Multi-level security protection communication method and platform for industrial control
By analyzing blockchain communication paths and quantifying risks in the industrial control system, and dynamically adjusting security protection strategies, the problems of blockchain communication delay and computing resource consumption are solved, efficient and low-latency security protection is achieved, and the real-time and security of industrial control networks are improved.
Patent Information
- Application Number
- CN202510431087.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, the configuration of the security protection protocol by the real-time dynamic negotiation mechanism leads to an increase in blockchain communication delay, affecting the real-timeness of industrial control systems and computing resource consumption.
Receive blockchain communication request information through the switch, use the OSPF protocol to parse the communication path, extract the characteristic items of the transit block, and calculate the risk quantitative indicators through the risk factor quantification model, dynamically adjust the security protection strategy, and configure the corresponding security protection protocol.
It reduces blockchain communication delay, optimizes computing resource allocation, improves real-time and security of industrial control networks, and ensures efficient and reliable communication operation.
Smart Images

Figure CN120263485A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of blockchain protection, and particularly to a multi-level security protection communication method and platform for industrial control. Background Art
[0002] In the field of industrial control communication, security protection is directly related to the stability of the production process and the confidentiality of data. Existing industrial control communication security protection methods mostly adopt a real-time dynamic negotiation mechanism to configure security protection protocols. This mechanism allows both parties of blockchain communication to negotiate and determine security parameters such as encryption algorithms and keys before each blockchain communication to ensure the security of blockchain communication.
[0003] However, the real-time dynamic negotiation mechanism will introduce additional communication delays. In industrial control scenarios, many control instructions require millisecond-level responses. Dynamic negotiation involves multiple steps such as identity authentication, key exchange, and policy matching. These operations will significantly increase data transmission delays, resulting in delays in the execution of control instructions, affecting the real-time performance and control accuracy of industrial control systems, and even causing system failures. Secondly, the dynamic negotiation process consumes a large amount of computing resources. Industrial control systems usually operate in resource-constrained environments. The frequent use of the dynamic negotiation mechanism will increase the computing burden, resulting in a decline in system performance and even affecting the normal operation of the system. Summary of the Invention
[0004] This application provides a multi-level security protection communication method and platform for industrial control, which solves the technical problems of the prior art that the use of a real-time dynamic negotiation mechanism to configure security protection protocols leads to an increase in blockchain communication delays, affects the real-time performance of industrial control systems, and increases the computing burden at the same time, and achieves the technical effects of configuring protection strategies based on risk quantification, reducing blockchain communication delays, enhancing the security of industrial control networks, and optimizing the allocation of computing resources.
[0005] In view of the above problems, on the one hand, this application provides a multi-level security protection communication method for industrial control. The method includes: a switch receives blockchain communication request information for industrial control; parses the blockchain communication path of the blockchain communication request information based on the OSPF protocol and identifies transit blocks; extracts multiple feature items of the transit blocks, and the multiple feature items include transit block types, the number of transit blocks, the security levels of transit blocks, and historical attacked data; performs risk quantification analysis on the multiple feature items through a risk factor quantification model, outputs a first risk quantification index of the transit blocks, and outputs the corresponding privacy security protection level of the blockchain communication request information according to the first risk quantification index. The security policy server of the switch configures the security protection protocol of the blockchain communication request information according to the privacy security protection level.
[0006] On the other hand, the present application also provides a multi-level security protection communication platform for industrial control. The platform includes: a request receiving module for receiving blockchain communication request information for industrial control through a switch; a path parsing module for parsing the blockchain communication path of the blockchain communication request information based on the OSPF protocol and identifying transit blocks; a block feature extraction module for extracting multiple feature items of the transit blocks, where the multiple feature items include transit block types, the number of transit blocks, the security level of the transit blocks, and historical attacked data; a protection configuration module for performing risk quantification analysis on the multiple feature items through a risk factor quantification model, outputting a first risk quantification index of the transit blocks, and outputting the corresponding privacy and security protection level of the blockchain communication request information according to the first risk quantification index, and the security policy server of the switch configures the security protection protocol of the blockchain communication request information according to the privacy and security protection level.
[0007] One or more technical solutions provided in the present application have at least the following beneficial effects:
[0008] The switch receives blockchain communication request information for industrial control and parses the blockchain communication path based on the OSPF protocol to identify the transit blocks therein, so as to clarify the key links that may be attacked during the blockchain communication process. Subsequently, multiple feature items of the transit blocks are extracted, including block types, quantities, security levels, and historical attacked data, and these features are analyzed using a risk factor quantification model to calculate the corresponding risk quantification indexes, providing a scientific basis for subsequent security protection strategy configuration. Based on this index, the security protection strategy of the blockchain communication request is dynamically adjusted to ensure that high-risk paths are subject to more stringent security protection, while low-risk paths adopt lightweight protection strategies to reduce unnecessary security negotiation delays. On this basis, the security policy server of the switch automatically configures the corresponding security protection protocol according to the assigned protection level, avoiding the high consumption of real-time computing resources in the traditional dynamic negotiation process, reducing the blockchain communication delay at the same time, and improving the system response speed and control accuracy, so as to realize an efficient, low-latency, and dynamically adjustable security protection mechanism while ensuring the security of the industrial control network.
