Industrial data security management method and system based on digitization

Through the digital-based industrial data security management system, the problem of data leakage is solved, data security protection and business application reliability are achieved, and data security standards are promoted.

CN120296757AInactive Publication Date: 2025-07-11LINYI MINTAI INFORMATION TECH CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510322085.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

Smart Images

  • Figure CN120296757A_ABST
    Figure CN120296757A_ABST
Patent Text Reader

Abstract

The invention provides an industrial data security management method and system based on digitization, and relates to the technical field of distributed object storage, and the system comprises a server module which is used for data interaction processing in a security management process; the data acquisition module is used for performing real-time acquisition on the industrial environment data in the use process; and the data monitoring and analyzing module is used for performing dynamic management on the data security risk and performing data processing in a normalized manner. The data storage module is used, data resources are regularly backed up to prevent data from being lost or damaged, when the data is accidentally lost, the data resources are quickly recovered through data backup, establishment and implementation of data safety standards are promoted, and the compatibility and interoperability of the system are improved; corresponding safety control measures are taken, safety protection can be carried out on the industrial data, ordered flow of the data is promoted, and safe use of business applications is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of industrial safety management, and particularly to a digital-based industrial data security management method and system. Background Art

[0002] Digitalization is the process of converting information into digital format, which means converting any continuously changing input such as the lines of a drawing into a series of discrete units, represented by 0 and 1 in a computer. Usually, an analog-to-digital converter is used to perform this conversion.

[0003] Big data, or massive data, refers to the data volume involved is so huge that it cannot be captured, managed, processed, and organized into information that helps enterprises make more proactive business decisions within a reasonable time through mainstream software tools.

[0004] Industrial big data refers to a large amount of data generated at high speed by industrial equipment, corresponding to the equipment status at different times. It is the information in the Internet of Things and is also related to the big data popular in information technology marketing. Industrial big data also means that the large amount of data generated by industrial equipment has its potential commercial value. Industrial big data will cooperate with the technology of the industrial Internet and use the original data to support management decisions, such as reducing maintenance costs and improving customer service.

[0005] Data needs to be protected in many aspects such as collection, storage, transmission, exchange, and use. By formulating data security management systems and security standards, information protection in the big data processing and application links can be strengthened. However, in the existing technologies, there is still a lack of technical solutions for data security management, resulting in data being easily leaked, which is not conducive to the development of the big data era. At the same time, during the storage process, the security of data cannot be protected to a certain extent. Summary of the Invention

[0006] The present invention proposes a digital-based industrial data security management method and system. By using the data storage module, data resources are regularly backed up to prevent data loss or damage. When an accidental loss of data occurs, the data resources can be quickly restored through the backup data, promoting the formulation and implementation of data security standards, improving the compatibility and interoperability of the system. By using the security protection module, according to the analysis results, corresponding security control measures are taken, which can protect the industrial data, promote the orderly flow of data, and ensure the secure use of business applications.

[0007] To achieve the above objectives, the present invention is realized through the following technical solutions: A digital-based industrial data security management system, comprising:

[0008] Server module: used for data interaction processing during security management;

[0009] Data acquisition module: used to collect industrial environment data in real time during use;

[0010] Data monitoring and analysis module: used to dynamically manage data security risks and regularly carry out data processing;

[0011] Data storage module: used for distributed storage of data during use to ensure data security;

[0012] Security protection module: according to the analysis results, take corresponding security control measures, select targeted data security capabilities around the identified data security risks, and implement technical protection measures;

[0013] User interface module: used to provide a user interface during system use to facilitate user operation;

[0014] The data storage module includes a data backup module, a data recovery module, and a data transmission module. The data backup module, the data recovery module, and the data transmission module are all bidirectionally signal-connected. The security protection module includes an access authentication module, an access control module, a limit management module, a network isolation module, a data encryption module, and a data desensitization module. The access authentication module, the access control module, the limit management module, the network isolation module, the data encryption module, and the data desensitization module are all bidirectionally signal-connected;

[0015] There is a bidirectional signal connection between the output end of the data transmission module in the data storage module and the access authentication module in the security protection module.

