Data security management method

By creating a micro-isolation environment in industrial equipment, using low-encryption strength to process cycle data exchange, and monitoring the matching degree of communication behavior, the problem of traditional encryption delays affecting production is solved, and the stability and rapid response of industrial data security management are achieved.

CN120979795APending Publication Date: 2025-11-18DIANCHI UNIVERSITY (KUNMING) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511315680.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-15
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Traditional industrial equipment lacks cybersecurity protection capabilities in its initial design, causing security devices to perform the same level of encryption on all data packets. This results in encryption delays during multiple rounds of data exchange within a short time window, affecting the production rhythm of industrial production lines.

Method used

Upon receiving a clock data exchange request, a micro-isolation environment is created for participating devices. Data transmission is performed using a lower encryption strength than usual, and external transmission is blocked. Non-clock data requests are cached, and regular encryption is restored after the clock cycle is completed. Utilizing the unique characteristic of clock data exchange, the matching degree between communication behavior and predefined templates is monitored, and abnormal behavior is identified to interrupt transmission. A dynamic trusted device table determines whether a legitimate device initiates the request.

Benefits of technology

To ensure that industrial data security is not affected by temporary security intensity adjustments, reduce production disruptions, quickly identify and block potential attacks, and improve the stability and security of data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979795A_ABST
    Figure CN120979795A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of industrial data management, in particular to a data security management method. The method comprises the following steps: when safety equipment receives a beat data exchange request initiated by industrial equipment, creating a micro-isolation environment for the industrial equipment participating in beat data exchange; in the micro-isolation environment, the security device adopts a processing mode lower than the conventional encryption strength to carry out proxy on data transmission between participating devices, and blocks data transmission from the devices in the micro-isolation environment to the outside at the same time; caching data requests which are not used for rhythm data exchange during rhythm data exchange; and after the beat data exchange period is finished, releasing the micro-isolation environment, and processing the cached data request by using the conventional encryption strength. According to the method, the safety management of the industrial data can be better ensured under the condition that the production is not influenced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of industrial data governance technology, and in particular to a data security management method. Background Technology

[0002] Because traditional industrial equipment was not designed with network security in mind, the common approach to industrial data security is a security device takeover model. This involves deploying dedicated security devices to proxy all data transmission and reception operations of these traditional devices, thereby providing unified security protection for the entire industrial network. In other words, traditional industrial equipment no longer directly participates in network communication; instead, all data transmission needs are handled by security devices, which act as network proxies for the industrial equipment, responsible for performing security functions such as data encryption and transmission.

[0003] This approach does solve the problem of insufficient security capabilities in older industrial equipment, but because the security equipment must perform the same level of encryption on every data packet, each encryption and decryption operation requires some processing time.

[0004] When there are rhythmic operations in an industrial production line that require multiple rounds of data exchange to be completed within a short time window, such as workpiece handover confirmation, the accumulated encryption delay may occasionally exceed the allowable range of the preset handover confirmation time window. This requires waiting for a preset period of time or re-exchanging data, which causes random short-term pauses in the actual workpiece processing process in the industrial production line due to the timeout waiting of these data exchanges, disrupting the production rhythm of the entire industrial production line.

[0005] Therefore, existing technologies still have some problems and cannot better ensure the secure management of industrial data without affecting production. Summary of the Invention

[0006] To address, or at least partially address, the aforementioned technical problems, this application provides a data security management method that can better ensure the secure management of industrial data without affecting production.

[0007] This application proposes a data security management method, which includes the following steps: When the safety device receives a clock data exchange request initiated by an industrial device, it creates a micro-isolation environment for the industrial device participating in the clock data exchange. In the micro-isolation environment, the security device uses a processing method with lower encryption strength than usual to proxy the data transmission between participating devices, while blocking the data transmission from the devices in the micro-isolation environment to the outside. During the clock data exchange, data requests not intended for clock data exchange are cached; After the tick data exchange period ends, the micro-segmentation environment is deactivated, and cached data requests are processed using the normal encryption strength.

[0008] Optionally, the data security management method further includes the following steps: Retrieve the corresponding predefined communication mode template based on the type of the current beat data exchange request; During operation in a micro-isolation environment, the security device continuously monitors the actual communication behavior between participating devices and calculates the uniqueness of the communication behavior matching the predefined communication pattern template. When the uniqueness matching degree is lower than the preset matching degree threshold, data transmission within the micro-isolation environment is interrupted.

