Industrial safety data encryption access control method and platform

By classifying industrial data by attributes, dividing it into security levels, and implementing multi-level encryption, combined with fine-grained access control, the problem of mismatch between encryption strategies and data security requirements in existing technologies is solved, and efficient and secure dynamic access management of industrial data is achieved.

CN120880809BActive Publication Date: 2026-03-20BEIJING RONGSHUAN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

Existing technologies lack sophisticated identification and hierarchical encryption mechanisms for the sensitivity levels of industrial data, resulting in a mismatch between encryption strategies and data security requirements. This affects data security and precise access control during dynamic access by multiple roles in industrial systems.

Method used

By collecting industrial system datasets, classifying and encoding attributes, establishing a data security quantitative indicator system for security level classification, constructing a multi-level data encryption algorithm list, configuring fine-grained access mechanisms and decryption interaction mechanisms, and realizing multi-dimensional correlation analysis and dynamic encrypted access collaborative management based on data attributes, security levels, and user roles.

Benefits of technology

It enhances the confidentiality, controllability, and auditability of industrial data storage and access, ensuring that data is encrypted as needed, used according to permissions, and is traceable throughout the entire process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880809B_ABST
    Figure CN120880809B_ABST
Patent Text Reader

Abstract

The application provides an encryption access control method and platform for industrial safety data, and relates to the technical field of data encryption access. The method comprises the following steps: performing attribute classification and coding identification on an industrial system data set; performing safety level division on the industrial system data set according to a data safety quantification index system; performing matching analysis on the multi-level industrial safety data set based on a data encryption algorithm list; performing encrypted storage on the industrial system data set based on the multi-level data encryption algorithm and the industrial data identification code set to generate an industrial encrypted data warehouse; establishing a fine-grained access mechanism and a decryption interaction mechanism according to a user role library; and performing access permission allocation and encryption access control on the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism. The application can solve the technical problem that the existing technology cannot meet the comprehensive requirements of high safety, high precision and high flexibility in modern industrial systems.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data encryption access, and particularly relates to an encryption access control method and platform for industrial security data. BACKGROUND

[0002] With the rapid development of industrial informatization, a large amount of industrial data is collected and stored in real time through automatic collection systems and industrial Internet of Things platforms, and has the characteristics of intensity, continuity and high sensitivity. Therefore, guaranteeing the security and reasonable use of industrial data has become an important prerequisite for the operation of industrial systems.

[0003] At present, the existing industrial data protection scheme mostly relies on traditional static encryption methods and coarse-grained access control mechanisms, such as uniform key encryption, simple permission allocation based on roles and the like. Although these methods have certain feasibility in small-scale or closed environments, in the face of multi-role concurrent access, large-scale distributed data storage, multi-level security level requirements and frequently changing access scenarios, the existing technology shows many shortcomings.

[0004] In summary, in the prior art, due to the lack of fine identification and hierarchical encryption mechanism for the sensitivity level of industrial data, the encryption strategy does not match the data security demand, which further affects the data security guarantee and precise control of permissions in the multi-role dynamic access process in the industrial system. SUMMARY

[0005] The purpose of the present application is to provide an encryption access control method and platform for industrial security data, to solve the technical problem in the prior art that due to the lack of fine identification and hierarchical encryption mechanism for the sensitivity level of industrial data, the encryption strategy does not match the data security demand, which further affects the data security guarantee and precise control of permissions in the multi-role dynamic access process in the industrial system.

[0006] In view of the above problems, the present application provides an encryption access control method and platform for industrial security data.

[0007] In a first aspect, the application provides an encryption access control method for industrial safety data, which is implemented by an encryption access control platform for industrial safety data, and includes the following steps: collecting an industrial system data set, performing attribute classification and encoding identification on the industrial system data set to obtain an industrial data identification code set; building a data security quantization index system, performing safety level division on the industrial system data set according to the data security quantization index system to obtain a multi-level industrial safety data set; constructing a data encryption algorithm list, performing matching analysis on the multi-level industrial safety data set based on the data encryption algorithm list, and configuring a multi-level data encryption algorithm; using the multi-level data encryption algorithm to perform encrypted storage on the industrial system data set based on the industrial data identification code set, and generating an industrial encrypted data warehouse; establishing a fine-grained access mechanism and a decryption interaction mechanism according to a user role library, and performing access permission allocation and encryption access control on the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

[0008] Preferably, the encryption access control method for industrial safety data further includes: constructing a data attribute classification element, the data attribute classification element including data source, data type, business requirement and collection time; performing data cleaning and attribute classification on the industrial system data set based on the data attribute classification element to obtain an industrial data attribute parameter set; designing an attribute encoding mapping table according to the data attribute classification element, the attribute encoding mapping table including encoding mode, encoding sequence and encoding length; and performing encoding identification on the industrial data attribute parameter set according to the attribute encoding mapping table to obtain the industrial data identification code set.

[0009] Preferably, the encryption access control method for industrial safety data further includes: performing safety requirement evaluation on the industrial system data set according to the data security quantization index system to generate a data index quantization coefficient matrix set; performing influence degree analysis on each index information in the data security quantization index system to obtain a safety index influence factor matrix; respectively performing weighted fusion on the data index quantization coefficient matrix set based on the safety index influence factor matrix to obtain an industrial data safety coefficient set; and performing safety level division on the industrial system data set according to the industrial data safety coefficient set to obtain the multi-level industrial safety data set.