[0016] Furthermore, the server module includes a resource management module, a situation awareness module, a risk reporting and sharing module, a technical test and verification module, and an event emergency response module. The resource management module, the situation awareness module, the risk reporting and sharing module, the technical test and verification module, and the event emergency response module are all bidirectionally signal-connected.

[0017] Furthermore, the data monitoring and analysis module includes a risk monitoring module, an analysis and processing module, a warning module, a reporting module, and a disposal module. The risk monitoring module, the analysis and processing module, the warning module, the reporting module, and the disposal module are all bidirectionally signal-connected.

[0018] Furthermore, the user interface module includes a system resource management module, a security policy configuration module, an operation control module, and a permission grading module. The system resource management module, the security policy configuration module, the operation control module, and the permission grading module are all bidirectionally signal-connected.

[0019] Further, the output end of the risk reporting and sharing module in the server module is bidirectionally signal-connected to the input end of the operation control module in the user interface module, and the output end of the risk reporting and sharing module in the server module is bidirectionally signal-connected to the input end of the risk monitoring module in the data monitoring and analysis module.

[0020] Further, the output end of the risk reporting and sharing module in the server module is bidirectionally signal-connected to the input end of the access authentication module in the security protection module, and the output end of the access authentication module in the security protection module is bidirectionally signal-connected to the input end of the operation control module in the user interface module.

[0021] Further, the output end of the access authentication module in the security protection module is bidirectionally signal-connected to the input end of the risk monitoring module in the data monitoring and analysis module, and the output end of the risk monitoring module in the data monitoring and analysis module is bidirectionally signal-connected to the input end of the data transmission module in the data storage module.

[0022] Further, the output end of the operation control module in the user interface module is signal-connected to the input end of the data transmission module in the data storage module.

[0023] Further, the output end of the data acquisition module is signal-connected to the input end of the risk monitoring module in the data monitoring and analysis module.

[0024] A digital-based industrial data security management method includes the following steps:

[0025] Step 1. Data classification and grading: Classify and identify data according to industry requirements, business needs, data sources, and uses, and form a data classification list. On this basis, manage the data at different levels according to its importance and sensitivity.

[0026] Step 2. Data life cycle management: Legally and compliantly collect data through the data acquisition module, process the data through the data monitoring and analysis module. At the same time, the security protection module establishes a monitoring and auditing mechanism for data transmission to detect and handle abnormal behaviors during data transmission. After completion, the data storage module performs secure storage, restricts access to the data public information network, and ensures the reliable availability of the data.

[0027] Step 3. Data security technology construction: Monitor and record database operations through the data monitoring and analysis module. For data that needs to be shared or made public, use data desensitization technology for processing to reduce the risk of data leakage. Use user behavior analysis technology to monitor and analyze users' operation behaviors and promptly detect abnormal behaviors.

[0028] Step 4: Data Security Assurance: Through data life cycle management, specific hierarchical protection requirements and operating procedures are formulated for different levels of data. A data security emergency plan and disposal process are developed, and emergency drills and evaluations are conducted regularly to improve the efficiency and effectiveness of emergency response.

[0029] Step 5: External Collaboration and Communication: Actively participate in the formulation of industry standards and specifications to promote the standardization and normalization of data security technologies.

[0030] The present invention provides a digital-based industrial data security management method and system, which has the following beneficial effects:

[0031] (1) For the digital-based industrial data security management method and system, by using the data storage module, data resources are backed up regularly to prevent data loss or damage. In case of accidental data loss, data resources can be quickly restored through the backup data, promoting the formulation and implementation of data security standards, and improving the compatibility and interoperability of the system.

