Method and System for Dynamically Constructing a Trusted Execution Environment for Domestic Application Operation
By collecting data in real time on domestic chemical industrial equipment and combining it with blockchain network, a trusted execution environment is dynamically built, and the credibility and security problems of domestic chemical industrial equipment in complex operating environments are solved, and data immutability and high reliability of verification are achieved.
Patent Information
- Application Number
- CN202510659994.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-05-22
AI Technical Summary
The existing technology cannot adapt to the dynamically changing operating state of domestic industrial equipment. Traditional static security protection is difficult to meet the trusted needs in complex operating environments. It has strong hardware dependence and is difficult to achieve flexible trusted consensus among distributed nodes.
By collecting mechanical operation data in real time and irreversibly bound to the device's unique identifier and time stamp, the data collection is generated and input into the blockchain network for segmentation and cross-verification, output verification information, and multi-dimensionally coupled with the real-time operation parameter flow, dynamically build a trusted execution environment.
It realizes a comprehensive perception of the operating status of industrial equipment, ensures that the data source is traceable and tamper-free, improves the adaptability of verification reliability and security policies, and adapts to dynamic security needs under complex operating conditions.
Smart Images

Figure CN120185941B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of industrial Internet of Things security technology, and in particular to a method and system for dynamically constructing a trusted execution environment for running domestic applications. Background Art
[0002] During the operation of domestically produced industrial equipment, critical applications must be executed in a trusted environment to prevent data tampering and malicious attacks. Because equipment operating states are complex and ever-changing, involving the interaction of multi-source heterogeneous data, traditional static security protections struggle to meet the real-time trust requirements of dynamic environments. Therefore, a method is urgently needed that can automatically build a trusted execution environment based on the real-time operating state of the equipment.
[0003] Existing solutions utilize static trusted execution environments (TEDEs) built on hardware-based trusted modules. This approach uses pre-configured security policies on the device and hardware encryption modules to isolate the runtime environment. This approach relies on a predefined rule base and utilizes hardware security chips to verify signatures on critical data, ensuring the trustworthiness of the execution environment.
[0004] This solution is unable to adapt to the dynamic operating conditions of domestically produced industrial equipment. Pre-configured security policies struggle to accommodate real-time operating adjustments, and its high hardware dependency makes it difficult to achieve flexible, trusted consensus across distributed nodes. Furthermore, static isolation mechanisms fail to effectively integrate real-time operational data, leading to a disconnect between environment construction and actual security needs. This makes it difficult to meet the trusted assurance requirements of highly dynamic industrial scenarios. Summary of the Invention
[0005] This application provides a method and system for dynamically constructing a trusted execution environment for running domestic applications, which is used to solve the problems of low data credibility and poor dynamic collaborative guarantee capability of execution environment security of domestic industrial equipment in complex operating environments in the existing technology.
[0006] In a first aspect, the present application provides a method for dynamically constructing a trusted execution environment for running domestic applications, including:
[0007] Real-time collection of mechanical operation data during the continuous operation cycle of domestically produced industrial equipment;
[0008] Irreversibly binding the machine operation data, the unique identifier of the domestically produced industrial equipment, and the collection timestamp to generate a data set;
[0009] Inputting the data set into a preset blockchain network, the blockchain network performs segmentation processing on the data set to obtain segmentation results, and performing cross-validation on the segmentation results between multiple independent nodes to output verification information;
[0010] Multidimensionally couple the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multidimensional coupling characteristics;
[0011] According to the multidimensional coupling characteristics, dynamically construct a trusted execution environment in combination with the domestic application operation data of the domestic industrial equipment.
[0012] Optionally, the inputting the data set into a preset blockchain network, where the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information, including:
[0013] Input the data set into a preset blockchain network, and through the segmentation module of the blockchain network, segment the mechanical operation data in the data set into multiple data segments according to the continuous time stamp order;
[0014] Through the distribution module of the blockchain network, distribute each data segment to an independent node in the blockchain network respectively, so that each independent node generates a verification identification code corresponding to the data segment;
[0015] Combine the verification identification codes corresponding to all the data segments in the time order of the data segments to generate a global verification identification code sequence corresponding to the data set;
[0016] In the blockchain network, according to the global verification identification code sequence, initiate a consistency confirmation request to the independent node that distributes the corresponding data segment. When more than a preset number threshold of independent nodes confirm the verification identification code of the same data segment to be consistent, generate verification information.
[0017] Optionally, the in the blockchain network, according to the global verification identification code sequence, initiate a consistency confirmation request to the independent node that distributes the corresponding data segment. When more than a preset number threshold of independent nodes confirm the verification identification code of the same data segment to be consistent, generate verification information, including:
[0018] In the blockchain network, establish a verification task queue corresponding to the global verification identification code sequence, where each verification task corresponds to a data segment and contains the identification information of the corresponding data segment and the independent node list;
[0019] For each verification task in the verification task queue, send a confirmation request to all the independent nodes in the independent node list corresponding to the verification task, and the confirmation request includes the verification identification code of the data segment to be confirmed;
[0020] Receiving the confirmation response information returned by each independent node in the independent node list for the same to-be-confirmed data segment, where the confirmation response information includes an approval or rejection mark for the verification identification code of the to-be-confirmed data segment;
[0021] According to the confirmation response information, counting the number of independent nodes that approve the verification identification code of the to-be-confirmed data segment;
[0022] When the number exceeds a preset quantity threshold, marking the verification identification code of the to-be-confirmed data segment as the confirmed state;
[0023] Recombining the verification identification codes of all data segments in the confirmed state in the original order in the global verification identification code sequence;
[0024] Generating verification information based on the recombined verification identification code sequence.
[0025] Optionally, the multi-dimensional coupling of the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features includes:
[0026] Extracting a set of continuous period parameters matching the timestamp traceability chain of the verification information from the real-time operation parameter stream of the domestic industrial equipment;
[0027] Dividing the set of continuous period parameters and the verification information into multiple parameter association groups according to the equipment operation stage, and each parameter association group contains real-time operation parameters synchronized in time within the same equipment operation stage and the recombined verified identification codes;
[0028] Performing multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features.
[0029] Optionally, the performing multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features includes:
[0030] Extracting the dynamic change features of the real-time operation parameters and calculating the credibility weights according to the confirmation status of the verified identification codes;
[0031] Superposing the dynamic change features and the credibility weights according to a preset weight relationship to generate a feature vector;
[0032] Calculating the inter-stage transition probability and the parameter change gradient according to the enhanced feature vectors of adjacent parameter association groups, and constructing an inter-stage continuity association matrix;
[0033] Combining the feature vectors of all parameter association groups and the inter-stage continuity association matrix to generate multi-dimensional coupling features.
[0034] Optionally, the step of respectively allocating each of the data segments to an independent node in the blockchain network so that each independent node generates a verification identification code corresponding to the data segment includes:
[0035] Allocating multiple data segments to different independent nodes in the blockchain network;
[0036] Based on each independent node's verification of the allocated data segment, verifying the consistency of the device unique identifier of the data segment and the continuity of the timestamp interval of the data segment;
[0037] When both the consistency and continuity are verified, generating a verification identification code.
[0038] Optionally, the step of dynamically constructing a trusted execution environment according to multi-dimensional coupling characteristics and combining the domestic application operation data of domestic industrial equipment includes:
[0039] Based on the multi-dimensional coupling characteristics, determining the environmental security level requirements corresponding to the current device operation stage;
[0040] According to the device function module call relationship recorded in the domestic application operation data, establishing a trusted execution environment configuration template that matches the environmental security level requirements;
[0041] Adapting the trusted execution environment configuration template to real-time operation parameters to generate an environment construction instruction set;
[0042] Executing the environment construction instruction set at the hardware layer of the domestic industrial equipment to construct a trusted execution environment.
