Method for hierarchical management and storage of industrial equipment semantic data using trusted edge channel

The construction of semantic structures and encryption algorithm processing through edge computing systems solves the problem of inefficient understanding and security threats when industrial equipment data is circulated among different departments, ensuring the sovereignty of data owners.

WO2025138572A1PCT designated stage expired Publication Date: 2025-07-03JIANGNAN UNIV

Patent Information

Application Number
PCT/CN2024/095870
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-27
Filing Date
2024-05-29
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

When industrial equipment data is circulated between different departments and enterprises, there are problems such as low efficiency in understanding the meaning of data, security threats and loss of data owner sovereignty.

Method used

The semantic data hierarchical management storage method of industrial equipment using a trusted edge channel is used to construct semantic structure data through an edge computing system, perform encryption algorithm processing, and design data access strategies for trusted resources to ensure the sovereignty of the data owner.

Benefits of technology

It realizes the rapid understanding of the meaning of data during data transmission, improves work efficiency, and ensures data security and owner's control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024095870_03072025_PF_FP_ABST
    Figure CN2024095870_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of multi-source heterogeneous data processing. Disclosed is a method for hierarchical management and storage of industrial equipment semantic data using a trusted edge channel. In the present invention, the semantic structure of equipment data is defined, and when the data is transmitted, a file having the semantic structure is carried, and after receiving the data, a receiver can quickly learn the meaning of the data on the basis of the semantic file, thereby accelerating the work efficiency; moreover, on the basis of the storage method, a data access policy for trusted resources is designed, so as to ensure the sovereignty of a data owner over shared data.
Need to check novelty before this filing date? Find Prior Art

Description

Hierarchical management and storage method for semantic data of industrial equipment using trusted edge channel

[0001] A hierarchical management and storage method for industrial equipment semantic data using trusted edge channels Technical Field

[0002] The present invention relates to a hierarchical management and storage method for semantic data of industrial equipment using a trusted edge channel, and belongs to the technical field of multi-source heterogeneous data processing. Background Art

[0003] Industrial equipment data includes data from control devices, instruments, sensors, and other equipment distributed throughout the factory. This data may belong to different stages, such as design, manufacturing, and management. Data from different stages often have different meanings and formats, forming heterogeneous data sources. Usually, there is a corresponding relationship between these heterogeneous data. When these heterogeneous data circulate among different departments of an enterprise and between enterprises, due to the different experience and knowledge required, staff often cannot quickly understand the meaning of the data, resulting in reduced work efficiency and even production accidents due to incorrect understanding of the data.

[0004] In addition, when industrial equipment data circulates between different departments of an enterprise and between enterprises, there are security threats such as privacy leakage and data tampering. Existing data sharing solutions cannot guarantee the data sovereignty of data owners. When data is sent out, physical control over the data is lost.

[0005] Summary of the Invention

[0006] In order to solve the problems existing in the current storage and circulation of industrial equipment data, the present invention provides a method for hierarchical management and storage of industrial equipment semantic data using a trusted edge channel, the method comprising:

[0007] Step 1: Real-time collection of equipment operating status data x(t i ) and set the corresponding experience threshold;

[0008] Step 2: Use edge computing system to i The device operation status data x(t i ) constructs semantic structure data, and then obtains the semantically encoded sensor signal X(t i );

[0009] Step 3: The edge computing system calculates X(t i) executes the core encryption algorithm to generate the device core data Y(t i ), and Y(t i ) is stored in the original database DB1;

[0010] Step 4: The edge computing system collects the device operation status data x(t i ) performs calculations and extracts the corresponding statistical eigenvalues ​​T(t i ), and the statistical eigenvalue T(t i ) to obtain the corresponding health index value, and compare the health index value with the pre-set experience threshold for diagnosis. When the health index value is higher than the threshold, the edge computing system will perform principal component analysis on X(t i ) executes important encryption algorithm processing to generate important device data G(t i ), and G(t i ) is stored in the fault database DB2;

[0011] Step 5: The edge computing system calculates the time from t1 to t m The equipment operation status data x(t i ) calculate the corresponding statistical characteristic values ​​and construct the equipment life cycle sequence T S ={T(t1), T(t2), T(t3),...T(t m )}, then T S The corresponding semantically encoded sensor signal X(t i ) performs data cleaning and desensitization processing to obtain desensitized data Qs, uses a general encryption algorithm to process Qs, generates device general data Ms, and stores Ms in the desensitized database DB3, so that the device general data Ms can be traded with external enterprises.

