Industrial internet data sharing method, device and equipment and storage medium

Through the data sharing system combined with quantum network and wireless communication network, the authentication management unit authentication and encrypted line transmission are used to solve the problems of complex lines and insufficient security in industrial Internet data sharing, and efficient and secure data sharing and storage are achieved.

CN120455097APending Publication Date: 2025-08-08INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510633179.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-16
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing industrial Internet data sharing methods are limited by wired connections, resulting in complex lines, dispersed storage data, high sharing pressure, and insufficient security.

Method used

A data sharing system combining quantum network and wireless communication network is adopted to authenticate, generate keys and establish encrypted lines through authentication management units to achieve secure transmission and storage of data.

Benefits of technology

It improves the efficiency and security of industrial Internet data sharing, reduces the use of lines in hardware equipment, simplifies fault repair, and ensures the consistency and accuracy of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455097A_ABST
    Figure CN120455097A_ABST
Patent Text Reader

Abstract

The invention discloses an industrial internet data sharing method and device, equipment and a storage medium, and relates to the technical field of data security, and the method comprises the steps: transmitting first target data to second industrial equipment through first industrial equipment, and transmitting a first equipment authentication application of the second industrial equipment to a preset authentication management unit; after the second industrial equipment passes the authentication, generating a key acquisition application by using a preset authentication management unit, determining a target key based on the key acquisition application, and storing the target key to target quantum key management equipment; generating an encrypted line in the communication terminal based on the target key through the target quantum key management device, so that the first industrial device sends second target data to the second industrial device through the encrypted line; and sending a second equipment authentication application of the second industrial equipment to a preset authentication management unit, and storing the first target data and the second target data based on an authentication result. According to the invention, the efficiency and security of industrial internet data sharing can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to an industrial Internet data sharing method, device, equipment and storage medium. Background Art

[0002] The Industrial Internet encompasses four major systems: networks, platforms, data, and security. It serves as the infrastructure for the digital, networked, and intelligent transformation of industry, as well as an application model for the deep integration of the internet, big data, artificial intelligence, and the real economy. It also represents a new business model and industry that will reshape businesses, supply chains, and industrial chains. The Industrial Internet connects industrial equipment, systems, and intelligent terminals to form an integrated, collaborative network. With the rapid development of industrial automation and intelligentization, the interaction and sharing of industrial data are becoming increasingly important. Existing Industrial Internet data sharing methods and systems, in practical applications, rely on data interfaces and data models to support transmission between industrial equipment and systems. These methods rely on proximity-based data sharing, which is limited by wired connections, resulting in complex wiring. Furthermore, near-source storage requires the use of multiple memory devices, resulting in fragmented data storage that must be subsequently shared and processed, placing significant pressure on data sharing across multiple industrial devices.

[0003] To sum up, how to improve the efficiency and security of industrial Internet data sharing is a technical problem that needs to be solved urgently. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide an industrial Internet data sharing method, device, equipment and storage medium, which can improve the efficiency and security of industrial Internet data sharing. The specific solution is as follows:

[0005] In a first aspect, the present application provides an industrial Internet data sharing method, which is applied to a data sharing system; wherein the method includes:

[0006] Using the first industrial device to send the first target data to the second industrial device through the communication terminal, and sending the first device authentication application corresponding to the second industrial device to the preset authentication management unit through the communication terminal, so as to authenticate the second industrial device using the preset authentication management unit;

[0007] After the second industrial device passes authentication, generating a key acquisition application using the preset authentication management unit, determining a target key based on the key acquisition application, and storing the target key in a target quantum key management device;

[0008] generating, by the target quantum key management device, an encrypted line in the communication terminal based on the target key, so that the first industrial device sends second target data to the second industrial device through the encrypted line; the second target data being verification data corresponding to the first target data;

[0009] The second industrial device is used to send a second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain a corresponding authentication result, and the first target data and the second target data are stored based on the authentication result.

[0010] Optionally, the data sharing system includes a quantum network and a wireless communication network; wherein, the quantum network includes a target quantum key source and the target quantum key management device, the wireless communication network includes industrial equipment, the communication terminal, the preset authentication management unit and a preset storage unit, and the quantum network and the wireless communication network communicate through the communication terminal.