[0010] Preferably, the industrial security data encryption access control method further comprises: using the multi-level data encryption algorithm to perform hierarchical encryption on the industrial system data set based on the industrial data identification code set, to obtain an industrial encrypted data set; performing collection time identification on the industrial encrypted data set, and designing a hierarchical storage structure according to data collection time, the hierarchical storage structure comprising a hot data layer and a cold data layer, wherein the collection time of the hot data layer is after that of the cold data layer; and mapping the industrial encrypted data set to the hierarchical storage structure for hierarchical encryption storage, to generate the industrial encrypted data warehouse.

[0011] Preferably, the industrial security data encryption access control method further comprises: setting a data access permission allocation rule, the data access permission allocation rule comprising role access control and dynamic attribute access control; performing permission allocation analysis on the user role library based on the role access control and the dynamic attribute access control, to construct a fine-grained access mechanism; and constructing an identity authentication strategy, performing permission verification and key interaction on the user role library based on the identity authentication strategy, to establish a decryption interaction mechanism.

[0012] Preferably, the industrial security data encryption access control method further comprises: performing access permission analysis on each role in the user role library based on the multi-level industrial security data set according to the role access control, to obtain role accessible level data; performing dynamic condition judgment on the access environment attribute of the user role library based on the dynamic attribute access control, to obtain role dynamic accessible range; taking the intersection of the role accessible level data and the role dynamic accessible range as role access permission data, to construct the fine-grained access mechanism.

[0013] Preferably, the industrial security data encryption access control method further comprises: obtaining an identity authentication mode combination, matching and analyzing the role access permission of the user role library with the identity authentication mode combination, to determine a role identity hierarchical verification program; performing full-line verification on the user role library based on the role identity hierarchical verification program, to construct the identity authentication strategy.

[0014] Preferably, the industrial security data encryption access control method further comprises: obtaining a target access user, performing dynamic permission allocation and industrial data calling on the target access user and the industrial encrypted data warehouse based on the fine-grained access mechanism, to obtain target access permission data; performing permission verification and key issuance on the target access user using the decryption interaction mechanism, to obtain a target decryption key; and performing decryption access control on the target access permission data based on the target decryption key.

[0015] Preferably, the industrial security data encryption access control method further comprises: recording access operations on the industrial encryption data warehouse, obtaining an industrial data access record log, and performing data audit tracking based on the industrial data access record log.

[0016] In a second aspect, the present application also provides an industrial security data encryption access control platform for performing the industrial security data encryption access control method of the first aspect, comprising: an encoding identification module for collecting an industrial system data set, performing attribute classification and encoding identification on the industrial system data set, and obtaining an industrial data identification code set; a security level division module for building a data security quantification index system, performing security level division on the industrial system data set according to the data security quantification index system, and obtaining a multi-level industrial security data set; a matching analysis module for constructing a data encryption algorithm list, performing matching analysis on the multi-level industrial security data set based on the data encryption algorithm list, and configuring multi-level data encryption algorithms; an encryption storage module for performing encryption storage on the industrial system data set based on the industrial data identification code set using the multi-level data encryption algorithms, and generating an industrial encryption data warehouse; and an encryption access control module for establishing a fine-grained access mechanism and a decryption interaction mechanism according to a user role library, and performing access permission allocation and encryption access control on the industrial encryption data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

[0017] The technical solutions provided in the present application have at least the following technical effects or advantages: by achieving the technical target of multi-dimensional correlation analysis and dynamic encryption access collaborative management based on data attributes, security levels and user roles, the confidentiality, controllability and auditability in the process of industrial data storage and access are improved, and the technical effect of ensuring data encryption on demand, usage according to rights and traceability throughout the process is achieved.

[0018] The above description is only a summary of the technical solutions of the present application. In order to enable one skilled in the art to better understand the technical means of the present application, the present application can be implemented according to the content of the specification, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. It should be understood that the content described in this section is not intended to identify key or important features of embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings described below are only exemplary, and other drawings can be obtained by those skilled in the art without creative effort on the basis of the provided drawings.

[0020] Figure 1 A flowchart of an industrial security data encryption access control method of the application.

[0021] Figure 2 A structural diagram of an industrial security data encryption access control platform of the application.

[0022] Legend: coding identification module 11, security level division module 12, matching analysis module 13, encryption storage module 14, encryption access control module 15. DETAILED DESCRIPTION

[0023] The application provides an industrial security data encryption access control method and platform, which solves the technical problem in the prior art that due to lack of fine identification and hierarchical encryption mechanism of industrial data sensitivity level, the encryption strategy does not match the data security demand, which further affects the data security guarantee and precise control of the right in the multi-role dynamic access process in the industrial system. The technical goal of multi-dimensional correlation analysis and dynamic encryption access collaborative management based on data attributes, security levels and user roles is achieved, the confidentiality, controllability and auditability in the industrial data storage and access process are improved, and the technical effect of ensuring data encryption on demand, right use and whole-process traceability is achieved.

[0024] The technical solutions in the application will be described clearly and completely below with reference to the drawings. Obviously, the described embodiments are only part of the embodiments of the application, not all embodiments of the application, and it should be understood that the application is not limited to the example embodiments described here. Based on the embodiments of the application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the application. In addition, it should be noted that only parts related to the application are shown in the drawings for convenience of description, not all.