[0009] In summary, the present application effectively reduces the blockchain communication delay caused by real-time dynamic negotiation and reduces the consumption of computing resources by pre-evaluating the risks in the blockchain communication path and dynamically adjusting the protection strategy according to the risk quantification results. This solution not only improves the real-time performance and response speed of the industrial control network, but also enhances the overall security of the industrial control system, ensuring the efficient and reliable operation of industrial control blockchain communication.
[0010] The above description is only an overview of the technical solution of the present application. In order to better understand the technical means of the present application, it can be implemented according to the content of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the specific embodiments of the present application are specifically exemplified below. Description of the Drawings
[0011] Figure 1 It is a schematic flowchart of a multi-level security protection communication method for industrial control provided by an embodiment of the present application.
[0012] Figure 2 It is a schematic flowchart of risk quantification analysis of multiple feature items through a risk factor quantification model in a multi-level security protection communication method for industrial control provided by an embodiment of the present application.
[0013] Figure 3 It is a schematic structural diagram of a multi-level security protection communication platform for industrial control provided by an embodiment of the present application.
[0014] Description of the reference numerals: Request receiving module 10, path parsing module 20, block feature extraction module 30, protection configuration module 40. Detailed Embodiments
[0015] By providing a multi-level security protection communication method and platform for industrial control in the embodiments of the present application, the technical problem in the prior art that the real-time dynamic negotiation mechanism is used to configure the security protection protocol, resulting in an increase in blockchain communication delay, affecting the real-time performance of the industrial control system, and increasing the computing burden at the same time, is solved. The technical effect of configuring the protection strategy based on risk quantification, reducing the blockchain communication delay, improving the security of the industrial control network, and optimizing the computing resource allocation is achieved.
[0016] Embodiment 1, as Figure 1 shown, the embodiments of the present application provide a multi-level security protection communication method for industrial control, and the method includes:
[0017] Step S1: The switch receives blockchain communication request information for industrial control.
[0018] Specifically, in the industrial control network, the switch is responsible for transmitting control signals and data between different devices. The switch receives blockchain communication request information from each device in the industrial control environment through the network interface. These blockchain communication request information are communication data requests issued by devices in the industrial control system based on the blockchain network transmission mechanism, usually encapsulated in the form of data packets, and contain key information such as source address, target address, and smart contract call parameters.
[0019] This step serves as the starting point of the entire secure blockchain communication method, ensuring that blockchain communication requests can be captured and processed by network devices.
[0020] Step S2: Parse the blockchain communication path of the blockchain communication request information based on the OSPF protocol and identify the transit blocks.
[0021] Specifically, the OSPF (Open Shortest Path First) protocol, that is, the Open Shortest Path First protocol, is an interior gateway protocol used to exchange routing information within the same autonomous system. This protocol sends link state information to all routers through flooding. Each router constructs a link state database based on the collected information and uses the Dijkstra algorithm to calculate the shortest path tree, thereby determining the optimal blockchain communication path from the source end to the destination end for the blockchain communication request. This blockchain communication path includes all the blocks and links passed through during the blockchain communication process.
[0022] Using the OSPF protocol, parse the blockchain communication request information received in step S1. The OSPF protocol determines the transmission path of the blockchain communication request in the network by analyzing information such as the source address and destination address in the blockchain communication request and combining the network topology information it has. In this process, the switch queries its internally stored network topology table (which is continuously updated and maintained by the OSPF protocol) to find the transit blocks on the blockchain communication path and identify these transit blocks. These transit blocks are the blocks other than the source block and the target block in the blockchain communication path, responsible for forwarding data and helping the data reach the target block from the source block, such as relay nodes, intermediate gateways, smart contract processors, etc.
[0023] The OSPF protocol can efficiently determine the blockchain communication path, ensuring that data can be transmitted along the optimal path and improving the blockchain communication efficiency.
[0024] Step S3: Extract multiple feature items of the transit blocks, and the multiple feature items include transit block types, the number of transit blocks, the security level of the transit blocks, and historical attacked data.
[0025] Specifically, based on the identified transit blocks, by querying the device management database of the switch or communicating with the network security management system, the characteristic information of the transit blocks is obtained, including the transit block type, the number of transit blocks, the security level of the transit blocks, and the historical attack data. Among them, the transit block type refers to the role and function of the transit block in the network, such as the core block, the regional boundary block, the terminal block, etc.; the number of transit blocks is the total number of transit blocks in the blockchain communication path, which can be obtained by directly counting the identified transit blocks; the security level of the transit blocks is the security level divided according to factors such as the security protection ability of the transit blocks and their network locations, for example, high, medium, and low levels, and these security levels are pre-set in the device management database; the historical attack data records the situations of the transit blocks being attacked by the network in the past, including information such as the attack type, frequency, and severity, which can be extracted from the security logs of the network security management system.