[0009] Optionally, the data security management method further includes the following steps: Based on the current runtime data of industrial equipment, a list of industrial equipment that may initiate a clock data exchange request is determined, forming a dynamic trusted equipment table; A micro-segmentation environment is created only when an industrial device in the dynamic trusted device table initiates a clock data exchange request.

[0010] Optionally, based on the current runtime data of the industrial equipment, a list of industrial equipment that may initiate cycle time data exchange requests is determined, forming a dynamic trusted equipment table, including the following steps: Establish a baseline value for the average operating power of each industrial device; Calculate the average power value of each industrial device within a preset sliding time window; When the average power value of an industrial device exceeds a preset duration within a preset deviation range of its corresponding power reference value, the industrial device that meets the conditions will be added to the dynamic trusted device list.

[0011] The technical solution provided in this application has the following advantages compared with the prior art: One of its beneficial effects and its working principle is as follows: Traditional industrial equipment is not designed with network security in mind. Current technologies generally use security devices to uniformly proxy the data transmission and reception of all industrial equipment and perform the same level of encryption on each data packet. As a result, when there are rhythmic operations in the industrial production line that require multiple rounds of data exchange within a short time window, such as workpiece handover confirmation, the accumulated encryption delay may occasionally exceed the allowable range of the preset handover confirmation time window. This causes random short-term pauses in the workpiece processing process in the industrial production line due to the timeout waiting of these data exchanges, disrupting the production rhythm of the entire industrial production line.

[0012] The data security management method provided in this application creates a micro-isolation environment for the participating equipment when the security device receives a clock data exchange request initiated by the industrial equipment. In the micro-isolation environment, a lower-strength encryption method is used to proxy the data transmission between the participating equipment. At the same time, the data transmission path from the equipment in the micro-isolation environment to the external network is blocked. Non-clock data requests during the micro-isolation period are temporarily stored in a buffer. When the micro-isolation environment is released, the cached data is processed with normal encryption strength.

[0013] The beneficial effect of this application lies in its utilization of the differences in security controllability between the clockwise data exchange period and the non-clockwise data exchange period. The clockwise data exchange period is characterized by its short duration, limited attack window for potential attackers, and high uniformity in the participating devices, exchanged data types, and clockwise patterns, making any abnormal behavior easily and quickly identifiable. In contrast, the non-clockwise data exchange period involves complex data exchange types and variable participating devices, lacking the controllability of the clockwise data exchange period. Abnormal behavior is difficult to identify, and it is impossible to determine whether lowering the encryption level is appropriate.

[0014] Therefore, this application utilizes the unique nature of data transmission during clock data exchange and achieves network blocking by creating a micro-isolation environment in a timely manner. This ensures that even with lower encryption strength, data cannot be leaked to the outside world, and guarantees the rapid and stable exchange of clock data.

[0015] Once the cycle data exchange is complete, the micro-segmentation environment is deactivated, and the regular-strength encryption mechanism is reactivated to process non-cycle data requests temporarily stored in the buffer during the cycle data exchange. This ensures that even if industrial equipment data is controlled by hackers or is untrusted before the installation of security equipment, the data transmitted through the security equipment is encrypted, making it impossible to effectively utilize even if leaked.

[0016] Therefore, the data security management method provided in this application ensures that industrial data security is not substantially affected by temporary adjustments in security intensity, while reducing the impact on production.

[0017] Its second beneficial effect and its working principle are as follows: Since security equipment is added later when data security governance is carried out in the factory, if a Trojan or other virus has already infiltrated and controlled a certain industrial equipment before that, it may take advantage of the low-encryption environment during the data exchange period to steal data and launch network attacks.

[0018] This application obtains a corresponding predefined communication mode template based on the type of the current clock data exchange request. During the operation of the micro-isolation environment, the security device continuously monitors the actual communication behavior between participating devices and calculates the uniqueness matching degree between the communication behavior and the predefined communication mode template in real time. When the uniqueness matching degree is lower than the preset matching degree threshold, the data transmission in the micro-isolation environment is immediately interrupted.

[0019] Its beneficial effect is that this application makes full use of the highly regular characteristics of real-time data exchange, such as the regular distribution of data packet sizes, to form a verification mode similar to a communication fingerprint.

[0020] Even if an attacker gains control of a legitimate device, attempting to steal other high-value data or inserting malicious behavior during tick data exchange can cause the tick data communication behavior to deviate from the template, i.e., it will not match the communication fingerprint.

[0021] This application uses pattern matching to quickly identify abnormal communication behavior. When an abnormality in the singleness of match is detected, data transmission within the micro-isolation environment is immediately interrupted to minimize security threats. It can also be used to detect industrial equipment that has been compromised by hackers before data security governance is implemented.

