Industrial digital twin end-to-end privacy protection methods, systems, and storage media
By using dynamic process knowledge graphs and cross-modal blockchain technology, the data privacy issue in digital twin models has been resolved, enabling dynamic desensitization of process data and product traceability, thereby improving data security and synchronization accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-28
- Publication Date
- 2026-04-03
AI Technical Summary
How can we ensure the privacy of data in digital twin models and improve internet security in industries with high levels of confidentiality, such as pharmaceuticals and the military?
By using dynamic desensitization processing driven by dynamic process knowledge graph and cross-chain fingerprint verification of spatiotemporal graph neural network, combined with cross-modal federated blockchain technology, dynamic desensitization of process data and product traceability are achieved, generating compliance reports.
It effectively hides key process parameters, reduces the risk of data leakage, prevents process reverse engineering, ensures business continuity and data compliance, improves the synchronization accuracy between the digital twin model and the real production line, and realizes the visual traceability of the twin model and data privacy protection.
Smart Images

Figure CN121030811B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of industrial internet security technology, and in particular to a method, system and storage medium for end-to-end privacy protection of industrial digital twins. Background Technology
[0002] Digital twins refer to the use of digital technology to model, simulate, and monitor physical entities, processes, or systems in the real world, thereby achieving a close connection and interaction between the digital and real worlds. Production line twins refer to the process of modeling, simulating, and optimizing actual production lines in a virtual environment using digital twin technology. By digitizing the physical results and process flow of the actual production line and reflecting them in the digital twin model in real time, combined with real-time data monitoring and analysis, accurate simulation and intelligent management of the entire lifecycle of the actual production line can be achieved. Production line twin technology can help enterprises optimize production processes, improve production efficiency, reduce costs, and achieve intelligent production and fault prediction.
[0003] Because digital twin models contain sensitive data such as process flow information, ensuring the privacy of data in digital twin models and improving internet security has become an important development direction in industries with high confidentiality requirements, such as pharmaceuticals and the military. Summary of the Invention
[0004] The technical objective of this application is to provide a method, system, and storage medium for end-to-end privacy protection of industrial digital twins, so as to improve the security of data privacy protection in digital twin models.
[0005] To address the aforementioned technical problems, embodiments of this application provide a method for end-to-end privacy protection of industrial digital twins, comprising:
[0006] Based on the overall equipment effectiveness (OEE) of the production line, the collected process data is subjected to dynamic desensitization processing driven by dynamic process knowledge graph to obtain desensitized process data;
[0007] If a product traceability request is received, a first cross-chain fingerprint is generated based on a spatiotemporal graph neural network, and then associated with and verified with a second cross-chain fingerprint obtained by integrating device data, the process desensitized data, and batch quality data through a cross-modal federated blockchain, to obtain an association verification result.
[0008] If the correlation verification result is successful, a compliance report is generated based on the equipment data, the process de-identification data, and the batch quality data.
[0009] Preferably, in the method described above, the step of performing dynamic desensitization processing on the collected process data based on dynamic process knowledge graph-driven dynamic process knowledge graph to obtain desensitized process data includes:
[0010] A dynamic process knowledge graph is established for the process data, and the process data is stored in a time-series database in the dynamic process knowledge graph.
[0011] Based on the overall equipment efficiency of the production line corresponding to the process data, the process data is dynamically desensitized to obtain the desensitized process data.
[0012] Furthermore, in the method described above, the step of dynamically desensitizing the process data based on the overall equipment efficiency of the production line corresponding to the process data to obtain the desensitized process data includes:
[0013] The desensitization coefficient is determined based on the overall equipment efficiency range of the production line.
[0014] The desensitization adjustment range is determined based on the actual values of the process data and the desensitization coefficient.
[0015] The desensitization value of the process desensitization data corresponding to the process data is obtained by calculating based on the actual value and the target value randomly selected from the desensitization adjustment range.
[0016] Specifically, in the method described above, the step of determining the desensitization coefficient based on the efficiency range of the overall equipment efficiency of the production line includes:
[0017] When the overall equipment efficiency of the production line is less than the first threshold, the desensitization coefficient is determined to be a value within a preset range;
[0018] When the overall equipment efficiency of the production line is less than the second threshold and greater than or equal to the first threshold, the desensitization coefficient is determined to be the value obtained based on the preset interval and the first floating value;
[0019] When the overall equipment efficiency of the production line is greater than the second threshold, the desensitization coefficient is determined to be the value obtained based on the preset range and the second floating value;
[0020] Wherein, the absolute value of the first floating value is greater than the absolute value of the second floating value.
[0021] Preferably, in the method described above, the step of dynamically desensitizing the process data based on the overall equipment efficiency of the production line corresponding to the process data to obtain the desensitized process data further includes:
[0022] Based on the generative adversarial network model and the equipment operating speed, the process desensitization data and the corresponding virtual yield curve and real yield curve are obtained respectively. If the virtual yield curve and the real yield curve do not meet the preset matching degree requirement, the generative adversarial network model is rolled back and an alarm is triggered.
[0023] And / or, based on the product's quality inspection data and standard documents, verify the impact of the process desensitization data on compliance. If the impact exceeds a preset threshold, generate a deviation record report and adjust the desensitization coefficient, the desensitization adjustment range, and / or the target value in the dynamic desensitization.
[0024] Preferably, in the method described above, the step of generating a first cross-chain fingerprint based on a spatiotemporal graph neural network and verifying its association with a second cross-chain fingerprint obtained by integrating device data, the process anonymized data, and batch quality data through a cross-modal federated blockchain to obtain an association verification result includes:
[0025] The first cross-chain fingerprint corresponding to the request information in the product traceability request is generated based on the product traceability request and the spatiotemporal graph neural network, wherein the request information includes at least the target batch number;
[0026] Cross-chain retrieval is performed based on the target batch to obtain the process de-identified data, the equipment data, and the batch quality data corresponding to the target batch.
