Industrial internet data security access method based on cloud edge collaboration

By collecting data in real time through edge security control devices and generating operating condition classification labels, combined with cloud authentication templates, the problems of imprecise access control and insufficient emergency response in the industrial internet are solved, and dynamic and secure data access control is achieved.

CN121509056AInactive Publication Date: 2026-02-10CHONGQING XINYIYUAN INTELLIGENT TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511838588.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-08
Publication Date
2026-02-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing industrial internet architecture lacks semantic tagging of edge business when production and environmental protection data are transmitted in a mixed manner, which makes it impossible to achieve fine-grained access control. Identity authentication entry points are scattered and audit logs are not easy to form unified credentials. Traditional strategies cannot perceive changes in edge operating conditions, resulting in the inability to dynamically adjust permissions, which affects data security and emergency response timeliness.

Method used

By collecting multi-dimensional data in real time through edge security control devices, generating hierarchical labels using a working condition quantification model, pre-building multi-granularity views, and combining them with a unified cloud authentication template, working condition-aware access credentials are generated, and dynamic permission adjustments are performed in real time when risks change.

Benefits of technology

It achieves fine-grained access control with on-demand authorization, unified identity authentication and complete audit logs, and can dynamically adjust permissions in response to changes in working conditions at the millisecond level, ensuring data security boundaries and emergency response timeliness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509056A_ABST
    Figure CN121509056A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of industrial internet security access, and discloses an industrial internet data security access method based on cloud-edge collaboration, which comprises the following steps: step 1, edge security control equipment acquires multi-dimensional original data of field production and environment in real time, analyzes the multi-dimensional original data by using a built-in working condition quantification model, and stores the analyzed multi-dimensional original data; calculating and generating a working condition grading label representing the current field state; step 2, the edge security control device pre-constructs data views with different data granularities for the multi-dimensional original data in the local storage space; edge multi-dimensional data collection and working condition semantic quantification are adopted, local multi-granularity view pre-construction is combined, the effect of authorizing views on demand for different function subjects is achieved, and compared with the scheme that data lacks edge business semantic marking in the prior art, the problem of mixed transmission of production and environmental protection data is solved; and core process parameters are not easy to shield effectively when supervision data are opened.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of secure access technology for the industrial internet, specifically a method for secure access to industrial internet data based on cloud-edge collaboration. Background Technology

[0002] The deep integration of new-generation information technology with industrial systems has made the Industrial Internet a core driving force for new industrialization and industrial upgrading. Data from core production processes such as industrial control systems, monitoring and data acquisition systems, and manufacturing execution systems are collected, aggregated, and transmitted to the cloud for big data analysis through the Industrial Internet of Things (IIoT) architecture to support remote operation and maintenance, quality optimization, and intelligent decision-making. While this transformation brings enormous production benefits, it also introduces unprecedented data security challenges.

[0003] Existing industrial internet architectures, especially in complex process industries and discrete manufacturing environments, face multiple security challenges:

[0004] The existing industrial internet architecture involves the mixed transmission of production and environmental protection data and lacks semantic tagging of edge business, which makes it impossible to achieve refined access control based on the function of the access subject. When necessary regulatory data is opened, it is not easy to effectively shield core process parameters, which poses a security risk of leakage of production secrets.

[0005] The independent construction of heterogeneous systems leads to the fragmentation of identity authentication entry points and the lack of a unified cloud aggregation mechanism. External personnel need to apply for accounts across systems to query data, and the scattered storage of audit logs makes it difficult to form unified credentials, which cannot meet the compliance requirements of full-link traceability of access behavior under the premise of protecting privacy.

[0006] Traditional static strategies cannot detect changes in edge conditions, resulting in the inability to automatically trigger dynamic adjustments of permissions in sudden emergencies. Furthermore, relying solely on cloud-based policies is susceptible to network latency and cannot take effect immediately, making it difficult to balance data security boundaries with the timeliness of critical data retrieval in emergency scenarios.

[0007] To address the aforementioned issues, this invention proposes a cloud-edge collaborative method for secure data access in the industrial internet. This method achieves condition-driven, refined, and adaptive security control of data access through condition-aware quantification, multi-granularity view pre-construction, and dynamic permission tightening. Summary of the Invention

[0008] To address the shortcomings of existing technologies, this invention provides a cloud-edge collaborative method for secure access to industrial internet data, thereby resolving the problems mentioned in the background section.

