An ai dynamic data security management method for industrial digital information collection
By extracting fields and aligning time benchmarks from industrial data, and combining industrial and process semantics to generate usage categories and restrictions, AI-powered dynamic strategy decision-making is used for field-level control. This solves the problem of generating differentiated control strategies in existing technologies and achieves dynamic protection of the legality and security of data use.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XIAMEN KUAIKUAI NETWORK TECH CO LTD
- Filing Date
- 2026-03-03
- Publication Date
- 2026-05-19
AI Technical Summary
Existing industrial data security management technologies are unable to flexibly adjust to dynamic business scenarios and human-computer interaction needs, and cannot automatically generate differentiated control strategies, resulting in a mismatch between security strategies and actual usage intentions.
By extracting fields and aligning them with time bases from the data output from industrial data source interfaces, a structured data package is generated. By combining industrial semantics and process semantics, a field item association path is constructed, and usage categories and usage restrictions are generated. AI dynamic strategy decision-making is used to generate a set of dynamic strategy actions, and field-level control and data flow control are performed through the strategy execution chain.
It enables precise determination of the purpose of industrial data fields, ensuring the legality, security and contextual consistency of data use, and dynamically matching the production line operation status and safety process requirements.
Smart Images

Figure CN121765754B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to an AI-based dynamic data security management method for industrial digital information acquisition. Background Technology
[0002] With the development of Industrial Internet and intelligent manufacturing technologies, the scale of digital information generated in industrial settings continues to grow, encompassing diverse and heterogeneous data sources such as equipment operating parameters, production process records, quality inspection data, and personnel operation logs. In industrial production environments, large amounts of data need to flow and be shared between different business processes, human-machine interaction methods are becoming increasingly diversified, and data collection and utilization scenarios are constantly expanding. To ensure production efficiency and business collaboration, industrial data is typically collected in real time through standardized interfaces and made accessible to upper-layer applications, forming a data service system for various purposes such as scheduling management, quality analysis, and equipment maintenance. In this process, industrial data acquisition technology is gradually evolving from simple data transmission models towards structured, semantic, and intelligent approaches. By parsing, encapsulating, and managing data fields, it improves data utilization efficiency and business support capabilities, becoming a crucial foundational technology for industrial digital transformation.
[0003] In existing industrial data security management technologies, data access control and security protection measures mostly rely on fixed rule configurations, making it difficult to flexibly adjust according to dynamic business scenarios and human-computer interaction needs. When industrial data flows in multi-purpose, multi-entity, and multi-network domain environments, traditional methods are insufficient in terms of fine-grained control at the field level, usage constraint management, and dynamic policy adaptation, easily leading to situations where security policies do not match actual usage intentions. Existing industrial data security management technologies have the problem of not being able to automatically generate differentiated control policies for different uses, and typically rely on manual configuration of access rules or static permission tables to manage data, in order to alleviate the contradiction between data security and business flexibility. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, this invention provides an AI-based dynamic data security management method for industrial digital information acquisition to solve the problem of difficulty in automatically generating differentiated control strategies for different uses.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0007] This invention provides an AI-driven dynamic data security management method for industrial digital information acquisition, comprising:
[0008] Perform field-level extraction and time-base alignment on the industrial data output from the industrial data source interface to generate a structured data package;
[0009] Based on the industrial semantics and process semantics mapped to the field items in the structured data packet, the purpose of the field items is determined to obtain the purpose category and purpose restriction. The structured data packet, purpose category and purpose restriction are then encapsulated to generate a purpose control data packet.
[0010] Based on the usage category and usage restrictions recorded in the usage control data package, a policy decision package is constructed, AI dynamic policy decision is executed on the policy decision package, a set of dynamic policy actions is output, and the set of dynamic policy actions is converted into a policy execution chain configuration package;
[0011] At the output end of the industrial data source interface, the policy execution chain configuration package is loaded according to the policy execution chain, and the purpose control data packet is input into the policy execution chain. Field-level control and data flow control are performed on the purpose control data packet to generate a controlled data flow and execution evidence package.
[0012] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the generation of the structured data packet specifically includes:
[0013] Receive industrial data from industrial data source interfaces and import it into the industrial raw data set;
[0014] In the raw industrial dataset, the industrial data is split into fields to form a set of field items consisting of multiple field items. Field identifiers are then added to the field items in the set of field items to form a field item mapping set.
[0015] Read the timestamps of each field item in the field item mapping set, convert them into time base tokens, and generate a field item mapping set with time base tokens;
[0016] The set of field items with time base tags is sorted according to the time base tag, and the field items under the same time base tag are grouped and encapsulated into a structured data packet.
[0017] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the method for obtaining the application category and application limitations specifically includes:
[0018] Read field items from the structured data package and synchronously read the industrial semantics and process semantics mapped to the field items;
[0019] Convert the industrial semantics and process semantics mapped to the field items into industrial semantic nodes and process semantic nodes;
[0020] An industrial semantic relationship graph is constructed based on industrial semantic nodes and process semantic nodes. Node connections from industrial semantic nodes to process semantic nodes are established in the industrial semantic relationship graph, and these node connections are bound to corresponding field items, thus forming a set of field item association paths.
[0021] Perform path pruning on the field item paths in the field item association path set, removing invalid field item paths that do not meet the process sequence and process constraints, and retaining valid field item paths that meet the process sequence and process constraints;
[0022] Based on the path type in the valid field item path, map the field item to the usage category, and set the corresponding usage restrictions for the usage category according to the path constraints recorded in the valid field item path.
[0023] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the path pruning refers to filtering and eliminating field item paths in the field item association path set based on the process sequence and process constraints.
[0024] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the output dynamic strategy action set specifically includes:
[0025] Read the usage category and usage restrictions from the usage control data packet, and read the security posture data from the industrial data security management center;
[0026] The application category, application restrictions, and security situation data are linked and combined to generate a strategy decision package;
[0027] The strategy decision package is input into the neural symbolic decision architecture, and the symbolic rule inferencer derives the strategy decision package logically to output the basic strategy action set.
[0028] The neural network predictor of the neural symbol decision architecture performs risk extrapolation on the policy decision package and outputs a risk prediction set.
