A data security management method and system based on intelligent robots
By generating actual fingerprints based on hardware unique identification and task type, the security risks of data interaction between intelligent robots and central controllers are solved, and the security and stability of data interaction are improved.
Patent Information
- Application Number
- CN202510660450.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2045-05-22
AI Technical Summary
In the prior art, there are security risks in the data interaction between intelligent robots and central controllers, especially security risks caused by the leakage of robot software and hardware information.
By obtaining the hardware unique identification of the intelligent robot and the task type and behavior data set of the previous authentication cycle, the key behavior data associated with the task type is filtered out, the actual fingerprint of the current authentication cycle is generated, and the interactive data is sent to match the pre-stored fingerprint.
Improve the security of data interaction, prevent the leakage of hardware unique identification of the same batch of robots from affecting other robots, and periodic authentication ensures data security during long-term operation.
Smart Images

Figure CN120185943B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and particularly relates to a data security management method and system based on intelligent robots. Background Art
[0002] The stable operation of people's livelihood infrastructure such as power plants, shipping terminals, and large warehouses is the key to economic development. However, the risk levels of some positions in these people's livelihood infrastructure are relatively high, and intelligent robots are usually used to replace manual labor to complete the work of these positions.
[0003] In current robot solutions, a framework of a central controller and multiple intelligent robots is often adopted. Specifically, each intelligent robot obtains data such as tasks, environmental parameters, and working parameters issued by the central controller through data interaction with the central controller, and then collaborates through these data.
[0004] However, in actual applications, there is a risk of data leakage in the data interaction between intelligent robots and the central controller. There are mainly two current solutions. For example, one solution is to encrypt the data interaction between intelligent robots and the central controller. If the key of this solution is leaked, there is still a risk.
[0005] Another solution is to set device fingerprints for intelligent robots. For example, in patent CN202011003574.6, a substation intelligent robot inspection system and its access operation method are provided. This patent discloses that robot software and hardware information is collected to form a device fingerprint, and the SM3 hashing algorithm is used to perform a Hash operation on the device fingerprint to obtain the digest value of the robot device fingerprint. However, in actual applications, the robot software and hardware information is relatively fixed (usually does not change within a certain period of time), and robot manufacturers usually produce a batch of robots in batches. At this time, if the software and hardware information of one robot is leaked, it may lead to the leakage of the software and hardware information of a batch of robots. Therefore, this solution of forming device fingerprints using the software and hardware information of robots still has security risks. Summary of the Invention
[0006] The purpose of the embodiments of this application is to propose a data security management method and system based on intelligent robots to solve the problem of potential security risks in the data interaction between the central controller and intelligent robots in the prior art.
[0007] To solve the above technical problems, the embodiments of this application provide a data security management method based on intelligent robots, including:
[0008] Obtain the data interaction requests of the intelligent robot in the current authentication cycle, where the data interaction requests carry the unique hardware identifier of the intelligent robot, as well as the task type and the set of behavior data of the intelligent robot in the previous authentication cycle, and the set of behavior data includes behavior data of multiple data types of the intelligent robot;
[0009] According to the task type, filter out the key behavior data associated with the task type from the behavior data of various data types in the set of behavior data;
[0010] Generate the actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the unique hardware identifier of the intelligent robot;
[0011] Obtain the corresponding pre-stored fingerprint through the unique hardware identifier of the intelligent robot and the task type of the intelligent robot in the previous authentication cycle;
[0012] When the actual fingerprint matches the pre-stored fingerprint, send interaction data to the intelligent robot.
[0013] Preferably, filtering out the key behavior data associated with the task type from the behavior data of various data types in the set of behavior data according to the task type specifically includes:
[0014] Obtain a pre-generated mapping relation table, where the mapping relation table is used to store various task types and the data types of the key behavior data respectively associated therewith;
[0015] According to the task type and the mapping relation table, filter out the key behavior data whose data type is associated with the task type from the behavior data of various data types in the set of behavior data.
[0016] Preferably, the task types stored in the mapping relation table include picking tasks, handling tasks, and assembly and maintenance tasks;
[0017] Among them, the data types of the key behavior data associated with the picking task include driving path data, the movement trajectory data of the robotic arm, the grasping force and success rate of the robotic arm, and joint attitude data;
[0018] The data types of the key behavior data associated with the handling task include driving path data, joint attitude data, and vibration data during the movement process;
[0019] The data types of the key behavior data associated with the assembly and maintenance task include the movement trajectory data of the robotic arm, the error data of the grasping and placing positions, and joint attitude data.
[0020] Preferably, the method further includes:
[0021] Previously, execute test tasks of multiple different task types through the intelligent robot to collect key behavior data samples of the intelligent robot when executing test tasks of multiple different task types;
[0022] Utilize the unique hardware identifier of the intelligent robot and the key behavior data samples of the intelligent robot when executing test tasks of multiple different task types to respectively generate the pre-stored fingerprints corresponding to the unique hardware identifier and various task types.
[0023] Preferably, the method further includes:
[0024] Obtain the historical task types of the first N authentication cycles of the intelligent robot and the associated historical key behavior data; where N is a positive integer greater than or equal to 3;
[0025] Respectively correct and update the pre-stored fingerprints of the corresponding historical task types through the obtained historical key behavior data.