[0043] In a second aspect, the present application provides a system for dynamically constructing a trusted execution environment for domestic application operation, including:
[0044] An acquisition module, configured to acquire mechanical operation data in real time during the continuous operation cycle of the domestic industrial equipment;
[0045] A generation module, configured to irreversibly bind the mechanical operation data, the unique identifier of the domestic industrial equipment, and the acquisition timestamp to generate a data set;
[0046] An input module, configured to input the data set into a preset blockchain network, where the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information;
[0047] A coupling module, configured to perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics;
[0048] A building block for dynamically building a trusted execution environment according to multi-dimensional coupling features and in combination with the domestic application operation data of domestic industrial equipment.
[0049] In a third aspect, the present application provides a computing device, including a processor and a memory. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the method for dynamically building a trusted execution environment for domestic application operation according to any one of the first aspect.
[0050] In a fourth aspect, the present application provides a computer storage medium, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the method for dynamically building a trusted execution environment for domestic application operation according to any one of the first aspect is implemented.
[0051] In the present application, a method for dynamically building a trusted execution environment for domestic application operation is provided. The method includes: during the continuous operation cycle of domestic industrial equipment, mechanically operating data is collected in real time; the mechanical operating data, the unique identifier of the domestic industrial equipment, and the collection timestamp are irreversibly bound to generate a data set; the data set is input into a preset blockchain network, and the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and cross-verification is performed on the segmentation result among multiple independent nodes to output verification information; the verification information is multi-dimensionally coupled with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features; according to the multi-dimensional coupling features, in combination with the domestic application operation data of domestic industrial equipment, a trusted execution environment is dynamically built.
[0052] The technical solution provided by the present application has the following beneficial effects:
[0053] The present application realizes the comprehensive perception of the operation state of industrial equipment and provides a raw data basis for building a trusted environment. By binding the device identifier and the timestamp, it ensures that the data source is traceable and cannot be tampered with, and establishes a trusted data basis. The distributed node consensus mechanism is used to verify the authenticity of the data, solve the single-point trust problem, and improve the reliability of verification. The verified trusted data is deeply associated with the real-time operation parameters to form a feature expression reflecting the true state of the device. Based on the real-time state features, the security policy is adaptively adjusted to achieve an accurate match between the environment and the device operation state.
[0054] Furthermore, the present application also divides the mechanical operation data into continuous data segments according to the timestamp through the blockchain network, distributes them to different independent nodes to generate verification identification codes, initiates multi-node consistency confirmation after global sequence recombination, and outputs verification information when a preset threshold is reached. This process realizes the segmented verification and distributed consensus of the data.
[0055] Moreover, through data sharding verification and cross-node consensus mechanism, this solution achieves highly reliable authentication of large-scale industrial data while ensuring verification efficiency. It not only avoids the performance bottleneck of single-node verification but also ensures the immutability of verification results through multi-node cross-checking, providing a trusted data foundation for subsequent dynamic environment construction.
[0056] These aspects or other aspects of the present application will be more clearly understood in the following description of the embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0058] Figure 1 It is a flowchart of a method for dynamically constructing a trusted execution environment for domestic application operation provided by an embodiment of the present application;
[0059] Figure 2 It is a schematic structural diagram of a system for dynamically constructing a trusted execution environment for domestic application operation provided by an embodiment of the present application;
[0060] Figure 3 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0061] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application.
[0062] In some processes described in the specification, claims and above-mentioned accompanying drawings of the present application, there are multiple operations that appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear herein or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., and do not represent a sequence, nor do they limit that "first" and "second" are of different types.
[0063] Researchers have found that current domestic industrial equipment has problems such as insufficient verification of data credibility and static rigidity of the execution environment during operation, making it difficult to meet the dynamic safety requirements under complex working conditions. Based on this, a method for dynamically constructing a trusted execution environment for domestic applications is provided. After irreversibly binding the equipment operation data with spatio-temporal information, this method uses a blockchain network to achieve distributed verification and deeply couples the verification results with real-time parameters, finally constructing a trusted execution environment that adapts to the equipment operation state. The technical solution of this application is applicable to scenarios such as health monitoring of domestic industrial equipment and intelligent manufacturing that require high-dynamic trusted guarantee.
[0064] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0065] Figure 1 The flowchart of a method for dynamically constructing a trusted execution environment for domestic application provided by the embodiment of the present application is as Figure 1 shown, and the method includes:
[0066] Step 101: During the continuous operation cycle of the domestic industrial equipment, collect mechanical operation data in real time.
[0067] In this step, the domestic industrial equipment refers to industrial production equipment manufactured using domestic independent technologies. The continuous operation cycle represents the complete working process of the equipment from startup to shutdown. The mechanical operation data represents physical parameters such as vibration, temperature, and rotational speed generated during the operation of the equipment. It is the mechanical motion data of the domestic industrial equipment.
[0068] In the embodiment of the present application, various mechanical parameter data during the operation of the equipment are collected in real time through domestic sensors installed on the equipment. The collection process covers the entire working cycle of the equipment to ensure the continuity and integrity of the data. The sensors obtain data according to the preset sampling frequency and temporarily store the original data in the local buffer for subsequent processing. The types of collected data include but are not limited to key operation indicators such as vibration amplitude, bearing temperature, and motor speed.
[0069] For example, taking a domestic numerical control machine tool as an example, during the machining process, the vibration sensor and temperature sensor installed on the spindle collect the spindle vibration data and bearing temperature data once per second. These data, together with the time stamp of the collection moment, are recorded and transmitted to the data processing unit. For example, at 8:00 am, the spindle vibration data is X units and the bearing temperature is Y degrees. These data are marked as the mechanical operation data at the same moment.
[0070] Step 102: Irreversibly bind the mechanical operation data, the unique identifier of the domestic industrial equipment, and the acquisition timestamp to generate a data set.
[0071] In this step, irreversible binding means an unalterable data association implemented by cryptographic methods. A data set means a data combination that has been structured.
[0072] In the embodiment of the present application, the collected mechanical operation data, the unique identity code burned at the time of equipment factory shipment, and the timestamp information accurate to the millisecond level are bound through a hash algorithm to generate a structured data packet with the characteristic of being unalterable. During the processing, the original data is first standardized and formatted, and then it is input into a hash function operation together with the equipment identifier and the timestamp, and finally a data digest with a fixed length is output to form a complete data set.
[0073] For example, continuing the previous example, the vibration data X and temperature data Y of a numerically controlled machine tool, together with the unique machine number Z and the acquisition time 8:00:00.000, are subjected to a hash operation to generate a 64-bit hexadecimal string as the data digest, and this digest and the original data together form a complete data set unit. For example, if the data digest is A1B2C3..., then a data packet containing the original data and the digest is formed.
[0074] Step 103: Input the data set into a preset blockchain network. The blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information.
[0075] In this step, the blockchain network refers to a distributed verification system composed of multiple domestic independent nodes. Each node performs parallel verification on the segmented data segments through a consensus mechanism to ensure that the verification process is decentralized and unalterable. This network uses a domestic encryption algorithm to achieve secure communication between nodes. Each node independently stores the complete data segment verification record, and ensures the credibility of the output verification information through cross-node consistency confirmation. Segmentation processing means decomposing a large data set into multiple small units that can be processed in parallel. Cross-verification means that multiple verification parties independently verify the same data. The verification information is information regarding the authenticity and chronological integrity of the data, used to prove that the source of the mechanical operation data is credible and has not been tampered with, and at the same time ensure that the data acquisition timestamps are continuous and conflict-free.
[0076] In the embodiments of the present application, the data set is sliced into several consecutive data segments according to the time sequence, and each data segment contains the data set within a fixed time duration. These data segments are distributed to different verification nodes in the blockchain network, and each node independently performs integrity verification on the received data segment, including verifying the matching of hash values, the continuity of timestamps, etc. After each node completes the verification, a verification result with a digital signature is generated. When a sufficient number of nodes verify a data segment successfully, the data segment is regarded as valid.
