Safe one-way data transmission system for industrial internet
By adopting a secure one-way data transmission system in the industrial Internet, using real-time acquisition programs and historical acquisition programs that are hot backup for each other, combined with data detection and hash value verification, the problems of incomplete data acquisition and discontinuous transmission are solved, and data reliability and security are achieved.
Patent Information
- Application Number
- CN202510478080.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-04-16
AI Technical Summary
In the industrial Internet, data collection is incomplete, transmission is discontinuous, and data is tampered with and security issues, affecting the reliability and integrity of the data.
A secure one-way data transmission system is adopted, including transmission processing module 1 and transmission processing module 2. It is connected through a forward isolation device, and data acquisition and transmission is carried out using the real-time acquisition program A and real-time acquisition program B, which are mutually hot-backed, and data acquisition or transmission is carried out through the link monitoring program and the history acquisition program in case of a failure, and data integrity is ensured by combining data detection and hash value verification.
It realizes the reliability of data acquisition and transmission, avoids interruptions caused by failures, improves data integrity and security, and ensures the reliability and integrity of data during transmission.
Smart Images

Figure CN120342684A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data secure transmission, and specifically relates to a secure unidirectional data transmission system for industrial Internet. Background Art
[0002] Currently, the data transmission in industrial Internet faces many challenges. In the data acquisition link, the data quality is uneven, and failures of data acquisition channels, devices, etc. occur frequently, resulting in incomplete and discontinuous data acquisition. During the data transmission process, the security issue is particularly prominent. The network attack means are becoming increasingly complex and diverse, and intrusion behaviors may lead to data being tampered with, stolen, or damaged, seriously affecting the reliability and security of data. For example, malicious attackers may utilize the loopholes in the transmission protocol to implant malicious codes and tamper with the data in transmission, causing the receiving end to obtain incorrect information, thus interfering with the production process and causing production accidents. Moreover, the data among various systems in the industrial Internet is closely related, and problems in one piece of data may trigger a chain reaction, destroying the integrity of the entire data system.
[0003] In summary, to meet the requirements of secure and reliable data transmission, the present invention provides a secure unidirectional data transmission system for industrial Internet. Summary of the Invention
[0004] The present invention aims to solve at least one of the technical problems existing in the prior art; for this purpose, the present invention provides a secure unidirectional data transmission system for industrial Internet, including a first transmission processing module and a second transmission processing module, which are connected by a forward isolation device; during the acquisition and transmission of the original data, data acquisition and transmission are carried out through real-time acquisition programs A and B that are hot standby for each other, which can avoid data acquisition or transmission interruption caused by the failure of the real-time acquisition program. Furthermore, in extreme cases, if real-time acquisition programs A and B fail simultaneously, the acquisition and transmission of the original data will be aborted. At this time, the link monitoring program identifies the start and end times of the failure, and then controls the historical acquisition program to supplement the acquisition or transmission of the data during the start and end times of the failure; the present invention carries out data acquisition and transmission through real-time acquisition programs A and B that are hot standby for each other, and with the assistance of the link monitoring program and the historical acquisition program, the reliability of the original data during the entire acquisition and transmission process can be ensured.
[0005] To achieve the above object, the first aspect of the present invention provides a secure unidirectional data transmission system for industrial Internet, including a first transmission processing module and a second transmission processing module, which are connected by a forward isolation device;
[0006] Transmission Processing Module 1: Used to collect the original data of the industrial Internet system; perform collection detection on the original data and filter to obtain Data Group 1; among them, the collection detection includes compliance detection and feature matching detection; and,
[0007] Transmit Data Group 1 and its verification sequence to Transmission Processing Module 2 through a forward isolation device; among them, the verification sequence is the hash value of different combinations of original data in Data Group 1;
[0008] Transmission Processing Module 2: Used to perform transmission detection on Data Group 1 and filter to obtain Data Group 2; perform integrity verification on Data Group 2 through the verification sequence, and transmit it to the data platform after passing the verification; among them, the transmission detection includes content detection and behavior detection.
[0009] Preferably, Transmission Processing Module 1 is connected to the industrial Internet system, and Transmission Processing Module 2 is connected to the data platform; the data platform is used to store data;
[0010] The forward isolation device is used to achieve one-way data transmission from Transmission Processing Module 1 to Transmission Processing Module 2.
