An access control method and system for industrial data security
Patent Information
- Application Number
- CN202511477343.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-16
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2045-10-16
AI Technical Summary
[0005]本发明提供了一种工业数据安全的访问控制方法及系统,以解决现有技术无法在动态工业环境中兼顾指令安全执行与精准威胁检测的问题
(1)本发明通过区块链构建指令序列日志的不可篡改记录,结合对称加密与数字签名生成加密保护的历史链,解决了传统日志易被篡改的问题,确保工业设备实时访问请求与权限变更数据的可追溯性,为后续威胁溯源提供可靠数据支撑。
Smart Images

Figure CN121396576B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to an access control method and system for industrial data security. Background Technology
[0002] Currently, with the rapid development of the Industrial Internet, data security has become a key pillar for ensuring production efficiency and core competitiveness of enterprises. As industrial equipment and systems become increasingly interconnected, data access control not only concerns the protection of enterprise information assets but also directly impacts the stability and reliability of production processes. The importance of industrial data security is increasingly prominent, especially in scenarios involving sensitive production data, equipment control commands, and user access management. Any security vulnerability could lead to production interruptions, data leaks, or even system paralysis. Therefore, building an efficient and secure access control mechanism has become a major issue that urgently needs to be addressed in the industrial sector.
[0003] Current mainstream industrial data access control methods largely rely on static encryption algorithms and fixed-rule permission management systems. These methods typically pre-define access permission lists for devices and users, use traditional encryption methods such as AES and RSA to protect transmitted data, and log access behavior for post-event auditing. For example, in a smart manufacturing workshop, the system assigns a fixed access permission level to each device, allowing only authorized devices to access specific data within a preset time period. Access logs are stored on a local server to trace the source of security issues. However, this approach has significant limitations: firstly, static permissions are ill-suited to the frequent permission changes caused by production task adjustments in industrial scenarios, and cannot respond to dynamic access requests in real time; secondly, locally stored logs are easily tampered with, and traditional encryption and rule detection struggle to identify highly concealed tampering behaviors, such as malicious attacks achieved through fine-tuning control command parameters, leading to delayed threat detection.
[0004] Therefore, existing technologies cannot simultaneously ensure secure command execution and accurate threat detection in dynamic industrial environments. Summary of the Invention
[0005] This invention provides an access control method and system for industrial data security, which solves the problem that existing technologies cannot simultaneously ensure secure instruction execution and accurate threat detection in dynamic industrial environments.
[0006] Firstly, in order to solve the above-mentioned technical problems, the present invention provides an access control method for industrial data security, comprising: Obtain real-time access requests and permission change data for industrial equipment; Based on the real-time access requests and permission change data, an immutable record of the instruction sequence log is constructed using blockchain to obtain the historical chain construction result under the encryption protection mechanism; Based on the historical chain construction results, access pattern characteristics in a high-concurrency compatible environment are obtained. If the access pattern characteristics match a preset dynamic demand change threshold, a legal instruction sequence is determined. Based on the legal instruction sequence, device log data is acquired and fused with dynamic data stream to generate a fused dataset. If there is data in the fused dataset that exceeds a preset behavior threshold, then the fused dataset is compared and analyzed through anomaly detection to obtain a set of deviation patterns. For the set of deviation patterns, the degree of concealment of abnormal behavior is judged, and the final threat classification result is obtained by prioritizing and sorting them. Based on the threat classification results, a dynamic instruction execution sequence is generated through permission verification, and tamper detection is performed to obtain updated access control rules; Based on the updated access control rules, the dynamic instruction execution sequence is processed using an encrypted transmission channel to obtain a secure instruction sequence.
[0007] In one optional implementation, the step of using blockchain to construct an immutable record of the instruction sequence log based on the real-time access request and permission change data to obtain the historical chain construction result under an encrypted protection mechanism includes: Determine whether the real-time access request and permission change data contain hidden tampering features. If they do, mark them as abnormal data to obtain the marked dataset. Based on the labeled dataset, a blockchain is used to generate an instruction sequence log; A unique data packet hash value is generated for each instruction sequence in the instruction sequence log, and stored in the blockchain node in combination with the timestamp and device identifier to generate an immutable log record; The immutable log record is symmetrically encrypted, and a digital signature is generated by combining it with the private key. The digital signature is then verified to match the preset public key. If they match, the encrypted log record is determined. The encrypted log records are linked in chronological order using a blockchain chain structure, so that the hash value of each block is associated with the previous block, resulting in a historical chain construction result under an encrypted protection mechanism.
[0008] In one optional implementation, based on the historical chain construction result, access pattern characteristics in a high-concurrency compatible environment are obtained. If the access pattern characteristics match a preset dynamic demand change threshold, a legal instruction sequence is determined, including: Based on the historical chain construction results, real-time monitoring data is obtained from a high-concurrency compatible environment; Based on the real-time monitoring data, combined with device identification information and timestamp records, a dataset containing access pattern characteristics is generated; If the dataset containing access pattern features matches a preset dynamic demand change threshold, a valid instruction sequence is generated through logical judgment.
[0009] In one optional implementation, the step of acquiring device log data based on the valid instruction sequence and fusing it with a dynamic data stream to generate a fused dataset includes: Obtain the dynamic data stream during the execution of the legal instruction sequence; Device log data is obtained from multiple data sources, and the device log data is standardized using a pre-established instruction sequence to generate a device log dataset in a unified format. The device log dataset is fused with the dynamic data stream to generate a fused dataset.
[0010] In one optional implementation, the step of judging the concealment level of abnormal behavior for the set of deviation patterns and obtaining the final threat classification result by prioritizing and sorting them includes: For the set of deviation patterns, the degree of concealment of abnormal behavior is determined by matching it with preset concealment assessment rules through correlation analysis, and a set of threat classifications is generated. For the aforementioned threat classification set, priority ranking is performed by combining priority levels with real-time monitoring data to obtain the final threat classification result.
[0011] In one optional implementation, the step of generating a dynamic instruction execution sequence based on the threat classification result through permission verification, and performing tamper detection to obtain updated access control rules includes: Based on the threat classification results, the basis for updating access control rules is determined by matching permission verification with real-time monitoring data, and a dynamic instruction execution sequence is generated. Based on the dynamic instruction execution sequence, hash verification is used to detect tampering of the access control rules and generate updated access control rules.
[0012] In one optional implementation, the step of processing the dynamic instruction execution sequence using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence includes: Based on the updated access control rules, the dynamic instruction execution sequence is processed through an encrypted transmission channel, and symmetric encryption is used to generate encrypted instruction sequence data packets. If no exception is triggered when the encrypted instruction sequence data packet is transmitted through the channel, the encrypted instruction sequence data packet is decrypted and parsed according to the preset parsing rules to obtain the secure instruction sequence.
[0013] In an optional implementation, after processing the dynamic instruction execution sequence using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence, the method further includes: Based on the secure instruction sequence, a historical chain is constructed to compare the secure instruction sequence with pre-established historical chain data to generate an execution path record.
[0014] The execution path record is compared with the pre-stored historical data using hash verification to verify the tampering detection results.