[0026] Extracting these characteristic items of the transit blocks comprehensively describes the state of the transit blocks, provides detailed data support for the next step of precise risk quantification analysis, and helps to more accurately judge the risks faced by the blockchain communication requests.
[0027] Step S4: Perform risk quantification analysis on the multiple characteristic items through a risk factor quantification model, output the first risk quantification index of the transit blocks, output the corresponding privacy security protection level of the blockchain communication request information according to the first risk quantification index, and the security policy server of the switch configures the security protection protocol for the blockchain communication request information according to the privacy security protection level.
[0028] Specifically, the risk factor quantification model is a model that converts various factors affecting risks into quantifiable indicators through mathematical methods. The privacy security protection level is different protection levels divided for the transit blocks in the communication path according to the risk quantification index. For example, the ordinary encryption layer, the high-strength encryption layer, the anonymous channel layer, the trusted execution environment layer, etc. Different privacy security protection levels correspond to different security protection measures. The security policy server is responsible for storing and managing security policies and configuring the corresponding security protection protocols according to the risk assessment results. These security protection protocols are security protocols applied in the blockchain communication process, such as IPSec, SSL / TLS, etc., which are used to encrypt data, authenticate identities, and ensure the confidentiality and integrity of the blockchain communication. Different protocols provide different levels of security protection. The security policy server is a server responsible for centrally managing and configuring all security protection policies in the network. In the industrial control network, the security policy server controls the security of each blockchain communication path through defined rules, protocols, and protection levels.
[0029] Input the multiple feature items of the transit block extracted in step S3 into the risk factor quantification model. The model calculates each feature item of the transit block according to a preset algorithm, and finally outputs a numerical index reflecting the risk degree of the transit block, that is, the first risk quantification index. This index can intuitively represent the risk level of the transit block. The larger the value of the first risk quantification index, the greater the security risk faced by the transit block. According to this first risk quantification index, determine the privacy security protection level corresponding to the blockchain communication request information through preset rules (such as different protection levels corresponding to the numerical range of the risk quantification index). Then, the security policy server of the switch selects the corresponding security protection protocol from the security protection protocol library it stores according to this privacy security protection level and configures it.
[0030] Determine the privacy security protection level through risk quantification analysis, and configure the corresponding security protection protocol by the security policy server, which realizes precise protection according to the actual risk situation of the transit block and improves the security of blockchain communication in the industrial control network.
[0031] Furthermore, the security policy server includes a defined multi-level protocol configuration template. The multi-level protocol configuration template corresponds to multiple privacy security protection levels. Among them, the configuration parameters of each level protocol configuration template include a protocol type combination and encryption parameters. The switch sends the privacy security protection level to the security policy server, and the security policy server obtains the matching protocol configuration template level according to the privacy security protection level; configure the security protection protocol of the blockchain communication request information according to the configuration parameters of the matching protocol configuration template level.
[0032] Specifically, the multi-level protocol configuration template is a set of templates used to define different security protection levels. Each template contains security protection parameters at different levels, such as a protocol type combination and encryption parameters. These templates help the security policy server flexibly configure appropriate security protection protocols according to different network environments and requirements. Among them, the protocol type combination refers to the combination method of different protocols used to ensure the security of blockchain communication, including encryption protocols (such as TLS, IPSec), authentication protocols (such as signature authentication, zero-trust access authentication, etc.), and these protocols work together to protect the confidentiality and integrity of blockchain communication data. The encryption parameters refer to the encryption technology and its related configuration items used in the blockchain communication process, such as encryption algorithms (such as AES, RSA), key lengths, encryption methods (symmetric encryption, asymmetric encryption), etc.
[0033] The switch sends the received privacy and security protection level information to the security policy server. The security policy server stores multiple pre-defined multi-level protocol configuration templates internally, and each template corresponds to a protection level. For example, the level 3 template includes "TLS + asymmetric encryption + link integrity check", while level 1 only includes "lightweight encryption + MAC address binding". The policy server searches for a matching protocol configuration template in the multi-level protocol configuration templates based on the received level information, and configures the security protection protocol for the blockchain communication request according to the configuration parameters of the template. For example, if the switch receives privacy and security protection level information indicating that a certain transit block belongs to a high-risk path, it will send a high-risk level protection requirement to the security policy server. The server then selects a protocol configuration template with high encryption strength and strict authentication, and configures a suitable security protection protocol for the transit block according to the configuration parameters, such as protocol type combination (TLS, ECC signature, IPsec), encryption parameters (AES-256 encryption + HMAC-SHA256 verification).
[0034] By establishing the correspondence between the multi-level protocol configuration template and the privacy and security protection level, it is possible to accurately configure the security protection protocol for the blockchain communication request information according to the risk status (privacy and security protection level) of the transit block. This makes the configuration of the security protection protocol more flexible and accurate, and can reduce the consumption of computing resources while ensuring the security of blockchain communication, optimizing the overall performance and resource utilization.
