Industrial Internet terminal security access method, system, equipment and medium
By generating security baseline data, collecting biometrics, and building dynamic rotation keys in the industrial Internet, the problem of real-time security monitoring of key updates in terminal communications is solved, dynamic key updates are achieved, and the security and reliability of terminal communications are improved.
Patent Information
- Application Number
- CN202510550632.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2045-04-29
AI Technical Summary
In the existing technology, key updates during terminal communication rely on predefined rules, which makes it difficult to cope with security threats in complex dynamic network environments, resulting in a high risk of key leakage and an inability to meet real-time security monitoring needs.
After accessing the industrial Internet, security baseline data is generated based on preset authentication parameters, biometrics of users entering the network are collected to assign session authentication tokens, a key parameter set is constructed based on the network threat level, and dynamically rotated keys are generated to achieve key updates under real-time security monitoring.
It realizes dynamic key update under real-time security monitoring, reduces the risk of key leakage, and enhances the security of data transmission process and system resource protection.
Smart Images

Figure CN120433914B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of terminal communication security technology. More specifically, the present application relates to an industrial Internet terminal security access method, system, equipment and medium. Background Art
[0002] With the rapid development of the Industrial Internet, terminal devices, as a bridge connecting the physical world and digital systems, have made communication security a core element in ensuring the stable operation of smart manufacturing, smart cities and other fields. Traditional security protection systems based on firewalls and static passwords have been unable to cope with increasingly complex network attacks, such as man-in-the-middle attacks, data tampering, and device counterfeiting. In recent years, terminal communication security technology has shown a dynamic, intelligent, and multi-layered development trend. Combined with technologies such as blockchain and quantum encryption, it has enhanced the tamper-proof nature of data transmission, improved the reliability and traceability of terminal communications, and laid a security foundation for the large-scale deployment of the Industrial Internet.
[0003] Terminal communication security mainly relies on encrypted communication protocols, identity authentication mechanisms, and secure access control. In addition, key management mechanisms play a vital role in communication security. Existing systems generally use symmetric encryption or public key infrastructure to ensure data transmission security. At the same time, security monitoring based on tools such as firewalls, intrusion detection systems, and security information and event management also provides a certain degree of security for terminal communications. However, in existing technologies, traditional security monitoring methods rely on predefined rules to update fixed keys, which makes the terminal communication process vulnerable to security threats brought by key leakage and cannot meet the security requirements of complex dynamic network environments. Therefore, how to achieve dynamic key updates under real-time security monitoring has become a difficult problem faced by the industry. Summary of the Invention
[0004] The present application provides an industrial Internet terminal security access method, system, equipment and medium, which can realize the dynamic update of keys under real-time security monitoring.
[0005] In a first aspect, the present application provides a method for secure access to an industrial Internet terminal, comprising the following steps:
[0006] Connecting the terminal device to the Industrial Internet, performing device access authentication on the terminal device based on preset authentication parameters, and generating security baseline data for the terminal device;
[0007] After the terminal device passes the device access authentication, the biometric features of the user accessing the terminal device are collected, and based on the user authority information corresponding to the biometric features, a session authentication token is allocated to the user accessing the industrial Internet;
[0008] establish a secure communication tunnel for data transmission between the terminal device and the industrial internet based on the session authentication token;
[0009] construct a key parameter set according to the security baseline data and a network threat level when the onboarding user accesses the industrial internet, and generate a dynamic rotation key for the onboarding user's session in the secure communication tunnel based on the key parameter set and a random perturbation factor used to generate the key;
[0010] transmit the onboarding user's session data according to the dynamic rotation key by the terminal device, and update the device security posture of the current terminal device.
[0011] In some embodiments, the terminal device is authenticated based on a preset authentication parameter, and the security baseline data of the terminal device is generated specifically including:
[0012] obtain the device identification information of the terminal device;
[0013] match the device identification information with a preset authentication parameter in an authentication database to obtain a matching relationship corresponding to the terminal device in the authentication process;
[0014] generate the security baseline data of the terminal device based on the matching relationship.
[0015] In some embodiments, the biological characteristics of the onboarding user when accessing the terminal device are collected specifically including:
[0016] connect a biological characteristic collection device to the terminal device and initialize the biological characteristic collection device;
[0017] collect the original biological characteristics of the onboarding user through the biological characteristic collection device;
[0018] preprocess the original biological characteristics to obtain the biological characteristics of the onboarding user when accessing the terminal device.
[0019] In some embodiments, the session authentication token for the onboarding user to access the industrial internet is assigned based on the user permission information corresponding to the biological characteristics specifically including:
[0020] construct a permission management database;
[0021] retrieve the user permission information corresponding to the biological characteristics in the permission management database;
[0022] generate the session authentication token for the onboarding user to access the industrial internet according to the user permission information.