[0009] To achieve the above objectives, the present invention provides the following technical solution: a method for secure access to industrial internet data based on cloud-edge collaboration, comprising:

[0010] Step 1: The edge security control device collects multi-dimensional raw data of on-site production and environment in real time, and uses the built-in working condition quantification model to analyze the multi-dimensional raw data and calculate and generate working condition classification labels that represent the current on-site status.

[0011] Step 2: The edge security control device pre-builds data views with different data granularities for multidimensional raw data in the local storage space, and establishes a mapping relationship between the data views and different sensitivity levels;

[0012] Step 3: The edge security control device receives the abstract access rule template issued by the cloud management platform, injects the real-time working condition classification label as a variable into the abstract access rule template for local instantiation calculation, and generates working condition-aware access credentials.

[0013] Step four: During the process of establishing a data access session using the working condition awareness access credentials on the external terminal, the edge security control device continuously monitors the changes in the value of the working condition classification label, and performs dynamic permission adjustment on the current data access session when the working condition classification label meets the preset risk threshold conditions.

[0014] Preferably, step one further includes:

[0015] Sub-step The edge security control device collects multi-dimensional raw data from the site in real time and performs preprocessing and feature extraction on the raw data. The edge security control device also collects real-time operating parameters from the on-site production control system, security monitoring system, and environmental monitoring system via an industrial protocol adapter. Edge security control equipment collects real-time operating parameters. Standardization preprocessing is performed to obtain a normalized feature vector set. ;

[0016] Sub-step The edge security control device utilizes a built-in operating condition quantization model, combined with the normalized feature vector set. and preset risk weight coefficients The on-site risk quantification score was calculated. The aforementioned risk quantification score The calculation uses the following weighted cumulative formula:

[0017] ,

[0018] in, To quantify the real-time risk score for on-site working conditions, The set of feature vectors after normalization The number of environmental parameters in the middle, For feature vector set The Middle Normalized values ​​of environmental parameters; For the first Risk weight coefficients corresponding to each environmental parameter; This represents a discrete numerical value indicating the current maintenance status of the equipment or operation. To maintain the weight coefficients corresponding to the states, Normalization factor;

[0019] Sub-step The edge security control device quantifies the risk score. With the preset set of working condition classification thresholds Comparisons are made to determine and generate condition classification labels that characterize the current field status. The set of thresholds for the classification of working conditions Define risk level ranges, including safe state, early warning state, and high-risk state; the edge safety control device determines the operating condition classification label according to the following condition judgment rules. :

[0020] like < safe state,

[0021] like ≤ < Alert status,

[0022] like ≥ High-risk status

[0023] in, The risk score threshold for transitioning from a safe state to a warning state. This is the risk score threshold for transitioning from a warning state to a high-risk state;

[0024] The working condition classification label As a dynamic parameter for instantiating access credentials.

[0025] Preferably, step two further includes:

[0026] Sub-step The edge security control device uses a preset data sensitivity classification table to analyze real-time operating parameters. Perform field sensitivity identification and labeling; the data sensitivity classification table defines the real-time operating parameters. Confidentiality level of each field The edge security control device monitors the real-time operating parameters. Data fields in Assign the corresponding security level ,in, This is the index number of the data field;

[0027] Sub-step The edge security control device uses the data sensitivity classification table to define and store views to construct a rule set. The view constructs a rule set. Specify the highest confidentiality level of the data fields that can be included in different types of data views. The view construction rule set With data view type The following mapping relationship is satisfied:

[0028] ,

[0029] in, For the first Various data view types, including but not limited to full pivot views, anonymized summary views, and publicly published views; For the first The highest allowed confidentiality level of the data fields that a data view type can include, used to filter data fields;

[0030] Sub-step The edge security control device constructs a rule set based on the view. Regarding the real-time operating parameters Pre-generated and stored virtual data views at multiple granularities The virtual data view Any data view in The generated data meets the following field filtering criteria:

[0031] ≤ ,

[0032] The virtual data view Any data view in A logical connection is established with the original data fields through mapping rules, and an independent view interface address is provided to the outside world. The edge security control device will use the view interface address. As part of the condition-aware access credentials.

