Industrial internet data security sharing method and system based on trusted space

By constructing a standard data feature template library and a dynamic mapping rule library, the problem of identifying multimodal heterogeneous data in industrial internet data sharing has been solved, enabling accurate data identification and secure sharing, and ensuring data validity and security.

CN121881386BActive Publication Date: 2026-07-24NINGBO JIWANG INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NINGBO JIWANG INFORMATION TECH CO LTD
Filing Date
2026-03-17
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing technologies lack targeted identification mechanisms for multimodal heterogeneous data in the process of data sharing in the industrial internet, making it difficult to accurately extract core data features, and failing to ensure trusted data sharing and secure management. Furthermore, the classification of data sensitivity dimensions, access permissions, and encryption types cannot be dynamically adjusted, leading to misjudgments and insufficient security.

Method used

A standard data feature template library for the industrial internet is constructed. Initial weight values ​​are assigned based on the differences in feature dimensions of different types of data. Core features of the data are extracted through adaptive recognition technology. A dynamic mapping rule library is built to identify the validity and authenticity of the data, dynamically adjust access permissions and encryption strategies, and form a trusted sharing closed loop.

Benefits of technology

It achieves accurate identification and effective differentiation of multimodal heterogeneous data, ensuring that the data entering the sharing process is valid and trustworthy, dynamically matching access permissions and encryption strategies, and guaranteeing the security protection of highly sensitive data and the efficient circulation of ordinary data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121881386B_ABST
    Figure CN121881386B_ABST
Patent Text Reader

Abstract

The application discloses an industrial internet data security sharing method and system based on a trusted space, relates to the technical field of data identification, and specifically comprises the following steps: data collection, self-adaptive identification, mapping rule library construction, dynamic mapping and security sharing execution; by constructing an industrial internet standard data feature template library, combining the feature dimension difference of different types of data to distribute an initial weight value, and then adjusting a dynamic adjustment coefficient according to the deviation of the original feature value and the standard core feature range, the data core feature extraction and effectiveness identification are completed; this process can realize accurate identification according to the characteristics of multi-modal heterogeneous data, effectively distinguish the effective and abnormal states of the data, provide reliable identification basis for the subsequent trusted sharing of the data, and ensure that the data entering the sharing link are all effective and trusted data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data identification technology, specifically to a method and system for secure data sharing in the industrial internet based on trusted space. Background Technology

[0002] Currently, the Industrial Internet is developing rapidly towards large-scale and intelligent development. Massive amounts of multimodal and heterogeneous data, such as sensor monitoring data, equipment operation log data, and production process control data, are being generated continuously. As the core production factor of the Industrial Internet, the demand for data sharing across entities and links is becoming increasingly urgent. However, in practical applications, it is difficult to balance the credibility and security of data sharing. How to ensure the effective flow of data while achieving precise control over the data has become a key issue that the industry urgently needs to address.

[0003] However, existing technologies lack targeted identification mechanisms for multimodal heterogeneous data in the process of data sharing in the industrial internet, making it difficult to accurately extract core data features and complete validity verification. At the same time, the data sensitivity dimension classification and the binding of access permissions and encryption types are mostly static configurations, which cannot dynamically adjust the matching strategy according to the actual characteristics of the data. In addition, the feature matching process lacks a closed-loop secondary identification mechanism, which is prone to misjudgment. This makes it difficult to ensure the security management of highly sensitive data and also to meet the needs of efficient sharing of ordinary data. Summary of the Invention

[0004] The purpose of this invention is to overcome the shortcomings of existing technologies and provide a method and system for secure data sharing in the industrial internet based on trusted space. This invention constructs a standard data feature template library for the industrial internet, assigns initial weight values ​​based on the differences in feature dimensions of different types of data, and then adjusts the dynamic adjustment coefficients according to the deviation between the original feature values ​​and the standard core feature range to complete the extraction of core data features and the identification of validity. This process can achieve accurate identification for the characteristics of multimodal heterogeneous data, effectively distinguish between valid and abnormal data states, provide a reliable identification basis for subsequent trusted data sharing, and ensure that all data entering the sharing process is valid and trusted data.