[0011] Optionally, the sending of the first target data to the second industrial device via the communication terminal using the first industrial device includes:

[0012] Using the communication terminal to encode the first target data sent by the first industrial device based on a preset data processing rule to obtain information bits corresponding to the first target data, and determining a target coding symbol corresponding to the first target data based on the information bits;

[0013] The target coding symbol is sent to the wireless channel of the communication terminal, so that the second industrial device receives the target coding symbol from the wireless channel based on the preset data processing rule, determines the information bit corresponding to the target coding symbol based on a preset channel equalization technology and a preset demodulation processing technology, and determines the first target data based on the information bit.

[0014] Optionally, the first target data includes target transmission data and target receiving device information;

[0015] Correspondingly, the authenticating the second industrial device by using the preset authentication management unit includes:

[0016] Using the preset authentication management unit to obtain the target receiving device information corresponding to the first target data and the first device authentication information corresponding to the second industrial device through the communication terminal;

[0017] Based on the first device authentication information, it is determined whether the second industrial device is consistent with the target receiving device information corresponding to the first target data, and a corresponding authentication result is generated based on the judgment result, so that the key acquisition application is generated when the authentication result indicates that the second industrial device has passed the authentication.

[0018] Optionally, determining a target key based on the key acquisition application and storing the target key in a target quantum key management device includes:

[0019] Using the preset authentication management unit to send the key acquisition application to the target quantum key management device through the communication terminal, and using the target quantum key management device to send the key acquisition application to a target quantum key source;

[0020] Generate an initial key based on a channel comparison basis vector result through the target quantum key source, and determine the target key corresponding to the initial key based on a preset error correction mechanism and a preset privacy amplification mechanism;

[0021] The target key is sent to the target quantum key management device by using the target quantum key source, so that the target quantum key management device stores the target key.

[0022] Optionally, the industrial Internet data sharing method further includes:

[0023] Determine a preset encryption function and a preset decryption function based on a symmetric encryption algorithm;

[0024] Accordingly, the first industrial device sends the second target data to the second industrial device through the encrypted line, including:

[0025] determining, through the encryption line, target encrypted data corresponding to the second target data sent by the first industrial device to the encryption line based on the target key and the preset encryption function;

[0026] The second target data corresponding to the target encrypted data is determined based on the target key and the preset decryption function through the encryption circuit, so that the second industrial device obtains the second target data from the encryption circuit.

[0027] Optionally, storing the first target data and the second target data based on the authentication result includes:

[0028] The preset authentication management unit is used to send the authentication result to the communication terminal, and when the authentication result indicates that the second industrial device has passed authentication, the communication terminal is used to send the first target data and the second target data to a preset storage unit, so that the preset storage unit stores the first target data and the second target data based on a preset block and a target data sharing time corresponding to the first target data.

[0029] In a second aspect, the present application provides an industrial Internet data sharing device, which is applied to a data sharing system; wherein the device includes:

[0030] a device authentication module, configured to use a first industrial device to send first target data to a second industrial device via a communication terminal, and to send a first device authentication application corresponding to the second industrial device to a preset authentication management unit via the communication terminal, so as to authenticate the second industrial device using the preset authentication management unit;

[0031] a target key determination module, configured to generate a key acquisition application using the preset authentication management unit after the second industrial device passes authentication, determine a target key based on the key acquisition application, and store the target key in a target quantum key management device;

[0032] a second target data sending module, configured to generate an encrypted line in the communication terminal based on the target key through the target quantum key management device, so that the first industrial device sends second target data to the second industrial device through the encrypted line; the second target data is verification data corresponding to the first target data;

[0033] The data storage module is used to use the second industrial device to send a second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain a corresponding authentication result, and store the first target data and the second target data based on the authentication result.

[0034] In a third aspect, the present application provides an electronic device, comprising:

[0035] Memory, used to store computer programs;

[0036] A processor is used to execute the computer program to implement the aforementioned industrial Internet data sharing method.

[0037] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned industrial Internet data sharing method is implemented.