[0035] Furthermore, configuring the security protection protocol for the blockchain communication request information according to the configuration parameters of the matching protocol configuration template level includes:
[0036] Obtain the high-risk transit block of the transit block, where the high-risk transit block is a transit block whose risk quantification index is greater than the preset risk quantification index; the switch sends the security protection protocol to the high-risk transit block, and the high-risk transit block performs security protection according to the corresponding block protocol content.
[0037] Specifically, the preset risk quantification index is a pre-set boundary for dividing the degree of risk, and the transit blocks above this boundary are identified as high-risk transit blocks. The risk quantification index of each transit block is compared with the preset risk quantification index, and the blocks with risk quantification index greater than the preset risk quantification index are identified and marked as high-risk transit blocks. These blocks may become potential attack targets because of their low security protection level, many historical attack records, or their critical location and role. Then, the switch sends the security protection protocol previously determined according to the configuration parameters of the matching protocol configuration template level to these high-risk transit blocks. The high-risk transit blocks perform security protection according to the corresponding block protocol content received, such as using strong encryption protocols, enabling multi-factor authentication, etc.
[0038] By automatically identifying and prioritizing the protection of high-risk transit blocks, it ensures that key security vulnerabilities in the network are better protected, while avoiding excessive protection of low-risk blocks, thereby improving the security of the entire industrial control blockchain communication while saving computing resources.
[0039] Further, such as Figure 2 As shown, in step S4, risk quantitative analysis is performed on the multiple feature items through a risk factor quantification model, including:
[0040] Step S41: Generate an M×N feature item matrix according to the multiple feature items of the transfer block, wherein M is the number of transfer blocks and N is the number of feature items.
[0041] Step S42: Analyze the block criticality according to the function of the transfer block, output the critical weight corresponding to the transfer block, and generate an M×1 weight matrix according to the critical weight corresponding to the transfer block.
[0042] Step S43: performing matrix calculation on the feature item matrix and the weight matrix, outputting a first risk quantification indicator matrix, and extracting the first risk quantification indicator of each transfer block by using the first risk quantification indicator matrix.
[0043] Specifically, multiple feature items of each transfer block are collected, including the type of transfer block, the number of transfer blocks, the security level of the transfer block, and historical attack data. Then, with the number of transfer blocks M as the number of rows and the number of feature items N as the number of columns, these feature items are organized into an M×N feature item matrix. Among them, M and N are both positive integers, M refers to the number of transfer blocks, and N refers to the number of feature items. For example, if there are 3 transfer blocks and each transfer block has 4 feature items, then a 3×4 feature item matrix will be constructed, and the feature items of each transfer block will be filled in the corresponding positions of the matrix in turn.
[0044] For each relay block, analyze its criticality according to its function in industrial control blockchain communication. For example, if a relay block is a hub connecting multiple critical devices, then the criticality of this block is relatively high. Score the criticality of the block according to its function, and output a corresponding critical weight for each relay block. The larger the weight, the higher the importance of the block in the network, and more protection measures should be given to it. Then, arrange these critical weights into an M×1 weight matrix according to the number M of relay blocks, where each row represents the weight of a block. For example, if there are 3 relay blocks with critical weights of 0.3, 0.5, and 0.2 respectively, then a 3×1 weight matrix is constructed and these weights are filled into the columns of the matrix in sequence.
[0045] Perform matrix calculations on the previously constructed feature item matrix and weight matrix, and obtain the first risk quantification index matrix through matrix multiplication. Each element in this first risk quantification index matrix corresponds to the risk quantification result of a relay block, and directly obtain the values of these elements as the first risk quantification index of the relay block.
[0046] Through the above steps, the security risks of each relay block can be comprehensively evaluated, and a specific risk quantification index can be generated according to its function, characteristics, and importance. This index provides a clear basis for subsequent security policy configuration, ensuring that blocks with higher risks in the network can be more strictly protected, and improving the security of the entire industrial control system.
[0047] Furthermore, the extraction of multiple feature items of the relay block in step S3 further includes:
[0048] Obtain the multiple feature items, including the relay block type, the number of relay blocks, the security level of the relay block, and historical attack data. Among them, the relay block type includes core blocks, regional boundary blocks, and terminal blocks, the number of relay blocks includes the number of core blocks, the number of regional boundary blocks, and the number of terminal blocks, the security level of the relay block includes the block encryption protocol level and the firewall level, and the historical attack data includes the frequency, size, and number of attacks within a preset period.
[0049] Specifically, by extracting detailed features of each relay block in the blockchain communication path, including the relay block type, the number of relay blocks, the security level of the relay block, and historical attack data, the security risk levels of each block can be accurately evaluated in subsequent risk quantification analysis.
[0050] A transit block refers to an intermediate node block that is neither the source nor the target in the blockchain communication path and is used for data relay, forwarding, consensus, or other support services. Different types of transit blocks have different roles in blockchain communication security protection. The core block undertakes key routing and data center functions and has the greatest impact on communication. The regional boundary block connects different logical regions or sub-chains and is used for inter-regional forwarding. The terminal block is close to the data source or destination, and its functions are usually relatively simple. To determine the type of transit block, by parsing the OSPF routing table, identifying the network topology structure, and judging the role of each transit block in the network, and then identifying whether each transit block is a core block, a regional boundary block, or a terminal block.