[0022] Therefore, the data security management method proposed in this application can better ensure the security of industrial data.

[0023] Its third beneficial effect and its working principle are as follows: This application forms a dynamic trusted device table by determining a list of industrial devices that may initiate a clock data exchange request based on the current runtime data of the industrial devices. A micro-isolation environment is created only when an industrial device in the dynamic trusted device table initiates a clock data exchange request.

[0024] Its beneficial effect lies in the fact that this application utilizes the operating status of equipment during industrial assembly line production to determine whether the equipment is likely to initiate a cycle data exchange request. For example, when upstream equipment is about to complete processing, downstream equipment needs to prepare to receive the workpiece handover request. By analyzing the operating data of industrial equipment, the participating equipment during these cycle data exchange periods can be identified in advance.

[0025] In this application, only legitimate devices identified based on analysis of their actual operating status can be included in the dynamic trusted device table. This qualification verification method based on runtime data context takes advantage of the technical characteristic that malicious devices find it difficult to forge a complete chain of device operating status.

[0026] When an unexpected device suddenly initiates a tick data exchange period request, this application can immediately identify this illogical abnormal behavior, determine it as a suspected security attack, and refuse to create a micro-isolation environment for it. This effectively blocks potential attack behaviors before the tick data exchange begins, preventing malicious devices from using the low-encryption environment of the tick data exchange period to steal data or penetrate the network.

[0027] Therefore, the data security management method proposed in this application can better ensure the security of industrial data. Attached Figure Description

[0028] Figure 1 This is a flowchart illustrating the data security management method provided in an embodiment of this application. Detailed Implementation

[0029] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0030] Many specific details are set forth in the following description to provide a thorough understanding of this application, but this application may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some embodiments of this application, and not all embodiments. It should be noted that, unless otherwise specified, the embodiments of this application and the features in the embodiments can be combined with each other.

[0031] Firstly, this application proposes a data security management method, such as... Figure 1 As shown, the data security management method includes the following steps: S101: When the safety device receives a clock data exchange request initiated by an industrial device, it creates a micro-isolation environment for the industrial device participating in the clock data exchange.

[0032] Specifically, a cycle data exchange request refers to a request from industrial equipment to complete multiple rounds of data transmission and confirmation according to a preset cycle within a preset time window, such as workpiece handover confirmation, equipment status synchronization, and process parameter transfer. Safety equipment can identify cycle data exchange requests by parsing the request type identifier in the packet header.

[0033] Specifically, creating micro-segmentation environments between industrial devices is an existing technology in the field of cybersecurity. In this application, the security device uses micro-segmentation technology to create a temporary logically isolated communication environment for industrial devices participating in clock data exchange. This environment uses software-defined networking technology to separate the devices participating in the clock data exchange from other devices at the network layer, establishing independent virtual network segments to ensure that clock data only flows within the isolated environment between the participating devices, while blocking the data transmission path from the isolated environment to the external network.

[0034] Specifically, in this embodiment of the application, during normal operation, not all devices create a micro-segmentation environment whenever they issue a tick data exchange request; the following steps are also included: Based on the current runtime data of industrial equipment, a list of industrial equipment that may initiate a clock data exchange request is determined, forming a dynamic trusted equipment table; Specifically, forming a dynamic trusted device table includes the following steps: Establish a baseline value for the average operating power of each industrial device; Specifically, the average operating power reference value for each industrial device is obtained through the following steps: Collect power data for each industrial device under standard operating conditions over 24 hours, and calculate the average value as the benchmark value for average operating power.

[0035] Calculate the average power value of each industrial device within a preset sliding time window; Specifically, in this embodiment, the length of the preset sliding time window is 60 seconds, and the average power value within the sliding window is calculated every 10 seconds. The relevant values ​​can be adjusted according to the actual working scenario.

[0036] When the average power value of an industrial device exceeds a preset duration within a preset deviation range of its corresponding power reference value, the industrial device that meets the conditions will be added to the dynamic trusted device list.

[0037] Specifically, in this embodiment, the preset deviation range is ±15% of the power baseline value, and the preset duration is 30 seconds. When the average power value of the device remains within 85% to 115% of the baseline value for 30 consecutive seconds, it is determined that the industrial equipment has performed a real working process, and its initiated cycle data exchange request is reliable.

[0038] A micro-segmentation environment is created only when an industrial device in the dynamic trusted device table initiates a clock data exchange request.