[0029] The system aligns and resolves conflicts between the basic strategy action set and the risk prediction set, outputting a dynamic strategy action set.
[0030] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the step of aligning and resolving conflicts between the basic strategy action set and the risk prediction set to output a dynamic strategy action set specifically includes:
[0031] Receive the basic strategy action set and risk prediction set through the collaborative arbitrator;
[0032] Analyze the relationship between the basic strategy action set and the risk prediction set to identify completely consistent actions, complementary actions, and conflicting actions.
[0033] Extract actions that are completely consistent with the basic strategy action set and the risk prediction set, and group them into a consistent action set;
[0034] The actions that complement each other in the basic strategy action set and the risk prediction set are merged to generate merged actions, which are then classified into a supplementary action set.
[0035] According to the predefined conflict resolution rules, actions that conflict with each other in the basic arbitration strategy action set and the risk prediction set are used to generate arbitration actions and are classified into a conflict arbitration action set.
[0036] Integrate the consistent action set, the supplementary action set, and the conflict arbitration action set to form a preliminary dynamic strategy action set;
[0037] Based on the usage categories and usage restrictions in the strategy decision package, verify the completeness of the initial dynamic strategy action set, supplement missing actions, and output the verified and supplemented dynamic strategy action set.
[0038] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the step of converting the dynamic policy action set into a policy execution chain configuration package specifically includes:
[0039] Load the pre-built security plugin component library, and match the corresponding security plugin for each action of the dynamic policy action set in the security plugin component library to form a set of alternative plugins;
[0040] Perform dependency analysis and topological sorting on the security plugins in the candidate plugin set to generate a plugin execution sequence;
[0041] The parameters of each action in the dynamic policy action set are formatted into the input parameter format of the corresponding security plugin to generate the plugin parameter set;
[0042] The plugin execution sequence and plugin parameter set are encapsulated to generate a strategy execution chain configuration package.
[0043] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the loading of the corresponding strategy execution chain specifically includes:
[0044] The system receives the strategy execution chain configuration package at the output end of the industrial data source interface, obtains the data access request, and parses the plugin execution sequence and plugin parameter set from the strategy execution chain configuration package.
[0045] Security plugins are loaded from the security plugin component library in the order recorded in the plugin execution sequence.
[0046] Based on the plugin parameter set, the loaded security plugins are initialized and instantiated into a policy execution chain.
[0047] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the generation of the controlled data stream and execution evidence package specifically includes:
[0048] The purpose control data packet is input into the policy execution chain, and the purpose verification plugin in the policy execution chain reads the purpose category and purpose restriction recorded in the purpose control data packet;
[0049] The usage category and usage restrictions are compared with the usage intent recorded in the data access request to generate usage verification results;
[0050] Based on the usage verification results, qualified usage categories and usage restrictions are selected, and field masking and field desensitization are performed on the usage control data packet to generate a field-controlled data packet;
[0051] Verify the data receiver identifier of the field-controlled data packet and generate a range-controlled data packet;
[0052] Perform network domain detection on the outflowing network domain of range-controlled data packets to generate a controlled data stream;
[0053] Collect usage verification results, field-controlled data packets, and scope-controlled data packets, and encapsulate them to generate an execution evidence package.
[0054] As a preferred embodiment of the AI dynamic data security management method for industrial digital information acquisition described in this invention, the field masking refers to making field items that are not allowed to be output in the purpose control data packet invisible based on the qualified purpose category and purpose restriction.
[0055] The aforementioned field desensitization refers to the process of weakening the content of field items in the purpose control data packet that are allowed to be output but need to be protected, based on the qualified purpose category and purpose restriction.
[0056] The beneficial effects of this invention are as follows: By constructing field item association paths driven by industrial and process semantics and performing path pruning based on process sequence and technological constraints, accurate determination of the purpose of industrial data fields is achieved. The semantic relationships between equipment objects, physical quantities, business attributes, and production links are expressed in a structured manner, and invalid or non-compliant data paths are eliminated in conjunction with actual process logic. This ensures that the understanding of data usage intent during human-computer interaction not only relies on static rules but also dynamically aligns with production line operating status and safety process requirements, thereby ensuring the legality, security, and contextual consistency of subsequent data calls from the source. Attached Figure Description
[0057] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0058] Figure 1 A flowchart for AI-driven dynamic data security management methods for industrial digital information collection.
[0059] Figure 2 A flowchart for generating control data packets for specific purposes.
[0060] Figure 3 A flowchart generated for configuring packages for AI dynamic policy decision-making and policy execution chains.
[0061] Figure 4 A flowchart for strategy execution chain loading and data control. Detailed Implementation
[0062] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0063] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0064] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0065] Reference Figures 1-4 This is one embodiment of the present invention, which provides an AI dynamic data security management method for industrial digital information acquisition, including the following steps:
[0066] S1. Perform field-level extraction and time-base alignment on the industrial data output from the industrial data source interface to generate a structured data package.
[0067] Industrial data is received from the industrial data source interface and imported into the industrial raw data set. Within the industrial raw data set, the industrial data is split into fields, forming a set of field items consisting of multiple field items. Field identifiers are then added to the field items in this set, creating a field item mapping set. Specifically:
[0068] Industrial data is read line by line from the raw industrial dataset. The data is then split into sets of field items according to predefined field splitting rules. These rules specify the field name, position, length, separator, encoding format, and data type of each field item within the dataset. Each field item in the set is assigned a field identifier, which consists of an industrial data source interface identifier, a data object identifier, a field name identifier, a data type identifier, and a source path identifier. These field identifiers are then bound one-to-one with the field items to form a field item mapping set, which is written into the raw industrial dataset. The field splitting rules are based on the communication protocol format and data structure conventions of the industrial data source interface and include the field name, position, length, separator, encoding format, and data type.
[0069] Read the timestamps of each field item in the field item mapping set, convert them into time base tokens, and generate a field item mapping set with time base tokens, specifically:
[0070] The time stamps of each field item in the field item mapping set are read one by one. According to the unified time format and unified time zone reference, the time stamps are processed by format standardization and time zone normalization. The time stamps from different sources are converted into time reference stamps with a unified expression form. The time reference stamps are written into the corresponding field item mapping positions to form a field item mapping set with time reference stamps.