[0026] Preferably, respectively correct and update the pre-stored fingerprints of the corresponding historical task types through the obtained historical key behavior data, specifically including:
[0027] Group the historical key behavior data of the first N authentication cycles according to the historical task types of the first N authentication cycles, where the historical task types corresponding to the historical key behavior data between groups are different, and the historical task types corresponding to the historical key behavior data in the same group are the same;
[0028] For each group respectively, use the average value of the historical key behavior data in the group to correct and update the pre-stored fingerprints of the corresponding historical task types.
[0029] Preferably, generate the actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the unique hardware identifier of the intelligent robot, specifically including:
[0030] Calculate the hash value of the unique hardware identifier through the hash algorithm, and extract the features of the key behavior data through feature engineering;
[0031] Combine the hash value and the features to generate a multi-dimensional vector as the actual fingerprint of the intelligent robot in the current authentication cycle.
[0032] Preferably, the method further includes:
[0033] In the case where the actual fingerprint does not match the pre-stored fingerprint, send a prompt message of authentication failure to the intelligent robot.
[0034] Preferably, the method further includes:
[0035] Calculating the similarity between the actual fingerprint and the pre-stored fingerprint;
[0036] Determining whether the similarity is less than a preset threshold, wherein if the similarity is less than the preset threshold, the actual fingerprint matches the pre-stored fingerprint, or if the similarity is greater than or equal to the preset threshold, the actual fingerprint does not match the pre-stored fingerprint.
[0037] To solve the above technical problems, an embodiment of the present application further provides a data security management system based on an intelligent robot, including:
[0038] A data interaction request acquisition unit, configured to acquire a data interaction request of the intelligent robot in the current authentication cycle, wherein the data interaction request carries the unique hardware identifier of the intelligent robot, and the task type and the behavior data set of the intelligent robot in the previous authentication cycle, and the behavior data set includes behavior data of various data types of the intelligent robot;
[0039] A screening unit, configured to screen out key behavior data associated with the task type from the behavior data of various data types in the behavior data set according to the task type;
[0040] A generating unit, configured to generate an actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the unique hardware identifier of the intelligent robot;
[0041] A pre-stored fingerprint acquisition unit, configured to acquire a corresponding pre-stored fingerprint through the unique hardware identifier of the intelligent robot and the task type of the intelligent robot in the previous authentication cycle;
[0042] A data sending unit, configured to send interaction data to the intelligent robot when the actual fingerprint matches the pre-stored fingerprint.
[0043] The present application provides a data security management method based on an intelligent robot, including obtaining a data interaction request of the intelligent robot in the current authentication cycle, where the data interaction request carries the unique hardware identifier of the intelligent robot, as well as the task type and the set of behavior data in the previous authentication cycle, and the set of behavior data includes behavior data of various data types of the intelligent robot; then, according to the task type, key behavior data associated with the task type is screened out from the behavior data of various data types in the set of behavior data; then, through the key behavior data and the unique hardware identifier of the intelligent robot, an actual fingerprint of the intelligent robot in the current authentication cycle is generated; then, through the unique hardware identifier of the intelligent robot and the task type of the intelligent robot in the previous authentication cycle, a corresponding pre-stored fingerprint is obtained; then, when the actual fingerprint matches the pre-stored fingerprint, interaction data is sent to the intelligent robot. In this method, on the one hand, since the actual fingerprint of the intelligent robot in the current authentication cycle is generated by the key behavior data and the unique hardware identifier of the intelligent robot, even if the unique hardware identifier of this intelligent robot or other intelligent robots of the same batch is leaked, it is difficult to generate this actual fingerprint, so the security of data interaction can be improved. On the other hand, since the actual fingerprint is periodically generated and authenticated through the task type in the previous authentication cycle and the key behavior data in the set of behavior data, even if the data of a certain authentication cycle of this intelligent robot is leaked, it will not affect the generation and authentication of the actual fingerprint in other authentication cycles, thus further ensuring the data security during the long-term operation. Therefore, it can solve the problem of potential security hazards in the data interaction between the central controller and the intelligent robot in the prior art and improve the security of data interaction. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the solutions in the present application, the following will briefly introduce the drawings required for the description of the embodiments of the present application. Obviously, the drawings below are some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0045] Figure 1 It is an architecture diagram of an exemplary intelligent system to which the present application can be applied;
[0046] Figure 2 It is a flowchart of the implementation of the data security management method based on an intelligent robot provided by the embodiment of the present application;
[0047] Figure 3 It is a schematic structural diagram of the data security management system based on an intelligent robot provided by the embodiment of the present application;
[0048] Figure 4Schematic structural diagram of an embodiment of a computer device according to the present application. Detailed implementation manners
[0049] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs; the terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the specification and claims of this application and the above drawings are intended to cover non-exclusive inclusion. The terms "first", "second", etc. in the specification and claims of this application or the above drawings are used to distinguish different objects and not to describe a specific order.
[0050] Reference to "embodiment" herein means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of this application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0051] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the drawings.