[0027] A second cross-chain fingerprint is obtained by performing multi-modal feature extraction and feature fusion on the process desensitization data, the equipment data, and the quality data through neural hash bridging.
[0028] The first cross-chain fingerprint and the second cross-chain fingerprint are associated and verified to obtain the association verification result.
[0029] Preferably, the method described above further includes:
[0030] The encrypted control commands sent by the user terminal regarding the target device are subjected to security verification based on a dynamic key to obtain the security verification result;
[0031] If the security verification result is successful, then the encryption control instruction is executed.
[0032] Specifically, in the method described above, when the encryption control command includes first verification information, the step of performing security verification based on a dynamic key on the encryption control command sent by the user terminal regarding the target device to obtain a security verification result includes:
[0033] The system acquires the biometric features pre-uploaded by the user, the quantum key recently requested by the user, the unique security identifier of the target device, and the production line environment characteristics. The unique security identifier is obtained based on the characteristic frequency of the security chip in the target device after being excited by production line vibration and temperature fluctuation. The security chip is preferably a chip based on a Physical Unclonable Function (PUF).
[0034] Based on the production line environment characteristics and the biological characteristics, a composite feature vector is generated;
[0035] The second verification information is obtained by performing an XOR operation on the composite feature vector, the quantum key, and the device's unique security identifier.
[0036] The first security verification is performed on the first verification information based on the second verification information to obtain the first security verification result, which is recorded as the security verification result.
[0037] Preferably, in the method described above, when the encrypted control command further includes third verification information, the third verification information being the overall equipment efficiency of the production line and / or a timestamp, the step of performing security verification based on a dynamic key on the encrypted control command sent by the user terminal regarding the target equipment to obtain a security verification result further includes:
[0038] Obtain the fourth verification information corresponding to the current production line, wherein the fourth verification information is the overall equipment efficiency of the current production line and the current timestamp;
[0039] The third verification information is verified based on the fourth verification information to obtain the second security verification result;
[0040] The security verification result is determined based on the first security verification result and the second security verification result, wherein the security verification result is determined to be verified when both the first security verification result and the second security verification result are verified.
[0041] Another preferred embodiment of this application also provides an industrial digital twin end-to-end privacy protection system, including:
[0042] The process data desensitization module is used to perform dynamic desensitization processing on the collected process data based on dynamic process knowledge graph driven by the overall equipment efficiency of the production line, so as to obtain desensitized process data.
[0043] The cross-chain verification module is used to generate a first cross-chain fingerprint based on a spatiotemporal graph neural network if a product traceability request is received, and to perform association verification with a second cross-chain fingerprint obtained by integrating equipment data, the process desensitized data and batch quality data through a cross-modal federated blockchain to obtain an association verification result.
[0044] The report generation module is used to generate a compliance report based on the equipment data, the process de-identification data, and the batch quality data if the correlation verification result is a successful verification.
[0045] Another preferred embodiment of this application provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the industrial digital twin end-to-end privacy protection method as described above.
[0046] Another preferred embodiment of this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the industrial digital twin end-to-end privacy protection method as described above.
[0047] Another preferred embodiment of this application also provides a computer program product, including computer instructions that, when executed by a processor, implement the steps of the industrial digital twin end-to-end privacy protection method as described above.
[0048] Compared with existing technologies, the industrial digital twin end-to-end privacy protection method, system, and storage medium provided in this application have at least the following beneficial effects:
[0049] This application uses a dynamic process knowledge graph-driven de-identification algorithm and real-time production line overall equipment efficiency to dynamically de-identify process data at the process layer. This effectively hides key process parameters, reduces the risk of data leakage, prevents process reverse engineering, ensures business continuity and data compliance, and can dynamically update relationship edges according to production line cycle time, improving the synchronization accuracy between the digital twin model and the real production line. At the batch layer, a multimodal federated blockchain supports the acquisition and output of de-identified data from multiple links, enabling visualized traceability of the twin model, protecting data privacy, and improving the correlation efficiency of batch data. This achieves a two-way closed loop between actual generation and the digital twin model, adapting to the transparent management and privacy protection needs of smart parks. Attached Figure Description
[0050] Figure 1 This is one of the flowcharts illustrating the end-to-end privacy protection method for industrial digital twins in this application.
[0051] Figure 2This is the second flowchart illustrating the end-to-end privacy protection method for industrial digital twins in this application.
[0052] Figure 3 This is the third flowchart illustrating the end-to-end privacy protection method for industrial digital twins in this application.
[0053] Figure 4 This is the fourth flowchart illustrating the end-to-end privacy protection method for industrial digital twins in this application.
[0054] Figure 5 This is the fifth flowchart illustrating the end-to-end privacy protection method for industrial digital twins in this application.
[0055] Figure 6 This is the sixth flowchart illustrating the end-to-end privacy protection method for industrial digital twins in this application.
[0056] Figure 7 This is the seventh flowchart illustrating the end-to-end privacy protection method for industrial digital twins in this application.
[0057] Figure 8 This is a schematic diagram of the structure of the industrial digital twin end-to-end privacy protection system in this application embodiment. Detailed Implementation
[0058] To make the technical problems, technical solutions, and advantages of this application clearer, a detailed description will be provided below in conjunction with the accompanying drawings and specific embodiments. In the following description, specific details such as particular configurations and components are provided merely to aid in a comprehensive understanding of the embodiments of this application. Therefore, those skilled in the art should understand that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Furthermore, for clarity and brevity, descriptions of known functions and structures have been omitted.
