Industrial control mainboard operation data security protection system

Through a comprehensive security protection system, including data collection, encrypted transmission, permission control and abnormal detection, the data security issues of the industrial control motherboard are solved, data security and management efficiency are improved, and the stability of industrial production is ensured.

CN120372643APending Publication Date: 2025-07-25SHENZHEN YDSTECH IND ELECTRONICS CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510440376.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing industrial control motherboard has a single data security protection measure and a lack of a systematic security protection system, which makes data susceptible to overprivileged access and the inability to detect potential threats in a timely manner. The recovery of data is complex when it is lost or damaged, affecting the continuity of industrial production.

Method used

The data acquisition module, encryption transmission module, storage management module, access control module, security monitoring module and exception detection model module are adopted, combined with the AES encryption algorithm, hash table structure, role-based access control model and autoencoder exception detection model, to achieve comprehensive data acquisition, encrypted transmission, permission verification and exception detection.

Benefits of technology

It improves the security and management efficiency of the operating data of the industrial control motherboard, promptly detects potential threats, reduces the risk of data leakage, simplifies the data recovery process, and ensures the stable operation of industrial production.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372643A_ABST
    Figure CN120372643A_ABST
Patent Text Reader

Abstract

The invention, which relates to the technical field of industrial automation control and information security, discloses an industrial control mainboard operation data security protection system comprising a data acquisition module, an encryption transmission module, a storage management module, an access control module, a security monitoring module and an anomaly detection model module. The data acquisition module is used for acquiring various data in the operation process of the industrial control mainboard; and the encryption transmission module is used for encrypting the collected data and transmitting the encrypted data to a storage device. The AES encryption algorithm is adopted, the safety of the data transmission process is guaranteed, efficient data storage management is achieved by means of a hash table, and strict access authority control is conducted by applying a role-based access control model. Meanwhile, based on the anomaly detection model of the auto-encoder, the anomaly mode in the data can be accurately identified, and potential security threats can be found in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of industrial automation control and information security, and specifically relates to a security protection system for the operation data of an industrial control mainboard. Background Art

[0002] In the field of industrial automation, as a core device, the industrial control mainboard carries various types of key operation data. These data are not only related to the stable operation of industrial production, but also involve the business secrets and security of enterprises. With the rapid development of the industrial Internet, the network attack means against industrial control systems have become increasingly complex, and security problems such as data leakage and tampering occur frequently.

[0003] Currently, most security protection measures for the operation data of industrial control mainboards are relatively single, lacking a systematic security protection system. For example, some systems only simply encrypt the data, but ignore the refined management of access rights, resulting in the data being easily accessed by unauthorized users; some systems fail to monitor the security status in real time and cannot detect potential security threats in a timely manner. These problems make the operation data of industrial control mainboards face greater security risks, and when the data is lost or damaged, the recovery process is complex and time-consuming, seriously affecting the continuity of industrial production and bringing economic losses to enterprises. Summary of the Invention

[0004] To solve the above technical problems, a security protection system for the operation data of an industrial control mainboard is provided, and the present technical solution solves the above problems.

[0005] To achieve the above objectives, the technical solution adopted by the present invention is as follows:

[0006] A security protection system for the operation data of an industrial control mainboard, the system includes a data acquisition module, an encrypted transmission module, a storage management module, an access control module, a security monitoring module, and an anomaly detection model module, wherein:

[0007] The data acquisition module is used to acquire various types of data during the operation of the industrial control mainboard;

[0008] The encrypted transmission module is used to encrypt the acquired data and transmit the encrypted data to the storage device;

[0009] The storage management module is used to manage the data in the storage device, including data storage, retrieval, and update;

[0010] The access control module is used to verify the permissions of requests to access the operation data of the industrial control mainboard according to the preset access policies;

[0011] The security monitoring module is used to monitor the security status of the system in real time and identify potential security threats;

[0012] Anomaly detection model module, which constructs an anomaly detection model based on an autoencoder to identify anomaly patterns in the operation data of industrial control mainboards.