[0038] In this application, first, a first industrial device is used to send a first target data to a second industrial device through a communication terminal, and the first device authentication application corresponding to the second industrial device is sent to a preset authentication management unit through the communication terminal, so that the preset authentication management unit can be used to authenticate the second industrial device; then, after the second industrial device passes the authentication, the preset authentication management unit is used to generate a key acquisition application, to determine the target key based on the key acquisition application, and to store the target key in a target quantum key management device; then, the target quantum key management device generates an encryption line in the communication terminal based on the target key, so that the first industrial device can send a second target data to the second industrial device through the encryption line; the second target data is the verification data corresponding to the first target data; finally, the second industrial device is used to send the second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain the corresponding authentication result, and based on the authentication result, the first target data and the second target data are stored. As can be seen from the above, in this application, the first target data is shared between industrial devices, and verification data, i.e., the second target data, is generated for the first target data of the directional transmission, and the second target data is encrypted. After the transmission is completed, it is stored after authentication. In this way, the present application can determine the consistency of data transmitted by different channels in the communication terminal, which can improve the efficiency, security and accuracy of data sharing between industrial Internet, and at the same time reduce the use of circuits in hardware equipment, which is beneficial for post-fault repair. At the same time, the present application stores the first target data and the second target data separately to ensure data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.

[0040] Figure 1 A flow chart of an industrial Internet data sharing method provided for this application;

[0041] Figure 2 A schematic diagram of a specific data sharing system provided for this application;

[0042] Figure 3 A specific industrial Internet shared data storage flow chart provided for this application;

[0043] Figure 4 A specific flow chart of the industrial Internet data sharing method provided for this application;

[0044] Figure 5 A specific flow chart of the industrial Internet data sharing method provided for this application;

[0045] Figure 6 A schematic diagram of the structure of an industrial Internet data sharing device provided in this application;

[0046] Figure 7 This is a structural diagram of an electronic device provided in this application. DETAILED DESCRIPTION

[0047] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0048] The Industrial Internet encompasses four major systems: network, platform, data, and security. It is not only the infrastructure for industrial digitalization, networking, and intelligent transformation, but also an application model for the deep integration of the Internet, big data, artificial intelligence, and the real economy. It is also a new business model and a new industry that will reshape the corporate form, supply chain, and industrial chain. The Industrial Internet connects industrial equipment, systems, and smart terminals to form an integrated network system that can work together. With the rapid development of industrial automation and intelligence, the interaction and sharing of industrial data have become increasingly important. In actual application, existing industrial Internet data sharing methods and systems use data interfaces and data models to support transmission between industrial equipment and systems, and are close to the source. However, due to the limitations of wired connections, the lines are too complicated, and near-source storage requires the use of multiple memories, which makes it easy for stored data to be relatively scattered. Subsequently, shared processing is still required, and data sharing between multiple industrial devices is under great pressure. To this end, the present application provides an industrial Internet data sharing solution that can improve the efficiency and security of industrial Internet data sharing.

[0049] See also Figure 1 As shown, an embodiment of the present invention discloses an industrial Internet data sharing method, which is applied to a data sharing system; wherein the method may include:

[0050] Step S11: Use the first industrial device to send first target data to the second industrial device through the communication terminal, and send the first device authentication application corresponding to the second industrial device to the preset authentication management unit through the communication terminal, so as to use the preset authentication management unit to authenticate the second industrial device.

[0051] In this embodiment, see Figure 2 As shown, the data sharing system includes a quantum network and a wireless communication network. The quantum network includes a target quantum key source and a target quantum key management device. The wireless communication network includes industrial equipment, the communication terminal, the preset authentication management unit, and a preset storage unit. The quantum network and the wireless communication network communicate through the communication terminal. Specifically, the quantum key source is used to generate quantum keys. The quantum key management device can support the application management and secure transmission of quantum keys between the quantum key source, the communication terminal, and the industrial equipment. The authentication management unit registers corresponding identity information for multiple industrial devices. The wireless communication network covers multiple industrial devices and supports wireless data sharing among these devices within the wireless communication network.