[0059] It should be understood that the phrase "an embodiment" or "one embodiment" throughout the specification means that a specific feature, result, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in one embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, results, or characteristics can be combined in any suitable manner in one or more embodiments.
[0060] In the various embodiments of this application, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0061] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.
[0062] In the embodiments provided in this application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean that B is determined solely based on A, but can also be determined based on A and / or other information.
[0063] To facilitate understanding of the end-to-end privacy protection method for industrial digital twins in this application by those skilled in the art, the following example uses industrial digital twins in the pharmaceutical industry.
[0064] See Figure 1 One embodiment of this application provides a method for end-to-end privacy protection of industrial digital twins, including:
[0065] Step S101: Based on the overall equipment efficiency of the production line, perform dynamic desensitization processing on the collected process data driven by dynamic process knowledge graph to obtain process desensitized data.
[0066] Step S102: If a product traceability request is received, a first cross-chain fingerprint is generated based on a spatiotemporal graph neural network, and then associated with and verified with a second cross-chain fingerprint obtained by integrating device data, the process desensitized data, and batch quality data through a cross-modal federated blockchain, to obtain an association verification result.
[0067] Step S103: If the association verification result is successful, a compliance report is generated based on the equipment data, the process desensitization data, and the batch quality data.
[0068] In this implementation, to ensure the privacy and security of process data during production line generation, the control system dynamically desensitizes the collected process data (including but not limited to process parameters such as temperature, liquid level, pressure, and weight) in real time based on the overall equipment efficiency of the production line. This results in desensitized process data, which is then displayed in the digital twin model. This effectively hides key process parameters. Furthermore, because the desensitization process relies on real-time overall equipment efficiency, the desensitized parameters can change dynamically and are difficult to crack, thus improving the effectiveness of the desensitization process, reducing the risk of data leakage, preventing process reverse engineering, and ensuring business continuity and data compliance (e.g., meeting the requirements of the U.S. Food and Drug Administration (FDA) and Good Manufacturing Practice (GMP)). Simultaneously, the dynamic desensitization process is driven by a dynamic process knowledge graph, allowing for dynamic updates of relationship edges based on parameters such as production line cycle time. This improves the synchronization accuracy between the digital twin model and the real production line, for example, improving it to within one minute.
[0069] Furthermore, upon receiving a user's product traceability request, indicating that the user needs to obtain traceability information such as relevant process data and batch quality data, the control system first generates a first cross-chain fingerprint based on the product traceability request and a pre-obtained spatiotemporal graph neural network. This first cross-chain fingerprint encodes the user's intent to query the association between product and equipment data, process data, and batch quality data. Then, by acquiring and integrating equipment data, anonymized process data, and batch quality data through a cross-modal federated blockchain, a second cross-chain fingerprint is obtained. Further association verification is performed on the first and second cross-chain fingerprints to obtain the association verification result. If the association verification result is successful, a readable compliance report can be generated based on the equipment data, anonymized process data, and batch quality data corresponding to the second cross-chain fingerprint, thereby facilitating the user's access to the corresponding product traceability information. The association verification methods include, but are not limited to, verification based on the cosine similarity between the first and second cross-chain fingerprints. The traceability request includes, but is not limited to, being generated by the user through a visual interface of the digital twin model via selection or input.
[0070] In one specific embodiment, equipment data, process anonymization data, and batch quality data are stored through multimodal sharding. Specifically, the process anonymization data is stored using a Hyperledger Fabric architecture, where each block has a capacity of 1MB and a block generation time of 10 seconds. Equipment data (e.g., equipment load, equipment health status) is stored in a consortium blockchain model, where nodes include equipment manufacturers and generating companies. The consensus mechanism in the consortium blockchain model is Practical Byzantine Fault Tolerance (PBFT), for example, a fault tolerance rate of 1 / 3. Batch quality data uses a zero-knowledge proof blockchain (ZK-Proof). Chain (ZKP) sharded storage, with sharding strategies including physical sharding and logical sharding, allows this zero-knowledge proof blockchain to connect to product monitoring nodes (such as drug regulatory nodes). Through these nodes, the quality compliance of any batch of products can be audited and used as batch quality data. This enables enterprises to achieve "verifiable but invisible" batch quality data without exposing original process parameters. By linking batch quality data with the overall equipment efficiency of the production line, anti-counterfeiting and traceability can be achieved, balancing regulatory compliance and the protection of trade secrets.
[0071] In summary, this application employs a dynamic process knowledge graph-driven de-identification algorithm and real-time production line overall equipment efficiency to dynamically de-identify process data at the process layer. This effectively hides key process parameters, reduces the risk of data leakage, prevents process reverse engineering, ensures business continuity and data compliance, and can dynamically update relationships based on production line cycle time to improve the synchronization accuracy between the digital twin model and the real production line. At the batch layer, a multimodal federated blockchain supports the acquisition and output of de-identified data across multiple links, enabling visualized traceability of the twin model and improving the correlation efficiency of batch data. This achieves a two-way closed loop between actual generation and the digital twin model, adapting to the transparent management and privacy protection requirements of smart parks.
[0072] It should also be noted that if the correlation verification result is that the verification fails, the twin model alarm will be triggered, that is, the abnormal equipment or process node will be marked on the visualization interface, and an anomaly report will be generated based on the abnormal equipment data and / or the desensitized process data to indicate the link where the data does not match, thereby facilitating manual intervention for investigation.
