Data encryption method of asset digital twin management platform based on knowledge graph
By employing knowledge graph-based dynamic attribute-based encryption and hierarchical encryption methods, the adaptability and security issues of data encryption in digital twin platforms are addressed, achieving fine-grained, adaptive, and searchable data protection, thereby improving data encryption efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA NAT INST OF STANDARDIZATION
- Filing Date
- 2025-11-03
- Publication Date
- 2026-05-15
AI Technical Summary
Existing digital twin platform data encryption technologies cannot adapt to the dynamic evolution characteristics and complex relationships of data, lack consideration of data quality factors, and are difficult to support efficient time-series range queries while ensuring security.
A data management graph is constructed based on a knowledge graph. Through dynamic attribute-based encryption, hierarchical encryption, and dynamic searchable symmetric encryption, combined with a data quality assessment mechanism, fine-grained, adaptive, and searchable data security protection is achieved.
It improves the efficiency and security of data encryption on the digital twin platform, enables online matching of data value and real-time requirements, reduces decryption overhead in high-performance computing scenarios, and meets the differentiated needs of industrial sites.
Smart Images

Figure CN121351114B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of platform data encryption technology, and in particular to a data encryption method for an asset digital twin management platform based on knowledge graphs. Background Technology
[0002] With the deepening of Industry 4.0 and digital transformation, asset digital twin management platforms are increasingly widely used in fields such as intelligent manufacturing and smart cities. These platforms achieve real-time monitoring and analysis of equipment status, operating data, and environmental information by constructing a virtual mapping of physical assets, providing key support for predictive maintenance and optimization decisions. Therefore, the security of platform operation and management is directly related to the operational security of enterprises and the protection of trade secrets. Developing new encryption technologies to ensure platform data security is imperative.
[0003] Current data encryption technologies for digital twin platforms suffer from the following limitations: First, traditional encryption methods often employ static, uniform encryption strategies, which cannot adapt to the dynamic evolution and complex relationships of data in a digital twin environment. Second, existing technologies lack consideration for data quality factors and fail to implement differentiated protection strategies based on the intrinsic value of the data. Furthermore, encryption schemes for time-series data often neglect the need for data searchability, making it difficult to support efficient time-series range queries while ensuring security. Therefore, this invention proposes a knowledge graph-based data encryption method for asset digital twin management platforms. This method constructs a data management knowledge graph and utilizes its graph structure features to achieve dynamic attribute-based encryption, combines a data quality assessment mechanism to implement hierarchical encryption, and employs dynamic searchable symmetric encryption technology that supports time-series queries. This method integrates data association characteristics, quality attributes, and time-series characteristics into the encryption process, achieving fine-grained, adaptive, and searchable data security protection. It significantly enhances the security protection capabilities of digital twin platforms in the face of complex attack scenarios and data usage needs, and is of great significance for promoting industrial digital transformation. Summary of the Invention
[0004] The purpose of this invention is to provide a data encryption method for an asset digital twin management platform based on knowledge graphs.
[0005] To achieve the above objectives, the present invention is implemented according to the following technical solution:
[0006] This invention includes the following steps:
[0007] The process involves acquiring digital data of physical assets, determining the storage location of this digital data, and constructing a data management knowledge graph. The digital data includes asset information, data attributes, and operational information. The storage location of the digital data includes graph nodes and a platform database.
[0008] The first encrypted data is obtained by dynamically encrypting the graph nodes based on the graph structure and edge relationship weights of the data management knowledge graph.
[0009] The data quality level of the operational information in the platform database is determined based on operation access information and statistical data. The operational information in the platform database is then hierarchically encrypted according to the data quality level and data attributes to obtain second encrypted data. The operational information in the platform database includes time-series operational status and time-series monitoring data.
[0010] The second encrypted data is dynamically searchable symmetrically encrypted according to the time sequence information to obtain the third encrypted data.
[0011] Furthermore, the method for constructing a data management knowledge graph includes:
[0012] Acquire digital data of physical assets; the digital data includes asset information, data attributes, and operational information; the asset information includes equipment location, equipment model, operating system, and hardware configuration; the data attributes include data sensitivity level and data format; the operational information includes sensor type, time-series operational status, and time-series monitoring data; the time-series operational status and time-series monitoring data are a set of correlated data;
[0013] Determine the storage path of the timing operation status and timing monitoring data in the platform database;
[0014] The graph node system is defined, specifically including subject nodes, attribute nodes, and data nodes; the subject nodes are used to store asset information metadata of the physical asset subject; the attribute nodes are used to store data attribute metadata of the physical asset subject; the data nodes are used to store sensor type and number metadata, and the data node corresponding to each sensor simultaneously stores the storage path of the corresponding time-series operating status and time-series monitoring data;
[0015] The edge relationship network is determined, including internal relationship edges of physical asset entities, horizontal relationship edges of entity nodes, horizontal relationship edges of attribute nodes, and horizontal relationship edges of data nodes. The specific determination method is as follows: internal relationship edges of physical asset entities are established between entity nodes, attribute nodes, and data nodes of the same physical asset entity; horizontal relationship edges of entity nodes are established for entity nodes with the same parameters such as device location, device model, and operating system; horizontal relationship edges of attribute nodes are established for attribute nodes with the same parameters such as data sensitivity level and data format; and horizontal relationship edges of data nodes are established for data nodes with the same sensor type.