[0071] To further explain, format standardization refers to adjusting the date, time, and time precision expressions of time stamps to a unified year, month, day, hour, minute, and second format according to a unified time format.
[0072] Time zone normalization refers to converting the local time zone information contained in the time stamp into a unified time zone expression form according to a unified time zone benchmark.
[0073] The set of field items with time base tags is sorted according to the time base tag, and the field items under the same time base tag are grouped and encapsulated into a structured data packet.
[0074] S2. Based on the industrial semantics and process semantics mapped to the field items in the structured data packet, perform usage determination on the field items to obtain the usage category and usage restrictions, and encapsulate the structured data packet, usage category and usage restrictions to generate a usage control data packet.
[0075] Read field items from the structured data package and synchronously read the industrial semantics and process semantics mapped to the field items; the industrial semantics and process semantics mapped to the field items are the equipment object semantics, physical quantity semantics, business attribute semantics, and link semantics in the production process sequence provided for the field items in the field item mapping set.
[0076] The industrial semantics and process semantics mapped to the field items are converted into industrial semantic nodes and process semantic nodes, specifically as follows:
[0077] The industrial semantics and process semantics mapped to field items are read from the structured data package. Based on the industrial semantic node dictionary and the process semantic node dictionary, node-based mapping processing is performed on the industrial semantics and process semantics mapped to field items. The industrial semantic node dictionary sets industrial semantic node identifiers and industrial semantic node names for equipment object semantics, physical quantity semantics, and business attribute semantics, respectively. The process semantic node dictionary sets process semantic node identifiers and process semantic node names for the semantics of links in the production process sequence. The industrial semantics mapped to field items are written into the corresponding industrial semantic node identifiers and industrial semantic node names to form industrial semantic nodes. The process semantics mapped to field items are written into the corresponding process semantic node identifiers and process semantic node names to form process semantic nodes. The industrial semantic nodes and process semantic nodes are then bound to the field items one-to-one.
[0078] To further explain, the industrial semantic node dictionary is a collection of semantic entries used to record the mapping relationship between equipment object semantics, physical quantity semantics, and business attribute semantics and the corresponding industrial semantic node identifiers; the process semantic node dictionary is a collection of semantic entries used to record the mapping relationship between the semantics of each link in the production process sequence and the corresponding process semantic node identifiers.
[0079] An industrial semantic relationship graph is constructed based on industrial semantic nodes and process semantic nodes. Node connections from industrial semantic nodes to process semantic nodes are established within this graph, and these connections are bound to corresponding field items. This is then aggregated to form a set of field item association paths. Specifically:
[0080] Using industrial semantic nodes and process semantic nodes as graph construction inputs, the data structure of the industrial semantic relationship graph is initialized, and an empty node table and an empty connection table are created. In the node table, a node storage location is allocated for each industrial semantic node and each process semantic node, and the node identifier and node name are registered, forming a writable industrial semantic relationship graph. The formed industrial semantic nodes and process semantic nodes are written one by one into the data structure of the industrial semantic relationship graph, establishing a corresponding node storage location for each industrial semantic node and each process semantic node. Based on the mapping and binding relationship between field items and industrial semantic nodes and process semantic nodes, node connections from industrial semantic nodes to process semantic nodes are established in the industrial semantic relationship graph, and the node connections are associated with the field items that generate the node connections. The node connections are organized sequentially according to the field item order, and the connections between industrial semantic nodes and process semantic nodes generated by the same field item are aggregated together to form the field item association path for the corresponding field item. All field item association paths are summarized and saved as a field item association path set.
[0081] Path pruning is performed on the field item paths in the field item association path set to remove invalid field item paths that do not meet the process sequence and technological constraints, and retain valid field item paths that do meet the process sequence and technological constraints. Path pruning refers to filtering and eliminating field item paths in the field item association path set based on the process sequence and technological constraints. The process sequence refers to the sequential execution order that the semantics of the links in the production process must follow in actual production activities. Technological constraints refer to the set of restrictions set on the equipment parameters, operating status, and interlocking relationships corresponding to the field items in production activities, specifically:
[0082] Read field item paths one by one from the field item association path set, read the semantic order of links in the production process sequence of the process semantic node from the field item path, and read the process constraint information of the corresponding field item of the industrial semantic node from the field item path.
[0083] The semantic arrangement of the steps in the production process sequence is checked for consistency with the process sequence. A satisfactory consistency check means that the semantic arrangement of the steps in the production process sequence is consistent with the sequential relationship of the process sequence and there is no reversal of the process sequence in the semantic arrangement of the steps in the production process sequence. A non-satisfactory consistency check means that the semantic arrangement of the steps in the production process sequence is inconsistent with the sequential relationship of the process sequence or there is a reversal of the process sequence in the semantic arrangement of the steps in the production process sequence.
[0084] The process constraint information is checked against the process constraints for compliance. A compliance check is satisfied when the range of process parameters, process state conditions, and process interlock conditions recorded in the process constraint information all meet the process constraints. A compliance check is not satisfied when any one of the range of process parameters, process state conditions, or process interlock conditions recorded in the process constraint information does not meet the process constraints.
[0085] To further explain, the process parameter range is the range of parameter values allowed for the production equipment in the process specification, for example, a temperature range of 50 to 80 degrees Celsius. The values are based on the process parameter configuration table and equipment operation parameter setting table provided by the industrial data source interface; the process status condition is the equipment operation state and process execution state that the production link must be in under normal production conditions; the process interlock condition is the linkage restriction relationship that the production link must simultaneously meet with other equipment states under safe production conditions.
[0086] Field item paths that fail to meet consistency checks are marked as invalid field item paths, and field item paths that fail to meet compliance checks are also marked as invalid field item paths. Invalid field item paths are removed from the field item associated path set. Field item paths that meet both consistency and compliance checks are retained as valid field item paths, forming a field item associated path set that contains only valid field item paths.