[0011] Preferably, the acquisition and transmission of the original data are realized through the HA mechanism, including:
[0012] Real-time Acquisition Program A and Real-time Acquisition Program B: Used to perform real-time acquisition and transmission of data; among them, Real-time Acquisition Program A and Real-time Acquisition Program B are hot standby for each other;
[0013] Historical Acquisition Program: Used to start when the real-time acquisition and transmission are abnormal, and perform data supplement acquisition or data supplement transmission; among them, data supplement acquisition includes breakpoint continuous acquisition or historical supplement acquisition, and data supplement transmission includes breakpoint continuous transmission or historical supplement transmission;
[0014] Link Monitoring Program: Used to record the start and end times of the fault when the real-time acquisition and transmission are abnormal, and control the Historical Acquisition Program to perform data supplement acquisition based on the start and end times of the fault.
[0015] Preferably, a configuration distribution communication API is set during the acquisition and transmission of the original data; the configuration distribution communication API is used to transfer the start and end times of the supplement acquisition corresponding to the manually configured and distributed historical supplement acquisition instructions;
[0016] The Historical Acquisition Program completes data supplement acquisition or data supplement transmission according to the start and end times of the supplement acquisition.
[0017] Preferably, the acquisition and transmission method of the original data includes:
[0018] Perform real-time acquisition and transmission of data through Real-time Acquisition Program A; when Real-time Acquisition Program A fails, perform real-time acquisition and transmission of data through Real-time Acquisition Program B;
[0019] When both real-time acquisition program A and real-time acquisition program B fail, the start and end time of the failure are recorded through the link monitoring program;
[0020] When either the real-time acquisition program A or the real-time acquisition program B resumes operation, the historical acquisition program is started to collect data within the corresponding range of the fault start and end time.
[0021] Preferably, collecting and testing the original data includes:
[0022] Perform protocol format verification on the original data, remove the data packets that fail the verification from the original data, and obtain basic data group 1;
[0023] The basic data group one is detected and compared through a preset feature association library, and the basic data group one is associated and eliminated according to the comparison result to obtain data group one; wherein, the feature association library is provided with demand data features and virus data features, and the associated elimination is achieved based on the correlation between the data.
[0024] Preferably, the basic data set 1 is detected and compared by using a preset feature association library, including:
[0025] According to the demand data features in the feature association library, matching is performed from the basic data group 1 to obtain matching data; wherein the demand data features are used to match the demand data;
[0026] Data associated with virus data features are removed from the matching data to obtain data group 1; wherein the virus data features are used to remove data containing malicious codes.
[0027] Preferably, transmission detection is performed on data group one to screen and obtain data group two, including:
[0028] Perform content detection on the data in data group 1, and integrate and mark the qualified data into basic data group 2; wherein the content detection includes keyword detection and data format detection;
[0029] The behavioral characteristics of the data in the basic data group 2 are identified through a machine learning algorithm, and the data with abnormal behavioral characteristics are associated and eliminated to obtain the data group 2; wherein the behavioral characteristics include transmission frequency and data volume.
[0030] Preferably, obtaining the verification sequence includes:
[0031] Combining the original data in the data group 1 to obtain a plurality of data combinations;
[0032] Based on a number of data combinations, the original data in the data group one is removed from association to obtain a number of basic data groups three, and hash values of the basic data groups three are calculated;
[0033] Integrate several hash values and their corresponding data combinations into a verification sequence, and associate the verification sequence with Data Group 1.
[0034] Preferably, perform integrity verification on Data Group 2 through the verification sequence, including:
[0035] Extract the data deletion records of Data Group 2 screened from Data Group 1, and identify the data combinations corresponding to the data deletion records;
[0036] Match and associate the hash values from the verification sequence according to the data combinations, and mark them as Hash Value 1; calculate the hash value of Data Group 2, and mark it as Hash Value 2;
[0037] Compare Hash Value 1 and Hash Value 2, and judge whether the integrity verification of Data Group 2 is qualified according to the comparison result.
[0038] Compared with the prior art, the beneficial effects of the present invention are:
[0039] 1. The secure unidirectional data transmission system of the present invention includes Transmission Processing Module 1 and Transmission Processing Module 2, and Transmission Processing Module 1 and Transmission Processing Module 2 are connected through a forward isolation device; during the acquisition and transmission of the original data, data acquisition and transmission are performed through the mutually hot standby Real-time Acquisition Program A and Real-time Acquisition Program B, which can avoid data acquisition or transmission interruption caused by the failure of the real-time acquisition program. Furthermore, in extreme cases, if Real-time Acquisition Program A and Real-time Acquisition Program B fail simultaneously, the acquisition and transmission of the original data will be aborted. At this time, the Link Monitoring Program is used to identify the start and end times of the failure, and then control the Historical Acquisition Program to re-acquire or re-transmit the data during the start and end times of the failure; the present invention performs data acquisition and transmission through the mutually hot standby Real-time Acquisition Program A and Real-time Acquisition Program B, and with the assistance of the Link Monitoring Program and the Historical Acquisition Program, the reliability of the original data during the entire acquisition and transmission process can be ensured.