[0023] In some embodiments, establishing a secure communication tunnel for data transmission between a terminal device and the industrial Internet based on the session authentication token specifically includes:
[0024] Parsing the session authentication token through the industrial Internet to obtain credential information corresponding to the session authentication token;
[0025] The industrial Internet allocates corresponding access resources to the terminal device based on the credential information;
[0026] A secure communication tunnel is established between the terminal device and the industrial Internet based on the access resource when the terminal device performs data transmission.
[0027] In some embodiments, constructing a key parameter set based on the security baseline data and the network threat level of the network user when accessing the industrial Internet specifically includes:
[0028] Determining a safety index value corresponding to the safety baseline data;
[0029] Obtaining the network threat level of the network user when accessing the industrial Internet;
[0030] A key parameter set is constructed based on the security indicator value and the threat score corresponding to the network threat level.
[0031] In some embodiments, the user's biometrics are collected through a fingerprint recognition device.
[0032] In a second aspect, the present application provides an industrial Internet terminal security access system, comprising:
[0033] A preprocessing module is used to connect the terminal device to the Industrial Internet, perform device access authentication on the terminal device based on preset authentication parameters, and generate security baseline data for the terminal device;
[0034] A processing module is configured to collect biometric features of a user accessing the terminal device after the terminal device passes device access authentication, and allocate a session authentication token to the user accessing the industrial Internet based on user authority information corresponding to the biometric features;
[0035] The processing module is further configured to establish a secure communication tunnel for data transmission between a terminal device and the industrial Internet based on the session authentication token;
[0036] The processing module is further configured to construct a key parameter set based on the security baseline data and the network threat level of the network user when accessing the industrial Internet, and generate a dynamic rotation key for the network user session in the secure communication tunnel based on the key parameter set and a random perturbation factor for generating a key;
[0037] The execution module is used to transmit the session data of the network user according to the dynamic rotation key by the terminal device, and update the device security status of the current terminal device.
[0038] In a third aspect, the present application provides a computer device comprising a memory and a processor, wherein the memory stores code, and the processor is configured to obtain the code and execute the above-mentioned industrial Internet terminal security access method.
[0039] In a fourth aspect, the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned industrial Internet terminal security access method.
[0040] The technical solutions provided by the embodiments disclosed in this application have the following beneficial effects:
[0041] In the industrial Internet terminal security access method, system, device and medium provided by the present application, first, the terminal device is connected to the industrial Internet, and the terminal device is authenticated for device access based on preset authentication parameters to generate security baseline data of the terminal device; secondly, after the terminal device passes the device access authentication, the biometric characteristics of the network user when accessing the terminal device are collected, and a session authentication token is allocated to the network user when accessing the industrial Internet based on the user authority information corresponding to the biometric characteristics; further, a secure communication tunnel is established with the industrial Internet for terminal device data transmission based on the session authentication token; then, a key parameter set is constructed based on the security baseline data and the network threat level of the network user when accessing the industrial Internet, and a dynamic rotation key for the network user session is generated in the secure communication tunnel based on the key parameter set and the random perturbation factor used to generate the key; finally, the terminal device transmits the session data of the network user based on the dynamic rotation key, and updates the device security status of the current terminal device.
[0042] It can be seen that the present application can realize the dynamic update of keys under real-time security monitoring; first, the terminal device is authenticated based on the preset authentication parameters, and the security baseline data of the terminal device is generated to comprehensively record the relevant information and authentication results of the terminal device, thereby providing a basis for subsequent security management; secondly, the identity information of the network user is matched with the authority based on the biometric characteristics when the network user accesses the terminal device, and then the session authentication token is allocated when the network user accesses the industrial Internet, thereby verifying the user identity and the corresponding authorized resources, so as to effectively realize secure access control and identity authentication; further, a terminal device is established based on the session authentication token and the industrial Internet. A secure communication tunnel is established during data transmission to effectively protect system resources; then, a dynamic rotation key is generated in the secure communication tunnel for the user's session based on the security baseline data and the network threat level when the user accesses the industrial Internet, thereby realizing dynamic update of the key to reduce the risk of key leakage, thereby enhancing the security of the data transmission process; finally, the terminal device transmits the session data of the user based on the dynamic rotation key, and updates the device security status of the current terminal device, so as to perform real-time dynamic monitoring and management of the data transmission and key update process; in summary, the technical solution provided by the present application can realize the dynamic update of the key under real-time security monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 This is an exemplary flow chart of a method for securely accessing an industrial Internet terminal according to some embodiments of the present application;
[0044] Figure 2 is an exemplary flow chart of establishing a secure communication tunnel according to some embodiments of the present application;
[0045] Figure 3 is an exemplary flow chart for determining a security index value according to some embodiments of the present application;
[0046] Figure 4 This is a schematic diagram of the structure of the industrial Internet terminal security access system according to some embodiments of the present application;
[0047] Figure 5 It is a structural diagram of a computer device for implementing a method for secure access to industrial Internet terminals according to some embodiments of the present application. DETAILED DESCRIPTION
[0048] In order to better understand the technical solution of the present application, the technical solution of the present application will be described in detail below with reference to the accompanying drawings and specific implementation methods.