[0087] Based on the path type in the valid field item path, map the field items to usage categories, and set corresponding usage restrictions for the usage categories according to the path constraints recorded in the valid field item path, specifically:
[0088] The path type in the valid field item path is used as the matching input for the purpose category. The purpose category with the same path type name is searched in the purpose category list, and the searched purpose category is used as the purpose category corresponding to the valid field item path. The field items in the valid field item path are written one by one into the field item list corresponding to the purpose category to form a mapping relationship between purpose category and field item. The path constraints recorded in the valid field item path are split into field output restrictions, data receiver restrictions, and outflow network domain restrictions. The field output restrictions are written into the field output restriction item of the purpose restriction, the data receiver restrictions are written into the data receiver restriction item of the purpose restriction, and the outflow network domain restrictions are written into the outflow network domain restriction item of the purpose restriction. The purpose restrictions are bound one-to-one with the purpose category to form the purpose restrictions corresponding to the purpose category.
[0089] The structured data packet, usage category, and usage restrictions are encapsulated together to generate a usage control data packet.
[0090] S3. Based on the usage category and usage restrictions recorded in the usage control data packet, construct a policy decision package, execute AI dynamic policy decisions on the policy decision package, output a set of dynamic policy actions, and convert the set of dynamic policy actions into a policy execution chain configuration package.
[0091] The application category and application restrictions are read from the application control data package, and the security status data is read from the industrial data security management center. The application category, application restrictions and security status data are associated and concatenated to generate a policy decision package.
[0092] The policy decision package is input into the neural symbolic decision architecture, and the symbolic rule inferencer logically derives the policy decision package, outputting a basic policy action set, specifically:
[0093] After the strategy decision package is fed into the neural symbolic decision architecture, the internal symbolic rule inferencer parses the fields of the strategy decision package, converting the usage category, usage restriction, and security status data into a symbolic fact set. The symbolic fact set contains usage category facts, usage restriction facts, and security status facts. The symbolic rule inferencer matches the symbolic fact set one by one in the symbolic rule set. The symbolic rule set consists of triggering conditions and action conclusions. The triggering conditions are combined constraints between usage category facts, usage restriction facts, and security status facts. The combined constraints consist of usage category matching conditions, usage restriction matching conditions, and security status level matching conditions. The action conclusions are a set of security policy action entries that correspond one-to-one with the combined constraints. The set of security policy action entries consists of a security policy action name field and a security policy action parameter field, and is written into the basic policy action set. The symbolic rule inferencer outputs the corresponding action conclusions for symbolic rules that meet the triggering conditions, writes the action conclusions into the basic policy action set, merges duplicate security policy actions in the basic policy action set into unique entries, and retains conflicting security policy actions in the basic policy action set as conflict marker entries, thus forming the basic policy action set.
[0094] It should be noted that the symbolic rule inferencer does not involve a training process. The symbolic rule inferencer performs logical matching and rule triggering on symbolic facts based on the symbolic rule set. The symbolic rule inference result is determined by the matching relationship between the triggering conditions in the symbolic rule set and the symbolic fact set. It does not involve sample learning, parameter updating or model optimization processes, and therefore does not involve a training process.
[0095] The neural network predictor of the neural symbolic decision architecture performs risk extrapolation on the policy decision package and outputs a risk prediction set, specifically:
[0096] After the strategy decision package is fed into the neural network predictor of the neural symbolic decision architecture, the neural network predictor performs field parsing on the strategy decision package. Field parsing includes extracting the usage category field, usage restriction field, and security situation data field from the strategy decision package, and converting the usage category field into usage category features, the usage restriction field into usage restriction features, and the security situation data field into security situation features. The neural network predictor concatenates the usage category features, usage restriction features, and security situation features in the order of the fields to form the neural network predictor input feature sequence. The neural network predictor performs risk mapping processing on the neural network predictor input feature sequence according to the neural network predictor parameters. Risk mapping processing includes mapping the neural network predictor input feature sequence into risk level prediction results and risk type prediction results, and attaching usage category identifiers and usage restriction identifiers to the risk level prediction results and risk type prediction results to form risk prediction result entries. The risk prediction result entries are summarized and packaged into a risk prediction set.
[0097] To further explain, the parameters of a neural network predictor are the weight and bias parameters that are formed and fixed during the training process of the neural network predictor. For example, they are the input layer weight parameters, hidden layer weight parameters, output layer weight parameters, and corresponding bias parameters. The parameters are based on the stable parameter results obtained after updating the parameters of the training sample set and training label set during the training process of the neural network predictor.
[0098] The neural network predictor training process involves: exporting historical policy decision packages, historical usage verification results, and historical security situation data from the Industrial Data Security Management Center; aligning and associating the usage category field, usage restriction field, and security situation data field in the historical policy decision packages with the usage verification result field in the historical usage verification results with the security event identifier field, thus forming a training sample set with usage category field, usage restriction field, security situation data field, usage verification result field, and security event identifier field; and exporting security event labels and risk level labels from the Industrial Data Security Management Center, aligning and associating the security event labels and risk level labels according to the security event identifier field, thus forming a training sample set with security event label field and risk level label. The process involves: 1) creating a training label set for the risk level labeling field; 2) converting the usage category field, usage restriction field, and security situation data field in the training sample set into input feature sequences for the neural network predictor; 3) converting the risk level labeling field and security event labeling field in the training label set into training target sequences; 4) inputting the neural network predictor input feature sequences and training target sequences into the neural network predictor to perform parameter updates, using the training target sequences as a monitoring signal to iteratively update the neural network predictor parameters; 5) solidifying the updated neural network predictor parameters into a neural network predictor parameter file and writing the neural network predictor parameter file to the parameter storage location of the security plug-in component library in the industrial data security management center.
[0099] The basic strategy action set and risk prediction set are aligned and conflict resolved to output a dynamic strategy action set, specifically:
[0100] The system receives the basic strategy action set and risk prediction set through a collaborative arbitrator; it analyzes the action relationships between the basic strategy action set and the risk prediction set, identifying completely consistent actions, complementary actions, and conflicting actions, specifically:
[0101] After receiving the basic strategy action set and the risk prediction set, the collaborative arbitrator establishes an alignment relationship between the use category identifier and the use restriction identifier of the basic strategy action set and the risk prediction result item in the risk prediction set. The collaborative arbitrator selects basic strategy actions in the basic strategy action set that have the same use category identifier and the same use restriction identifier as the risk prediction result item in the risk prediction set, and combines and encapsulates the basic strategy action and the risk prediction result item into an action alignment item.