[0077] For example, all the data sets generated by a numerically controlled machine tool during the period from 8:00 to 8:05 in the morning are packaged into a data segment and assigned to three independent nodes in the blockchain network for verification. Node 1 verifies that the hash values of 30 data packets within this period are all correct and the timestamps are continuous; Nodes 2 and 3 also draw the same conclusion. When two of the three nodes confirm that the data is valid, the system generates the verification information for this period, including the time range of successful verification and data characteristics.
[0078] Step 104: Perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics.
[0079] In this step, the real-time operation parameter stream represents the operation state data of the device at the current moment. Multi-dimensional coupling means the deep fusion of various data characteristics. The multi-dimensional coupling characteristics are composite feature vectors generated by fusing the credibility index in the verification information and the state index in the real-time operation parameters. It not only includes the quantization values of the current physical states such as vibration and temperature of the device, but also integrates the data credibility score generated in the blockchain verification link, and forms a unified feature expression that can reflect both the actual operation situation of the device and the data reliability through weighted association.
[0080] In the embodiments of the present application, the output verification information and the real-time sensor data stream of the device are subjected to feature-level fusion processing. First, the two types of data are aligned in time, and then the credibility features in the verification information and the state features in the real-time data are extracted, and a composite feature vector that can reflect both the actual state of the device and include credibility evaluation is generated through a feature weighted fusion algorithm. This process ensures that the output features include both real-time performance and credible guarantee.
[0081] For example, the vibration data of the numerically controlled machine tool at the current moment (8:06) is X', which is compared with the data characteristics of the 8:00 - 8:05 data verified in Step 103. The system calculates the deviation degree between the current vibration data and the verified data characteristics, and combines credibility indicators such as the number of verification nodes to generate a two-dimensional feature vector including the state value and credibility. For example, the feature vector is (0.85, 0.92), indicating normal state and high data credibility.
[0082] Step 105: Dynamically construct a trusted execution environment based on the multi-dimensional coupling features and in combination with the domestic application operation data of domestic industrial equipment.
[0083] In this step, the domestic application operation data refers to the real-time operation logs and status records generated by domestic control software, monitoring systems, etc. running on industrial equipment, including runtime information such as program call sequences and resource occupancy. These data, together with the device hardware status features, serve as the basis for formulating policies for dynamically constructing a trusted execution environment, ensuring that the environment configuration precisely matches the actual needs of domestic applications. The trusted execution environment represents a secure operating space.
[0084] In the embodiment of this application, based on the generated multi-dimensional coupling features, the system dynamically evaluates the current required security protection level. According to the values of each dimension in the feature vector, a matching configuration scheme is selected from a predefined security policy library, including parameters such as memory isolation strength and data encryption level. Then, the security instruction set at the device bottom layer is called to dynamically construct a trusted execution environment that matches the current device operating state.
[0085] For example, when the feature vector of a numerically controlled machine tool shows a status value of 0.85 (normal range 0.8 - 1.2) and a credibility of 0.92 (high credibility threshold 0.9), the system selects a medium security protection policy: enable memory isolation while maintaining high computing performance. The specific implementation is: divide a dedicated memory area to run the machining program, and at the same time maintain the normal communication bandwidth with the sensor data channel.
[0086] This method realizes the dynamic trusted guarantee of the operating environment of domestic industrial equipment through the complete closed-loop processing from data acquisition to environment construction. It ensures data authenticity from the source, improves credibility through distributed verification, and finally constructs a secure execution environment that precisely matches the real-time state of the device. The entire process requires no manual intervention, ensuring both security and operation efficiency, and is particularly suitable for industrial manufacturing scenarios with high requirements for both real-time performance and credibility.
[0087] To solve the integrity and credibility problems of industrial equipment data during the distributed verification process, in some embodiments, Step 103: Input the data set into a preset blockchain network, and the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information, including:
[0088] Step 201: Input the data set into a preset blockchain network, and through the segmentation module of the blockchain network, segment the mechanical operation data in the data set into multiple data segments according to the continuous time stamp order.
[0089] In step 201, a data segment refers to a mechanical operation data unit divided by time continuity, where each data segment contains continuous mechanical operation data associated with a unique device identifier and the corresponding time stamp interval.
[0090] In the embodiment of the present application, the segmentation module of the blockchain network adopts the time sliding window technology. Based on the device sampling period, the data set with continuous time stamps is segmented into several data segments of equal length. A segment identifier and start and end time marks are added to the head of each data segment to form an independently verifiable data unit.
[0091] Step 202: Through the distribution module of the blockchain network, each of the data segments is respectively distributed to an independent node in the blockchain network, so that each of the independent nodes generates a verification identification code corresponding to the data segment.
[0092] In step 202, the verification identification code is an anti-counterfeiting verification label generated by an independent node, and includes a data segment hash value, a node digital signature, and a verification time stamp.
[0093] In the embodiment of the present application, the distribution module adopts a round-robin scheduling algorithm to evenly distribute each data segment to the independent nodes in the network. After each node receives a data segment, it first verifies the continuity of the time stamp, then calculates the hash value of the data segment content, and finally signs the "hash value + time stamp" with the node private key to generate a unique verification identification code.
[0094] Step 203: Combine the verification identification codes corresponding to all the data segments in the time order of the data segments to generate a global verification identification code sequence corresponding to the data set.
[0095] In step 203, the global verification identification code sequence is a chained structure of verification identification codes arranged in time order, and each position corresponds to a specific time period in the original data set.
[0096] In the embodiment of the present application, after the system collects the verification identification codes returned by all nodes, it reorders them according to the start time of the data segments, and ensures the time continuity of the sequence by comparing the end time and start time of the front and back data segments. Finally, an identification code chain covering the complete time period is generated.
[0097] Step 204: In the blockchain network, according to the global verification identification code sequence, initiate a consistency confirmation request to the independent node that distributes the corresponding data segment. When more than a preset number threshold of independent nodes confirm the verification identification code of the same data segment to be consistent, verification information is generated.
[0098] In step 204, the preset number threshold refers to the minimum number of consensus nodes required to determine the validity of data in the blockchain network, and is usually set to more than two-thirds of the total number of nodes.
[0099] In this embodiment, the network broadcasts a global sequence to all participating nodes, requiring them to reconfirm the identification codes of the data segments they have verified. Each node verifies the digital signature validity and timestamp logic of the identification code and returns a confirmation result. When the number of confirmations for a data segment reaches a threshold, the system generates a final verification report containing all verification information for that period.
[0100] Here's a specific example:
[0101] In the CNC machine tool example, 30 data packets generated between 8:00 AM and 8:05 AM (six per minute, each containing vibration data X, temperature data Y, machine number Z, and a timestamp) are segmented into five data segments, each corresponding to six data packets within a minute. The blockchain network's distribution module sends these five data segments to three independent verification nodes (nodes A, B, and C). Node A receives the 1st and 4th minute segments, node B receives the 2nd and 5th minute segments, and node C receives the 3rd minute segment. Each node verifies each received data segment by first checking that the timestamps of the six packets are consecutive (e.g., 8:00:00.000 to 8:00:59.999). It then recalculates the hash value of each packet and compares it to the original digest. If all of the digests pass, a verification code is generated (e.g., node A generates verification code M1 for the 1st minute segment, which includes the node's digital signature). The system combines the identification codes of the five time periods into a global sequence [M1, M2, M3, M4, M5] in chronological order and initiates confirmation requests from each node. For example, for the first minute, nodes A and C (unverified but with a stored copy) confirm the data. When two nodes (a threshold exceeding half of the three nodes) return consistent confirmation, the time period passes verification. The resulting verification information includes the validity status of each minute period (e.g., "verified" for the first minute), characteristic statistics (e.g., vibration mean value 0.85 = ΣX / 6, temperature range 1.2 = Ymax - Ymin), and the number of nodes participating in the verification.