[0005] To solve the above-mentioned technical problems, the present invention provides the following technical solution: On the one hand, a method for secure data sharing in the industrial internet based on trusted space, the specific steps of which are as follows: Data Acquisition: Integrates distributed data acquisition nodes of the Industrial Internet, and acquires multimodal heterogeneous data such as sensor monitoring data, equipment operation log data and production process control data in real time through industrial Ethernet, and performs preprocessing to form a multimodal heterogeneous data set; Adaptive recognition: Based on a multimodal heterogeneous dataset, adaptive recognition technology is used to analyze the structural and semantic features of the multimodal heterogeneous data. The parameters are adjusted in real time according to the feature differences of different types of data, the core features of each type of data are extracted, and the validity and authenticity of the data are identified to obtain the recognition results. Mapping rule base construction: Build a dynamic mapping rule base that connects recognition results with trusted space access permissions and encryption strategies. This includes the correspondence between core data features and access permission levels and encryption types, and presets feature matching thresholds and standard values ​​for each dimension. Dynamic mapping: The dynamic mapping rule base is called, and the recognition results are combined with the feature matching algorithm to calculate the feature matching degree. The result is then compared with the feature matching threshold to determine the corresponding access permission level and encryption type. This completes the real-time binding of the recognition results with the trusted space, and the binding result is obtained. Secure sharing execution: Based on the binding results, grant access rights to the corresponding trusted space to eligible sharing entities, encrypt the data using the matched encryption type, and allow only entities with the corresponding permissions and verified identity to access the encrypted data.

[0006] Furthermore, in the data acquisition process, the preprocessing steps for multimodal heterogeneous data are as follows: identifying and removing duplicate data in the multimodal heterogeneous data, filtering out data with missing fields through data integrity verification, and dividing the filtered data into three categories: time-series data, text data, and structured data. The corresponding data format conversion protocols are used to uniformly convert all types of data into a common data format to form a unified multimodal heterogeneous data set.

[0007] Furthermore, in the adaptive recognition process, the adaptive recognition technology uses the multimodal heterogeneous data core feature extraction formula as the execution carrier. The specific steps for extracting the core features of each type of data and completing the data validity and authenticity recognition are as follows: Feature dimension processing is performed on each type of data in the multimodal heterogeneous data set to remove noise interference information, and the original feature values ​​of each feature dimension are extracted. Initial values ​​are assigned to the weights of each feature dimension according to the data type. In time-series data, the initial weight of the time dimension feature is higher than that of other dimensions; in text-type data, the initial weight of the semantic dimension feature is higher than that of other dimensions; and in structured data, the initial weight of the field association dimension feature is higher than that of other dimensions. In addition to other dimensions, an industrial internet standard data feature template library is constructed based on historically normal sensor data, logs of equipment without abnormalities, and standardized production process data. The standard core feature range of various types of data is stored according to data type. Then, the deviation value of the original feature value of the current feature dimension and the standard core feature range of similar data is calculated. Based on the deviation value, the dynamic adjustment coefficient is adjusted to optimize the feature extraction accuracy. Finally, the core feature value of the data is calculated through the multimodal heterogeneous data core feature extraction formula. The core feature of the data is composed of the core feature value and the decomposition value of each dimension. It is determined whether the core feature value of the data falls within the standard core feature range of similar data to complete the identification of data validity and authenticity.

[0008] Furthermore, the formula for extracting core features from multimodal heterogeneous data is as follows: ,in, These are the core feature values ​​of the data. This represents the total number of feature dimensions. For the first The weights of each feature dimension are determined based on statistical analysis of the importance of historical effective sample features from different types of industrial internet data. For the first The original feature values ​​of each feature dimension. For the first The dynamic adjustment coefficients for each feature dimension; where the dimension decomposition value For data number The single-dimensional feature values ​​obtained after calculating the core feature extraction formula for multimodal heterogeneous data in each feature dimension are the basic units constituting the core feature values ​​of the data; the core features of the data are composed of the core feature values ​​of the data. and the decomposition values ​​of each dimension Together they constitute a whole-part relationship, with core data feature values. It is the sum of the decomposition values ​​of each dimension, that is The core characteristic attributes representing the overall data, dimensional decomposition values The core feature attributes that represent a single feature dimension of the data, and the combination of the two, completely represent all the core features of the data.