[0052] As mentioned above, in the currently adopted framework of a central controller and multiple intelligent robots, interaction data is sent between the central controller and the intelligent robots through data interaction, but there is a risk of data leakage in data interaction. One existing solution is to encrypt the data interaction between the intelligent robots and the central controller, but if the key of this solution is leaked, there is still a risk; another solution is to set device fingerprints for the intelligent robots. Currently, the software and hardware information of the robots is mainly used to form device fingerprints. However, since robot manufacturers usually produce robots in batches, and the software and hardware information between robots in the same batch often has certain rules, if the software and hardware information of one robot is leaked, it may lead to the leakage of the software and hardware information of a batch of robots. Therefore, this solution of forming device fingerprints using the software and hardware information of robots still has security risks for batches of robots.
[0053] In view of this, the embodiments of this application provide a data security management method and system based on intelligent robots, which can be used to solve the problems in the prior art. For the sake of easy understanding, the intelligent system of the central controller and multiple intelligent robots can be described first, as Figure 1The following is a schematic structural diagram of the intelligent system. The intelligent system includes a central controller 10 and multiple intelligent robots 20. These intelligent robots 20 are respectively connected to the central controller 10, so as to be able to perform data interaction with the central controller 10. At this time, the central controller 10 can send interaction data to each intelligent robot 20.
[0054] When applying this intelligent system to the process of people's livelihood infrastructure, it is necessary to send interaction data such as tasks, environmental parameters, and working parameters from the central controller 10 to each intelligent robot 20, so that these intelligent robots 20 can respectively execute their own tasks according to these interaction data, thereby realizing collaborative work. For example, in a large warehouse, tasks such as picking and transporting goods can be completed through this intelligent system.
[0055] The embodiment of the present application provides a data security management method based on intelligent robots. Among them, this method can be executed by Figure 1 the central controller 10 in the intelligent system shown in the figure. As Figure 2 The following is a schematic diagram of the specific process of this method. This method includes the following steps:
[0056] Step S31: Obtain the data interaction request of the intelligent robot in the current authentication cycle.
[0057] Among them, the intelligent robot can specifically be Figure 1 any one of the intelligent robots in the intelligent system shown in the figure. In practical applications, during the long-term data interaction process between the central controller and the intelligent robots, in order to ensure long-term data security, the central controller usually authenticates each intelligent robot periodically. Among them, the authentication period (that is, the authentication cycle) can be 1 week, 1 day, 3 hours or other time cycles, so as to improve data security by authenticating each intelligent robot periodically.
[0058] This application is for a process in which a certain intelligent robot (which can be any intelligent robot) in the intelligent system sends a data interaction request to the central controller in the current authentication cycle. At this time, the central controller obtains this data interaction request and then performs authentication. Among them, this data interaction request can be the first data interaction request sent by the intelligent robot to the central controller in the current authentication cycle.
[0059] For example, the authentication cycle can be set to 3 hours. At this time, every new authentication cycle after 3 hours is used as the current authentication cycle. For the first data interaction request sent by the intelligent robot to the central controller, after the central controller receives the first data interaction request sent by the intelligent robot in this current authentication cycle, corresponding authentication needs to be performed.
[0060] When the authentication of the first data interaction request passes, subsequent data interaction requests in the current authentication cycle may no longer require authentication. Conversely, when the authentication of the first data interaction request fails, subsequent data interaction requests may continue to be authenticated until the authentication passes.
[0061] In addition, to facilitate the implementation of authentication in this application, the data interaction request carries the unique hardware identifier of the intelligent robot, as well as the task type and the set of behavior data of the intelligent robot in the previous authentication cycle. Among them, the set of behavior data includes behavior data of various data types of the intelligent robot. The previous authentication cycle is specifically the previous authentication cycle of the current authentication cycle.
[0062] Specifically, the unique hardware identifier of the intelligent robot can be the device number, production serial number, etc. of the intelligent robot, and the unique hardware identifier can uniquely identify the corresponding intelligent robot. However, in this application, the unique hardware identifier is not directly used as the fingerprint of the intelligent robot because current hacking techniques can hijack the intelligent robot through hijacking techniques, thereby stealing the unique hardware identifier of the intelligent robot, or cracking the unique hardware identifier of the intelligent robot by using the unique hardware identifiers of other intelligent robots in the same batch.
[0063] Regarding the task type and the set of behavior data of the intelligent robot in the previous authentication cycle, among them, the task type can be, for example, picking, transporting, and assembly and maintenance, etc. These different types of tasks can be assigned by the central controller to the intelligent robot. The behavior data in the set of behavior data is the data of various data types of the intelligent robot during the task execution process in the previous authentication cycle, including driving path data, motion trajectory data of the robotic arm, grasping force and success rate of the robotic arm, grasping and placement position error data, joint attitude data, vibration data during the motion process, etc. These behavior data can reflect the relevant characteristics of the intelligent robot during the task execution process in the previous authentication cycle, and these characteristics characterize the relevant performance of the intelligent robot during the motion process. Obviously, these performances have certain rules (that is, there will be certain differences between different intelligent robots) and continuity. The same intelligent robot cannot change significantly in several authentication cycles. Therefore, it provides a basis for generating fingerprints and serving as an authentication basis in the future.