[0040] 2. On the basis of ensuring the reliable acquisition and transmission of the original data, the present invention also optimizes the process of the original data from production, transmission to storage. Mainly, acquisition detection and transmission detection are performed on the original data. Acquisition detection is used to evaluate the compliance of the original data and whether it carries known malicious codes. Acquisition detection improves the data quality and at the same time reduces the data transmission volume; transmission detection mainly detects the content and behavior of the original data; the original data that does not meet the requirements is associated and excluded to obtain the final Data Group 2. Transmission detection further identifies the abnormal data in the original data and improves the data reliability. Moreover, the overall comparison method of hash values is used to verify Data Group 2, which can determine whether there are unknown data packets inserted into Data Group 2, which can not only complete the data integrity verification but also improve the security of Data Group 2. Description of the Drawings
[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0042] Figure 1 It is a schematic diagram of the system principle of the secure unidirectional data transmission system in the first embodiment of the present invention;
[0043] Figure 2 It is a schematic diagram of the implementation principle of the HA mode in data acquisition and transmission in the first embodiment of the present invention;
[0044] Figure 3 It is a schematic diagram of the method steps for data transmission optimization in the second embodiment of the present invention;
[0045] Figure 4 It is a schematic diagram of the method steps for data integrity verification during data transmission optimization in the second embodiment of the present invention. Detailed implementation manners
[0046] The following will clearly and completely describe the technical solutions of the present invention in combination with the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0047] In the process of secure data transmission, it is not only necessary to ensure the data transmission quality, but also to improve the data quality. During the data transmission process, it is very likely that one or more of the data acquisition channels, data transmission channels, data acquisition devices, etc. fail, resulting in incomplete or discontinuous data content being collected. Of course, it is also possible that the data is tampered with due to intrusion behavior, thus affecting the reliability of the data.
[0048] In view of the current data transmission problems in the industrial Internet, the present invention provides a secure unidirectional data transmission system for the industrial Internet.
[0049] Embodiment 1:
[0050] Please refer to Figure 1 - Figure 2 , the first aspect embodiment of the present invention provides a secure unidirectional data transmission system for the industrial Internet, including a transmission processing module one and a transmission processing module two, and the transmission processing module one and the transmission processing module two are connected through a forward isolation device;
[0051] Transmission Processing Module 1: It is used to collect and obtain the original data; perform acquisition detection on the original data, and filter to obtain Data Group 1; and transmit Data Group 1 and its check sequence to Transmission Processing Module 2 through a forward isolation device;
[0052] Transmission Processing Module 2: It is used to perform transmission detection on Data Group 1, filter to obtain Data Group 2; perform integrity check on Data Group 2 through the check sequence, and transmit it to the data platform after passing the check.
[0053] The secure unidirectional data transmission system provided by the present invention is mainly applied to the field of industrial Internet. Of course, it can also be used in other fields that require ensuring data transmission security, such as the power system field. The core components of this system include Transmission Processing Module 1, Transmission Processing Module 2, and a forward isolation device.
[0054] Transmission Processing Module 1 is connected to the industrial Internet system that needs to perform data acquisition and transmission to collect relevant data generated by the system, such as the industrial Internet system and the power system. The forward isolation device is arranged between Transmission Processing Module 1 and Transmission Processing Module 2 and is used to control the unidirectional transmission of data from Transmission Processing Module 1 to Transmission Processing Module 2. Transmission Processing Module 2 is connected to the data platform, and the data platform can store or deeply process the data. It should be noted that the data acquisition and transmission in this embodiment include data acquisition (supplementary acquisition) or data transmission (supplementary transmission). For example, both data acquisition and supplementary acquisition are included between Transmission Processing Module 1 and the industrial Internet system.
[0055] Both Transmission Processing Module 1 and Transmission Processing Module 2 have data processing capabilities, and data processing algorithms adapted to data transmission and data security requirements can be built in according to needs. The forward isolation device is a unidirectional data transmission device for high-security areas to low-security areas. There are currently many existing products that meet the requirements, such as the NARI forward isolation device, the Tiandi Hexing forward isolation device, etc. Select according to actual needs.