[0051] Next, traverse all the devices on the blockchain communication path and classify and count the numbers of core blocks, regional boundary blocks, and terminal blocks.
[0052] For the block encryption protocol level in the security level of the transit block, it is determined by checking the encryption protocol adopted by the transit block. For example, view the configuration file of the block or use a network security detection tool to determine whether it adopts the SSL / TLS protocol and the specific version number, so as to determine its encryption protocol level. For the firewall level, it can be determined by viewing the setting rules and protection ability parameters of the firewall. For example, if the firewall can perform deep packet inspection and has advanced intrusion prevention functions, then its firewall level may be relatively high.
[0053] For the frequency, size, and quantity of attacks suffered within a preset period in the historical attacked data, they are obtained through network security logs. The network security logs record the relevant information of the transit block being attacked within a certain time (preset period), and the number of times (frequency) that a certain transit block is attacked within the preset period, the amount of data involved in each attack (size), and the total number of different types of attacks suffered (quantity) can be counted.
[0054] Furthermore, step S2 further includes:
[0055] Step S21: Construct a first transit block topology network according to the identified transit block.
[0056] Step S22: Identify the connected blocks of the identified transit block and construct a second transit block topology network, where the second transit block topology network is a lower-level topology network of the first transit block topology network.
[0057] Step S23: Perform risk quantification analysis on the second transit block topology network and output a second risk quantification index based on the identified transit block.
[0058] Step S24: Update the corresponding privacy and security protection level of the blockchain communication request information according to the second risk quantification index.
[0059] Specifically, according to the physical connection or logical connection relationship between the identified relay blocks, a connection relationship diagram of the blocks is drawn, thereby constructing a first relay block topology network. For example, the identified relay blocks are a group of routers located in the data center. By querying the interface configuration information of the routers, it is determined which routers are connected to each other, and then a first relay block topology network composed of these routers is constructed.
[0060] For each identified relay block, find the blocks directly connected to it, and these blocks are the connection blocks. Then, taking these connection blocks as the main body, a second relay block topology network is constructed according to the connection relationship between the blocks.
[0061] After constructing the second relay block topology network, similar to the method of determining the first risk quantification index described above, risk quantification analysis is performed on each element in this network, specifically including: extracting the connection block feature items, constructing a corresponding risk quantification model, and calculating the second risk quantification index based on the identified relay blocks. This index reflects the risk level based on the identified relay blocks and their lower-level topology network (the second relay block topology network), and is used to evaluate the overall security status of the second-layer network devices.
[0062] According to the obtained second risk quantification index, update the corresponding privacy and security protection level in the blockchain communication request information. If the second risk quantification index is relatively high, it indicates that the risk of the lower-level topology network based on the identified relay blocks is relatively large, then it is necessary to improve the privacy and security protection level, such as increasing the encryption intensity, strengthening access control, etc.; if the index is relatively low, the privacy and security protection level can be appropriately reduced to improve efficiency. For example, if the second risk quantification index shows that a certain local network is vulnerable to external attacks, then when the blockchain communication request passes through this local network, the privacy and security protection level is upgraded from low level to medium level.
[0063] The above steps can refine the scope of network risk analysis by constructing a multi-level topology network and performing detailed risk quantification analysis, expanding the risk analysis from the identified relay blocks to their connection blocks, so as to more comprehensively evaluate the network risk.
[0064] Furthermore, step S23 includes:
[0065] Extract multiple feature items of each block in the second intermediate transfer block topology network, where the multiple feature items include the intermediate transfer block type, the number of intermediate transfer blocks, the security level of the intermediate transfer blocks, and historical attack data; perform risk quantification analysis on the multiple feature items through the risk factor quantification model, and output the second risk quantification index in the second intermediate transfer block topology network.
[0066] Specifically, in order to evaluate the security risks of the second-layer intermediate transfer blocks, it is necessary to extract multiple key feature items, including: intermediate transfer block type (i.e., core blocks, regional boundary blocks, terminal blocks, etc. in the second-layer topology), the number of intermediate transfer blocks (i.e., the total number of devices and the distribution of various types of devices in the second-layer topology), the security level of the intermediate transfer blocks (including encryption protocol strength, firewall rule complexity, etc.), historical attack data (including the number of attacks, attack types, attack traffic, etc. within a predetermined period), and then perform risk quantification analysis on the multiple feature items through the risk factor quantification model to determine the second risk quantification index in the second intermediate transfer block topology network.
[0067] Parse all devices in the second-layer network, count the number of devices of each type after classifying them by device type, obtain the security level of the devices, and then extract historical attack data.
[0068] According to the multiple feature items of each block in the second intermediate transfer block topology network extracted, construct an M×N feature matrix, where M is the number of devices and N is the number of feature items. Analyze the criticality of each connected block according to the function of each connected block, and assign corresponding critical weights to each connected block to form an M×1 weight matrix, which is used to represent the criticality of each device. Perform matrix multiplication on the feature matrix and the weight matrix to obtain the second risk quantification index of each connected block in the second intermediate transfer block topology network.
