Data safety management method and system of belt conveyor RCM platform

Through the four-level data classification system and differentiated protection measures, the problems of chaotic data management and insufficient security in the traditional RCM platform have been solved, and detailed data management and efficient and secure transmission have been achieved, ensuring the stable operation of the belt conveyor.

CN120785584APending Publication Date: 2025-10-14SHANTOU POWER PLANT OF HUANENG (GUANGDONG) ENERGY DEVELOPMENT CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510882273.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

Traditional RCM platforms have defects in data management and security, including insufficiently detailed data classification, insufficient data transmission security, and a lack of a review mechanism for model parameter maintenance. These defects lead to chaotic data management, low security, and are prone to unplanned downtime.

Method used

A four-level data classification system is adopted, combined with blockchain evidence storage, two-person modification and review, trusted execution environment, dynamic permission control and encryption technology, to implement differentiated protection measures, including static data partition encryption, dynamic data memory encryption, power encryption tunnel, dynamic desensitization and multi-factor authentication, and real-time adjustment of authentication strength to ensure data security.

Benefits of technology

It achieves refined management and security protection of different types of data, ensures data integrity and confidentiality, reduces the risk of data leakage, avoids unplanned downtime, and improves the security and operation and maintenance efficiency of the RCM platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785584A_ABST
    Figure CN120785584A_ABST
Patent Text Reader

Abstract

The invention discloses a data security management method and system for a belt conveyor RCM platform, and belongs to industrial equipment predictive maintenance, a belt conveyor RCM four-level data classification system is established, and second-level data is protected by block chain evidence storage and double modification and recheck; performing calculation on the third-level data through a trusted execution environment for protection; based on the four-level data classification system, according to the dynamic permission instruction, differential protection measures are executed in the full life cycle of data, and the differential protection measures comprise the steps that in the storage stage, static data are subjected to partition encryption through an SM4 national cryptographic algorithm, and dynamic data are encrypted through a memory; in the transmission stage, a power encryption tunnel is adopted between the PLC and the server, and an API interface adopts HTTPS and JWT tokens; in the use stage, dynamic desensitization and a three-member discrete permission model are implemented; a dynamic permission instruction is issued to a data full life cycle through a dynamic permission control engine, access is carried out in non-working time, service life model modification is operated outside a geo-fence, and forced multi-factor authentication is triggered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of predictive maintenance of industrial equipment, and specifically relates to a data security management method and system for a belt conveyor RCM platform. Background Art

[0002] In the production and operation of coal-fired power plants, belt conveyors are key equipment, responsible for the vital task of vertically transporting materials. Their stable operation is directly related to the plant's production efficiency and safety. To better manage and maintain belt conveyors, a Reliability-Centered Maintenance (RCM) platform has emerged, built on the principles of reliability-centered maintenance (RCM). This platform contains a wealth of high-value data, providing strong support for the reliable operation of equipment.

[0003] The FMEA (Failure Modes and Effects Analysis) library records historical failure modes, such as belt conveyor failures. This valuable data, derived through detailed analysis and summary of failures that have occurred over the long term, helps maintenance personnel understand potential equipment failure types and their impacts in advance, allowing them to develop targeted preventative measures. Life models predict the remaining life of key components, such as motors and belt conveyors, based on their sensitive parameters. This allows maintenance personnel to plan repairs in advance and avoid production interruptions caused by sudden component failure.

[0004] However, traditional RCM platform protection has three significant flaws. In terms of data management, data classification is too extensive, and there is no effective distinction between different types of data, such as real-time sensor data and maintenance knowledge bases. This leads to chaotic data management and makes it difficult to fully realize the value of various types of data. In terms of data transmission security, cross-system transmission relies on plaintext protocols, such as the unencrypted Modbus protocol, which makes data extremely vulnerable to man-in-the-middle attacks during transmission, posing the risk of data leakage and tampering. In addition, the maintenance of model parameters lacks a review mechanism. Once an erroneous operation occurs, it may lead to inaccurate prediction results, which in turn causes unplanned downtime and huge economic losses to power plants. Therefore, it is of great practical significance to improve these defects. Summary of the Invention