[0015] Secondly, the present invention provides an access control system for industrial data security, comprising: The data acquisition module acquires real-time access requests and permission change data from industrial equipment. The chain-building encryption module, based on the real-time access requests and permission change data, uses the blockchain to build an immutable record of the instruction sequence log, and obtains the historical chain-building result under the encryption protection mechanism. The legality determination module obtains access pattern characteristics in a high-concurrency compatible environment based on the historical chain construction results. If the access pattern characteristics match a preset dynamic demand change threshold, then a legal instruction sequence is determined. The data fusion module, based on the legal instruction sequence, acquires device log data and fuses it with the dynamic data stream to generate a fused dataset; The anomaly detection module, if there is data in the fused dataset that exceeds a preset behavior threshold, performs comparative analysis on the fused dataset through anomaly detection to obtain a set of deviation patterns; The threat classification module assesses the degree of concealment of abnormal behavior based on the set of deviation patterns, and obtains the final threat classification result by prioritizing and sorting the patterns. The rule update module generates a dynamic instruction execution sequence based on the threat classification results through permission verification, performs tamper detection, and obtains updated access control rules. The encrypted execution module processes the dynamic instruction execution sequence using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence.
[0016] Thirdly, the present invention also provides an electronic device including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements an industrial data security access control method as described in any one of the above.
[0017] Fourthly, the present invention also provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to perform an access control method for industrial data security as described above.
[0018] Compared with the prior art, the present invention has the following beneficial effects: (1) This invention constructs an immutable record of instruction sequence logs through blockchain, and generates an encrypted and protected historical chain by combining symmetric encryption and digital signatures. This solves the problem that traditional logs are easily tampered with, ensures the traceability of real-time access requests and permission change data of industrial equipment, and provides reliable data support for subsequent threat tracing.
[0019] (2) For high-concurrency industrial environments, this invention determines the legal instruction sequence by analyzing access pattern characteristics and matching them with preset dynamic demand change thresholds, and optimizes the abnormal behavior detection process by integrating real-time monitoring data. Compared with static permission management methods, it can more accurately capture potential threats and improve the security and compatibility of instruction execution in dynamic environments.
[0020] (3) This invention processes access log deviations through an anomaly detection model, classifies threats by combining concealment assessment rules, dynamically updates access control rules, and uses encrypted transmission channels to process instruction sequences. At the same time, it backtracks the historical chain to verify the tampering detection results, forming a complete protection chain of "detection-response-verification". This effectively improves the ability to respond to concealed tampering threats and ensures the security of the entire process of industrial data access and instruction execution. Attached Figure Description
[0021] Figure 1 This is a schematic flowchart of an access control method for industrial data security provided in the first embodiment of the present invention; Figure 2 This is a schematic diagram of an industrial data security access control system provided in the second embodiment of the present invention. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] Reference Figure 1 The first embodiment of the present invention provides an access control method for industrial data security, comprising the following steps: S11, obtain real-time access requests and permission change data for industrial equipment; S12, based on the real-time access requests and permission change data, an immutable record of the instruction sequence log is constructed using blockchain to obtain the historical chain construction result under the encryption protection mechanism; S13, Based on the historical chain construction result, obtain the access pattern characteristics in the high-concurrency compatible environment. If the access pattern characteristics match the preset dynamic demand change threshold, then determine the legal instruction sequence. S14, Based on the legal instruction sequence, acquire device log data and fuse it with dynamic data stream to generate a fused dataset; S15, if there is data in the fused dataset that exceeds a preset behavior threshold, then the fused dataset is compared and analyzed through anomaly detection to obtain a set of deviation patterns; S16, For the set of deviation patterns, the degree of concealment of abnormal behavior is judged, and the final threat classification result is obtained by prioritizing and sorting. S17. Based on the threat classification results, a dynamic instruction execution sequence is generated through permission verification, and tamper detection is performed to obtain updated access control rules. S18, based on the updated access control rules, the dynamic instruction execution sequence is processed using an encrypted transmission channel to obtain a secure instruction sequence.
[0024] In step S11, it is necessary to obtain real-time access requests and permission change data of industrial equipment.
[0025] It should be noted that real-time access requests are immediate requests initiated by industrial equipment during operation to obtain data or perform operations, such as requests from the equipment to the server to "read production parameters" or "start running programs." Permission change data refers to data related to the adjustment of access permissions for equipment or users in the industrial system, such as an administrator changing a device's "read-only permission" to "read-write permission," or the system automatically modifying the access scope of a device due to adjustments in production tasks. Furthermore, the data obtained must be targeted at potential hidden tampering threats between industrial equipment to provide a basis for subsequent detection.
[0026] This step primarily involves data acquisition through data acquisition modules deployed in the industrial environment. These modules need to establish communication connections with various industrial devices and be compatible with the communication protocols of different devices to ensure the collection of necessary real-time access requests and permission change data from various types of industrial equipment. The acquired data is then initially processed to remove obviously invalid data, preparing it for subsequent processing.
[0027] For example, in an Industrial Internet of Things (IIoT) scenario, the data acquisition module can capture communication data between devices based on the MQTT protocol. By subscribing to device access requests and permission change topics, it can obtain data packets in real time. For instance, when a smart machine tool in a factory needs to access raw material inventory data, it sends a real-time access request to the inventory management system. The data acquisition module subscribes to the smart machine tool's access request topic via the MQTT protocol, thus capturing this access request data in a timely manner. When the smart machine tool's operating permissions change, such as adding operating permissions for a certain precision machining program, the permission change data will also be captured by the data acquisition module through the corresponding topic subscription.
[0028] In step S12, based on the real-time access requests and permission change data, an immutable record of the instruction sequence log is constructed using blockchain technology to obtain the historical chain construction result under an encrypted protection mechanism, including: Determine whether the real-time access request and permission change data contain hidden tampering features. If they do, mark them as abnormal data to obtain the marked dataset. Based on the labeled dataset, a blockchain is used to generate an instruction sequence log; A unique data packet hash value is generated for each instruction sequence in the instruction sequence log, and stored in the blockchain node in combination with the timestamp and device identifier to generate an immutable log record; The immutable log record is symmetrically encrypted, and a digital signature is generated by combining it with the private key. The digital signature is then verified to match the preset public key. If they match, the encrypted log record is determined. The encrypted log records are linked in chronological order using a blockchain chain structure, so that the hash value of each block is associated with the previous block, resulting in a historical chain construction result under an encrypted protection mechanism.
[0029] It should be noted that a hash value is a fixed-length unique string obtained by calculating input data of arbitrary length using the SHA-256 hash algorithm. The SHA-256 hash algorithm first groups the input data into 512-bit groups and pads them, and then performs logical operations and constant iterations on the initial 256-bit hash value through 64 rounds of loops, finally outputting a 256-bit fixed-length hash value. The process is irreversible and the result is unique.