[0056] In order to improve the reliability of data transmission, the secure unidirectional data transmission system of the present invention performs additional redundant configurations during layout, such as device redundancy, channel redundancy, process redundancy, and storage redundancy. Through these redundant configurations, the failures that occur during the data acquisition and transmission process can be avoided from affecting the reliability of data acquisition and transmission.
[0057] Collecting and transmitting the original data from the industrial Internet system is mainly achieved by using the HA high-availability operation mode, which mainly includes:
[0058] Real-time acquisition program (channel) A and real-time acquisition program (channel) B: They are mainly responsible for the real-time acquisition and transmission of data, and real-time acquisition program A and real-time acquisition program B are in hot standby with each other. If one fails, the other will be automatically started;
[0059] Historical acquisition program: It is used to start when there is an abnormality in real-time acquisition and transmission, and perform data supplementary acquisition or data retransmission; data supplementary acquisition includes breakpoint continuation acquisition or historical supplementary acquisition, so its target object is the industrial Internet system; data retransmission includes breakpoint continuation retransmission or historical retransmission, and its target object is the device during the data transmission process;
[0060] Link monitoring program: It is used to record the start and end time of the fault when there is an abnormality in real-time acquisition and transmission, and control the historical acquisition program to perform data supplementary acquisition based on the start and end time of the fault; the link monitoring program cooperates with the historical acquisition program to achieve data supplementary acquisition or data retransmission.
[0061] The link monitoring program can automatically record the start and end time of the fault corresponding to the abnormality in data acquisition or transmission, and start the historical acquisition program to supplement or retransmit the data corresponding to the start and end time of the fault (such as Figure 2 the historical retransmission time period in). Of course, data supplementary acquisition or data retransmission can also be achieved through manual configuration. Specifically, a configuration distribution communication API can be set. After manually configuring and distributing the historical supplementary acquisition (retransmission) instruction, the configuration distribution communication API can transfer the supplementary acquisition start and end time in the instruction to the historical acquisition program, and the historical acquisition program can perform data supplementary acquisition or data retransmission according to the supplementary acquisition start and end time.
[0062] Next, the acquisition and transmission process of the original data in the present invention will be described in detail:
[0063] The industrial Internet system (which can also be applied to systems such as power systems with similar requirements for data transmission) generates original data and transmits the original data to the first transmission processing module. After the first transmission processing module performs acquisition detection on the original data, it obtains data set one, transmits data set one to the forward isolation device, and then transmits it to the second transmission processing module. After the second transmission processing module performs transmission detection, it obtains data set two and transmits data set two to the data platform.
[0064] In the above-mentioned original data transmission process, the real-time acquisition program A can be used to complete the acquisition and transmission. Once the acquisition program A fails, the real-time acquisition program B that is hot standby with it will take over to complete the acquisition and transmission of the original data. The real-time acquisition program A and the real-time acquisition program B can be acquisition or transmission channels.
[0065] When both the real-time acquisition program A and the real-time acquisition program B fail, the acquisition or transmission of the original data cannot be completed at this time. The link monitoring program can record the start and end time of the fault, and this start and end time of the fault is the duration of the simultaneous failure of the real-time acquisition program A and the real-time acquisition program B.
[0066] After determining the start and end times of a fault, the original data corresponding to the start and end times of the fault can be collected by using the historical acquisition program (channel), without affecting the acquisition and transmission of the original data by the real-time acquisition program A.
[0067] In addition to being controlled by the link monitoring program, the historical acquisition program also responds to the configuration download communication API. When it is necessary to collect data for a certain period, the historical supplementary acquisition instruction can also be manually configured and downloaded. The configuration download communication API transfers the time range corresponding to the historical supplementary acquisition instruction to the historical acquisition program, and the historical acquisition program starts and collects the original data within the corresponding time range.
[0068] It should be noted that Transmission Processing Module 1 and Transmission Processing Module 2 can be integrated into a specific product, and this product only needs to include the functions defined above. Transmission Processing Module 1 can collect the original data produced in the industrial Internet system in real time through iec104 (IEC60870-5-104 telecontrol communication protocol). For historical supplementary acquisition, it can be the supplementary acquisition of stopwatch data, and for historical continuous acquisition, it can be the acquisition of historical table data. Of course, the industrial Internet system can also perform storage redundancy settings, store the data it generates first, for subsequent supplementary acquisition or continuous acquisition.
[0069] The transmission types of data between Transmission Processing Module 1 and the forward isolation device, Transmission Processing Module 2 and the data platform include real-time forwarding, endpoint continuous transmission, and historical continuous transmission. The transmission types between the forward isolation device and Transmission Processing Module 2 include real-time acquisition, breakpoint continuous transmission, and historical continuous transmission.