[0005] The purpose of the present invention is to overcome the problem that the protection of traditional RCM platform affects the operation and maintenance of belt conveyor, and proposes a data security management method for belt conveyor RCM platform.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions: In a first aspect, the present invention provides a data security management method for a belt conveyor RCM platform, comprising the following steps: establishing a four-level data classification system for belt conveyor RCM, including primary data, secondary data, tertiary data, and quaternary data; secondary data includes belt conveyor FMEA library data, which is protected by blockchain evidence storage and two-person modification and review; tertiary data includes belt conveyor and motor life prediction model parameters, which are protected by executing calculations in a trusted execution environment; Based on a four-level data classification system and dynamic permission instructions, differentiated protection measures are implemented throughout the data lifecycle, including: During the storage phase, static data is encrypted using the SM4 national encryption algorithm, and dynamic data is encrypted using memory encryption. During the transmission phase, an encrypted tunnel is used between the PLC and the server, and the API interface uses HTTPS and JWT tokens; During the usage phase, dynamic desensitization and three-member separation of authority model are implemented; Dynamic permission instructions are issued to the entire data life cycle through the dynamic permission control engine. The dynamic permission control engine is based on a four-level data classification system and dynamically improves the authentication strength of the data throughout the life cycle based on environmental risks. Access during non-working hours and modification of the life cycle model outside the geographic fence trigger mandatory multi-factor authentication.

[0007] Furthermore, blockchain evidence storage and two-person modification review are used for protection. Specifically, when modifying the RPN value of the belt conveyor fault in the FMEA library, the following steps are performed: If the change in the RPN value of a belt conveyor failure exceeds the amplitude threshold, a three-level review and approval process will be triggered. After approval, the operation hash value will be written into the cross-factory alliance chain for evidence storage. Belt conveyor failures include deviation, rope pulling, coal blockage, and slipping.

[0008] Furthermore, the first-level data includes the real-time vibration and current status data of the belt conveyor, which is protected by transmission encryption and memory processing isolation; Level 4 data includes cross-power plant maintenance work order records, which are protected by implementing field-level desensitization and access IP whitelist control.

[0009] Furthermore, scenarios that trigger mandatory multi-factor authentication include: The access time is during the non-maintenance window period; The distance between the login location and the belt conveyor workshop is greater than the threshold; Retrieve the predicted value of the remaining life of the motor from the third-level data.

[0010] Furthermore, static data in the storage phase is encrypted by data type partition, and the key is managed by the hardware security module; dynamic data in the storage phase is processed in Intel SGX or ARM TrustZone encrypted memory, and dynamic data is prohibited from leaving the TEE environment; The use stage includes a maintenance decision stage, and the safety control of the maintenance decision stage includes: a maintenance work order is additionally signed with an SM2 digital signature, positioning data is transmitted by a national secret algorithm through on-site maintenance software, and local storage time is less than a cache limit time; The use stage and the transmission stage include a feedback iteration stage, and the safety control of the feedback iteration stage includes: a comparison difference value is obtained by automatically comparing actual belt conveyor wear data and a belt conveyor wear prediction value deviation, an audit alarm is triggered when the comparison difference value exceeds a comparison threshold value, and an update package of a belt conveyor and motor life prediction model is deployed to a TEE environment after being verified by a CA certificate.

[0011] Further, the deployment of the differential protection measures in the whole life cycle of data further includes: In the collection stage, a message signature is enabled for a PLC industrial protocol of the belt conveyor, and a lightweight TLS is deployed for a PLC edge gateway of the belt conveyor. In the destruction stage, multiple physical overwriting deletions are performed on a scrapped hard disk.

[0012] Further, the deployment of the intelligent risk perception engine includes: An abnormal access mode is monitored in real time, the abnormal access mode includes a FMEA library download operation exceeding an access threshold value times in a single hour, if the abnormal access mode is detected, an account permission is automatically limited and a screen recording is started, and an abnormal access root cause is analyzed based on a SHAP algorithm.

[0013] In a second aspect, the present application provides a data security management system of a belt conveyor RCM platform, comprising: A data classification module is configured to establish a four-level data classification system of the belt conveyor RCM, including first-level data, second-level data, third-level data and fourth-level data, the second-level data includes belt conveyor FMEA library data, and the data is protected by block chain storage and double-person modification review, and the third-level data includes belt conveyor and motor life prediction model parameters, and the parameters are protected by calculation in a trusted execution environment; A differential protection module is configured to execute differential protection measures in the whole life cycle of data according to dynamic permission instructions based on the four-level data classification system, including: In the storage stage, static data is partitioned and encrypted by an SM4 national secret algorithm, and dynamic data is encrypted by memory; In the transmission stage, a power encryption tunnel is used between the PLC and the server, and HTTPS and a JWT token are used for an API interface; In the use stage, a dynamic desensitization and a three-person separate permission model are implemented. The dynamic instruction issuing module is used for issuing the dynamic permission instruction to the data full life cycle through the dynamic permission control engine.