[0032] (2) For the digital-based industrial data security management method and system, by using the security protection module, corresponding security control measures are taken according to the analysis results, which can protect industrial data, promote the orderly flow of data, and ensure the secure use of business applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] Figure 1 It is the overall system diagram of a digital-based industrial data security management method and system of the present invention;

[0034] Figure 2 It is the schematic diagram of the server module of a digital-based industrial data security management method and system of the present invention;

[0035] Figure 3 It is the schematic diagram of the data monitoring and analysis module of a digital-based industrial data security management method and system of the present invention;

[0036] Figure 4 It is the schematic diagram of the data storage module of a digital-based industrial data security management method and system of the present invention;

[0037] Figure 5 It is the schematic diagram of the security protection module of a digital-based industrial data security management method and system of the present invention;

[0038] Figure 6 It is the schematic diagram of the user interface module of a digital-based industrial data security management method and system of the present invention;

[0039] Figure 7This is a flowchart of a digital-based industrial data security management method and system of the present invention.

[0040] In the figure: 1. Server module; 2. Data acquisition module; 3. Data monitoring and analysis module; 4. Data storage module; 5. Security protection module; 6. User interface module. Specific implementation manners

[0041] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments.

[0042] Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary and are intended to explain the present invention and should not be construed as a limitation to the present invention.

[0043] The present invention will be further described below in conjunction with the accompanying drawings and embodiments:

[0044] Please refer to Figures 1-7 , the present invention provides a technical solution: a digital-based industrial data security management system, including:

[0045] Server module 1: Used for data interaction processing during the security management process;

[0046] Data acquisition module 2: Used for real-time acquisition of industrial environment data during use;

[0047] Data monitoring and analysis module 3: Used for dynamic management of data security risks and regular data processing;

[0048] Data storage module 4: Used for distributed storage of data during use to ensure data security;

[0049] Security protection module 5: According to the analysis results, take corresponding security control measures, select targeted data security capabilities around the identified data security risks, and implement technical protection measures;

[0050] User interface module 6: Used to provide a user interface during the use of the system to facilitate user operation;

[0051] The data storage module 4 includes a data backup module, a data recovery module, and a data transmission module. The data backup module, the data recovery module, and the data transmission module are all connected by two-way signals. The security protection module 5 includes an access authentication module, an access control module, a limit management module, a network isolation module, a data encryption module, and a data de-sensitization module. The access authentication module, the access control module, the limit management module, the network isolation module, the data encryption module, and the data de-sensitization module are all connected by two-way signals;

[0052] There is a two-way signal connection between the output end of the data transmission module in the data storage module 4 and the access authentication module in the security protection module 5.

[0053] Specifically, the server module 1 includes a resource management module, a situation awareness module, a risk reporting and sharing module, a technical test and verification module, and an event emergency response module. The resource management module, the situation awareness module, the risk reporting and sharing module, the technical test and verification module, and the event emergency response module are all connected by two-way signals.

[0054] Specifically, the data monitoring and analysis module 3 includes a risk monitoring module, an analysis and processing module, a warning module, a reporting module, and a disposal module. The risk monitoring module, the analysis and processing module, the warning module, the reporting module, and the disposal module are all connected by two-way signals.

[0055] Specifically, the user interface module 6 includes a system resource management module, a security policy configuration module, an operation control module, and a permission grading module. The system resource management module, the security policy configuration module, the operation control module, and the permission grading module are all connected by two-way signals.

[0056] Specifically, the output end of the risk reporting and sharing module in the server module 1 is connected to the input end of the operation control module in the user interface module 6 by two-way signals, and the output end of the risk reporting and sharing module in the server module 1 is connected to the input end of the risk monitoring module in the data monitoring and analysis module 3 by two-way signals.

[0057] Specifically, the output end of the risk reporting and sharing module in the server module 1 is connected to the input end of the access authentication module in the security protection module 5 by two-way signals, and the output end of the access authentication module in the security protection module 5 is connected to the input end of the operation control module in the user interface module 6 by two-way signals.