[0049] refer to Figure 1, which is an exemplary flow chart of a method for securely accessing an industrial Internet terminal according to some embodiments of the present application. The method 100 for securely accessing an industrial Internet terminal mainly includes the following steps:
[0050] In step 101, the terminal device is connected to the industrial Internet, the terminal device is authenticated based on preset authentication parameters, and security baseline data of the terminal device is generated.
[0051] In specific implementation, the terminal device is connected to the industrial Internet, that is: first, the device type of the terminal device is determined, and a corresponding industrial gateway is equipped for it to ensure the compatibility of the communication interface and protocol of the terminal device and the gateway; secondly, the terminal device is connected to the industrial gateway through wireless communication, and the network parameters of the industrial gateway are configured to complete device identification. In addition, in other embodiments, the connection can also be made through other methods, such as field bus, etc., which are not limited here; then, the industrial gateway is connected to the industrial Internet through the industrial Ethernet network, thereby completing the connection of the terminal device to the industrial Internet.
[0052] It should be noted that the terminal device in this application refers to a device that can be connected to a network system and perform functions such as data acquisition, control, and communication. The core feature of the terminal device is that it has data interaction capabilities. In addition, it should be noted that the industrial Internet in this application refers to an intelligent and interconnected industrial network system built by deeply integrating industrial systems, equipment, production processes with digital technologies such as the Internet, cloud computing, artificial intelligence, and big data, and has an authentication server that can provide authentication services. The industrial Internet optimizes production and management through intelligent technology.
[0053] In some embodiments, the terminal device is subjected to device access authentication based on preset authentication parameters, and the security baseline data of the terminal device is generated in the following manner, namely:
[0054] Obtaining device identification information of the terminal device;
[0055] Matching the device identification information with the authentication parameters preset in the authentication database to obtain a corresponding matching relationship of the terminal device during the authentication process;
[0056] The security baseline data of the terminal device is generated based on the matching relationship.
[0057] In a specific implementation, the device identifier information of the terminal device is acquired, that is, after the terminal device accesses the industrial internet, the device identifier information of the terminal device is acquired through a preset interface, and the device identifier information includes a device model, a device serial number, a hardware fingerprint, an operating system version, an installed software list, an IP address, a MAC address, a subnet mask, and a gateway address. It should be noted that the preset interface in this embodiment includes a device management interface, an operating system API, and a network protocol stack interface. Through the preset interface, the hardware information, software information, and network information of the terminal device can be acquired.
[0058] In a specific implementation, the device identifier information is matched with preset authentication parameters in an authentication database to obtain a matching relationship corresponding to the terminal device in an authentication process, that is, the device identifier information is matched with authentication parameters pre-stored in the authentication database, and the authentication parameters include a list of compliant device models, a white list of device serial numbers, an authorized operating system version range, security software installation requirements, and network configuration rules. If the device identifier information is consistent with the corresponding rules in the authentication parameters, it is determined that the terminal device passes the device access authentication. If any item of the device identifier information does not match the preset authentication parameters, it is determined that the terminal device does not pass the device access authentication, and the determination result is used as the matching relationship corresponding to the terminal device in the authentication process.
[0059] In a specific implementation, the security baseline data of the terminal device is generated based on the matching relationship, that is, first, for the matching relationship corresponding to the terminal device that does not pass the device access authentication, the security baseline data includes specific mismatch item information, and for the matching relationship corresponding to the terminal device that passes the device access authentication, the security baseline data includes a device firmware version, an operating system version, a security patch status, a history of security events of the device, and a current network status. Then, the generated security baseline data is stored in a security management server and can be accessed and called by subsequent processes to dynamically adjust a response mechanism based on a security state.
[0060] It should be noted that the security baseline data in this application represents a security management document generated after the terminal device accesses the industrial internet. By generating the security baseline data, the device security posture and related information and authentication results of the terminal device can be comprehensively recorded, thereby providing a basis for subsequent security management.
[0061] In step 102, after the terminal device passes the device access authentication, the biometric features of a network access user accessing the terminal device are collected, and a session authentication token of the network access user when accessing the industrial internet is assigned based on user permission information corresponding to the biometric features.
[0062] In some embodiments, the biological feature of the user accessing the terminal device can be collected in the following manner, that is:
[0063] connecting the biological feature collection device with the terminal device and initializing the biological feature collection device;
[0064] collecting the original biological feature of the user accessing the terminal device through the biological feature collection device;
[0065] preprocessing the original biological feature to obtain the biological feature of the user accessing the terminal device.
[0066] In a specific implementation, the biological feature collection device is connected with the terminal device and the biological feature collection device is initialized, that is, first, the biological feature collection device is connected with the terminal device, and in this embodiment, a fingerprint identification instrument is selected as the biological feature collection device, and in other embodiments, other biological feature collection devices can also be selected, for example, a face recognition camera, an iris identification instrument, and the like, which are not limited here; then, it is checked whether the sensor surface of the biological feature collection device is clean, and whether the circuit connection state and the data transmission state are normal through the sending of a self-checking instruction; finally, the resolution and sensitivity of the biological feature collection device are set, and the specific parameters can be set according to actual application requirements, which are not limited here.