[0069] The execution process of determining the second risk quantification index is similar to the process of determining the first risk quantification index, and the specific execution steps of determining the second risk quantification index can be referred to the foregoing.
[0070] By accurately evaluating the security risks of the second-layer intermediate transfer blocks and calculating the risk quantification index according to factors such as intermediate transfer block type, historical attack data, and encryption protocol strength, it can dynamically adapt to the security requirements of different industrial control environments, ensure that critical devices are subject to more stringent security protection, and avoid resource waste at the same time.
[0071] Further, step S22 includes:
[0072] Query devices through the SNMP protocol to obtain the list of direct connected devices of the identified intermediate transfer blocks, and obtain the connected blocks; record the IP addresses, port numbers, and link status of the connected blocks, and construct the second intermediate transfer block topology network.
[0073] Specifically, the SNMP (Simple Network Management Protocol), that is, the Simple Network Management Protocol, is a standard protocol for network device management and monitoring. This protocol allows network administrators to manage the network by querying and setting relevant parameters of network devices (such as routers, switches, etc.). By using the SNMP protocol to send a query request to the identity transfer block, the SNMP protocol will perform a query operation according to the device's management information base to determine the list of directly connected devices of the identity transfer block and obtain the connection block.
[0074] For each obtained connection block, record the IP address, port number, and link status of the connection block, and construct a second transfer block topology network. The IP address determines the location of the device, the port number specifies the blockchain communication interface, and the link status reflects the connection quality. The comprehensive presentation of this information can provide a more comprehensive understanding of the structure and status of the local network, and provide a clear network structure model for subsequent operations such as risk quantification analysis. Specifically, obtain its IP address by querying the network interface configuration of the device. At the same time, query the port mapping relationship between the switch port and the connected device to obtain the port number. In addition, the link status also needs to be recorded, and information such as whether the link is normal and the bandwidth of the link is obtained by sending a link detection packet or querying the link status monitoring function of the device. Finally, construct a second transfer block topology network based on the IP address, port number, and link status information of these recorded connection blocks. For example, a graphical tool can be used to draw the connection blocks according to their connection relationship of IP address and port number, and represent them with different colors or lines according to the link status (such as green lines indicating normal links and red lines indicating link failures).
[0075] Furthermore, based on the OSPF protocol, analyze the blockchain communication path of the blockchain communication request information, and identify the transfer block, including:
[0076] Analyze the blockchain communication request information based on the OSPF protocol, output OSPF analysis data, and identify the transfer block according to the characteristics of the OSPF analysis data.
[0077] Specifically, when the switch receives a blockchain communication request for industrial control, it parses the blockchain communication request according to the rules of the OSPF protocol. The OSPF protocol will check information such as the source address, destination address, and related network identifiers in the blockchain communication request. For example, in a blockchain communication request based on an IP network, the OSPF protocol will analyze information such as the source IP address, destination IP address, and the network area where the data packet is located in the IP data packet. According to this information, the Dijkstra algorithm is used to calculate the shortest routing path to form OSPF parsing data. According to the path information parsed by OSPF, all blocks that are neither the source device nor the target device are extracted, and these are the transit blocks. By parsing the blockchain communication path through OSPF and identifying the transit blocks, all transit blocks through which the data flows can be accurately identified, avoiding omission of key devices.
[0078] In summary, the multi-level security protection communication method for industrial control provided by the embodiments of the present application has the following beneficial effects:
[0079] The switch receives the industrial control blockchain communication request information, parses the blockchain communication path based on the OSPF protocol, and identifies the transit blocks therein to clarify the key links that may be attacked during the blockchain communication process. Subsequently, multiple feature items of the transit blocks are extracted, including block type, quantity, security level, and historical attacked data, and these features are analyzed using a risk factor quantification model to calculate the corresponding risk quantification indicators. Further, a first transit block topology network and a second transit block topology network are constructed to provide an overall structure view of the network and a more detailed block connection relationship. Devices are queried through the SNMP protocol to obtain a list of directly connected devices, and the IP addresses, port numbers, and link statuses of the connected blocks are recorded to ensure the accuracy and detail of the topology network. Risk quantification analysis is performed on the second transit block topology network to output a second risk quantification indicator, further improving the accuracy of risk assessment. According to the risk quantification indicators, the privacy security protection level of the blockchain communication request is updated, and the security policy server of the switch configures the corresponding security protection protocol according to the protection level. Through the multi-level protocol configuration template, it is ensured that high-risk transit blocks are given a higher level of protection, while low-risk paths adopt lightweight protection strategies to reduce unnecessary security negotiation delays, avoid high consumption of real-time computing resources during the dynamic negotiation process, and at the same time reduce the blockchain communication delay, improve the system response speed and control accuracy, thereby realizing an efficient, low-latency, and dynamically adjustable security protection mechanism while ensuring the security of the industrial control network.
