of the industrial data transmitted in real time is parsed by the industrial protocol deep analysis module to extract the function code and the data address; the extracted function code is compared with the whitelist instruction set; if the function code is in the whitelist instruction set, the data address is detected to see if it is in the permitted range to determine the legality of the industrial data; if the data address is in the permitted range, the transmission of the industrial data to the industrial database is allowed; if the data address is not in the permitted range, the transmission of the industrial data is blocked and an alarm message is generated; in addition, if the function code is not in the whitelist instruction set (such as an illegal write instruction), the transmission of the industrial data is blocked and an alarm message is generated.
[0037] Specifically, the Modbus message is parsed through the industrial protocol deep analysis module, the function code 04 and the data address 0x0000 to 0xFFFF are extracted, and the function code and data address are compared according to the whitelist instruction set to determine the legitimacy of the industrial data.
[0038] It is worth noting that in step S2, for the network behavior in the dynamic device fingerprint, an anomaly detection model is deployed at the edge node. The anomaly detection model predicts the network behavior of the next cycle through LSTM time series prediction analysis based on historical network behavior. It is worth noting that this process is different from the network behavior verification in dynamic device fingerprint verification. This process is independent of the network behavior verification in dynamic device fingerprint verification.
[0039] Preferably, in step S2, a threshold is preset, and an abnormality detection model is used to determine whether the predicted network behavior exceeds the preset threshold. When the predicted network behavior exceeds the preset threshold, an alarm is triggered.
[0040] Deploy a lightweight anomaly detection model on edge nodes (such as routers, gateways, terminal devices, etc.). The anomaly detection model uses LSTM (Long Short-Term Memory Network) and is specifically designed to predict the normal pattern of time series data. By analyzing the network behavior of the device (such as time series data such as traffic and CPU usage), the anomaly detection model enables identification of whether abnormal behavior has occurred, such as attacks or failures. You can also use machine learning or deep learning models to model network behavior to obtain an anomaly detection model. The anomaly detection model can learn the normal behavior pattern of the device based on historical data (such as time series data such as traffic and CPU usage) and detect whether there is abnormal behavior. If the behavior deviates from the normal range learned by the anomaly detection model (that is, the set threshold), it means that there is a problem with the behavior.
[0041] In addition to network behavior, deploying anomaly detection models on edge nodes can also detect the following types of anomalies: Network anomalies: including traffic anomalies, abnormal connection frequency, and malicious communication patterns, such as DDoS attacks or abnormal data traffic; Behavioral anomalies: unusual patterns of user behavior or device operation, such as unusual login attempts, unusual file access or modification; Security incidents: early signs of attacks such as APT attacks, malware, and ransomware; Hardware failure: abnormal status of the device or sensor, such as hardware failure and device offline; System performance anomalies: These include unusual usage patterns of resources such as CPU, memory, and storage, such as excessive load or performance degradation.
[0042] When making predictions based on LSTM (Long Short-Term Memory Network), the anomaly detection model mainly relies on the following key factors to predict the network behavior in the next cycle: Historical data, LSTM (Long Short-Term Memory Network) makes predictions by learning and memorizing the time series patterns of historical data. It captures trends and periodic changes in data by considering the network behavior over the past period of time, and infers future changes in network behavior.
[0043] Time series characteristics, LSTM (Long Short-Term Memory Network) uses the "memory" mechanism to retain data dependencies over a long time span to make accurate predictions on time series data. The anomaly detection model uses the network behavior of the previous few cycles as input to predict the network behavior of the next cycle.
[0044] Threshold setting: Based on the rule base, a threshold is set (for example, the upper and lower limits of the predicted value). When the predicted network behavior in the next cycle exceeds this threshold, the system will issue an alarm to indicate potential anomalies or risks.
[0045] The cloud uses the Deep Q Network (DQN) to analyze the correlation of multi-node alarms and identify APT attack chains. DQN processes and analyzes the alarm data of multiple nodes through deep learning, learns the temporal and spatial correlation between alarms, and thus identifies the pattern of APT attack chains.
[0046] It is worth noting that in step S2, the network behavior exceeding the preset threshold is used as an abnormal data feature, and the abnormal data feature is transmitted to the deep reinforcement learning (DRL) model in the cloud for deep reinforcement learning training to adjust the rule base of the edge node. Through the reinforcement training model in the cloud, the rule base is continuously updated and optimized to enhance the detection capability of the edge node in complex scenarios.