[0009] Furthermore, in the construction of the mapping rule base, the trusted space access permission is the permitted scope for a sharing entity to access, read, and use industrial internet data. Access permission levels are divided based on industrial information security protection standards and data sensitivity. Sensitive dimensions are categorized for the core data features, which consist of core feature values ​​and their decomposed values. These are divided into basic attribute dimensions, business association dimensions, and privacy / confidentiality dimensions. Basic attribute dimensions cover core data feature values ​​corresponding to basic information such as data source and format. Business association dimensions cover core data feature values ​​corresponding to business information such as production process association and equipment collaboration association. Privacy / confidentiality dimensions cover core data feature values ​​corresponding to confidential information such as trade secrets and technical parameters. Based on the security requirements of different sensitive dimensions in the industrial information security protection standards, basic weights are assigned to each sensitive dimension, with privacy / confidentiality dimensions having the highest basic weight, followed by business association dimensions, and basic attribute dimensions having the lowest. The comprehensive weight of each sensitive dimension is then obtained through a comprehensive weight formula. The access permission level corresponding to the data is determined based on the combination of the comprehensive weights of each sensitive dimension, and the corresponding encryption type is matched according to the access permission level. The comprehensive weight formula for the sensitive dimensions is as follows: ,in, For the first The combined weight of each sensitive dimension, These correspond to the basic attribute dimension, business association dimension, and privacy and confidentiality dimension, respectively. For the first The basic weights of each sensitive dimension This represents the total number of feature dimensions. For the core features of the data dimensional decomposition values In the Contribution in each sensitive dimension, based on The correlation analysis of each sensitive dimension was used to determine this.

[0010] Furthermore, in the construction of the mapping rule base, the storage structure of the dynamic mapping rule base is divided into a feature association table, a permission-encryption mapping table, and a parameter configuration table. The feature association table stores the correspondence between core data features and sensitive dimensions. The permission-encryption mapping table stores the binding rules between access permission levels and encryption types. The parameter configuration table stores the configuration information of weight parameters, feature matching thresholds, and standard values ​​of each feature dimension. The access permission levels are divided into four levels: basic access permission, general access permission, advanced access permission, and administrator access permission. The encryption types include symmetric encryption and asymmetric encryption. Basic access permission and general access permission correspond to symmetric encryption, while advanced access permission and administrator access permission correspond to asymmetric encryption.

[0011] Furthermore, in the dynamic mapping, based on the decomposition values ​​of each dimension in the recognition result, combined with the standard values ​​of each dimension of the features of similar data in the dynamic mapping rule base, the feature matching degree is calculated through a feature matching algorithm. The feature matching degree is compared with the feature matching threshold. If it is greater than or equal to the feature matching threshold, the matching is determined to be successful, and the corresponding access permission level and encryption type are retrieved from the permission-encryption mapping table. If it is less than the feature matching threshold, the matching is determined to be unsuccessful, and a secondary recognition mechanism is initiated to readjust the dynamic adjustment coefficient for core feature extraction. If the feature matching threshold is still not met after the secondary recognition, the corresponding data is marked as non-shareable data, stored in a preset isolated data storage unit, and log information such as data identifier, collection time, matching result, and deviation value is recorded.

[0012] Furthermore, in the dynamic mapping, the calculation formula for the feature matching algorithm is: ,in, For feature matching degree, The first core feature of the data Decomposition values ​​of each dimension The first characteristic Standard values ​​for each dimension The weight is the combined weight of the sensitive dimensions, that is, the weight of the current traversal. The comprehensive weight of the sensitivity dimension corresponding to each feature dimension; when From 1 to When traversing all feature dimensions, Following the The sensitive dimensions to which each feature dimension belongs are simultaneously switched to the comprehensive weight value of the corresponding sensitive dimension, ensuring that the feature matching degree calculation matches the sensitive attributes of each feature dimension. For the first The weights of each feature dimension.