[0025] Embodiment one, please refer to the attached Figure 1 The application provides an industrial security data encryption access control method, which is applied to an industrial security data encryption access control platform, and specifically includes the following steps:

[0026] S1: Collecting an industrial system data set, performing attribute classification and coding identification on the industrial system data set, and obtaining an industrial data identification code set.

[0027] Specifically, collecting an industrial system dataset refers to collecting various forms of data such as temperature, current, device operating state, fault alarm record, etc. that may come from multiple different subsystems or device sources from industrial production or operation and maintenance processes through sensors, controllers, monitoring systems, etc. Attribute classification is performed on the industrial system dataset, and the data is divided according to dimensions such as data source, type, purpose, and time. For example, temperature sensor data of the same production line can be classified into one category, and power consumption data for energy consumption statistics can be classified into another category. Different classifications can help to clarify the functional attributes and business relationships of each category of data. Encoding identification refers to generating a unique identification code for each piece of data based on the classification results to obtain an industrial data identification code set, and then providing each piece of collected and classified data with a clear identity for subsequent retrieval, encryption, permission control, etc. Through the continuous process of collection, classification, and coding, the original scattered data can be transformed into a clear and traceable dataset.

[0028] S2: Building a data security quantification index system, dividing the industrial system dataset into different security levels according to the data security quantification index system, and obtaining a multi-level industrial security dataset.

[0029] Specifically, building a data security quantification index system refers to establishing a standardized evaluation system for evaluating the importance of different data in the industrial system in terms of security, which is composed of multiple quantifiable security indicators such as data sensitivity, business dependency, access frequency, modification risk, and historical leakage records. Each indicator measures its impact on data security by assigning specific numerical values, such as sensitivity, which can be rated from 0 to 10, with higher ratings indicating greater sensitivity. Dividing the industrial system dataset into different security levels according to the data security quantification index system refers to scoring each piece or each category of data based on the indicators, then calculating the comprehensive security score, and then dividing different security levels according to the score interval, so as to group the data from high to low according to security needs, and obtain a multi-level industrial security dataset, which helps to clarify the data that needs strong encryption and strict access control, thereby improving processing efficiency while ensuring security.

[0030] S3: Building a data encryption algorithm list, performing matching analysis on the multi-level industrial security dataset based on the data encryption algorithm list, and configuring multi-level data encryption algorithms.

[0031] Specifically, a data encryption algorithm list is constructed, a set of encryption algorithms suitable for different security levels is pre-arranged and selected, which can include symmetric encryption, asymmetric encryption, hash algorithm and hybrid encryption technology, etc., among which symmetric encryption such as AES is suitable for data processing with high efficiency requirement, asymmetric encryption such as RSA is suitable for key data transmission link, hash algorithm such as SHA is used for data integrity check, and hybrid encryption combines symmetric and asymmetric algorithms to balance security and performance. Based on the data encryption algorithm list, the multi-level industrial safety data set is matched and analyzed, according to the security requirements of different data levels, the specific requirements of encryption strength, encryption speed, key length, etc. are analyzed, and the most suitable encryption algorithm is selected for adaptation, for example, first-level high-sensitive data may need asymmetric encryption with dynamic key, and third-level low-sensitive data may only need basic symmetric encryption. The matching result is implemented, and the corresponding encryption method and parameter are specified for each security level data, that is, the multi-level data encryption algorithm is configured, which not only can guarantee the confidentiality and integrity of different level data, but also can avoid the waste of resources caused by using high-strength encryption for all data.

[0032] S4: using the multi-level data encryption algorithm to encrypt and store the industrial system data set based on the industrial data identification code set, to generate an industrial encrypted data warehouse.

[0033] Specifically, using the multi-level data encryption algorithm, the industrial system data set is encrypted and stored based on the industrial data identification code set, that is, according to the data encryption algorithm list, the corresponding encryption method is selected for processing according to the security level of each type of data, for example, highly sensitive data, medium sensitive data and low sensitive data are respectively processed by different encryption methods, so as to realize the targeted configuration of encryption method. Using the classification information and security level information contained in the identification code of each data, the corresponding encryption algorithm is automatically matched and the original data is encrypted, and then the encrypted data is stored in order according to the identification code structure, thereby forming a recognizable, decryptable and manageable data set. All the data processed by hierarchical encryption is uniformly organized into a structured storage platform to generate an industrial encrypted data warehouse, so that the industrial encrypted data warehouse not only has high security, but also supports efficient retrieval and scheduling management according to data level, time or source and other dimensions.

[0034] S5: according to the user role library, establishing a fine-grained access mechanism and a decryption interaction mechanism, and distributing access permissions and controlling encrypted access to the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

[0035] Specifically, the user role library is a pre-established user information set, wherein each user has a unique identity and is associated with information such as the role to which the user belongs, the scope of responsibility, the level of authority, and the use environment, for example, an administrator, a device engineer, and a security auditor of a certain enterprise have different data access permissions in the role library. According to the user role library, a fine-grained access mechanism is established to further refine the access control granularity, considering not only the user identity and role permission, but also dynamic factors such as the security level of the data, the access time, the operation type, and the use scenario.