[0016] Furthermore, the method for obtaining the first encrypted data by performing dynamic attribute-based encryption includes:
[0017] The dynamic attribute set of the physical asset entity is determined based on the graph nodes and edge relationships of the data management knowledge graph, expressed as follows:
[0018]
[0019] in for physical asset entity at any time The dynamic attribute set, The operational status of the physical asset entity. For physical asset entities The set of edge relationships with other physical asset entities. For global context, The inference function is extracted from the knowledge graph using predefined rules;
[0020] The edge relationship weights of each graph node are calculated based on the edge relationships in the data management knowledge graph. The average edge relationship weight of each node is then calculated based on these weights. Finally, the dynamic attribute set of the physical asset entity is updated based on the average edge relationship weight of each node. The expression is as follows:
[0021]
[0022]
[0023]
[0024] in Update the dynamic attribute set of the main node. Update the dynamic attribute set of the attribute node. For data nodes Dynamic attribute set update, , , For adjustment function, For physical asset entities Average edge relation weight of the main node The average edge relation weight of the attribute node. For data nodes Average edge relation weights;
[0025] Based on the dynamic attribute set update of the physical asset entity, the dynamic access strategies for three types of nodes are determined, and the CP-ABE algorithm is used to encrypt the three types of nodes respectively to obtain the first encrypted data, the expression of which is:
[0026]
[0027]
[0028] in for physical asset entity at any time Dynamic access policies, including dynamic access policies for principal nodes. Dynamic access strategy for attribute nodes Data nodes Dynamic access strategy , This is a preset static strategy. Update the dynamic attribute set of the physical asset entity, including , , , The average edge relation weight of the node includes , , , The first encrypted data for the physical asset entity, including the first encrypted data of the principal node. First encrypted data of attribute nodes Data nodes First encrypted data , For public key, Metadata stored for the physical asset entity, including principal node metadata. Attribute node metadata and data nodes Metadata , This refers to the CP-ABE algorithm.
[0029] Furthermore, the method for calculating the average edge relation weight of nodes includes:
[0030] The edge relationship weights of each graph node are calculated based on the edge relationships in the data management knowledge graph. The specific method is as follows:
[0031] The strength of internal associations is quantified based on the relationship density index, and the weight of the internal relationship edges within the same physical asset entity is calculated; the relationship density index includes the frequency of interaction between nodes, data flow intensity, and information entropy;
[0032] The similarity of the physical assets' locations, equipment, and systems is calculated based on the similarity metric, and the average value is taken as the weight of the horizontal relationship edge between the two main nodes.
[0033] Based on the consistency assessment method, the data sensitivity level consistency, data classification correlation and data compliance of different physical asset entities are calculated, and the average value is taken as the weight of the horizontal relationship edge between the two attribute nodes.
[0034] Homogeneity analysis is used to calculate the similarity of sensing technologies and data patterns of data nodes of different physical asset entities, and the mean value is taken as the weight of the horizontal relationship edge between two data nodes.
[0035] The average edge relationship weight of a node is calculated based on the edge relationship weight; the average edge relationship weight of a node includes the average edge relationship weight of the main node, the average edge relationship weight of the attribute node, and the average edge relationship weight of the data node.
[0036] The average edge relationship weight of the main node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the average weight of all horizontal relationship edges of the corresponding physical asset entity's main nodes;
[0037] The average edge relationship weight of the attribute node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the average weight of all horizontal relationship edges of the corresponding physical asset entity's attribute nodes.
[0038] The average edge relationship weight of the data node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the weight of the horizontal relationship edges of all data nodes of the same sensor of the corresponding physical asset entity.
[0039] Furthermore, the method for determining the data quality level of the operational information within the platform database includes:
[0040] The operation access information of the physical asset entity's sensors is obtained through the asset digital twin management platform. The operation access information is normalized and weighted according to the historical benchmark value of each operation access information to obtain the operation access information quality score. The operation access information is positively correlated with the data quality level, including access frequency, operation frequency and number of accessing departments.
[0041] The asset digital twin management platform compiles statistical data on the current operational information input from each sensor of the physical asset. , on statistical data After normalization, a weighted average is used to obtain the statistical data quality score; the statistical data is negatively correlated with the data quality level, including data missing rate, data anomaly rate and data volatility;
[0042] The data quality score is obtained by weighting the operation access information quality score and the statistical data quality score, and the data quality level is determined by a preset mapping relationship.
[0043] Furthermore, the method for obtaining encrypted physical asset data through hierarchical encryption includes:
[0044] The platform database's operational information is encrypted in a tiered manner according to the data sensitivity level of the data attributes to obtain the second encrypted data; the data sensitivity level includes... Public level Internal level Sensitivity level and Core level;
[0045] The specific steps are as follows:
[0046] Based on data quality level The public-level runtime information is obfuscated and an integrity tag is generated to obtain the second encrypted data, expressed as:
[0047]
[0048]
[0049]
[0050] in for Public-level operational information Obfuscated data, The SHA-256 hash function is used. To obfuscate the key, It is a random number. To adjust the factor, For data quality levels, For data integrity labels, For message authentication code functions, For integrity key, for The second encrypted data;
[0051] Based on data quality level Internal operational information is symmetrically encrypted and an authentication tag is added to obtain second encrypted data, expressed as:
[0052]
[0053]
[0054]
[0055] in Encryption key for content, This is the system master key. Assign a physical asset number. The output is ciphertext for symmetric encryption. for Certification label for Symmetric encryption function, for Internal-level operational information For associated data, including physical asset number, data sensitivity level, and timestamp, for The second encrypted data;
[0056] Based on data quality level Sensitive operational information is subjected to symmetric encryption and attribute-based encryption to obtain the second encrypted data, expressed as:
[0057]
[0058]
[0059]
[0060]
[0061] in For data encryption keys, Number the sensor. for Sensitive Operational Information Symmetric encryption output, for Symmetric encryption function, for Attribute-based encryption results For attribute-based encryption functions, for System public key, for Strategy, Based on access control policies, For quality threshold, As an additional strategy, for The second encrypted data;
[0062] Determine the initialization key based on the data quality level. and number of encryption layers ,right Core-level operational information undergoes multi-layered symmetric encryption and attribute-based encryption, and a time lock is added to obtain the second encrypted data. The expression is:
[0063]
[0064]
[0065]
[0066]
[0067]
[0068] in For the first The symmetric encryption key for the encryption layer. For the encryption layer index, for Core-level operational information In the Symmetric encryption output of the encryption layer, for Attribute-based encryption results The puzzle of time lock for The second encrypted data, For strict access policies, The number of hash iterations. The target value for time lock, This is the time-locked salt value.
