Petroleum and petrochemical site data safety management system and method and computer equipment

By deploying edge computing terminals and blockchain technologies on petroleum and petrochemical enterprise sites, data is collected, encrypted and processed and shared in real time, data security and management problems are solved, and efficient and secure data sharing and traceability are achieved.

CN120378080APending Publication Date: 2025-07-25CHINA PETROLEUM & CHEMICAL CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410110202.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In traditional management, the site data of petroleum and petrochemical enterprises has problems such as data security, opaque data sources, and easy to be tampered with and lost during data flow, and it is difficult for enterprises to trace data and effectively manage data.

Method used

The device unit-level edge computing terminal is used to collect and encrypt work data in real time, simulate and predict through enterprise-level edge computing terminals, share data using the central cloud computing platform, and use blockchain technology to build transactions to upload to the side chain to ensure data security and integrity.

Benefits of technology

Large-scale data processing and secure sharing are realized, data security and traceability are ensured, data management efficiency and quality are improved, and data leakage and tampering are avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378080A_ABST
    Figure CN120378080A_ABST
Patent Text Reader

Abstract

The invention provides a petroleum and petrochemical site data safety management system and method and computer equipment, and belongs to the field of petroleum and petrochemical site data processing. The petroleum and petrochemical site data security management system comprises: a device unit level edge computing terminal for collecting working data of each working device and processing the working data of each working device in real time to obtain effectively encrypted working data; the enterprise-level edge computing terminal receives and stores the effective encrypted working data, manages the effective encrypted working data, and performs simulation prediction according to the effective encrypted working data to obtain a first prediction result; the central cloud computing platform receives and stores the effective encrypted working data and a plurality of first prediction results, manages the effective encrypted working data, simulates and predicts according to the first prediction results to obtain a second prediction result, and sends the second prediction result to the enterprise-level edge computing terminal; and the block chain storage module is used for acquiring the effective encrypted working data and uploading the effective encrypted working data to a side chain of the block chain network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of oil and petrochemical site data processing, and particularly to an oil and petrochemical site data security management system, an oil and petrochemical site data security management method, a computer device, and a computer-readable storage medium. Background Art

[0002] In the general environment where industrial Internet is gradually popularized, the site survey data of oil and petrochemical enterprises gradually enters laboratory management systems such as LIMS systems. However, the use of data is only limited to within the enterprise. Most enterprises have not explored a set of site management models based on the industrial Internet architecture, and the data sources cannot be confirmed, and the authenticity of the data remains to be verified. Enterprises often have concerns about the confidentiality of their own real data, and trade secrets cannot be properly protected and are easily obtained by illegal users. There is no perfect solution for the security management of enterprise site data, posing a great hidden danger to data security.

[0003] Currently, there are two technical methods to implement enterprise environmental management systems. One is the local computing method, that is, all environmental data and environmental protection management data of oil and petrochemical enterprises are analyzed and processed by the local system. This method is limited by the processing capacity of the local server and cannot perform large-scale data processing. At the same time, it is also impossible to update the environmental protection data model in real time, and can only rely on the existing data model of the current system for management. The second method is the central cloud computing method. All environmental monitoring data and environmental protection management data of oil and petrochemical enterprises need to be transmitted to the central cloud computing platform for analysis and processing. The disadvantage is that because a large amount of data and videos need to be transmitted, oil and petrochemical enterprises need to be equipped with high-speed dedicated lines to access the central cloud, and the investment cost is relatively large. In addition, all data is transmitted to the central cloud, and data leakage is likely to occur, and data confidentiality cannot be guaranteed. Therefore, in the traditional data management of oil and petrochemical enterprises, problems such as data tampering and loss exist during the data flow process, resulting in the inability to effectively guarantee data security; at the same time, due to the opacity of data sources and data processing processes, it is difficult for enterprises to trace and monitor data, and it is impossible to effectively control and manage data quality. Summary of the Invention

[0004] To solve the above technical defects, the present invention provides an oil and petrochemical site data security management system, method, and computer device.

[0005] The first aspect of the present invention provides an oil and petrochemical site data security management system, including:

[0006] The device unit-level edge computing terminal is installed in each working device in the oil and petrochemical sites, and is used to collect the working data of each working device, perform real-time processing on the working data of each working device, and obtain effective encrypted working data after processing;

[0007] The enterprise-level edge computing terminal is used to receive and store the effective encrypted working data from the device unit-level edge computing terminal, manage the received effective encrypted working data, and perform simulation prediction based on the effective encrypted working data transmitted by each device unit-level edge computing terminal to obtain multiple first prediction results;

[0008] The central cloud computing platform is used to receive and store the effective encrypted working data and multiple first prediction results from each enterprise-level edge computing terminal, manage the received effective encrypted working data, simulate and predict according to the multiple first prediction results to obtain a second prediction result, and send the second prediction result to the enterprise-level edge computing terminal for data sharing;

[0009] The blockchain storage module is used to obtain the effective encrypted working data of the device unit-level edge computing terminal, construct blockchain transactions on the side of each working device based on the encrypted working data, and upload the constructed blockchain transactions to the side chain of the blockchain network.

[0010] In the embodiment of the present invention, the device unit-level edge computing terminal includes a data acquisition unit, a data management unit, a network transmission unit, and an edge-end collaboration unit;

[0011] The data acquisition unit is used to collect the working data of each working device;

[0012] The data management unit is used to receive the working data of each working device from the data acquisition unit, perform real-time processing on the working data of each working device, and obtain the effective encrypted working data of each working device;

[0013] The network transmission unit is used to encrypt and transmit the effective encrypted working data of each working device to the enterprise-level edge computing terminal;

[0014] The edge-end collaboration unit is used to communicate with the enterprise-level edge computing terminal.

[0015] In the embodiment of the present invention, the real-time processing of the working data of each working device by the data management unit specifically includes:

[0016] Classifying, marking, encrypting, and compressing the working data of each working device in sequence to obtain encrypted working data;

[0017] Storing the encrypted working data in the data storage of the device unit-level edge computing terminal;

[0018] Filter out the valid encrypted working data from the encrypted working data and upload the valid encrypted data to the enterprise-level edge computing terminal.

[0019] In the embodiment of the present invention, the filtering out of the valid encrypted working data from the encrypted working data includes:

[0020] Obtain the data value of the encrypted working data, determine whether the data value of the encrypted working data exceeds a preset threshold, and transmit the encrypted working data that exceeds the preset threshold as the valid encrypted working data;

[0021] Obtain the data period of the encrypted working data, determine whether the data period of the encrypted working data is complete, and transmit the encrypted working data with a complete data period as the valid encrypted working data;

[0022] Obtain the storage requirement of the encrypted working data, determine whether the storage requirement of the encrypted working data is for long-term storage, and transmit the encrypted working data with a long-term storage requirement as the valid encrypted working data;

[0023] Obtain the complexity level of the encrypted working data, determine whether the complexity level of the encrypted working data is a highly complex level, and transmit the encrypted working data with a highly complex level as the valid encrypted working data;

[0024] Obtain the confidentiality level of the encrypted working data, determine whether the confidentiality level of the encrypted working data is a high confidentiality level, and transmit the encrypted working data with a high confidentiality level as the valid encrypted data;

[0025] Among them, the storage requirement includes long-term storage and short-term storage, the complexity level includes a highly complex level and a low complex level, and the confidentiality level includes a high confidentiality level and a low confidentiality level.