[0013] Furthermore, in the secure sharing process, identity verification is achieved through a multi-factor authentication mechanism, including account password verification, device fingerprint verification, and dynamic password verification. The account password is encrypted and stored using SHA-256, the device fingerprint is generated based on a unique hardware identifier, and the dynamic password is updated every 60 seconds. Subjects with access rights must pass the three verifications in sequence to obtain the decryption key.

[0014] On the other hand, an industrial internet data security sharing system based on trusted space, which includes: Data acquisition module: Integrates distributed data acquisition nodes of industrial Internet, and acquires multimodal heterogeneous data such as sensor monitoring data, equipment operation log data and production process control data in real time through industrial Ethernet, and performs preprocessing to form a multimodal heterogeneous data set; Adaptive recognition module: Receives multimodal heterogeneous data sets, uses adaptive recognition technology to analyze the structural and semantic features of the multimodal heterogeneous data, adjusts parameters in real time according to the feature differences of different types of data, extracts the core features of each type of data, completes the recognition of data validity and authenticity, and obtains the recognition results; Mapping rule base construction module: Builds a dynamic mapping rule base for recognition results and trusted space access permissions and encryption strategies. It includes the correspondence between core data features and access permission levels and encryption types, and presets feature matching thresholds and standard values ​​for each dimension. Dynamic mapping module: It calls the dynamic mapping rule base, combines the recognition results, calculates the feature matching degree through the feature matching algorithm, compares it with the feature matching threshold, determines the corresponding access permission level and encryption type, completes the real-time binding of the recognition results and the trusted space, and obtains the binding result; Secure sharing execution module: Based on the binding results, grant access rights to the corresponding trusted space to eligible sharing entities, execute the matched encryption type to encrypt the data, and only allow entities with the corresponding permissions and verified identity to access the encrypted data.

[0015] Compared with existing technologies, this industrial internet data security sharing method and system based on trusted space has the following advantages: I. This invention constructs an industrial internet standard data feature template library, assigns initial weight values ​​based on the differences in feature dimensions of different types of data, and then adjusts the dynamic adjustment coefficients according to the deviation between the original feature values ​​and the standard core feature range to complete the extraction of core data features and the identification of validity. This process can achieve accurate identification for the characteristics of multimodal heterogeneous data, effectively distinguish between valid and abnormal data states, provide a reliable identification basis for the subsequent trusted sharing of data, and ensure that all data entering the sharing process is valid and trustworthy data.

[0016] Second, this invention establishes a dynamic mapping rule base that includes a feature association table, a permission-encryption mapping table, and a parameter configuration table. This base associates core data features with sensitive dimensions and then uses a feature matching algorithm to compare the data with preset standard features. When a match is successful, the corresponding access permissions and encryption type are retrieved. When a match fails, a secondary identification mechanism is initiated. This process achieves dynamic and precise binding of data features with permissions and encryption strategies, ensuring that highly sensitive data receives strong security protection while enabling efficient circulation of ordinary data, forming a complete and trustworthy sharing closed loop.

[0017] Other advantages, objectives and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination or study, or may be learned from the practice of the invention. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.

[0019] Figure 1 A flowchart of an industrial internet data security sharing method based on trusted space; Figure 2 A framework diagram of an industrial internet data security sharing system based on trusted space; Figure 3 This is a flowchart of the dynamic mapping process in the industrial internet data security sharing method based on trusted space. Detailed Implementation

[0020] To further illustrate the technical means and effects of the present invention in achieving its intended purpose, the following detailed description of the specific implementation methods, structures, features, and effects of the present invention, in conjunction with the accompanying drawings and preferred embodiments, is provided below.