[0080] Overall, through pre-evaluating risks and dynamically adjusting protection strategies, the embodiments of this application reduce the blockchain communication latency caused by real-time dynamic negotiation, optimize the allocation of computing resources, improve the real-time performance and response speed of the industrial control network, and at the same time enhance the overall security of the industrial control system, ensuring the efficient and reliable operation of industrial control blockchain communication.
[0081] Embodiment 2, as Figure 3 shown, based on the same inventive concept as the foregoing Embodiment 1, the embodiments of this application provide a multi-level security protection communication platform for industrial control, and the platform includes:
[0082] A request receiving module 10, configured to receive blockchain communication request information for industrial control through a switch.
[0083] A path parsing module 20, configured to parse the blockchain communication path of the blockchain communication request information based on the OSPF protocol and identify transit blocks.
[0084] A block feature extraction module 30, configured to extract multiple feature items of the transit block, and the multiple feature items include transit block types, the number of transit blocks, the security level of the transit block, and historical attack data.
[0085] A protection configuration module 40, configured to perform risk quantification analysis on the multiple feature items through a risk factor quantification model, output a first risk quantification index of the transit block, output a corresponding privacy and security protection level of the blockchain communication request information according to the first risk quantification index, and a security policy server of the switch configures a security protection protocol for the blockchain communication request information according to the privacy and security protection level.
[0086] Further, the security policy server includes defined multi-level protocol configuration templates, and the multi-level protocol configuration templates correspond to multiple privacy and security protection levels. Among them, the configuration parameters of each level protocol configuration template include protocol type combinations and encryption parameters; the switch sends the privacy and security protection level to the security policy server, and the security policy server obtains a matching protocol configuration template level according to the privacy and security protection level; configures the security protection protocol for the blockchain communication request information according to the configuration parameters of the matching protocol configuration template level.
[0087] Further, the protection configuration module 40 of the embodiments of this application is further configured to perform the following steps:
[0088] Obtain the high-risk transit blocks of the transit blocks, where the high-risk transit blocks are transit blocks with a risk quantification index greater than a preset risk quantification index; the switch sends the security protection protocol to the high-risk transit blocks, and the high-risk transit blocks perform security protection according to the corresponding block protocol content.
[0089] Further, the protection configuration module 40 in the embodiment of the present application is further configured to perform the following steps:
[0090] Generate an M×N feature item matrix according to multiple feature items of the transit blocks, where M is the number of transit blocks and N is the number of feature items; analyze the criticality of the transit blocks according to the functions of the transit blocks, output the corresponding key weights of the transit blocks, and generate an M×1 weight matrix according to the corresponding key weights of the transit blocks; perform matrix calculation on the feature item matrix and the weight matrix, output a first risk quantification index matrix, and extract the first risk quantification index of each transit block from the first risk quantification index matrix.
[0091] Further, the block feature extraction module 30 in the embodiment of the present application is further configured to perform the following steps:
[0092] Obtain the multiple feature items, including the transit block type, the number of transit blocks, the security level of the transit blocks, and the historical attack data; where the transit block type includes the core block, the regional boundary block, and the terminal block, the number of transit blocks includes the number of core blocks, the number of regional boundary blocks, and the number of terminal blocks, the security level of the transit blocks includes the block encryption protocol level and the firewall level, and the historical attack data includes the attack frequency, size, and quantity within a preset period.
[0093] Further, the path parsing module 20 in the embodiment of the present application is further configured to perform the following steps:
[0094] Construct a first transit block topology network according to the identified transit blocks; identify the connected blocks of the identified transit blocks, construct a second transit block topology network, where the second transit block topology network is a lower-level topology network of the first transit block topology network; perform risk quantification analysis on the second transit block topology network, output a second risk quantification index based on the identified transit blocks; update the corresponding privacy and security protection level of the blockchain communication request information according to the second risk quantification index.
[0095] Further, the path parsing module 20 in the embodiment of the present application is further configured to perform the following steps:
[0096] Extract multiple feature items of each block in the second transit block topology network, where the multiple feature items include the transit block type, the number of transit blocks, the security level of the transit blocks, and historical attack data; perform risk quantification analysis on the multiple feature items through the risk factor quantification model, and output a second risk quantification index in the second transit block topology network.
[0097] Further, the path parsing module 20 in the embodiment of the present application is further configured to perform the following steps:
[0098] Query the device through the SNMP protocol to obtain a list of directly connected devices that identify the transit block, and obtain the connected blocks; record the IP addresses, port numbers, and link status of the connected blocks, and construct a second transit block topology network.
[0099] Further, the path parsing module 20 in the embodiment of the present application is further configured to perform the following steps:
[0100] Parse the blockchain communication request information based on the OSPF protocol, output OSPF parsing data, and identify the transit block according to the characteristics of the OSPF parsing data.
[0101] Through the foregoing detailed description of the multi-level security protection communication method for industrial control in this specification, those skilled in the art can clearly know the multi-level security protection communication platform for industrial control in this embodiment. For the platform disclosed in Embodiment 2, since it corresponds to the method disclosed in Embodiment 1, it has corresponding functional modules and beneficial effects. For the relevant parts, refer to the description in the method part.