[0026] In the embodiment of the present invention, the enterprise-level edge computing terminal includes an enterprise-level data center, an enterprise-level intelligent site management unit, a cloud-edge-end collaboration unit, and a first prediction model;

[0027] The cloud-edge-end collaboration unit is used to communicate with the device unit-level edge computing terminal and the central cloud computing platform respectively;

[0028] The enterprise-level data center is used to store the valid encrypted working data from the device unit-level edge computing terminal;

[0029] The enterprise-level intelligent site management unit is used to manage the received valid encrypted working data, parse the valid encrypted working data, and obtain the valid working data;

[0030] The first prediction model is used to perform simulation prediction based on the effective working data to obtain a first prediction result.

[0031] In an embodiment of the present invention, the central cloud computing platform includes a cloud data center, a central-level intelligent site management unit, a cloud-edge collaboration unit, and a second prediction model;

[0032] The cloud-edge collaboration unit is used to communicate with enterprise-level edge computing terminals;

[0033] The cloud data center is used to store the effective encrypted working data and the first prediction result from the enterprise-level edge computing terminals;

[0034] The central-level intelligent site management unit is used to process the effective encrypted data, analyze the effective encrypted working data, and obtain the effective working data;

[0035] The second prediction model is used to perform simulation prediction based on the effective working data and the first prediction result to obtain a second prediction result, and send the second prediction result to the enterprise-level edge computing terminal for data sharing.

[0036] In an embodiment of the present invention, the blockchain storage module includes a data transfer unit and a smart contract formulation unit;

[0037] The data transfer unit is used to transfer the blockchain transactions stored on the side chain of the blockchain network to the main chain of the blockchain network according to the side chain transfer rules;

[0038] The smart contract formulation unit is used to formulate a side chain transfer contract.

[0039] In an embodiment of the present invention, the side chain transfer contract includes:

[0040] When the blockchain transaction volume on the side chain of the blockchain network reaches a preset threshold, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0041] When the data cycle of the encrypted working data corresponding to the blockchain transaction on the side chain of the blockchain network is complete, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0042] When the confidentiality level of the encrypted working data corresponding to the blockchain transaction on the side chain of the blockchain network is at a high confidentiality level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0043] When the complexity level of the encrypted working data corresponding to the blockchain transaction on the side chain of the blockchain network is at a highly complex level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0044] Set a scheduled transfer time. When the scheduled transfer time is reached, transfer the blockchain transactions on the side chain of the blockchain network to the main chain of the blockchain network.

[0045] In an embodiment of the present invention, the smart contract formulation unit is further configured to formulate an access permission contract and a usage permission contract;

[0046] Access the encrypted work data stored in the blockchain network according to the formulated access permission contract;

[0047] Use the encrypted work data stored in the blockchain network according to the formulated usage permission contract.

[0048] The second aspect of the present invention provides a method for data security management of oil and petrochemical sites, the method comprising:

[0049] Real-time collect the work data of each working device in the oil and petrochemical site through the device unit-level edge computing terminal, and perform real-time processing on the work data of each working device to obtain effective encrypted work data after processing;

[0050] Receive and store the effective encrypted work data from the device unit-level edge computing terminal through the enterprise-level edge computing terminal, manage the effective encrypted work data transmitted by each device unit-level edge computing terminal, and perform simulation prediction based on the effective encrypted work data to obtain a first prediction result;

[0051] Through the central cloud computing platform, receive and store the effective encrypted work data and multiple first prediction results from each enterprise-level edge computing terminal, manage the effective encrypted work data transmitted by each enterprise-level edge computing terminal, perform simulation prediction based on the multiple first prediction results to obtain a second prediction result, and send the second prediction result to the enterprise-level edge computing terminal for data sharing;

[0052] Obtain the effective encrypted work data of the device unit-level edge computing terminal through the blockchain storage module, construct a blockchain transaction on the side of each working device based on the encrypted work data, and upload the constructed blockchain transaction to the side chain of the blockchain network.

[0053] The third aspect of the present invention provides a computer device, comprising:

[0054] A memory;

[0055] A processor; and

[0056] A computer program;

[0057] Wherein, the computer program is stored in the memory and is configured to be executed by the processor to perform the above-mentioned method for data security management of oil and petrochemical sites.

[0058] In a third aspect of the present invention, a computer-readable storage medium is provided, on which a computer program is stored, and the computer program is executed by a processor to implement the above-mentioned method for data security management of oil and petrochemical sites.

[0059] The present invention collects the working data of the site at the edge side of the device unit level, and processes the working data in real time to obtain effectively encrypted working data, thereby realizing large-scale data processing. Each oil and petrochemical enterprise processes the effectively encrypted working data through an enterprise-level edge computing terminal, and makes a prediction to obtain a first prediction result. Each enterprise uploads the first prediction result to the central cloud computing platform. The central cloud computing platform conducts a simulation prediction for the first prediction result to obtain a second prediction result, realizing data merging, analysis and sharing among enterprises without leaking their respective original data. The blockchain storage module uses blockchain technology to ensure the security, integrity and traceability of the effectively encrypted working data of the device unit-level edge computing terminal.

[0060] Other features and advantages of the technical solution of the present invention will be described in detail in the following specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of the present invention. The schematic embodiments and descriptions thereof of the present invention are used to explain the present invention, and do not constitute an improper limitation to the present invention. In the drawings:

[0062] Figure 1 is a schematic structural diagram of the oil and petrochemical site data security management system provided in Embodiment 1 of the present invention;

[0063] Figure 2 is a flowchart of the method for data security management of oil and petrochemical sites provided in Embodiment 2 of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0064] In order to make the technical solutions and advantages in the embodiments of the present invention clearer and more understandable, the following further describes the exemplary embodiments of the present invention in detail with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than an exhaustive list of all embodiments. It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0065] In addition, the terms "first" and "second" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, the meaning of "a plurality" is at least two, such as two, three, etc., unless otherwise specifically defined.

[0066] In the present invention, unless otherwise clearly defined and limited, terms such as "installed", "connected", "linked", "fixed", etc. shall be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or integrated; it may be a mechanical connection, an electrical connection, or capable of communicating with each other; it may be directly connected, or indirectly connected through an intermediate medium, and may be the internal communication of two components or the interaction relationship between two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0067] In the process of implementing the present invention, the inventors found that there are two technical methods to implement the current enterprise environmental management system. One is the local computing method, that is, all environmental data and environmental protection management data of petrochemical enterprises are analyzed and processed by the local system. This method is limited by the processing capacity of the local server, unable to perform large-scale data processing, and unable to update the environmental protection data model in real time, and can only rely on the existing data model of the current system for management. The second method is the central cloud computing method. All environmental monitoring data and environmental protection management data of petrochemical enterprises need to be transmitted to the central cloud computing platform for analysis and processing. The disadvantage is that because a large amount of data and videos need to be transmitted, petrochemical enterprises need to be equipped with high-speed dedicated lines to access the central cloud, and the investment cost is relatively large. In addition, all data is transmitted to the central cloud, which is prone to data leakage and the data confidentiality cannot be guaranteed. Therefore, in the traditional data management of petrochemical enterprises, there are problems such as data tampering and loss during the data flow process, resulting in the inability to effectively guarantee the security of data; at the same time, due to the opacity of the data source and the data processing process, it is difficult for enterprises to trace and monitor the data, and it is impossible to effectively control and manage the data quality.