[0073] See Figure 2 Preferably, in the method described above, the step of performing dynamic desensitization processing on the collected process data based on dynamic process knowledge graph-driven dynamic process knowledge graph to obtain desensitized process data includes:
[0074] Step S201: Establish a dynamic process knowledge graph about the process data, in which the process data is stored in a time-series database;
[0075] Step S202: Based on the overall equipment efficiency of the production line corresponding to the process data, dynamically desensitize the process data to obtain the desensitized process data.
[0076] In this embodiment, when acquiring anonymized process data, a dynamic process knowledge graph is first established based on the real-time collected process data. In this dynamic process knowledge graph, the process data is stored in a time-series graph database. Since knowledge graphs are widely used, their specific establishment process will not be elaborated here. It should be noted that the dynamic ontology layer of the dynamic process knowledge graph in this application includes: equipment status (generating / to be cleaned), process associations (such as the relationship between stirring speed and yield, where the yield represents the percentage of actual qualified output to the theoretical maximum output, used to measure the efficiency and economy of the generation process), and batch constraints (parameter differences between batches). Then, based on the overall equipment efficiency of the production line corresponding to the process data, the process data is dynamically anonymized to obtain anonymized process data, which is stored using the Hyperledger Fabric architecture.
[0077] To facilitate understanding of the above-described dynamic desensitization process by those skilled in the art, the specific steps are illustrated below.
[0078] See Figure 3 Furthermore, in the method described above, the step of dynamically desensitizing the process data based on the overall equipment efficiency of the production line corresponding to the process data to obtain the desensitized process data includes:
[0079] Step S301: Determine the desensitization coefficient based on the efficiency range of the overall equipment efficiency of the production line;
[0080] Step S302: Determine the desensitization adjustment range based on the actual value of the process data and the desensitization coefficient;
[0081] Step S303: Calculate the desensitization value of the process desensitization data corresponding to the process data based on the actual value and the target value randomly selected from the desensitization adjustment range.
[0082] In this embodiment, dynamic desensitization is preferably performed using dynamic interval Gaussian blurring. First, a desensitization coefficient is determined based on the overall efficiency range of the production line equipment. In a specific embodiment, the overall efficiency of the production line equipment is divided into three large efficiency ranges using a first threshold and a second threshold. Specifically, when the overall efficiency of the production line equipment is less than the first threshold, the desensitization coefficient is determined to be a value within a preset range; when the overall efficiency of the production line equipment is less than the second threshold but greater than or equal to the first threshold, the desensitization coefficient is determined to be a value obtained based on the preset range and a first floating value; when the overall efficiency of the production line equipment is greater than the second threshold, the desensitization coefficient is determined to be a value obtained based on the preset range and a second floating value; wherein the absolute value of the first floating value is greater than the absolute value of the second floating value.
[0083] Furthermore, based on the actual values of the process data and the desensitization coefficient, a desensitization adjustment range is determined, preferably by determining the maximum adjustment value of the desensitization adjustment range according to a first preset formula, for example: ,in, This is the maximum adjustment value; The desensitization coefficient is mentioned above. For the true value The product of this and a preset coefficient, for example, a preset coefficient of 0.02; the desensitization adjustment range at this time is... .
[0084] Finally, the desensitization value of the process data corresponding to the process data is obtained by calculating based on the actual value and the target value randomly selected from the desensitization adjustment range. In one embodiment, it can be specifically expressed as: .
[0085] By performing the dynamic desensitization process described above, the actual values of process data can be avoided from being sent directly to the digital twin model, thereby improving the privacy and security of process data.
[0086] Preferably, in the method described above, the step of dynamically desensitizing the process data based on the overall equipment efficiency of the production line corresponding to the process data to obtain the desensitized process data further includes:
[0087] Based on the generative adversarial network model and the equipment operating speed, the process desensitization data and the corresponding virtual yield curve and real yield curve are obtained respectively. If the virtual yield curve and the real yield curve do not meet the preset matching degree requirement, the generative adversarial network model is rolled back and an alarm is triggered.
[0088] And / or, based on the product's quality inspection data and standard documents, verify the impact of the process desensitization data on compliance. If the impact exceeds a preset threshold, generate a deviation record report and adjust the desensitization coefficient, the desensitization adjustment range, and / or the target value in the dynamic desensitization.
[0089] In this embodiment, to ensure the normal use of the desensitized process data, further judgment will be made based on the yield curve and the degree of impact of the desensitized process data on compliance.
[0090] When making judgments based on yield curves, the de-identified process data, historical de-identified process data, and equipment operating speed are input into the generative adversarial network (GAN) model to obtain the virtual yield curve corresponding to the de-identified process data. Similarly, the real yield curve corresponding to the process data can be obtained based on the real process data, historical process data, and equipment operating speed. Then, the trend matching degree between the real yield curve and the virtual yield curve is compared. If the matching degree requirement is met (e.g., trend matching degree greater than 97%), the de-identified process data is determined to be usable. If the matching degree requirement is not met, the de-identified process data is determined to be unusable, which will lead to inconsistency between the real yield curve and the virtual yield curve, thus making it impossible to base the accuracy on the digital twin model. In this case, the GAN model is rolled back to the previous stable version and an alarm is triggered to promptly remind technicians to intervene and check the equipment status.
[0091] When assessing the impact of process anonymization data on compliance, the impact is verified based on product quality testing data (e.g., pass rate) and standard documents. If the impact is less than or equal to a preset threshold, the impact on compliance is considered small, and the process anonymization data can be used directly. If the impact is greater than the preset threshold, the impact is considered significant. To avoid or reduce this impact, a deviation record report is generated, and the anonymization coefficient, anonymization adjustment range, and / or target value in dynamic anonymization are adjusted.