[0030] Furthermore, covert tampering characteristics refer to features that indicate data may have been maliciously modified but are not easily detected, such as CRC32 or MD5 hash values of data packets that do not match the expected values, or subtle adjustments to the data content that do not conform to normal business logic; the chain structure of the blockchain associates the hash value of each block with the previous block, ensuring the logs are immutable; symmetric encryption refers to an encryption method that uses the same key for encryption and decryption. In this invention, the AES-256 algorithm (a symmetric encryption algorithm that divides data into 128-bit blocks, performs 14 rounds of substitution, shifting, and other operations, and encrypts and decrypts with a 256-bit key) is used to ensure the confidentiality of log storage and transmission; digital signatures and public key verification are used to confirm the legitimacy of the log source and prevent fake logs; the blockchain adopts a private chain structure and is deployed on the factory's intranet nodes based on the PBFT consensus mechanism to ensure the immutability and consistency of log records; the digital signature uses the ECDSA algorithm, with the private key stored in the hardware security module (HSM) and the public key pre-embedded in each verification node.
[0031] In this step, the collected real-time access requests and permission change data are first assessed for concealed tampering characteristics. Data containing these characteristics is marked as anomalous data, forming a marked dataset. This step is the initial screening and risk identification of the data. Further, the marked dataset formed from the anomalous data is used to generate instruction sequence logs using blockchain technology. A unique hash value is generated for each instruction sequence, combined with a timestamp and device identifier, and stored on a blockchain node to generate immutable log records. This step utilizes the characteristics of blockchain to ensure the originality and immutability of the log records. For example, if a device sends an anomalous instruction at 14:31:00... The log records the hash value and timestamp, allowing auditors to trace the source of abnormal instructions through the blockchain. Next, the immutable log records are symmetrically encrypted and combined with a private key to generate a digital signature. This signature is then verified by matching it with a preset public key, confirming the encrypted log record. This step further enhances the security of the log records, preventing unauthorized access and tampering during storage and transmission. Finally, the encrypted log records are linked chronologically according to the blockchain's chain structure, associating the hash value of each block with the previous block, forming a historical chain under an encrypted protection mechanism. This completes the entire process from data filtering to the final historical chain construction.
[0032] For example, when determining whether real-time access requests and permission change data contain hidden tampering characteristics, the integrity check value of the data packet, such as CRC32 or MD5 hash value (CRC32 is a low-security, high-efficiency check algorithm, while MD5 is a high-security, slightly less efficient hash algorithm; the difference lies in their security level and computational efficiency), can be analyzed and compared with the expected value. For instance, if a device's access request data packet contains the source address, timestamp, and permission level, and its CRC32 hash value does not match the expectation, it is marked as abnormal data, belonging to data containing hidden tampering characteristics.
[0033] Furthermore, after generating instruction sequence logs based on the labeled dataset, a unique data packet hash value is generated for each instruction sequence using the SHA-256 hash algorithm. For example, an access request data packet may contain a device ID of DEV001, a timestamp of 2025-08-28 12:00:00, and a permission change to "read and write". After generating a unique hash value, this hash value is combined with the timestamp and device ID DEV001 and stored on the blockchain node to generate an immutable log record. Then, the immutable log record is encrypted using the AES-256 symmetric encryption algorithm, and an ECDSA digital signature is generated using the private key. During verification, a preset public key is used to check if the signature matches. If the signature verification of a log record passes, it is determined to be the encrypted log record.
[0034] Furthermore, the encrypted log records are linked chronologically according to the blockchain's chain structure. For example, block 1 records the access request log at 10:00:00, block 2 records the permission change log at 10:01:00, and the hash value of block 2 contains the hash value of block 1, forming a chain structure and obtaining the historical chain construction result under the encryption protection mechanism. A factory's equipment management system successfully detected an unauthorized permission change attempt using this solution and quickly located the source of the problem through blockchain records, reducing the potential risk of production interruption.
[0035] In step S13, based on the historical chain construction results, access pattern characteristics in a high-concurrency compatible environment need to be obtained. If the access pattern characteristics match a preset dynamic demand change threshold, a legal instruction sequence is determined, including: Based on the historical chain construction results, real-time monitoring data is obtained from a high-concurrency compatible environment; Based on the real-time monitoring data, combined with device identification information and timestamp records, a dataset containing access pattern characteristics is generated; If the dataset containing access pattern features matches a preset dynamic demand change threshold, a valid instruction sequence is generated through logical judgment.
[0036] It should be noted that a high-concurrency compatible environment refers to an industrial system where a large number of devices simultaneously perform data interaction and access requests. In such an environment, data traffic is high, access frequency is high, and the requirements for real-time and accuracy of data processing are higher. Real-time monitoring data refers to the data obtained by monitoring the operating status, data transmission, and access request status of devices in a high-concurrency compatible environment. This data reflects the actual operation and access status of the devices in the current environment. Access pattern characteristics refer to the features extracted from real-time monitoring data that reflect the patterns of device access behavior, such as the frequency of device access requests, the distribution of access request types, and the time interval patterns of access requests. The preset dynamic demand change threshold is obtained by analyzing the statistical characteristics of historical normal data samples. It is used to determine whether the access pattern meets the normal demand range. The threshold will be dynamically adjusted according to the system's operating status and demand changes to adapt to access control requirements under different circumstances. For example, during the full-speed operation of the production line, the request frequency threshold can be increased to 150% of the baseline value; during maintenance periods, it can be decreased to 50% of the baseline value.
[0037] The legitimate instruction sequence is a structured set containing device identifiers (such as DEV001, DEV002), timestamps (such as 2025-08-28 12:00:00), operation types (such as "read data" or "switch operation"), and unique hash verification information. It also needs to be generated as an immutable log record through the blockchain and stored in association with the device identifier and timestamp. Its function is to serve as an anomaly detection benchmark, to standardize log data and filter out deviation behaviors to generate threat identifiers, to serve as the basis for secure instruction execution, to support subsequent encrypted transmission and authorization verification, and to provide support for log tracing (assisting in locating the source of abnormal instructions) and closed-loop verification (comparing with historical chains to verify tamper detection results). At the same time, it provides data reference for the dynamic updating of access control rules.
[0038] In this step, firstly, based on the historical blockchain construction results, real-time monitoring data is collected from a high-concurrency compatible environment. The historical blockchain construction results provide historical reference for the analysis of real-time monitoring data, helping to better identify the rationality of the current access pattern. Then, the acquired real-time monitoring data is processed. Device identification information is used to identify the device to which the data belongs, and timestamp records are used to determine the data's generation time. Access pattern characteristics are then extracted to form a dataset containing these characteristics. Finally, the dataset containing access pattern characteristics is compared with a preset dynamic demand change threshold to determine if they match. If they match, the access pattern meets normal requirements, and a corresponding legal instruction sequence is generated; if they do not match, no legal instruction sequence is generated. Furthermore, the generated legal instruction sequence also needs to be recorded in an immutable log through the blockchain, forming part of the historical blockchain so that auditors can trace its origin.