[0014] In a third aspect, the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and a data security management method of a belt conveyor RCM platform implemented when the processor executes the computer program.

[0015] In a fourth aspect, the present application provides a computer readable storage medium, which stores a computer program, and a data security management method of a belt conveyor RCM platform implemented when the processor executes the computer program.

[0016] Compared with the prior art, the present application has the following beneficial technical effects: The data security management method of the belt conveyor RCM platform divides the belt conveyor RCM into four levels, each level being bound with differentiated protection measures: two-level block chain storage, three-level TEE (Trusted Execution Environment, trusted execution environment) calculation, and implanting security control points at each link of data flow; the authentication strength is adjusted in real time through environmental risk perception, the block chain storage ensures the integrity of the FMEA library, the TEE calculation protects the confidentiality of the model parameters, the dynamic desensitization and IP white list prevent data leakage, the security control is embedded in the RCM process, does not affect the operation and maintenance efficiency, and guarantees the confidentiality, integrity and availability of core data such as dynamic state data, static fault mode library and FMEA library; the safety exchange and compliance storage of cross-plant data are realized; and the dynamic risk self-adaptive security protection mechanism is established. BRIEF DESCRIPTION OF DRAWINGS

[0017] The drawings described herein are for illustrative purposes only and are not intended to limit the scope of the present application in any way. In addition, the shapes and scale sizes of the components in the drawings are only illustrative and are used to help understand the present application, and are not specific limitations on the shapes and scale sizes of the components. In the drawings: Figure 1 The flowchart of the data security management method of the belt conveyor RCM platform of the present application.

[0018] Figure 2 The structural diagram of the data security management system of the belt conveyor RCM platform of the present application.

[0019] Figure 3It is an electronic device diagram of a data security management method of a belt conveyor RCM platform of the application.

[0020] Figure 4 It is a data full life cycle five stage schematic diagram in the embodiment of the application.

[0021] Figure 5 It is an FMEA library closed loop modification operation flow schematic diagram in the embodiment of the application.

[0022] Figure 6 It is a storage stage protection data security management logic schematic diagram in the embodiment of the application.

[0023] Figure 7 It is a use stage protection data security management logic schematic diagram in the embodiment of the application.

[0024] Figure 8 It is a transmission stage protection closed loop data security management logic schematic diagram in the embodiment of the application.

[0025] Figure 9 It is a use stage protection closed loop data security management logic schematic diagram in the embodiment of the application.

[0026] Figure 10 It is a data full life cycle each stage coordination relationship schematic diagram in the embodiment of the application.

[0027] Figure 11 It is a dynamic authentication strength based on environmental risk in the embodiment of the application. DETAILED DESCRIPTION

[0028] In order to make the personnel in the art better understand the application scheme, the technical scheme in the embodiment of the application will be described clearly and completely below in combination with the drawings in the embodiment of the application. Obviously, the described embodiments are only a part of the embodiments of the application, not all. Based on the embodiments in the application, all other embodiments obtained by the person skilled in the art without creative labor should belong to the scope of protection of the application.