[0036] The decryption interaction mechanism refers to when a user requests to access controlled data, after verifying the legitimacy of the user's identity, the decryption operation is completed through key distribution and permission verification, for example, a temporary key is distributed to qualified users through a two-factor authentication encryption method and the identity of the user is verified to see if it matches the permission level. Based on the fine-grained access mechanism and the decryption interaction mechanism, the access permission of the industrial encrypted data warehouse is allocated and the encrypted access control is controlled, whether the user can access the data, what kind of data the user can access, how the user accesses the data, and whether the access process triggers the dynamic negotiation of the key. Through the user role library, the identity basis is provided, the fine-grained access mechanism provides precise control conditions, and the decryption interaction mechanism ensures the security of the key. The three work together to build a strict and dynamically adjustable encrypted access control system, which can effectively meet the industrial security access needs of different users, different scenarios, and different data sensitivity.

[0037] Further, the application also includes: constructing a data attribute classification element, the data attribute classification element including data source, data type, business requirement, and collection time; performing data cleaning and attribute classification on the industrial system data set based on the data attribute classification element to obtain an industrial data attribute parameter set; designing an attribute coding mapping table according to the data attribute classification element, the attribute coding mapping table including coding mode, coding order, and coding length; and coding the industrial data attribute parameter set according to the attribute coding mapping table to obtain the industrial data identification code set.

[0038] Specifically, constructing a data attribute classification element means dividing different attribute dimensions for the industrial system data set to describe the basic characteristics of the data. The data attribute classification element includes data source, data type, business requirement, and collection time. Among them, the data source refers to which device, system, or platform the industrial system data set is collected from, for example, from a sensor, a control system, or a database; the data type is a distinction of the content form of the industrial system data set, such as numerical, textual, image, or state quantity; the business requirement indicates the purpose of the industrial system data set in the business process, such as alarm judgment, device predictive maintenance, or energy consumption analysis; and the collection time refers to the specific time stamp of the collection of the industrial system data set, which is used for subsequent sorting, synchronization, and analysis.

[0039] Subsequently, data cleaning and attribute classification are performed on the industrial system dataset based on the data attribute classification elements, the original data is cleaned and processed such as denoising, deduplication, and format standardization to improve data quality and consistency, and the data is classified according to dimensions such as data source, data type, business requirement, and collection time. For example, multiple data of the same device within the same time period can be aggregated together and attributed to the same classification, so that the data can be more clearly organized and queried, and a structured industrial data attribute parameter set is obtained.

[0040] Further, an attribute coding mapping table is designed according to the data attribute classification elements, which is used to specify how to convert different attributes of the data into standardized codes. The attribute coding mapping table includes coding method, coding order, and coding length. The coding method is, for example, to use Arabic numerals, letters, or hash algorithm for coding; the coding order determines the order of appearance of each attribute in the final identification code, for example, the source first and then the type; and the coding length represents the fixed or variable byte number of each coding segment, for example, the data source can be represented by four digits.

[0041] Finally, each industrial data attribute parameter in the industrial data attribute parameter set is converted into a unique identification code according to the attribute coding mapping table, forming an industrial data identification code set. Each identification code is equivalent to labeling the original data with an information tag, which facilitates subsequent data classification, security control, or index access.

[0042] Further, the present application also includes: performing security requirement evaluation on the industrial system dataset according to the data security quantification index system, generating a data index quantification coefficient matrix set; performing influence degree analysis on each index information in the data security quantification index system, obtaining a security index influence factor matrix; respectively weighting and fusing the data index quantification coefficient matrix set based on the security index influence factor matrix, obtaining an industrial data security coefficient set; and dividing the industrial system dataset into security levels according to the industrial data security coefficient set, obtaining the multi-level industrial security dataset.

[0043] Specifically, the security requirement evaluation on the industrial system dataset is performed according to the data security quantification index system. A set of standard system for measuring data security is prepared in advance, and each piece of industrial data is analyzed to determine its security requirements in dimensions such as confidentiality, integrity, and availability. The data security quantification index system includes multiple specific indexes, such as sensitivity level, business dependency, access frequency, and data granularity. By scoring each type of data in the industrial system, a plurality of quantification values can be formed, and finally a data index quantification coefficient matrix set is formed, in which each row corresponds to a piece of data and each column corresponds to a security index item. The value in the matrix represents the quantification score of each row of data under each column of index.

[0044] Next, the influence degree of each index information in the data security quantitative index system is analyzed, and the weight and contribution of each security index in the overall data security evaluation are evaluated. Different indexes have different influence degrees on security, such as the sensitivity level of data, which may be more critical to security than access frequency. Through expert experience, statistical analysis or regression algorithm, etc., the influence degree of each index can be quantified, a security index influence factor matrix is generated, and the weight value of each index in the overall security scoring system is recorded.

[0045] Based on the security index influence factor matrix, the data index quantitative coefficient matrix set is weighted and fused, the quantitative score of each index is multiplied by the corresponding influence factor, and then the results are accumulated to obtain a set of comprehensive scores, that is, an industrial data security coefficient set, which represents the security coefficient of each data under comprehensive security evaluation. The higher the value, the more the index data needs to be strictly protected.

[0046] Finally, according to the industrial data security coefficient set, the industrial system data set is divided into security levels, and then all the data is allocated to different security levels. It can usually be divided into three or five security levels, such as low, medium, high, or one to five levels, corresponding to different encryption strategies and access permissions. The result of the division is a multi-level industrial security data set, and different levels of data will use different encryption and access control methods in subsequent processes.