[0033] Preferably, step three further includes:

[0034] Sub-step The edge security control device receives the abstract access rule template issued by the cloud management platform. And verify the identity of the external terminal's access request. ;

[0035] The abstract access rule template Define the access subject role for a general logical structure. Classification labels for specific working conditions Within a given range, the types of view interfaces that are allowed to be accessed. The mapping relationship; the identity of the access request from the edge security control device to the external terminal. Decryption and Roles Matching to determine the applicable abstract access rule template. ;

[0036] Sub-step Edge security control devices will classify and label operating conditions in real time. Substituted into the abstract access rule template as a dynamic parameter In this process, localized matching calculations are performed to determine the target data view type. The localized matching calculation satisfies the following conditional judgment logic:

[0037] ,

[0038] in, External terminal roles and abstract access rule templates The matching results of the preset roles, For abstract access rule templates The first defined in A range of allowed access to work condition classification labels. Classification of working conditions and labeling range The type of target data view that external terminals are authorized to access;

[0039] Edge security control devices are based on a defined target data view type Get the corresponding view interface address ;

[0040] Sub-step The edge security control device is based on the view interface address. Generate encrypted condition-aware access credentials The working condition awareness access credential The generation uses either symmetric or asymmetric encryption algorithms. It includes the following authorization information:

[0041] ,

[0042] in, Access credentials for operational condition awareness. For the identification of external terminals, This refers to the view interface address that external terminals are authorized to access. The validity period of the voucher, A snapshot of the working condition classification label at the time the voucher was generated;

[0043] The edge security control device will use the operational condition awareness access credential. It is sent to the external terminal to establish a data access session.

[0044] Preferably, step four further includes:

[0045] Sub-step The edge security control device receives access credentials from an external terminal using operational condition awareness. After the data access session is established, continuous monitoring will be performed at the preset frequency. Real-time updates of current operating condition classification labels ;

[0046] The edge security control device is also accessed by the operational condition awareness credential. Parse the working condition classification label when the voucher is generated. and the view interface address locked in the current session. The monitoring frequency It must meet the real-time requirements of industrial sites to ensure a rapid response to sudden changes in operating conditions;

[0047] Sub-step Edge security control devices are based on real-time operating condition classification tags. Operating condition classification label when generating vouchers Perform risk trend analysis and determine whether the preset dynamic permission adjustment conditions are met. ;

[0048] The risk trend analysis uses the following discrete rate of change. calculate:

[0049] ,

[0050] in, To correspond to the real-time operating condition classification label Risk quantification score; To correspond to the working condition classification label Risk quantification score, This is the time interval from the time the voucher was generated to the current time.

[0051] The dynamic permission adjustment conditions for:

[0052] ≥ ,

[0053] In the formula, The current working condition classification label level is higher than the working condition classification label level when the voucher was generated. The preset risk score change rate threshold is used to determine whether the risk deteriorates rapidly in a short period of time;

[0054] Sub-step When the dynamic permission adjustment conditions When true, the edge security control device performs an adaptive permission tightening operation on the current data access session. The adaptive permission tightening operation include:

[0055] Access Degradation: Edge security control devices, based on the current... Forced by pre-built virtual data views Choose an alternative view interface address with a high security level and low data granularity. The edge security control device sends a redirection command to the data stream channel of the external terminal, switching the data source to the alternative view interface address. ;

[0056] Connection failure: If the real-time operating condition classification label is broken. Upon reaching the highest risk level, the edge security control device directly injects a termination signal into the connection of the external terminal and clears the operational condition awareness access credential. The state is valid locally.

[0057] Preferably, the industrial internet data security access method includes: during the data access session, the edge security control device generates audit logs for each data read or write operation of the external terminal. The audit log The operating condition classification label is forcibly bound to the time when the record read operation occurs. The type of data view being accessed External terminal identification and the type of the operation behavior The edge security control device periodically sends the audit logs. The data is hashed and encrypted before being uploaded to a cloud management platform for long-term storage and tamper-proof traceability.

[0058] Preferably, the generation of the de-identified summary view includes a de-identification operation. The desensitization operation The following function is used to implement this:

[0059] ,

[0060] in, For real-time running parameters High-security level raw data fields ; For data fields Preset desensitization rules include data generalization, differential privacy addition, or displacement masking; These are the statistical or summary values ​​after the data has been anonymized, used to replace the corresponding original data fields in the anonymized summary view.

[0061] Preferably, the abstract access rule template The cloud management platform performs unified configuration and version management based on a preset user role and data sensitivity level matrix; upon receiving the working condition classification label, the cloud management platform... When the trend changes are reported, the abstract access rule template is dynamically adjusted. Risk grading intervals and the corresponding view interface type The cloud management platform transmits the updated abstract access rule template through an encrypted channel. The application was deployed across the entire network, replacing the old templates stored in the edge security control devices. .