[0068] In view of the above problems, an oil and petrochemical site data security management system is provided in an embodiment of the present invention, including: a device unit-level edge computing terminal installed in each working device in the oil and petrochemical site, collecting the working data of each working device, and performing real-time processing on the working data of each working device to obtain effectively encrypted working data; an enterprise-level edge computing terminal for receiving and storing the effectively encrypted working data from the device unit-level edge computing terminal, managing the received effectively encrypted working data, and performing simulation prediction based on the effectively encrypted working data transmitted by each device unit-level edge computing terminal to obtain multiple first prediction results; a central cloud computing platform for receiving and storing the effectively encrypted working data and multiple first prediction results from each enterprise-level edge computing terminal, managing the received effectively encrypted working data, performing simulation prediction according to the multiple first prediction results to obtain a second prediction result, and sending the second prediction result to the enterprise-level edge computing terminal for data sharing; a blockchain storage module for obtaining the effectively encrypted working data of the device unit-level edge computing terminal, constructing a blockchain transaction on the side of each working device based on the encrypted working data, and uploading the constructed blockchain transaction to the side chain of the blockchain network. The present invention realizes large-scale data processing by collecting the working data of the site at the device unit-level edge side and performing real-time processing on the working data to obtain effectively encrypted working data. Each oil and petrochemical enterprise processes the effectively encrypted working data through the enterprise-level edge computing terminal and performs prediction to obtain the first prediction result. Each enterprise uploads the first prediction result to the central cloud computing platform. The central cloud computing platform performs simulation prediction on the first prediction result to obtain the second prediction result, realizing data merging, analysis, and sharing among enterprises without disclosing their respective original data.

[0069] Embodiment 1

[0070] Figure 1 It is a schematic structural diagram of the oil and petrochemical site data security management system provided in Embodiment 1 of the present invention. As Figure 1 shown, the oil and petrochemical site data security management system provided in this embodiment includes:

[0071] A device unit-level edge computing terminal installed in each working device in the oil and petrochemical site, collecting the working data of each working device, and performing real-time processing on the working data of each working device to obtain effectively encrypted working data;

[0072] An enterprise-level edge computing terminal for receiving and storing the effectively encrypted working data from the device unit-level edge computing terminal, managing the received effectively encrypted working data, and performing simulation prediction based on the effectively encrypted working data transmitted by each device unit-level edge computing terminal to obtain multiple first prediction results;

[0073] A central cloud computing platform is used to receive and store valid encrypted work data and multiple first prediction results from each enterprise-level edge computing terminal, manage the received valid encrypted work data, simulate and predict a second prediction result based on the multiple first prediction results, and send the second prediction result to the enterprise-level edge computing terminal for data sharing;

[0074] A blockchain storage module is used to obtain the valid encrypted work data of the device unit-level edge computing terminal, construct blockchain transactions on the side of each working device based on the encrypted work data, and upload the constructed blockchain transactions to the side chain of the blockchain network.

[0075] In this embodiment, in the embodiment of the present invention, the device unit-level edge computing terminal includes a data acquisition unit, a data management unit, a network transmission unit, and an edge-side collaboration unit; the data acquisition unit is used to acquire the work data of each working device; the data management unit is used to receive the work data of each working device from the data acquisition unit, perform real-time processing on the work data of each working device, and obtain the valid encrypted work data of each working device; the network transmission unit is used to encrypt and transmit the valid encrypted work data of each working device to the enterprise-level edge computing terminal; the edge-side collaboration unit is used to communicate with the enterprise-level edge computing terminal.

[0076] Specifically, the device unit-level edge computing terminal is installed on each device and each site remediation project in petrochemical enterprises, and uses sensors, drones, handheld terminals, etc. to collect local data and perform real-time processing. The device unit-level edge computing terminal can utilize existing computers, embedded devices, or other types of computing devices, and its specific hardware and software configurations can be adjusted according to relevant site application scenarios.

[0077] The data acquisition unit collects real-time working data of monitoring points in the acquisition site, covering soil samples, groundwater samples, and surface water samples. The acquisition parameters include pH value, antimony, cobalt, vanadium, copper, nickel, lead, cadmium, beryllium, arsenic, hexavalent chromium, mercury, volatile organic compounds, semi-volatile organic compounds, and total petroleum hydrocarbons, etc. The data acquisition unit adopts an adaptive data acquisition method, such as a gradient-based algorithm, etc., which can dynamically adjust the data acquisition frequency and acquisition content of on-site site monitoring data according to the actual scenario. The data acquisition unit is used to collect site monitoring and online monitoring data information of petrochemical enterprises, and is connected to the edge sensing devices included in the connection device, including but not limited to online monitoring devices, high-definition cameras, etc. The data processing unit is used to manage the collected working data, including operations such as storage, classification, and cleaning. The network transmission unit is used to encrypt and transmit the processed data to the enterprise-level edge computing terminal. The network transmission unit includes methods such as WiFi and Ethernet to connect to the online monitoring and high-definition cameras of the device, collect data such as on-site site data and high-definition video images; and connect to the enterprise-level edge computing terminal in the ways of 4G, 5G, WiFi, and Ethernet for uploading data. The edge-cloud collaboration unit is used to communicate with the enterprise-level edge computing terminal to achieve data interaction and synchronization, and the edge-cloud collaboration unit is used to collaborate edge computing and end computing.

[0078] In this embodiment, in addition to the online monitoring data, the working data takes projects such as pollution investigation, risk assessment, and remediation construction of petrochemical enterprises as basic units, and collects data such as pollution investigation, analysis and testing, risk assessment, remediation construction, effect evaluation, and long-term monitoring in a standardized data format.

[0079] The data management unit processes the working data of each working device in real time, specifically:

[0080] Classify, label, encrypt, and compress the working data of each working device in sequence to obtain encrypted working data;

[0081] Store the encrypted working data in the data storage of the device unit-level edge computing terminal;

[0082] Screen out the valid encrypted working data from the encrypted working data and upload the valid encrypted data to the enterprise-level edge computing terminal.

[0083] Specifically, data classification is performed on the collected work data (site monitoring data) for better management and analysis. The work data collected by refining enterprises covers soil samples, groundwater samples, and surface water samples. The collection parameters include pH value, antimony, cobalt, vanadium, copper, nickel, lead, cadmium, beryllium, arsenic, hexavalent chromium, mercury, volatile organic compounds, semi-volatile organic compounds, and total petroleum hydrocarbons, etc. The system classifies data by defining data tags or attributes, categorizes different types of work data, and stores them in the blockchain respectively. For example, monitoring data such as antimony, cobalt, vanadium, copper, nickel, lead, cadmium, beryllium, arsenic, hexavalent chromium, mercury, etc. are marked as the "heavy metal category", etc. In this way, when the work data is collected and stored in the blockchain, each work data entry carries the corresponding classification tag.

[0084] By classifying the work data, enterprises can more conveniently query, retrieve, and analyze specific types of data. They can focus only on certain types of data as needed, and quickly obtain all the data related to the corresponding classification tag by querying. This helps enterprises conduct more accurate data analysis, problem troubleshooting, and monitor the status of site soil, groundwater, and surface water.

[0085] The data marking specifically includes the following steps:

[0086] Determine the data category of the work data;

[0087] Determine the corresponding marking type for the data category of the work data;

[0088] Associate the corresponding marking type with the work data.

[0089] Data encryption is to protect the confidentiality and security of work data, preventing unauthorized access and tampering. Refining enterprises collect and store various sensitive data of site monitoring types, and these data need to be properly protected during transmission and storage to prevent malicious attacks or unauthorized access. The system encrypts sensitive monitoring data and converts it into ciphertext form to ensure the confidentiality of the data. Encryption can be achieved by using various encryption algorithms and technologies, such as symmetric encryption, asymmetric encryption, etc. Only authorized users or systems can obtain the key and decrypt the ciphertext to restore it to the original plaintext data.