[0064] Of course, for the behavior data of these data types, it can usually be collected through the sensors of the intelligent robot itself. For example, during the task execution process of the intelligent robot in the previous authentication cycle, it can collect the behavior data of these data types through its own sensors, and then generate the set of behavior data of the intelligent robot in the previous authentication cycle.
[0065] This application generates the fingerprint of the intelligent robot in the current authentication cycle (referred to as the actual fingerprint) based on the unique hardware identifier of the intelligent robot, as well as the task type and the set of behavior data in the previous authentication cycle. In this way, the generation of the actual fingerprint combines the task type in the previous authentication cycle and the behavior data in the set of behavior data, which is different from the static data of the unique hardware identifier of the intelligent robot. The task type and behavior data belong to dynamic data and may vary to a certain extent in each authentication cycle, making it more difficult to be hijacked and cracked.
[0066] Step S32: According to the task type, screen out the key behavior data associated with the task type from the behavior data of various data types in the set of behavior data.
[0067] Since the behavior data of various data types in the set of behavior data is collected through the sensors of the intelligent robot itself, and the hardware structures of these intelligent robots have little deviation, especially when the intelligent robots are produced in the same batch, during the task execution in the previous authentication cycle, these sensors will collect relevant behavior data, thus collecting behavior data of basically the same data type. However, due to different task types among different intelligent robots, some behaviors can better represent the task types they execute. Therefore, for a specific task type, it is necessary to screen out the key behavior data associated with the task type from the set of behavior data. This key behavior data can better reflect the characteristics of the intelligent robot during task execution compared to other behavior data in the data set.
[0068] For example, for an intelligent robot performing a picking task, its driving path data, the movement trajectory data of the robotic arm, the grasping force and success rate of the robotic arm, joint posture data, etc. can better reflect the characteristics of the intelligent robot when performing the picking task. Therefore, the behavior data of these data types, namely the driving path data, the movement trajectory data of the robotic arm, the grasping force and success rate of the robotic arm, and joint posture data, can be used as the key behavior data associated with this task type (i.e., the picking task).
[0069] For an intelligent robot performing a handling task (the task type of this intelligent robot is the handling task), its driving path data, joint posture data, vibration data during movement, etc. can better reflect the characteristics of the intelligent robot when performing the handling task. Therefore, the behavior data of these data types, namely the driving path data, joint posture data, and vibration data during movement, are used as the key behavior data associated with this task type (i.e., the picking task).
[0070] Similarly, for an intelligent robot performing assembly and maintenance tasks (the task type of this intelligent robot is assembly and maintenance tasks), the key behavior data associated with this task type are motion trajectory data, grasping and placement position error data, and joint attitude data.
[0071] Therefore, in this step S31, according to the task type, the key behavior data associated with this task type can be filtered out from the behavior data of various data types in the behavior data set. Specifically, for example, a pre-generated mapping table can be obtained, where this mapping table is used to store various task types and the data types of the key behavior data respectively associated with them. For example, according to the above content, a mapping table as shown in Table 1 below can be pre-generated.
[0072] Table 1: Mapping Table
[0073]
[0074] After pre-generating this mapping table, the behavior data whose data type is associated with this task type can be further filtered out from the behavior data of various data types in the behavior data set according to the task type of this intelligent robot in the previous authentication cycle and this mapping table, and used as this key behavior data.
[0075] Step S33: Generate the actual fingerprint of this intelligent robot in the current authentication cycle through this key behavior data and the hardware unique identifier of this intelligent robot.
[0076] For the specific implementation method of this step S33, for example, the hash value of this hardware unique identifier can be calculated first through a hash algorithm (referred to as hardware hash), and the features of this key behavior data can be extracted through feature engineering. These features include coding features (such as encoding the driving path data), statistical features (statistical grasping force and success rate of the robotic arm, variance, average value, etc. of the grasping and placement position error data), time-frequency domain features (time domain and frequency domain features of the vibration data during the motion process), etc.; then the hash value and these features are combined to generate a multi-dimensional vector (for example, the hash value is encoded and used as the value of one dimension of this multi-dimensional vector), and then this multi-dimensional vector can be used as the actual fingerprint of this intelligent robot in the current authentication cycle.
[0077] Step S34: Obtain the corresponding pre-stored fingerprint through the hardware unique identifier of the intelligent robot and the task type of this intelligent robot in the current authentication cycle.
[0078] In this application, considering that the same intelligent robot can execute tasks of multiple different task types, and the key behavior data corresponding to tasks of different task types is different, multiple different actual fingerprints can be generated accordingly. In view of this, for the same intelligent robot, this application sets multiple different pre-stored fingerprints, which are thus applied to different task types. Therefore, for a certain pre-stored fingerprint in this application, the pre-stored fingerprint corresponds to the unique hardware identifier of the intelligent robot and the task type.
[0079] For example, as shown in Table 2 of the correspondence table of pre-stored fingerprints, the corresponding relationship between the pre-stored fingerprints, the unique hardware identifier of the intelligent robot, and the task type is recorded.