[0067] In a specific implementation, the original biological feature of the user accessing the terminal device is collected through the biological feature collection device, that is, first, the biological feature collection device scans the fingerprint information on the surface of the finger of the user accessing the terminal device through a sensor, and converts the fingerprint information into digital image data; then, the collected digital image data is transmitted to the terminal device as the original biological feature of the user accessing the terminal device, so as to facilitate subsequent identity verification and management.
[0068] In a specific implementation, the original biological feature is preprocessed to obtain the biological feature of the user accessing the terminal device, that is, the original biological feature is preprocessed through Open CV, and the preprocessed original biological feature is taken as the biological feature of the user accessing the terminal device, and the preprocessing includes denoising, normalization, and feature extraction, and the biological feature obtained through preprocessing has stronger feature expression capability, so that the matching accuracy can be improved.
[0069] In some embodiments, the session authentication token of the user accessing the industrial internet can be allocated in the following manner based on the user permission information corresponding to the biological feature, that is:
[0070] constructing a permission management database;
[0071] retrieving user permission information corresponding to the biometric feature from the permission management database;
[0072] generating a session authentication token for the user accessing the industrial internet according to the user permission information.
[0073] In a specific implementation, a permission management database is constructed, that is, biometric information of all users having access to the industrial internet is collected, and the collected biometric information and the permission corresponding to each user are stored in the database, so as to complete the construction of the permission management database. The permission management database represents a database for storing and managing user permission information in the system. By constructing the permission management database, access control and permission management can be realized, thereby ensuring the security and integrity of system resources.
[0074] It should be noted that in the present embodiment, the user permission information represents related data for specifying the permissions and restrictions of the user on various resources and operations. The user permission information is stored in the form of a permission list, including the identity of the user, the type of accessible industrial internet resources, and operation permissions. In addition, in other embodiments, the user permission information can also contain other contents, which are not limited here. By determining the user permission information, the security of the data can be improved. As a preferred embodiment, the user permission information corresponding to the biometric feature is retrieved from the permission management database in the following manner:
[0075] determining the similarity matching degree between the biometric feature and each biometric feature information in the permission management database;
[0076] determining the user permission information corresponding to the biometric feature based on all the similarity matching degrees.
[0077] In a specific implementation, the similarity matching degree between the biometric feature and each biometric feature information in the permission management database is determined, that is, the cosine similarity between the biometric feature and each biometric feature information in the permission management database is calculated, and the calculation result is taken as the similarity matching degree between the biometric feature and each biometric feature information in the permission management database.
[0078] In specific implementation, the user authority information corresponding to the biometric feature is determined based on all similarity matching degrees, that is: first, a matching threshold is set. When the similarity matching degree is higher than the matching threshold, the biometric feature is determined to be matched successfully, and the corresponding user identity is obtained. When the similarity matching degree is lower than the matching threshold, the match is determined to be failed, the subsequent process is terminated, and the identity authentication failure information is fed back to the user; then, based on the user identity obtained by the successful match, the authority corresponding to the user is queried in the authority management database, and the authority obtained by the query is used as the user authority information corresponding to the biometric feature.
[0079] In a specific implementation, a session authentication token is generated for the network user to access the industrial Internet based on the user permission information, that is: first, a token generation algorithm is used to generate a session authentication token for the network user to access the industrial Internet based on the user permission information. Specifically, a JWT (JSON Web Token, JWT) generation algorithm can be used to encode the user identity, permission information, and credential validity period into the session authentication token, and the HMAC SHA-256 signature algorithm is used to sign the session authentication token to ensure the integrity and non-tamperability of the identification information; then, the generated session authentication token is sent to the terminal device for use by the network user to access the industrial Internet.
[0080] It should be noted that the session authentication token in this application represents a security credential used to verify user identity and authorize resources in computer systems and network applications. It is an important protection mechanism for implementing secure access control and identity authentication. By generating a session authentication token, system resources can be effectively protected while providing a convenient user experience.
[0081] In step 103, a secure communication tunnel is established between the terminal device and the industrial Internet based on the session authentication token for data transmission.
[0082] In some embodiments, reference Figure 2 As shown in FIG, this figure is an exemplary flow chart of establishing a secure communication tunnel according to some embodiments of the present application. In this embodiment, the secure communication tunnel for data transmission between the terminal device and the industrial Internet based on the session authentication token can be implemented by the following steps:
[0083] First, in step 1031, the session authentication token is parsed through the industrial Internet to obtain credential information corresponding to the session authentication token;
[0084] Then, in step 1032, the industrial Internet allocates corresponding access resources to the terminal device based on the credential information;
[0085] Finally, in step 1033, a secure communication tunnel is established between the terminal device and the industrial Internet based on the access resource for the terminal device to transmit data.