[0029] Embodiment one Referring to Figure 1 , Figure 4 and Figure 5 , a data security management method of a belt conveyor RCM platform, comprising the following steps: establishing a four-level data classification system of the belt conveyor RCM, including first-level data, second-level data, third-level data and fourth-level data; The first-level data includes real-time state data of the equipment, which is protected by transmission encryption and memory processing isolation; the bearing temperature data of the belt conveyor collected by the DCS system is processed in the encrypted memory after signing through the OPC UA protocol; Secondary data includes belt conveyor FMEA library data, which is protected by blockchain evidence storage and two-person modification review. Blockchain evidence storage: ensures the non-tamperability of data modification operations; two-person review and modification mechanism: reduces the risk of tampering through multi-person collaborative approval. Specifically: when modifying the belt conveyor fault RPN value in the FMEA library, perform the following steps: If the change in the belt conveyor fault RPN value exceeds the amplitude threshold, such as 15%, a three-level joint approval is triggered; after approval, the operation hash value is written to the cross-plant alliance chain, and the group node and power plant node store evidence. Belt conveyor faults include deviation, rope pulling, coal blockage, and slippage. Two-person review is a static rule, and risk-adaptive dynamic approval is achieved through amplitude thresholds. Low-risk modifications may not require joint signatures. It is clear that evidence storage occurs in the RPN value modification scenario, and what is written to the alliance chain is the operation hash value, not the original data, taking into account both efficiency and non-tamperability. By limiting the application scenario, RPN modification quantifies the amplitude threshold and refines the approval process, and three-level joint signatures, the abstract protection requirements of secondary data are transformed into a feasible method. Level 3 data includes lifespan prediction model parameters, which are protected by computing through a trusted execution environment (TEE). Level 4 data includes cross-plant maintenance work order records, which are protected by implementing field-level desensitization and access IP whitelist control. The manufacturer's technical manuals in the maintenance work order desensitize key parameters for unauthorized personnel, including torque thresholds.

[0030] Based on the four-level data classification system and dynamic authority instructions, differentiated protection measures are implemented throughout the data life cycle. Differentiated measures are deployed along the five stages of the longitudinal protection belt conveyor: collection, transmission, storage, use, and destruction. Figure 4 The collaborative relationship between each stage is as follows: Figure 10 Different levels of data use different technologies at the same stage, including: During the collection phase, the conveyor belt PLC uploads data via signed Modbus messages. The edge gateway uses the national encryption SM3 digest algorithm, the industrial protocol Modbus-TCP uses message signatures, and the edge node conveyor belt PLC deploys lightweight TLS 1.3. In the storage stage, the static data history fault library is partitioned by device type, such as conveyor belt type / motor type, and encrypted using SM4-CTR mode. The dynamic data real-time diagnosis results are processed in ARM TrustZone encrypted memory; Figure 6Static data in the storage stage is encrypted by data type partition, and the key is managed by the hardware security module HSM; solve the security risks of key storage, meet the requirements for key management, and physically isolate; dynamic data in the storage stage is processed in Intel SGX or ARM TrustZone encrypted memory, and plaintext leakage is prohibited; data output vulnerabilities in the TEE environment are closed to prevent parameter leakage caused by side channel attacks; plaintext leakage is prohibited and all dynamic data is forced to be closed-loop processed in the TEE. The output results must be encrypted or signed to ensure that even if the platform is invaded, the attacker cannot obtain the key in the HSM or the model plaintext in the TEE, achieving the security effect of being visible to the attacker and unavailable.

[0031] like Figure 7 、 Figure 8 、 Figure 9 ,During the transmission stage, a power-specific encrypted tunnel, IPSec-VPN, is established between the DCS and MES in the factory network. HTTPS and JWT tokens are used for remote access to the API interface, and the token validity period is ≤15 minutes. During the use stage, dynamic desensitization and three-member separation of authority model are implemented, including system administrator, security officer, and auditor.

[0032] The usage phase includes the maintenance decision-making phase. The security controls in the maintenance decision-making phase include: attaching a digital signature based on the SM2 algorithm after the maintenance work order is generated to prevent instruction tampering; the on-site maintenance APP forcibly enables the national secret algorithm to transmit positioning data, binds the transmission encryption requirements of the fourth-level work order, and restricts local storage of data; and converts the usage phase protection of the fourth-level work order data into an executable signed work order.

[0033] The usage and transmission stages include the feedback iteration stage. The security controls in the feedback iteration stage include: automatic comparison of the actual equipment maintenance data with the output value of the life prediction model, and triggering an audit alarm when the comparison difference exceeds the comparison threshold, such as 20%; the model update package must be signed by the CA certificate before being deployed to the TEE environment to enhance the security of the transmission stage.

[0034] During the destruction phase, scrapped hard drives undergo three physical overwrites. Decommissioned hard drives are overwritten according to the DoD 5220.22-M standard, with three rewrites of 0x00 / 0xFF / random numbers. Integrity protection based on three-level model parameters is also implemented, along with a dynamic audit mechanism.