[0052] It should be noted that the communication terminal includes a wireless transmission module and a wireless reception module. The above-mentioned use of the first industrial device to send the first target data to the second industrial device via the communication terminal can include: first, using the communication terminal to encode the first target data sent by the first industrial device based on preset data processing rules to obtain information bits corresponding to the first target data, and determining the target coding symbols corresponding to the first target data based on the information bits; then, sending the target coding symbols to the wireless channel of the communication terminal, so that the second industrial device can receive the target coding symbols from the wireless channel based on the preset data processing rules, and determine the information bits corresponding to the target coding symbols based on preset channel equalization technology and preset demodulation processing technology, and determine the first target data based on the information bits. Specifically, the wireless transmission module of the communication terminal can encode the data block into information bits according to the data processing rules corresponding to the communication terminal, then modulate them to form coding symbols, and finally send them into the wireless channel. The wireless receiving module of the communication terminal can receive coded symbols from the wireless channel according to the data processing rules corresponding to the communication terminal, decode the information bits through channel equalization technology and demodulation processing technology, and finally recover the data block sent by the network side. In this way, the first industrial device can send the first target data to the second industrial device through the conventional transmission line of the communication terminal.

[0053] In a specific embodiment, the first target data sent by the first industrial device includes target transmission data and target receiving device information; accordingly, the above-mentioned authentication of the second industrial device using the preset authentication management unit can include: first, using the preset authentication management unit to obtain the target receiving device information corresponding to the first target data and the first device authentication information corresponding to the second industrial device through the communication terminal; then, based on the first device authentication information, determining whether the second industrial device is consistent with the target receiving device information corresponding to the first target data, and generating a corresponding authentication result based on the judgment result, so that when the authentication result indicates that the second industrial device has passed the authentication, the key acquisition application is generated. It should be noted that the communication terminal also includes an authentication control module. In this embodiment, the authentication control module of the communication terminal can send an authentication application to the preset authentication management unit according to the data verification requirements during the wireless data sharing process of the industrial devices to verify the identity of the industrial devices.

[0054] Step S12: After the second industrial device passes authentication, a key acquisition application is generated using the preset authentication management unit, a target key is determined based on the key acquisition application, and the target key is stored in a target quantum key management device.

[0055] In this embodiment, after the preset authentication management unit authenticates the second industrial device as the target receiving device, the preset authentication management unit generates a key acquisition request. The above-mentioned determination of the target key based on the key acquisition request and storage of the target key in the target quantum key management device may include: first, using the preset authentication management unit to send the key acquisition request to the target quantum key management device through the communication terminal, and using the target quantum key management device to send the key acquisition request to the target quantum key source; then, using the target quantum key source to generate an initial key based on the channel comparison basis vector result, and determining the target key corresponding to the initial key based on a preset error correction mechanism and a preset privacy amplification mechanism; finally, using the target quantum key source to send the target key to the target quantum key management device so that the target quantum key management device can store the target key. Specifically, the preset authentication management unit sends the key acquisition request to the target quantum key management device, and the target quantum key management device transmits the key acquisition request to the target quantum key source, so that the target quantum key source generates a key for the target quantum key management device. In a specific embodiment, the key generation of the target quantum key source selects a channel comparison basis vector, retains the consistency of the basis vector to form an initial key, and forms a target key through an error correction mechanism and a privacy amplification mechanism.

[0056] Step S13: Generate an encryption line in the communication terminal based on the target key through the target quantum key management device, so that the first industrial device sends second target data to the second industrial device through the encryption line; the second target data is verification data corresponding to the first target data.

[0057] It should be noted that when encrypting shared data between industrial devices, the target key is encrypted using a symmetric encryption algorithm. This embodiment can determine a preset encryption function and a preset decryption function based on the symmetric encryption algorithm; accordingly, the above-mentioned first industrial device sends the second target data to the second industrial device through the encryption line, which may include: first, determining the target encrypted data corresponding to the second target data sent by the first industrial device to the encryption line based on the target key and the preset encryption function through the encryption line; then, determining the second target data corresponding to the target encrypted data based on the target key and the preset decryption function through the encryption line, so that the second industrial device can obtain the second target data from the encryption line. It should be noted that data encryption and data decryption are automatically performed in the encryption line. Specifically, the encryption formula and decryption formula are as follows:

[0058] ;

[0059] Where K is the target key, M is the plaintext, or the second target data, C is the ciphertext, or the target encrypted data corresponding to the second target data, and E is the encryption function. By encrypting and decrypting the second target data, shared data within the encrypted channel is protected from external interference, facilitating verification of data shared over conventional transmission lines for errors or loss.