[0013] Preferably, when the data acquisition module executes the acquisition of various data during the operation of the industrial control mainboard, it includes:

[0014] Collecting the hardware status data of the industrial control mainboard through sensors, where the hardware status data includes temperature, voltage, and fan speed;

[0015] Extracting the business data generated by the application programs running in the industrial control mainboard.

[0016] Preferably, when the encryption transmission module executes the encryption of the collected data, it uses the AES encryption algorithm, and the encryption process is as follows:

[0017] C = E K (P)

[0018] Where C is the ciphertext, P is the plaintext, K is the encryption key, and E is the AES encryption operation.

[0019] Preferably, when the storage management module executes the management of the data in the storage device, it uses a hash table structure for data storage, and the hash function is:

[0020] h(k) = k mod m

[0021] Where h(k) is the hash value of the key value k, and m is the size of the hash table.

[0022] Preferably, when the access control module executes the permission verification of the request to access the operation data of the industrial control mainboard according to the preset access policy, it uses a role-based access control model, and the verification process is as follows:

[0023] Determine the role of the requester;

[0024] According to the preset role permission table, judge whether this role has the permission to access the requested data.

[0025] Preferably, the preset role permission table includes role information, data resource information, and corresponding permission operation information;

[0026] The roles at least include system administrator, ordinary operator, and data maintainer;

[0027] For the system administrator role, it has the permissions of reading, writing, modifying, and deleting all the operation data of the industrial control mainboard;

[0028] The ordinary operator role only has the permission to read part of the business data;

[0029] The data maintenance staff role has the operation permissions to read specific hardware status data and to back up and restore the stored data.

[0030] Preferably, the anomaly detection model module constructs an autoencoder-based anomaly detection model including an encoder and a decoder, and the model structure is as follows:

[0031] The encoder maps the input industrial control motherboard operation data to a low-dimensional space, and its transformation process is:

[0032] H = f e (X; θ e )

[0033] where X is the input data, H is the low-dimensional feature vector, f e is the encoder function, and θ e are the encoder parameters;

[0034] The decoder reconstructs the low-dimensional feature vector into data in the original data space, and its transformation process is:

[0035]

[0036] where, is the reconstructed data, f d is the decoder function, and θ d are the decoder parameters.

[0037] Preferably, the anomaly detection model module uses the reconstruction error to judge whether the data is abnormal, and the reconstruction error calculation method is:

[0038]

[0039] where when the reconstruction error E exceeds the preset threshold, the data is determined to be abnormal data, and the preset value is determined comprehensively based on the historical fluctuation range of the industrial control motherboard hardware status data, the normal value range of the business data, and the data change characteristics during past security attacks.

[0040] Preferably, the system further includes a data backup module, and the data backup module is used to regularly back up the data in the storage device, and the backup strategy is as follows:

[0041] Set the backup period T;

[0042] Within each backup period T, perform a full backup of the data in the storage device.

[0043] Preferably, when the data backup module performs data backup, it adopts an incremental backup method, and the incremental backup process is as follows:

[0044] Compare the difference between the current data and the previous backup data;

[0045] Only back up the data that has changed.

[0046] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0047] The industrial control motherboard operation data security protection system proposed by the present invention comprehensively collects operation data through sensors and application program data extraction; adopts the AES encryption algorithm to ensure the security of the data transmission process, and uses a hash table to achieve efficient data storage management, and applies a role-based access control model to perform strict access permission control. At the same time, the anomaly detection model based on the autoencoder can accurately identify the abnormal patterns in the data and timely discover potential security threats. In terms of data backup, the system supports regular full backups and incremental backups, greatly improving the efficiency of data recovery. In summary, the industrial control motherboard operation data security protection system and method proposed by the present invention can significantly improve the security and management efficiency of the industrial control motherboard operation data, effectively reduce the data security risk, and ensure the stable operation of industrial production. Description of the Drawings

[0048] Figure 1 It is the system architecture flow chart of the present invention. Detailed Embodiments

[0049] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variations.