[0070] In some preferred embodiments, during the process of the original data starting from the industrial Internet system, passing through Transmission Processing Module 1, the forward isolation device, Transmission Processing Module 2, and finally reaching the data platform, the real-time acquisition program A and real-time acquisition program B, historical acquisition program, link monitoring program, and configuration download communication API that are mutually hot standby are configured throughout the process, that is, reliable transmission of the original data can be achieved throughout the entire transmission process.
[0071] In some other preferred embodiments, according to the reliability requirements of data acquisition or transmission, the real-time acquisition program A and real-time acquisition program B, historical acquisition program, link monitoring program, and configuration download communication API that are mutually hot standby can be configured at a certain stage in the original data transmission process. Other stages do not need to be configured.
[0072] In the process of collecting and transmitting the original data in this embodiment, data collection and transmission are carried out through the real-time collection program A and the real-time collection program B that are hot standby for each other, which can avoid data collection or transmission interruption caused by the failure of the real-time collection program. Furthermore, in extreme cases, if the real-time collection program A and the real-time collection program B fail simultaneously, the collection and transmission of the original data will be aborted. At this time, the link monitoring program identifies the start and end times of the failure, and then controls the historical collection program to supplement the collection or retransmission of the data within the start and end times of the failure. It can be seen that through the data collection and transmission by the real-time collection program A and the real-time collection program B that are hot standby for each other, and with the assistance of the link monitoring program and the historical collection program, the reliability of the original data in the entire collection and transmission process can be guaranteed.
[0073] Embodiment 2: On the basis of the configuration in Embodiment 1, this embodiment optimizes the collection and transmission of the original data through the built-in data processing algorithm to improve the collection and transmission efficiency and the data transmission security. Please refer to Figure 3 and Figure 4 。
[0074] After using the technical solution in Embodiment 1 to transmit the original data from the industrial Internet system to the transmission processing module 1, the original data is collected and detected through the algorithm built in the transmission module 1, specifically including:
[0075] Perform protocol format verification on the original data, remove the data packets with unqualified verification from the original data to obtain the basic data group 1; detect and compare the basic data group 1 through the preset feature association library, and perform association removal on the basic data group 1 according to the comparison result to obtain the data group 1.
[0076] Taking the industrial Internet system as an example, the data it produces follows specific industrial protocols, such as Modbus, OPC, etc. In the transmission processing module 1, the data format of the original data is verified according to the protocol specifications, and the original data with unqualified data format verification is removed, and the remaining original data is integrated into the basic data group 1.
[0077] All the data formats of the original data in the basic data group 1 meet the protocol requirements. At this time, in order to reduce the data transmission volume and improve the data transmission efficiency, the original data in the basic data group 1 is preliminarily detected. The main content of the preliminary detection is to judge whether it is the required data and whether it carries viruses. Specifically, the original data is screened through the preset required data features, and the original data that meets the required data features is retained. For example, if the data of a certain device is required, the device is set as the required data feature. Of course, it can also be set in the reverse way, such as not requiring the data of a certain device. Then, a feature library of known malicious codes and viruses is established as the virus data feature, and the remaining original data is compared with the virus data feature by using the signature matching technology, and the original data containing virus data and malicious codes is removed.
[0078] It should be noted that some of the raw data in the industrial Internet system are interrelated. Taking the power system as an example, the operation data of power generation equipment, the power transmission data of the power grid, and the power consumption data of users are interrelated. If the real-time power data of a certain power generation equipment is wrongly excluded, it may lead to incorrect calculation of the power grid load and affect the integrity of the data of the entire power system. When there is a parent-child relationship or a reference relationship between data, excluding the parent data may cause the child data to lose its meaning and the reference data to become invalid, destroying the logical connection between the data and thus affecting the integrity.
[0079] Therefore, the method adopted in this embodiment for data exclusion is associated exclusion, that is, if a certain raw data needs to be excluded, the raw data associated with it will also be excluded, so as to improve the effectiveness and integrity of the data, and can also reduce the data volume and improve the transmission efficiency. The "association" between the raw data in this embodiment can be defined from the exclusion result, that is, if a certain raw data is excluded, the raw data "associated" with it cannot be utilized or loses its value. Of course, these raw data only do not enter the next link, and necessary backups and storage are still carried out on them for subsequent use.