[0092] See Figure 4 Preferably, in the method described above, the step of generating a first cross-chain fingerprint based on a spatiotemporal graph neural network and verifying its association with a second cross-chain fingerprint obtained by integrating device data, the process anonymized data, and batch quality data through a cross-modal federated blockchain to obtain an association verification result includes:
[0093] Step S401: Generate the first cross-chain fingerprint corresponding to the request information in the product traceability request based on the product traceability request and the spatiotemporal graph neural network. The request information includes at least the target batch number.
[0094] Step S402: Perform cross-chain retrieval based on the request information to obtain the process de-identification data, the equipment data, and the batch quality data corresponding to the request information;
[0095] Step S403: Perform multi-modal feature extraction and feature fusion on the desensitized process data, the equipment data, and the quality data through neural hash bridging to obtain the second cross-chain fingerprint;
[0096] Step S404: Perform association verification on the first cross-chain fingerprint and the second cross-chain fingerprint to obtain the association verification result.
[0097] In this embodiment, during product traceability, a first cross-chain fingerprint corresponding to the request information is first generated based on a pre-trained spatiotemporal graph neural network. Then, cross-chain retrieval is performed based on the request information, specifically in the device chain storing device data, the process chain storing process anonymization data, and the batch quality chain storing batch quality data. This retrieves the process anonymization data and batch quality data corresponding to the request information. Multi-modal feature extraction and feature fusion are then performed on the process anonymization data, device data, and quality data using a neural hash bridge to obtain the second cross-chain fingerprint. The multi-modal feature extraction includes: extracting time-series features of temperature and pressure (e.g., peak occurrence times) from the process anonymization data; extracting correlation features between device health status and device load from the device data (e.g., the rate of change in device health status when device load increases); and extracting the mapping relationship between yield and production time. Furthermore, the extracted multi-modal features are fused to obtain the second cross-chain fingerprint that represents the actual on-chain record of the target batch in the request information. Finally, the cosine similarity between the first and second cross-chain fingerprints is calculated and compared with a preset similarity value to obtain the association verification result. In one specific embodiment, the preset similarity value is 0.9; and if the obtained cosine similarity is greater than the preset similarity value, the association verification result is determined to be verified as passed; otherwise, the verification fails.
[0098] In one specific embodiment, the first cross-chain fingerprint and the second cross-chain fingerprint are 256-dimensional search fingerprints.
[0099] In one specific embodiment, the request information may include, in addition to the target batch number, the tank number, tank grade, etc.
[0100] See Figure 5 Preferably, the method described above further includes:
[0101] Step S501: Perform security verification based on dynamic key on the encrypted control command about the target device sent by the user terminal to obtain the security verification result;
[0102] Step S502: If the security verification result is successful, then execute the encryption control command.
[0103] In another embodiment of this application, to further ensure the privacy and security of process data, when the user sends control commands for the target device, it encrypts them to obtain encrypted control commands. After receiving the encrypted control commands, the control system performs security verification based on a dynamic key, and executes the encrypted control commands to control the target device only after the verification is successful. This enables real-time verification of the encrypted control commands, thereby effectively reducing the risk of command hijacking, solving the problem of static keys being easily cracked, and ensuring the hardware identity security and command authenticity of the production line.
[0104] See Figure 6 Specifically, in the method described above, when the encryption control command includes first verification information, the step of performing security verification based on a dynamic key on the encryption control command sent by the user terminal regarding the target device to obtain a security verification result includes:
[0105] Step S601: Obtain the biometric features pre-uploaded by the user terminal, the quantum key recently requested by the user terminal, the device security unique identifier of the target device, and the production line environment characteristics. The device security unique identifier is obtained based on the characteristic frequency of the security chip in the target device after being excited by production line vibration and temperature fluctuation. The security chip is preferably a chip based on a physically unclonable function.
[0106] Step S602: Generate a composite feature vector based on the production line environment characteristics and the biological characteristics;
[0107] Step S603: Perform an XOR operation on the composite feature vector, the quantum key, and the device security unique identifier to obtain the second verification information;
[0108] Step S604: Perform a first security verification on the first verification information based on the second verification information to obtain a first security verification result, and record it as the security verification result.
[0109] In this embodiment, the encryption control command includes first verification information, namely the encryption key, for verification. The security verification steps can be specifically described as follows: First, the control system, based on the user terminal corresponding to the encryption control command, obtains the biometrics uploaded by the user terminal in advance, the quantum key recently requested by the user terminal, the unique security identifier of the target device, and the production line environment characteristics. The biometrics include, but are not limited to, the RR interval of the electrocardiogram and the peak value of hand electromyography. The quantum key is the quantum key requested by the user terminal when sending the encryption control command. The unique security identifier of the target device is obtained based on the characteristic frequency of the security chip (e.g., carbon nanotube PUF chip) in the target device after being excited by production line vibration (e.g., 5-50Hz) and temperature fluctuation (±5℃). The extracted characteristic frequency is preferably a 384-dimensional feature. The unique security identifier of the device obtained based on the characteristic frequency is preferably generated by SHA-3 hash. The production line environment characteristics include, but are not limited to, the device vibration frequency and the ambient temperature and humidity.
[0110] Furthermore, based on the aforementioned production line environment characteristics and biometric features, feature fusion is performed to generate a 192-dimensional composite feature vector. This composite feature vector, along with the quantum key and the device's unique security identifier, is then XORed to obtain second verification information. This second verification information can then be used to verify the first verification information, thus achieving secure verification of encrypted control commands. By fusing the PUF and quantum key to obtain the verification information, the risk of device command hijacking can be effectively reduced, thereby ensuring hardware identity security and command authenticity.