[0102] In the embodiments of this application, this solution ensures the efficiency of large-scale industrial data verification through time-series data segmentation and distributed consensus verification. It also ensures data authenticity through multi-node cross-verification, providing a reliable data foundation for a dynamic trusted execution environment. The entire process does not rely on specific hardware and is fully adapted to the application scenarios of domestically produced industrial equipment.
[0103] To address the coordination and efficiency issues of multi-node verification in a blockchain network, in some embodiments, step 204: in the blockchain network, based on the global verification identification code sequence, a consistency confirmation request is initiated to the independent nodes assigned to the corresponding data segment. When more than a preset number of independent nodes confirm that the verification identification code for the same data segment is consistent, verification information is generated, including:
[0104] Step 301: In the blockchain network, establish a verification task queue corresponding to the global verification identification code sequence, where each verification task corresponds to a data segment and includes the identification information of the corresponding data segment and a list of independent nodes.
[0105] In step 301, the verification task queue is a first-in-first-out list storing tasks of data segments to be verified. Each task includes a data segment number, a time range, and a list of node IDs responsible for verification. Exemplarily, node A generates the identification code H1 of data segment 1. After nodes B and C receive the confirmation request, they need to calculate the hash value H1' of data segment 1 by themselves and compare it with H1. If H1' = H1, the identification code is recognized.
[0106] In the embodiment of the present application, the system parses the global verification identification code sequence, creates a verification task for each data segment, and records in the task the position index of the data segment in the original sequence, the number of verification identification codes included (such as 6 per minute), and the node information that has participated in verification (such as nodes A and B). The queue is arranged in the time order of data segments to ensure the verification timeliness.
[0107] Step 302: For each verification task in the verification task queue, send a confirmation request to all independent nodes in the list of independent nodes corresponding to the verification task. The confirmation request includes the verification identification code of the data segment to be confirmed.
[0108] In step 302, the confirmation request is an instruction message triggering the node to perform secondary verification. The data segment to be confirmed refers to each segmented data segment as the data segment to be confirmed.
[0109] In the embodiment of the present application, the network controller takes out the task from the head of the queue and sends a request message to each verified node on record. The message is signed using the domestic encryption algorithm SM2, and the content includes the ciphertext form of all verification identification codes of the data segment (such as M1 generated by node A and M1' generated by node C), and the system time when the request is initiated. After each node receives it, it first verifies the validity of the signature.
[0110] Step 303: Receive the confirmation response information returned by each independent node in the list of independent nodes for the same data segment to be confirmed. The confirmation response information includes an approval or rejection mark for the verification identification code of the data segment to be confirmed.
[0111] In step 303, the confirmation response information is a simple reply returned by the node, including a binary judgment result (approval / rejection) and a response timestamp.
[0112] In the embodiments of the present application, after each node receives a request, it re-verifies the matching of the original data segment stored locally with the verification identification code (such as recalculating the hash), and checks whether the timestamp is within the valid window (such as ±5 seconds). After passing the verification, an approval mark (value 1) is generated, otherwise a rejection mark (value 0) is generated, and after appending the current time, it is signed with the node's private key and returned.
[0113] Step 304: According to the confirmation response information, count the number of independent nodes that approve the verification identification code of the data segment to be confirmed.
[0114] In step 304, the approval quantity statistics is a process of summing up all the node response results for a specific data segment.
[0115] In the embodiments of the present application, the system collects all node responses within a preset timeout period (such as 10 seconds), first verifies the digital signature of each response, and then accumulates the approval mark values. For example, if responses from node A (1), node B (1), and node C (0) are received, the approval quantity is 2. The statistical result is compared with the threshold required for this data segment (such as 2 / 3 majority).
[0116] Step 305: When the quantity exceeds the preset quantity threshold, mark the verification identification code of the data segment to be confirmed as the confirmed state.
[0117] In step 305, the confirmed state is the marked state after the data segment passes the verification, including metadata such as the passing time and the number of participating nodes.
[0118] In the embodiments of the present application, when the approval count of a certain data segment reaches the threshold (such as 2 approvals out of 3 nodes), the system appends a status mark to its verification identification code, and records the passing moment and the list of node IDs participating in the verification. The data segments that do not reach the threshold are marked as the to-be-reviewed state, triggering the subsequent processing flow.
[0119] Step 306: Reorganize the verification identification codes of all data segments in the confirmed state according to their original order in the global verification identification code sequence.
[0120] In step 306, the reorganization operation is a process of rearranging the data segments that have passed the decentralized verification back in the time line.
[0121] In the embodiments of the present application, the system scans all data segments marked as the confirmed state, and reconnects them in their original time order (such as 8:00, 8:01, 8:02...). For missing time periods (such as data segments that are not confirmed due to some nodes not responding), a supplementary verification process is automatically initiated to ensure the time continuity of the final sequence.
[0122] Step 307: Generate verification information based on the reorganized verification identification code sequence.
[0123] In the embodiment of the present application, the system generates a structured report based on the recombined sequence, including: verification status of each period (such as verified from 8:00 to 8:04), data characteristic values (such as vibration average value 0.85), number of participating nodes (such as 2 out of 3 nodes passed), etc. The report is encapsulated in a format and signed with a network root certificate to ensure integrity.
[0124] The following is a specific example:
[0125] Based on the data verification scenario of the CNC machine from 8:00 to 8:05, the system first establishes a queue containing 5 verification tasks (corresponding to 1 data segment per minute). Taking the 8:00 period as an example, this verification task records the data segment number DS001, time range 8:00:00.000 - 8:00:59.999, and the list of nodes that participated in the verification of this segment [Node A, Node C]. The system sends a confirmation request to these two nodes, and the request contains the verification identification code M1 generated by Node A before (calculated from the average value of vibration data 0.85 = (0.84 + 0.86 + 0.83 + 0.87 + 0.85 + 0.85) / 6) and the temperature range difference 1.2 = 46.3 - 45.1. After receiving the request, Node A rechecks the 6 original data packets stored locally, confirms that the timestamps are continuous and the hash values match (such as the hash value of the first data packet at 8:00:00.000 is still A1B2C3...), and then returns an approval mark; although Node C did not participate in the initial verification, it also returns an approval after completing the same verification through the stored copy. The system receives 2 approval responses within 10 seconds (the preset threshold is 2), and then marks DS001 as the confirmed status, and records the passing time as 8:05:30.500. After processing the verification tasks of 5 periods in sequence, the system recombines the verification identification codes in the order of [DS001, DS002, DS003, DS004, DS005], and the generated final verification information includes: status of each period (such as DS003 initially had only 1 approval due to Node B being down, and then passed through supplementary verification at 8:06:15.200), vibration characteristic value (overall average value of 5 minutes is 0.86 = (0.85×1 + 0.87×1 + 0.84×1 + 0.88×1 + 0.86×1) / 5), and node participation situation (a total of 3 nodes were used to complete the verification).
[0126] In the embodiment of the present application, this solution ensures the rigor of the verification process through task queue management and multi-round node confirmation mechanism, and can automatically handle node anomalies. Finally, it outputs a verification report with time continuity and complete credibility evaluation, providing accurate data authenticity guarantee for the construction of the dynamic environment of industrial equipment.
[0127] To solve the problem of the integration of real-time data of industrial equipment and the blockchain verification results, in some embodiments, step 104: The multi-dimensional coupling of the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features includes:
[0128] Step 401: Extract a set of continuous period parameters that match the timestamp traceability chain of the verification information from the real-time operation parameter stream of the domestic industrial equipment.