[0039] For example, in a high-concurrency compatible environment, the data acquisition module can acquire real-time monitoring data by subscribing to the communication channels between devices based on the OPCUA protocol, capturing access requests and operational status information. For instance, in the production workshop of a large automobile manufacturing plant, a large number of industrial robots and automated production line equipment operate simultaneously. These devices frequently interact and make access requests. The data acquisition module subscribes to the communication channels of these devices via the OPCUA protocol to acquire real-time access request data (such as robots requesting component location data, and production line equipment requesting production plan data) and operational status data (such as equipment temperature, speed, and work progress).
[0040] Furthermore, based on the acquired real-time monitoring data, combined with device identification information (e.g., ID DEV002) and timestamp records (e.g., 2025-08-28 14:30:00), the data is processed to extract access pattern features. For example, device DEV002's access request frequency is 2 times per minute, and the access request is "read data". Assuming the preset dynamic demand change threshold is a maximum request frequency of 5 times per minute, then device DEV002's access pattern feature dataset matches the preset dynamic demand change threshold, generating a valid instruction sequence, such as "DEV002, 2025-08-28 14:30:00, read data, hash value: a8f5c...3d2e". If a device's access request frequency is 10 times per minute, exceeding the preset dynamic demand change threshold, then the device's access pattern feature dataset does not match the threshold, and no valid instruction sequence will be generated, further enabling anomaly detection of the device's access behavior.
[0041] In step S14, based on the legal instruction sequence, device log data needs to be acquired and fused with the dynamic data stream to generate a fused dataset, including: Obtain the dynamic data stream during the execution of the legal instruction sequence; Device log data is obtained from multiple data sources, and the device log data is standardized using a pre-established instruction sequence to generate a device log dataset in a unified format. The device log dataset is fused with the dynamic data stream to generate a fused dataset.
[0042] It should be noted that dynamic data flow during the execution of a valid instruction sequence refers to the real-time data flow between devices and between devices and the system when the valid instruction sequence is executed. This data can reflect the real-time status and process of instruction execution, such as parameter change data of devices, data transmission status data, and feedback data of instruction execution results. Device log data refers to the recorded data generated by various devices, servers, applications, etc. in the industrial system during operation. It includes information such as device operation behavior, system operating status, and data access. Device log data from multiple data sources can reflect the operation and access status of the system from different perspectives, improving the comprehensiveness of the data.
[0043] The pre-established instruction sequence is a set of rules and templates for standardizing device log data in different formats. Since the device log data generated by different data sources may have different formats (such as some device log data in JSON format, some in CSV format, and some in custom format), the pre-established instruction sequence can convert these different formats of device log data into a unified format, which facilitates subsequent data processing and analysis.
[0044] In this step, the dynamic data stream generated during the execution of a legal instruction sequence is captured in real time to ensure that complete real-time data during instruction execution can be obtained. Then, device log data is collected from multiple data sources (such as firewalls, servers, industrial equipment, applications, etc.). Since the log formats of different data sources are different, these device log data are standardized using a pre-established instruction sequence and converted into a device log dataset in a unified format (such as a unified JSON format, which includes fields such as time, source device identifier, target device identifier, operation type, and data content).
[0045] In one implementation, a time-series-based data fusion method can be used to fuse the standardized device log dataset with the captured dynamic data stream. The device log data and dynamic data within the same time period are associated through timestamps, relevant data fields are integrated, redundant data is removed, data conflicts are handled, and finally a fused dataset is generated.
[0046] It is worth noting that data fusion can also be carried out using a feature-based association approach, which involves associating and fusing data based on the feature fields of the data (such as device identifier, operation type, etc.), which helps to uncover the inherent connections between different data.
[0047] For example, in the network security system of an industrial enterprise, during the execution of the legitimate command sequence "DEV002, 2025-08-28 14:30:00, read data, hash value: a8f5c...3d2e", a dynamic data stream is obtained. This dynamic data stream contains the data transmission status between device DEV002 and the production data server during 14:30:00-14:35:00, such as data transmission rate, data packet size, and response time of data requests. Device log data is obtained from multiple data sources, including firewall logs (JSON format, including timestamp, source IP, destination IP, request type, and whether it was blocked), production data server access logs (CSV format, including timestamp, accessed device ID, accessed data type, and access result), and device DEV002 operation logs (custom format, including time, operation command, and operation status).
[0048] These device log data are standardized using a pre-established instruction sequence, converting firewall logs, server access logs, and device operation logs into a unified JSON-formatted device log dataset containing fields such as "Time," "Source Device Identifier," "Target Device Identifier," "Operation Type," "Operation Result," and "Data Details." For example, in the firewall logs, "Source IP" is converted to "Source Device Identifier," "Target IP" to "Target Device Identifier," "Request Type" directly to "Operation Type," and "Blocked or Not Blocked" to "Operation Result" ("Not Blocked" for success, "Blocked" for failure), with relevant "Data Details" added. Similar field mapping and supplementation are performed on server access logs and device operation logs to generate a unified format device log dataset.
[0049] Furthermore, a time-series-based data fusion method is adopted, using a 1-minute time window to fuse the standardized device log dataset with the dynamic data stream. For example, within the time window of 14:30:00-14:31:00, the operation record of device DEV002 on the production data server in the device log dataset, "DEV002, 2025-08-28 14:30:00, read data, hash value: a8f5c...3d2e", is correlated and integrated with data such as the data transmission rate and data packet size between device DEV002 and the production data server during the same time period in the dynamic data stream. Duplicate records are removed (e.g., time and device identification information contained in both device log data and dynamic data are only retained once), and potential data conflicts are handled (e.g., device log data shows successful operation but dynamic data shows partial data packet transmission failure; in this case, considering whether the device subsequently re-requests data, the fusion result is determined to be "partially successful operation, data packet retransmission exists"). Finally, a fused dataset is generated.
[0050] In step S15, if there is data in the fused dataset that exceeds a preset behavior threshold, then the fused dataset is compared and analyzed through anomaly detection to obtain a set of deviation patterns.
[0051] It should be noted that the preset behavior thresholds are obtained by analyzing the statistical characteristics of historical normal data samples. For example, the access request frequency threshold can be set to the upper limit of twice the standard deviation of the average historical normal access frequency. This is used to measure whether the data in the fused dataset conforms to the standard of normal behavior. Different types of data correspond to different preset behavior thresholds, such as device access request frequency thresholds, data transmission rate thresholds, and operation response time thresholds. Anomaly detection refers to determining whether the data in the fused dataset exceeds the preset behavior thresholds to identify abnormal behavior. The deviation pattern set refers to the set formed by classifying and organizing the abnormal behaviors in the fused dataset according to their characteristics and patterns after anomaly detection analysis. Each deviation pattern represents a specific type of abnormal behavior, including the characteristic description of the abnormal behavior, the time of occurrence, and the devices involved. The deviation pattern set provides clear targets and basis for subsequent threat analysis and processing.
[0052] In this step, the first step is to define the preset behavior thresholds for each data field in the fused dataset. For example, for the "device access request frequency" field, the preset behavior threshold might be set to "no more than 50 times per hour"; for the "data transfer rate" field, the preset behavior threshold might be set to "normal range 5-20 MB / s, peak value no more than 30 MB / s". Then, the fused dataset is iterated through, and the actual value of each data field is compared with the corresponding preset behavior threshold, filtering out data that exceeds the preset behavior threshold. Next, anomaly detection analysis is performed on the filtered data that exceeds the threshold. Finally, the abnormal behaviors identified through anomaly detection are categorized and organized according to their characteristics (such as high-frequency access, abnormal data transfer rate, excessively long response time, etc.) and patterns, generating a deviation pattern set.