[0062] Preferably, the industrial internet data security access method includes an emergency takeover mechanism:

[0063] When the edge security control device detects a specific emergency alarm signal When this occurs, the edge security control device automatically triggers the emergency takeover mode; in the emergency takeover mode, the edge security control device does not rely on the abstract access rule template. Directly generate temporary high-privilege credentials pointing to the complete perspective view. The edge security control device will use the temporary high-privilege credential. The data is pushed to a pre-set emergency rescue terminal for real-time retrieval.

[0064] Preferably, the risk weight coefficient in the operating condition quantification model and the set of thresholds for work condition classification The settings support machine learning training and optimization based on historical safety incident records and real-time environmental change data;

[0065] The cloud management platform uses historical data to train and obtain optimized weight coefficients. and threshold set Furthermore, the model parameters are updated by sending them to the edge security control device via a security protocol, thereby improving the operational condition classification label. The accuracy and early warning capabilities.

[0066] This invention provides a method for secure data access in the industrial internet based on cloud-edge collaboration. It offers the following advantages:

[0067] 1. This invention adopts edge multidimensional data acquisition and working condition semantic quantification, combined with local multi-granularity view pre-construction, to achieve the effect of authorizing views on demand for different functional entities. Compared with the existing technology, which lacks edge business semantic labeling, this invention solves the shortcomings of mixed transmission of production and environmental protection data and the difficulty in effectively shielding core process parameters when opening up regulatory data.

[0068] 2. This invention adopts cloud-based unified authentication and policy template distribution, combined with end-to-end context auditing and credential on-chaining, to achieve a traceability effect of unified access subject identity and complete audit log environment context. Compared with the existing technology of heterogeneous systems being built independently and audit logs being stored in a decentralized manner, this invention solves the shortcomings of decentralized identity authentication entry points and the difficulty in forming unified credentials from audit logs, which cannot meet the requirements of end-to-end traceability.

[0069] 3. This invention adopts edge condition awareness and credential instantiation, combined with session-level dynamic monitoring and adaptive tightening, to achieve millisecond-level dynamic adjustment of permissions. Compared with the existing technology, which uses static policies that cannot detect changes in edge conditions and rely on cloud-based instructions, this invention solves the problem that permissions cannot be automatically triggered for dynamic adjustment in sudden emergency situations, and is not easy to balance data security boundaries and emergency timeliness. Attached Figure Description

[0070] Figure 1 This is a flowchart of the present invention. Detailed Implementation

[0071] To enable those skilled in the art to understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort should fall within the scope of protection of the present invention.

[0072] The present invention will now be described in detail with reference to the accompanying drawings:

[0073] Example:

[0074] Please see the appendix Figure 1 This invention provides a method for secure access to industrial internet data based on cloud-edge collaboration, comprising:

[0075] Step 1: The edge security control device collects multi-dimensional raw data of on-site production and environment in real time, and uses the built-in working condition quantification model to analyze the multi-dimensional raw data and calculate and generate working condition classification labels that represent the current on-site status.

[0076] Step 2: The edge security control device pre-builds data views with different data granularities for multidimensional raw data in the local storage space, and establishes a mapping relationship between the data views and different sensitivity levels;

[0077] Step 3: The edge security control device receives the abstract access rule template issued by the cloud management platform, injects the real-time working condition classification label as a variable into the abstract access rule template for local instantiation calculation, and generates working condition-aware access credentials.

[0078] Step four: During the process of establishing a data access session using the working condition awareness access credentials on the external terminal, the edge security control device continuously monitors the changes in the value of the working condition classification label, and performs dynamic permission adjustment on the current data access session when the working condition classification label meets the preset risk threshold conditions.

[0079] Step one further includes:

[0080] Sub-step The edge security control device collects multi-dimensional raw data from the field in real time and performs preprocessing and feature extraction on the raw data. Through an industrial protocol adapter, the edge security control device collects real-time operating parameters from the field production control system, security monitoring system, and environmental monitoring system. Edge security control equipment collects real-time operating parameters. Standardization preprocessing is performed to obtain a normalized feature vector set. ;

[0081] Sub-step Edge security control devices utilize a built-in operational condition quantification model, combined with a normalized feature vector set. and preset risk weight coefficients The on-site risk quantification score was calculated. Risk Quantification Score The calculation uses the following weighted cumulative formula:

[0082] ,

[0083] in, To quantify the real-time risk score for on-site working conditions, The set of feature vectors after normalization The number of environmental parameters in the middle, For feature vector set The Middle Normalized values ​​of environmental parameters; For the first Risk weight coefficients corresponding to each environmental parameter; This represents a discrete numerical value indicating the current maintenance status of the equipment or operation. To maintain the weight coefficients corresponding to the states, Normalization factor;

[0084] Sub-step Edge security control devices quantify and score risks. With the preset set of working condition classification thresholds Comparisons are made to determine and generate condition classification labels that characterize the current field status. ; set of thresholds for work condition classification Define risk level ranges, including safe state, early warning state, and high-risk state; edge safety control equipment determines its operating condition classification label according to the following judgment rules. :

[0085] like < safe state,

[0086] like ≤ < Alert status,

[0087] like ≥ High-risk status

[0088] in, The risk score threshold for transitioning from a safe state to a warning state. This is the risk score threshold for transitioning from a warning state to a high-risk state;

[0089] Operating condition classification label As a dynamic parameter for instantiating access credentials.

[0090] Step two further includes:

[0091] Sub-step The edge security control device uses a preset data sensitivity classification table to analyze real-time operating parameters. Perform field sensitivity identification and labeling; define real-time running parameters for the data sensitivity classification table. Confidentiality level of each field Edge security control equipment monitors real-time operating parameters. Data fields in Assign the corresponding security level ,in, This is the index number of the data field;

[0092] Sub-step Edge security control devices utilize data sensitivity classification tables to define and store views to construct rule sets. View building rule set Specify the highest confidentiality level of the data fields that can be included in different types of data views. View building rule set With data view type The following mapping relationship is satisfied:

[0093] ,

[0094] in, For the first Various data view types, including but not limited to full pivot views, anonymized summary views, and publicly published views; For the first The highest allowed confidentiality level of the data fields that a data view type can include, used to filter data fields;

[0095] Sub-step Edge security control devices build rule sets based on views. For real-time operating parameters Pre-generated and stored virtual data views at multiple granularities Virtual data view Any data view in The generated data meets the following field filtering criteria:

[0096] ≤ ,

[0097] Virtual Data View Any data view in A logical connection is established with the original data fields through mapping rules, and an independent view interface address is provided to the outside world. The edge security control device will use the view interface address. As part of the condition-aware access credentials.

[0098] Step three further includes:

[0099] Sub-step The edge security control device receives the abstract access rule template issued by the cloud management platform. And verify the identity of the external terminal's access request. ;

[0100] Abstract Access Rule Template Define the access subject role for a general logical structure. Classification labels for specific working conditions Within a given range, the types of view interfaces that are allowed to be accessed. The mapping relationship; the identity of the edge security control device's access request to the external terminal. Decryption and Roles Matching to determine the applicable abstract access rule template. ;

[0101] Sub-step Edge security control devices will classify and label operating conditions in real time. Substituted as a dynamic parameter into the abstract access rule template In this process, localized matching calculations are performed to determine the target data view type. The localized matching calculation meets the following condition determination logic:

[0102] ,

[0103] in, External terminal roles and abstract access rule templates The matching results of the preset roles, For abstract access rule templates The first defined in A range of allowed access to work condition classification labels. Classification of working conditions and labeling range The type of target data view that external terminals are authorized to access;

[0104] Edge security control devices are based on a defined target data view type Get the corresponding view interface address ;

[0105] Sub-step The edge security control device is based on the view interface address. Generate encrypted condition-aware access credentials Condition-aware access credentials The generation uses either symmetric or asymmetric encryption algorithms. It includes the following authorization information:

[0106] ,

[0107] in, Access credentials for operational condition awareness. For the identification of external terminals, This refers to the view interface address that external terminals are authorized to access. The validity period of the voucher, A snapshot of the working condition classification label at the time the voucher was generated;

[0108] Edge security control devices will use condition-aware access credentials Send to an external terminal to establish a data access session.

[0109] Step four further includes:

[0110] Sub-step The edge security control device receives access credentials from an external terminal using operational condition awareness. After the data access session is established, continuous monitoring will be performed at the preset frequency. Real-time updates of current operating condition classification labels ;

[0111] Edge security control devices also have access credentials based on operational conditions. Parse the working condition classification label when the voucher is generated. and the view interface address locked in the current session. Monitoring frequency It must meet the real-time requirements of industrial sites to ensure a rapid response to sudden changes in operating conditions;

[0112] Sub-step Edge security control devices are based on real-time operating condition classification tags. Operating condition classification label when generating vouchers Perform risk trend analysis and determine whether the preset dynamic permission adjustment conditions are met. ;

[0113] Risk trend analysis uses the following discrete rate of change. calculate:

[0114] ,

[0115] in, To correspond to the real-time operating condition classification label Risk quantification score; To correspond to the working condition classification label Risk quantification score, This is the time interval from the time the voucher was generated to the current time.