[0129] In step 401, the timestamp interval of the global verification identification code sequence in the verification information; the timestamp interval is defined by the start point and end point of the timestamp of each data segment after being segmented by the blockchain network. Continuous means an uninterrupted and complete period that exactly matches the timestamp traceability chain in the verification information. Specific example: If the timestamp traceability chain of the verification information is [T1, T2, T3] (continuous from T1 to T2 to T3), then [T1 data, T2 data, T3 data] is extracted from the real-time parameter stream as the set of continuous period parameters, with the requirements: the middle period cannot be missing (such as only extracting T1 and T3); the period interval needs to be equal to the device sampling period (for example, if it is sampled once every 1 second, then T2 = T1 + 1 second). The set of continuous period parameters is a data segment intercepted from the real-time data stream and aligned with the verified period, containing a sequence of sensor readings with the same time span.
[0130] In the embodiments of the present application, the system extracts the parameter sequence of the corresponding period from the real-time data buffer according to the time range recorded in the verification information (such as 8:00 - 8:05). When extracting, the sliding window matching algorithm is used to ensure that the timestamps are exactly aligned (for example, the data corresponding to 8:00:30.000 in the verification information must match the data with the same timestamp in the real-time stream), and linear interpolation is automatically performed to complete the missing data.
[0131] Step 402: Divide the set of continuous period parameters and the verification information into multiple parameter association groups according to the equipment operation stage, and each parameter association group contains the real-time operation parameters synchronized in time within the same equipment operation stage and the reorganized verified identification codes.
[0132] In step 402, in the scenario of health monitoring of domestic industrial equipment, the equipment operation stage includes the start-up stage, the stable operation stage, the load fluctuation stage, and the shutdown transition stage. The parameter association group is a data unit divided according to the equipment working state, containing the paired combination of the verified data features and the real-time parameters. The verified identification code is the state of the verification identification code after node consistency confirmation (that is, after being recognized by more than a preset number of independent nodes), and it is a verification identification code that has been confirmed to be valid.
[0133] In the embodiment of the present application, the system first identifies the device operation stage (such as startup, processing, idle), and then classifies and pairs the statistical values of each time period in the verification information (such as the average vibration per minute) with the real-time parameters according to the stage. Strict time synchronization is ensured within each group (for example, the average value of 0.87 at 8:01 in the verification is paired with 6 original readings at 8:01 in the real-time stream), and the belonging operation stage is marked (such as "processing stage").
[0134] Step 403: Perform multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features.
[0135] In step 403, the multi-dimensional coupling processing is an analysis process of generating a composite index through feature weighted fusion.
[0136] In the embodiment of the present application, for each parameter association group, perform: calculate the deviation degree of the real-time parameter from the verification benchmark (such as the difference of 0.01 between the real-time vibration value of 0.88 at 8:01 and the verification average value of 0.87); calculate the weight coefficient (0.01×0.67 = 0.0067) in combination with the verification credibility (such as 2 / 3 nodes passing in this time period); generate a three-dimensional feature vector including the original value, deviation degree, and credibility. The vectors of all groups are arranged in chronological order to form the final feature matrix.
[0137] The following is a specific example:
[0138] Based on the verification information of the CNC machine tool from 8:00 to 8:05 (including the average vibration value per minute [0.85, 0.86, 0.84, 0.87, 0.85] and the temperature range [1.1, 1.2, 1.0, 1.3, 1.1]), the system first extracts the vibration and temperature data for the 5 minutes before 8:06:00 from the real-time data stream (6 samples per minute, a total of 30 data points). After dividing these real-time parameters by minute, they are matched with the corresponding period means in the verification information: for example, the real-time vibration data [0.83, 0.84, 0.85, 0.84, 0.86, 0.85] in the 8:02 period is compared with the verification mean of 0.84, and the current minute vibration mean 0.845 = (0.83 + 0.84 + 0.85 + 0.84 + 0.86 + 0.85) / 6 is calculated. The deviation from the verification value is |0.845 - 0.84| / 0.84 = 0.006; at the same time, according to the number of verified nodes in this period, which is 2 (a total of 3 nodes), the credibility weight 0.67 = 2 / 3 is calculated. Finally, a multi-dimensional feature vector for this minute segment is generated (vibration mean 0.845, deviation 0.006, credibility 0.67). The feature vectors of the 5 periods are combined in the order of [8:02, 8:03, 8:04, 8:05, 8:06], and overall trend indicators such as the vibration change rate 0.01 = (the current 8:06 mean 0.85 - the earliest 8:02 mean 0.845) / 4 are calculated to form a complete coupled feature set for environmental construction decision-making.
[0139] In the embodiment of the present application, this solution realizes the multi-level feature fusion of the real-time state of the device and the blockchain verification result through spatio-temporal alignment data association and dynamic weighted fusion, which not only retains the detailed features of the original data but also integrates the credibility information of distributed verification, providing a decision-making basis that takes into account both accuracy and reliability for subsequent dynamic environment construction.
[0140] To solve the problem of the accuracy of multi-source data fusion of industrial equipment, in some embodiments, step 403: the multi-dimensional coupling process for each parameter association group to generate multi-dimensional coupling features includes:
[0141] Step 501: Extract the dynamic change features of the real-time operation parameters and calculate the credibility weight according to the confirmation status of the verified identification code.
[0142] In step 501, the dynamic change feature is a quantitative index reflecting the parameter fluctuation law, including statistical quantities such as mean, variance, and range. The confirmed status refers to passing the node consistency verification by exceeding the preset quantity threshold. The unconfirmed status refers to not passing the threshold verification. The credibility weight is a confidence coefficient calculated according to the verification node ratio and the degree of consistency.
[0143] In the embodiment of the present application, the system calculates the third-order statistical features for the real-time operation parameters within each parameter association group: moving average (taking a 10-second window); sum of absolute differences of adjacent samples (fluctuation intensity); difference between peak and valley (dynamic range). Meanwhile, according to the number of node confirmations recorded in the verified identification code during this period (such as 2 confirmations out of 3 nodes), the adjusted credibility coefficient is calculated according to the formula: weight = number of confirmations / total number of nodes × 0.8 + 0.2 (basic credibility).
[0144] Step 502: Superimpose the dynamic change feature and the credibility weight according to a preset weight relationship to generate a feature vector.
[0145] In step 502, the feature vector is a composite data structure that fuses the original feature and credibility, and there is a preset weighting relationship between each dimension.
[0146] In the embodiment of the present application, a dynamic weighting method is adopted for fusion: multiply the vibration-related features (mean, fluctuation intensity) by the credibility weight; multiply the temperature-related features (mean, dynamic range) by the square of the weight (highlighting highly credible data); splice the processed feature values to form a 6-dimensional vector (vibration processed value × 2, temperature processed value × 2, original weight, timestamp encoding).
[0147] Step 503: Calculate the inter-stage transition probability and parameter change gradient based on the enhanced feature vectors of adjacent parameter association groups, and construct an inter-stage continuity association matrix.