[0021] Example: In the industrial internet data sharing scenario of the final assembly workshop of a large automobile manufacturing enterprise, the workshop needs to achieve cross-departmental secure sharing of three types of data: welding robot operation status, painting production line environmental monitoring, and vehicle assembly process control. This involves four sharing entities: the production management department, equipment maintenance department, supply chain collaboration department, and visitor display department. Distributed acquisition nodes located at key nodes of the welding stations, painting lines, and final assembly lines are integrated to acquire textual data from welding robot operation logs, time-series data generated by temperature and humidity sensors on the painting production line, and structured control data from vehicle assembly process records in real time via industrial Ethernet. Preprocessing is performed on the three types of multimodal heterogeneous data: duplicate welding robot operation log entries are removed, painting sensor data lacking key monitoring parameters is filtered out, and the three types of data are uniformly converted into a common data format according to a preset format conversion protocol, ultimately forming a standardized multimodal heterogeneous data set, such as... Figure 1 As shown.

[0022] Based on a standardized multimodal heterogeneous dataset, targeted data identification is conducted using adaptive recognition technology. Feature dimension processing is performed on three types of data within the multimodal heterogeneous dataset to remove invalid character noise from welding robot operation logs and electromagnetic interference noise from coating sensor data. The original feature values ​​of each data feature dimension are extracted, and initial weights are assigned to each feature dimension according to data type. For time-series coating sensor data, the initial weight of the time dimension feature is higher than other dimensions; for text-based robot operation log data, the initial weight of the semantic dimension feature is higher than other dimensions; and for structured assembly control data, the initial weight of the field association dimension feature is higher. In other dimensions; based on the robot log data from the workshop's nearly one year of normal operation, the abnormal painting sensor data, and the standardized vehicle assembly process data, an industrial internet standard data feature template library is constructed. The library stores the standard core feature ranges of various data types according to three categories: text, time-series, and structured data. The deviation between the current data's original feature value and the standard core feature range of similar data in the industrial internet standard data feature template library is calculated. Based on the deviation, a dynamic adjustment coefficient is adjusted to optimize feature extraction accuracy. Then, the core feature values ​​of the data are calculated using the multimodal heterogeneous data core feature extraction formula. The multimodal heterogeneous data core feature extraction formula is as follows: ,in, These are the core feature values ​​of the data. This represents the total number of feature dimensions. For the first The weights of each feature dimension are determined based on statistical analysis of the importance of historical effective sample features from different types of industrial internet data. For the first The original feature values ​​of each feature dimension. For the first The dynamic adjustment coefficients for each feature dimension; the core data features are composed of core feature values ​​and decomposed values ​​of each dimension. It is determined whether the core feature values ​​fall within the standard core feature range of similar data in the Industrial Internet standard data feature template library, thereby completing a comprehensive identification of data validity and authenticity, and obtaining the final identification result, such as... Figure 2 As shown.

[0023] Next, a dynamic mapping rule base is constructed to associate the recognition results with trusted space access permissions and encryption strategies. This dynamic mapping rule base contains the correspondence between core data features and access permission levels and encryption types, and also presets feature matching thresholds and standard values ​​for each dimension. The storage structure of this dynamic mapping rule base is divided into three parts: a feature association table, a permission-encryption mapping table, and a parameter configuration table. The feature association table specifically stores the correspondence between core data features and sensitive dimensions. The permission-encryption mapping table specifically stores the binding rules between four levels of access permissions and two encryption types: symmetric encryption and asymmetric encryption. The parameter configuration table specifically stores the configuration information of weight parameters, feature matching thresholds, and standard values ​​for each feature dimension. Among them, the access permission levels are divided into four levels: basic access permission, general access permission, advanced access permission, and administrator access permission. Basic access permission and general access permission correspond to symmetric encryption, and advanced access permission and administrator access permission correspond to asymmetric encryption. First, the specific definition of trusted space access permissions is clarified, that is, the total number of access permissions in the workshop is... The scope of permissions for entities to access, read, and use industrial internet data is defined, with four levels of access control based on industrial information security protection standards and the sensitivity of the data itself. Sensitive dimensions are categorized based on the core characteristics of the identified data, into three categories: basic attribute dimensions, business association dimensions, and privacy / confidentiality dimensions. Basic attribute dimensions cover core data feature values ​​corresponding to basic information such as data source and data format; business association dimensions cover core data feature values ​​corresponding to business information such as production process association and equipment collaboration association; and privacy / confidentiality dimensions cover core data feature values ​​corresponding to confidential information such as welding process core parameters and coating / assembly parties. Based on the security requirements for different sensitive dimensions in industrial information security protection standards, basic weights are assigned to each sensitive dimension, with the privacy / confidentiality dimension having the highest basic weight, followed by the business association dimension, and the basic attribute dimension having the lowest. The comprehensive weight of each sensitive dimension is then calculated using a comprehensive weight formula: ,in, For the first The combined weight of each sensitive dimension, These correspond to the basic attribute dimension, business association dimension, and privacy and confidentiality dimension, respectively. For the first The basic weights of each sensitive dimension This represents the total number of feature dimensions. For the core features of the data dimensional decomposition values In the Contribution in each sensitive dimension, based on The access permission level is determined by correlation analysis of each sensitive dimension; the access permission level is determined by the combination of the comprehensive weights of each sensitive dimension, and then the corresponding encryption type is matched according to the access permission level.