[0090] Data compression is to reduce the requirements for data storage and transmission and improve the efficiency of the system.

[0091] Refining enterprises collect and record monitoring data of different site blocks, such as pH value, heavy metals, volatile organic compounds, etc. Storing these real-time data in the form of original measurement values will occupy a large amount of storage space and consume more bandwidth and time during transmission. This system will compress these original working data to reduce the storage and transmission requirements of the working data. Compression can be achieved using various algorithms and technologies, such as lossless compression, lossy compression, etc., to convert it into a more compact representation. For example, the continuous pH value monitoring data sequence can be converted into a smaller data set using a compression algorithm, only retaining key data points or change trends, thereby reducing the data storage requirements.

[0092] During the data transmission process, the encrypted working data can be transmitted to the enterprise-level edge computing terminal or the central cloud computing platform more securely, preventing the data from being stolen or tampered with during transmission. At the receiving end, a legitimate decryption operation can convert the ciphertext into plaintext data for subsequent analysis and processing.

[0093] During the data transmission process, the compressed working data can be transmitted to the enterprise-level edge computing terminal or the central cloud computing platform more quickly, thereby improving the data transmission efficiency. At the receiving end, a decompression operation can be performed to restore it to the original working data format for subsequent analysis and processing.

[0094] In this embodiment, screening out the valid encrypted working data from the encrypted working data includes:

[0095] Obtain the data value of the encrypted working data, determine whether the data value of the encrypted working data exceeds a preset threshold, and transmit the encrypted working data that exceeds the preset threshold as the valid encrypted working data; specifically, it is determined according to the real-time importance of the working data. Emergency data: The equipment suddenly overheats. Non-emergency data: Daily temperature monitoring data. Transmit the emergency data as the valid encrypted data.

[0096] Obtain the data period of the encrypted working data, determine whether the data period of the encrypted working data is complete, and transmit the encrypted working data with a complete data period as the valid encrypted working data; specifically, it is determined according to the integrity of the data set. Complete data set: All site temperature data within a day. Partial data: Site temperature data in the morning. Transmit the complete data set as the valid encrypted data.

[0097] Obtain the storage requirements of the encrypted work data, determine whether the storage requirements of the encrypted work data are for long-term storage, and transmit the encrypted work data with long-term storage requirements as valid encrypted work data; specifically, it is determined according to the storage requirements of the data. Long-term storage: Site monitoring data from last year. Short-term or temporary storage: Site monitoring data today. Transmit the work data that needs long-term storage as valid encrypted data.

[0098] Obtain the complexity level of the encrypted work data, determine whether the complexity level of the encrypted work data is a highly complex level, and transmit the encrypted work data with a highly complex level as valid encrypted work data; specifically, it is determined according to the processing complexity of the data. High processing requirements: Data that needs to be used for deep learning model training. Low processing requirements: Simple average temperature calculation. Transmit the work data with high processing requirements as valid encrypted data.

[0099] Obtain the confidentiality level of the encrypted work data, determine whether the confidentiality level of the encrypted work data is a high confidentiality level, and transmit the encrypted work data with a high confidentiality level as valid encrypted data; specifically, it is determined according to the sensitivity and security of the data. High security level: Data containing critical operations or sensitive information. Low security level: Routine site monitoring data. Transmit the work data with a high security level as valid encrypted data.

[0100] It is also determined according to the network condition of the data processing unit. Network stable: 4G signal is full, and data can be sent. Network unstable: In an area with poor signal, give priority to sending emergency data.

[0101] Among them, the storage requirements include long-term storage and short-term storage, the complexity level includes a highly complex level and a low complexity level, and the confidentiality level includes a high confidentiality level and a low confidentiality level.

[0102] In this embodiment, the enterprise-level edge computing terminal includes an enterprise-level data center, an enterprise-level intelligent site management unit, a cloud-edge-end collaboration unit, and a first prediction model; the cloud-edge-end collaboration unit is used to communicate with the device unit-level edge computing terminal and the central cloud computing platform respectively; the enterprise-level data center is used to store the valid encrypted work data from the device unit-level edge computing terminal; the enterprise-level intelligent site management unit is used to process the valid encrypted work data, parse the valid encrypted work data, and obtain valid work data; the first prediction model is used to perform simulation prediction according to the valid work data to obtain a first prediction result. Specifically, the first prediction model includes, but is not limited to, relevant professional models such as site pollution characterization, site analysis prediction, site early warning assessment, and site technology screening.

[0103] In this embodiment, the central cloud computing platform includes a cloud data center, a central-level intelligent site management unit, a cloud-edge collaboration unit, and a second prediction model; the cloud-edge collaboration unit is used to communicate with enterprise-level edge computing terminals; the cloud data center is used to store the effective encrypted work data and the first prediction result from the enterprise-level edge computing terminals; the central-level intelligent site management unit is used to process the effective encrypted data, analyze the effective encrypted work data, and obtain the effective work data; the second prediction model is used to perform simulation prediction based on the effective work data and the first prediction result to obtain a second prediction result.

[0104] In this embodiment, the blockchain storage module includes a data transfer unit and a smart contract formulation unit; the data transfer unit is used to transfer blockchain transactions stored on the side chain of the blockchain network to the main chain of the blockchain network according to the side chain transfer rules; the smart contract formulation unit is used to formulate side chain transfer contracts.

[0105] The blockchain storage module applies blockchain technology to upload the effective encrypted work data to the blockchain network. In the application of blockchain technology, a blockchain node refers to a participant in a distributed network, and each node contains a complete data copy and the consensus algorithm of the blockchain. Nodes can be computers or servers managed and maintained by refining enterprises, third-party institutions, or other relevant participants. Each node has the function of verifying and recording transactions and participates in the consensus process of the blockchain network. Data is transmitted and shared between nodes through a peer-to-peer communication method, thereby realizing the distributed storage and management of data. The number and location of nodes can be flexibly configured according to actual needs to meet the requirements of data management.

[0106] In this embodiment, the side chain transfer contract includes:

[0107] When the blockchain transaction volume on the side chain of the blockchain network reaches a preset threshold, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0108] When the data cycle of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is complete, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0109] When the confidentiality level of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is at a high confidentiality level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0110] When the complexity level of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is at a highly complex level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0111] Set a timing transfer time. When the timing transfer time is reached, transfer the blockchain transactions on the side chain of the blockchain network to the main chain of the blockchain network.

[0112] Specifically, the side chain transfer contract is shown in the following table:

[0113]

[0114] The side chain of the blockchain network refers to an additional chain based on blockchain technology, which is interconnected and operates with the main blockchain network. When the device unit-level edge computing terminal collects and processes the data to obtain valid encrypted working data, these valid encrypted working data are first stored on the side chain instead of directly on the main chain. This can reduce the burden on the main chain and improve the performance and scalability of the system. In the refining site data management system: when the valid encrypted working data reaches the above conditions on the side chain, the data transfer is automatically triggered by the smart contract. Before the valid encrypted working data is transferred from the side chain to the main chain, it is first encrypted and verified. Only the valid encrypted working data that passes the verification can be transferred to the main chain. Once the valid encrypted working data is successfully transferred to the main chain, the corresponding data on the side chain can be marked as "synchronized" or directly deleted to save storage space. The smart contract defines the transfer rules of data from the side chain to the main chain, how to verify the integrity and authenticity of the data, and how to handle data conflicts or exceptions. By executing the smart contract on the edge computing terminal, the data transmission delay can be reduced and the system response speed can be improved.