[0058] Specifically, the output end of the access authentication module in the security protection module 5 is connected to the input end of the risk monitoring module in the data monitoring and analysis module 3 by two-way signals, and the output end of the risk monitoring module in the data monitoring and analysis module 3 is connected to the input end of the data transmission module in the data storage module 4 by two-way signals.

[0059] Specifically, the output signal of the operation control module in the user interface module 6 is connected to the input end of the data transmission module in the data storage module 4.

[0060] Specifically, the output signal of the data acquisition module 2 is connected to the input end of the risk monitoring module in the data monitoring and analysis module 3.

[0061] The data acquisition module 2 collects data in the industrial environment in real time through devices such as sensors and cameras, including equipment status, production parameters, personnel activities, etc.

[0062] The data storage module 4 adopts a distributed storage system and combines data encryption technology to ensure the security of data storage. At the same time, through data backup and recovery mechanisms, the reliability of data is improved.

[0063] The data monitoring and analysis module 3 uses big data technology and machine learning algorithms to analyze and process data in real time, and identify potential security threats and abnormal behaviors.

[0064] According to the analysis results, the security protection module 5 takes corresponding security control measures, such as access control, data encryption, network isolation, etc., to ensure the secure transmission and use of data.

[0065] The user interface module 6 provides a friendly user interface, which is convenient for users to monitor the data security status, configure security policies, and manage system resources.

[0066] Data acquisition is obtained from CSV files, databases, or other online data sources. Assume that a CSV file is used for data collection:

[0067] import pandas as pd

[0068] # Load data from a CSV file

[0069] data = pd.read_csv('data.csv')

[0070] print(data.head()) # Display the first few rows of data

[0071] Code explanation:

[0072] import pandas as pd: Import the Pandas library. Pandas is a powerful tool for processing data.

[0073] pd.read_csv('data.csv): Read data from the specified file.

[0074] data.head(): Display the first few rows of data.

[0075] Data preprocessing, including cleaning, deduplication, filling missing values, standardization, etc.

[0076] # Remove duplicate data

[0077] data.drop_duplicates(inplace=True)

[0078] # Fill missing values

[0079] data.fillna(data.mean(), inplace=True) # Fill missing values with the mean value

[0080] Code explanation:

[0081] data.drop_duplicates(inplace=True): Delete duplicate rows.

[0082] data.fillna(data.mean(), inplace=True): Fill missing values with the mean value of each column.

[0083] Feature selection and extraction, select features that contribute to model training, usually using correlation analysis to select features.

[0084] # Select features and target variables

[0085] features = data[['feature1', 'feature2', 'feature3']] # Custom features

[0086] target = data['label'] # Target variable

[0087] Code explanation:

[0088] features: Select the feature columns considered important.

[0089] target: Define the target label.

[0090] Data hierarchical classification model selection, use classifiers such as decision trees and random forests. The following is an example of using a random forest:

[0091] from sklearn.ensemble import RandomForestClassifier

[0092] # Create a model object

[0093] model = RandomForestClassifier()

[0094] Code Explanation:

[0095] from skleamn.ensemble import RandomForestClassifier: Import the random forest classifier.

[0096] model = RandomForestClassifier(): Initialize the random forest model object.

[0097] Model training, train the model on the training set:

[0098] # Split the training set and test set

[0099] from sklearn.model_selection import train_test_split

[0100] X_train, x_test, y_train, y_test = train_test_split(features, target, test_size = 0.2, random_state

[0101] # Train the model

[0102] model.fit(x_train, y_train)

[0103] Code Explanation:

[0104] train_test_split: Split the dataset into a training set and a test set.

[0105] model.fit(x_train, y_train): Train the model using the training data.

[0106] Model evaluation, evaluate the model performance. The confusion matrix is one of the commonly used metrics for measuring classification models.