[0047] Transmit abnormal data features to the cloud server through the edge node network interface. Load the deep reinforcement learning (DRL) model on the cloud server. The deep reinforcement learning (DRL) model analyzes large-scale historical attack data and input abnormal data features, first classifies the attack mode or abnormal behavior, and then dynamically obtains new rules through reinforcement learning based on different types of attack modes or abnormal behaviors. The new rules are traffic thresholds, CPU usage thresholds, and other rules. The deep reinforcement learning (DRL) model outputs these new rules. Adjust the original rules in the rule base of the edge node by replacement. Obtain the adjusted rule base and transmit it to the edge node through the communication channel from the cloud to the edge node. Based on these rule bases, the edge node can adjust local protection measures in a timely manner to detect and respond to new attacks or abnormal behaviors.
[0048] Preferably, in step S2, the adjusted rule base of the edge node is used to adjust a preset threshold of the anomaly detection model.
[0049] When adjusting the rule base, the edge node needs to adjust the preset threshold of the anomaly detection model to adapt to the new network behavior. Necessity of threshold adjustment: The original threshold may no longer be applicable and needs to be adjusted according to the new rule base to avoid false positives or false negatives. The latest rule base content is transmitted to the edge node through the cloud to obtain the latest rule base content received by the edge node. According to the latest rule base content, the basis for adjusting the anomaly detection threshold parameters is analyzed to determine the threshold that needs to be adjusted.
[0050] The rule base contains the basis for adjusting the thresholds corresponding to the anomaly detection model, such as adjusting the threshold corresponding to the CPU usage rate from 80% to 75%. Obtain the anomaly detection model currently deployed on the edge node and analyze the existing threshold configuration in the anomaly detection model, such as the threshold corresponding to the current traffic is 1000Mbps. Update the rule base to the edge node through cloud transmission, and the edge node receives the latest rule base content, such as the threshold corresponding to the adjusted traffic and the threshold corresponding to the CPU usage rate. Analyze the basis for adjusting the thresholds corresponding to the anomaly detection model based on the latest rule base content, and determine the thresholds that need to be adjusted, such as adjusting the threshold corresponding to the traffic to 1200Mbps. Rerun the anomaly detection model with the adjusted thresholds and obtain the prediction results through LSTM. For example, the predicted value of the traffic is 1300Mbps, which exceeds the threshold of 1200Mbps and is determined to be abnormal.
[0051] The role of the rule base is to provide fast and real-time anomaly detection capabilities for edge nodes. Specifically, the role of the edge rule base includes: Real-time detection: Edge nodes can use predefined rules in the rule base to quickly identify and respond to abnormal events, such as network attacks or equipment failures; Reduce latency: By applying the rule base locally at the edge node, it can quickly process and respond at the location where the data is generated, reducing the delay in data transmission to the cloud; Local decision-making: The rule base helps edge nodes make some decisions and processing independently, reducing dependence on cloud computing resources.
[0052] In this solution, multimodal dynamic authentication is used to combine biometrics and device behavior fingerprints to overcome the defect that traditional static keys are easy to copy. Through load-aware encryption, security and real-time requirements of industrial systems are balanced according to data classification and real-time resource monitoring. Through protocol-level zero-trust control, semantic parsing based on industrial protocols is achieved, and fine-grained instruction whitelists are implemented to block protocol abuse attacks. Through edge-cloud collaborative detection, lightweight edge models ensure low-latency responses, and cloud models continue to evolve to respond to new threats.
[0053] In this solution, a dynamic switching mechanism is used to solve the industrial real-time problem caused by the use of fixed encryption algorithms. The industrial protocol semantic level whitelist is used instead of relying solely on IP / port filtering. The introduction of device network behavior fingerprints can make up for the single-point verification defects of hardware features (hardware features are to enter the correct CPU serial number and MAC address of the hardware). The advantages of network behavior verification are mainly reflected in the following aspects: dynamic verification, network behavior is the dynamic feature of the device in actual use. Compared with static hardware features (such as MAC address, serial number, etc.), it is more real-time and changeable, and can reflect the real behavior of the device in a specific environment; increase security, by monitoring and analyzing the network behavior patterns of the device, such as traffic characteristics, communication frequency and request patterns, abnormal behavior can be identified, which helps to detect attack behaviors disguised as legitimate devices and increase the multiple levels of verification; prevent hardware cloning, traditional hardware feature verification is easy to be cloned or forged, while network behavior fingerprints are difficult to imitate. Attackers need to have similar network behaviors and interaction patterns. This method greatly improves security; strong adaptability, network behavior can adapt to changing work scenarios, especially when the device interacts with different network environments, behavioral fingerprints can be flexibly adapted to avoid the limitation that a single hardware feature cannot identify new environments or new devices; continuous monitoring and adjustment, by continuously monitoring the network behavior of the device, the system can continuously adjust and optimize the verification mode of the device to adapt to possible behavioral changes in long-term use. Through the above design, active protection of the entire life cycle of the industrial database can be achieved at one time.