[0086] In specific implementation, the session authentication token is parsed through the industrial Internet to obtain the credential information corresponding to the session authentication token, that is: first, the terminal device sends the session authentication token to the authentication server of the industrial Internet, and the authentication server verifies the format of the session authentication token after receiving the session authentication token; secondly, the signature of the session authentication token is verified by the authentication server to ensure that the session authentication token has not been tampered with after the above processing; then, if the signature verification is successful, the user identity, permission information, and credential validity period in the session authentication token are extracted, and the extracted information is used as the credential information corresponding to the session authentication token; it should be noted that after extracting the credential information, the authentication server needs to check the credential validity period. If the session authentication token has expired, the authentication server rejects the communication request of the terminal device and prompts the network user to obtain a valid credential again. If the session authentication token is within the validity period, the subsequent operations continue.
[0087] In specific implementation, the industrial Internet allocates corresponding access resources to the terminal device based on the credential information, that is: first, the authentication server of the industrial Internet performs an authorization check on the permission information in the credential information to ensure that the resources and operations requested by the terminal device to access are within the limited permission range. If the request exceeds the permission range, the authentication server will reject the request and return a corresponding error message; then, after the authorization check is passed, the authentication server of the industrial Internet allocates corresponding access resources to the terminal device based on the permission information in the credential information. For example, if the credential information indicates that the network user has the permission to access the production equipment data, the authentication server will open access rights to the production equipment data interface to the terminal device.
[0088] In specific implementation, a secure communication tunnel is established between the terminal device and the industrial Internet based on the access resource for the terminal device to transmit data, that is: first, the communication protocol and port between the terminal device and the industrial Internet are determined based on the type of the terminal device, the access resource and the nature of the transmitted data; secondly, based on the selected communication protocol, the terminal device and the industrial Internet perform a handshake process. Specifically, both ends of the communication send confirmation messages to each other, indicating that the secure communication tunnel has been successfully established. The digital identities of each other are verified through the handshake process to ensure that both parties reach an agreement on the establishment of the secure communication tunnel; then, the terminal device and the industrial Internet start to monitor their respective communication ports. At this time, the terminal device can send data requests or upload data to the industrial Internet in accordance with the established communication protocol and permissions, and the industrial Internet server can also push relevant data and instructions to the terminal device.
[0089] In step 104, a key parameter set is constructed based on the security baseline data and the network threat level of the network user when accessing the industrial Internet, and a dynamic rotation key for the network user session is generated in the secure communication tunnel based on the key parameter set and the random perturbation factor used to generate the key.
[0090] In some embodiments, the key parameter set may be constructed based on the security baseline data and the network threat level of the network user when accessing the industrial Internet in the following manner, namely:
[0091] Determining a safety index value corresponding to the safety baseline data;
[0092] Obtaining the network threat level of the network user when accessing the industrial Internet;
[0093] A key parameter set is constructed based on the security indicator value and the threat score corresponding to the network threat level.
[0094] It should be noted that the security index value in this embodiment represents a numerical indicator for quantitatively evaluating the security status of the system. Specifically, the security index value in this embodiment refers to a security assessment indicator for the terminal device based on the security baseline data. The security index value converts the complex security status into a specific numerical value so that relevant researchers can quickly understand the security status of the terminal device. The higher the security index value, the better the security. Conversely, it indicates a higher security risk. By determining the security index value, a basis for security decision-making can be provided. As a preferred embodiment, reference Figure 3 As shown in FIG. 1 , this figure is an exemplary flow chart for determining a security index value according to some embodiments of the present application. In this embodiment, determining the security index value corresponding to the security baseline data can be achieved by using the following steps:
[0095] Firstly, in step 1041, the firmware version, the operating system version, the security patch state, the historical security events of the device and the network status of the terminal device are extracted from the security baseline data;
[0096] Then, in step 1042, the weight proportions of the firmware version, the operating system version, the security patch state, the historical security events of the device and the network status are determined respectively;
[0097] Further, in step 1043, the element scores corresponding to the firmware version, the operating system version, the security patch state, the historical security events of the device and the network status are determined respectively;
[0098] Finally, in step 1044, the security index value corresponding to the security baseline data is determined based on all the element scores and the weight proportions corresponding to each element score.
[0099] In specific implementation, the weight proportions of the firmware version, the operating system version, the security patch state, the historical security events of the device and the network status are determined respectively, that is, according to the business characteristics of the industrial internet and the statistics of past security incidents, the firmware version, the operating system version, the security patch state, the historical security events of the device and the network status are respectively assigned with corresponding weight proportions, and the specific weight values can be set according to actual application requirements, which are not limited here, for example, the weight proportions of the firmware version, the operating system version, the security patch state, the historical security events of the device and the network status are set as 20%, 20%, 20%, 15% and 25% respectively.