[0115] In this embodiment, the smart contract formulation unit is further configured to formulate an access permission contract and a usage permission contract;

[0116] Access the encrypted working data stored in the blockchain network according to the formulated access permission contract;

[0117] Use the encrypted working data stored in the blockchain network according to the formulated usage permission contract.

[0118] Specifically, in the application of the smart contract, it supports customizing various access control strategies for data. There are mainly the following types of strategies, which are customized according to the enterprise's own needs, and the enterprise can set a suitable strategy matrix.

[0119] Role-based: Assign different data access permissions according to the user's role (such as operator, grass-roots manager, middle-level manager, senior manager, operation and maintenance personnel, etc.).

[0120] Time-based: Automatically delete according to the expiration date of the data assignment.

[0121] Based on data types: Different access rights can be set for real-time monitoring data and historical data.

[0122] Based on security levels: Data with a high security level is accessed by specific users or systems.

[0123] In this embodiment, the device unit-level edge computing terminal can utilize existing computers, embedded devices, or other types of computing devices, and its specific hardware and software configurations can be adjusted according to relevant site application scenarios. The enterprise-level edge computing terminal can be an independent computer system, which includes multiple nodes, and each node can be deployed at different locations, such as each device workshop, the site remediation project construction site, each office area, and so on. The enterprise-level edge computing terminal can be connected to the device unit-level computing terminal through a wired or wireless network, collect local data, and perform real-time processing and storage. At the same time, the enterprise-level edge computing terminal can upload data to the central cloud computing platform for more in-depth analysis and processing. The central cloud computing platform can be one or more cloud servers, with high-performance computing capabilities and scalability. The central cloud computing platform can use existing cloud computing platform technologies, such as open cloud computing platforms, private cloud computing platforms, hybrid cloud computing platforms, etc. The central cloud computing platform processes the site data of the refining enterprise through its connection with the enterprise-level edge computing terminal and uses blockchain technology to ensure the security and integrity of the data.

[0124] The present invention is used to merge, analyze, and share data between multiple device unit-level edge computing terminals or enterprise-level edge computing terminals without leaking their respective original data. For example, two enterprises in a chemical industrial park with close geographical locations hope to further analyze their respective site pollution status and future predictions and need to use each other's data to jointly participate in simulation calculations. Through the present invention, the merged simulation calculation results can be obtained without sharing the original monitoring data.

[0125] Under the industrial Internet architecture, there are currently two technical methods to manage the site data in the oil and petrochemical industries. One is the local computing method, that is, all the site environmental data and site environmental protection management data of oil and petrochemical enterprises are analyzed and processed by the local system. This method is limited by the processing power of the local server and cannot perform large-scale data processing. At the same time, it cannot update the environmental protection data model in real time and can only rely on the existing data model of the current system for management. The second method is the central cloud computing method. All the environmental monitoring data and environmental protection management data of oil and petrochemical enterprises need to be transmitted to the central cloud computing platform for analysis and processing. The disadvantage is that because a large amount of data and videos need to be transmitted, oil and petrochemical enterprises need to be equipped with high-speed dedicated lines to access the central cloud, and the investment cost is relatively large. In addition, all the data is transmitted to the central cloud, which is prone to data leakage and the data confidentiality cannot be guaranteed. Moreover, the uploaded data needs to be cleaned and screened during model training, and it cannot be guaranteed that all the key data for training is in the cloud. Enterprises often have concerns about the confidentiality of their own real data, and trade secrets cannot be properly protected and are easily obtained by illegal users. Compared with the traditional site data management method, the present invention has the following beneficial effects:

[0126] 1. Data security is guaranteed. By using blockchain technology, the data is encrypted and stored on distributed nodes, and the data of each node is verified, ensuring the integrity and security of the data.

[0127] 2. Data traceability. Blockchain technology has the characteristic of being immutable, which can effectively record the source and transfer path of the data, realizing data traceability and monitoring.

[0128] 3. Efficient and secure data sharing. Through smart contract technology, automated data processing and sharing are realized. Enterprises can share data safely and efficiently, promoting collaborative innovation and resource sharing.

[0129] The present invention proposes a complete set of blockchain technology-based solutions for the collection, encryption, transmission, and storage of oil and petrochemical site data, which can guarantee the integrity, reliability, and security of the data, and help improve the efficiency and quality of data management in oil and petrochemical enterprises. The present invention organically integrates the device unit-level edge computing terminal, enterprise-level edge computing terminal, and central cloud computing platform, and conducts data security management through blockchain technology. This comprehensive industrial Internet model combines the advantages of local real-time processing, edge computing, and central cloud computing, providing a comprehensive data management and analysis solution for refining enterprises.

[0130] Embodiment 2

[0131] Figure 2 It is a flowchart of the oil and petrochemical site data security management method provided by Embodiment 2 of the present invention. AsFigure 2 As shown in the figure, the data security management method for petrochemical sites provided in this embodiment includes the following steps:

[0132] S1. The working data of each working device in the petrochemical site is collected in real time through the device unit-level edge computing terminal, and the working data of each working device is processed in real time. After processing, effective encrypted working data is obtained;

[0133] S2. The enterprise-level edge computing terminal receives and stores the effective encrypted working data from the device unit-level edge computing terminal, manages the effective encrypted working data transmitted by each device unit-level edge computing terminal, and performs simulation prediction based on the effective encrypted working data to obtain a first prediction result;

[0134] S3. Through the central cloud computing platform, the effective encrypted working data and multiple first prediction results from each enterprise-level edge computing terminal are received and stored, the effective encrypted working data transmitted by each enterprise-level edge computing terminal is managed, and a second prediction result is obtained by simulation prediction based on the first prediction result;

[0135] S4. The effective encrypted working data of the device unit-level edge computing terminal is obtained through the blockchain storage module, a blockchain transaction is constructed on the side of each working device based on the encrypted working data, and the constructed blockchain transaction is uploaded to the side chain of the blockchain network.

[0136] The data security management method for petrochemical sites provided in this embodiment is implemented based on a petrochemical site data security management system, and the system includes:

[0137] The device unit-level edge computing terminal is installed in each working device in the petrochemical site, collects the working data of each working device, and processes the working data of each working device in real time to obtain effective encrypted working data;

[0138] The enterprise-level edge computing terminal is used to receive and store the effective encrypted working data from the device unit-level edge computing terminal, manage the received effective encrypted working data, and perform simulation prediction based on the effective encrypted working data transmitted by each device unit-level edge computing terminal to obtain multiple first prediction results;

[0139] The central cloud computing platform is used to receive and store the effective encrypted working data and multiple first prediction results from each enterprise-level edge computing terminal, manage the received effective encrypted working data, obtain a second prediction result by simulation prediction based on multiple first prediction results, and send the second prediction result to the enterprise-level edge computing terminal for data sharing;

[0140] The blockchain storage module is used to obtain the effective encrypted working data of the device unit-level edge computing terminal, construct blockchain transactions on the side of each working device based on the encrypted working data, and upload the constructed blockchain transactions to the side chain of the blockchain network.