[0116] Dynamic permission adjustment conditions for:

[0117] ≥ ,

[0118] In the formula, The current working condition classification label level is higher than the working condition classification label level when the voucher was generated. The preset risk score change rate threshold is used to determine whether the risk deteriorates rapidly in a short period of time;

[0119] Sub-step When dynamic permission adjustment conditions When true, the edge security control device performs an adaptive permission tightening operation on the current data access session. Adaptive permission tightening operation include:

[0120] Access Degradation: Edge security control devices, based on the current... Forced by pre-built virtual data views Choose an alternative view interface address with a high security level and low data granularity. The edge security control device sends a redirection command to the data stream channel of the external terminal, switching the data source to an alternative view interface address. ;

[0121] Connection failure: If the real-time operating condition classification label is broken. Upon reaching the highest risk level, the edge security control device directly injects a termination signal into the connection to the external terminal and clears the condition-aware access credentials. The state is valid locally.

[0122] By collecting various raw operating parameters in real time, such as temperature, pressure, gas concentration, and equipment status, through edge security control devices, and using a built-in operating condition quantification model for weighted calculations, complex on-site environmental information can be transformed into risk quantification scores, generating clear operating condition classification labels. This ability to convert physical world operating conditions into digital security semantic labels provides dynamic and reliable input for access control policies, solving the problem of traditional security policies lacking real-time on-site context information, and laying the foundation for realizing operating condition-driven dynamic access control.

[0123] Edge security control devices use a pre-defined data sensitivity classification table to label the confidentiality levels of each field in real-time operating parameters, thereby pre-generating virtual data views at various granularities. These views strictly limit the data sets and granularity exposed externally through field filtering conditions, effectively isolating core process parameters from non-sensitive data. When accessed by external terminals, regardless of the on-site operating conditions, the external terminals access only the minimum necessary and least sensitive data through authorized view interface addresses, fundamentally preventing the risk of production secrets being leaked.

[0124] Edge security control devices receive a general abstract access rule template from the cloud and use defined real-time operational condition classification labels as core dynamic parameters to perform localized matching calculations. Local instantiation calculations fully utilize real-time operational condition data from the edge side to quickly determine the current operational condition and the authorized target data view type under the external terminal role. This generates encrypted operational condition-aware access credentials containing identity identifiers, view interface addresses, validity periods, and operational condition snapshots. This solves the latency problem of cloud-based policy distribution, ensures the real-time generation of credentials, and aggregates identity, permissions, resources, and environmental status into a unified credential, providing a secure entry point for external terminals to establish sessions.

[0125] After a data access session is established, the edge security control device continuously monitors the current operational condition classification label and performs trend analysis with the risk level at the time of credential generation. Once the real-time risk score change rate exceeds a preset threshold and the operational condition level deteriorates, the system immediately triggers adaptive permission tightening operations. Tightening operations include permission downgrading and connection termination. This mechanism ensures that permissions are no longer static but automatically tightened based on escalating on-site risks, effectively addressing data security risks in sudden emergencies and guaranteeing the dynamic adjustability and timeliness of data security boundaries.

[0126] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for secure data access in the industrial internet based on cloud-edge collaboration, characterized in that, include: Step 1: The edge security control device collects multi-dimensional raw data of on-site production and environment in real time, and uses the built-in working condition quantification model to analyze the multi-dimensional raw data and calculate and generate working condition classification labels that represent the current on-site status. Step 2: The edge security control device pre-builds data views with different data granularities for multidimensional raw data in the local storage space, and establishes a mapping relationship between the data views and different sensitivity levels; Step 3: The edge security control device receives the abstract access rule template issued by the cloud management platform, injects the real-time working condition classification label as a variable into the abstract access rule template for local instantiation calculation, and generates working condition-aware access credentials. Step four: During the process of establishing a data access session using the working condition awareness access credentials on the external terminal, the edge security control device continuously monitors the changes in the value of the working condition classification label, and performs dynamic permission adjustment on the current data access session when the working condition classification label meets the preset risk threshold conditions.