[0050] Referring to Figure 1 As shown, an industrial control motherboard operation data security protection system includes a data acquisition module, an encryption transmission module, a storage management module, an access control module, a security monitoring module, and an anomaly detection model module, wherein:

[0051] The data acquisition module is used to collect various types of data during the operation of the industrial control motherboard;

[0052] The encryption transmission module is used to encrypt the collected data and transmit the encrypted data to the storage device;

[0053] The storage management module is used to manage the data in the storage device, including data storage, retrieval, and update;

[0054] The access control module is used to verify the permissions of requests to access the industrial control motherboard operation data according to the preset access policies;

[0055] The security monitoring module is used to monitor the security status of the system in real time and identify potential security threats;

[0056] Anomaly detection model module, which constructs an anomaly detection model based on an autoencoder to identify anomaly patterns in the operation data of industrial control mainboards.

[0057] Specifically, this system is a comprehensive security protection system. Each module collaborates with each other to ensure the security of the operation data of industrial control mainboards. First, the data acquisition module is the data source of the entire system, comprehensively collecting various types of data during the operation of industrial control mainboards. These data are the basis for subsequent security protection operations. The encrypted transmission module encrypts the collected data to prevent the data from being stolen or tampered with during transmission, and securely transmits the encrypted data to the storage device. The storage management module is responsible for the orderly management of the data in the storage device, including operations such as storing new data, retrieving required data, and updating existing data, ensuring the standardization and effectiveness of data storage. The access control module, based on the preset access policy, strictly verifies the permissions of requests attempting to access the operation data of industrial control mainboards. Only requests with corresponding permissions can access the data, thus preventing illegal access. The security monitoring module real-time monitors the security status of the system. By analyzing various data and system behaviors, it can promptly detect potential security threats so as to take corresponding measures. The anomaly detection model module constructs an anomaly detection model based on an autoencoder, which can learn the patterns of normal data and identify the anomaly patterns in the data by comparing the differences between the input data and the reconstructed data, further enhancing the security of the system. This way of multi-module collaborative work forms a complete security protection chain from data acquisition, transmission, storage, access to security monitoring and anomaly detection, comprehensively ensuring the security and integrity of the operation data of industrial control mainboards, effectively reducing security risks such as data leakage and tampering, and improving the stability and reliability of industrial control systems.

[0058] When the data acquisition module executes the acquisition of various types of data during the operation of industrial control mainboards, it includes:

[0059] Collecting the hardware status data of the industrial control mainboard through sensors, and the hardware status data includes temperature, voltage, and fan speed;

[0060] Extracting the business data generated by the application programs running in the industrial control mainboard.

[0061] Specifically, the data acquisition module uses two different methods to collect data. On the one hand, various sensors installed on the industrial control motherboard are used to collect hardware status data in real time, such as temperature, voltage, and fan speed. These hardware status data can reflect the actual operating conditions of the industrial control motherboard. For example, too high temperature may mean problems with motherboard heat dissipation, and unstable voltage may affect the normal operation of the motherboard. On the other hand, business data generated by the application programs running in the industrial control motherboard is extracted. These business data are related to the specific business of the industrial control system, such as production process data, equipment control instructions, etc. By comprehensively collecting hardware status data and business data, it provides a rich and accurate data basis for subsequent security protection operations. Hardware status data can help detect potential hardware faults in a timely manner, take maintenance measures in advance, and avoid data loss or system failures caused by hardware problems. The collection of business data helps monitor and analyze the business processes of the industrial control system to ensure the normal operation of the business.

[0062] When the encryption and transmission module encrypts the collected data, it uses the AES encryption algorithm. The encryption process is as follows:

[0063] C = E K (P)

[0064] Where C is the ciphertext, P is the plaintext, K is the encryption key, and E is the AES encryption operation.

[0065] Specifically, the encryption and transmission module plays a key security guarantee role in the data transmission process. By using the AES encryption algorithm to encrypt the collected data, the AES algorithm is a symmetric encryption algorithm with the characteristics of fast encryption speed and high security. During the encryption process, the same key is used to encrypt and decrypt the data. The encryption and transmission module encrypts the collected data according to the rules of the AES algorithm, converts the plaintext data into ciphertext data, and then transmits the ciphertext data to the storage device through the network or other transmission media. Therefore, by using the AES encryption algorithm, it can effectively prevent data from being stolen or tampered with during the transmission process. Even if the data is intercepted during the transmission process, the attacker cannot obtain the sensitive information without the correct key. This encryption method greatly improves the security of data transmission and protects the confidentiality of the operating data of the industrial control motherboard.