[0100] In a specific implementation, factor scores corresponding to the firmware version, the operating system version, the security patch status, the historical security events of the device, and the network status are determined respectively. That is, for the firmware version and the operating system version, the firmware version and the operating system version are compared with the latest versions released by the corresponding manufacturers. If the versions are the same or the difference is within an acceptable range, the corresponding factor score is set to full score. If the version is too low and there is a known security vulnerability, the vulnerability risk level is determined with the help of the CVE (Common Vulnerabilities and Exposures, CVE) database, and points are deducted according to the corresponding rules. For the security patch status, the difference between the installed patch and the patch released by the current manufacturer is analyzed. If a critical security patch is not installed, the factor score is deducted accordingly based on the importance of the patch. The importance can refer to the patch weight in the NVD (National Vulnerability Database, NVD). For the historical security events of the device, the attack type and frequency of security events occurring in the terminal device are counted, and a Poisson distribution model is constructed to output the risk probability value as the corresponding factor score. For the network status, the network connection features collected in real time, such as abnormal ports and traffic mutations, are combined with LSTM (Long short-term memory, LSTM) neural network to classify threat levels and output a standardized score of 0-1 as the corresponding factor score.
[0101] In specific implementation, the security index value corresponding to the security baseline data is determined based on all factor scores and the weight ratio corresponding to each factor score, that is: first, all factor scores are converted to the same scale through the Min-Max normalization method, so as to avoid calculation errors caused by different data scales; then, the normalized factor scores are weighted and summed, and the calculation result is used as the security index value corresponding to the security baseline data, wherein the weight corresponding to each factor score is its corresponding weight ratio.
[0102] In specific implementation, the network threat level of the network user when accessing the industrial Internet is obtained, that is: the network threat level of the network user when accessing the industrial Internet is obtained through the intrusion detection system, abnormal traffic analysis, and threat intelligence platform deployed in the industrial Internet network. The network threat level can be divided into low, medium, high, and severe, and different levels represent different degrees of security risks.
[0103] In a specific implementation, a key parameter set is constructed based on the security index value and the threat score corresponding to the network threat level, that is: first, a mapping level model is constructed to assign a corresponding score to each network threat level to obtain a threat score corresponding to the network threat level. The specific score division can be set based on historical network security assessment experience and is not limited here. For example, the threat score for the low risk level is set to 30, the threat score for the medium risk level is set to 60, the threat score for the high risk level is set to 85, and the threat score for the severe level is set to 100; then, the device identification information of the terminal device is obtained, and the device identification information, the security index value and the threat score are integrated into a set, and the set is used as the key parameter set when generating the key.
[0104] In some embodiments, the dynamic rotation key for generating an incoming user session in the secure communication tunnel based on the key parameter set and the random perturbation factor used to generate the key may be generated in the following manner, namely:
[0105] determining a random perturbation factor used to generate a key;
[0106] Determining a security trigger value for generating a key based on the key parameter set and the random perturbation factor;
[0107] A dynamic rotation key is generated in the secure communication tunnel for an incoming user session based on the security trigger value.
[0108] In the specific implementation, the random perturbation factor used to generate the key is determined. That is, in order to enhance the randomness and security of the key, a random number of fixed length is generated through a cryptographically secure pseudo-random number generator, and the generated random number is used as the random perturbation factor for generating the key. Specifically, a 16-byte random number can be generated through a pseudo-random number generation algorithm based on the AES-CTR mode.
[0109] In a specific implementation, a security trigger value for generating a key is determined based on the key parameter set and the random perturbation factor. That is, a SHA-256 hash algorithm is used to perform a hash operation on the key parameter set and the random perturbation factor to obtain a fixed-length, irreversible hash value. The hash value is used as the security trigger value for generating the key, thereby achieving preliminary obfuscation of information and improving the security of subsequent key generation.
[0110] In a specific implementation, a dynamic rotation key for a user session on the network is generated in the secure communication tunnel based on the security trigger value, that is: first, based on the security trigger value, a key derivation function HKDF (HMAC-based KeyDerivation Function, HKDF) is used to generate a master key material with the security trigger value as an input parameter. The HKDF function expands the input data into the master key material through an algorithm, thereby enhancing the security and randomness of the key; then, since different communication scenarios have different requirements for key length, a byte sequence of corresponding length is intercepted from the master key material according to the key length required by the secure communication tunnel as an initial dynamic rotation key; further, in order to ensure that even if part of the data is stolen during the communication process, the key is difficult to be cracked, a secure Diffie-Hellman key exchange protocol is used between the terminal device and the industrial Internet server, and the initial dynamic rotation key is used as a seed to generate a dynamic rotation key for a user session on the network; finally, the generated dynamic rotation key is stored in a secure storage area, for example, TPM 2.0 secure enclave, which is used to subsequently encrypt and decrypt transmitted data in the secure communication tunnel to ensure the confidentiality and integrity of communications. It should be noted that this embodiment only calls the above-mentioned algorithms and protocols and optimizes the input parameters. As a prior art, the specific implementation process of the algorithms and protocols will not be repeated here.