2. The industrial internet data security access method based on cloud-edge collaboration according to claim 1, characterized in that, Step one further includes: Sub-step The edge security control device collects multi-dimensional raw data from the site in real time and performs preprocessing and feature extraction on the raw data. The edge security control device also collects real-time operating parameters from the on-site production control system, security monitoring system, and environmental monitoring system via an industrial protocol adapter. Edge security control equipment collects real-time operating parameters. Standardization preprocessing is performed to obtain a normalized feature vector set. ; Sub-step The edge security control device utilizes a built-in operating condition quantization model, combined with the normalized feature vector set. and preset risk weight coefficients The on-site risk quantification score was calculated. The aforementioned risk quantification score The calculation uses the following weighted cumulative formula: , in, To quantify the real-time risk score for on-site working conditions, The set of feature vectors after normalization The number of environmental parameters in the middle, For feature vector set Middle Normalized values ​​of environmental parameters; For the first Risk weight coefficients corresponding to each environmental parameter; This represents a discrete numerical value indicating the current maintenance status of the equipment or operation. To maintain the weight coefficients corresponding to the states, Normalization factor; Sub-step The edge security control device quantifies the risk score. With the preset set of working condition classification thresholds Comparisons are made to determine and generate condition classification labels that characterize the current field status. The set of thresholds for the classification of working conditions Define risk level ranges, including safe state, early warning state, and high-risk state; the edge safety control device determines the operating condition classification label according to the following condition judgment rules. : like < safe state, like ≤ < Alert status, like ≥ High-risk status in, The risk score threshold for transitioning from a safe state to a warning state. This is the risk score threshold for transitioning from a warning state to a high-risk state; The working condition classification label As a dynamic parameter for instantiating access credentials.

3. The industrial internet data security access method based on cloud-edge collaboration according to claim 1, characterized in that, Step two further includes: Sub-step The edge security control device uses a preset data sensitivity classification table to analyze real-time operating parameters. Perform field sensitivity identification and labeling; the data sensitivity classification table defines the real-time operating parameters. Confidentiality level of each field The edge security control device monitors the real-time operating parameters. Data fields in Assign the corresponding security level ,in, This is the index number of the data field; Sub-step The edge security control device uses the data sensitivity classification table to define and store views to construct a rule set. The view constructs a rule set. Specify the highest confidentiality level of the data fields that can be included in different types of data views. The view construction rule set With data view type The following mapping relationship is satisfied: , in, For the first Various data view types, including but not limited to full pivot views, anonymized summary views, and publicly published views; For the first The highest allowed confidentiality level of the data fields that a data view type can include, used to filter data fields; Sub-step The edge security control device constructs a rule set based on the view. Regarding the real-time operating parameters Pre-generated and stored virtual data views at multiple granularities The virtual data view Any data view in The generated data meets the following field filtering conditions: ≤ , The virtual data view Any data view in A logical connection is established with the original data fields through mapping rules, and an independent view interface address is provided to the outside world. The edge security control device will use the view interface address. As part of the condition-aware access credentials.

4. The industrial internet data security access method based on cloud-edge collaboration according to claim 1, characterized in that, Step three further includes: Sub-step The edge security control device receives the abstract access rule template issued by the cloud management platform. And verify the identity of the external terminal's access request. ; The abstract access rule template Define the access subject role for a general logical structure. Classification labels for specific working conditions Within a given range, the types of view interfaces that are allowed to be accessed. The mapping relationship; the identity of the access request from the edge security control device to the external terminal. Decryption and Roles Matching to determine the applicable abstract access rule template. ; Sub-step Edge security control devices will classify and label operating conditions in real time. Substituted into the abstract access rule template as a dynamic parameter In this process, localized matching calculations are performed to determine the target data view type. The localized matching calculation satisfies the following conditional judgment logic: , in, External terminal roles and abstract access rule templates The matching results of the preset roles, For abstract access rule templates The first one defined in A range of allowed access to work condition classification labels. Classification of working conditions and labeling range The type of target data view that external terminals are authorized to access; Edge security control devices are based on a defined target data view type Get the corresponding view interface address ; Sub-step The edge security control device is based on the view interface address. Generate encrypted condition-aware access credentials The working condition awareness access credential The generation uses either symmetric or asymmetric encryption algorithms. It includes the following authorization information: , in, Access credentials for operational condition awareness. For the identification of external terminals, This refers to the view interface address that external terminals are authorized to access. The validity period of the voucher, A snapshot of the working condition classification label at the time the voucher was generated; The edge security control device will use the operational condition awareness access credential. It is sent to the external terminal to establish a data access session.