[0102] Extract the security policy action name and security policy action parameters of the basic policy action from the action alignment entries, and extract the risk level prediction results and risk type prediction results corresponding to the risk prediction results entries. Perform name consistency comparison on the security policy action name and parameter consistency comparison on the security policy action parameters.
[0103] Actions with the same security policy action name and the same security policy action parameters are marked as completely identical actions. Actions with the same security policy action name but different security policy action parameters, or whose security policy action parameters have a parallel compatibility relationship, are marked as complementary actions. Actions with the same security policy action name but different security policy action parameters, or whose security policy action parameters have a mutual exclusion relationship, are marked as conflicting actions.
[0104] Actions that are completely consistent between the basic strategy action set and the risk prediction set are extracted and grouped into a consistent action set; actions that are complementary between the basic strategy action set and the risk prediction set are merged to generate merged actions and grouped into a supplementary action set; actions that conflict between the basic strategy action set and the risk prediction set are arbitrated according to predefined conflict resolution rules, generating arbitration actions and grouping them into a conflict arbitration action set; the conflict resolution rules are set based on the priority of usage category, the strictness of usage restrictions, and the relationship between risk level, including high-risk priority rules, strict restriction priority rules, and security protection priority rules.
[0105] To further explain, the priority of usage categories is a hierarchical relationship determined by the order of their impact on security sensitivity; the higher the priority, the greater the impact of the usage category on data security. The strictness of usage restrictions is determined by the degree of tightening of the restrictions on the output fields, the data recipient, and the outgoing network domain; the smaller the restriction range, the higher the strictness. The level of risk is a security risk level determined by the risk level prediction results output from the risk prediction set; the higher the risk level value, the higher the risk level.
[0106] Integrate the consistent action set, the supplementary action set, and the conflict arbitration action set to form a preliminary dynamic strategy action set; based on the usage category and usage restrictions in the strategy decision package, verify the completeness of the preliminary dynamic strategy action set, supplement missing actions, and output the verified and supplemented dynamic strategy action set, specifically:
[0107] After receiving the usage category and usage restriction recorded in the policy decision packet, the collaborative arbitrator converts the usage category into a usage category required action list and the usage restriction into a usage restriction required action list. The usage category required action list lists the security policy action names that the usage category must have, and the usage restriction required action list lists the security policy action names corresponding to field output restriction actions, data receiver restriction actions, and outflow network domain restriction actions.
[0108] The security policy action names in the initial dynamic policy action set are summarized into an existing action name list, and the corresponding security policy action parameters are retained for the security policy action names in the existing action name list; the security policy action names in the purpose category requirement action list are matched item by item with the existing action name list, and the security policy action names in the purpose category requirement action list that do not match the existing action name list are recorded as the purpose category missing action list.
[0109] The fields in the action list for usage restriction requirements are output as the security policy action names corresponding to the restricted actions, the security policy action names corresponding to the data receiver restriction actions, and the security policy action names corresponding to the outgoing network domain restriction actions. These are then matched item by item with the existing action name list. Security policy action names in the action list for usage restriction requirements that do not match the existing action name list are recorded as the action list for missing usage restriction actions.
[0110] Write the names of security policy actions from the list of missing action categories and the list of missing action restrictions into the initial dynamic policy action set one by one. Then, write the field output restrictions, data recipient restrictions, and outgoing network domain restrictions from the use categories and use restrictions into the security policy action parameter positions corresponding to the newly added security policy action names to form a verified and supplemented dynamic policy action set.
[0111] Load the pre-built security plugin component library, and match the corresponding security plugin for each action in the dynamic policy action set in the security plugin component library to form a candidate plugin set, specifically:
[0112] Extract the security policy action name and security policy action parameter from the dynamic policy action set; retrieve security plugin entries from the security plugin component library, which contain the security plugin name, supported action type, and supported parameter type.
[0113] The security policy action name is compared with the supported action type in the security plugin entry for name consistency, and the security policy action parameter type is compared with the supported parameter type in the security plugin entry for type consistency. When the security policy action name and the supported action type are consistent, and the security policy action parameter type and the supported parameter type are consistent, the corresponding security plugin entry is marked as a successful match. When the security policy action name and the supported action type are inconsistent, or the security policy action parameter type and the supported parameter type are inconsistent, the corresponding security plugin entry is marked as a failed match and excluded from the candidate plugin set.
[0114] All successfully matched security plugin entries are bound one by one to actions in the dynamic policy action set according to their correspondence, forming a set of alternative plugins corresponding to the dynamic policy action set.
[0115] It should be noted that the security plugin component library encapsulates field masking, field anonymization, purpose verification, data receiver verification, and outgoing network domain verification as independent security plugin entries. Each security plugin entry is registered with a security plugin name, supported action types, supported parameter types, a list of input fields, and a list of output fields. These are then aggregated to form a dedicated security plugin component library. This library provides a source of matchable, combinable, and sortable security plugin entries for dynamic policy action sets during the policy execution phase, and is used to load and execute the policy execution chain. Specifically, field masking, field anonymization, purpose verification, data receiver verification, and outgoing network domain verification are security policy action types. These are specific security control actions that purpose-controlled data packets must perform during security management, used to constrain and control field content, data usage, and data flow.
[0116] Dependency analysis and topological sorting are performed on the security plugins in the candidate plugin set to generate a plugin execution sequence, specifically:
[0117] Extract the security plugin name, input field list, and output field list from each security plugin in the candidate plugin set; establish dependency entries based on the field reference relationship between the input field list and the output field list. When the input field list of one security plugin contains a field from the output field list of another security plugin, establish a sequential dependency entry between the two security plugins.
[0118] All sequential dependency entries are compiled into a security plugin dependency table. Each security plugin name in the security plugin dependency table is registered as a security plugin node, and each sequential dependency entry in the security plugin dependency table is registered as a directed connection. After all security plugin nodes and all directed connections are established, a security plugin dependency graph is formed.