[0141] In this embodiment, in the embodiment of the present invention, the device unit-level edge computing terminal includes a data acquisition unit, a data management unit, a network transmission unit, and an edge-side collaboration unit; the data acquisition unit is used to acquire the working data of each working device; the data management unit is used to receive the working data of each working device from the data acquisition unit, and perform real-time processing on the working data of each working device to obtain the effective encrypted working data of each working device; the network transmission unit is used to encrypt and transmit the effective encrypted working data of each working device to the enterprise-level edge computing terminal; the edge-side collaboration unit is used to communicate with the enterprise-level edge computing terminal.

[0142] Specifically, the device unit-level edge computing terminal is installed on various devices and various site remediation projects in petrochemical enterprises, and uses sensors, drones, and handheld terminals to collect local data and perform real-time processing. The device unit-level edge computing terminal can utilize existing computers, embedded devices, or other types of computing devices, and its specific hardware and software configurations can be adjusted according to relevant site application scenarios.

[0143] The data acquisition unit is used to collect the real-time working data of the site monitoring points, covering soil samples, groundwater samples, and surface water samples. The acquisition parameters include pH value, antimony, cobalt, vanadium, copper, nickel, lead, cadmium, beryllium, arsenic, hexavalent chromium, mercury, volatile organic compounds, semi-volatile organic compounds, and total petroleum hydrocarbons, etc. The data acquisition unit adopts an adaptive data acquisition method, such as a gradient-based algorithm, etc., which can dynamically adjust the data acquisition frequency and acquisition content of the on-site site monitoring data according to the actual scenario. The data acquisition unit is used to collect the site monitoring and online monitoring data information of petrochemical enterprises, and connect to the edge sensing devices included in the device, including but not limited to online monitoring devices, high-definition cameras, etc. The data processing unit is used to manage the acquired working data, including operations such as storage, classification, and cleaning. The network transmission unit is used to encrypt and transmit the processed data to the enterprise-level edge computing terminal. The network transmission unit includes ways such as WiFi and Ethernet to connect to the online monitoring and high-definition cameras of the device to collect data such as on-site site data and high-definition video images; and connect to the enterprise-level edge computing terminal in the ways of 4G, 5G, WiFi, and Ethernet for uploading data. The edge-side collaboration unit is used to communicate with the enterprise-level edge computing terminal to achieve data interaction and synchronization, and the edge-side collaboration unit is used to collaborate edge computing and end computing.

[0144] In this embodiment, in addition to the online monitoring data, the working data takes projects such as pollution surveys, risk assessments, and remediation construction in petrochemical enterprises as basic units, and collects data such as pollution surveys, analytical tests, risk assessments, remediation construction, effect evaluations, and long-term monitoring in a standardized data format.

[0145] The data management unit processes the working data of each working device in real time, specifically as follows:

[0146] Classify, label, encrypt, and compress the working data of each working device in sequence to obtain encrypted working data;

[0147] Store the encrypted working data in the data storage of the device unit-level edge computing terminal;

[0148] Screen out the valid encrypted working data from the encrypted working data and upload the valid encrypted data to the enterprise-level edge computing terminal.

[0149] Specifically, data classification is carried out on the collected working data (site monitoring data) for better management and analysis. The working data collected by refining enterprises covers soil samples, groundwater samples, and surface water samples. The collection parameters include pH value, antimony, cobalt, vanadium, copper, nickel, lead, cadmium, beryllium, arsenic, hexavalent chromium, mercury, volatile organic compounds, semi-volatile organic compounds, and total petroleum hydrocarbons, etc. The system will classify the data by defining data tags or attributes, and classify and store different types of working data in the blockchain respectively. For example, monitor data such as antimony, cobalt, vanadium, copper, nickel, lead, cadmium, beryllium, arsenic, hexavalent chromium, mercury, etc. are marked as the "heavy metal" category. In this way, when the working data is collected and stored in the blockchain, each working data entry carries the corresponding classification label.

[0150] By classifying the working data, enterprises can more conveniently query, retrieve, and analyze specific types of data. They can focus only on certain types of data as needed, and quickly obtain all data related to this label by querying the corresponding classification label. This helps enterprises conduct more accurate data analysis, problem troubleshooting, and monitor the status of site soil, groundwater, and surface water.

[0151] Data marking specifically includes the following steps:

[0152] Determine the data category of the working data;

[0153] Determine the corresponding marking type for the data category of the working data;

[0154] Associate the corresponding marking type with the working data.

[0155] Data encryption is to protect the confidentiality and security of work data, preventing unauthorized access and tampering. Refining and chemical enterprises collect and store various types of sensitive data on site monitoring. These data need to be properly protected during transmission and storage to prevent malicious attacks or unauthorized access. The system will encrypt sensitive monitoring data and convert it into ciphertext form to ensure data confidentiality. Encryption can be achieved using various encryption algorithms and technologies, such as symmetric encryption, asymmetric encryption, etc. Only authorized users or systems can obtain the key and decrypt the ciphertext to restore it to the original plaintext data.

[0156] Data compression is to reduce the requirements for data storage and transmission and improve the efficiency of the system.

[0157] Refining and chemical enterprises collect and record monitoring data of different site blocks, such as pH value, heavy metals, volatile organic compounds, etc. Storing these real-time data in the form of original measurement values will occupy a large amount of storage space and consume more bandwidth and time during transmission. This system will compress these original work data to reduce the storage and transmission requirements of work data. Compression can be achieved using various algorithms and technologies, such as lossless compression, lossy compression, etc. Convert it into a more compact representation form. For example, the compression algorithm can be used to convert a continuous sequence of pH value monitoring data into a smaller data set, only retaining key data points or change trends, thereby reducing the storage requirements of the data.

[0158] During data transmission, the encrypted work data can be transmitted more securely to the enterprise-level edge computing terminal or the central cloud computing platform, preventing the data from being stolen or tampered with during transmission. At the receiving end, a legitimate decryption operation can convert the ciphertext into plaintext data for subsequent analysis and processing.

[0159] During data transmission, the compressed work data can be transmitted more quickly to the enterprise-level edge computing terminal or the central cloud computing platform, thereby improving the efficiency of data transmission. At the receiving end, a decompression operation can be performed to restore it to the data format of the original work data for subsequent analysis and processing.

[0160] In this embodiment, screening out valid encrypted work data from the encrypted work data includes:

[0161] Obtain the data value of the encrypted work data, determine whether the data value of the encrypted work data exceeds a preset threshold, and transmit the encrypted work data that exceeds the preset threshold as valid encrypted work data; specifically, it is determined according to the real-time importance of the work data. Emergency data: The equipment suddenly overheats. Non-emergency data: Daily temperature monitoring data. Transmit the emergency data as valid encrypted data.

[0162] Obtain the data period of the encrypted working data, determine whether the data period of the encrypted working data is complete, and transmit the encrypted working data with a complete data period as valid encrypted working data; specifically, it is determined according to the integrity of the data set. Complete data set: All site temperature data within one day. Partial data: Site temperature data in the morning. Transmit the complete data set as valid encrypted data.

[0163] Obtain the storage requirement of the encrypted working data, determine whether the storage requirement of the encrypted working data is long-term storage, and transmit the encrypted working data with a long-term storage requirement as valid encrypted working data; specifically, it is determined according to the storage requirement of the data. Long-term storage: Site monitoring data from last year. Short-term or temporary storage: Site monitoring data today. Transmit the working data that needs long-term storage as valid encrypted data.