5. The industrial internet data security access method based on cloud-edge collaboration according to claim 1, characterized in that, Step four further includes: Sub-step The edge security control device receives access credentials from an external terminal using operational condition awareness. After the data access session is established, continuous monitoring will be performed at the preset frequency. Real-time updates of current operating condition classification labels ; The edge security control device is also accessed by the operational condition awareness credential. Parse the working condition classification label when the voucher is generated. and the view interface address locked in the current session. The monitoring frequency It must meet the real-time requirements of industrial sites to ensure a rapid response to sudden changes in operating conditions; Sub-step Edge security control devices are based on real-time operating condition classification tags. Operating condition classification label when the voucher is generated Perform risk trend analysis and determine whether the preset dynamic permission adjustment conditions are met. ; The risk trend analysis uses the following discrete rate of change. calculate: , in, To correspond to the real-time operating condition classification label Risk quantification score; To correspond to the working condition classification label Risk quantification score, This is the time interval from the time the voucher was generated to the current time. The dynamic permission adjustment conditions for: ≥ , In the formula, The current working condition classification label level is higher than the working condition classification label level when the voucher was generated. The preset risk score change rate threshold is used to determine whether the risk deteriorates rapidly in a short period of time; Sub-step When the dynamic permission adjustment conditions When true, the edge security control device performs an adaptive permission tightening operation on the current data access session. The adaptive permission tightening operation include: Access Degradation: Edge security control devices, based on the current... Forced by pre-built virtual data views Choose an alternative view interface address with a high security level and low data granularity. The edge security control device sends a redirection command to the data stream channel of the external terminal, switching the data source to the alternative view interface address. ; Connection failure: If the real-time operating condition classification label is broken. Upon reaching the highest risk level, the edge security control device directly injects a termination signal into the connection of the external terminal and clears the operational condition awareness access credential. The state is valid locally.

6. The industrial internet data security access method based on cloud-edge collaboration according to claim 1, characterized in that, The industrial internet data security access method includes: during the data access session, the edge security control device generates audit logs for each data read or write operation of the external terminal. The audit log The operating condition classification label is forcibly bound to the time when the record read operation occurs. The type of data view being accessed External terminal identification and the type of the operation behavior The edge security control device periodically sends the audit logs. The data is hashed and encrypted before being uploaded to a cloud management platform for long-term storage and tamper-proof traceability.

7. The industrial internet data security access method based on cloud-edge collaboration according to claim 3, characterized in that, The generation of the de-identified summary view includes de-identification operations. The desensitization operation The following function is used to implement this: , in, For real-time running parameters High-security level raw data fields ; For data fields Preset desensitization rules include data generalization, differential privacy addition, or displacement masking; These are the statistical or summary values ​​after the data has been anonymized, used to replace the corresponding original data fields in the anonymized summary view.

8. A method for secure access to industrial internet data based on cloud-edge collaboration according to claim 4, characterized in that, The abstract access rule template The cloud management platform performs unified configuration and version management based on a preset user role and data sensitivity level matrix; upon receiving the working condition classification label, the cloud management platform... When the trend changes are reported, the abstract access rule template is dynamically adjusted. Risk grading intervals and the corresponding view interface type ; The cloud management platform transmits the updated abstract access rule template through an encrypted channel. The application was deployed across the entire network, replacing the old templates stored in the edge security control devices. .

9. A method for secure access to industrial internet data based on cloud-edge collaboration according to claim 5, characterized in that, The industrial internet data security access method includes an emergency takeover mechanism: When the edge security control device detects a specific emergency alarm signal When this occurs, the edge security control device automatically triggers the emergency takeover mode; In the emergency takeover mode, the edge security control device does not depend on the abstract access rule template. Directly generate temporary high-privilege credentials pointing to the complete perspective view. The edge security control device will use the temporary high-privilege credential. The data is pushed to a pre-set emergency rescue terminal for real-time retrieval.

10. A method for secure access to industrial internet data based on cloud-edge collaboration according to claim 1, characterized in that, Risk weight coefficient in the operating condition quantification model and the set of thresholds for work condition classification The settings support machine learning training and optimization based on historical safety incident records and real-time environmental change data; The cloud management platform uses historical data to train and obtain optimized weight coefficients. and threshold set Furthermore, the model parameters are updated by sending them to the edge security control device via a security protocol, thereby improving the operational condition classification label. The accuracy and early warning capabilities.