[0060] Step S14: Using the second industrial device, sending a second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain a corresponding authentication result, and storing the first target data and the second target data based on the authentication result.

[0061] In this embodiment, see Figure 3As shown, storing the first target data and the second target data based on the authentication result can include: using the preset authentication management unit to send the authentication result to the communication terminal, and when the authentication result indicates that the second industrial device has passed authentication, using the communication terminal to send the first target data and the second target data to a preset storage unit, so that the preset storage unit can store the first target data and the second target data based on the preset block and the target data sharing time corresponding to the first target data. Specifically, by connecting the storage unit to the communication terminal, the shared data is stored according to the different wireless data sharing times of different industrial devices, and the authentication management unit is fed back to the communication terminal to verify that the shared data is normal. In a specific embodiment, the storage unit includes multiple blocks connected in parallel, each of which contains two sub-blocks. The directional wireless shared data and the verification shared data of different industrial devices are combined and stored in the sub-blocks, and stored together with the reverse wireless shared data and the verification shared data in a parent block. During the data transmission between the communication terminal and the storage unit, the shared data belonging to multiple industrial devices in the storage unit can be prevented from being lost or damaged at the same time, which helps to ensure data security. In this way, in this embodiment, by storing the data shared in the conventional transmission line and the verification data transmitted by the encryption line inside the storage unit, based on the fact that the various storage blocks inside the storage unit are in a parallel state, the mutual influence between the various blocks in the storage unit can be avoided during the data transmission between the communication terminal.

[0062] As can be seen from the above, in this embodiment, first, a first industrial device transmits first target data to a second industrial device via a communication terminal. The communication terminal then transmits a first device authentication request corresponding to the second industrial device to a preset authentication management unit, which then authenticates the second industrial device using the preset authentication management unit. After the second industrial device passes authentication, the preset authentication management unit generates a key acquisition request, determines a target key based on the key acquisition request, and stores the target key in a target quantum key management device. The target quantum key management device then generates an encrypted line in the communication terminal based on the target key, allowing the first industrial device to transmit second target data to the second industrial device via the encrypted line. The second target data is verification data corresponding to the first target data. Finally, the second industrial device transmits a second device authentication request corresponding to the second industrial device to the preset authentication management unit to obtain a corresponding authentication result. Based on the authentication result, the first and second target data are stored. As can be seen from the above, in this embodiment, first target data is shared between industrial devices, verification data (i.e., second target data) is generated for the directed transmission of the first target data, and the second target data is encrypted. After transmission is complete, the data is authenticated and stored. In this way, this embodiment can determine the consistency of data transmitted by different channels in the communication terminal, which can improve the efficiency, security and accuracy of data sharing between industrial Internets, and at the same time reduce the use of circuits in hardware devices, which is beneficial for post-fault repair. At the same time, the storage of the first target data and the second target data in this application is conducive to ensuring data security.

[0063] In one embodiment, see Figure 4 and Figure 5 As shown in the figure, the process of the industrial Internet data sharing method is as follows:

[0064] S1: Use communication terminals to wirelessly share data between multiple different industrial devices;

[0065] The multiple different industrial equipment include industrial equipment 1 and industrial equipment 2, and industrial equipment 1 and industrial equipment 2 merely indicate different industrial equipment and do not indicate the number of industrial equipment;

[0066] S2: Use communication terminals to create a communication bridge between the wireless communication network and the quantum network;

[0067] S3: The communication terminal sends an authentication request to the authentication management unit on behalf of industrial device 2, causing the authentication management unit to send a key request to the quantum key management device;

[0068] Among them, the authentication management unit registers corresponding identity information among multiple industrial devices;

[0069] S4: The quantum key management device transmits the key application to the quantum key source, which enables the quantum key source to generate a key for the quantum key management device;

[0070] S5: The quantum key management device generates a verification data transmission line, i.e., an encryption line, between industrial device 1 and industrial device 2, and encrypts the shared data on the line;

[0071] The wireless data sharing is sent from industrial device 1 to industrial device 2, and the verification data transmission line generation requirement is sent from industrial device 2 to industrial device 1. When wireless data sharing is performed between different devices, conventional transmission lines are used for data sharing, and an independent verification data transmission line, that is, an encryption line different from the conventional transmission line, is used to encrypt the shared data and then share it again.