[0080] In the correspondence table of pre-stored fingerprints shown in Table 2, for the intelligent robot with the unique hardware identifier XXX, the pre-stored fingerprint for its picking task is pre-stored fingerprint 1, the pre-stored fingerprint for its handling task is pre-stored fingerprint 2, and the pre-stored fingerprint for its assembly and maintenance task is pre-stored fingerprint 3; for the intelligent robot with the unique hardware identifier YYY, the pre-stored fingerprints corresponding to its picking task, handling task, and assembly and maintenance task are pre-stored fingerprint 4, pre-stored fingerprint 5, and pre-stored fingerprint 6 respectively.
[0081] Therefore, in step S34, the corresponding pre-stored fingerprint can be obtained through the unique hardware identifier of the intelligent robot and the task type of the intelligent robot in the current authentication cycle. For example, by querying the correspondence table of pre-stored fingerprints shown in Table 2 above through the unique hardware identifier of the intelligent robot and the task type of the intelligent robot in the current authentication cycle, the corresponding pre-stored fingerprint can be obtained.
[0082] Table 2: Correspondence Table of Pre-stored Fingerprints
[0083]
[0084] It should be emphasized that this application can also pre-generate the pre-stored fingerprint in the following way. Specifically, the intelligent robot can be pre-executed with test tasks of multiple different task types to collect key behavior data samples of the intelligent robot when executing test tasks of multiple different task types. For example, the test task of the picking task can be executed by the intelligent robot first to collect the corresponding key behavior data samples, and the test tasks of the handling task and the assembly and maintenance task can be executed to facilitate the collection of the corresponding key behavior data samples. Then, using the unique hardware identifier of the intelligent robot and the key behavior data samples of the intelligent robot when executing test tasks of multiple different task types, the pre-stored fingerprints corresponding to the unique hardware identifier and various task types are respectively generated. Among them, the specific method of generating the pre-stored fingerprint can be the same as the method of generating the actual fingerprint described above.
[0085] For example, for the test task of the intelligent robot picking task and the corresponding key behavior data samples collected, the hash value of the unique hardware identifier of the intelligent robot can be calculated through the hash algorithm, and the features of the key behavior data can be extracted through feature engineering. Then, the hash value and the features are combined to generate a multi-dimensional vector, and the multi-dimensional vector is used as the pre-stored fingerprint for the picking task of the intelligent robot. Similarly, the pre-stored fingerprints for the handling task and the assembly and maintenance task can also be generated in this way.
[0086] After generating the pre-stored fingerprint in the above manner, one way is to directly use the pre-stored fingerprint to match the actual fingerprint for authentication in the long term. However, considering that during the long-term use of the intelligent robot, its own performance will also change slowly, so the behavior data in each authentication cycle (even if the task types are the same) will also be different. In order to make the authentication result more stable, the embodiments of the present application can also adaptively update the pre-stored fingerprint. Specifically, the historical task types of the intelligent robot in the previous N authentication cycles and the associated historical key behavior data can be obtained, where N is a positive integer greater than or equal to 3. For example, N can be 5, that is, the historical task types of the previous 5 authentication cycles of the current authentication cycle and the associated historical key behavior data can be collected. Then, the pre-stored fingerprint of the corresponding historical task type is corrected and updated respectively through the obtained historical key behavior data, so that the authentication can be performed by matching the corrected and updated pre-stored fingerprint with the actual fingerprint.
[0087] Among them, the pre-stored fingerprint of the corresponding historical task type is corrected and updated respectively through the obtained historical key behavior data. Specifically, it can include grouping the historical key behavior data of the previous N authentication cycles according to the historical task types of the previous N authentication cycles. Among them, the historical task types corresponding to the historical key behavior data between groups are different, and the historical task types corresponding to the historical key behavior data in the same group are the same. Then, for each group, the average value of the historical key behavior data in the group is used to correct and update the pre-stored fingerprint of the corresponding historical task type.
[0088] For example, the historical task types of the previous 5 authentication cycles of the current authentication cycle and the associated historical key behavior data can be collected, which are the historical task type N1 of the previous 1st authentication cycle and the associated historical key behavior data P1, the historical task type N2 of the previous 1st authentication cycle and the associated historical key behavior data P2, and the corresponding (N3, P3), (N4, P4), (N5, P5), so as to obtain the following data (N1, P1), (N2, P2), (N3, P3), (N4, P4), (N5, P5).
[0089] Then, group according to the historical task types of (N1, P1), (N2, P2), (N3, P3), (N4, P4), (N5, P5), that is, N1, N2, N3, N4, N5. For example, if N1 and N2 are both picking tasks, and N3, N4, and N5 are all transportation tasks, at this time, P1 and P2 can be divided into one group (referred to as the first group), and P3, P4, and P5 can be divided into one group (referred to as the second group); then calculate the average value of P1 and P2 in the first group to correct and update the pre-stored fingerprint for the picking task. For example, a new fingerprint can be recalculated through this average value to replace the pre-stored fingerprint; similarly, the average value of P3, P4, and P5 in the second group can be calculated to correct and update the transportation task of the picking task.