[0066] When the storage management module manages the data in the storage device, it uses a hash table structure for data storage. The hash function is:

[0067] h(k) = k mod m

[0068] Where h(k) is the hash value of the key value k, and m is the size of the hash table.

[0069] Specifically, a hash table is an efficient data storage structure that maps the key values of data to specific positions in the hash table through a hash function. When storing data, the storage management module calculates the position of the data in the hash table based on the key value of the data and stores the data at that position. When retrieving data, the position is also calculated based on the key value, and the data is directly obtained from that position. Therefore, using a hash table structure for data storage can significantly improve the storage and retrieval efficiency of data. Compared with traditional linear storage methods, a hash table can complete data insertion, search, and deletion operations in constant time, greatly shortening the data processing time. This can improve the response speed and processing ability of the industrial control system that needs to frequently store and retrieve data.

[0070] When the access control module executes the permission verification for the request to access the operation data of the industrial control main board according to the preset access policy, it adopts a role-based access control model, and the verification process is as follows:

[0071] Determine the role of the requester;

[0072] According to the preset role permission table, determine whether this role has the permission to access the requested data.

[0073] Specifically, the access control module adopts a role-based access control model for permission verification. When a request to access the operation data of the industrial control main board arrives, the access control module first determines the role of the requester, such as a system administrator, an ordinary operator, etc. Then, according to the preset role permission table, it checks whether this role has the permission to access the requested data. The role permission table clearly stipulates the access permissions of different roles to different data resources. Only when the role of the requester has the corresponding permission is it allowed to access the data. By dividing users into different roles and assigning specific permissions to each role, the access scope of different users to data can be effectively controlled, avoiding security risks caused by chaotic permission management. This method improves the security of the system and the confidentiality of data, ensuring that only authorized users can access sensitive data.

[0074] The preset role permission table includes role information, data resource information, and corresponding permission operation information;

[0075] The roles at least include system administrator, ordinary operator, and data maintainer;

[0076] For the system administrator role, it has the permissions to read, write, modify, and delete all the operation data of the industrial control main board;

[0077] The ordinary operator role only has the permission to read some business data;

[0078] The data maintenance staff role has the operation permissions to read specific hardware status data and to back up and restore stored data.

[0079] Specifically, the preset role permission table defines in detail the access permissions of different roles to data resources. The role information clarifies the types of roles existing in the system, such as system administrators, ordinary operators, and data maintenance staff. The data resource information lists different categories of industrial control motherboard operation data, including hardware status data and business data, etc. The corresponding permission operation information stipulates the operations that each role can perform on different data resources. System administrators have the highest permissions and can perform read, write, modify, and delete operations on all industrial control motherboard operation data because they need to comprehensively manage and maintain the entire system. Ordinary operators can only read part of the business data to ensure that they can complete their work tasks without affecting the core data of the system. Data maintenance staff are mainly responsible for reading specific hardware status data and performing backup and recovery operations on stored data to ensure data security and recoverability. This detailed role permission division makes the permission management of the system clearer and more standardized. Users with different roles can only operate within their permission scopes, effectively preventing unauthorized access and incorrect operations, further improving the security and stability of the system. At the same time, reasonable permission allocation can also improve work efficiency. Users with different roles can focus on their own job responsibilities, avoiding work inconveniences caused by excessive or insufficient permissions.

[0080] The anomaly detection model based on the autoencoder constructed by the anomaly detection model module includes an encoder and a decoder, and the model structure is as follows:

[0081] The encoder maps the input industrial control motherboard operation data to a low-dimensional space, and its transformation process is:

[0082] H = f e (X; θ e )

[0083] where X is the input data, H is the low-dimensional feature vector, f e is the encoder function, and θ e is the encoder parameter;

[0084] The decoder reconstructs the low-dimensional feature vector into data in the original data space, and its transformation process is:

[0085]

[0086] where is the reconstructed data, f d is the decoder function, and θ d is the decoder parameter.