[0119] In the security plugin dependency graph, a security plugin without input dependencies is selected as the starting security plugin. The order of subsequent security plugins is determined according to the connection direction of the dependencies. The order of security plugins that satisfy the dependencies is output step by step. When there are circular dependencies or security plugins that cannot satisfy the input dependencies in the security plugin dependency graph, the corresponding security plugin is marked as an unexecutable plugin and excluded from the plugin execution sequence. The plugin execution sequence is formed and written into the policy execution chain configuration package. Among them, the unsatisfactory input dependencies are fields in the list of input fields required by the security plugin that are not present in the output field list of all security plugins in the execution order, resulting in the security plugin being unable to execute due to the lack of necessary input fields.
[0120] The parameters of each action in the dynamic policy action set are formatted into the input parameter format of the corresponding security plugin to generate a plugin parameter set; the plugin execution sequence and the plugin parameter set are encapsulated to generate a policy execution chain configuration package.
[0121] S4. At the output end of the industrial data source interface, configure the package according to the policy execution chain, load the corresponding policy execution chain, and input the purpose control data packet into the policy execution chain. Perform field-level control and data flow control on the purpose control data packet to generate a controlled data flow and execution evidence package.
[0122] The system receives the policy execution chain configuration package at the output end of the industrial data source interface and obtains the data access request. It then parses the plugin execution sequence and plugin parameter set from the policy execution chain configuration package, specifically:
[0123] The system continuously listens for policy execution chain configuration packages and data access requests from the upper-level control port at the output end of the industrial data source interface. When the policy execution chain configuration package arrives at the output end of the industrial data source interface, it performs structured reading processing on the contents of the policy execution chain configuration package. The structured reading processing includes reading the plugin execution sequence field and plugin parameter set field recorded in the policy execution chain configuration package field by field. The plugin execution sequence field is then sequentially expanded according to the record order to form a plugin execution sequence list containing multiple security plugin names.
[0124] The fields of the plugin parameter set are split and organized according to the field correspondence, and the input parameter items and parameter values corresponding to each security plugin are completely extracted to form a plugin parameter set that corresponds one-to-one with the plugin execution sequence.
[0125] After the strategy execution chain configuration package completes the structured reading process, it simultaneously reads the data access request from the request channel of the industrial data source interface, completely obtains the access subject identifier, access destination identifier, and access object identifier in the data access request, and associates and stores them with the already parsed plugin execution sequence and plugin parameter set, thereby completing the parsing of the strategy execution chain configuration package and the acquisition of the data access request.
[0126] According to the order recorded in the plugin execution sequence, security plugins are loaded from the security plugin component library; based on the plugin parameter set, the loaded security plugins are initialized with parameters and instantiated into a policy execution chain, specifically as follows:
[0127] In the security plugin component library, the security plugin program files corresponding to the security plugin names are retrieved one by one according to the order of the security plugin names recorded in the plugin execution sequence; each retrieved security plugin program file is loaded into the runtime environment to form a security plugin instance in a state of pending initialization; based on the already parsed plugin parameter set, the input parameter names and input parameter values recorded in the plugin parameter set are written into the parameter interface position of the corresponding security plugin instance.
[0128] The output restriction parameters, data receiver restriction parameters, and outflow network domain restriction parameters recorded in the plugin parameter set are written into the control parameter positions of the corresponding security plugin instances. After each security plugin instance completes parameter initialization, the output field interface of the previous security plugin instance is connected to the input field interface of the next security plugin instance according to the order in the plugin execution sequence, forming a sequentially connected security plugin instance queue.
[0129] Once all security plugin instances in the plugin execution sequence have completed parameter initialization and sequential connection (i.e., the output field interface of the previous security plugin instance is connected one-to-one with the input field interface of the next security plugin instance to form a chain structure of security plugin instances that can transmit data in a predetermined order), a complete queue of security plugin instances that can be executed in sequence is obtained. The complete queue of security plugin instances is determined as the policy execution chain, thereby completing the instantiation of the policy execution chain.
[0130] The purpose control data packet is input into the policy execution chain. The purpose verification plugin in the policy execution chain reads the purpose category and purpose restriction recorded in the purpose control data packet. The purpose category and purpose restriction are compared with the usage intent recorded in the data access request to generate a purpose verification result, specifically:
[0131] The purpose category field and purpose restriction field recorded in the purpose control data packet are read, and the use intent field is extracted from the data access request. The use intent field contains the access subject identity information, access purpose information, and access object scope information. The purpose verification plugin compares the access purpose information in the use intent field with the allowed use scenarios recorded in the purpose category for name consistency, compares the access subject identity information in the use intent field with the data receiver restriction content recorded in the purpose restriction for consistency, compares the access object scope information in the use intent field with the field output restriction scope recorded in the purpose restriction for consistency, and compares the access path information in the use intent field with the outflow network domain restriction content recorded in the purpose restriction for consistency.
[0132] When the purpose information matches the usage category, and the access subject's identity information, access object scope information, and access path information all meet the usage restriction requirements, the usage verification result is marked as passed. When any comparison result does not meet the requirements, the usage verification result is marked as failed, and the usage verification result is written into the subsequent processing stage of the policy execution chain.
[0133] To further explain, the usage restriction requirements are the allowed usage boundary conditions set in the usage control data packet regarding the field output range, data recipient range, and outgoing network domain range. Specifically, the field output range is the set of fields allowed to be provided externally in the usage control data packet. For example, allowed output fields include "equipment temperature field," "equipment current field," and "production batch field," while prohibited output fields include "equipment identification field" and "operator identification field," based on the field output restrictions explicitly listed in the usage restrictions corresponding to the usage category. The data recipient range is the range of entities allowed to receive data in the usage control data packet. For example, allowed data recipients include "quality monitoring terminals" and "production scheduling terminals," while prohibited data recipients include "external third-party terminals," based on the usage category authorization list and data access permission allocation records. The outgoing network domain range is the network area range where data transmission is allowed in the usage control data packet. For example, allowed outgoing network domains include "plant intranet domain A" and "plant intranet domain B," while prohibited outgoing network domains include "external internet domains," based on industrial network security partitioning policies and network domain access whitelist configurations.