[0054] The embodiments of the present invention are described in detail above with reference to the accompanying drawings, but the present invention is not limited to the described embodiments. For those skilled in the art, various changes, modifications, substitutions and variations of these embodiments are made without departing from the principles and spirit of the present invention, and still fall within the scope of protection of the present invention.
Claims
1. An industrial database protection method based on multimodal authentication and encryption, characterized in that: The following steps are involved: S1: obtaining input data to be input into an industrial database, wherein the input data includes user identity information and industrial data transmitted in real time; S2: using a multimodal authentication gateway to verify the user identity information, the verification process is to generate a three-level identity verification mark by integrating biometrics, dynamic device fingerprints and quantum random number tokens; S3: After passing the three-level identity verification, the encryption algorithm of the adaptive encryption engine is determined according to the sensitivity level of the industrial data transmitted in real time and the system load status, and the industrial data transmitted in real time is encrypted by the encryption algorithm; S4: For the encrypted real-time transmitted industrial data, the industrial protocol deep analysis module is used to parse the function code of the Modbus message of the real-time transmitted industrial data, establish a whitelist instruction set, and intercept the industrial data with function codes that are not in the whitelist instruction set.
2. The industrial database protection method based on multimodal authentication and encryption according to claim 1 is characterized in that: In the step S2, the biometric feature is a voiceprint or an iris feature; Obtain device hardware features and network behavior data, and obtain dynamic device fingerprints through fuzzy hash calculation; A random number sequence is generated by a quantum random number generator and combined with a timestamp to generate a unique one-time authentication key as a quantum random number token.
3. The industrial database protection method based on multimodal authentication and encryption according to claim 2 is characterized in that: In step S3, the system CPU load is monitored in real time by a load monitoring unit to obtain the system load status, the sensitivity level is determined according to the data category of the industrial data transmitted in real time by a data classification table, and the encryption algorithm is determined by the sensitivity level and the system load status.
4. The industrial database protection method based on multimodal authentication and encryption according to claim 3 is characterized in that: In step S4, the Modbus message of the industrial data transmitted in real time is parsed by the industrial protocol deep analysis module to extract the function code and the data address; the extracted function code is compared with the whitelist instruction set, and if the function code is in the whitelist instruction set, it is detected whether the data address is in the permitted range. If the data address is in the permitted range, the transmission of the industrial data to the industrial database is allowed; if the data address is not in the permitted range, the transmission of the industrial data is blocked and an alarm message is generated; in addition, if the function code is not in the whitelist instruction set, the transmission of the industrial data is blocked and an alarm message is generated.
5. The industrial database protection method based on multimodal authentication and encryption according to claim 4 is characterized in that: In step S2, for the network behavior in the dynamic device fingerprint, an anomaly detection model is deployed on the edge node. The anomaly detection model predicts the network behavior of the next cycle through LSTM time series prediction analysis based on the historical network behavior.
6. The industrial database protection method based on multimodal authentication and encryption according to claim 5 is characterized in that: In step S2, a threshold is preset, and an abnormality detection model is used to determine whether the predicted network behavior exceeds the preset threshold. When the predicted network behavior exceeds the preset threshold, an alarm is triggered.
7. The industrial database protection method based on multimodal authentication and encryption according to claim 6 is characterized in that: In step S2, the network behavior exceeding a preset threshold is used as an abnormal data feature, and the abnormal data feature is transmitted to a deep reinforcement learning model in the cloud for deep reinforcement learning training, and the rule base of the edge node is adjusted.
8. The industrial database protection method based on multimodal authentication and encryption according to claim 7 is characterized in that: In step S2, the adjusted rule base of the edge node is used to adjust a preset threshold of the anomaly detection model.
Citation Information
Patent Citations
Industrial network safety protection method based on serial link
CN106888185A
Industrial internet protection system and method
CN116743434A
Dynamic encryption method and system, computer equipment and storage medium
CN117131484A
Identity authentication method and system
CN118349975A
Cited By
Power system cloud side data secure transmission method and system
CN120750648A
Traffic overload control data security protection system based on quantum encryption technology
CN120825313A
Traffic overload data security protection system based on quantum encryption technology
CN120825313B
Federal alarm real-time compression method and system for 5G multi-domain operation and maintenance
CN121367955A
A federated alarm real-time compression method and system for 5G multi-domain operation and maintenance
CN121367955B