[0087] Specifically, the encoder compresses and transforms the input operating data of the industrial control mainboard, maps it to a low-dimensional space. In this process, the encoder learns the main features of the data and extracts the key information. The decoder then receives the low-dimensional feature vector output by the encoder and reconstructs it into data in the original data space. By comparing the differences between the input data and the reconstructed data, it is possible to determine whether the data is abnormal. By comparing the differences between the input data and the reconstructed data, abnormal patterns in the data can be quickly and accurately identified. This method does not require prior knowledge of the specific characteristics of the abnormality, and has strong generality and adaptability. At the same time, mapping the data to a low-dimensional space can reduce the dimension of the data, lower the computational complexity, and improve the detection efficiency.

[0088] The abnormal detection model module uses the reconstruction error to determine whether the data is abnormal. The calculation method of the reconstruction error is as follows:

[0089]

[0090] Among them, when the reconstruction error E exceeds the preset threshold, the data is determined to be abnormal data. The preset value is comprehensively determined based on the historical fluctuation range of the hardware status data of the industrial control mainboard, the normal value range of the business data, and the data change characteristics during past security attacks.

[0091] Specifically, the reconstruction error reflects the degree of difference between the input data and the normal pattern learned by the model. The preset threshold is the standard for judging whether the data is abnormal, and it is comprehensively determined based on the historical fluctuation range of the hardware status data of the industrial control mainboard, the normal value range of the business data, and the data change characteristics during past security attacks. Using the reconstruction error and the preset threshold for abnormal detection can effectively identify abnormal situations in the data. By comprehensively considering the hardware status data, business data, and historical attack data to determine the preset threshold, the setting of the threshold is made more reasonable and accurate, and it can adapt to different industrial control system environments and data characteristics. Timely discovery of abnormal data can help system administrators take corresponding measures to prevent security accidents and ensure the normal operation of the industrial control system.

[0092] The system also includes a data backup module. The data backup module is used to regularly back up the data in the storage device. The backup strategy is as follows:

[0093] Set the backup period T;

[0094] Within each backup period T, perform a full backup of the data in the storage device.

[0095] Specifically, the data backup module is an important part of the system to ensure data security. It performs a complete backup of the data in the storage device according to the set backup period T. The backup period T can be adjusted according to actual needs, for example, a backup can be performed daily, weekly, or monthly. Within each backup period, the data backup module copies all the data in the storage device and stores it in another secure location, such as an external storage device or a remote server. When data loss or damage occurs, the normal operation of the system can be quickly restored by restoring the backup data, reducing the losses caused by data loss. The complete backup method can ensure the integrity of the backup data and provide a reliable guarantee for the system recovery.

[0096] When the data backup module performs data backup, it adopts an incremental backup method. The incremental backup process is as follows:

[0097] Compare the current data with the previous backup data for differences;

[0098] Only back up the data that has changed.

[0099] Specifically, the incremental backup method first compares the current data with the previous backup data to find out which data has changed. Then, only these changed data are backed up instead of all the data. The incremental backup method can improve the backup efficiency and reduce the time and storage space required for backup. Since only the changed data is backed up, the backup process is more efficient and at the same time reduces the requirements for the storage device. When data needs to be restored, the data of the complete backup and the incremental backup can be combined to quickly restore to the latest state, ensuring both data security and improving the system recovery efficiency.

[0100] The above shows and describes the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed.

Claims

1. An industrial control mainboard operation data security protection system, characterized in that, The system includes a data acquisition module, an encrypted transmission module, a storage management module, an access control module, a security monitoring module, and an anomaly detection model module, where: The data acquisition module is used to collect various types of data during the operation of the industrial control mainboard; The encrypted transmission module is used to encrypt the collected data and transmit the encrypted data to the storage device; The storage management module is used to manage the data in the storage device, including data storage, retrieval, and update; The access control module is used to verify the permissions of requests to access the operation data of the industrial control mainboard according to the preset access policy; The security monitoring module is used to monitor the security status of the system in real time and identify potential security threats; The anomaly detection model module constructs an anomaly detection model based on an autoencoder to identify anomaly patterns in the operation data of the industrial control mainboard.