[0024] The pre-built dynamic mapping rule base is invoked, and combined with the recognition results, a feature matching algorithm is used to accurately calculate the feature matching degree. The calculation formula for the feature matching algorithm is as follows: ,in, For feature matching degree, The first core feature of the data Decomposition values ​​of each dimension The first characteristic Standard values ​​for each dimension The weighting is based on the sensitivity dimensions. For the first The weights of each feature dimension are calculated; the calculated feature matching degree is compared with the preset feature matching threshold in the rule base. If the feature matching degree is greater than or equal to the feature matching threshold, the match is considered successful, and the access permission level and encryption type corresponding to the standard feature are retrieved from the permission-encryption mapping table. If the feature matching degree is less than the feature matching threshold, the match is considered unsuccessful, and a secondary recognition mechanism is immediately initiated. The dynamic adjustment coefficient is readjusted, and the core feature is extracted again. After the secondary recognition, the feature matching degree is recalculated and compared with the feature matching threshold again. If the feature matching threshold requirement is still not met, the corresponding data is marked as non-shareable data, stored in an isolated data storage unit, and the log information of data identification, collection time, matching result, and deviation value is fully recorded. Finally, the real-time binding of the recognition result and the trusted space is completed, and the binding result is obtained, such as... Figure 3 As shown.

[0025] Based on the binding results, qualified sharing entities are granted access privileges for the corresponding trusted space. Specifically, the Production Management Department is granted administrator access, the Equipment Maintenance Department is granted advanced access, the Supply Chain Collaboration Department is granted general access, and the Visitor Display Department is granted basic access. Data is encrypted according to the matching encryption type based on the binding results. Administrator and advanced access permissions correspond to asymmetric encryption, while general and basic access permissions correspond to symmetric encryption. Each sharing entity must sequentially pass a multi-factor authentication mechanism involving account password verification, device fingerprint verification, and dynamic password verification. Account passwords are encrypted using SHA-256, device fingerprints are generated based on the unique identifier of the workshop terminal hardware, and dynamic passwords are updated every 60 seconds. Only sharing entities that pass all three authentications can obtain the decryption key, and only these entities with the corresponding permissions are allowed to access the encrypted data.

[0026] In summary, to address the cross-departmental sharing needs of three types of multimodal heterogeneous data—welding robot operation logs in the automotive manufacturing final assembly workshop, sensor monitoring on the painting production line, and vehicle assembly process control—adaptive recognition is used to accurately determine the validity and authenticity of the data. A dynamic mapping rule base is used to accurately match core data features with access permissions and encryption types. Combined with a multi-factor authentication mechanism, data access security is ensured. Ultimately, differentiated data sharing among multiple entities such as the production management department and the equipment maintenance department is achieved. This ensures both the secure control of confidential information such as welding process parameters and meets the reasonable data usage needs of various departments, promoting the safe and efficient flow of industrial internet data in the workshop.

[0027] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.