[0047] Further, the application also includes: using the multi-level data encryption algorithm to perform hierarchical encryption on the industrial system data set based on the industrial data identification code set, to obtain an industrial encrypted data set; collecting time identification of the industrial encrypted data set, and designing a layered storage structure according to the data collection time, the layered storage structure including a hot data layer and a cold data layer, wherein the collection time of the hot data layer is after the cold data layer; mapping the industrial encrypted data set to the layered storage structure for hierarchical encryption storage, to generate the industrial encrypted data warehouse.

[0048] Specifically, the multi-level data encryption algorithm is used to perform hierarchical encryption on the industrial system data set based on the industrial data identification code set, and the security level information contained in the identification code corresponding to each industrial data is used to select a matching encryption method to encrypt different levels of data respectively. The multi-level data encryption algorithm represents the strategy of using different encryption strengths for data corresponding to different security levels, for example, level one data uses RSA algorithm, level two data uses AES algorithm, and level three data may only use lightweight hash encryption, thereby forming an industrial encrypted data set, that is, an industrial data set after hierarchical encryption processing. Table 1 shows part of the records of the last industrial system data hierarchical encryption.

[0049] Table 1: Partial records of the last industrial system data encryption

[0050]

[0051] Then, after the data is encrypted, the collection time of the industrial encrypted data set is marked, and the collection time of each data record is recorded, and a hierarchical storage structure is designed according to the data collection time, and the data is divided into different storage levels. The hierarchical structure is mainly divided into hot data layer and cold data layer. The hot data layer contains recently collected data, and the access frequency is high, such as the data of the last 7 days; and the cold data layer includes historical data, and the access frequency is low, for example, data more than 30 days. Further, optimization between storage resource utilization and access speed can be achieved.

[0052] The industrial encrypted data set is mapped to the hierarchical storage structure for hierarchical encryption storage. The encrypted and time-identified data is allocated to the hot data layer or the cold data layer according to the time period it belongs to, and is further organized and stored according to different security levels, to generate an industrial encrypted data warehouse, and to build a unified and structured industrial encrypted data warehouse. The industrial encrypted data warehouse not only has high security, but also has good retrieval efficiency and scalability.

[0053] Further, the application also includes: setting a data access permission allocation rule, the data access permission allocation rule including role access control and dynamic attribute access control; performing permission allocation analysis on the user role library based on the role access control and the dynamic attribute access control, and constructing a fine-grained access mechanism; constructing an identity verification strategy, performing permission verification and key interaction on the user role library based on the identity verification strategy, and establishing a decryption interaction mechanism.

[0054] Specifically, to ensure the safe and compliant use of industrial encrypted data, a management mechanism is developed to restrict the access permissions of different users, that is, a data access permission allocation rule is set to control data access behavior according to user identity and use environment to prevent unauthorized reading, modification or leakage. The data access permission allocation rule includes role access control and dynamic attribute access control. The role access control assigns different roles, such as administrators, operators or auditors, corresponding data access ranges and permission levels according to the roles of users in the organizational structure, for example, administrators can access all data and have modification permissions, while operators can only read data related to the work section they are responsible for, which is conducive to maintaining consistency with the organizational permission system. The dynamic attribute access control is to further introduce dynamic environmental attributes such as user behavior, access time, access location or use equipment for real-time judgment based on role permissions to determine whether to authorize access.

[0055] After the permission assignment analysis of the user role library based on the role-based access control and the dynamic attribute-based access control, and the basic access permission of each user role is clear, further combined with real-time environmental factors, such as access time, geographic location, terminal device type and other dynamic attributes, the permission of each role is further adjusted and refined, so that the access range of all users in the user role library is accurately divided. The role-based access control is based on the access strategy of the function assumed by the user identity, for example, the dispatcher can view the running data but cannot modify the device parameters, and the dynamic attribute-based access control is a dynamic authorization method according to the current state of the user, for example, the user of the same role can access the core system in the intranet environment of the company, but can only read part of the information when accessing the external network. Based on the rules in two dimensions, the permission is disassembled to the smallest granularity, so that each user can only access the data resources that completely match his role and environment, thereby building a set of precise fine-grained access mechanism to realize higher-dimensional security management.

[0056] According to the permission level, access frequency and business risk level of different user roles, a corresponding identity authentication mode combination is designed, for example, only a username and password are required for ordinary monitoring users, and biometric identification and dynamic password dual authentication are required for system maintenance personnel, thereby forming a set of differentiated verification specifications. Based on the identity verification strategy, the permission verification and key interaction of the user role library are carried out, when the user initiates an access request, the corresponding verification program is called according to the identity information in the user role library, and the access key is issued after the verification is passed, thereby completing the user identity confirmation and decryption process. After verification, the decryption key required for access is sent to the user through a secure channel, so that the key is not exposed in an insecure network environment, and the integrity and confidentiality of the data are ensured. The user identity verification and key management process are organically integrated, so that a complete verification and authorization process can be performed before each data access operation, the whole process control of sensitive data access behavior is realized, and finally the decryption interaction mechanism is established.

[0057] Further, the application further comprises: performing access permission analysis on each role in the user role library based on the multi-level industrial safety data set according to the role-based access control, to obtain role accessible level data; performing dynamic condition judgment on the access environment attributes of the user role library based on the dynamic attribute-based access control, to obtain role dynamic accessible range; taking the intersection of the role accessible level data and the role dynamic accessible range as role access permission data, to construct the fine-grained access mechanism.