[0164] Obtain the complexity level of the encrypted working data, determine whether the complexity level of the encrypted working data is a highly complex level, and transmit the encrypted working data with a highly complex level as valid encrypted working data; specifically, it is determined according to the processing complexity of the data. High processing requirement: Data that needs to be used for deep learning model training. Low processing requirement: Simple average temperature calculation. Transmit the working data with high processing requirements as valid encrypted data.

[0165] Obtain the confidentiality level of the encrypted working data, determine whether the confidentiality level of the encrypted working data is a high confidentiality level, and transmit the encrypted working data with a high confidentiality level as valid encrypted data; specifically, it is determined according to the sensitivity and security of the data. High security level: Data containing critical operations or sensitive information. Low security level: Routine site monitoring data. Transmit the working data with a high security level as valid encrypted data.

[0166] It is also determined according to the network condition of the data processing unit. Network stable: 4G signal is full, and data can be sent. Network unstable: In an area with poor signal, give priority to sending emergency data.

[0167] Among them, the storage requirement includes long-term storage and short-term storage, the complexity level includes highly complex level and low complexity level, and the confidentiality level includes high confidentiality level and low confidentiality level.

[0168] In this embodiment, the enterprise-level edge computing terminal includes an enterprise-level data center, an enterprise-level intelligent site management unit, a cloud-edge-end collaboration unit, and a first prediction model; the cloud-edge-end collaboration unit is used to communicate with the device unit-level edge computing terminal and the central cloud computing platform respectively; the enterprise-level data center is used to store the effective encrypted work data from the device unit-level edge computing terminal; the enterprise-level intelligent site management unit is used to process the effective encrypted work data, parse the effective encrypted work data, and obtain the effective work data; the first prediction model is used to perform simulation prediction based on the effective work data to obtain a first prediction result. Specifically, the first prediction model includes, but is not limited to, relevant professional models such as site pollution characterization, site analysis prediction, site early warning assessment, and site technology screening.

[0169] In this embodiment, the central cloud computing platform includes a cloud data center, a central-level intelligent site management unit, a cloud-edge collaboration unit, and a second prediction model; the cloud-edge collaboration unit is used to communicate with the enterprise-level edge computing terminal; the cloud data center is used to store the effective encrypted work data and the first prediction result from the enterprise-level edge computing terminal; the central-level intelligent site management unit is used to process the effective encrypted data, parse the effective encrypted work data, and obtain the effective work data; the second prediction model is used to perform simulation prediction based on the effective work data and the first prediction result to obtain a second prediction result.

[0170] In this embodiment, the blockchain storage module includes a data transfer unit and a smart contract formulation unit; the data transfer unit is used to transfer blockchain transactions stored on the side chain of the blockchain network to the main chain of the blockchain network according to the side chain transfer rules; the smart contract formulation unit is used to formulate side chain transfer contracts.

[0171] The blockchain storage module applies blockchain technology to upload the effective encrypted work data to the blockchain network. In the application of blockchain technology, a blockchain node refers to a participant in a distributed network, and each node contains a complete data copy and a consensus algorithm of the blockchain. A node can be a computer or server managed and maintained by a refining enterprise, a third-party institution, or other relevant participants. Each node has the function of verifying and recording transactions and participates in the consensus process of the blockchain network. Nodes transmit and share data through a peer-to-peer communication method, thereby realizing the distributed storage and management of data. The number and location of nodes can be flexibly configured according to actual needs to meet the requirements of data management.

[0172] In this embodiment, the side chain transfer contract includes:

[0173] When the blockchain transaction volume on the side chain of the blockchain network reaches a preset threshold, transfer the blockchain transactions on the side chain of the blockchain network to the main chain of the blockchain network;

[0174] When the data cycle of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is complete, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0175] When the confidentiality level of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is at a high confidentiality level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0176] When the complexity level of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is at a highly complex level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network;

[0177] Set a scheduled transfer time, and when the scheduled transfer time arrives, transfer the blockchain transactions on the side chain of the blockchain network to the main chain of the blockchain network.

[0178] Specifically, the side chain transfer contract is as shown in the following table:

[0179]

[0180] The side chain of the blockchain network refers to an additional chain based on blockchain technology, which is interconnected and operates with the main blockchain network. When the device unit-level edge computing terminal collects and processes data to obtain valid encrypted work data, these valid encrypted work data are first stored on the side chain, rather than directly on the main chain. This can reduce the burden on the main chain and improve the performance and scalability of the system. In the refining site data management system: when the valid encrypted work data meets the above conditions on the side chain, the data transfer is automatically triggered through a smart contract. Before the valid encrypted work data is transferred from the side chain to the main chain, it is first encrypted and verified. Only the valid encrypted work data that passes the verification can be transferred to the main chain. Once the valid encrypted work data is successfully transferred to the main chain, the corresponding data on the side chain can be marked as "synchronized" or directly deleted to save storage space. The smart contract defines the transfer rules of data from the side chain to the main chain, how to verify the integrity and authenticity of the data, and how to handle data conflicts or exceptions. By executing the smart contract on the edge computing terminal, the data transmission delay can be reduced and the system response speed can be improved.

[0181] In this embodiment, the smart contract formulation unit is further used to formulate an access permission contract and a usage permission contract;

[0182] Access the encrypted work data stored in the blockchain network according to the formulated access right contract;

[0183] Use the encrypted work data stored in the blockchain network according to the formulated usage right contract.

[0184] Specifically, in the application of smart contracts, support the customization of various access control policies for data. There are mainly the following types of policies customized according to the needs of the enterprise itself, and the enterprise can set a suitable policy matrix.

[0185] Role-based: Assign different data access rights according to the user's role (such as operator, grass-roots manager, middle-level manager, senior manager, operation and maintenance personnel, etc.).

[0186] Time-based: Automatically delete according to the expiration date of data allocation.

[0187] Data type-based: Different access rights can be set for real-time monitoring data and historical data.

[0188] Security level-based: Data with a high security level is accessed by specific users or systems.

[0189] In this embodiment, the device unit-level edge computing terminal can utilize existing computers, embedded devices or other types of computing devices, and its specific hardware and software configurations can be adjusted according to relevant site application scenarios. The enterprise-level edge computing terminal can be an independent computer system, which includes multiple nodes, and each node can be deployed in different locations, such as each device workshop, the site remediation project construction site, each office area, etc. The enterprise-level edge computing terminal can be connected to the device unit-level computing terminal through a wired or wireless network, collect local data, and perform real-time processing and storage. At the same time, the enterprise-level edge computing terminal can upload data to the central cloud computing platform for more in-depth analysis and processing. The central cloud computing platform can be one or more cloud servers, with high-performance computing capabilities and scalability. The central cloud computing platform can use existing cloud computing platform technologies, such as open cloud computing platforms, private cloud computing platforms, hybrid cloud computing platforms, etc. The central cloud computing platform processes the site data of the refining enterprise through its connection with the enterprise-level edge computing terminal, and uses blockchain technology to ensure the security and integrity of the data.

[0190] Embodiment 3

[0191] The embodiment of the present invention also provides a computer device, including: a memory, a processor, and a computer program, where the computer program is stored in the memory and is configured to be executed by the processor to implement the above-mentioned oil and petrochemical site data security management method.

[0192] Embodiment 4

[0193] An embodiment of the present invention also provides a machine-readable storage medium, on which computer program instructions are stored, and when the computer program instructions are executed by a processor, the above-mentioned method for data security management of oil and petrochemical sites is implemented.

[0194] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The solutions in the embodiments of the present invention can be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript.

[0195] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0196] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0197] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks or multiple blocks.

[0198] Although the preferred embodiments of the present invention have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present invention.