[0069] Furthermore, the method for obtaining triple-encrypted data through dynamic searchable symmetric encryption includes:
[0070] Extract the time series of runtime information, process it according to a preset mapping rule to obtain a mapped time series, generate a time index and a time salt value based on the mapped time series, calculate the time index key for the current time interval based on the time index, time salt value, and the time index key of the previous time interval, and encrypt the time index entry based on the time index key of the current time interval. The expression is:
[0071]
[0072]
[0073] in for Time index key for time interval, The SHA-256 cryptographic hash function. for Time index of time interval, for The relevant time salt value, It is a random number. For encrypted data time index entries, It uses the AES-GCM symmetric encryption algorithm. For time index entries, include the time index and data pointer;
[0074] Calculate the data encryption key for the current time interval based on the time index entry, sensor code, and system master key. Then, encrypt the second encrypted data using the current time interval's data encryption key to obtain the third encrypted data. The expression is:
[0075]
[0076]
[0077] in for Data encryption key for time intervals, This is the system master key. Encode the sensor, for Second encrypted data time interval The data after symmetric encryption, i.e., the third encrypted data, Indexes based on data sensitivity levels;
[0078] The encrypted data time index entries are stored according to the original storage path of the runtime information. Third encrypted data and corresponding time salinity .
[0079] The beneficial effects of this invention are:
[0080] This invention relates to a data encryption method for a knowledge graph-based asset digital twin management platform. Compared with existing technologies, this invention has the following technical advantages:
[0081] This invention enhances data preprocessing capabilities and model adaptability in asset digital twin management platform data encryption by constructing a knowledge graph, dynamic attribute-based encryption, data quality rating, hierarchical encryption, and dynamic searchable symmetric encryption steps. This improves the efficiency of data encryption in asset digital twin management platforms, and refines the encryption granularity from the "library level" to the "node-edge-time point level." It achieves online matching of security strength with data value and real-time requirements, significantly reduces decryption overhead in high-performance computing scenarios, and meets differentiated needs such as millisecond-level response and delayed release of core data in industrial settings. This provides a feasible native security framework for digital twin platforms. Attached Figure Description
[0082] Figure 1 This is a flowchart illustrating the steps of the data encryption method for the knowledge graph-based asset digital twin management platform of the present invention. Detailed Implementation
[0083] The present invention will be further described below through specific embodiments. The illustrative embodiments and descriptions herein are used to explain the present invention, but are not intended to limit the present invention.
[0084] The data encryption method for the knowledge graph-based asset digital twin management platform of this invention includes the following steps:
[0085] like Figure 1 As shown, this embodiment includes the following steps:
[0086] The process involves acquiring digital data of physical assets, determining the storage location of this digital data, and constructing a data management knowledge graph. The digital data includes asset information, data attributes, and operational information. The storage location of the digital data includes graph nodes and a platform database.
[0087] The first encrypted data is obtained by dynamically encrypting the graph nodes based on the graph structure and edge relationship weights of the data management knowledge graph.
[0088] The data quality level of the operational information in the platform database is determined based on operation access information and statistical data. The operational information in the platform database is then hierarchically encrypted according to the data quality level and data attributes to obtain second encrypted data. The operational information in the platform database includes time-series operational status and time-series monitoring data.
[0089] The second encrypted data is dynamically searchable symmetrically encrypted according to the time sequence information to obtain the third encrypted data.
[0090] In this embodiment, the method for constructing a data management knowledge graph includes:
[0091] Acquire digital data of physical assets; the digital data includes asset information, data attributes, and operational information; the asset information includes equipment location, equipment model, operating system, and hardware configuration; the data attributes include data sensitivity level and data format; the operational information includes sensor type, time-series operational status, and time-series monitoring data; the time-series operational status and time-series monitoring data are a set of correlated data;
[0092] Determine the storage path of the timing operation status and timing monitoring data in the platform database;
[0093] The graph node system is defined, specifically including subject nodes, attribute nodes, and data nodes; the subject nodes are used to store asset information metadata of the physical asset subject; the attribute nodes are used to store data attribute metadata of the physical asset subject; the data nodes are used to store sensor type and number metadata, and the data node corresponding to each sensor simultaneously stores the storage path of the corresponding time-series operating status and time-series monitoring data;
[0094] The edge relationship network is determined, including internal relationship edges of physical asset entities, horizontal relationship edges of entity nodes, horizontal relationship edges of attribute nodes, and horizontal relationship edges of data nodes. The specific determination method is as follows: internal relationship edges of physical asset entities are established between entity nodes, attribute nodes, and data nodes of the same physical asset entity; horizontal relationship edges of entity nodes are established for entity nodes with the same parameters of equipment location, equipment model, and operating system; horizontal relationship edges of attribute nodes are established for attribute nodes with the same parameters of data sensitivity level and data format; and horizontal relationship edges of data nodes are established for data nodes with the same sensor type.