[0107] from sklearn.metrics import confusion_matrix

[0108] # Model prediction

[0109] predictions = model.predict(x_test)

[0110] # Generate the confusion matrix

[0111] conf_matrix = confusion_matrix(y_test, predictions) It should be noted that there seems to be a misspelling in "skleamn" in line 3, it should probably be "sklearn".

[0112] print(conf_matrix)

[0113] Code explanation:

[0114] model.predict(x_test): Make predictions on the test set.

[0115] confusion_matrix(y_test, predictions): Generate and print the confusion matrix.

[0116] Result output, output the classification results to an Excel or CSV file:

[0117] # Save the results to a CSV file

[0118] output = pd.DataFrame({'Actual': y_test, 'Predicted': predictions})

[0119] output.to_csv('output.csv', index = False)

[0120] Code explanation:

[0121] pd.DataFrame({....}): Create a new data frame to save the actual and predicted values.

[0122] output.to_csv('output.csv', index = False): Output the results as a CSV file.

[0123] An industrial data security management method based on digitization, comprising the following steps:

[0124] Step 1. Data classification and grading: Classify and identify data according to industry requirements, business needs, data sources and uses, and form a data classification list. On the basis of classification, manage data grading according to data importance and sensitivity;

[0125] Step 2. Data life cycle management: Legally and compliantly collect data through the data acquisition module 2, process the data through the data monitoring and analysis module 3. At the same time, the security protection module 5 establishes a monitoring and auditing mechanism for data transmission to discover and dispose of abnormal behaviors in data transmission. After completion, the data storage module 4 performs secure storage, restricts access to the data public information network, and ensures the reliable availability of the data;

[0126] Step 3: Construction of data security technology: Monitor and record database operations through the data monitoring and analysis module 3. For data that needs to be shared or made public, use data desensitization technology to process it and reduce the risk of data leakage. Utilize user behavior analysis technology to monitor and analyze users' operation behaviors and promptly detect abnormal behaviors;

[0127] Step 4: Data security guarantee: Through data life cycle management, formulate specific hierarchical protection requirements and operating procedures for different levels of data, formulate data security emergency plans and disposal processes, and conduct emergency drills and evaluations regularly to improve the efficiency and effectiveness of emergency response;

[0128] Step 5: External cooperation and communication: Actively participate in the formulation of industry standards and specifications to promote the standardization and normalization development of data security technology.

[0129] The main technical features of the present invention are as follows: It simultaneously realizes the quasi-real-time and efficient merging of incremental data and the merging of stored data after demand cooling. It supports setting differential merging strategies at the user or bucket level, and various parameters can be set for each merging strategy according to actual needs, thereby improving the merging efficiency and the relevance of the merged files, and enhancing the read and write performance and space utilization rate.

[0130] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the inventive concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention.

Claims

1. A digital-based industrial data security management system, characterized in that, Including: Server module (1): for data interaction processing during security management; Data acquisition module (2): for real-time acquisition of industrial environment data during use; Data monitoring and analysis module (3): for dynamically managing data security risks and regularly carrying out data processing; Data storage module (4): for distributed storage of data during use to ensure data security; Security protection module (5): According to the analysis results, take corresponding security control measures, select targeted data security capabilities around the identified data security risks, and implement technical protection measures; User interface module (6): for providing a user interface during system use to facilitate user operation; The data storage module (4) includes a data backup module, a data recovery module, and a data transmission module. The data backup module, the data recovery module, and the data transmission module are all bidirectionally signal-connected. The security protection module (5) includes an access authentication module, an access control module, a limit management module, a network isolation module, a data encryption module, and a data de-sensitization module. The access authentication module, the access control module, the limit management module, the network isolation module, the data encryption module, and the data de-sensitization module are all bidirectionally signal-connected; The output end of the data transmission module in the data storage module (4) is bidirectionally signal-connected to the access authentication module in the security protection module (5).