[0080] The transmission processing module 1 excludes the data in the raw data that does not conform to the protocol specification, carries malicious code or viruses, and obtains the data group 1. This data group 1 will be transmitted to the transmission processing module 2 through the forward isolation device, and the transmission processing module 2 will perform content detection on it to obtain the data group 2, which specifically includes:
[0081] Perform content detection on the data in the data group 1, and integrate and mark the qualified data as the basic data group 2; identify the behavior characteristics of the data in the basic data group 2 through machine learning algorithms, and exclude the data with abnormal behavior characteristics associated with it to obtain the data group 2.
[0082] Content detection includes keyword detection and data format detection. Specifically, according to the set security policy, keyword matching is performed on the text content of the raw data in the data group 1. If the data contains sensitive information (such as key configuration information of the business system, user privacy data, etc.) or blacklist keywords (such as attack instructions, sensitive business operation keywords, etc.), the data will be intercepted to prevent the leakage of sensitive information or the execution of malicious operation instructions. Data format detection mainly judges whether the raw data meets the preset format, and if it does not meet, format conversion processing can be performed. The purpose of content detection is to further screen the data content to ensure that the content of the raw data can meet the requirements.
[0083] The detection of behavioral characteristics is to prevent the system from being invaded and attacked by using the transmission of raw data. The specific implementation logic is as follows: collect the behavioral characteristics of normal data transmission of various types of raw data, such as data transmission frequency, connection duration, data volume, etc. Build a normal behavior model through machine learning algorithms and other means. For example, use clustering algorithms to cluster normal behavior data into different categories, determine the boundaries and characteristics of various behaviors. When the real-time monitored data transmission behavior deviates from the normal model, there may be abnormal behavior, give early warnings for abnormal behavior in a timely manner, and process the corresponding raw data in a timely manner.
[0084] In some other preferred embodiments, the algorithm for performing transmission detection on Data Group 1 and screening to obtain Data Group 2 can also be integrated into the forward isolation device. Once the data is abnormal, the forward isolation device can intercept the abnormal data.
[0085] In this embodiment, the acquisition and detection responsible by Transmission Processing Module 1 can ensure that all the raw data in Data Group 1 conform to the protocol specifications and do not carry known malicious codes and viruses. This can not only improve data reliability, but also reduce the data volume by detecting and eliminating unavailable data; then, through the transmission detection responsible by Transmission Processing Module 2, detect the content and behavior of the raw data in Data Group 1, further improve the availability of the data, and prevent the entire system from being invaded.
[0086] Since the raw data may be invaded and tampered with during the acquisition and transmission processes, when Transmission Processing Module 2 transmits Data Group 2 to the data platform for storage, it is necessary to verify the data integrity of Data Group 2. In this embodiment, hash values are used for verification, and the verification method is as follows:
[0087] Combine the raw data in Data Group 1 to obtain several data combinations;
[0088] Based on several data combinations, perform associated elimination on the raw data in Data Group 1 to obtain several basic Data Group 3s, calculate the hash values of several basic Data Group 3s; after associating several hash values with the corresponding data combinations, integrate them into a verification sequence, and associate the verification sequence with Data Group 1.
[0089] Extract the data elimination records of the data screened from Data Group 1 to obtain Data Group 2, identify the data combinations corresponding to the data elimination records; match the associated hash values from the verification sequence according to the data combinations, and mark them as Hash Value 1; calculate the hash value of Data Group 2, and mark it as Hash Value 2; compare Hash Value 1 and Hash Value 2, and judge whether the integrity verification of Data Group 2 is qualified according to the comparison result.
[0090] Using hash values for data integrity verification is a common method in existing solutions. Its general process is to calculate the hash value of a data packet at the sending end, and then recalculate the hash value at the receiving end and determine data integrity by comparison. This method is suitable for verifying the integrity of a single data packet. When there are multiple data packets, they need to be verified one by one, and there may be malicious and unrecognizable data packets implanted, making it difficult to achieve data integrity verification.
[0091] Moreover, considering that multiple correlation eliminations are performed during the acquisition and transmission of the original data in the present invention, what is eliminated is not a single original data, and the original data associated with it will also be eliminated. This will result in the situation that when verifying according to data packets, the original data corresponding to some hash values has been deleted, and accurate integrity verification cannot be performed.
[0092] When performing integrity verification in this embodiment, it is not carried out for the data packets of individual original data, but is implemented based on the entire data group. Specifically, it is implemented based on data group one.
[0093] The data included in data group one has undergone acquisition detection, and the corresponding data is the required data. Generally, the hash value of data group one can be directly calculated, and then after the transmission processing module two receives data group one, calculate its hash value and compare it to complete the integrity verification.