[0012] Optionally, step 2 includes:

[0013] Step 2.1: Construct an industrial concept ontology and design an original database. The concept ontology includes four categories: equipment, personnel, and parts and tools. Each ontology includes several entities, each of which has object attributes and data attributes. The object attributes refer to its relationship with other entities, and the data attributes refer to the characteristics of the entity itself. The original database stores the object attributes and data attributes corresponding to each entity.

[0014] Step 2.2, determine the mapping relationship between the industrial concept ontology and the original database;

[0015] Step 2.3, according to the mapping relationship t i The equipment operation status data x(t i ) constructs semantic structure data and encapsulates it in json, which is defined as the semantically encoded sensor signal X(ti ).

[0016] Optionally, when the device general data Ms is traded with an external enterprise, the method includes:

[0017] Step S1: Create the desensitized data Qs as a trusted resource, create a resource offer for the desensitized data Qs as a data carrier, and assign a unique ID to the resource offer;

[0018] Step S2: Create a data access policy, which includes the number of uses, the usage time, and whether to charge;

[0019] Step S3: Establish a correspondence between the ID of each resource offer and the data access policy;

[0020] Step S4: Access the data in the resource offer according to the ID and the corresponding data access policy.

[0021] Optionally, setting a corresponding experience threshold in step 1 includes:

[0022] Set the data processing period Δt;

[0023] Extract the equipment operation status data x(t i ) corresponding to the statistical eigenvalue T(t i )={T1(t i ), T2(t i ),…,T m (t i )}, m is the number of statistical features;

[0024] The principal component analysis method was used to analyze T(t i ) is analyzed to obtain q statistical features that can characterize the fault change characteristics as the main component features, and the corresponding weights are set. The q main component features are recorded as T p (t i ), the corresponding weight is recorded as a p , p=1,2,…,q;

[0025] The health index value HI corresponding to the equipment operating status data sequence within the data processing period Δt is calculated according to the following formula t ;

[0026] Among them, Y p (t i ) is the principal component feature T obtained by principal component analysis method to characterize the fault change characteristics p (ti ) corresponds to the transformed features.

[0027] The 3σ principle is used to determine each empirical threshold: (|HI t -μ|>4σ)&(|HI t-1 -μ|>3σ)&(|HI t-2 -μ|>3σ)

[0028] in,

[0029] μ——the average value of the health index of the equipment operation status data sequence from 0 to t-3;

[0030] σ——The standard deviation value of the health indicator of the equipment operating status data sequence from 0 to t-3.

[0031] Optionally, in step 5, T S Data cleaning processing includes selecting subsets, renaming column names, deleting duplicate values, processing missing values, consistency processing, data sorting processing and outlier processing.

[0032] Optionally, the general encryption algorithm in step 5 is the Base64 algorithm.

[0033] Optionally, the core encryption algorithm in step 3 is the asymmetric encryption algorithm RSA.

[0034] Optionally, in step 4, X(t i ) performs calculations and extracts the corresponding statistical eigenvalues ​​T(t i ),include:

[0035] Step 4.1: Obtain the equipment operation status data x(t i );

[0036] Step 4.2, calculate the corresponding statistical characteristic value according to each statistical characteristic formula;

[0037] Step 4.3, store the calculated statistical characteristic value T(t i ).

[0038] Optionally, the important encryption algorithm in step 4 is the DES algorithm.

[0039] The present application also provides a hierarchical management and storage method for heterogeneous data, which adopts the above method for management and storage.

[0040] The beneficial effects of the present invention are:

[0041] By defining the semantic structure of industrial equipment data, files with semantic structures will be carried during data transmission. After receiving the data, the recipient can quickly understand the meaning of the data based on the semantic files, thereby improving work efficiency. Based on this storage method, a data access strategy for trusted resources is designed to ensure the sovereignty of data owners over shared data. Furthermore, this application provides a method for setting empirical thresholds. For different equipment operating status data, the principal component analysis method is used to determine the statistical features that best reflect the fault characteristics, thereby obtaining more accurate fault data. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0043] Figure 1 is a schematic diagram of the hierarchical management and storage mode of semantic data of industrial equipment using edge computing.

[0044] Figure 2 is a diagram of the bearing operation and maintenance data ontology model.

[0045] FIG3 is an example diagram of object attributes and data attributes of industrial equipment data.

[0046] Figure 4 is an example diagram of bearing instance data attributes.

[0047] Figure 5 is a diagram of the mapping principle.

[0048] FIG6A is a flowchart of RSA algorithm encryption.

[0049] FIG6B is a flowchart of RSA algorithm decryption.

[0050] Figure 7 is a DES encryption flow chart.