[0199] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. An oil and petrochemical site data security management system, characterized in that, Including: Device unit-level edge computing terminals, installed in each working device in the oil and petrochemical sites, for collecting the working data of each working device and performing real-time processing on the working data of each working device to obtain effectively encrypted working data; Enterprise-level edge computing terminals, for receiving and storing the effectively encrypted working data from the device unit-level edge computing terminals, managing the received effectively encrypted working data, and performing simulation prediction based on the effectively encrypted working data transmitted by each device unit-level edge computing terminal to obtain multiple first prediction results; Central cloud computing platform, for receiving and storing the effectively encrypted working data and multiple first prediction results from each enterprise-level edge computing terminal, managing the received effectively encrypted working data, performing simulation prediction based on the multiple first prediction results to obtain a second prediction result, and sending the second prediction result to the enterprise-level edge computing terminal for data sharing; Blockchain storage module, for obtaining the effectively encrypted working data of the device unit-level edge computing terminal, constructing blockchain transactions on the side of each working device based on the encrypted working data, and uploading the constructed blockchain transactions to the side chain of the blockchain network.

2. The petroleum and petrochemical site data security management system according to claim 1, wherein The device unit-level edge computing terminal includes a data acquisition unit, a data management unit, a network transmission unit, and an edge-side collaboration unit; The data acquisition unit is used for collecting the working data of each working device; The data management unit is used for receiving the working data of each working device from the data acquisition unit and performing real-time processing on the working data of each working device to obtain the effectively encrypted working data of each working device; The network transmission unit is used for encrypting and transmitting the effectively encrypted working data of each working device to the enterprise-level edge computing terminal; The edge-side collaboration unit is used for communicating with the enterprise-level edge computing terminal.

3. The data security management system for oil and petrochemical sites according to claim 2, wherein The real-time processing of the working data of each working device by the data management unit specifically includes: Successively classifying, marking, encrypting, and compressing the working data of each working device to obtain encrypted working data; Storing the encrypted working data in the data storage of the device unit-level edge computing terminal; Screening out the effectively encrypted working data from the encrypted working data and uploading the effectively encrypted data to the enterprise-level edge computing terminal.

4. The oil and petrochemical site data security management system according to claim 3, characterized in that The screening out of the effectively encrypted working data from the encrypted working data includes: Obtaining the data value of the encrypted working data, judging whether the data value of the encrypted working data exceeds a preset threshold, and transmitting the encrypted working data exceeding the preset threshold as the effectively encrypted working data; Obtaining the data period of the encrypted working data, judging whether the data period of the encrypted working data is complete, and transmitting the encrypted working data with a complete data period as the effectively encrypted working data; Obtaining the storage requirement of the encrypted working data, judging whether the storage requirement of the encrypted working data is for long-term storage, and transmitting the encrypted working data with a long-term storage requirement as the effectively encrypted working data; Obtain the complexity level of the encrypted work data, determine whether the complexity level of the encrypted work data is a highly complex level, and transmit the encrypted work data with a highly complex level as the valid encrypted work data; Obtain the confidentiality level of the encrypted work data, determine whether the confidentiality level of the encrypted work data is a high confidentiality level, and transmit the encrypted work data with a high confidentiality level as the valid encrypted data; Among them, the storage requirements include long-term storage and short-term storage, the complexity levels include highly complex levels and lowly complex levels, and the confidentiality levels include high confidentiality levels and low confidentiality levels.

5. The petroleum and petrochemical site data security management system according to claim 1, wherein The enterprise-level edge computing terminal includes an enterprise-level data center, an enterprise-level intelligent site management unit, a cloud-edge-end collaboration unit, and a first prediction model; The cloud-edge-end collaboration unit is used to communicate with the device unit-level edge computing terminal and the central cloud computing platform respectively; The enterprise-level data center is used to store the valid encrypted work data from the device unit-level edge computing terminal; The enterprise-level intelligent site management unit is used to manage the received valid encrypted work data, parse the valid encrypted work data, and obtain the valid work data; The first prediction model is used to perform simulation prediction based on the valid work data to obtain the first prediction result.

6. The petroleum and petrochemical site data security management system according to claim 1, characterized in that, The central cloud computing platform includes a cloud data center, a central-level intelligent site management unit, a cloud-edge collaboration unit, and a second prediction model; The cloud-edge collaboration unit is used to communicate with the enterprise-level edge computing terminal; The cloud data center is used to store the valid encrypted work data and the first prediction result from the enterprise-level edge computing terminal; The central-level intelligent site management unit is used to process the valid encrypted data, parse the valid encrypted work data, and obtain the valid work data; The second prediction model is used to perform simulation prediction based on the valid work data and the first prediction result to obtain the second prediction result, and send the second prediction result to the enterprise-level edge computing terminal for data sharing.

7. The petroleum and petrochemical site data security management system according to claim 1, characterized in that, The blockchain storage module includes a data transfer unit and a smart contract formulation unit; The data transfer unit is used to transfer the blockchain transactions stored on the side chain of the blockchain network to the main chain of the blockchain network according to the side chain transfer rules; The smart contract formulation unit is used to formulate the side chain transfer contract.

8. The data security management system for oil and petrochemical sites according to claim 7, characterized in that The side chain transfer contract includes: When the blockchain transaction volume on the side chain of the blockchain network reaches the preset threshold, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network; When the data cycle of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is complete, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network; When the confidentiality level of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is a high confidentiality level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network; When the complexity level of the encrypted work data corresponding to the blockchain transaction on the side chain of the blockchain network is a highly complex level, transfer the blockchain transaction on the side chain of the blockchain network to the main chain of the blockchain network; Set a scheduled transfer time. When the scheduled transfer time arrives, transfer the blockchain transactions on the side chain of the blockchain network to the main chain of the blockchain network.

9. The data security management system for oil and petrochemical sites according to claim 7, characterized in that, The smart contract formulation unit is further configured to formulate an access permission contract and a usage permission contract; Access the encrypted work data stored in the blockchain network according to the formulated access permission contract; Use the encrypted work data stored in the blockchain network according to the formulated usage permission contract.

10. A method for data security management of an oil and petrochemical site, characterized in that, The method includes: Real-time collect the work data of each working device in the oil and petrochemical site through the device unit-level edge computing terminal, and perform real-time processing on the work data of each working device to obtain effective encrypted work data after processing; Receive and store the effective encrypted work data from the device unit-level edge computing terminal through the enterprise-level edge computing terminal, manage the effective encrypted work data transmitted by each device unit-level edge computing terminal, and perform simulation prediction based on the effective encrypted work data to obtain a first prediction result; Through the central cloud computing platform, receive and store the effective encrypted work data and multiple first prediction results from each enterprise-level edge computing terminal, manage the effective encrypted work data transmitted by each enterprise-level edge computing terminal, perform simulation prediction based on the multiple first prediction results to obtain a second prediction result, and send the second prediction result to the enterprise-level edge computing terminal for data sharing; Obtain the effective encrypted work data of the device unit-level edge computing terminal through the blockchain storage module, construct a blockchain transaction on the side of each working device based on the encrypted work data, and upload the constructed blockchain transaction to the side chain of the blockchain network.

11. A computer device, characterized in that, It includes: A memory; A processor; And A computer program; Wherein, the computer program is stored in the memory and is configured to be executed by the processor to implement the oil and petrochemical site data security management method described in claim 10.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer program is executed by the processor to implement the oil and petrochemical site data security management method described in claim 10.