[0094] However, before data group one is transmitted to the data platform, transmission detection needs to be performed. This transmission detection may detect original data that does not meet the requirements and eliminate the original data associated with it from data group one. Therefore, after obtaining data group one, the original data of data group one is combined to obtain several data combinations, and each data combination includes at least one original data. It should be noted that when constructing data combinations, their "association" is not considered.
[0095] Taking these several data combinations as target combinations, the original data in the target combinations is eliminated from data group one by association, and the remaining original data is integrated into the basic data group three. Calculate the hash value of this basic data group three and associate this hash value with the target combination. In this way, several data combinations correspond to several hash values, and the several data combinations and their associated hash values are integrated into a verification sequence. The verification sequence corresponds to the hash value of the whole of the remaining original data when different data combinations are eliminated. It should be noted that "integration" in the present invention generally refers to incorporating multiple data into the same data group.
[0096] The verification sequence is transmitted (encrypted) along with the transmission of Data Group 1. After Transmission Processing Module 2 receives Data Group 2 and performs transmission detection and associated elimination, Data Group 2 is obtained. The original data in this Data Group 2 can be understood as conforming to the protocol specifications, content requirements, data requirements, and having normal behavioral characteristics. However, during the process from Data Group 1 to Data Group 2, since the acquisition detection and transmission detection processes require a certain amount of time, it is still possible for unknown viruses or malicious data packets that cannot be identified using the existing database to be implanted during this period.
[0097] Therefore, before Data Group 2 is transmitted to the data platform for storage, the verification sequence is used to perform integrity verification on Data Group 2. Passing this integrity verification means that all the original data in Data Group 2 has been collected through the industrial Internet system, there is no implanted intrusion data, and each original data meets the preset requirements. The integrity verification is specifically as follows:
[0098] Identify and extract the associated elimination records of the original data during the process of screening Data Group 2 from Data Group 1, that is, which original data has been associated and eliminated. Integrate the original data in the associated elimination records into a data combination, and match the hash value corresponding to this data combination in the verification sequence.
[0099] Then calculate the hash value of Data Group 2, and compare this hash value with the hash value obtained by matching the data combination. If the two are compared and are consistent, the integrity verification of Data Group 2 passes; otherwise, the integrity verification fails. If it fails, consider whether there is a malicious data packet implanted. By comparing one by one, the implanted malicious data packet can be identified, and targeted handling measures can be taken.
[0100] Based on the system structure of Embodiment 1, this embodiment optimizes the process of the original data from production, transmission to storage. It mainly performs acquisition detection and transmission detection on the original data. The acquisition detection is used to evaluate the compliance of the original data and whether it carries known malicious code, and the transmission detection mainly detects the content and behavior of the original data; the original data that does not meet the requirements during the detection is associated and eliminated to obtain the final Data Group 2. Since the elimination method adopted in the present invention is associated elimination, if the hash value comparison is performed on a single original data, there may be a situation where there is a hash value but no corresponding original data. In this case, the specific reason for the non-existence of the original data cannot be determined. Therefore, the overall hash value verification of Data Group 2 in the present invention, on the one hand, avoids the above situation, and on the other hand, can also determine whether there are unknown data packets inserted into Data Group 2, which can not only complete the data integrity verification but also improve the security of Data Group 2.
[0101] In some other embodiments, the integrity verification process can be carried out through the data platform, that is, after the data platform receives the second data group, it uses the verification sequence of the first data group to compare the hash values of the second data group, so as to determine whether the second data group is complete as a whole.
[0102] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A secure unidirectional data transmission system for the industrial Internet, characterized in that, It includes a transmission processing module 1 and a transmission processing module 2, wherein the transmission processing module 1 and the transmission processing module 2 are connected via a forward isolation device; Transmission processing module 1: used to collect raw data of the industrial Internet system; collect and detect the raw data, and screen to obtain data group 1; wherein the collection and detection includes compliance detection and feature matching detection; and, The data group 1 and its check sequence are transmitted to the transmission processing module 2 through the forward isolation device; wherein the check sequence is the hash value of different original data combinations in the data group 1; Transmission processing module two: used to perform transmission detection on the data group one, and screen out the data group two; perform integrity verification on the data group two through the verification sequence, and transmit it to the data platform after passing the verification; wherein, the transmission detection includes content detection and behavior detection.
2. The secure unidirectional data transmission system for industrial Internet according to claim 1, characterized in that The transmission processing module 1 is connected to the industrial Internet system, and the transmission processing module 2 is connected to the data platform; the data platform is used to store data; The forward isolation device is used to realize unidirectional data transmission from the transmission processing module 1 to the transmission processing module 2.