Claims

1. A method for secure data sharing in the industrial internet based on trusted spaces, characterized in that: The specific steps of this method are as follows: Data Acquisition: Integrates distributed data acquisition nodes of the Industrial Internet, and acquires multimodal heterogeneous data such as sensor monitoring data, equipment operation log data and production process control data in real time through industrial Ethernet, and performs preprocessing to form a multimodal heterogeneous data set; Adaptive Recognition: Based on a multimodal heterogeneous dataset, adaptive recognition technology is used to analyze the structural and semantic features of the multimodal heterogeneous data. Parameters are adjusted in real time according to the feature differences of different data types to extract the core features of each data type, thereby completing the identification of data validity and authenticity, and obtaining the recognition results. The formula for extracting the core features of multimodal heterogeneous data is: ,in, For the core feature values ​​of the data, This represents the total number of feature dimensions. For the first Weights of each feature dimension, For the first The original feature values ​​of each feature dimension. For the first Dynamic adjustment coefficients for each feature dimension; Mapping rule base construction: A dynamic mapping rule base is built to link identification results with trusted space access permissions and encryption strategies. This base includes the correspondence between core data features and access permission levels and encryption types, and presets feature matching thresholds and standard values ​​for each dimension. In the construction of the mapping rule base, trusted space access permissions define the permitted scope for shared entities to access, read, and use industrial internet data. Access permission levels are determined based on industrial information security protection standards and data sensitivity. Sensitive dimensions are defined for the core data features, which consist of core feature values ​​and decomposed values ​​of each dimension: basic attribute dimensions, business association dimensions, and privacy / confidentiality dimensions. Based on the security requirements of different sensitive dimensions in industrial information security protection standards, basic weights are assigned to each sensitive dimension. A comprehensive weight formula for each sensitive dimension is then used to obtain the comprehensive weight of each sensitive dimension. The access permission level corresponding to the data is determined based on the combination of the comprehensive weights of each sensitive dimension, and then the corresponding encryption type is matched according to the access permission level. The comprehensive weight formula for the sensitive dimension is: ,in, For the first The combined weight of each sensitive dimension, These correspond to the basic attribute dimension, business association dimension, and privacy and confidentiality dimension, respectively. For the first The basic weights of each sensitive dimension This represents the total number of feature dimensions. For the core features of the data dimensional decomposition values In the Contribution in each sensitive dimension; Dynamic mapping: The dynamic mapping rule base is invoked, and combined with the recognition results, a feature matching algorithm is used to calculate the feature matching degree. This degree is then compared with the feature matching threshold to determine the corresponding access permission level and encryption type. This completes the real-time binding of the recognition results to the trusted space, yielding the binding result. The calculation formula for the feature matching algorithm is: ,in, For feature matching degree, The first core feature of the data Decomposition values ​​of each dimension The first characteristic Standard values ​​for each dimension The weighting is based on the sensitivity dimensions. For the first Weights of each feature dimension; Secure sharing execution: Based on the binding results, grant access rights to the corresponding trusted space to eligible sharing entities, encrypt the data using the matched encryption type, and allow only entities with the corresponding permissions and verified identity to access the encrypted data.

2. The industrial internet data security sharing method based on trusted space according to claim 1, characterized in that, In the data acquisition process, the preprocessing steps for multimodal heterogeneous data are as follows: identifying and removing duplicate data in the multimodal heterogeneous data, filtering out data with missing fields through data integrity verification, and dividing the filtered data into three categories: time-series data, text data, and structured data. The corresponding data format conversion protocols are used to convert all types of data into a common data format to form a unified multimodal heterogeneous data set.

3. The industrial internet data security sharing method based on trusted space according to claim 1, characterized in that, In the adaptive recognition process, the adaptive recognition technology uses the multimodal heterogeneous data core feature extraction formula as the execution carrier. The specific steps for extracting the core features of each type of data and completing the data validity and authenticity recognition are as follows: Feature dimension processing is performed on each type of data in the multimodal heterogeneous data set to remove noise interference information and extract the original feature values ​​of each feature dimension. Initial values ​​are assigned to the weights of each feature dimension according to the data type. An industrial internet standard data feature template library is constructed based on historically normal operating sensor data, abnormal equipment logs, and standardized production process data. The standard core feature ranges of each type of data are stored according to data type. Then, the deviation value between the original feature value of the current feature dimension and the standard core feature range of similar data is calculated. Based on the deviation value, the dynamic adjustment coefficient is adjusted to optimize the feature extraction accuracy. Finally, the core feature value of the data is calculated using the multimodal heterogeneous data core feature extraction formula. The core feature of the data consists of the core feature value and the decomposition values ​​of each dimension. It is then determined whether the core feature value of the data falls within the standard core feature range of similar data, thus completing the data validity and authenticity recognition.