[0058] Specifically, the role-based access control performs access permission analysis on each role in the user role library based on a multi-level industrial security dataset, that is, using the established role access rules, combined with the different security levels of the industrial data, the system permission of all user roles is evaluated, and the data content level that each type of role can access under the security level system is determined. The multi-level industrial security dataset refers to the different levels of data sets divided according to data security, for example, the first level is core sensitive data, the second level is general business data, and the third level is public operation data. The user role library is a collection of all users and their responsibility information, such as maintenance personnel, dispatch personnel, and device administrators. By matching the role and the data level, a role accessible level data can be generated to define the data range that each role is theoretically allowed to access.

[0059] Further, the environmental attributes at the time of access are introduced, and the dynamic condition judgment of the access environment attributes of the user role library is performed based on dynamic attribute access control, such as whether the access device is registered with the company, whether the access location is in the allowed area, whether the access time is during the working day, and the like, to evaluate whether the access behavior conforms to the security policy under the current environment. The access environment attributes have dynamic change characteristics, and different times or devices may result in different permission determination results, so that the precision of the access control can be improved by dynamic attribute judgment.

[0060] The intersection of the role accessible level data and the dynamic accessible range of the role is taken as the role access permission data, that is, only when the role is allowed within the static permission range and the current access environment conditions meet the requirements, the final access right can be given. The intersection constitutes the role access permission data, ensuring that any access behavior meets the security requirements of both role responsibility and real-time environment. Further, a fine-grained access mechanism is constructed and applied to all data access processes to achieve precise management and dynamic adjustment of each access behavior.

[0061] Further, the present application also includes: obtaining an identity verification mode combination, matching and analyzing the role access permission of the user role library and the identity verification mode combination to determine a role identity hierarchical verification program; performing full-line verification on the user role library based on the role identity hierarchical verification program to construct the identity verification strategy.

[0062] Specifically, a plurality of identity authentication means are preset, such as password authentication, biometric identification, dynamic token, digital certificate, etc., the identity authentication mode combination is obtained, and then the identity authentication means are combined according to the security level and application scenario to form a plurality of authentication schemes to support access control of different intensity. The combination of identity authentication modes can provide multi-layer protection, for example, low sensitive data can use single password authentication, and high sensitive data needs to perform fingerprint identification and hardware key matching at the same time, thereby improving the security of the overall system. According to the role access permission of the user role library and the identity authentication mode combination, the permission level of each role is analyzed, the security verification intensity required by the level is combined, the most matched authentication means are screened out from the authentication mode combination, the exclusive authentication program for identity confirmation of the role is generated, and the role identity hierarchical authentication program is determined. Different roles will perform different complexity verification processes, for example, ordinary users only need to input passwords, while system administrators need to complete three verification steps, including face recognition, USB encryption key and mobile phone verification code synchronization, to ensure that the role permission matches the verification intensity.

[0063] Based on the role identity hierarchical authentication program, the user role library is verified in a whole line, and the authentication program is applied to all users in the user role library one by one. Only after the user successfully completes the respective verification process, the user is recognized as a trusted identity by the system, thereby ensuring that the visitor not only has role permission in logic, but also has been safely screened in actual authentication behavior. Finally, the identity authentication strategy is constructed, the hierarchical authentication rule is solidified as a system, and a complete identity authentication system is formed for continuous management and audit of user identity.

[0064] Further, the application also includes: obtaining a target access user, dynamically assigning permissions to the target access user and the industrial encrypted data warehouse based on the fine-grained access mechanism, and calling industrial data to obtain target access permission data; using the decryption interaction mechanism to verify the permissions of the target access user and issue keys to obtain a target decryption key; and decrypting the target access permission data based on the target decryption key for access control.

[0065] Specifically, when receiving an access request, a specific access subject is identified, and then a target access user is obtained, such as a certain equipment maintenance engineer or dispatcher. The accessible resource range is calculated in real time according to the current user identity, access environment and data security level, and the corresponding data is extracted from the encrypted warehouse according to the accessible resource range, and finally the target access permission data is obtained.

[0066] Then, the target decryption key is used to decrypt the target access permission data, and the extracted encrypted data is decrypted in the user end or the controlled environment, and integrity check and access record are performed in the decryption process; the decryption access control not only includes restoring the data content, but also performs access audit and use restriction on the decrypted data according to the user permission, so as to ensure that the user can only view and operate the data within the permission range.

[0067] Then, the target decryption key is used to decrypt the target access permission data, and the extracted encrypted data is decrypted in the user end or the controlled environment, and integrity check and access record are performed in the decryption process; the decryption access control not only includes restoring the data content, but also performs access audit and use restriction on the decrypted data according to the user permission, so as to ensure that the user can only view and operate the data within the permission range.

[0068] Further, the application also includes: recording the access operation of the industrial encrypted data warehouse, obtaining an industrial data access record log, and performing data audit tracking based on the industrial data access record log.

[0069] Specifically, the access operation of the industrial encrypted data warehouse is recorded, and when the user performs any reading, modifying, copying or downloading operation on the encrypted data, corresponding record information is automatically generated, including user identity, access time, access path, access mode and operation type fields, to obtain an industrial data access record log.

[0070] The fields that may appear in the industrial data access record log include user number, role, IP address, access data item number, access start time, access duration, etc., which are recorded with a time precision of seconds. Based on the industrial data access record log, data audit tracking is performed, the content of the industrial data access record log is analyzed, and it is judged whether the user's access behavior conforms to the permission rules, whether there are frequent access to high-sensitive data, unauthorized behavior or access anomalies, etc., which are used to analyze long-term use trends, access behavior patterns and find potential internal security risks.