[0090] Step S35: When the actual fingerprint matches the pre-stored fingerprint, send interaction data to the intelligent robot.
[0091] For the specific implementation method of this step S35, for example, it can be determined whether the actual fingerprint matches the pre-stored fingerprint. If the two match, it means that the intelligent robot has passed the authentication in the current authentication cycle. In this way, the central controller can send interaction data to the intelligent robot; on the contrary, if the two do not match, it means that the intelligent robot has failed the authentication this time, and the central controller does not send interaction data to the intelligent robot. Of course, at this time, a prompt message of authentication failure can be sent to the intelligent robot.
[0092] It should be noted that there are various ways to determine whether the actual fingerprint matches the pre-stored fingerprint. For example, one way can be to calculate the similarity between the actual fingerprint and the pre-stored fingerprint. This similarity can be, for example, cosine similarity or Hamming distance, etc., and then determine whether the similarity is less than the preset threshold. At this time, when the similarity is less than the preset threshold, it means that the two match; on the contrary, when the similarity is greater than or equal to the preset threshold, it means that the two do not match.
[0093] Adopt the data security management method based on an intelligent robot provided by the embodiment of the present application. The method includes obtaining a data interaction request of the intelligent robot in the current authentication cycle. The data interaction request carries the unique hardware identifier of the intelligent robot, as well as the task type and the set of behavior data in the previous authentication cycle. The set of behavior data includes behavior data of various data types of the intelligent robot. Then, according to the task type, key behavior data associated with the task type is screened out from the behavior data of various data types in the set of behavior data. Then, through the key behavior data and the unique hardware identifier of the intelligent robot, an actual fingerprint of the intelligent robot in the current authentication cycle is generated. Then, through the unique hardware identifier of the intelligent robot and the task type of the intelligent robot in the previous authentication cycle, a corresponding pre-stored fingerprint is obtained. Then, when the actual fingerprint matches the pre-stored fingerprint, interaction data is sent to the intelligent robot.
[0094] In this method, on the one hand, since the actual fingerprint of the intelligent robot in the current authentication cycle is generated through the key behavior data and the unique hardware identifier of the intelligent robot, even if the unique hardware identifier of this intelligent robot or other intelligent robots of the same batch is leaked, it is difficult to generate this actual fingerprint. Therefore, the security of data interaction can be improved. On the other hand, since the actual fingerprint is periodically generated through the task type in the previous authentication cycle and the key behavior data in the set of behavior data for periodic authentication, even if the data of a certain authentication cycle of this intelligent robot is leaked, it will not affect the generation and authentication of the actual fingerprint in other authentication cycles, thus further ensuring the data security during the long-term operation. Therefore, it can solve the problem of potential security hazards in the data interaction between the central controller and the intelligent robot in the prior art and improve the security of data interaction.
[0095] Those of ordinary skill in the art can understand that all or part of the processes in implementing the methods of the above embodiments can be completed by instructing relevant hardware through computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above various methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), etc., or a random access memory (RAM), etc.
[0096] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the sequence indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit and can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.
[0097] Based on the same inventive concept as the data security management method for intelligent robots provided in the embodiments of the present application, the embodiments of the present application also provide a data security management system for intelligent robots. For the content in the embodiments of this system, if there is any unclear point, reference can be made to the corresponding content in the method embodiments. As Figure 3 shown in the specific structural schematic diagram of the system 40, the system 40 includes: a data interaction request acquisition unit 401, a screening unit 402, a generation unit 403, a pre-stored fingerprint acquisition unit 404, and a data sending unit 405, where:
[0098] The data interaction request acquisition unit 401 is configured to acquire the data interaction request of the intelligent robot in the current authentication cycle, where the data interaction request carries the hardware unique identifier of the intelligent robot, as well as the task type and the behavior data set of the intelligent robot in the previous authentication cycle, and the behavior data set includes the behavior data of various data types of the intelligent robot;
[0099] The screening unit 402 is configured to screen out the key behavior data associated with the task type from the behavior data of various data types in the behavior data set according to the task type;
[0100] The generation unit 403 is configured to generate the actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the hardware unique identifier of the intelligent robot;
[0101] [[ID=?]]The pre-stored fingerprint acquisition unit 404 is configured to acquire the corresponding pre-stored fingerprint through the hardware unique identifier of the intelligent robot and the task type of the intelligent robot in the previous authentication cycle;
[0102] The data sending unit 405 is configured to send interaction data to the intelligent robot when the actual fingerprint matches the pre-stored fingerprint.
[0103] Since the system 40 adopts the same inventive concept as the method provided in the embodiments of the present application, it can also solve the problems in the prior art, and details are not described herein again.
[0104] Among them, according to the task type, screening out the key behavior data associated with the task type from the behavior data of various data types in the behavior data set may specifically include:
[0105] Obtaining a pre-generated mapping relation table, where the mapping relation table is used to store various task types and the data types of the key behavior data respectively associated therewith;
[0106] According to the task type and the mapping relation table, screening out the key behavior data whose data type is associated with the task type from the behavior data of various data types in the behavior data set.