[0148] In step 503, the inter-stage transition probability is a quantitative indicator of the likelihood that a domestic industrial device switches from one operating stage (such as "start-up") to another (such as "processing"). Its calculation is based on the statistical frequency of stage switches in historical operation data. Specifically, the system analyzes the operation stage markers of adjacent parameter association groups (such as stage codes 1 to 2) and counts the proportion of the number of specific transitions (such as "start-up to processing") occurring in the total number of transitions starting from the "start-up" stage. For example, if the number of times the device transfers from "start-up" to "processing" in the historical data accounts for 80% of the total number of "start-up" times, the corresponding transition probability is recorded as 0.8. This probability is used to predict the evolution trend of the device operation state and provide a forward-looking basis for constructing a dynamic environment. The parameter change gradient is a directional indicator that describes the rate of change of key operating parameters (such as vibration and temperature) between adjacent stages, reflecting the severity of the device state change. Its calculation method is: the change amount of the mean value of the same parameter (such as vibration value) between two stages divided by the stage time interval (unit: minute). For example, if the vibration mean value in the "start-up" stage is 0.5 and rises to 0.8 after transferring to "processing", taking 2 minutes, then the gradient is (0.8 - 0.5) / 2 = 0.15 / minute. The gradient value can be positive or negative. A positive gradient indicates an upward trend of the parameter (such as the temperature gradually increasing), while a negative gradient indicates a downward trend (such as the rotational speed decreasing). This indicator is used to quantitatively evaluate the stability of the device state change and provide a quantitative basis for adjusting the environmental safety strategy. The cross-stage continuity correlation matrix is a transfer relationship table that describes the parameter evolution law between different operating stages.
[0149] In the embodiment of the present application, the system analyzes the difference in eigenvectors of adjacent parameter association groups in chronological order: calculates the vibration mean change rate = (the mean value of the latter group - the mean value of the former group) / time interval; counts the temperature fluctuation correlation (covariance divided by the product of the standard deviations of the two groups); records the stage transfer marker (such as "processing to idle"). Finally, a matrix containing 16 possible transfer states is generated, and each element stores the probability and typical parameter gradient of the corresponding transfer.
[0150] Step 504: Combine the eigenvectors of all parameter association groups and the cross-stage continuity correlation matrix to generate multi-dimensional coupled features.
[0151] In the embodiment of the present application, the 6D eigenvectors of each time period are arranged in chronological order as a feature matrix, and at the same time, a compressed representation of the correlation matrix (taking the first 3 principal components) is added to the head of the matrix. Finally, a coupled feature package containing N×6 + 3 dimensions is generated, where N is the number of parameter association groups.
[0152] The following is a specific example:
[0153] Based on 5 parameter correlation groups (1 group per minute) during the period from 8:02 to 8:06 on the CNC machine tool, the system first processes the group at 8:03: extracts the real-time vibration data [0.84, 0.85, 0.86, 0.85, 0.87, 0.86] to calculate dynamic features. Among them, the sliding average value 0.855 = (0.84 + 0.85 + 0.86 + 0.85 + 0.87 + 0.86) / 6, and the fluctuation intensity 0.03 = (|0.85 - 0.84| + |0.86 - 0.85| +...) / 5; combines the verification information (2 / 3 nodes passed) during this period to calculate the credibility weight 0.67 = 2 ÷ 3 × 0.8 + 0.2 (basic value), and generates the feature vector of the group at 8:03 [0.855 × 0.67, 0.03 × 0.67, 46.2 × 0.67², 1.2 × 0.67², 0.67, 3] (the temperature value 46.2 and the range 1.2 are from real-time data). Then analyzes the stage transition from 8:03 to 8:04: the vibration change rate (0.86 - 0.855) / 1 = 0.005 / minute (the average value 0.86 at 8:04 is calculated from real-time data), the temperature correlation 0.92 (obtained by calculating covariance), and updates the statistical value of the "processing → processing" item in the association matrix (the historical probability 0.9 plus the current change rate of 0.005). Finally, combines the feature vectors of the 5 groups with the principal components [0.88, 0.09, 0.03] of the association matrix (obtained by matrix eigenvalue decomposition) to form a multi-dimensional coupling feature set including features such as vibration trend (rising by 0.02 in 5 minutes) and temperature stability (range fluctuation < 0.2) for use by the environment construction module.
[0154] In the embodiment of the present application, this solution realizes the refined characterization of the equipment operation state through dynamic weight adjustment and cross-stage association analysis, not only retains the detailed features of real-time parameters, but also improves the reliability of feature expression through credibility weighting and transfer law mining, providing a decision-making basis with both timeliness and accuracy for subsequent environment construction.
[0155] To solve the problem of efficient allocation of data verification tasks in the blockchain network, in some embodiments, step 202: the process of separately allocating each of the data segments to an independent node in the blockchain network so that each of the independent nodes generates a verification identification code corresponding to the data segment includes:
[0156] Step 601: Allocate multiple data segments to different independent nodes in the blockchain network.
[0157] In step 601, the data segment allocation refers to the process of distributing the cut data units to different verification nodes according to a preset strategy.
[0158] In the embodiment of the present application, the scheduling module of the blockchain network adopts a polling allocation algorithm and evenly distributes data segments to each independent node according to the current load of the node (such as the number of tasks to be verified) and the network topology distance. Each node receives at most 3 data segments each time, and the data segments of the same device need to be allocated to nodes in different physical regions (for example, node A is located in East China and node B is located in North China) to ensure regional disaster tolerance. When allocating, the mapping relationship between the data segments and the nodes is recorded for subsequent traceability of verification results.
[0159] Step 602: Based on each independent node's allocated data segment, verify the consistency of the device unique identifier of the data segment and the continuity of the timestamp interval of the data segment.
[0160] In step 602, the identifier consistency verification is a process of checking whether the device IDs of all data packets in the data segment are exactly the same. The timestamp continuity verification is a judgment process of confirming whether the data packet timestamps are strictly increasing and without interruption.
[0161] In the embodiment of the present application, after receiving the data segment, the node performs double verification: extracts the device identifier of the first data packet (such as machine tool number Z001) and verifies whether all subsequent data packets carry the same identifier; after sorting the data packets by timestamp, calculates the adjacent time differences, confirms that all differences are equal to the sampling interval (such as 1 second), and there are no duplicate or missing time points. If an abnormality is found during the verification process (such as a mutation of the device ID or a break in the timestamp), the processing is immediately terminated and an error code is returned.
[0162] Step 603: When both the consistency and continuity are verified, generate a verification identification code.
[0163] In the embodiment of the present application, when the data segment passes the double verification, the node performs: calculates the combined hash value of all data packets in the data segment (hashes again after concatenating the hash values of each packet in chronological order); digitally signs "combined hash + time interval" with the node's private key; generates a verification identification code containing the signature result, time interval, and node ID. This identification code is encrypted and stored using a domestic algorithm to ensure it cannot be forged.
[0164] The following is a specific example:
[0165] Based on the data verification scenario of the CNC machine tool from 8:00 to 8:05, the system distributes 5 data segments (each segment contains 6 data packets) to 3 nodes: Node A receives the 8:00 and 8:03 segments, Node B receives the 8:01 and 8:04 segments, and Node C receives the 8:02 segment. When Node A processes the 8:00 segment, it first checks that the device numbers of the 6 data packets are all Z001, confirms that the timestamps are continuous from 8:00:00.000 to 8:00:50.000 (with an interval of 10 seconds because the sampling frequency is 0.1Hz). Then it recalculates the hash value for each data packet (e.g., the hash value of the data packet at 8:00:00.000 = hash function(vibration value 0.84 || temperature 45.1 || Z001 || timestamp)). After comparing it with the original digest and finding them consistent, it concatenates the 6 hash values in chronological order into a string H1 - H6, and then hashes again to get the combined hash value JH1 = hash function(H1 + H2 +... + H6). Finally, it signs "JH1 || 8:00:00.000 - 8:00:50.000" with the private key of Node A to generate the verification identification code M1 = {signature result, JH1, time interval, Node A number}. Similarly, when Node B generates M2 for the 8:01 segment, it finds that the vibration value 0.88 of the 4th data packet (8:01:30.000) does not match the original record 0.87, and the hash comparison fails, so it aborts the processing and feedbacks an exception. The system automatically redistributes the 8:01 segment to the standby node D, and generates the corrected M2' after verification. Finally, the 5 identification codes [M1, M2', M3, M4, M5] enter the subsequent consensus process. Among them, the verification information of the 8:01 segment is specially marked as "re-verified and passed by Node D", and its average vibration value 0.865 = (0.86 + 0.85 + 0.87 + 0.86 + 0.88 + 0.87) / 6, and the temperature range 1.1 = 46.0 - 44.9 (the maximum and minimum values come from the temperature data Y of the 6 data packets).