[0071] In summary, the industrial security data encryption access control method provided by the application has the following technical effects: by realizing the technical target of multi-dimensional correlation analysis and dynamic encryption access collaborative management based on data attributes, security levels and user roles, the confidentiality, controllability and auditability in the process of industrial data storage and access are improved, and the technical effects of on-demand encryption, on-right use and full-process traceability are ensured.

[0072] Embodiment two, based on the same inventive concept as the industrial security data encryption access control method in the foregoing embodiments, the application also provides an industrial security data encryption access control platform, please refer to the attachedFigure 2 comprises: an encoding identification module 11, configured to collect an industrial system dataset, perform attribute classification and encoding identification on the industrial system dataset, and obtain an industrial data identification code set; a security level division module 12, configured to build a data security quantification index system, perform security level division on the industrial system dataset according to the data security quantification index system, and obtain a multi-level industrial security dataset; a matching analysis module 13, configured to construct a data encryption algorithm list, perform matching analysis on the multi-level industrial security dataset based on the data encryption algorithm list, and configure a multi-level data encryption algorithm; an encrypted storage module 14, configured to perform encrypted storage on the industrial system dataset based on the industrial data identification code set by using the multi-level data encryption algorithm, and generate an industrial encrypted data warehouse; and an encrypted access control module 15, configured to establish a fine-grained access mechanism and a decryption interaction mechanism according to a user role library, and perform access permission allocation and encrypted access control on the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

[0073] Further, the industrial security data encryption access control platform is further configured to: construct a data attribute classification element, the data attribute classification element comprising data source, data type, business requirement, and collection time; perform data cleaning and attribute classification on the industrial system dataset based on the data attribute classification element, and obtain an industrial data attribute parameter set; design an attribute encoding mapping table according to the data attribute classification element, the attribute encoding mapping table comprising encoding mode, encoding sequence, and encoding length; and perform encoding identification on the industrial data attribute parameter set according to the attribute encoding mapping table, and obtain the industrial data identification code set.

[0074] Further, the industrial security data encryption access control platform is further configured to: perform security requirement evaluation on the industrial system dataset according to the data security quantification index system, and generate a data index quantification coefficient matrix set; perform influence degree analysis on each index information in the data security quantification index system, and obtain a security index influence factor matrix; respectively perform weighted fusion on the data index quantification coefficient matrix set based on the security index influence factor matrix, and obtain an industrial data security coefficient set; and perform security level division on the industrial system dataset according to the industrial data security coefficient set, and obtain the multi-level industrial security dataset.

[0075] Further, the industrial security data encryption access control platform is further configured to: perform hierarchical encryption on the industrial system data set based on the industrial data identification code set by using the multi-level data encryption algorithm, to obtain an industrial encrypted data set; perform collection time identification on the industrial encrypted data set, and design a hierarchical storage structure according to data collection time, the hierarchical storage structure including a hot data layer and a cold data layer, wherein the collection time of the hot data layer is later than that of the cold data layer; and map the industrial encrypted data set to the hierarchical storage structure for hierarchical encryption storage, to generate the industrial encrypted data warehouse.

[0076] Further, the industrial security data encryption access control platform is further configured to: set a data access permission allocation rule, the data access permission allocation rule including role access control and dynamic attribute access control; perform permission allocation analysis on the user role library based on the role access control and the dynamic attribute access control, to construct a fine-grained access mechanism; and construct an identity authentication strategy, perform permission verification and key interaction on the user role library based on the identity authentication strategy, and establish a decryption interaction mechanism.

[0077] Further, the industrial security data encryption access control platform is further configured to: perform access permission analysis on each role in the user role library based on the multi-level industrial security data set according to the role access control, to obtain role accessible level data; perform dynamic condition judgment on access environment attributes of the user role library based on the dynamic attribute access control, to obtain role dynamic accessible range; and take the intersection of the role accessible level data and the role dynamic accessible range as role access permission data, to construct the fine-grained access mechanism.

[0078] Further, the industrial security data encryption access control platform is further configured to: obtain an identity authentication mode combination, match and analyze the role access permission of the user role library with the identity authentication mode combination, to determine a role identity hierarchical verification program; perform full-line verification on the user role library based on the role identity hierarchical verification program, to construct the identity authentication strategy.

[0079] Further, the industrial security data encryption access control platform is further configured to: obtain a target access user, perform dynamic permission allocation and industrial data calling on the target access user and the industrial encrypted data warehouse based on the fine-grained access mechanism, to obtain target access permission data; perform permission verification and key issuance on the target access user by using the decryption interaction mechanism, to obtain a target decryption key; and perform decryption access control on the target access permission data based on the target decryption key.

[0080] Further, the industrial security data encryption access control platform is further used for: recording the access operation of the industrial encryption data warehouse, obtaining an industrial data access record log, and performing data audit tracking based on the industrial data access record log.

[0081] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The industrial security data encryption access control method and specific example in the first embodiment are also applicable to the industrial security data encryption access control platform in the present embodiment. The industrial security data encryption access control platform in the present embodiment can be clearly known by those skilled in the art through the foregoing detailed description of the industrial security data encryption access control method. Therefore, for the sake of brevity of the specification, it will not be described in detail here.

[0082] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

[0083] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application also intends to include these modifications and variations.