2. The industrial control mainboard operation data security protection system according to claim 1, characterized in that, When the data acquisition module executes the collection of various types of data during the operation of the industrial control mainboard, it includes: Collecting the hardware status data of the industrial control mainboard through sensors, where the hardware status data includes temperature, voltage, and fan speed; Extracting the business data generated by the application programs running in the industrial control mainboard.

3. The data security protection system for the operation of an industrial control mainboard according to claim 1, characterized in that When the encrypted transmission module executes the encryption of the collected data, it uses the AES encryption algorithm, and the encryption process is as follows: C = E K (P) Among them, C is the ciphertext, P is the plaintext, K is the encryption key, and E is the AES encryption operation.

4. A data security protection system for the operation of an industrial control mainboard according to claim 1, wherein, When the storage management module executes the management of the data in the storage device, it uses a hash table structure for data storage, and the hash function is: h(k) = k mod m Among them, h(k) is the hash value of the key value k, and m is the size of the hash table.

5. A data security protection system for the operation of an industrial control mainboard according to claim 1, characterized in that, When the access control module executes the verification of the permissions of requests to access the operation data of the industrial control mainboard according to the preset access policy, it uses a role-based access control model, and the verification process is as follows: Determine the role of the requester; According to the preset role permission table, judge whether this role has the permission to access the requested data.

6. The data security protection system for the operation of an industrial control mainboard according to claim 5, wherein, The preset role permission table includes role information, data resource information, and corresponding permission operation information; The roles at least include system administrator, ordinary operator, and data maintainer; For the system administrator role, it has the permissions to read, write, modify, and delete all the operation data of the industrial control mainboard; The ordinary operator role only has the permission to read part of the business data; The data maintainer role has the permission to read specific hardware status data and the operations of backing up and restoring the stored data.

7. A system for protecting the operation data security of an industrial control mainboard according to claim 1, characterized in that, The anomaly detection model based on the autoencoder constructed by the anomaly detection model module includes an encoder and a decoder, and the model structure is as follows: The encoder maps the input operation data of the industrial control mainboard to a low-dimensional space, and its transformation process is: H = f e (X; θ e ) Among them, X is the input data, H is the low-dimensional feature vector, and f e is the encoder function, and θ e is the encoder parameter; The decoder reconstructs the low-dimensional feature vector into the data in the original data space, and its transformation process is: Among them, is the reconstructed data, f d is the decoder function, θ d is the decoder parameter.

8. A data security protection system for the operation of an industrial control mainboard according to claim 7, characterized in that The anomaly detection model module uses the reconstruction error to judge whether the data is abnormal, and the calculation method of the reconstruction error is: Among them, when the reconstruction error E exceeds a preset threshold, the data is determined to be abnormal data, and the preset value is determined comprehensively based on the historical fluctuation range of the industrial control motherboard hardware status data, the normal value range of the business data, and the data change characteristics during past security attacks.

9. The industrial control mainboard operation data security protection system according to any one of claims 1 to 8, characterized in that The system also includes a data backup module, and the data backup module is used to regularly back up the data in the storage device. The backup strategy is as follows: Set the backup period T; Within each backup period T, perform a full backup of the data in the storage device.

10. A data security protection system for the operation of an industrial control mainboard according to claim 1, characterized in that When the data backup module performs data backup, it adopts an incremental backup method. The incremental backup process is as follows: Compare the difference between the current data and the previous backup data; Only back up the changed data.

Citation Information

Patent Citations

  • Intelligent protection method for photovoltaic inverter

    CN118503963A

  • Safety processing method for industrial internet data

    CN118972135A

  • Security protection method and system for information management system and storage medium

    CN119397599A

  • Network security threat monitoring method and system based on artificial intelligence

    CN119628963A