[0166] In the embodiment of the present application, through the intelligent allocation and double-check mechanism, this solution not only realizes the load balancing of the verification tasks, but also ensures the data authenticity through strict identity and timing checks, providing high-quality preliminary verification results for the subsequent consensus verification, and overall improving the processing efficiency and reliability of the blockchain network in the industrial data verification scenario.
[0167] To solve the problem of dynamic adaptation of the security environment of domestic industrial equipment, in some embodiments, step 105: dynamically constructing a trusted execution environment according to the multi-dimensional coupling characteristics and combining the domestic application operation data of domestic industrial equipment includes:
[0168] Step 701: Determine the environmental security level requirements corresponding to the current device operation stage based on the multi-dimensional coupling characteristics.
[0169] In step 701, the current device operation stage refers to the specific working state (such as startup, operation, shutdown, etc.) of domestic industrial equipment during real-time operation, which is the same concept as the same device operation stage, both referring to the time period division of the device under the same working state. The definition criteria of the operation stage in the two expressions are exactly the same. The former emphasizes real-time, and the latter focuses on the stage matching during data grouping. The environmental safety level requirement is the safety protection intensity level divided according to the device operation state, including three levels: basic protection, enhanced protection, and strict protection.
[0170] In the embodiment of the present application, the system analyzes indicators such as vibration trend and temperature stability in the multi-dimensional coupling characteristics, and combines the preset level mapping rules (such as triggering strict protection when the vibration change rate > 0.05 / minute and the temperature range > 2.0) to determine the current required safety level. Among them, the vibration change rate = (current vibration average - historical average) / time interval, and the temperature range is directly taken from the temperature index in the coupling characteristics.
[0171] Step 702: Establish a trusted execution environment configuration template that matches the environmental safety level requirement according to the device function module call relationship recorded in the domestic application operation data.
[0172] In step 702, the trusted execution environment configuration template is a pre-defined combination of security policies, including elements such as memory isolation schemes, data encryption methods, and access control lists.
[0173] In the embodiment of the present application, according to the program module call graph (such as the frequency of the main control module calling sensor reading and writing) recorded in the domestic application operation data, a matching template is selected from the policy library. For example, when the sensor is called frequently, the "memory partition isolation + lightweight encryption" template is used, and when it is called infrequently, the "full memory encryption + strict access control" template is used.
[0174] Step 703: Adapt the trusted execution environment configuration template to the real-time operation parameters to generate an environment construction instruction set.
[0175] In step 703, the environment construction instruction set is intermediate code that converts template parameters into executable commands, including hardware operation instructions and resource allocation schemes.
[0176] In the embodiment of the present application, the system adjusts the template parameters according to the real-time operation parameters (such as CPU load (CPU Load, CPU), memory margin): when the CPU load > 70%, the encryption intensity is reduced; the size of the memory isolation area is dynamically divided according to the current number of tasks. Finally, an instruction sequence containing specific register configuration values, memory address ranges, etc. is generated.
[0177] Step 704: Execute the environment construction instruction set at the hardware layer of domestic industrial equipment to construct a trusted execution environment.
[0178] In step 704, the hardware layer execution refers to the process of directly loading the instruction set through a domestic security chip and reconstructing the computing environment at the physical level.
[0179] In the embodiment of this application, after the domestic security coprocessor carried by the device receives the instruction set: it resets the isolation area configuration of the memory management unit; loads the specified encryption algorithm engine; sets the hardware-level access control register. All operations are completed through the internal security bus of the chip to ensure that the execution process is not interfered by the main system.
[0180] The following is a specific example:
[0181] Based on the multi-dimensional coupling characteristics of the CNC machine tool at 8:06 (including the vibration average value of 0.86, temperature range difference of 1.1, and credibility of 0.92 in the first 5 minutes), the system first determines that it is currently in the "precision machining" stage. According to the vibration volatility of 0.01 = (0.86 - 0.85) / 1 (the difference between the current average value of 0.86 and the average value of 0.85 in the previous minute) and the temperature stability index (the range difference of 1.1 is less than the threshold of 1.5), it is determined that "three-level security protection" needs to be adopted. Querying the domestic application operation data finds that the G-code processing program is currently being executed (the sensor module is called once every 10 milliseconds). Based on this, the preset "high-frequency sampling protection template" is selected (including: the memory is divided into three isolation areas - the core algorithm area of 1.5GB, the real-time data area of 0.8GB, and the communication buffer area of 0.2GB, using the national cipher SM4 encryption algorithm). Combining with the real-time monitored CPU load rate of 70% = (the current number of used cores of 4 / the total number of cores of 6) × 100%, the template parameters are adjusted to: the core algorithm area is reduced to 1.2GB, and the encryption rounds are reduced from 12 rounds to 8 rounds. The generated instruction set includes: [Configure 0x0000 - 0x4B000000 as the algorithm area, load the 8-round SM4 key, set the white list of the sensor data channel...]. After being executed by the security chip built into the machine tool, the environment construction is completed at 8:06:30. At this time, the processing program runs in the protected algorithm area, the vibration data acquisition channel is isolated in the data area, and data is exchanged between the two areas through the encrypted buffer area. Moreover, each sensor call needs to pass the security verification to ensure that the processing process not only meets the precision control requirements but also has the anti-tampering ability.
[0182] In the embodiment of this application, this solution realizes the precise matching of the operation environment of domestic industrial equipment and the real-time working conditions through dynamic security level assessment and hardware-level environment reconstruction. It not only ensures the safe isolation of key operations but also maintains the system performance through elastic resource allocation, effectively solving the problem of insufficient adaptability of traditional static protection solutions in complex industrial scenarios.
[0183] Figure 2 The following is a schematic structural diagram of a trusted execution environment dynamic construction system for domesticated application operation provided by an embodiment of the present application. As Figure 2 shown, the system includes:
[0184] An acquisition module 21, configured to acquire mechanical operation data in real time during the continuous operation cycle of domesticated industrial equipment.
[0185] A generation module 22, configured to irreversibly bind the mechanical operation data, the unique identifier of the domesticated industrial equipment, and the acquisition timestamp to generate a data set.
[0186] An input module 23, configured to input the data set into a preset blockchain network, the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information.
[0187] A coupling module 24, configured to perform multi-dimensional coupling on the verification information and the real-time operation parameter stream of the domesticated industrial equipment to obtain multi-dimensional coupling characteristics.
[0188] A construction module 25, configured to dynamically construct a trusted execution environment according to the multi-dimensional coupling characteristics and in combination with the domesticated application operation data of the domestic industrial equipment.
[0189] Figure 2 The above-mentioned trusted execution environment dynamic construction system for domesticated application operation can execute Figure 1 the trusted execution environment dynamic construction method described in the embodiment shown. The implementation principle and technical effects will not be elaborated again. For the above-mentioned trusted execution environment dynamic construction system for domesticated application operation, the specific manners of operations performed by each module and unit have been described in detail in the embodiment related to the method, and will not be elaborated here.
[0190] In a possible design, Figure 2 the trusted execution environment dynamic construction system described in the embodiment shown can be implemented as a computing device. As Figure 3 shown, the computing device may include a storage component 31 and a processing component 32;
[0191] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32.
[0192] The processing component 32 is used for the Figure 1 trusted execution environment dynamic construction method described in the above
[0193] Among them, the processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components, and is used to execute the above method.
[0194] The storage component 31 is configured to store various types of data to support the operation of the terminal. The storage component can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disks or optical discs.
[0195] Of course, the computing device may also necessarily include other components, such as input / output interfaces, display components, communication components, etc.