[0095] In actual assessment, the storage path of the time-series operation status and time-series monitoring data in the platform database was determined to be "physical asset entity / operation information / sensor type / sensor number / time-series monitoring data-time-series operation status";
[0096] Each physical asset entity contains only one subject node and one attribute node, and data nodes are set according to the number of sensors in the physical asset entity. The subject node stores metadata including device location, device model, operating system and hardware configuration. The attribute node stores metadata including data sensitivity level and data format. Each data node stores metadata of the corresponding sensor type / number, as well as the storage path of the time-series operating status and time-series monitoring data collected by the corresponding sensor.
[0097] The internal relationship edges of the physical asset entity also include the ownership relationship edges between the entity node and the attribute node (representing the data characteristics of the asset), the generation relationship edges between the entity node and the data node (identifying the physical asset from which the data originates), and the description relationship edges between the attribute node and the data node (defining the security attributes and processing requirements of the data).
[0098] The horizontal relationships of the main nodes also include the same location relationship (when the physical asset entities have the same equipment location), the same model relationship (when the equipment models of the physical asset entities belong to the same category after being merged), and the same system relationship (when the system information belongs to the same type after being fuzzed). These relationships form asset clusters, supporting the asset digital twin management platform to perform batch strategy applications and impact scope analysis.
[0099] The horizontal relationship edges of attribute nodes also include sibling relationship edges (when all nodes are labeled with the same sensitivity level) and similar relationship edges (when the runtime information is stored in the same format).
[0100] In this embodiment, the method for obtaining the first encrypted data by performing dynamic attribute-based encryption includes:
[0101] The dynamic attribute set of the physical asset entity is determined based on the graph nodes and edge relationships of the data management knowledge graph, expressed as follows:
[0102]
[0103] in for physical asset entity at any time The dynamic attribute set, The operational status of the physical asset entity. For physical asset entities The set of edge relationships with other physical asset entities. For global context, The inference function is extracted from the knowledge graph using predefined rules;
[0104] The edge relationship weights of each graph node are calculated based on the edge relationships in the data management knowledge graph. The average edge relationship weight of each node is then calculated based on these weights. Finally, the dynamic attribute set of the physical asset entity is updated based on the average edge relationship weight of each node. The expression is as follows:
[0105]
[0106]
[0107]
[0108] in Update the dynamic attribute set of the main node. Update the dynamic attribute set of the attribute node. For data nodes Dynamic attribute set update, , , For adjustment function, For physical asset entities Average edge relation weight of the main node The average edge relation weight of the attribute node. For data nodes Average edge relation weights;
[0109] Based on the dynamic attribute set update of the physical asset entity, the dynamic access strategies for three types of nodes are determined, and the CP-ABE algorithm is used to encrypt the three types of nodes respectively to obtain the first encrypted data, the expression of which is:
[0110]
[0111]
[0112] in for physical asset entity at any time Dynamic access policies, including dynamic access policies for principal nodes. Dynamic access strategy for attribute nodes Data nodes Dynamic access strategy , This is a preset static strategy. Update the dynamic attribute set of the physical asset entity, including , , , The average edge relation weight of the node includes , , , The first encrypted data for the physical asset entity, including the first encrypted data of the principal node. First encrypted data of attribute nodes Data nodes First encrypted data , For public key, Metadata stored for the physical asset entity, including principal node metadata. Attribute node metadata and data nodes Metadata , The CP-ABE algorithm;
[0113] In practical assessments, when determining the dynamic attribute set of a physical asset entity based on the graph nodes and edge relationships of the data management knowledge graph, the inference function... The predefined rules include:
[0114] (1) Status triggering rules: if the physical asset entity is in operation status The set of edge relations is a "fault". For physical asset entities that are "part of a critical production line", add the attribute "UrgentRepair"; entity running status. This includes operation, malfunctions, and maintenance;
[0115] (2) Time context rules, if the global context If the time is "working hours", then add the attribute "WorkHours"; global context Including time, security alerts, business cycles, etc.
[0116] (3) Security context rules, if the global context If the network security alert level is "high risk", then add the attribute "HighRisk";
[0117] (4) Relationship dependency rule, if entity relationship To show an association with high-value assets, add the attribute "CriticalAssociation"; entity relationship. Including isPartOf, isManagedBy, etc.;
[0118] When updating the dynamic attribute set of a fixed physical asset entity ( For high-sensitivity weight threshold, (Assuming a low-sensitivity weight threshold), the adjustment function is defined as:
[0119] for ,when When adding the attributes "HighConnectivity" and "EnhancedMonitoring", When the condition is met, remove the attribute "EnhancedMonitoring" and add the attribute "StandardAccess"; otherwise, keep the dynamic attribute set unchanged.
[0120] (2) For ,when When adding the attributes "StrictPolicy" and "CrossValidation", When the condition is met, remove the attribute "StrictPolicy" and add the attribute "RelaxedPolicy"; otherwise, keep the dynamic attribute set unchanged.
[0121] (3) For ,when When adding the attributes "FrequentAccess" and "RealTimeProcessing", When the time is right, remove the attribute "RealTimeProcessing" and add the attribute "BatchProcessing"; otherwise, keep the dynamic attribute set unchanged.