3. The secure unidirectional data transmission system for industrial Internet according to claim 2, wherein The collection and transmission of the original data is realized through the HA mechanism, including: Real-time acquisition program A and real-time acquisition program B: used for real-time data acquisition and transmission; wherein, real-time acquisition program A and real-time acquisition program B are hot standby for each other; Historical collection program: used to start when real-time collection and transmission are abnormal, and to perform data supplementary collection or data supplementary transmission; data supplementary collection includes breakpoint continuous collection or historical supplementary collection, and data supplementary transmission includes breakpoint continuous transmission or historical supplementary transmission; Link monitoring program: used to record the start and end time of the fault when collecting transmission anomalies in real time, and control the historical collection program to perform data supplementary collection based on the start and end time of the fault.
4. The secure unidirectional data transmission system for industrial Internet according to claim 3, characterized in that, A configuration and sending communication API is provided in the process of collecting and transmitting the raw data; the configuration and sending communication API is used to transmit the supplementary collection start and end time corresponding to the historical supplementary collection instruction issued by manual configuration; The historical collection program completes data supplementary collection or data supplementary transmission according to the supplementary collection start and end time.
5. The secure unidirectional data transmission system for industrial Internet according to claim 4, wherein The original data collection and transmission method comprises: The real-time data collection and transmission is performed through the real-time data collection program A; when the real-time data collection program A fails, the real-time data collection and transmission is performed through the real-time data collection program B; When both the real-time acquisition program A and the real-time acquisition program B fail, the start and end time of the failure are recorded by the link monitoring program; When either the real-time acquisition program A or the real-time acquisition program B resumes operation, the historical acquisition program is started to supplement the data within the range corresponding to the start and end time of the fault.
6. The security one-way data transmission system for industrial Internet according to claim 1 or 5, characterized in that The raw data is collected and tested, including: Performing protocol format verification on the original data, removing data packets that fail the verification from the original data, and obtaining a basic data group 1; The basic data group one is detected and compared through a preset feature association library, and the basic data group one is associated and eliminated according to the comparison result to obtain data group one; wherein, the feature association library is provided with demand data features and virus data features, and the associated elimination is achieved based on the correlation between the data.
7. The secure unidirectional data transmission system for industrial Internet according to claim 6, wherein Detect and compare the first group of basic data through a preset feature association library, including: Match from the first group of basic data according to the requirement data features in the feature association library to obtain matching data; among them, the requirement data features are used to match requirement data; Eliminate the data associated and matched with the virus data features from the matching data to obtain the first data group; among them, the virus data features are used to eliminate the data containing malicious code.
8. The secure unidirectional data transmission system for industrial Internet according to claim 1 or 5, characterized in that Conduct transmission detection on the first data group and screen to obtain the second data group, including: Conduct content detection on the data in the first data group, and integrate and mark the qualified data as the second group of basic data; among them, the content detection includes keyword detection and data format detection; Identify the behavior features of the data in the second group of basic data through a machine learning algorithm, and eliminate the data with abnormal behavior features associated, to obtain the second data group; among them, the behavior features include transmission frequency and data volume.
9. The secure unidirectional data transmission system for industrial Internet according to claim 8, wherein The acquisition of the verification sequence includes: Combine the original data in the first data group to obtain several data combinations; Based on several data combinations, eliminate the original data in the first data group associated, to obtain several third groups of basic data, and calculate the hash values of several third groups of basic data; Integrate the several hash values associated with the corresponding data combinations into a verification sequence, and associate the verification sequence with the first data group.
10. The secure unidirectional data transmission system for industrial Internet according to claim 9, characterized in that, Conduct integrity verification on the second data group through the verification sequence, including: Extract the data elimination records of the second data group screened from the first data group, and identify the data combinations corresponding to the data elimination records; Match and associate the hash values from the verification sequence according to the data combinations, and mark them as the first hash value; calculate the hash value of the second data group, and mark it as the second hash value; Compare the first hash value and the second hash value, and judge whether the integrity verification of the second data group is qualified according to the comparison result.
Citation Information
Patent Citations
Information sharing method and device based on multi-level supply chain
CN117113419A
Management method based on intelligent operation and maintenance of informatization system
CN119356243A
Anonymization system and anonymization method
JP2023060684A
Remote Fault Recovery System on Wireless Network
KR102501380B1
Data processing system, and data uploading method and data processing method thereof
WO2024087206A1