4. The industrial internet data security sharing method based on trusted space according to claim 1, characterized in that, In the construction of the mapping rule base, the storage structure of the dynamic mapping rule base is divided into a feature association table, a permission-encryption mapping table, and a parameter configuration table. The feature association table stores the correspondence between core data features and sensitive dimensions. The permission-encryption mapping table stores the binding rules between access permission levels and encryption types. The parameter configuration table stores the configuration information of weight parameters, feature matching thresholds, and standard values ​​of each feature dimension. The access permission levels are divided into four levels: basic access permission, general access permission, advanced access permission, and administrator access permission. The encryption types include symmetric encryption and asymmetric encryption. Basic access permission and general access permission correspond to symmetric encryption, while advanced access permission and administrator access permission correspond to asymmetric encryption.

5. The industrial internet data security sharing method based on trusted space according to claim 1, characterized in that, In the dynamic mapping, based on the decomposition values ​​of each dimension in the recognition result, combined with the standard values ​​of each dimension of the features of similar data in the dynamic mapping rule base, the feature matching degree is calculated by the feature matching algorithm. The feature matching degree is compared with the feature matching threshold. If it is greater than or equal to the feature matching threshold, the matching is determined to be successful, and the corresponding access permission level and encryption type are retrieved from the permission-encryption mapping table. If the value is less than the feature matching threshold, the matching is deemed to have failed. A secondary recognition mechanism is then initiated to readjust the dynamic adjustment coefficients for core feature extraction. If the feature matching threshold is still not met after the secondary recognition, the corresponding data is marked as non-shareable data, stored in a preset isolated data storage unit, and log information including data identifier, collection time, matching result, and deviation value is recorded.

6. The industrial internet data security sharing method based on trusted space according to claim 1, characterized in that, During the secure sharing process, identity verification is achieved through a multi-factor authentication mechanism, including account password verification, device fingerprint verification, and dynamic password verification. The account password is encrypted and stored using SHA-256, the device fingerprint is generated based on a unique hardware identifier, and the dynamic password is updated every 60 seconds. Subjects with access rights must pass the three verifications in sequence to obtain the decryption key.

7. A trusted space-based industrial internet data security sharing system, the system being applicable to the trusted space-based industrial internet data security sharing method as described in any one of claims 1-6, characterized in that, The system includes: Data acquisition module: Integrates distributed data acquisition nodes of industrial Internet, and acquires multimodal heterogeneous data such as sensor monitoring data, equipment operation log data and production process control data in real time through industrial Ethernet, and performs preprocessing to form a multimodal heterogeneous data set; Adaptive recognition module: Receives multimodal heterogeneous data sets, uses adaptive recognition technology to analyze the structural and semantic features of the multimodal heterogeneous data, adjusts parameters in real time according to the feature differences of different types of data, extracts the core features of each type of data, completes the recognition of data validity and authenticity, and obtains the recognition results; Mapping rule base construction module: Builds a dynamic mapping rule base for recognition results and trusted space access permissions and encryption strategies. It includes the correspondence between core data features and access permission levels and encryption types, and presets feature matching thresholds and standard values ​​for each dimension. Dynamic mapping module: It calls the dynamic mapping rule base, combines the recognition results, calculates the feature matching degree through the feature matching algorithm, compares it with the feature matching threshold, determines the corresponding access permission level and encryption type, completes the real-time binding of the recognition results and the trusted space, and obtains the binding result; Secure sharing execution module: Based on the binding results, grant access rights to the corresponding trusted space to eligible sharing entities, execute the matched encryption type to encrypt the data, and only allow entities with the corresponding permissions and verified identity to access the encrypted data.