[0122] During decryption, the user key Bind to a set of attributes, decryption is successful only when the corresponding attribute satisfies the corresponding dynamic access structure. The storage location of the metadata and status / monitoring data corresponding to each graph node of the data management knowledge graph can be read through the asset digital twin management platform, and data statistics and correlation analysis can be performed based on the metadata.
[0123] In this embodiment, the method for calculating the average edge relation weight of nodes includes:
[0124] The edge relationship weights of each graph node are calculated based on the edge relationships in the data management knowledge graph. The specific method is as follows:
[0125] The strength of internal associations is quantified based on the relationship density index, and the weight of the internal relationship edges within the same physical asset entity is calculated; the relationship density index includes the frequency of interaction between nodes, data flow intensity, and information entropy;
[0126] The similarity of the physical assets' locations, equipment, and systems is calculated based on the similarity metric, and the average value is taken as the weight of the horizontal relationship edge between the two main nodes.
[0127] Based on the consistency assessment method, the data sensitivity level consistency, data classification correlation and data compliance of different physical asset entities are calculated, and the average value is taken as the weight of the horizontal relationship edge between the two attribute nodes.
[0128] Homogeneity analysis is used to calculate the similarity of sensing technologies and data patterns of data nodes of different physical asset entities, and the mean value is taken as the weight of the horizontal relationship edge between two data nodes.
[0129] The average edge relationship weight of a node is calculated based on the edge relationship weight; the average edge relationship weight of a node includes the average edge relationship weight of the main node, the average edge relationship weight of the attribute node, and the average edge relationship weight of the data node.
[0130] The average edge relationship weight of the main node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the average weight of all horizontal relationship edges of the corresponding physical asset entity's main nodes;
[0131] The average edge relationship weight of the attribute node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the average weight of all horizontal relationship edges of the corresponding physical asset entity's attribute nodes.
[0132] The average edge relationship weight of the data node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the weight of the horizontal relationship edges of all data nodes of the same sensor of the corresponding physical asset entity.
[0133] In actual evaluation, the interaction frequency between each node is calculated as the maximum value of the historical interaction frequency, the data flow intensity is calculated as the maximum value of the historical data flow intensity, and the information entropy is calculated as the maximum value of the historical information entropy. The average of the three ratios is taken as the weight of the internal relationship edge between the two graph nodes of the same physical asset.
[0134] The location similarity of two physical asset entities is determined based on geographical distance or network topology. The equipment similarity of the two physical asset entities is calculated based on the cosine similarity of the feature vector composed of equipment type / equipment parameters / manufacturer. The system similarity of the physical asset entities is calculated based on the compatibility of operating system / configuration strategy. The mean values of location similarity, equipment similarity and system similarity are calculated as the weights of the horizontal relationship edges between the two entity nodes.
[0135] Sensitivity level consistency is set to 1 when the data sensitivity levels are the same, 0.5 when they are adjacent, and 0 otherwise. Data classification correlation is set to 0.5 when the classification standards are the same and when the classification purposes are the same (such as monitoring and early warning, data analysis, traceability and archiving). Data compliance is determined according to the standard data format, and the average value is used as the weight of the horizontal relationship edge between the two attribute nodes.
[0136] The similarity of sensing technologies is determined by calculating the cosine similarity between feature vectors composed of sensing principles, sensing accuracy, and sensing range. The similarity of data patterns is determined by calculating the cosine similarity between feature vectors composed of data format, temporal features, and data specifications. The average value is taken as the weight of the horizontal relationship edge between the two data nodes.
[0137] The weighting weight is 0.5 / 0.5 when calculating the average edge relationship weight of the main node, and 0.3 / 0.7 when calculating the average edge relationship weight of the attribute node and the average edge relationship weight of the data node.
[0138] In this embodiment, the method for determining the data quality level of operational information within the platform database includes:
[0139] The operation access information of the physical asset entity's sensors is obtained through the asset digital twin management platform. The operation access information is normalized and weighted according to the historical benchmark value of each operation access information to obtain the operation access information quality score. The operation access information is positively correlated with the data quality level, including access frequency, operation frequency and number of accessing departments.
[0140] The asset digital twin management platform compiles statistical data on the current operational information input from each sensor of the physical asset. , on statistical data After normalization, a weighted average is used to obtain the statistical data quality score; the statistical data is negatively correlated with the data quality level, including data missing rate, data anomaly rate and data volatility;
[0141] The data quality score is obtained by weighting the operation access information quality score and the statistical data quality score, and the data quality level is determined by a preset mapping relationship;
[0142] In actual evaluation, when calculating the quality score of operation access information, the operation access information is normalized by calculating the ratio of access frequency, operation frequency and number of accessing departments to the corresponding historical baseline value. The weighted weights of the normalized values of the three types of indicators are 0.2, 0.6 and 0.2, respectively.
[0143] When calculating the quality score of statistical data, the formula is used. Normalize the statistical data; The data quality sensitivity coefficient is set to 100.
[0144] After obtaining a weighted data quality score, a data quality level mapping is performed. The data quality levels include 1 / 2 / 3 / 4 / 5. The data acquired by each sensor is fixed within a fixed transmission time period.