[0111] See Figure 7 Preferably, in the method described above, when the encrypted control command further includes third verification information, the third verification information being the overall equipment efficiency of the production line and / or a timestamp, the step of performing security verification based on a dynamic key on the encrypted control command sent by the user terminal regarding the target equipment to obtain a security verification result further includes:
[0112] Step S701: Obtain the fourth verification information corresponding to the current production line, wherein the fourth verification information is the overall equipment efficiency of the current production line and the current timestamp;
[0113] Step S702: Verify the third verification information based on the fourth verification information to obtain the second security verification result;
[0114] Step S703: Determine the security verification result based on the first security verification result and the second security verification result, wherein the security verification result is determined to be verified when both the first security verification result and the second security verification result are verified.
[0115] In this embodiment, the encrypted control command may further include third verification information, which can be the overall equipment efficiency of the production line and / or a timestamp. Therefore, during security verification, in addition to verification based on the first and second verification information, a fourth verification information of the current production line will be obtained, namely the current overall equipment efficiency of the production line and the current timestamp. Verification will then be performed based on the fourth and third verification information to obtain a second security verification result. If the third verification information only includes the overall equipment efficiency of the production line, the matching degree of the overall equipment efficiency in the two verification information will be judged. When the matching degree is greater than a preset matching degree (e.g., 99.95%), the second security verification result is determined to be successful. The overall equipment efficiency data of the production line (e.g., equipment operating speed, production cycle time) is an environmental characteristic of the command verification; it is neither part of the key nor encrypted data, but rather a verification factor used to ensure the authenticity of the command. By introducing real-time overall equipment efficiency data of the production line, it is ensured that the command is issued based on the current equipment operating status, further blocking man-in-the-middle attacks and illegal command injection. When the third verification information only includes a timestamp, the absolute difference between the timestamps of the two verification information is compared. If this absolute difference is less than a preset time (the update cycle for generating the first verification information, for example, 5 seconds), the second security verification result is determined to be successful. This is mainly used to prevent replay attacks: after the control system receives an instruction, if the key update cycle is greater than the preset time, it can be determined as a replay attack and execution will be refused. Even if an attacker intercepts a historical key, it cannot be reused because the timestamp has expired. Its function is to independently verify the timeliness of the instruction sent, preventing attackers from reusing historical instructions. When the third verification information includes a timestamp and the overall equipment efficiency of the production line, both are judged separately. If both satisfy the corresponding judgment conditions, the second security verification result is determined to be successful. Therefore, when both the first and second security verification results are successful, the security verification result is determined to be successful.
[0116] See Figure 8 Another preferred embodiment of this application also provides an industrial digital twin end-to-end privacy protection system, including:
[0117] The process data desensitization module 801 is used to perform dynamic desensitization processing on the collected process data based on dynamic process knowledge graph driven by the overall equipment efficiency of the production line, so as to obtain process desensitized data.
[0118] The cross-chain verification module 802 is used to generate a first cross-chain fingerprint based on a spatiotemporal graph neural network if a product traceability request is received, and to perform association verification with a second cross-chain fingerprint obtained by integrating equipment data, the process desensitized data and batch quality data through a cross-modal federated blockchain to obtain an association verification result.
[0119] The report generation module 803 is used to generate a compliance report based on the equipment data, the process desensitization data, and the batch quality data if the correlation verification result is a successful verification.
[0120] Preferably, in the system described above, the process data desensitization module includes:
[0121] The first processing submodule is used to establish a dynamic process knowledge graph about the process data, in which the process data is stored through a time series database.
[0122] The second processing submodule is used to dynamically desensitize the process data based on the overall equipment efficiency of the production line corresponding to the process data, so as to obtain the desensitized process data.
[0123] Furthermore, in the system described above, the second processing submodule includes:
[0124] The first processing unit is used to determine the desensitization coefficient based on the efficiency range of the overall equipment efficiency of the production line.
[0125] The second processing unit is used to determine the desensitization adjustment range based on the actual value of the process data and the desensitization coefficient;
[0126] The third processing unit is used to calculate, based on the true value and the target value randomly selected from the desensitization adjustment range, the desensitization value of the process desensitization data corresponding to the process data.
[0127] Specifically, in the system described above, the first processing unit includes:
[0128] When the overall equipment efficiency of the production line is less than the first threshold, the desensitization coefficient is determined to be a value within a preset range;
[0129] When the overall equipment efficiency of the production line is less than the second threshold and greater than or equal to the first threshold, the desensitization coefficient is determined to be the value obtained based on the preset interval and the first floating value;
[0130] When the overall equipment efficiency of the production line is greater than the second threshold, the desensitization coefficient is determined to be the value obtained based on the preset range and the second floating value;
[0131] Wherein, the absolute value of the first floating value is greater than the absolute value of the second floating value.
[0132] Preferably, in the system described above, the second processing submodule further includes:
[0133] The fourth processing unit is used to obtain the process desensitization data and the virtual yield curve and real yield curve corresponding to the process data according to the generative adversarial network model and the equipment operating speed, respectively. If the virtual yield curve and the real yield curve do not meet the preset matching degree requirement, the generative adversarial network model is rolled back and an alarm is triggered.
[0134] And / or, the fifth processing unit is used to verify the impact of the process desensitization data on compliance based on the product's quality inspection data and standard documents. If the impact is greater than a preset threshold, a deviation record report is generated, and the desensitization coefficient, the desensitization adjustment range, and / or the target value in the dynamic desensitization are adjusted.