[0053] For example, suppose that in the industrial control system of a chemical company, the fused dataset contains access request frequency data for device DEV003. During the filtering of the fused dataset, it was found that device DEV003's access request frequency reached 60 times per hour between 09:00 and 10:00 on August 29, 2025, exceeding the preset behavior threshold (e.g., the device access request frequency should not exceed 30 times per hour). Therefore, this data was filtered out through anomaly detection. Simultaneously, analysis of other fields in the fused dataset revealed that during the period of high access request frequency, the requested data was mostly core production process parameter data, and the response time for some requests reached 5 seconds, exceeding the preset behavior threshold (e.g., the response time should not exceed 2 seconds), further indicating that the device's behavior was abnormal. Based on the above analysis, the "high-frequency access to core production process parameter data and excessively long response times for some requests" of device DEV003 during 09:00 to 10:00 on August 29, 2025 was determined to be abnormal behavior and added as a deviation pattern to the deviation pattern set.
[0054] Furthermore, the fused dataset revealed that device DEV004 frequently sent data modification requests between 02:00 and 03:00 on August 29, 2025 (non-working hours). During this period, the device sent 15 data modification requests per hour, exceeding the preset behavior threshold (no more than 5 data modification requests per hour during non-working hours). Through anomaly detection analysis, combined with the device's historical operating data (historically, data modification requests during non-working hours were extremely rare, averaging no more than 2 times per month) and real-time monitoring data (which showed data interaction with unknown external IP addresses when sending data modification requests), it was determined that the device's "frequent sending of data modification requests during non-working hours and interaction with unknown external IPs" constituted another abnormal behavior. This was also added as a deviation pattern to the deviation pattern set, ultimately forming a deviation pattern set containing multiple deviation patterns.
[0055] In step S16, the degree of concealment of the abnormal behavior needs to be determined for the set of deviation patterns. The final threat classification result is obtained by prioritizing and sorting the patterns, including: For the set of deviation patterns, the degree of concealment of abnormal behavior is determined by matching it with preset concealment assessment rules through correlation analysis, and a set of threat classifications is generated. For the aforementioned threat classification set, priority ranking is performed by combining priority levels with real-time monitoring data to obtain the final threat classification result.
[0056] It should be noted that the association analysis method is based on a machine learning classifier, focusing on feature matching between deviant patterns and known malicious behavior patterns. It extracts core features from the two types of patterns (such as operation sequences, access targets, and data interaction methods) to construct feature vectors. The classifier is trained using historically labeled threat data (including feature vectors of known malicious behavior patterns and feature vectors of normal behavior data), enabling it to distinguish between normal and malicious behavior features. (The classifier can employ Support Vector Machine (SVM) or Random Forest.) Common classification algorithms such as Forest are used (trained with historical labeled data). The feature vectors of the deviation patterns are input into the trained classifier. The classifier compares the cosine similarity between the feature vectors and the feature vectors of known malicious behavior patterns to accurately identify whether the deviation patterns have malicious attributes. The concealment assessment rules use IP proxy switching frequency and request anomaly as the core scoring dimensions. The higher the IP proxy switching frequency and the more significant the request anomaly, the higher the concealment score, ensuring that the assessment results match the typical disguise characteristics of malicious behavior in industrial scenarios. Priority classification needs to combine the concealment score with the threat impact in real-time monitoring data (such as whether core data is involved) to achieve a scientific division of threat levels and meet the clear requirements of industrial data security for threat response priorities.
[0057] In this step, known malicious behavior patterns include features such as "switching to access the core database via high-frequency proxy IPs," "abnormally requesting device control permissions during non-working hours," and "forging requests to tamper with production parameters." Each malicious behavior pattern is labeled with core identification features (such as proxy IP switching frequency thresholds, request time ranges, and target data types). Next, feature extraction is performed on each deviation pattern in the deviation pattern set to obtain key information such as IP usage, request frequency, request time period, and access target. These are then compared one by one with known malicious behavior features using correlation analysis methods. For example, the feature extracted from a certain deviation pattern is "IP address switches proxies 8 times within 1 hour, requesting access to the production scheduling system during non-working hours (02:00-04:00)." This matches the feature "switching to access the core database via high-frequency proxy IPs" in the known malicious behavior pattern library, initially determining that this deviation pattern corresponds to potential malicious behavior.
[0058] Furthermore, deviation patterns identified as potentially malicious behaviors are scored according to the concealment assessment rules. For example, the IP proxy switching frequency scoring standard is as follows: 0 switches within 1 hour = 1 point (no disguise), 1-3 switches = 3 points (low disguise), 4-6 switches = 6 points (medium disguise), 7 switches or more = 10 points (high disguise); the request anomaly scoring standard is as follows: request frequency 1-1.5 times the preset behavior threshold = 2 points (minor anomaly), 1.6-2 times = 5 points (moderate anomaly), more than 2 times = 10 points (serious anomaly), requests outside working hours add 3 points, and accessing unauthorized target data adds 5 points. The IP proxy switching frequency score and the request anomaly score are added to obtain the total concealment score. A total score of 1-5 points is considered low concealment, 6-12 points is considered medium concealment, and 13-20 points is considered high concealment; the scoring standard is obtained by calculating the average value corresponding to historical data.
[0059] For example, the above-mentioned deviation pattern of "switching proxies 8 times in 1 hour and accessing the core system during non-working hours" scores 10 points for IP proxy switching frequency and 8 points for request abnormality due to "non-working hours (3 points) and accessing unauthorized core systems (5 points)", for a total score of 18 points. It is judged as a high level of concealment, and a threat classification set labeled with categories such as "high concealment - malicious proxy access to the core system" and "medium concealment - unauthorized parameter modification" is generated.
[0060] In one implementation, a priority-based ranking system is also required to sort the threat categories. A comprehensive scoring system is constructed based on the total stealth score (weight 0.5), real-time impact (weight 0.3, 10 points for core data, 3 points for ordinary data), and urgency (weight 0.2, 10 points for ongoing threat, 3 points for stopped threat). A comprehensive score is calculated for each threat category. For example, the threat "High Stealth - Malicious Proxy Access to Core Systems" scores 18 points for stealth, 10 points for real-time impact, and 10 points for urgency, for a comprehensive score of 18×0.5+10×0.3+10×0.2=9+3+2=14 points, and is classified as high-risk. The threat "Medium Stealth - Unauthorized Modification of Parameters on Ordinary Devices" scores 9 points for stealth, 3 points for real-time impact, and 3 points for urgency, for a comprehensive score of 9×0.5+3×0.3+3×0.2=4.5+0.9+0.6=6 points, and is classified as medium-risk. Finally, the threats are sorted from highest to lowest based on their overall scores to form the final threat classification results; the weights are obtained through statistical analysis of historical data and can be determined or adjusted through conventional debugging in this field.