[0102] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A multi-level security protection communication method for industrial control, characterized in that, The method includes: The switch receives blockchain communication request information for industrial control; Based on the OSPF protocol, parse the blockchain communication path of the blockchain communication request information and identify the transit block; Extract multiple feature items of the transit block, where the multiple feature items include the transit block type, the number of transit blocks, the security level of the transit block, and historical attack data; Perform risk quantification analysis on the multiple feature items through a risk factor quantification model, output the first risk quantification index of the transit block, and output the corresponding privacy and security protection level of the blockchain communication request information according to the first risk quantification index. The security policy server of the switch configures the security protection protocol of the blockchain communication request information according to the privacy and security protection level.
2. The method according to claim 1, wherein, The security policy server includes defined multi-level protocol configuration templates, and the multi-level protocol configuration templates correspond to multiple privacy and security protection levels. Among them, the configuration parameters of each level protocol configuration template include protocol type combinations and encryption parameters; The switch sends the privacy and security protection level to the security policy server, and the security policy server obtains the matching protocol configuration template level according to the privacy and security protection level; Configure the security protection protocol of the blockchain communication request information according to the configuration parameters of the matching protocol configuration template level.
3. The method according to claim 2, wherein Configure the security protection protocol of the blockchain communication request information according to the configuration parameters of the matching protocol configuration template level. The method further includes: Obtain the high-risk transit blocks of the transit block, where the high-risk transit block is a transit block with a risk quantification index greater than a preset risk quantification index; The switch sends the security protection protocol to the high-risk transit block, and the high-risk transit block performs security protection according to the corresponding block protocol content.
4. The method according to claim 2, wherein Perform risk quantification analysis on the multiple feature items through a risk factor quantification model. The method includes: Generate a feature item matrix of M×N according to the multiple feature items of the transit block, where M is the number of transit blocks and N is the number of feature items; Analyze the criticality of the block according to the function of the transit block, output the corresponding key weight of the transit block, and generate a weight matrix of M×1 according to the corresponding key weight of the transit block; Perform matrix calculation on the feature item matrix and the weight matrix, output the first risk quantification index matrix, and extract the first risk quantification index of each transit block from the first risk quantification index matrix.
5. The method according to claim 1, characterized in that, Extract multiple feature items of the transit block. The method further includes: Obtain the multiple feature items, including the transit block type, the number of transit blocks, the security level of the transit block, and historical attack data; Among them, the transit block type includes a core block, a regional boundary block, and a terminal block. The number of transit blocks includes the number of core blocks, the number of regional boundary blocks, and the number of terminal blocks. The security level of the transit block includes the block encryption protocol level and the firewall level. The historical attack data includes the frequency, size, and number of attacks within a preset period.
6. The method according to claim 1, characterized in that Parse the blockchain communication path of the blockchain communication request information based on the OSPF protocol, identify the transit block, and the method further includes: Construct a first transit block topology network according to the identified transit block; Identify the connected blocks of the identified transit block and construct a second transit block topology network, where the second transit block topology network is a lower-level topology network of the first transit block topology network; Perform risk quantification analysis on the second transit block topology network and output a second risk quantification index based on the identified transit block; Update the corresponding privacy and security protection level of the blockchain communication request information according to the second risk quantification index.
7. The method according to claim 6, wherein Perform risk quantification analysis on the second transit block topology network, and the method includes: Extract multiple feature items of each block in the second transit block topology network, where the multiple feature items include the transit block type, the number of transit blocks, the security level of the transit block, and historical attack data; Perform risk quantification analysis on the multiple feature items through the risk factor quantification model and output the second risk quantification index in the second transit block topology network.
8. The method according to claim 6, wherein Identify the connected blocks of the identified transit block, and the method includes: Query the device through the SNMP protocol to obtain the list of directly connected devices of the identified transit block and obtain the connected blocks; Record the IP address, port number, and link status of the connected blocks and construct a second transit block topology network.
9. The method according to claim 1, characterized in that, Parse the blockchain communication path of the blockchain communication request information based on the OSPF protocol, identify the transit block, and the method includes: Parse the blockchain communication request information based on the OSPF protocol, output the OSPF parsing data, and identify the transit block according to the characteristics of the OSPF parsing data.
10. A multi-level security protection communication platform for industrial control, characterized in that, The platform is used to execute the multi-level security protection communication method for industrial control according to any one of claims 1-9, and includes: A request receiving module for receiving blockchain communication request information for industrial control through a switch; A path parsing module for parsing the blockchain communication path of the blockchain communication request information based on the OSPF protocol and identifying the transit block; A block feature extraction module for extracting multiple feature items of the transit block, where the multiple feature items include the transit block type, the number of transit blocks, the security level of the transit block, and historical attack data; A protection configuration module for performing risk quantification analysis on the multiple feature items through a risk factor quantification model, outputting a first risk quantification index of the transit block, outputting the corresponding privacy and security protection level of the blockchain communication request information according to the first risk quantification index, and the security policy server of the switch configuring the security protection protocol of the blockchain communication request information according to the privacy and security protection level.