[0135] Preferably, in the system described above, the cross-chain verification module includes:
[0136] The third processing submodule is used to generate the first cross-chain fingerprint corresponding to the request information in the product traceability request based on the product traceability request and the spatiotemporal graph neural network. The request information includes at least the target batch number.
[0137] The fourth processing submodule is used to perform cross-chain retrieval based on the target batch to obtain the process de-identified data, the equipment data, and the batch quality data corresponding to the target batch.
[0138] The fifth processing submodule is used to perform multi-modal feature extraction and feature fusion on the process desensitization data, the equipment data and the quality data through neural hash bridging to obtain the second cross-chain fingerprint;
[0139] The sixth processing submodule is used to perform association verification on the first cross-chain fingerprint and the second cross-chain fingerprint to obtain the association verification result.
[0140] Preferably, the system described above further includes:
[0141] The command verification module is used to perform security verification based on dynamic keys on the encrypted control commands sent by the user terminal regarding the target device, and obtain the security verification result;
[0142] The instruction execution module is used to execute the encryption control instruction if the security verification result is successful.
[0143] Specifically, in the system described above, when the encryption control instruction includes first verification information, the instruction verification module includes:
[0144] The first acquisition submodule is used to acquire the biometric features pre-uploaded by the user terminal, the quantum key recently requested by the user terminal, the device security unique identifier of the target device, and the production line environment characteristics. The device security unique identifier is obtained based on the characteristic frequency of the security chip in the target device after being excited by production line vibration and temperature fluctuation. The security chip is preferably a chip based on a physically unclonable function.
[0145] The feature fusion submodule is used to generate a composite feature vector based on the production line environment features and the biological features;
[0146] The key fusion submodule is used to perform an XOR operation on the composite feature vector, the quantum key, and the device security unique identifier to obtain the second verification information.
[0147] The first security verification submodule is used to perform a first security verification on the first verification information based on the second verification information, obtain a first security verification result, and record it as the security verification result.
[0148] Preferably, in the system described above, where the encryption control command further includes third verification information, the third verification information being the overall equipment efficiency of the production line and / or a timestamp, the command verification module further includes:
[0149] The second acquisition submodule is used to acquire the fourth verification information corresponding to the current production line, wherein the fourth verification information is the overall equipment efficiency of the current production line and the current timestamp.
[0150] The second security verification submodule is used to verify the third verification information based on the fourth verification information to obtain a second security verification result;
[0151] The second security verification submodule is used to determine the security verification result based on the first security verification result and the second security verification result, wherein the security verification result is determined to be verified when both the first security verification result and the second security verification result are verified.
[0152] The industrial digital twin end-to-end privacy protection system embodiment of this application is a system corresponding to the above-described industrial digital twin end-to-end privacy protection method embodiment. All implementation means in the above method embodiments are applicable to the system embodiment and can achieve the same technical effect. The system provided by this application embodiment can implement all the method steps implemented in the above method embodiments and can achieve the same technical effect. Therefore, the parts that are the same as those in the method embodiments and their beneficial effects will not be described in detail here.
[0153] Another preferred embodiment of this application provides an electronic device, including a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the steps of the industrial digital twin end-to-end privacy protection method as described above and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0154] Another preferred embodiment of this application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the steps of the industrial digital twin end-to-end privacy protection method described above and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0155] Another preferred embodiment of this application provides a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the industrial digital twin end-to-end privacy protection method as described above, and achieve the same technical effect. To avoid repetition, it will not be described again here.
[0156] Furthermore, reference numerals and / or letters may be repeated in different examples within this application. Such repetition is for the purpose of simplification and clarity and does not in itself indicate a relationship between the various embodiments and / or settings discussed.
[0157] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion.
[0158] The above description is the preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principles described in this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method for end-to-end privacy protection in industrial digital twins, characterized in that, include: Based on the overall equipment efficiency of the production line, the collected process data is subjected to dynamic desensitization processing driven by dynamic process knowledge graph to obtain process desensitized data; If a product traceability request is received, a first cross-chain fingerprint is generated based on a spatiotemporal graph neural network, and then associated with and verified with a second cross-chain fingerprint obtained by integrating device data, the process desensitized data, and batch quality data through a cross-modal federated blockchain, to obtain an association verification result. If the correlation verification result is successful, a compliance report is generated based on the equipment data, the process de-identification data, and the batch quality data. The steps of performing dynamic desensitization processing on the collected process data based on the overall equipment efficiency of the production line, driven by a dynamic process knowledge graph, to obtain desensitized process data include: A dynamic process knowledge graph is established for the process data, and the process data is stored in a time-series database in the dynamic process knowledge graph. Based on the overall equipment efficiency of the production line corresponding to the process data, the process data is dynamically desensitized to obtain the desensitized process data. The step of dynamically desensitizing the process data based on the overall equipment efficiency of the production line corresponding to the process data to obtain the desensitized process data includes: The desensitization coefficient is determined based on the overall equipment efficiency range of the production line. The desensitization adjustment range is determined based on the actual values of the process data and the desensitization coefficient. The desensitization value of the process desensitization data corresponding to the process data is obtained by calculating based on the actual value and the target value randomly selected from the desensitization adjustment range. The step of determining the desensitization coefficient based on the efficiency range of the overall equipment efficiency of the production line includes: When the overall equipment efficiency of the production line is less than the first threshold, the desensitization coefficient is determined to be a value within a preset range. When the overall equipment efficiency of the production line is less than the second threshold and greater than or equal to the first threshold, the desensitization coefficient is determined to be the value obtained based on the preset interval and the first floating value; When the overall equipment efficiency of the production line is greater than the second threshold, the desensitization coefficient is determined to be the value obtained based on the preset range and the second floating value; Wherein, the absolute value of the first floating value is greater than the absolute value of the second floating value.