[0061] For example, the deviation pattern set in an industrial scenario includes two deviation patterns: "IP1 device switches proxies 10 times per hour, requesting access to unauthorized target data during off-peak hours" and "IP2 device switches proxies 2 times per hour, requesting to read ordinary production data twice the preset behavior threshold during working hours." Through correlation analysis, the deviation pattern of IP1 matches the known malicious behavior pattern of "high-frequency proxy, modification of control parameters during off-peak hours," while the deviation pattern of IP2 matches the known malicious behavior pattern of "low-frequency proxy, reading data exceeding the threshold." According to the concealment evaluation rules, IP1 scores 10 points for IP proxy switching frequency and 8 points for request abnormality due to "off-peak hours (3 points) and access to unauthorized target data (5 points)," for a total score of 18 points (high concealment). IP2 scores 3 points for IP proxy switching frequency and 10 points for request abnormality due to "exceeding the preset behavior threshold twice," for a total score of 13 points (high concealment).
[0062] Furthermore, based on the priority grading algorithm, the overall threat score for IP1 is 18×0.5+10×0.3+10×0.2=14 points (high risk), and the overall threat score for IP2 is 13×0.5+3×0.3+3×0.2=6.5+0.9+0.6=8 points (medium risk). The final threat classification result is that IP1 device is a high-risk behavior and IP2 device is a medium-risk behavior.
[0063] It is worth noting that the concealment assessment rules are manually set by those skilled in the art when managing the system based on the security requirements of industrial scenarios, historical threat data characteristics, and business priorities. In practice, they can be dynamically modified according to the production management and privacy protection needs of different industrial equipment. The weights and scores mentioned in the concealment assessment rules here are only examples for understanding purposes.
[0064] In step S17, based on the threat classification results, a dynamic instruction execution sequence needs to be generated through permission verification, and tamper detection needs to be performed to obtain updated access control rules, including: Based on the threat classification results, the basis for updating access control rules is determined by matching permission verification with real-time monitoring data, and a dynamic instruction execution sequence is generated. Based on the dynamic instruction execution sequence, hash verification is used to detect tampering of the access control rules and generate updated access control rules.
[0065] It should be noted that permission verification must be based on the preset permission system of industrial equipment to verify whether the device involved in the threat has the legitimate permission to operate the target, and to ensure that the dynamic instruction execution sequence conforms to the permission boundary; the hash verification method compares the hash value of the access control rule with the historically stored rule hash value to accurately identify whether the rule has been tampered with, and avoids the unauthorized modification of the rule from affecting the secure execution of the instruction.
[0066] In this step, core information is first extracted from the threat classification results. For example, a high-risk threat is "the on / off operation command of device A has been tampered with and changed to a restart operation." The key information extracted is "Device ID: Device A, Original operation type: On / off operation, Modified operation type: Restart operation, Execution time: 2025-08-28 02:00". Permission verification is initiated by retrieving the preset permission table for device A (set according to industrial system design, business requirements, and historical security rules). It is confirmed that device A only has "on / off operation" permission and not "restart operation" permission. Combined with real-time monitoring data (showing that the restart command initiated by device A at 02:00 has no permission approval record), the basis for updating the access control rules is determined to be "a new 'device operation command and permission binding verification' clause needs to be added to prohibit the execution of unauthorized operation commands." Based on this basis, a dynamic command execution sequence is generated, for example, "Device A is only allowed to execute on / off operations at 2025-08-28 02:00; before execution, it is necessary to verify whether the command operation type matches the device permission; if a mismatch between operation type and permission is detected, the command is immediately intercepted and the anomaly is recorded."
[0067] Furthermore, hash verification is employed to detect tampering in existing access control rules. Assuming existing rules include clauses such as "Device A can perform switch operations" and "Device operations during non-working hours (22:00-06:00) require secondary verification," the hash value of the existing rule is calculated using the SHA-256 algorithm as "abc123." This is compared with the original hash value "abc123" of the rule pre-stored in the blockchain node to confirm that the rule has not been tampered with. Based on the dynamic instruction execution sequence and tampering detection results, an updated set of access control rules is generated. New clauses include "Before the device executes an instruction, it must verify the consistency between the operation type and the device's permissions using a permission verification algorithm; if inconsistent, the instruction is intercepted," and "Record the operation type and permission verification results for each instruction execution, generate an execution log, and store it in the blockchain," ensuring that the rules can address threats such as "instruction type tampering." The blockchain nodes are deployed in a trusted network environment, and node identities must be authenticated by a CA certificate to prevent unauthorized nodes from accessing the network. The system periodically compares the hash value of the blockchain log with the offline stored baseline value to detect whether collusive tampering has occurred.
[0068] For example, regarding the threat classification result of "Device B's temperature adjustment command being tampered with into a pressure adjustment command", after extracting key information, permission verification is initiated. It is found that Device B lacks pressure adjustment permissions, and the update basis is determined to be "strengthening the binding verification between command operation type and device permissions". A dynamic command execution sequence is generated as follows: "Device B is only allowed to execute temperature adjustment commands; before execution, the command operation type field is verified, and if it is pressure adjustment, it is blocked." After performing SHA-256 hash verification on the existing rules and confirming that they have not been tampered with, the updated rules add a "Device B operation command type whitelist (temperature adjustment only)" clause, completing the generation of the updated access control rules.
[0069] In step S18, the dynamic instruction execution sequence needs to be processed using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence, including: Based on the updated access control rules, the dynamic instruction execution sequence is processed through an encrypted transmission channel, and symmetric encryption is used to generate encrypted instruction sequence data packets. If no exception is triggered when the encrypted instruction sequence data packet is transmitted through the channel, the encrypted instruction sequence data packet is decrypted and parsed according to the preset parsing rules to obtain the secure instruction sequence.
[0070] It should be noted that the abnormal triggering conditions of the encrypted transmission channel need to be preset (such as latency threshold and packet loss rate threshold) to avoid data corruption or delay during transmission affecting instruction execution; the preset parsing rules are set according to the industrial instruction format, access control rules and data fusion requirements, and are used to parse encrypted data packets to ensure the integrity and compliance of instructions.
[0071] In this step, the encrypted transmission requirements are first clarified according to the updated access control rules. For example, "Dynamic instruction execution sequences must be transmitted through an encrypted transmission channel, using AES-256 symmetric encryption, with a transmission delay threshold not exceeding 100 milliseconds and a packet loss rate not exceeding 1%" (the thresholds are set by industry standards for the real-time requirements of industrial networks or determined through conventional network performance tests in this field). Taking the dynamic instruction execution sequence "Device A performs a switching operation at 02:00 on 2025-08-28" as an example, it is encrypted using the AES-256 symmetric encryption algorithm. Using a pre-shared key between the sender and receiver, the instruction sequence is converted into a binary encrypted data stream, generating an encrypted instruction sequence data packet. The data packet contains the encrypted instruction content, the device A identifier, and the 2025-08-28 02:00 timestamp.