[0039] In another embodiment, the dynamic trusted device table can be maintained using blockchain technology. The operating status data and trust status changes of each industrial device are stored on the blockchain as immutable records. The device trust assessment and dynamic trusted device table are automatically executed through smart contracts, ensuring that multiple security devices can make collaborative decisions based on unified and tamper-proof trusted device information, thereby further enhancing security.

[0040] S102: In the micro-isolation environment, the security device uses a processing method with lower encryption strength than usual to proxy the data transmission between participating devices, while blocking the data transmission from the devices in the micro-isolation environment to the outside.

[0041] Specifically, standard encryption strength refers to the data encryption methods employed by security devices in normal operating mode, including but not limited to: using RSA-2048 or RSA-4096 asymmetric encryption algorithms for key exchange, AES-256 symmetric encryption algorithm for data transmission, and SHA-256 or SHA-512 hash algorithms for data integrity verification. These high-strength encryption algorithms provide security guarantees that comply with security governance standards.

[0042] Specifically, lower-than-standard encryption strength refers to simplified encryption methods used in micro-segmentation environments. This is relative to standard encryption strength and includes, but is not limited to: using AES-128 instead of AES-256 for data encryption, using lightweight hash algorithms such as CRC32 instead of SHA-256 for integrity checks, or directly using plaintext transmission combined with checksum verification. These simplified methods can reduce the latency of a single data processing operation to 1-5 milliseconds, meeting the real-time requirements of tick-based data exchange.

[0043] It should be noted that data is still relayed through a secure device, rather than through direct communication between devices. The secure device receives data from device A, performs simplified encryption, and then forwards it to device B, and vice versa. This ensures that data transmission occurs at a low encryption level in a micro-segmented environment.

[0044] S103: During the beat data exchange, cache data requests that are not used for beat data exchange.

[0045] After the tick data exchange period ends, the micro-segmentation environment is deactivated, and cached data requests are processed using the normal encryption strength.

[0046] Specifically, data requests not used for cycle data exchange refer to various data communication requests initiated by other industrial equipment, monitoring systems, maintenance terminals, or management systems outside the micro-isolation environment during the cycle data exchange period. Examples include: equipment status query requests, historical data reading requests, parameter configuration modification requests, alarm information reporting requests, and remote diagnostic access requests.

[0047] Specifically, data request caching refers to the process by which a security device temporarily stores received non-tick data requests in a pre-allocated buffer instead of processing and forwarding them immediately.

[0048] Specifically, the criteria for determining the end of the clock data exchange period include: the data packet header sent by the participating devices includes a confirmation signal indicating the completion of the clock, the preset clock time window has expired, or an anomaly in the clock data exchange period is detected, requiring forced termination. Once the clock data exchange period is confirmed to have ended, the security device immediately de-isolates the micro-isolation environment.

[0049] After the micro-segmentation environment is deactivated, cached data requests are processed using standard encryption strength. The cached data requests are then encrypted according to standard procedures and forwarded to the corresponding target device.

[0050] S104: Obtain the corresponding predefined communication mode template based on the type of the current beat data exchange request.

[0051] Specifically, the cycle data exchange request type refers to the classification identifier of cycle operations in different industrial scenarios, including: workpiece handover confirmation type, equipment status synchronization type, process parameter transmission type, quality inspection coordination type, and fault emergency handling type, etc.

[0052] Each type of tick data exchange period operation has a specific data exchange mode and timing requirements, namely the timing fingerprint of the corresponding type.

[0053] Specifically, the predefined communication mode template refers to a standard communication behavior description file pre-established for each type of clock data exchange request, which defines the normal communication characteristics of this type of operation, including: data packet frequency pattern, data packet size distribution range, and time interval pattern.

[0054] Among them, the data packet frequency mode describes the time interval pattern of data transmission in this type of cycle operation. For example, the data packet frequency mode of the workpiece handover confirmation type sends a data packet every 50 milliseconds ± 10 milliseconds for a duration of 400 milliseconds; while the frequency mode of the equipment status synchronization type sends a data packet every 100 milliseconds ± 20 milliseconds for a duration of 200 milliseconds.

[0055] The data packet size distribution range defines the expected size range of data packets at different stages in this type of operation. For example, in the workpiece handover confirmation type, the size range of the quality data packet is 240-270 bytes, the size range of the confirmation response packet is 60-80 bytes, and the size range of the completion notification packet is 120-150 bytes.

[0056] The time interval rule defines the standard time interval between each step in the interaction sequence. For example, the interval from quality data transmission to quality data confirmation should be 10-15 milliseconds, and the interval from process parameter confirmation to physical handover instruction should be 50-80 milliseconds.