[0111] It should also be noted that the dynamic rotation key in this application refers to an encryption key that is dynamically generated and updated as the session, time or environmental conditions change. Unlike static keys, dynamic rotation keys will not remain fixed for a long time, but will be refreshed regularly or generated on demand according to security policies to ensure that even if the key at a certain moment is stolen by an attacker, the key cannot be used to decrypt communication data for a long time. By generating dynamic rotation keys, the risk of key leakage can be reduced, thereby enhancing the security of the data transmission process.
[0112] In step 105, the terminal device transmits the session data of the network user according to the dynamic rotation key, and updates the device security status of the current terminal device.
[0113] In a specific implementation, the terminal device transmits the session data of the networked user based on the dynamic rotation key and updates the device security status of the current terminal device, namely: first, the terminal device encrypts the session data of the networked user based on the dynamic rotation key, specifically, uses a symmetric encryption algorithm to encrypt the session data to generate encrypted session data, and sends the encrypted session data to the server of the industrial Internet through the established secure communication tunnel; secondly, uses a data verification mechanism to attach a verification code to the encrypted session data so that the recipient can perform integrity verification to prevent data tampering, specifically, the data hash value of the encrypted session data can be calculated by a hash algorithm, and the data hash value is sent together with the encrypted session data to the server of the industrial Internet; further, after receiving the encrypted session data, the industrial Internet server decrypts the data based on the dynamic rotation key, uses the same symmetric encryption algorithm as the terminal device for reverse decryption, and restores the encrypted session data to a plaintext data In addition, the industrial Internet server verifies the integrity of the decrypted plaintext data by comparing the data hash value received from the terminal device with the recalculated plaintext data hash value to ensure the integrity of the data. If the verification passes, the plaintext data is further processed and stored. If the verification fails, an error message is sent to the terminal device, requesting the data to be resent. Finally, after completing the session data transmission, the terminal device collects relevant security information during the session, including transmission time, transmission data volume, whether a transmission error occurred, etc., and checks the running status of the security software. The collected information is used as the new device security situation to update the security baseline data. If a security incident occurs during the session, such as a transmission error or detection of abnormal network traffic, it is necessary to record the type, occurrence time and possible impact of the incident in detail in the new baseline data, store the updated security baseline data in the local storage of the terminal device, and upload it to the server of the industrial Internet for real-time dynamic monitoring and management of the data transmission process.
[0114] In addition, in another aspect of the present application, in some embodiments, the present application provides an industrial Internet terminal security access system, referring to Figure 4 , which is a schematic diagram of the structure of an industrial Internet terminal security access system according to some embodiments of the present application. The industrial Internet terminal security access system 200 includes: a pre-processing module 201, a processing module 202 and an execution module 203, which are described as follows:
[0115] Preprocessing module 201, in this application, the preprocessing module 201 is mainly used to connect the terminal device to the industrial Internet, perform device access authentication on the terminal device based on preset authentication parameters, and generate security baseline data for the terminal device;
[0116] The processing module 202 is mainly used to collect the biological characteristics of the user accessing the terminal device after the terminal device passes the device access authentication, and distribute the session authentication token of the user accessing the industrial internet based on the user permission information corresponding to the biological characteristics.
[0117] The processing module 202 is also used to establish a secure communication tunnel for data transmission of the terminal device based on the session authentication token and the industrial internet.
[0118] In addition, the processing module 202 is also used to construct a key parameter set according to the security baseline data and the network threat level of the user accessing the industrial internet, and generate a dynamic rotation key for the session of the user accessing the industrial internet based on the key parameter set and a random disturbance factor for generating a key in the secure communication tunnel.
[0119] The execution module 203 is mainly used to transmit the session data of the user accessing the terminal device according to the dynamic rotation key, and update the device security posture of the current terminal device.
[0120] In addition, the present application also provides a computer device, which comprises a memory and a processor, the memory stores codes, and the processor is configured to acquire the codes and execute the above-mentioned industrial internet terminal security access method.
[0121] In some embodiments, referring to Figure 5 The figure is a structural schematic diagram of a computer device for implementing the industrial internet terminal security access method according to some embodiments of the present application. The industrial internet terminal security access method in the above-mentioned embodiments can be implemented by the computer device shown in the figure, which is a computer device 300. Figure 5 The computer device 300 comprises at least one processor 301, a communication bus 302, a memory 303 and at least one communication interface 304.
[0122] The processor 301 can be a general central processing unit (CPU), an application-specific integrated circuit (ASIC) or one or more circuits for controlling the execution of the industrial internet terminal security access method in the present application.
[0123] The communication bus 302 can be used to transmit information between the above-mentioned components.
[0124] The memory 303 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM), or other type of dynamic storage device that can store information and instructions, and can be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disk storage, a magneto-optical disk, a magnetic disk or other magnetic storage device, or any other medium capable of storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto. The memory 303 can exist independently, and is connected to the processor 301 through the communication bus 302. The memory 303 can also be integrated with the processor 301.