[0072] S6: The industrial device 2 sends an authentication request to the authentication management unit and obtains the authentication result from the data of the verification data transmission line;

[0073] The communication terminal sends an authentication request to the authentication management unit on behalf of industrial device 2. After the authentication management unit verifies the identity of industrial device 2, it obtains the authentication result from the data shared between the industrial devices and finally feeds the result back to the communication terminal to ensure the security and accuracy of wireless data sharing.

[0074] S7: The authentication management unit feeds back the authentication result to the communication terminal and stores it;

[0075] Among them, by making industrial equipment 2 send an authentication application to the authentication management unit after obtaining the shared data on the verification data transmission line, and after obtaining the authentication result, it is fed back to the communication terminal for storage, so that records can be retained during the process of industrial Internet data sharing, providing a basis for checking errors in subsequent data sharing.

[0076] Accordingly, see Figure 6 As shown, the embodiment of the present application further provides an industrial Internet data sharing device, which is applied to a data sharing system; wherein the device may include:

[0077] The device authentication module 11 is configured to use the first industrial device to send first target data to the second industrial device via the communication terminal, and to send the first device authentication application corresponding to the second industrial device to the preset authentication management unit via the communication terminal, so as to authenticate the second industrial device using the preset authentication management unit;

[0078] a target key determination module 12, configured to generate a key acquisition application using the preset authentication management unit after the second industrial device passes authentication, determine a target key based on the key acquisition application, and store the target key in a target quantum key management device;

[0079] a second target data sending module 13, configured to generate an encrypted line in the communication terminal based on the target key through the target quantum key management device, so that the first industrial device sends second target data to the second industrial device through the encrypted line; the second target data is verification data corresponding to the first target data;

[0080] The data storage module 14 is configured to use the second industrial device to send a second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain a corresponding authentication result, and store the first target data and the second target data based on the authentication result.

[0081] As can be seen from the above, in this application, the first target data is first sent to the second industrial device via the communication terminal using the first industrial device, and the first device authentication application corresponding to the second industrial device is sent to the preset authentication management unit via the communication terminal, so that the second industrial device is authenticated by the preset authentication management unit; then, after the second industrial device passes the authentication, the preset authentication management unit is used to generate a key acquisition application, to determine the target key based on the key acquisition application, and the target key is stored in the target quantum key management device; then, the target quantum key management device generates an encryption line in the communication terminal based on the target key, so that the first industrial device sends the second target data to the second industrial device via the encryption line; the second target data is the verification data corresponding to the first target data; finally, the second industrial device sends the second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain the corresponding authentication result, and stores the first target data and the second target data based on the authentication result. As can be seen from the above, in this application, the first target data is shared between industrial devices, and verification data, i.e., the second target data, is generated for the first target data transmitted in a directional manner, and the second target data is encrypted. After the transmission is completed, it is authenticated and stored. In this way, the present application can determine the consistency of data transmitted by different channels in the communication terminal, which can improve the efficiency, security and accuracy of data sharing between industrial Internet, and at the same time reduce the use of circuits in hardware equipment, which is beneficial for post-fault repair. At the same time, the present application stores the first target data and the second target data separately to ensure data security.

[0082] In some specific embodiments, the data sharing system includes a quantum network and a wireless communication network; wherein the quantum network includes a target quantum key source and a target quantum key management device, the wireless communication network includes industrial equipment, the communication terminal, the preset authentication management unit and a preset storage unit, and the quantum network and the wireless communication network communicate through the communication terminal.

[0083] In some specific implementations, the device authentication module 11 may include:

[0084] a target coding symbol determining unit, configured to use the communication terminal to perform coding processing on the first target data sent by the first industrial device based on a preset data processing rule to obtain information bits corresponding to the first target data, and determine a target coding symbol corresponding to the first target data based on the information bits;

[0085] A first target data determination unit is configured to send the target coding symbol to a wireless channel of the communication terminal, so that the second industrial device receives the target coding symbol from the wireless channel based on the preset data processing rule, determines the information bits corresponding to the target coding symbol based on a preset channel equalization technology and a preset demodulation processing technology, and determines the first target data based on the information bits.