[0035] Dynamic permission instructions are issued to the entire data life cycle through the dynamic permission control engine. The dynamic permission control engine is based on a four-level data classification system and automatically improves the authentication strength of the entire data life cycle through environmental perception. Figure 11The dynamic permission control engine forces the use of multi-factor authentication in the following situations: the access time is during the non-maintenance window period; the FMEA library is accessed on non-working days; the login location is greater than the distance threshold from the belt conveyor workshop; the life model is downloaded from an unauthorized IP address; the motor remaining life prediction value in the third-level data is retrieved; the belt conveyor interlocking logic parameters are modified, etc.

[0036] The deployment of the intelligent risk perception engine includes: real-time analysis of access patterns and identification of abnormal behavior, including intensive downloads of belt conveyor maintenance manuals greater than 5 times within a single hour, and cross-geofenced access, such as logging in remotely to retrieve drawings; response mechanism: automatic restriction of account permissions and initiation of screen recording and archiving to the audit area, analysis of the root cause of abnormal access based on the SHAP algorithm, and centralized access to sensitive interfaces by UAs with specific IP addresses.

[0037] In traditional methods, data classification, lifecycle control, and permission management are independent of each other. However, the present invention uses a closed-loop feedback mechanism and a three-level lifecycle model to automatically activate the strongest protection TEE and multi-factor authentication during the critical use phase of high-value data; low-risk operation level one data query does not add redundant control to ensure business efficiency. Tampering with the FMEA library requires two-person review and blockchain evidence storage to ensure non-repudiation of operations; the lifecycle model runs within the TEE to prevent parameter theft. Dynamic desensitization increases the efficiency of sharing maintenance work orders by 50%; lightweight TLS reduces edge PLC resource usage by >30%. This embodiment targets the business characteristics of belt conveyors. Belt conveyor life-sensitive maintenance relies on the FMEA library, integrating the national secret algorithm SM2 / 3 / 4 to ensure data confidentiality, ensuring the integrity of core assets through blockchain and TEE, and dynamically adjusting the protection intensity based on environmental risks to balance security and efficiency.

[0038] Example 2 See also Figure 2 , a data security management system for a belt conveyor RCM platform, including: The data classification module is used to establish a four-level data classification system for belt conveyor RCM, including primary, secondary, tertiary, and quaternary data. The secondary data includes the belt conveyor FMEA library data, which is protected by blockchain evidence storage and two-person modification and review. The tertiary data includes the belt conveyor and motor life prediction model parameters, which are protected by computing through a trusted execution environment. The differentiated protection module is used to implement differentiated protection measures throughout the data lifecycle based on a four-level data classification system and dynamic permission instructions, including: During the storage phase, static data is encrypted using the SM4 national encryption algorithm, and dynamic data is encrypted using memory encryption. During the transmission phase, an encrypted tunnel is used between the PLC and the server, and the API interface uses HTTPS and JWT tokens; In the use stage, dynamic desensitization and a three-member separate authority model are implemented. The dynamic instruction issuing module is configured to issue the dynamic permission instruction to the data full life cycle through the dynamic permission control engine, and the dynamic permission control engine is configured to dynamically improve the authentication strength of the data full life cycle based on the four-level data classification system and based on the environmental risk, and to modify the trigger of the forced multi-factor authentication in the non-working time access geographic fence operation life model.

[0039] Embodiment three Referring to Figure 3 An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the data security management method of the belt conveyor RCM platform when executing the computer program.

[0040] Embodiment four A computer readable storage medium stores a computer program, and the computer program implements the data security management method of the belt conveyor RCM platform when executed by a processor.

[0041] Embodiment five This embodiment combines the actual working conditions of the A / B belt conveyor type coal handling device of a certain power plant, and the belt conveyor fault includes the fault modes such as deviation, rope pulling, coal blocking, slipping and motor overload. Taking the health monitoring scene of the belt conveyor and the motor of the belt conveyor as an example, a data security management method of a belt conveyor RCM platform is executed, and the data classification system and the protection strategy are shown in Table 1 as follows: Table 1 Data classification system and protection strategy

[0042] The full life cycle safety control process is as follows: 1. Data acquisition stage Sensor layer: The belt tension sensor and the motor current transformer transmit data through the OPC-UA protocol, and the edge PLC node uses the national SM2 algorithm to sign the data. The signed data is uploaded to the platform through lightweight TLS 1.3 encryption, which is suitable for the low computing power scene of the belt conveyor PLC.