[0072] The encrypted instruction sequence data packet is sent through an encrypted transmission channel, with the channel status monitored in real time during transmission. If the data packet transmission delay is 80 milliseconds (below the 100 millisecond threshold), the packet loss rate is 0%, and no anomaly is triggered, the receiving end uses the pre-shared key to decrypt the data packet using AES-256, recovering the original instruction sequence binary data stream. Based on the preset parsing rules of the secure execution path, the device ID (device A), execution time (2025-08-28 02:00), and operation type (switch operation) are extracted from the decrypted data stream. The instruction sequence is verified to be consistent with the updated access control rule that "device A is only allowed to perform switch operations," thus confirming it as a secure instruction sequence.
[0073] If the data packet delay reaches 120 milliseconds during transmission (triggering a delay exception), the transmission is immediately interrupted. The sending end regenerates a new data packet using AES-256 encryption and retransmits it through the encrypted transmission channel until the data packet arrives at the receiving end within 100 milliseconds, ensuring that the instruction transmission meets security requirements.
[0074] For example, for the dynamic instruction execution sequence "Device B performs a temperature adjustment operation (target temperature 85℃) at 10:30 on 2025-08-29", after generating a data packet using AES-256 encryption, it is transmitted through the channel. The monitoring shows a delay of 75 milliseconds and no packet loss. After the receiving end decrypts and parses the data, it verifies that the operation type (temperature adjustment) is consistent with the "Device B operation instruction whitelist" in the update rules, thus obtaining a secure instruction sequence. If the parsing finds that the operation type has been tampered with and changed to pressure adjustment, it is determined that it does not conform to the rules and is rejected as a secure instruction sequence.
[0075] Furthermore, in one implementation, after step S18, the following is also required: Based on the secure instruction sequence, a historical chain is constructed to compare the secure instruction sequence with pre-established historical chain data to generate an execution path record.
[0076] The execution path record is compared with the pre-stored historical data using hash verification to verify the tampering detection results.
[0077] It should be noted that the pre-established historical chain data stores the legitimate instruction execution records (such as device ID, operation type, execution time, and hash value) from a certain period of time in the past, providing a reliable benchmark for the comparison of the current instruction sequence; the execution path record must include a secure instruction sequence, authorization verification results, and encrypted transmission information, comprehensively reflecting the entire instruction execution process; the hash verification algorithm (such as SHA-256) for closed-loop verification must be consistent with the hash algorithm of the historical chain data to ensure the accuracy of the comparison results and verify that the execution path record has not been tampered with.
[0078] In this step, pre-established historical chain data is first extracted from the blockchain nodes. Historical records related to secure instruction sequences are then filtered out. For example, if the secure instruction sequence is "Device A performs a switch operation at 02:00 on 2025-08-28", then the historical chain execution records of Device A between 01:00 and 03:00 on 2025-08-28 (such as the switch operation record at 01:00) are filtered. The secure instruction sequence is compared with the historical records to analyze the consistency of execution time (02:00 is within a reasonable time period) and operation type (the switch operation is consistent with the historical operation). An execution path record is then generated, which includes "Device A, switch operation, 02:00 on 2025-08-28, AES-256 encryption, authorization verification passed, transmission delay 80 milliseconds".
[0079] Next, the hash value of the execution path record is calculated using the SHA-256 hash algorithm as "def456". The hash values of similar execution path records for device A are extracted from historical chain data (e.g., the hash value of the 01:00 execution record is "def456"), and the two are compared. If the hash values match, it indicates that the execution path record has not been tampered with, and the previous tampering detection result is valid. If the hash values do not match (e.g., the current hash value is "ghi789"), it is determined that the execution path record may have been tampered with. The system immediately triggers an alarm, suspends the execution of subsequent instructions from device A, and notifies the administrator to investigate the cause of the tampering.
[0080] For example, a secure instruction sequence is "Device B performs a temperature adjustment operation (85℃) at 10:30 on 2025-08-29". This is compared with three temperature adjustment records of Device B in the historical chain between 10:00 and 10:29 to confirm that the operation type and execution time are consistent, and an execution path record is generated. The SHA-256 hash value of this record is calculated as "jkl123", and compared with the historical hash value "jkl123", they match, verifying the effectiveness of the tampering detection result. If a hash value difference is found in any comparison, the system triggers an alarm and suspends the operation of Device B. Upon investigation, it is found that the temperature parameter in the execution path record has been tampered with to 95℃, thus promptly blocking the execution of abnormal instructions.
[0081] In summary, this invention discloses an access control method for industrial data security, comprising: acquiring real-time access requests and permission change data of industrial equipment; constructing an immutable record of instruction sequence logs using blockchain based on the real-time access requests and permission change data to obtain a historical chain construction result under an encrypted protection mechanism; acquiring access pattern characteristics in a high-concurrency compatible environment based on the historical chain construction result; determining a legitimate instruction sequence if the access pattern characteristics match a preset dynamic demand change threshold; acquiring equipment log data and fusing it with a dynamic data stream based on the legitimate instruction sequence to generate a fused dataset; comparing and analyzing the fused dataset with data exceeding a preset behavior threshold through anomaly detection to obtain a deviation pattern set; judging the concealment degree of abnormal behavior for the deviation pattern set and sorting it by priority to obtain a final threat classification result; generating a dynamic instruction execution sequence through permission verification based on the threat classification result and performing tamper detection to obtain updated access control rules; and processing the dynamic instruction execution sequence using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence. This invention constructs an immutable record of instruction sequence logs using blockchain, and combines symmetric encryption and digital signatures to generate an encrypted historical chain, solving the problem of traditional logs being easily tampered with. This ensures the traceability of real-time access requests and permission changes for industrial equipment, providing reliable data support for subsequent threat tracing. For high-concurrency industrial environments, this invention determines legitimate instruction sequences by analyzing access pattern characteristics and matching them with preset dynamic demand change thresholds. It integrates real-time monitoring data to optimize the abnormal behavior detection process. Compared to static permission management methods, it can more accurately capture potential threats and improve the security and compatibility of instruction execution in dynamic environments. Furthermore, this invention handles access log deviations through an anomaly detection model, classifies threats based on concealment assessment rules, dynamically updates access control rules, and uses encrypted transmission channels to process instruction sequences. Simultaneously, it backtracks the historical chain to verify tampering detection results, forming a complete "detection-response-verification" protection chain. This effectively enhances the ability to respond to concealed tampering threats and ensures the security of the entire process of industrial data access and instruction execution.
[0082] Reference Figure 2 The second embodiment of the present invention provides an access control system for industrial data security, comprising: The data acquisition module acquires real-time access requests and permission change data from industrial equipment. The chain-building encryption module, based on the real-time access requests and permission change data, uses the blockchain to build an immutable record of the instruction sequence log, and obtains the historical chain-building result under the encryption protection mechanism. The legality determination module obtains access pattern characteristics in a high-concurrency compatible environment based on the historical chain construction results. If the access pattern characteristics match a preset dynamic demand change threshold, then a legal instruction sequence is determined. The data fusion module, based on the legal instruction sequence, acquires device log data and fuses it with the dynamic data stream to generate a fused dataset; The anomaly detection module, if there is data in the fused dataset that exceeds a preset behavior threshold, performs comparative analysis on the fused dataset through anomaly detection to obtain a set of deviation patterns; The threat classification module assesses the degree of concealment of abnormal behavior based on the set of deviation patterns, and obtains the final threat classification result by prioritizing and sorting the patterns. The rule update module generates a dynamic instruction execution sequence based on the threat classification results through permission verification, performs tamper detection, and obtains updated access control rules. The encrypted execution module processes the dynamic instruction execution sequence using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence.