[0086] In some specific embodiments, the first target data includes target transmission data and target receiving device information;

[0087] Accordingly, the device authentication module 11 may include:

[0088] a first device authentication information acquisition unit, configured to use the preset authentication management unit to acquire, through the communication terminal, the target receiving device information corresponding to the first target data and the first device authentication information corresponding to the second industrial device;

[0089] A conditional judgment unit is used to judge whether the target receiving device information corresponding to the second industrial device and the first target data is consistent based on the first device authentication information, and generate a corresponding authentication result based on the judgment result, so as to generate the key acquisition application when the authentication result indicates that the second industrial device has passed the authentication.

[0090] In some specific implementations, the target key determination module 12 may include:

[0091] a key acquisition application sending unit, configured to use the preset authentication management unit to send the key acquisition application to the target quantum key management device through the communication terminal, and use the target quantum key management device to send the key acquisition application to a target quantum key source;

[0092] a target key determination unit, configured to generate an initial key based on a channel comparison basis vector result through the target quantum key source, and determine the target key corresponding to the initial key based on a preset error correction mechanism and a preset privacy amplification mechanism;

[0093] A target key sending unit is configured to send the target key to the target quantum key management device using the target quantum key source, so that the target quantum key management device stores the target key.

[0094] In some specific implementations, the industrial Internet data sharing device may further include:

[0095] An encryption function determination module, used to determine a preset encryption function and a preset decryption function based on a symmetric encryption algorithm;

[0096] Accordingly, the second target data sending module 13 may include:

[0097] a target encrypted data determining unit, configured to determine, through the encryption line, target encrypted data corresponding to the second target data sent by the first industrial device to the encryption line based on the target key and the preset encryption function;

[0098] The second target data acquisition unit is configured to determine the second target data corresponding to the target encrypted data based on the target key and the preset decryption function through the encryption line, so that the second industrial device acquires the second target data from the encryption line.

[0099] In some specific implementations, the data storage module 14 may include:

[0100] a data storage unit, configured to use the preset authentication management unit to send the authentication result to the communication terminal, and when the authentication result indicates that the second industrial device has passed authentication, use the communication terminal to send the first target data and the second target data to a preset storage unit, so that the preset storage unit stores the first target data and the second target data based on a preset block and a target data sharing time corresponding to the first target data.

[0101] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 7This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be considered as any limitation on the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the industrial Internet data sharing method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0102] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0103] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0104] The operating system 221 is used to manage and control the hardware devices on the electronic device 20 and the computer program 222, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including computer programs that can be used to implement the industrial Internet data sharing method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include computer programs that can be used to perform other specific tasks.

[0105] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when executed by a processor, the computer program implements the aforementioned disclosed industrial Internet data sharing method. The specific steps of this method can be referred to the corresponding content disclosed in the aforementioned embodiments and will not be repeated here.

[0106] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.

[0107] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0108] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0109] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.

[0110] The above is a detailed introduction to the technical solution provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the ideas of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. An industrial Internet data sharing method, characterized in that: Applied to a data sharing system; wherein the method comprises: Using the first industrial device to send the first target data to the second industrial device through the communication terminal, and sending the first device authentication application corresponding to the second industrial device to the preset authentication management unit through the communication terminal, so as to authenticate the second industrial device using the preset authentication management unit; After the second industrial device passes authentication, generating a key acquisition application using the preset authentication management unit, determining a target key based on the key acquisition application, and storing the target key in a target quantum key management device; generating, by the target quantum key management device, an encrypted line in the communication terminal based on the target key, so that the first industrial device sends second target data to the second industrial device through the encrypted line; the second target data being verification data corresponding to the first target data; The second industrial device is used to send a second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain a corresponding authentication result, and the first target data and the second target data are stored based on the authentication result.

2. The industrial Internet data sharing method according to claim 1, characterized in that: The data sharing system includes a quantum network and a wireless communication network; wherein the quantum network includes a target quantum key source and a target quantum key management device, the wireless communication network includes industrial equipment, the communication terminal, the preset authentication management unit and a preset storage unit, and the quantum network and the wireless communication network communicate through the communication terminal.