[0134] Based on the usage verification results, qualified usage categories and restrictions are selected. Then, field masking and desensitization are performed on the usage control data packet according to these qualified usage categories and restrictions, generating a field-controlled data packet. Field masking refers to making fields in the usage control data packet that are not allowed to be output invisible based on the qualified usage categories and restrictions. Field desensitization refers to weakening the content of fields in the usage control data packet that are allowed to be output but require protection, based on the qualified usage categories and restrictions. Specifically:
[0135] After obtaining the usage verification result in the policy execution chain, the usage verification plugin reads the verification status field in the usage verification result. When the verification status field is "passed", it marks the corresponding usage category and usage restriction in the usage control data packet as qualified usage category and qualified usage restriction. When the verification status field is "failed", it marks the corresponding usage category and usage restriction in the usage control data packet as unqualified usage category and unqualified usage restriction, and stops subsequent data output processing.
[0136] After completing the screening of qualified usage categories and qualified usage restrictions, the field masking plugin checks all fields in the usage control data packet one by one according to the field output restriction items recorded in the qualified usage restrictions. Fields not listed in the field output restriction items are marked as prohibited output fields, and the prohibited output fields are made invisible. The invisible processing replaces the field value of the prohibited output field with unreadable placeholder content, thereby preventing the prohibited output fields from being transmitted outward.
[0137] Based on the field protection requirements recorded in the qualified use restrictions, the field protection requirements are security protection conditions set in the use restrictions for permitted output field items that require content weakening processing; each field item that is permitted to be output but requires protection is identified, the field items that require protection are marked as sensitive field items, and the field values of sensitive field items are subjected to content weakening processing. Content weakening processing is to replace the key information in the sensitive field item with obfuscated or masked content in order to reduce the identifiability of the sensitive field item.
[0138] After the field masking and field desensitization processes are completed, the purpose control data packets that have undergone invisibility and content weakening processes are uniformly organized to form a field-controlled data packet containing only output field items and sensitive field items that have been protected.
[0139] The data receiver identifier of the field-controlled data packet is validated, and a range-controlled data packet is generated, specifically as follows:
[0140] The data receiver identifier field is read from the field-controlled data packet, and simultaneously the data receiver restriction field from the qualified usage restrictions recorded in the usage control data packet is read. The data receiver verification plugin compares the receiver identity information in the data receiver identifier field with the list of allowed receiver identities in the data receiver restriction field. When the receiver identity information in the data receiver identifier field is completely included in the list of allowed receiver identities, the list of receiver identities is the set of access subject identifiers that are allowed to receive data, pre-listed in the usage control data packet according to the usage category authorization record and data access permission allocation rules, such as the quality monitoring terminal identifier and the production scheduling terminal identifier. The data receiver identifier verification result is marked as passed. When the receiver identity information in the data receiver identifier field is not included in the list of allowed receiver identities, the data receiver identifier verification result is marked as failed.
[0141] If the data receiver identifier verification result is successful, the field-controlled data packet continues to be transmitted as output data. If the data receiver identifier verification result is unsuccessful, the field-controlled data packet is rejected for output and transmission is stopped. The field-controlled data packets after the data receiver identifier verification process is completed are uniformly encapsulated into range-controlled data packets.
[0142] Perform network domain inspection on the outgoing network domain of the controlled data packets to generate a controlled data stream, specifically:
[0143] Read the data transmission path information from the scope-controlled data packet, which contains the target network domain identifier to which the data will flow; read the outflow network domain restriction field recorded in the eligible purpose restriction from the purpose control data packet, which contains a list of allowed data outflow network domain identifiers.
[0144] The outflow network domain verification plugin compares the target network domain identifier in the data transmission path information with the list of allowed outflow network domain identifiers. When the target network domain identifier completely falls within the list of allowed outflow network domain identifiers (the list of network domain names allowed for data transmission as defined in the purpose control data packet), the outflow network domain verification result is marked as passed. When the target network domain identifier does not fall within the list of allowed outflow network domain identifiers, the outflow network domain verification result is marked as failed. If the outflow network domain verification result is passed, the controlled data packet is continued to be transmitted outward as legitimate output data, forming a controlled data stream. If the outflow network domain verification result is failed, the controlled data packet's output is blocked and data transmission is stopped, thus completing the network domain detection of the controlled data packet and generating a controlled data stream.
[0145] Collect usage verification results, field-controlled data packets, and scope-controlled data packets, encapsulate them to generate an execution evidence packet; send the controlled data stream to the data bus, and send the execution evidence packet back to the industrial data security management center.
[0146] This embodiment also provides a computer device applicable to the AI dynamic data security management method for industrial digital information acquisition, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to realize the AI dynamic data security management method for industrial digital information acquisition as proposed in the above embodiment.
[0147] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0148] This embodiment also provides a storage medium storing a computer program. When executed by a processor, the program implements the AI dynamic data security management method for industrial digital information acquisition as proposed in the above embodiments. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Red-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0149] In summary, this invention achieves accurate determination of the purpose of industrial data fields by constructing field item association paths driven by industrial and process semantics and performing path pruning based on process sequence and technological constraints. It structures and expresses the semantic relationships between equipment objects, physical quantities, business attributes, and production links, and eliminates invalid or non-compliant data paths by combining actual process logic. This ensures that the understanding of data usage intent during human-computer interaction not only relies on static rules but also dynamically aligns with production line operating status and safety process requirements, thereby ensuring the legality, security, and contextual consistency of subsequent data calls from the source.