[0196] The input / output interface provides an interface between the processing component and the peripheral interface module, and the above peripheral interface module may be an output device, an input device, etc.
[0197] The communication component is configured to facilitate communication between the computing device and other devices in a wired or wireless manner, etc.
[0198] Among them, the computing device may be a physical device or an elastic computing host provided by a cloud computing platform, etc. At this time, the computing device may refer to a cloud server, and the above processing component, storage component, etc. may be basic server resources leased or purchased from a cloud computing platform.
[0199] An embodiment of the present application also provides a computer storage medium storing a computer program, which can implement the above-mentioned Figure 1 A method for dynamically constructing a trusted execution environment for domestic application operation shown in the embodiment.
[0200] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.
[0201] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0202] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0203] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments or perform equivalent replacements for some of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for dynamically constructing a trusted execution environment for domestic applications to run, characterized in that, Including: During the continuous operation cycle of domestic industrial equipment, mechanically operating data is collected in real time; The mechanically operating data, the unique identifier of the domestic industrial equipment, and the collection timestamp are irreversibly bound to generate a data set; The data set is input into a preset blockchain network, and the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes, and outputs verification information; The verification information is multi-dimensionally coupled with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics; According to the multi-dimensional coupling characteristics, combined with the domestic application operation data of the domestic industrial equipment, a trusted execution environment is dynamically constructed; The multi-dimensionally coupling the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling characteristics includes: In the real-time operation parameter stream of the domestic industrial equipment, a continuous period parameter set matching the timestamp traceability chain of the verification information is extracted; The continuous period parameter set and the verification information are divided into multiple parameter association groups according to the equipment operation stage, and each parameter association group contains real-time operation parameters synchronized in time within the same equipment operation stage and the recombined verified identification code; Perform multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling characteristics; The performing multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling characteristics includes: Extract the dynamic change characteristics of the real-time operation parameters, and calculate the credibility weight according to the confirmation status of the verified identification code; Superimpose the dynamic change characteristics and the credibility weight according to a preset weight relationship to generate a feature vector; According to the enhanced feature vectors of adjacent parameter association groups, calculate the inter-stage transition probability and the parameter change gradient, and construct an inter-stage continuity association matrix; Combine the feature vectors of all parameter association groups and the inter-stage continuity association matrix to generate multi-dimensional coupling characteristics.
2. The method according to claim 1, characterized in that, The inputting the data set into a preset blockchain network, and the blockchain network performing segmentation processing on the data set to obtain a segmentation result, and performing cross-verification on the segmentation result among multiple independent nodes, and outputting verification information includes: Input the data set into a preset blockchain network, and through the segmentation module of the blockchain network, segment the mechanically operating data in the data set into multiple data segments according to the continuous timestamp order; Through the allocation module of the blockchain network, each data segment is respectively allocated to an independent node in the blockchain network, so that each independent node generates a verification identification code corresponding to the data segment; Combine the verification identification codes corresponding to all the data segments in the time order of the data segments to generate a global verification identification code sequence corresponding to the data set; In the blockchain network, according to the global verification identification code sequence, initiate a consistency confirmation request to the independent node that allocated the corresponding data segment, and when more than a preset number threshold of independent nodes confirm the verification identification code of the same data segment to be consistent, generate verification information.
3. The method according to claim 2, wherein In the blockchain network, according to the global verification identification code sequence, a consistency confirmation request is initiated to independent nodes assigned corresponding data segments. When the verification identification codes of the same data segment are confirmed to be consistent by more than a preset quantity threshold of independent nodes, verification information is generated, including: In the blockchain network, a verification task queue corresponding to the global verification identification code sequence is established, where each verification task corresponds to a data segment and includes the identification information of the corresponding data segment and a list of independent nodes; For each verification task in the verification task queue, a confirmation request is sent to all independent nodes in the list of independent nodes corresponding to the verification task, and the confirmation request includes the verification identification code of the data segment to be confirmed; Receiving the confirmation response information returned by each independent node in the list of independent nodes for the same data segment to be confirmed, where the confirmation response information includes an approval or rejection mark for the verification identification code of the data segment to be confirmed; According to the confirmation response information, counting the number of independent nodes that approve the verification identification code of the data segment to be confirmed; When the quantity exceeds the preset quantity threshold, marking the verification identification code of the data segment to be confirmed as the confirmed state; Recombining the verification identification codes of all data segments in the confirmed state in the original order in the global verification identification code sequence; Based on the recombined verification identification code sequence, generating verification information.
4. The method according to claim 2, wherein The step of respectively allocating each data segment to an independent node in the blockchain network so that each independent node generates a verification identification code corresponding to the data segment includes: Allocating multiple data segments to different independent nodes in the blockchain network; Based on each independent node's verification of the allocated data segment, verifying the consistency of the device unique identifier of the data segment and the continuity of the time stamp interval of the data segment; When both the consistency and continuity are verified to pass, generating a verification identification code.
5. The method according to claim 1, wherein The step of dynamically constructing a trusted execution environment according to the multi-dimensional coupling characteristics and combining the domestic application operation data of domestic industrial equipment includes: Based on the multi-dimensional coupling characteristics, determining the environmental security level requirements corresponding to the current device operation stage; According to the device function module call relationship recorded in the domestic application operation data, establishing a trusted execution environment configuration template matching the environmental security level requirements; Adapting the trusted execution environment configuration template to real-time operation parameters to generate an environment construction instruction set; Executing the environment construction instruction set at the hardware layer of the domestic industrial equipment to construct a trusted execution environment.
6. A dynamic construction system for a trusted execution environment for domestic application operation, characterized in that, Including: An acquisition module for real-time acquiring mechanical operation data during the continuous operation cycle of the domestic industrial equipment; A generation module for irreversibly binding the mechanical operation data, the unique identifier of the domestic industrial equipment, and the acquisition time stamp to generate a data set; An input module for inputting the data set into a preset blockchain network, where the blockchain network performs segmentation processing on the data set to obtain a segmentation result, and performs cross-verification on the segmentation result among multiple independent nodes and outputs verification information; A coupling module for multi-dimensionally coupling the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features; A construction module for dynamically constructing a trusted execution environment according to the multi-dimensional coupling features in combination with the domestic application operation data of the domestic industrial equipment; The multi-dimensionally coupling the verification information with the real-time operation parameter stream of the domestic industrial equipment to obtain multi-dimensional coupling features includes: Extracting a set of continuous period parameters matching the timestamp traceability chain of the verification information from the real-time operation parameter stream of the domestic industrial equipment; Dividing the set of continuous period parameters and the verification information into multiple parameter association groups according to the equipment operation stage, and each parameter association group contains real-time operation parameters synchronized in time within the same equipment operation stage and the recombined verified identification codes; Performing multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features; The performing multi-dimensional coupling processing on each parameter association group to generate multi-dimensional coupling features includes: Extracting the dynamic change features of the real-time operation parameters and calculating the credibility weights according to the confirmation status of the verified identification codes; Superimposing the dynamic change features and the credibility weights according to a preset weight relationship to generate a feature vector; Calculating the inter-stage transition probability and the parameter change gradient according to the enhanced feature vectors of adjacent parameter association groups, and constructing an inter-stage continuity association matrix; Combining the feature vectors of all parameter association groups and the inter-stage continuity association matrix to generate multi-dimensional coupling features.
7. A computing device, characterized in that, It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a method for dynamically constructing a trusted execution environment for domestic application operation as described in any one of claims 1 to 5.
8. A computer storage medium, characterized in that, A computer program is stored, and when the computer program is executed by a computer, it implements a method for dynamically constructing a trusted execution environment for domestic application operation as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Method and system for realizing trusted timestamp service based on block chain
CN110535663A
Electric energy consumption monitoring method and system based on block chain
CN113179309A