[0107] Among them, the task types stored in the mapping relation table include picking tasks, handling tasks, and assembly and maintenance tasks;
[0108] Among them, the data types of the key behavior data associated with the picking task include driving path data, motion trajectory data of the robotic arm, grasping force and success rate of the robotic arm, and joint attitude data;
[0109] The data types of the key behavior data associated with the handling task include driving path data, joint attitude data, and vibration data during the motion process;
[0110] The data types of the key behavior data associated with the assembly and maintenance task include motion trajectory data of the robotic arm, grasping and placing position error data, and joint attitude data.
[0111] Among them, the system 40 may further include a pre-stored fingerprint generation unit, which is used to pre-collect the key behavior data samples of the intelligent robot when performing test tasks of multiple different task types by the intelligent robot; using the hardware unique identifier of the intelligent robot and the key behavior data samples of the intelligent robot when performing test tasks of multiple different task types, respectively generating the pre-stored fingerprints corresponding to the hardware unique identifier and various task types.
[0112] Among them, the system 40 may further include a pre-stored fingerprint update unit, which is used to obtain the historical task types of the intelligent robot in the previous N authentication cycles and the associated historical key behavior data; where N is a positive integer greater than or equal to 3; respectively correcting and updating the pre-stored fingerprints of the corresponding historical task types through the obtained respective historical key behavior data.
[0113] Among them, by using the obtained historical key behavior data respectively to correct and update the pre-stored fingerprints for the corresponding historical task types, it may specifically include: grouping the historical key behavior data for the first N authentication cycles according to the historical task types of the first N authentication cycles, where the historical task types corresponding to the historical key behavior data between groups are different, and the historical task types corresponding to the historical key behavior data in the same group are the same; respectively for each group, using the average value of the historical key behavior data in the group to correct and update the pre-stored fingerprints for the corresponding historical task types.
[0114] Among them, generating the actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the unique hardware identifier of the intelligent robot may specifically include:
[0115] Calculating the hash value of the unique hardware identifier through a hash algorithm, and extracting the features of the key behavior data through feature engineering;
[0116] Combining the hash value and the features to generate a multi-dimensional vector as the actual fingerprint of the intelligent robot in the current authentication cycle.
[0117] Among them, the system 40 may further include an authentication failure prompt unit, configured to send a prompt message of authentication failure to the intelligent robot when the actual fingerprint does not match the pre-stored fingerprint.
[0118] Among them, the system 40 may further include a similarity matching unit, configured to calculate the similarity between the actual fingerprint and the pre-stored fingerprint; determining whether the similarity is less than a preset threshold, where if the similarity is less than the preset threshold, the actual fingerprint matches the pre-stored fingerprint, or if the similarity is greater than or equal to the preset threshold, the actual fingerprint does not match the pre-stored fingerprint.
[0119] To solve the above technical problems, an embodiment of the present application further provides a computer device. Specifically, please refer to Figure 4 , Figure 4 which is the basic structural block diagram of the computer device in the embodiment of the present application.
[0120] The computer device 500 includes a memory 510, a processor 520, and a network interface 530 that are communicatively connected to each other via a system bus. It should be noted that only the computer device 500 with components 510 - 530 is shown in the figure. However, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Among them, those skilled in the art of the present technology can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, a microprocessor, an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), an embedded device, etc. In practical applications, the computer device 500 can be used as Figure 1 the central controller 10 in the intelligent system shown.
[0121] The memory 510 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 510 may be an internal storage unit of the computer device 500, such as the hard disk or memory of the computer device 500. In other embodiments, the memory 510 may also be an external storage device of the computer device 500, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 500. Of course, the memory 510 may also include both the internal storage unit and the external storage device of the computer device 500. In the embodiments of the present application, the memory 510 is generally used to store the operating system and various application software installed on the computer device 500, such as computer-readable instructions of the method. In addition, the memory 510 may also be used to temporarily store various data that have been output or will be output.
[0122] In some embodiments, the processor 520 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips. The processor 520 is generally used to control the overall operation of the computer device 500. In the embodiments of the present application, the processor 520 is used to run the computer-readable instructions stored in the memory 510 or process data, such as running the computer-readable instructions of the method provided in the embodiments of the present application.
[0123] The network interface 530 may include a wireless network interface or a wired network interface, and this network interface 530 is generally used to establish a communication connection between the computer device 500 and other electronic devices.
[0124] The present application also provides another implementation manner, that is, to provide a computer-readable storage medium storing computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to execute the steps of the method as described above.
[0125] Through the description of the above embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions to enable a terminal device (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present application.
[0126] Obviously, the above-described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The drawings show the preferred embodiments of the present application, but do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure content of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing specific embodiments, or perform equivalent replacements for some of the technical features. Any equivalent structure directly or indirectly using the content of the specification and drawings of the present application in other related technical fields shall be similarly within the scope of the patent protection of the present application.