[0043] 2. Analysis and calculation stage Trusted computing layer: The encrypted data is decrypted in the Intel SGX enclave, matched with the different synchronization belt conveyor in the FMEA library History failure mode, and the residual life prediction value of the belt conveyor is generated. The output result is attached with the SM3 hash value and the SM2 signature timestamp to prevent result tampering.

[0044] 3. Maintenance execution stage Work order and field operation: the system automatically desensitizes the belt conveyor position coordinates, generates a maintenance work order signed with SM2. Maintenance personnel operate by scanning the code through the secure sandbox APP: the APP forces the use of national encryption algorithm to encrypt the transmission of positioning trajectory; local cache data ≤ 2 hours, preventing device loss and leakage.

[0045] 4. Feedback update phase Model iteration and audit: compare actual belt conveyor wear data with predicted values, actual wear 0.8mm vs predicted value 0.3mm, difference >10% triggers audit: new model signed by provincial power CA is deployed to SGX environment to ensure source credibility.

[0046] The core logic of differentiated protection in the storage phase is shown in Table 2: Table 2 Core logic of differentiated protection in the storage phase

[0047] The dynamic permission engine forces multi-factor authentication in the following scenarios: iris and dynamic token; access time is during the coal feeding peak period, non-maintenance window; login location is >1km from the belt conveyor workshop, geofencing strategy; access to motor overload prediction coefficients in level 3 data.

[0048] In the scenario of sudden belt slip leading to shutdown of B-line belt conveyor, complete safety event response: Current sensor detects abnormal fluctuation of level 1 data, which is uploaded after SM2 signature and TLS encryption; compare real-time data with FMEA library in SGX enclave, match belt conveyor out-of-sync fault mode; engineer modifies RPN value at 23:00 non-working time, triggers multi-factor authentication; blockchain record shows that account A did not trigger double-check, system automatically rolls back operation and freezes account; actual wear 0.8mm vs predicted value 0.3mm, deviation >10% triggers safety audit, trace shows that parameter β was tampered with, system automatically rolls back modification, freezes account and alerts.

[0049] Verify technical feasibility, the verification results are shown in Table 3: Table 3 Verification results of technical feasibility

[0050] This embodiment directly responds to the pain points such as belt slip in a certain power plant, and through four-level data classification driving protection, real-time current data lightweight encryption and life model full isolation, while protecting FMEA library in level 2 data to prevent tampering with level 3 data protection model parameters, level 1 data protection only needs to be signed, reducing the edge PLC computing power load. The actual measurement shows that the delay introduced by the security mechanism is <50ms, which does not affect the real-time control of the belt conveyor.

[0051] Those skilled in the art will appreciate that embodiments of the application can be devised for a method, a system, or a computer program product. Accordingly, the present application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.

[0052] The present application is described in reference to the flowchart and / or block diagrams of the method, apparatus (system) and computer program product according to embodiments of the application. It will be understood that each block of the flowchart and / or block diagrams, and combinations of blocks in the flowchart and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.

[0053] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.

[0054] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks. Figure 1 one or more functions specified in the flowchart and / or block diagram block or blocks.

[0055] Finally, it should be noted that the above-mentioned embodiments are only used to illustrate the technical solutions of the present application, but not to limit it. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that the specific embodiments of the present application can be modified or replaced, and any modification or replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the present application.

Claims

1. A data security management method for a belt conveyor RCM platform, characterized in that: The following steps are involved: Establish The belt conveyor RCM four-level data classification system includes primary, secondary, tertiary, and tertiary data. The secondary data includes the belt conveyor FMEA library data, which is protected by blockchain evidence storage and two-person modification and review. The tertiary data includes the belt conveyor and motor life prediction model parameters, which are protected by computing in a trusted execution environment. Based on a four-level data classification system and dynamic permission instructions, differentiated protection measures are implemented throughout the data lifecycle, including: During the storage phase, static data is encrypted using the SM4 national encryption algorithm, and dynamic data is encrypted using memory encryption. During the transmission phase, an encrypted tunnel is used between the PLC and the server, and the API interface uses HTTPS and JWT tokens; During the usage phase, dynamic desensitization and three-member separation of authority model are implemented; The dynamic permission instructions are issued to the entire life cycle of data through the dynamic permission control engine. The dynamic permission control engine is based on a four-level data classification system and dynamically improves the authentication strength of the entire life cycle of data based on environmental risks. Access during non-working hours and modification of the operation life model outside the geographic fence trigger mandatory multi-factor authentication.