2. The method according to claim 1, characterized in that, The step of dynamically desensitizing the process data based on the overall equipment efficiency of the production line corresponding to the process data to obtain the desensitized process data further includes: Based on the generative adversarial network model and the equipment operating speed, the process desensitization data and the corresponding virtual yield curve and real yield curve are obtained respectively. If the virtual yield curve and the real yield curve do not meet the preset matching degree requirement, the generative adversarial network model is rolled back and an alarm is triggered. And / or, based on the product's quality inspection data and standard documents, verify the impact of the process desensitization data on compliance. If the impact exceeds a preset threshold, generate a deviation record report and adjust the desensitization coefficient, the desensitization adjustment range, and / or the target value in the dynamic desensitization.
3. The method according to claim 1, characterized in that, The step of generating a first cross-chain fingerprint based on a spatiotemporal graph neural network and verifying its association with a second cross-chain fingerprint obtained by integrating device data, the de-identified process data, and batch quality data through a cross-modal federated blockchain to obtain the association verification result includes: The first cross-chain fingerprint corresponding to the request information in the product traceability request is generated based on the product traceability request and the spatiotemporal graph neural network, wherein the request information includes at least the target batch number; Cross-chain retrieval is performed based on the target batch to obtain the process de-identified data, the equipment data, and the batch quality data corresponding to the target batch; The process desensitization data, equipment data, and quality data are subjected to multi-modal feature extraction and feature fusion through neural hash bridging to obtain the second cross-chain fingerprint. The first cross-chain fingerprint and the second cross-chain fingerprint are associated and verified to obtain the association verification result.
4. The method according to claim 1, characterized in that, Also includes: The encrypted control commands sent by the user terminal regarding the target device are subjected to security verification based on a dynamic key to obtain the security verification result; If the security verification result is successful, then the encryption control instruction is executed.
5. The method according to claim 4, characterized in that, When the encryption control command includes first verification information, the step of performing security verification based on a dynamic key on the encryption control command sent by the user terminal regarding the target device to obtain a security verification result includes: The system acquires the biometric features pre-uploaded by the user, the quantum key recently requested by the user, the unique security identifier of the target device, and the production line environment characteristics. The unique security identifier is obtained based on the characteristic frequency of the security chip in the target device after being excited by production line vibration and temperature fluctuations. The security chip is a chip based on the physical no-cloning function. Based on the production line environment characteristics and the biological characteristics, a composite feature vector is generated; The second verification information is obtained by performing an XOR operation on the composite feature vector, the quantum key, and the device's unique security identifier. The first security verification is performed on the first verification information based on the second verification information to obtain the first security verification result, which is recorded as the security verification result.
6. The method according to claim 5, characterized in that, When the encrypted control command further includes third verification information, which is the overall equipment efficiency of the production line and / or a timestamp, the step of performing security verification based on a dynamic key on the encrypted control command sent by the user terminal regarding the target equipment to obtain a security verification result further includes: Obtain the fourth verification information corresponding to the current production line, wherein the fourth verification information is the overall equipment efficiency of the current production line and the current timestamp; The third verification information is verified based on the fourth verification information to obtain the second security verification result; The security verification result is determined based on the first security verification result and the second security verification result, wherein the security verification result is determined to be verified when both the first security verification result and the second security verification result are verified.
7. An industrial digital twin end-to-end privacy protection system, characterized in that, include: The process data desensitization module is used to perform dynamic desensitization processing on the collected process data based on dynamic process knowledge graph driven by the overall equipment efficiency of the production line, so as to obtain desensitized process data. The cross-chain verification module is used to generate a first cross-chain fingerprint based on a spatiotemporal graph neural network if a product traceability request is received, and to perform association verification with a second cross-chain fingerprint obtained by integrating equipment data, the process desensitized data and batch quality data through a cross-modal federated blockchain to obtain an association verification result. The report generation module is used to generate a compliance report based on the equipment data, the process de-identification data, and the batch quality data if the correlation verification result is a successful verification. The process data desensitization module includes: The first processing submodule is used to establish a dynamic process knowledge graph about the process data, in which the process data is stored through a time series database. The second processing submodule is used to dynamically desensitize the process data according to the overall equipment efficiency of the production line corresponding to the process data, so as to obtain the desensitized process data. The second processing submodule includes: The first processing unit is used to determine the desensitization coefficient based on the efficiency range of the overall equipment efficiency of the production line. The second processing unit is used to determine the desensitization adjustment range based on the actual value of the process data and the desensitization coefficient; The third processing unit is used to calculate, based on the true value and the target value randomly selected from the desensitization adjustment range, the desensitization value of the process desensitization data corresponding to the process data; The first processing unit includes: When the overall equipment efficiency of the production line is less than the first threshold, the desensitization coefficient is determined to be a value within a preset range. When the overall equipment efficiency of the production line is less than the second threshold and greater than or equal to the first threshold, the desensitization coefficient is determined to be the value obtained based on the preset interval and the first floating value; When the overall equipment efficiency of the production line is greater than the second threshold, the desensitization coefficient is determined to be the value obtained based on the preset range and the second floating value; Wherein, the absolute value of the first floating value is greater than the absolute value of the second floating value.
8. An electronic device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the industrial digital twin end-to-end privacy protection method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when executed by a processor, the computer program implements the steps of the industrial digital twin end-to-end privacy protection method as described in any one of claims 1 to 6.
10. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps of the industrial digital twin end-to-end privacy protection method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Digital artwork block chain authentication and traceability method and system
CN120658367A
Cross-platform education data privacy protection analysis system
CN120781380A