3. The industrial Internet data sharing method according to claim 1, characterized in that: The method of sending the first target data to the second industrial device via the communication terminal using the first industrial device includes: Using the communication terminal to encode the first target data sent by the first industrial device based on a preset data processing rule to obtain information bits corresponding to the first target data, and determining a target coding symbol corresponding to the first target data based on the information bits; The target coding symbol is sent to the wireless channel of the communication terminal, so that the second industrial device receives the target coding symbol from the wireless channel based on the preset data processing rule, determines the information bit corresponding to the target coding symbol based on a preset channel equalization technology and a preset demodulation processing technology, and determines the first target data based on the information bit.

4. The industrial Internet data sharing method according to claim 1, characterized in that: The first target data includes target transmission data and target receiving device information; Correspondingly, the authenticating the second industrial device by using the preset authentication management unit includes: Using the preset authentication management unit to obtain the target receiving device information corresponding to the first target data and the first device authentication information corresponding to the second industrial device through the communication terminal; Based on the first device authentication information, it is determined whether the second industrial device is consistent with the target receiving device information corresponding to the first target data, and a corresponding authentication result is generated based on the judgment result, so that the key acquisition application is generated when the authentication result indicates that the second industrial device has passed the authentication.

5. The industrial Internet data sharing method according to claim 1, characterized in that: The determining a target key based on the key acquisition application and storing the target key in a target quantum key management device includes: Using the preset authentication management unit to send the key acquisition application to the target quantum key management device through the communication terminal, and using the target quantum key management device to send the key acquisition application to a target quantum key source; Generate an initial key based on a channel comparison basis vector result through the target quantum key source, and determine the target key corresponding to the initial key based on a preset error correction mechanism and a preset privacy amplification mechanism; The target key is sent to the target quantum key management device by using the target quantum key source, so that the target quantum key management device stores the target key.

6. The industrial Internet data sharing method according to claim 1, characterized in that: Also includes: Determine a preset encryption function and a preset decryption function based on a symmetric encryption algorithm; Accordingly, the first industrial device sends the second target data to the second industrial device through the encrypted line, including: determining, through the encryption line, target encrypted data corresponding to the second target data sent by the first industrial device to the encryption line based on the target key and the preset encryption function; The second target data corresponding to the target encrypted data is determined based on the target key and the preset decryption function through the encryption circuit, so that the second industrial device obtains the second target data from the encryption circuit.

7. The industrial Internet data sharing method according to any one of claims 1 to 6, characterized in that: The storing the first target data and the second target data based on the authentication result includes: The preset authentication management unit is used to send the authentication result to the communication terminal, and when the authentication result indicates that the second industrial device has passed authentication, the communication terminal is used to send the first target data and the second target data to a preset storage unit, so that the preset storage unit stores the first target data and the second target data based on a preset block and a target data sharing time corresponding to the first target data.

8. An industrial Internet data sharing device, characterized in that: Applicable to a data sharing system; wherein the device comprises: a device authentication module, configured to use a first industrial device to send first target data to a second industrial device via a communication terminal, and to send a first device authentication application corresponding to the second industrial device to a preset authentication management unit via the communication terminal, so as to authenticate the second industrial device using the preset authentication management unit; a target key determination module, configured to generate a key acquisition application using the preset authentication management unit after the second industrial device passes authentication, determine a target key based on the key acquisition application, and store the target key in a target quantum key management device; a second target data sending module, configured to generate an encrypted line in the communication terminal based on the target key through the target quantum key management device, so that the first industrial device sends second target data to the second industrial device through the encrypted line; the second target data is verification data corresponding to the first target data; The data storage module is used to use the second industrial device to send a second device authentication application corresponding to the second industrial device to the preset authentication management unit to obtain a corresponding authentication result, and store the first target data and the second target data based on the authentication result.

9. An electronic device, characterized in that: The electronic device includes a processor and a memory; wherein, the memory is used to store a computer program, and the computer program is loaded and executed by the processor to implement the industrial Internet data sharing method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that Used to store a computer program, which, when executed by a processor, implements the industrial Internet data sharing method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Certification method, device and system for data transmission in Internet of Things

    CN102802154A

  • Information collection method, communication device, server, system and storage medium

    CN113660385A

  • Encryption channel construction method and device, electronic equipment and storage medium

    CN118054900A

  • Quantum encryption communication method and system adapted to wireless communication system switching

    CN119155035A