[0145] In this embodiment, the method for obtaining encrypted physical asset data through hierarchical encryption includes:
[0146] The platform database's operational information is encrypted in a tiered manner according to the data sensitivity level of the data attributes to obtain the second encrypted data; the data sensitivity level includes... Public level Internal level Sensitivity level and Core level;
[0147] The specific steps are as follows:
[0148] Based on data quality level The public-level runtime information is obfuscated and an integrity tag is generated to obtain the second encrypted data, expressed as:
[0149]
[0150]
[0151]
[0152] in for Public-level operational information Obfuscated data The SHA-256 hash function is used. To obfuscate the key, It is a random number. To adjust the factor, For data quality levels, For data integrity labels, For message authentication code functions, For integrity key, for The second encrypted data;
[0153] Based on data quality level Internal operational information is symmetrically encrypted and an authentication tag is added to obtain second encrypted data, expressed as:
[0154]
[0155]
[0156]
[0157] in Encryption key for the content, This is the system master key. Assign a physical asset number. The output is ciphertext for symmetric encryption. for Certification label for Symmetric encryption function, for Internal-level operational information For associated data, including physical asset number, data sensitivity level, and timestamp, for The second encrypted data;
[0158] Based on data quality level Sensitive operational information is subjected to symmetric encryption and attribute-based encryption to obtain the second encrypted data, expressed as:
[0159]
[0160]
[0161]
[0162]
[0163] in For data encryption keys, Number the sensor. for Sensitive Operational Information Symmetric encryption output, for Symmetric encryption function, for Attribute-based encryption results For attribute-based encryption functions, for System public key, for Strategy, Based on access control policies, For quality threshold, As an additional strategy, for The second encrypted data;
[0164] Determine the initialization key based on the data quality level. and number of encryption layers ,right Core-level operational information undergoes multi-layered symmetric encryption and attribute-based encryption, and a time lock is added to obtain the second encrypted data. The expression is:
[0165]
[0166]
[0167]
[0168]
[0169]
[0170] in For the first The symmetric encryption key for the encryption layer. For the encryption layer index, for Core-level operational information In the Symmetric encryption output of the encryption layer, for Attribute-based encryption results The puzzle of time lock for The second encrypted data, For strict access policies, The number of hash iterations. The target value for time lock, Salt value for time lock;
[0171] In actual assessments, when tiered encryption is applied to four types of operational information with different data sensitivity levels (time-series status data, time-series monitoring data), the encryption algorithm takes into account the data quality level; all digital data of the same physical asset has the same data sensitivity level;
[0172] right When encrypting public-level operational information, the adjustment factor is... Take 0.5, integrity key ;
[0173] right When encrypting internal-level operational information, Key length Bit, Authentication label length Bit;
[0174] right When encrypting sensitive operational information, Key length Bit, quality threshold Take 0.7, additional strategy For "HighQuality" high-quality strategy;
[0175] right When encrypting core-level operational information, the number of encryption layers Determined based on data quality level (proportional to), and taken as follows: Initialize key Initial key The final ciphertext of multi-layer symmetric encryption is Number of hash iterations , Base value;
[0176] During decryption, the physical asset entity is first identified, and the corresponding graph node is located through the asset digital twin management platform. The first encrypted data of the physical asset entity in the data management knowledge graph (graph node) is decrypted to obtain the metadata of each graph node (mainly extracting the data sensitivity level on the attribute node) and the storage path of the operation information (extracting the data quality level on the relevant data tag through the storage path).
[0177] After user verification is completed, the second encrypted data is processed using the data quality level specified. Regenerate the HMAC key, verify its integrity, and then deobfuscate it to obtain the result. Public-level operational information; data quality level adopted. Derivative decryption key Perform AES-GCM decryption and verify the authentication tag to obtain Internal-level operational information; based on data quality level Use ABE to decrypt and obtain the data encryption key. Then use it to decrypt the AES and ABE ciphertexts to obtain... Sensitive operational information; first, data quality level. Determine the number of hash iterations and the number of symmetric encryption layers Solve the time lock puzzle to obtain the initialization key. Combined with the initialization key and the number of symmetric encryption layers Perform reverse decryption of AES multi-layered ciphertext and direct decryption of ABE ciphertext to obtain... Core-level operational information.
[0178] In this embodiment, the method for obtaining triple-encrypted data through dynamic searchable symmetric encryption includes:
[0179] Extract the time series of runtime information, process it according to a preset mapping rule to obtain a mapped time series, generate a time index and a time salt value based on the mapped time series, calculate the time index key for the current time interval based on the time index, time salt value, and the time index key of the previous time interval, and encrypt the time index entry based on the time index key of the current time interval. The expression is:
[0180]
[0181]
[0182] in for Time index key for time interval, The SHA-256 cryptographic hash function. for Time index of time interval, for The relevant time salt value, It is a random number. For encrypted data time index entries, It uses the AES-GCM symmetric encryption algorithm. For time index entries, include the time index and data pointer;
[0183] Calculate the data encryption key for the current time interval based on the time index entry, sensor code, and system master key. Then, encrypt the second encrypted data using the current time interval's data encryption key to obtain the third encrypted data. The expression is:
[0184]
[0185]
[0186] in for Data encryption key for time intervals, This is the system master key. Encode the sensor, for Second encrypted data time interval The data after symmetric encryption, i.e., the third encrypted data, Indexes based on data sensitivity levels;
[0187] The encrypted data time index entries are stored according to the original storage path of the runtime information. Third encrypted data and corresponding time salinity ;
[0188] In practical evaluation, when performing dynamic searchable symmetric encryption, the system master key is first generated. (Stored in the hardware security module), initial time index key (randomly generated or from) (derived), and set the initial time index. and initial salinity The time index keys for each time interval are generated sequentially according to the time chain, and the time index entries are encrypted. The data encryption keys for each time interval are generated according to the time index, and the second encrypted data is encrypted.