[0150] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. An AI-based dynamic data security management method for industrial digital information acquisition, characterized in that: include, Perform field-level extraction and time-base alignment on the industrial data output from the industrial data source interface to generate a structured data package; Based on the industrial semantics and process semantics mapped to the field items in the structured data packet, the purpose of the field items is determined to obtain the purpose category and purpose restriction. The structured data packet, purpose category and purpose restriction are then encapsulated to generate a purpose control data packet. Based on the usage category and usage restrictions recorded in the usage control data package, and the security situation data read from the industrial data security management center, a strategy decision package is constructed, AI dynamic strategy decision is executed on the strategy decision package, a set of dynamic strategy actions is output, and the set of dynamic strategy actions is converted into a strategy execution chain configuration package. At the output end of the industrial data source interface, a policy execution chain configuration package is configured according to the policy execution chain, the corresponding policy execution chain is loaded, and the purpose control data packet is input to the policy execution chain. Field-level control and data flow control are performed on the purpose control data packet to generate a controlled data flow and an execution evidence package. The obtained usage categories and usage restrictions are specifically as follows: Read field items from the structured data package and synchronously read the industrial semantics and process semantics mapped to the field items; Convert the industrial semantics and process semantics mapped to the field items into industrial semantic nodes and process semantic nodes; An industrial semantic relationship graph is constructed based on industrial semantic nodes and process semantic nodes. Node connections from industrial semantic nodes to process semantic nodes are established in the industrial semantic relationship graph, and these node connections are bound to corresponding field items, thus forming a set of field item association paths. Perform path pruning on the field item paths in the field item association path set, removing invalid field item paths that do not meet the process sequence and process constraints, and retaining valid field item paths that meet the process sequence and process constraints; Based on the path type in the valid field item path, map the field item to the usage category, and set the corresponding usage restrictions for the usage category according to the path constraints recorded in the valid field item path.
2. The AI dynamic data security management method for industrial digital information acquisition as described in claim 1, characterized in that: The generated structured data packet specifically refers to... Receive industrial data from industrial data source interfaces and import it into the industrial raw data set; In the raw industrial dataset, the industrial data is split into fields to form a set of field items consisting of multiple field items. Field identifiers are then added to the field items in the set of field items to form a field item mapping set. Read the timestamps of each field item in the field item mapping set, convert them into time base tokens, and generate a field item mapping set with time base tokens; The set of field items with time base tags is sorted according to the time base tag, and the field items under the same time base tag are grouped and encapsulated into a structured data packet.
3. The AI dynamic data security management method for industrial digital information acquisition as described in claim 1, characterized in that: The path pruning refers to filtering and eliminating field item paths in the field item association path set based on the process sequence and process constraints.
4. The AI dynamic data security management method for industrial digital information acquisition as described in claim 1, characterized in that: The set of output dynamic policy actions is specifically as follows: Read the purpose category and purpose restrictions from the purpose control data packet; The application category, application restrictions, and security situation data are linked and combined to generate a strategy decision package; The strategy decision package is input into the neural symbolic decision architecture, and the symbolic rule inferencer derives the strategy decision package logically to output the basic strategy action set. The neural network predictor of the neural symbol decision architecture performs risk extrapolation on the policy decision package and outputs a risk prediction set. The system aligns and resolves conflicts between the basic strategy action set and the risk prediction set, outputting a dynamic strategy action set.
5. The AI dynamic data security management method for industrial digital information acquisition as described in claim 4, characterized in that: The process involves aligning and resolving conflicts between the basic strategy action set and the risk prediction set, outputting a dynamic strategy action set. Specifically... Receive the basic strategy action set and risk prediction set through the collaborative arbitrator; Analyze the relationship between the basic strategy action set and the risk prediction set to identify completely consistent actions, complementary actions, and conflicting actions. Extract actions that are completely consistent with the basic strategy action set and the risk prediction set, and group them into a consistent action set; The actions that complement each other in the basic strategy action set and the risk prediction set are merged to generate merged actions, which are then classified into a supplementary action set. According to the predefined conflict resolution rules, actions that conflict with each other in the basic arbitration strategy action set and the risk prediction set are used to generate arbitration actions and are classified into a conflict arbitration action set. Integrate the consistent action set, the supplementary action set, and the conflict arbitration action set to form a preliminary dynamic strategy action set; Based on the usage categories and usage restrictions in the strategy decision package, verify the completeness of the initial dynamic strategy action set, supplement missing actions, and output the verified and supplemented dynamic strategy action set.
6. The AI dynamic data security management method for industrial digital information acquisition as described in claim 1, characterized in that: The process of converting the dynamic policy action set into a policy execution chain configuration package specifically involves... Load the pre-built security plugin component library, and match the corresponding security plugin for each action of the dynamic policy action set in the security plugin component library to form a set of alternative plugins; Perform dependency analysis and topological sorting on the security plugins in the candidate plugin set to generate a plugin execution sequence; The parameters of each action in the dynamic policy action set are formatted into the input parameter format of the corresponding security plugin to generate the plugin parameter set; The plugin execution sequence and plugin parameter set are encapsulated to generate a strategy execution chain configuration package.
7. The AI dynamic data security management method for industrial digital information acquisition as described in claim 1, characterized in that: The loading of the corresponding strategy execution chain is specifically as follows: The system receives the strategy execution chain configuration package at the output end of the industrial data source interface, obtains the data access request, and parses the plugin execution sequence and plugin parameter set from the strategy execution chain configuration package. Security plugins are loaded from the security plugin component library in the order recorded in the plugin execution sequence. Based on the plugin parameter set, the loaded security plugins are initialized and instantiated into a policy execution chain.
8. The AI dynamic data security management method for industrial digital information acquisition as described in claim 1, characterized in that: The generation of the controlled data stream and execution evidence package specifically includes, The purpose control data packet is input into the policy execution chain, and the purpose verification plugin in the policy execution chain reads the purpose category and purpose restriction recorded in the purpose control data packet; The usage category and usage restrictions are compared with the usage intent recorded in the data access request to generate usage verification results; Based on the usage verification results, qualified usage categories and usage restrictions are selected, and field masking and field desensitization are performed on the usage control data packet to generate a field-controlled data packet; Verify the data receiver identifier of the field-controlled data packet and generate a range-controlled data packet; Perform network domain detection on the outflowing network domain of range-controlled data packets to generate a controlled data stream; Collect usage verification results, field-controlled data packets, and scope-controlled data packets, and encapsulate them to generate an execution evidence package.
9. The AI dynamic data security management method for industrial digital information acquisition as described in claim 8, characterized in that: The field masking refers to making fields that are not allowed to be output in the purpose control data packet invisible, based on the qualified purpose category and purpose restriction; The aforementioned field desensitization refers to the process of weakening the content of field items in the purpose control data packet that are allowed to be output but need to be protected, based on the qualified purpose category and purpose restriction.