Claims

1. A method for encrypted access control of industrial security data, characterized in that, The method includes: Collect industrial system datasets, classify and encode the industrial system datasets according to their attributes, and obtain an industrial data identifier code set; A data security quantitative indicator system is established, and the industrial system dataset is classified into security levels according to the data security quantitative indicator system to obtain a multi-level industrial security dataset. Construct a list of data encryption algorithms, perform matching analysis on the multi-level industrial security dataset based on the list of data encryption algorithms, and configure multi-level data encryption algorithms; The multi-level data encryption algorithm is used to encrypt and store the industrial system dataset based on the industrial data identifier code set, thereby generating an industrial encrypted data warehouse. Based on the user role library, a fine-grained access mechanism and a decryption interaction mechanism are established. Based on these mechanisms, access permissions and encrypted access control are performed on the industrial encrypted data warehouse, including: Set data access permission allocation rules, which include role access control and dynamic attribute access control; Based on the aforementioned role-based access control and dynamic attribute-based access control, permission allocation and parsing are performed on the user role database to construct a fine-grained access mechanism, including: Based on the multi-level industrial security dataset, the access control system performs access permission analysis on each role in the user role library according to the role access control, and obtains role access level data. Based on the dynamic attribute access control, the access environment attributes of the user role library are dynamically judged to obtain the dynamic access range of the role. The intersection of the character's accessibility level data and the character's dynamic accessibility range is used as the character's access permission data to construct the fine-grained access mechanism. Construct an authentication policy, perform permission verification and key exchange on the user role database based on the authentication policy, and establish a decryption exchange mechanism, including: Obtain the combination of authentication methods, and match and parse the combination of authentication methods with the role access permissions in the user role database to determine the role identity hierarchical verification procedure; The user role database is fully verified based on the role identity classification verification procedure, and the identity verification strategy is constructed.

2. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The obtained industrial data identifier code set includes: Construct data attribute classification elements, which include data source, data type, business requirements, and collection time; Based on the data attribute classification elements, the industrial system dataset is cleaned and its attributes are classified to obtain an industrial data attribute parameter set. Based on the data attribute classification elements, an attribute coding mapping table is designed, which includes coding method, coding order and coding length. The industrial data attribute parameter set is encoded and identified according to the attribute encoding mapping table to obtain the industrial data identifier code set.

3. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The obtained multi-level industrial safety dataset includes: The security requirements of the industrial system dataset are assessed according to the data security quantification index system, and a set of data index quantification coefficient matrix is ​​generated. An impact analysis was performed on each indicator in the data security quantitative indicator system to obtain a security indicator impact factor matrix. Based on the safety index influence factor matrix, the data index quantification coefficient matrix set is weighted and fused to obtain the industrial data safety coefficient set. The industrial system dataset is classified into security levels according to the industrial data security coefficient set to obtain the multi-level industrial security dataset.

4. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The generation of the industrial encrypted data warehouse includes: The multi-level data encryption algorithm is used to perform hierarchical encryption on the industrial system dataset based on the industrial data identifier code set to obtain an industrial encrypted dataset. The industrial encrypted dataset is identified by its acquisition time, and a hierarchical storage structure is designed according to the data acquisition time. The hierarchical storage structure includes a hot data layer and a cold data layer, wherein the acquisition time of the hot data layer is after that of the cold data layer. The industrial encrypted dataset is mapped to the hierarchical storage structure for hierarchical encrypted storage, thereby generating the industrial encrypted data warehouse.

5. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The method of allocating access permissions and controlling encrypted access to the industrial encrypted data warehouse based on the fine-grained access mechanism and decryption interaction mechanism includes: The target access user is obtained, and dynamic permission allocation and industrial data retrieval are performed on the target access user and the industrial encrypted data warehouse based on the fine-grained access mechanism to obtain target access permission data; The decryption interaction mechanism is used to verify the access rights of the target user and issue a key to obtain the target decryption key; Access control is performed on the target access permission data based on the target decryption key.

6. The encrypted access control method for industrial security data as described in claim 1, characterized in that, The method further includes: Access operations to the industrial encrypted data warehouse are recorded to obtain an industrial data access log, and data auditing and tracing are performed based on the industrial data access log.

7. An encrypted access control platform for industrial security data, characterized in that, The steps for implementing the encrypted access control method for industrial security data according to any one of claims 1 to 6 include: The encoding and identification module is used to collect industrial system datasets, classify and encode the industrial system datasets to obtain an industrial data identification code set. The security level classification module is used to build a data security quantitative indicator system, and classify the industrial system dataset into security levels according to the data security quantitative indicator system to obtain a multi-level industrial security dataset. The matching analysis module is used to construct a list of data encryption algorithms, perform matching analysis on the multi-level industrial security dataset based on the list of data encryption algorithms, and configure multi-level data encryption algorithms. An encrypted storage module is used to encrypt and store the industrial system dataset based on the industrial data identifier code set using the multi-level data encryption algorithm, thereby generating an industrial encrypted data warehouse. The encrypted access control module is used to establish a fine-grained access mechanism and a decryption interaction mechanism based on the user role library, and to allocate access permissions and perform encrypted access control for the industrial encrypted data warehouse based on the fine-grained access mechanism and the decryption interaction mechanism.

Citation Information

Patent Citations

  • Enterprise internal software authority management method and device, equipment and storage medium

    CN118627100A

  • Information data security management method, system, equipment and medium

    CN119046957A