2. The data security management method of the belt conveyor RCM platform according to claim 1 is characterized in that: The protection is achieved by using blockchain evidence storage and two-person modification review. Specifically, when modifying the RPN value of the belt conveyor fault in the FMEA library, the following steps are performed: If the change in the RPN value of a belt conveyor failure exceeds the amplitude threshold, a three-level review and approval process will be triggered. After approval, the operation hash value will be written into the cross-factory alliance chain for evidence storage. Belt conveyor failures include deviation, rope pulling, coal blockage, and slipping.

3. The data security management method of a belt conveyor RCM platform according to claim 1 is characterized in that: The first-level data includes real-time monitoring data of conveyor belt current and vibration, which is protected by transmission encryption and memory processing isolation; The fourth-level data includes cross-power plant maintenance work order records, which are protected by implementing field-level desensitization and access IP whitelist control.

4. The data security management method of a belt conveyor RCM platform according to claim 1 is characterized in that: The scenarios that trigger mandatory multi-factor authentication include: The access time is during the non-maintenance window period; The distance between the login location and the belt conveyor workshop is greater than the threshold; Retrieve the predicted value of the remaining life of the motor from the third-level data.

5. The data security management method of a belt conveyor RCM platform according to claim 1 is characterized in that: Static data in the storage phase is encrypted by data type partition, and the key is managed by the hardware security module; dynamic data in the storage phase is processed in Intel SGX or ARM TrustZone encrypted memory, and dynamic data is prohibited from leaving the TEE environment; The use phase includes a maintenance decision phase, wherein security controls in the maintenance decision phase include: attaching an SM2 digital signature to the maintenance work order, transmitting positioning data using a national secret algorithm using on-site maintenance software, and ensuring that the local storage time is less than the cache limit time; The usage phase and transmission phase include a feedback iteration phase. The security control of the feedback iteration phase includes: automatically comparing the deviation between the actual belt conveyor wear data and the belt conveyor wear prediction value to obtain a comparison difference value, triggering an audit alarm when the comparison difference value exceeds the comparison threshold, and deploying the update package of the belt conveyor and motor life prediction model to the TEE environment after verification by the CA certificate.

6. The data security management method of a belt conveyor RCM platform according to claim 1 is characterized in that: Deploying differentiated protection measures throughout the data lifecycle also includes: During the collection phase, the PLC industrial protocol of the belt conveyor enables message signatures, and the PLC edge gateway of the belt conveyor deploys lightweight TLS; During the destruction phase, multiple physical overwrite deletions are performed on the scrapped hard disk.

7. The data security management method of a belt conveyor RCM platform according to claim 1 is characterized in that: The deployment of the intelligent risk perception engine includes: Real-time monitoring of abnormal access patterns, including FMEA library download operations that exceed the access threshold within a single hour. If the access pattern is abnormal, the account permissions are automatically restricted and screen recording is started. The root cause of the abnormal access is analyzed based on the SHAP algorithm.

8. A data security management system for a belt conveyor RCM platform, characterized in that: include: The data classification module is used to establish a four-level data classification system for belt conveyor RCM, including primary, secondary, tertiary, and quaternary data. The secondary data includes the belt conveyor FMEA library data, which is protected by blockchain evidence storage and two-person modification and review. The tertiary data includes the belt conveyor and motor life prediction model parameters, which are protected by computing through a trusted execution environment. The differentiated protection module is used to implement differentiated protection measures throughout the data lifecycle based on a four-level data classification system and dynamic permission instructions, including: During the storage phase, static data is encrypted using the SM4 national encryption algorithm, and dynamic data is encrypted using memory encryption. During the transmission phase, an encrypted tunnel is used between the PLC and the server, and the API interface uses HTTPS and JWT tokens; During the usage phase, dynamic desensitization and three-member separation of authority model are implemented; The dynamic instruction issuing module is used to issue the dynamic permission instructions to the entire life cycle of data through the dynamic permission control engine. The dynamic permission control engine is based on a four-level data classification system and dynamically improves the authentication strength of the entire life cycle of data based on environmental risks. Access during non-working hours and modification of the operation life model outside the geographic fence trigger mandatory multi-factor authentication.

9. An electronic device, characterized in that: It includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the data security management method for a belt conveyor RCM platform as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the data security management method for a belt conveyor RCM platform described in any one of claims 1 to 7 is implemented.