[0083] It should be noted that the industrial data security access control system provided in this embodiment of the invention is used to execute all the process steps of the industrial data security access control method in the above embodiment. The working principles and beneficial effects of the two are one-to-one, so they will not be described again.
[0084] It should be noted that the system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the system embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0085] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. An access control method for industrial data security, characterized in that, include: Obtain real-time access requests and permission change data for industrial equipment; Based on the real-time access requests and permission change data, an immutable record of the instruction sequence log is constructed using blockchain to obtain the historical chain construction result under the encryption protection mechanism; Based on the historical chain construction results, access pattern characteristics in a high-concurrency compatible environment are obtained. If the access pattern characteristics match a preset dynamic demand change threshold, a legal instruction sequence is determined. Based on the legal instruction sequence, device log data is acquired and fused with dynamic data stream to generate a fused dataset. If there is data in the fused dataset that exceeds a preset behavior threshold, then the fused dataset is compared and analyzed through anomaly detection to obtain a set of deviation patterns. For the set of deviation patterns, the degree of concealment of abnormal behavior is judged, and the final threat classification result is obtained by prioritizing and sorting them. Based on the threat classification results, a dynamic instruction execution sequence is generated through permission verification, and tamper detection is performed to obtain updated access control rules; Based on the updated access control rules, the dynamic instruction execution sequence is processed using an encrypted transmission channel to obtain a secure instruction sequence; The step of judging the concealment level of abnormal behavior for the set of deviation patterns, and obtaining the final threat classification result by prioritizing and sorting them, includes: For the set of deviation patterns, the degree of concealment of abnormal behavior is determined by matching it with preset concealment assessment rules through correlation analysis, and a set of threat classifications is generated. For the aforementioned threat classification set, priority ranking is performed by combining priority levels with real-time monitoring data to obtain the final threat classification result; The step of generating a dynamic instruction execution sequence based on the threat classification result through permission verification, performing tamper detection, and obtaining updated access control rules includes: Based on the threat classification results, the basis for updating access control rules is determined by matching permission verification with real-time monitoring data, and a dynamic instruction execution sequence is generated. Based on the dynamic instruction execution sequence, hash verification is used to detect tampering of the access control rules and generate updated access control rules.
2. The access control method for industrial data security according to claim 1, characterized in that, The step of constructing an immutable record of the instruction sequence log using blockchain based on the real-time access requests and permission change data, and obtaining the historical chain construction result under the encryption protection mechanism, includes: Determine whether the real-time access request and permission change data contain hidden tampering features. If they do, mark them as abnormal data to obtain the marked dataset. Based on the labeled dataset, a blockchain is used to generate an instruction sequence log; A unique data packet hash value is generated for each instruction sequence in the instruction sequence log, and stored in the blockchain node in combination with the timestamp and device identifier to generate an immutable log record; The immutable log record is symmetrically encrypted, and a digital signature is generated by combining it with the private key. The digital signature is then verified to match the preset public key. If they match, the encrypted log record is determined. The encrypted log records are linked in chronological order using a blockchain chain structure, so that the hash value of each block is associated with the previous block, resulting in a historical chain construction result under an encrypted protection mechanism.
3. The access control method for industrial data security according to claim 1, characterized in that, Based on the historical chain construction results, access pattern characteristics in a high-concurrency compatible environment are obtained. If the access pattern characteristics match a preset dynamic demand change threshold, a legal instruction sequence is determined, including: Based on the historical chain construction results, real-time monitoring data is obtained from a high-concurrency compatible environment; Based on the real-time monitoring data, combined with device identification information and timestamp records, a dataset containing access pattern characteristics is generated; If the dataset containing access pattern features matches a preset dynamic demand change threshold, a valid instruction sequence is generated through logical judgment.
4. The access control method for industrial data security according to claim 1, characterized in that, The process of acquiring device log data based on the legal instruction sequence and fusing it with dynamic data streams to generate a fused dataset includes: Obtain the dynamic data stream during the execution of the legal instruction sequence; Device log data is obtained from multiple data sources, and the device log data is standardized using a pre-established instruction sequence to generate a device log dataset in a unified format. The device log dataset is fused with the dynamic data stream to generate a fused dataset.
5. The access control method for industrial data security according to claim 1, characterized in that, The step of processing the dynamic instruction execution sequence using an encrypted transmission channel based on the updated access control rules to obtain a secure instruction sequence includes: Based on the updated access control rules, the dynamic instruction execution sequence is processed through an encrypted transmission channel, and symmetric encryption is used to generate encrypted instruction sequence data packets. If no exception is triggered when the encrypted instruction sequence data packet is transmitted through the channel, the encrypted instruction sequence data packet is decrypted and parsed according to the preset parsing rules to obtain the secure instruction sequence.
6. The access control method for industrial data security according to claim 1, characterized in that, After processing the dynamic instruction execution sequence using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence, the method further includes: Based on the secure instruction sequence, a historical chain is constructed to compare the secure instruction sequence with pre-established historical chain data to generate an execution path record; The execution path record is compared with the pre-stored historical data using hash verification to verify the tampering detection results.
7. An industrial data security access control system, characterized in that, For implementing the method as described in any one of claims 1-6, comprising: The data acquisition module acquires real-time access requests and permission change data from industrial equipment. The chain-building encryption module, based on the real-time access requests and permission change data, uses the blockchain to build an immutable record of the instruction sequence log, and obtains the historical chain-building result under the encryption protection mechanism. The legality determination module obtains access pattern characteristics in a high-concurrency compatible environment based on the historical chain construction results. If the access pattern characteristics match a preset dynamic demand change threshold, then a legal instruction sequence is determined. The data fusion module, based on the legal instruction sequence, acquires device log data and fuses it with the dynamic data stream to generate a fused dataset; The anomaly detection module, if there is data in the fused dataset that exceeds a preset behavior threshold, performs comparative analysis on the fused dataset through anomaly detection to obtain a set of deviation patterns; The threat classification module assesses the degree of concealment of abnormal behavior based on the set of deviation patterns, and obtains the final threat classification result by prioritizing and sorting the patterns. The rule update module generates a dynamic instruction execution sequence based on the threat classification results through permission verification, performs tamper detection, and obtains updated access control rules. The encrypted execution module processes the dynamic instruction execution sequence using an encrypted transmission channel according to the updated access control rules to obtain a secure instruction sequence.
Citation Information
Patent Citations
Network security protection method and system based on information fusion
CN120378214A
Data security encryption transmission and access control method and system based on block chain
CN120455103A