2. The industrial data security management system based on digitization according to claim 1, characterized in that: The server module (1) includes a resource management module, a situation awareness module, a risk reporting and sharing module, a technical test and verification module, and an event emergency response module. The resource management module, the situation awareness module, the risk reporting and sharing module, the technical test and verification module, and the event emergency response module are all bidirectionally signal-connected.

3. A digital-based industrial data security management system according to claim 1, characterized in that: The data monitoring and analysis module (3) includes a risk monitoring module, an analysis and processing module, a warning module, a reporting module, and a disposal module. The risk monitoring module, the analysis and processing module, the warning module, the reporting module, and the disposal module are all bidirectionally signal-connected.

4. An industrial data security management system based on digitization according to claim 1, characterized in that: The user interface module (6) includes a system resource management module, a security policy configuration module, an operation control module, and a permission grading module. The system resource management module, the security policy configuration module, the operation control module, and the permission grading module are all bidirectionally signal-connected.

5. A digital-based industrial data security management system according to claim 1, characterized in that: The output end of the risk reporting and sharing module in the server module (1) is bidirectionally signal-connected to the input end of the operation control module in the user interface module (6). The output end of the risk reporting and sharing module in the server module (1) is bidirectionally signal-connected to the input end of the risk monitoring module in the data monitoring and analysis module (3).

6. The industrial data security management system based on digitization according to claim 1, characterized in that: The output end of the risk reporting and sharing module in the server module (1) is bidirectionally signal-connected to the input end of the access authentication module in the security protection module (5). The output end of the access authentication module in the security protection module (5) is bidirectionally signal-connected to the input end of the operation control module in the user interface module (6).

7. The industrial data security management system based on digitization according to claim 1, wherein: The output end of the access authentication module in the security protection module (5) is bidirectionally signal-connected to the input end of the risk monitoring module in the data monitoring and analysis module (3), and the output end of the risk monitoring module in the data monitoring and analysis module (3) is bidirectionally signal-connected to the input end of the data transmission module in the data storage module (4).

8. The industrial data security management system based on digitization according to claim 1, characterized in that: The output end of the operation control module in the user interface module (6) is signal-connected to the input end of the data transmission module in the data storage module (4).

9. A digital-based industrial data security management system according to claim 1, characterized in that: The output end of the data acquisition module (2) is signal-connected to the input end of the risk monitoring module in the data monitoring and analysis module (3).

10. A digital-based industrial data security management method, characterized in that, Including the following steps: S1. Data classification and grading: Classify and identify data according to industry requirements, business needs, data sources, and uses, and form a data classification list. On the basis of classification, manage data grading according to the importance and sensitivity of the data. S2. Data life cycle management: Legally and compliantly collect data through the data acquisition module (2), process the data through the data monitoring and analysis module (3), and at the same time, the security protection module (5) establishes a monitoring and auditing mechanism for data transmission to detect and handle abnormal behaviors in data transmission. After completion, the data storage module (4) performs secure storage, restricts access to the data public information network, and ensures the reliable availability of the data. S3. Data security technology construction: Monitor and record database operations through the data monitoring and analysis module (3). For data that needs to be shared or made public, use data desensitization technology for processing to reduce the risk of data leakage, and use user behavior analysis technology to monitor and analyze the operation behaviors of users to promptly detect abnormal behaviors. S4. Data security guarantee: Through data life cycle management, formulate specific hierarchical protection requirements and operating procedures for different levels of data, formulate data security emergency plans and disposal processes, and conduct emergency drills and evaluations regularly to improve the efficiency and effectiveness of emergency response. S5. External cooperation and communication: Actively participate in the formulation of industry standards and specifications to promote the standardization and regularization of data security technologies.

Citation Information

Patent Citations

  • Method for controlling data integrity of industrial database

    CN102541940A

  • Numerical control system security situation awareness and analysis system, method, equipment and terminal

    CN115996146A

  • Data management method and system based on data resource security identification level

    CN119442320A

  • Data security management method and system based on cloud computing

    CN119475369A