Claims
1. A data security management method based on an intelligent robot, characterized in that, Including: Obtain the data interaction request of the intelligent robot in the current authentication cycle, where the data interaction request carries the unique hardware identifier of the intelligent robot, as well as the task type and the set of behavior data of the intelligent robot in the previous authentication cycle, and the set of behavior data includes behavior data of various data types of the intelligent robot; According to the task type, screen out the key behavior data associated with the task type from the behavior data of various data types in the set of behavior data; Generate the actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the unique hardware identifier of the intelligent robot; Obtain the corresponding pre-stored fingerprint through the unique hardware identifier of the intelligent robot and the task type of the intelligent robot in the previous authentication cycle; When the actual fingerprint matches the pre-stored fingerprint, send interaction data to the intelligent robot; Wherein, the method further includes: Previously, let the intelligent robot execute test tasks of multiple different task types to collect key behavior data samples of the intelligent robot when executing test tasks of multiple different task types; Use the unique hardware identifier of the intelligent robot and the key behavior data samples of the intelligent robot when executing test tasks of multiple different task types to generate the pre-stored fingerprints corresponding to the unique hardware identifier and various task types respectively.
2. The method according to claim 1, wherein According to the task type, screen out the key behavior data associated with the task type from the behavior data of various data types in the set of behavior data, specifically including: Obtain a pre-generated mapping table, where the mapping table is used to store various task types and the data types of the key behavior data respectively associated therewith; According to the task type and the mapping table, screen out the key behavior data whose data type is associated with the task type from the behavior data of various data types in the set of behavior data.
3. The method according to claim 2, wherein The task types stored in the mapping table include picking tasks, handling tasks, and assembly and maintenance tasks; Among them, the data types of the key behavior data associated with the picking task include driving path data, the movement trajectory data of the robotic arm, the grasping force and success rate of the robotic arm, and joint attitude data; The data types of the key behavior data associated with the handling task include driving path data, joint attitude data, and vibration data during the movement process; The data types of the key behavior data associated with the assembly and maintenance task include the movement trajectory data of the robotic arm, the error data of the grasping and placing positions, and joint attitude data.
4. The method according to claim 1, characterized in that, The method further includes: Obtain the historical task types of the intelligent robot in the previous N authentication cycles, and the associated historical key behavior data; where N is a positive integer greater than or equal to 3; Respectively correct and update the pre-stored fingerprints of the corresponding historical task types through the obtained respective historical key behavior data.
5. The method according to claim 4, wherein Respectively correct and update the pre-stored fingerprints of the corresponding historical task types through the obtained respective historical key behavior data, specifically including: Group the historical key behavior data for the first N authentication cycles according to the historical task types of the first N authentication cycles. Among them, the historical task types corresponding to the historical key behavior data between groups are different, and the historical task types corresponding to the historical key behavior data in the same group are the same; For each group, use the average value of the historical key behavior data in the group to correct and update the pre-stored fingerprint for the corresponding historical task type.
6. The method according to claim 1, characterized in that, Generate the actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the hardware unique identifier of the intelligent robot, specifically including: Calculate the hash value of the hardware unique identifier through the hash algorithm, and extract the features of the key behavior data through feature engineering; Combine the hash value and the features to generate a multi-dimensional vector as the actual fingerprint of the intelligent robot in the current authentication cycle.
7. The method according to claim 1, characterized in that, The method further includes: In the case where the actual fingerprint does not match the pre-stored fingerprint, send a prompt message of authentication failure to the intelligent robot.
8. The method according to claim 1, characterized in that, The method further includes: Calculate the similarity between the actual fingerprint and the pre-stored fingerprint; Judge whether the similarity is less than a preset threshold. Among them, if the similarity is less than the preset threshold, the actual fingerprint matches the pre-stored fingerprint, or if the similarity is greater than or equal to the preset threshold, the actual fingerprint does not match the pre-stored fingerprint.
9. A data security management system based on an intelligent robot, characterized in that Includes: A data interaction request acquisition unit, configured to acquire a data interaction request of the intelligent robot in the current authentication cycle, where the data interaction request carries the hardware unique identifier of the intelligent robot, and the task type and behavior data set of the intelligent robot in the previous authentication cycle, and the behavior data set includes behavior data of multiple data types of the intelligent robot; A screening unit, configured to screen out key behavior data associated with the task type from the behavior data of various data types in the behavior data set according to the task type; A generation unit, configured to generate the actual fingerprint of the intelligent robot in the current authentication cycle through the key behavior data and the hardware unique identifier of the intelligent robot; A pre-stored fingerprint acquisition unit, configured to acquire the corresponding pre-stored fingerprint through the hardware unique identifier of the intelligent robot and the task type of the intelligent robot in the previous authentication cycle; A data sending unit, configured to send interaction data to the intelligent robot in the case where the actual fingerprint matches the pre-stored fingerprint; The system further includes a pre-stored fingerprint generation unit, configured to pre-collect key behavior data samples of the intelligent robot when performing test tasks of multiple different task types by the intelligent robot; use the hardware unique identifier of the intelligent robot and the key behavior data samples of the intelligent robot when performing test tasks of multiple different task types to respectively generate the pre-stored fingerprints corresponding to the hardware unique identifier and various task types.
Citation Information
Patent Citations
Intelligent robot inspection system for transformer substation and access operation method thereof
CN112102516A
Equipment fingerprint implementation method based on user behaviors and hardware information
CN110287698A