[0125] The memory 303 is configured to store program codes for implementing the solutions of the present application, and the processor 301 is configured to execute the program codes stored in the memory 303. The program codes can include one or more software modules. The determination of the industrial internet terminal secure access method in the above embodiments can be implemented by one or more software modules in the program codes in the processor 301 and the memory 303.
[0126] The communication interface 304 is configured to communicate with other devices or communication networks, such as an Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc., using any transceiver-like device.
[0127] In a specific implementation, as an example, the computer device can include a plurality of processors, each of which can be a single-CPU processor or a multi-CPU processor. The processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0128] The aforementioned computer device can be a general-purpose computer device or a dedicated computer device. In a specific implementation, the computer device can be a desktop computer, a portable computer, a network server, a personal digital assistant (PDA), a mobile phone, a tablet computer, a wireless terminal device, a communication device, or an embedded device. The embodiments of this application do not limit the type of computer device.
[0129] In addition, the present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned industrial Internet terminal security access method.
[0130] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.
[0131] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A method for secure access to industrial Internet terminals, characterized in that: The steps include: Connecting the terminal device to the Industrial Internet, performing device access authentication on the terminal device based on preset authentication parameters, and generating security baseline data for the terminal device; After the terminal device passes the device access authentication, the biometric features of the user accessing the terminal device are collected, and based on the user authority information corresponding to the biometric features, a session authentication token is allocated to the user accessing the industrial Internet; Establishing a secure communication tunnel for data transmission between a terminal device and the industrial Internet based on the session authentication token; Constructing a key parameter set based on the security baseline data and the network threat level of the network user when accessing the industrial Internet, and generating a dynamic rotation key for the network user session in the secure communication tunnel based on the key parameter set and a random perturbation factor used to generate the key; The terminal device transmits the session data of the network user according to the dynamic rotation key and updates the device security status of the current terminal device.
2. The method according to claim 1, wherein Performing device access authentication on the terminal device based on preset authentication parameters to generate security baseline data for the terminal device specifically includes: Obtaining device identification information of the terminal device; Matching the device identification information with the authentication parameters preset in the authentication database to obtain a corresponding matching relationship of the terminal device during the authentication process; The security baseline data of the terminal device is generated based on the matching relationship.
3. The method according to claim 1, wherein The biometric characteristics of the user accessing the terminal device are collected, specifically including: Connecting a biometric feature collection device to the terminal device and initializing the biometric feature collection device; Collecting original biometrics of the user joining the network through the biometrics collection device; The original biometric features are pre-processed to obtain the biometric features of the network user when accessing the terminal device.
4. The method according to claim 1, wherein Allocating a session authentication token for the network user to access the industrial Internet based on the user authority information corresponding to the biometric feature specifically includes: Build a rights management database; Retrieving user authority information corresponding to the biometric feature in the authority management database; A session authentication token is generated based on the user authority information for the network user to access the industrial Internet.
5. The method according to claim 1, wherein Establishing a secure communication tunnel for data transmission between the terminal device and the industrial Internet based on the session authentication token specifically includes: Parsing the session authentication token through the industrial Internet to obtain credential information corresponding to the session authentication token; The industrial Internet allocates corresponding access resources to the terminal device based on the credential information; A secure communication tunnel is established between the terminal device and the industrial Internet based on the access resource when the terminal device performs data transmission.
6. The method according to claim 1, wherein Constructing a key parameter set based on the security baseline data and the network threat level of the network user when accessing the industrial Internet specifically includes: Determining a safety index value corresponding to the safety baseline data; Obtaining the network threat level of the network user when accessing the industrial Internet; A key parameter set is constructed based on the security indicator value and the threat score corresponding to the network threat level.
7. The method according to claim 1, wherein The user's biometrics are collected through a fingerprint recognition device.
8. An industrial Internet terminal security access system, characterized in that: include: A preprocessing module is used to connect the terminal device to the Industrial Internet, perform device access authentication on the terminal device based on preset authentication parameters, and generate security baseline data for the terminal device; A processing module is configured to collect biometric features of a user accessing the terminal device after the terminal device passes device access authentication, and allocate a session authentication token to the user accessing the industrial Internet based on user authority information corresponding to the biometric features; The processing module is further configured to establish a secure communication tunnel for data transmission between a terminal device and the industrial Internet based on the session authentication token; The processing module is further configured to construct a key parameter set based on the security baseline data and the network threat level of the network user when accessing the industrial Internet, and generate a dynamic rotation key for the network user session in the secure communication tunnel based on the key parameter set and a random perturbation factor for generating a key; The execution module is used to transmit the session data of the network user according to the dynamic rotation key by the terminal device, and update the device security status of the current terminal device.
9. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores code, and the processor is configured to obtain the code and execute the industrial Internet terminal security access method as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the industrial Internet terminal security access method as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Method for performing security configuration on Nginx server based on SSR baseline library
CN107104985A
Access control method and device, terminal, connector and storage medium
CN113472758A