[0057] Specifically, in this embodiment of the application, when a beat data exchange request is received, the type identifier field in the request header is parsed first, and the corresponding predefined communication mode template is retrieved based on the identifier, providing a standard reference for subsequent singleness matching degree calculation.

[0058] S105: During operation in a micro-isolation environment, the security device continuously monitors the actual communication behavior between participating devices and calculates the uniqueness of the communication behavior matching the predefined communication pattern template.

[0059] Specifically, the calculation of uniqueness match includes the following steps: Frequency matching degree calculation: Compare the actual data packet transmission interval with the standard frequency pattern defined in the template, and calculate the percentage deviation.

[0060] Size matching degree calculation: Compare the actual data packet size with the size distribution range defined in the template, and calculate the matching degree percentage.

[0061] Timing matching degree calculation: Compare the actual interaction time interval with the time interval pattern defined in the template to calculate the timing matching degree.

[0062] Specifically, the singleness of fit is calculated using a weighted average method, which is the sum of the product of frequency fit, size fit, and time fit, and their corresponding weight coefficients. The weight coefficients are set as empirical parameters, based on experience and the perceived importance of each parameter. For example, in this embodiment, the weight coefficient for frequency fit is set to 0.4, and the weight coefficients for size fit and time fit are set to 0.3.

[0063] Specifically, in this embodiment, a sliding window algorithm is used to calculate the matching degree. The window size is the communication behavior of the most recent 20 data packets. After the security device collects communication behavior data of 20 data packets, it immediately performs a singleness matching degree calculation and compares it with a preset matching degree threshold.

[0064] S106: When the uniqueness matching degree is lower than the preset matching degree threshold, the data transmission in the micro-isolation environment is interrupted.

[0065] When the matching degree falls below the preset threshold, the micro-isolation environment is immediately interrupted and the security event is recorded.

[0066] Specifically, the matching threshold is a preset value. In this embodiment, the preset matching threshold is set to 75%. This value needs to be determined based on test data from an actual industrial environment to ensure that obvious abnormal communication behavior can be effectively identified, while avoiding false alarms caused by fluctuations in normal equipment operation.

[0067] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. Moreover, in the description of the embodiments of this application, unless otherwise stated, " / " signifies "or," for example, A / B can mean A or B; "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist, for example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more.

[0068] The above description is merely a specific embodiment of this application, enabling those skilled in the art to understand or implement this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data security management method, characterized in that, The data security management method includes the following steps: When the safety device receives a clock data exchange request initiated by an industrial device, it creates a micro-isolation environment for the industrial device participating in the clock data exchange. In the micro-isolation environment, the security device uses a processing method with lower encryption strength than usual to proxy the data transmission between participating devices, while blocking the data transmission from the devices in the micro-isolation environment to the outside. During the clock data exchange, data requests not intended for clock data exchange are cached; After the tick data exchange period ends, the micro-segmentation environment is deactivated, and cached data requests are processed using the normal encryption strength.

2. The data security management method according to claim 1, characterized in that, The data security management method further includes the following steps: Retrieve the corresponding predefined communication mode template based on the type of the current beat data exchange request; During operation in a micro-isolation environment, the security device continuously monitors the actual communication behavior between participating devices and calculates the uniqueness of the communication behavior matching the predefined communication pattern template. When the uniqueness matching degree is lower than the preset matching degree threshold, data transmission within the micro-isolation environment is interrupted.

3. The data security management method according to claim 1, characterized in that, The data security management method further includes the following steps: Based on the current runtime data of industrial equipment, a list of industrial equipment that may initiate a clock data exchange request is determined, forming a dynamic trusted equipment table; A micro-segmentation environment is created only when an industrial device in the dynamic trusted device table initiates a clock data exchange request.

4. The data security management method according to claim 3, characterized in that, Based on the current runtime data of industrial equipment, a list of industrial equipment that may initiate cycle time data exchange requests is determined, forming a dynamic trusted equipment table, including the following steps: Establish a baseline value for the average operating power of each industrial device; Calculate the average power value of each industrial device within a preset sliding time window; When the average power value of an industrial device exceeds a preset duration within a preset deviation range of its corresponding power reference value, the industrial device that meets the conditions will be added to the dynamic trusted device list.

Citation Information

Patent Citations

  • Data exchange isolation method, system and device for internal and external networks, and storage medium

    CN116743460A

  • Systems and methods for providing an fully functional isolated execution environment for accessing content

    US20110296487A1