[0189] During decryption, the asset digital twin management platform user terminal determines the time range based on the user's query request. Generate time tokens from the sensor list using the following expression:
[0190]
[0191]
[0192] in For time tokens, To query the start time, The query end time. To prevent replay attacks, random numbers are used. Sign up for the user. For the user's private key, The moment the token is generated;
[0193] The asset digital twin management platform system verifies time tokens, including user signatures. The system checks whether the user's public key is used and whether the time range of the query request is within the user's permissions.
[0194] After verification, the system processes the time range of the query request according to the preset mapping rules to obtain the mapped time range, and extracts the time salt value from the corresponding storage path. And generate the original time index based on the mapped time range, starting from the initial time index key. Calculate the time index key sequentially, and decrypt the encrypted data of the data time index entry based on the time index key to obtain the original time index entry;
[0195] The data encryption key is calculated based on the original time index entry, system master key, and sensor code. The third encrypted data is then decrypted using the data encryption key to obtain the second encrypted data.
[0196] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A data encryption method for a knowledge graph-based asset digital twin management platform, characterized in that, Includes the following steps: S1. Acquire digital data of physical assets, determine the storage location of the digital data, and construct a data management knowledge graph; the digital data includes asset information, data attributes, and operational information; the storage location of the digital data includes graph nodes and platform database; S2. Based on the graph structure and edge relationship weights of the data management knowledge graph, perform dynamic attribute base encryption on the graph nodes to obtain the first encrypted data; S3. Determine the data quality level of the operational information in the platform database based on the operation access information and statistical data. Then, perform hierarchical encryption on the operational information in the platform database according to the data quality level and data attributes to obtain the second encrypted data. The operational information in the platform database includes time-series operational status and time-series monitoring data. S4. Perform dynamic searchable symmetric encryption on the second encrypted data according to the time sequence information to obtain the third encrypted data.
2. The data encryption method for a knowledge graph-based asset digital twin management platform according to claim 1, characterized in that, The method for constructing a data management knowledge graph includes: Acquire digital data of physical assets; the digital data includes asset information, data attributes, and operational information; the asset information includes equipment location, equipment model, operating system, and hardware configuration; the data attributes include data sensitivity level and data format; the operational information includes sensor type, time-series operational status, and time-series monitoring data; the time-series operational status and time-series monitoring data are a set of correlated data; Determine the storage path of the timing operation status and timing monitoring data in the platform database; The graph node system is defined, specifically including subject nodes, attribute nodes, and data nodes; the subject nodes are used to store asset information metadata of the physical asset subject; the attribute nodes are used to store data attribute metadata of the physical asset subject; the data nodes are used to store sensor type and number metadata, and the data node corresponding to each sensor simultaneously stores the storage path of the corresponding time-series operating status and time-series monitoring data; The edge relationship network is determined, including internal relationship edges of physical asset entities, horizontal relationship edges of entity nodes, horizontal relationship edges of attribute nodes, and horizontal relationship edges of data nodes. The specific determination method is as follows: internal relationship edges of physical asset entities are established between entity nodes, attribute nodes, and data nodes of the same physical asset entity; horizontal relationship edges of entity nodes are established for entity nodes with the same parameters such as device location, device model, and operating system; horizontal relationship edges of attribute nodes are established for attribute nodes with the same parameters such as data sensitivity level and data format; and horizontal relationship edges of data nodes are established for data nodes with the same sensor type.
3. The data encryption method for a knowledge graph-based asset digital twin management platform according to claim 1, characterized in that, The method for obtaining the first encrypted data by performing dynamic attribute-based encryption includes: The dynamic attribute set of the physical asset entity is determined based on the graph nodes and edge relationships of the data management knowledge graph, expressed as follows: in for physical asset entity at any time Dynamic attribute set, The operational status of the physical asset entity. For physical asset entities The set of edge relationships with other physical asset entities. For global context, The inference function is extracted from the knowledge graph using predefined rules; The edge relationship weights of each graph node are calculated based on the edge relationships in the data management knowledge graph. The average edge relationship weight of each node is then calculated based on these weights. Finally, the dynamic attribute set of the physical asset entity is updated based on the average edge relationship weight of each node. The expression is as follows: in Update the dynamic attribute set of the main node. Update the dynamic attribute set of the attribute node. For data nodes Dynamic attribute set update, , , For adjustment function, For physical asset entities Average edge relation weight of the main node The average edge relation weight of the attribute node. For data nodes Average edge relation weights; Based on the dynamic attribute set update of the physical asset entity, the dynamic access strategies for three types of nodes are determined, and the CP-ABE algorithm is used to encrypt the three types of nodes respectively to obtain the first encrypted data, the expression of which is: in for physical asset entity at any time Dynamic access policies, including dynamic access policies for principal nodes. Dynamic access strategy for attribute nodes Data nodes Dynamic access strategy , This is a preset static strategy. Update the dynamic attribute set of the physical asset entity, including , , , The average edge relation weight of the node includes , , , The first encrypted data for the physical asset entity, including the first encrypted data of the principal node. First encrypted data of attribute nodes Data nodes First encrypted data , For public key, Metadata stored for the physical asset entity, including principal node metadata. Attribute node metadata and data nodes Metadata , This refers to the CP-ABE algorithm.
4. The data encryption method for a knowledge graph-based asset digital twin management platform according to claim 3, characterized in that, The method for calculating the average edge relation weight of nodes includes: The edge relationship weights of each graph node are calculated based on the edge relationships in the data management knowledge graph. The specific method is as follows: The strength of internal associations is quantified based on the relationship density index, and the weight of the internal relationship edges within the same physical asset entity is calculated; the relationship density index includes the frequency of interaction between nodes, data flow intensity, and information entropy; The similarity of the physical assets' locations, equipment, and systems is calculated based on the similarity metric, and the average value is taken as the weight of the horizontal relationship edge between the two main nodes. Based on the consistency assessment method, the data sensitivity level consistency, data classification correlation and data compliance of different physical asset entities are calculated, and the average value is taken as the weight of the horizontal relationship edge between the two attribute nodes. Homogeneity analysis is used to calculate the similarity of sensing technologies and data patterns of data nodes of different physical asset entities, and the mean value is taken as the weight of the horizontal relationship edge between two data nodes. The average edge relationship weight of a node is calculated based on the edge relationship weight; the average edge relationship weight of a node includes the average edge relationship weight of the main node, the average edge relationship weight of the attribute node, and the average edge relationship weight of the data node. The average edge relationship weight of the main node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the average weight of all horizontal relationship edges of the corresponding physical asset entity's main nodes; The average edge relationship weight of the attribute node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the average weight of all horizontal relationship edges of the corresponding physical asset entity's attribute nodes. The average edge relationship weight of the data node is the weighted sum of the average weight of all internal relationship edges of the same physical asset entity and the weight of the horizontal relationship edges of all data nodes of the same sensor of the corresponding physical asset entity.
5. The data encryption method for a knowledge graph-based asset digital twin management platform according to claim 1, characterized in that, The method for determining the data quality level of operational information within the platform database includes: The operation access information of the physical asset entity's sensors is obtained through the asset digital twin management platform. The operation access information is normalized and weighted according to the historical benchmark value of each operation access information to obtain the operation access information quality score. The operation access information is positively correlated with the data quality level, including access frequency, operation frequency and number of accessing departments. The asset digital twin management platform compiles statistical data on the current operational information input from each sensor of the physical asset. , on statistical data After normalization, a weighted average is used to obtain the statistical data quality score; the statistical data is negatively correlated with the data quality level, including data missing rate, data anomaly rate and data volatility; The data quality score is obtained by weighting the operation access information quality score and the statistical data quality score, and the data quality level is determined by a preset mapping relationship.
6. The data encryption method for a knowledge graph-based asset digital twin management platform according to claim 1, characterized in that, The method for obtaining encrypted physical asset data through hierarchical encryption includes: The platform database's operational information is encrypted in a tiered manner according to the data sensitivity level of the data attributes to obtain the second encrypted data; the data sensitivity level includes... Public level Internal level Sensitivity level and Core level; The specific steps are as follows: Based on data quality level The public-level runtime information is obfuscated and an integrity tag is generated to obtain the second encrypted data, expressed as: in for Public-level operational information Obfuscated data The SHA-256 hash function is used. To obfuscate the key, It is a random number. To adjust the factor, For data quality levels, For data integrity labels, For message authentication code functions, For integrity key, for The second encrypted data; Based on data quality level Internal operational information is symmetrically encrypted and an authentication tag is added to obtain second encrypted data, expressed as: in Encryption key for the content, This is the system master key. Assign a physical asset number. For symmetric encryption, output the ciphertext. for Certification label for Symmetric encryption function, for Internal-level operational information For associated data, including physical asset number, data sensitivity level, and timestamp, for The second encrypted data; Based on data quality level Sensitive operational information is subjected to symmetric encryption and attribute-based encryption to obtain the second encrypted data, expressed as: in For data encryption keys, Number the sensor. for Sensitive Operational Information Symmetric encryption output, for Symmetric encryption function, for Attribute-based encryption results For attribute-based encryption functions, for System public key, for Strategy, Based on access control policies, For quality threshold, As an additional strategy, for The second encrypted data; Determine the initialization key based on the data quality level. and number of encryption layers ,right Core-level operational information undergoes multi-layered symmetric encryption and attribute-based encryption, and a time lock is added to obtain the second encrypted data. The expression is: in For the first The symmetric encryption key for the encryption layer. For the encryption layer index, for Core-level operational information In the Symmetric encryption output of the encryption layer, for Attribute-based encryption results The puzzle of locking time for The second encrypted data, For strict access policies, The number of hash iterations. The target value for time lock. This is the time-locked salt value.
7. The data encryption method for a knowledge graph-based asset digital twin management platform according to claim 1, characterized in that, The method for obtaining third encrypted data through dynamic searchable symmetric encryption includes: Extract the time series of runtime information, process it according to a preset mapping rule to obtain a mapped time series, generate a time index and a time salt value based on the mapped time series, calculate the time index key for the current time interval based on the time index, time salt value, and the time index key of the previous time interval, and encrypt the time index entry based on the time index key of the current time interval. The expression is: in for Time index key for time interval, The SHA-256 cryptographic hash function. for Time index of time interval, for The relevant time salt value, It is a random number. For encrypted data time index entries, It uses the AES-GCM symmetric encryption algorithm. For time index entries, include the time index and data pointer; Calculate the data encryption key for the current time interval based on the time index entry, sensor code, and system master key. Then, encrypt the second encrypted data using the current time interval's data encryption key to obtain the third encrypted data. The expression is: in for Data encryption key for time intervals, This is the system master key. Encode the sensor, for Second encrypted data time interval The data after symmetric encryption, i.e., the third encrypted data, Indexes based on data sensitivity levels; The encrypted data time index entries are stored according to the original storage path of the runtime information. Third encrypted data and corresponding time salinity .