[0051] FIG8 is a schematic diagram of the key iteration process of the DES encryption algorithm.

[0052] FIG9 is a schematic diagram of a trusted resource framework. DETAILED DESCRIPTION

[0053] To make the objectives, technical solutions and advantages of the present invention more clear, the embodiments of the present invention will be described in further detail below with reference to the accompanying drawings.

[0054] Example 1:

[0055] This embodiment provides a method for hierarchical management and storage of semantic data of industrial equipment using a trusted edge channel, including:

[0056] Step 1: Real-time collection of equipment operating status data x(t i ) and set the corresponding experience threshold;

[0057] When setting the corresponding empirical threshold, first set the data processing period Δt;

[0058] Extract the equipment operation status data x(t i ) corresponding to the statistical eigenvalue T(t i )={T1(t i ), T2(t i ),…,T m (t i )}, m is the number of statistical features;

[0059] The principal component analysis method was used to analyze T(t i ) is analyzed to obtain q statistical features that can characterize the fault change characteristics as the main component features, and the corresponding weights are set. The q main component features are recorded as T p (t i ), the corresponding weight is recorded as a p , p=1,2,……,q;

[0060] The health index value HI corresponding to the equipment operating status data sequence within the data processing period Δt is calculated according to the following formula t ;

[0061] Among them, Y p (t i ) is the principal component feature T obtained by principal component analysis method to characterize the fault change characteristics p (t i ) corresponds to the transformed features.

[0062] The 3σ principle is used to determine each empirical threshold: (|HI t -μ|>4σ)&(|HI t-1 -μ|>3σ)&(|HI t-2 -μ|>3σ)

[0063] in,

[0064] μ——the average value of the health index of the equipment operation status data sequence from 0 to t-3;

[0065] σ——The standard deviation value of the health indicator of the equipment operating status data sequence from 0 to t-3.

[0066] Step 2: Use edge computing system to i The device operation status data x(t i) constructs semantic structure data, and then obtains the semantically encoded sensor signal X(t i ), the semantically encoded sensor signal X(t i ) as the original data;

[0067] Raw data is usually stored in the form of key-value pairs. For example:

[0068] {

[0069] No.: GDZC_0001_202312150805

[0070] Collection time: 2023-12-15 08:05

[0071] Collect data: x(t i )

[0072] Collection device: ZJJ_A001

[0073] }

[0074] Step 3: The edge computing system calculates X(t i ) executes the core encryption algorithm to generate the device core data Y(t i ), and Y(t i ) is stored in the original database DB1;

[0075] Step 4: The edge computing system collects the device operation status data x(t i ) performs calculations and extracts the corresponding statistical eigenvalues ​​T(t i ), and the statistical eigenvalue T(t i ) to obtain the corresponding health index value, and compare the health index value with the pre-set experience threshold for diagnosis. When the health index value is higher than the threshold, the edge computing system will perform principal component analysis on X(t i ) executes important encryption algorithm processing to generate important device data G(t i ), and G(t i ) is stored in the fault database DB2;

[0076] For X(t i ) performs calculations and extracts the corresponding statistical eigenvalues ​​T(t i )include:

[0077] Obtain the equipment operating status data x(t i );

[0078] According to each statistical characteristic formula, calculate the corresponding statistical characteristic value;

[0079] Store the calculated statistical characteristic value T(t i).

[0080] The statistical features involved in this application include time domain features and frequency domain features. The statistical features in the time domain and the corresponding calculation formulas are as follows:

[0081] 1. Absolute Mean (AM)

[0082] 2. Root Mean Square (RMS)

[0083] 3. Square root magnitude (SMR)

[0084] 4. Peak: Peak=max|x i |

[0085] 5. Skewness

[0086] 6. Kurtosis

[0087] 7. Variance (Var)

[0088] 8. Kurtosis index (K f )

[0089] 9. Peak Index (C)

[0090] 10. Pulse indicator (I f )

[0091] 11. Waveform indicator (S f )

[0092] While time-domain signals can demonstrate the overall trend of normal operation, they lack detailed information, making it difficult to determine the type of fault, resulting in low precision. Frequency-domain analysis can obtain more detailed fault information. Fourier transform of the signal reveals the frequency composition of the spectrum and the amplitude of each frequency. The Fourier transform formula is shown below.

[0093] Assume that the original vibration signal of the bearing is x i (i=1,2,……N), which is converted into spectrum signal y after FFT transformation k (k=1,2,….,M), M represents the length of the spectrum signal, r k is the frequency amplitude, f kRepresents the frequency value.

[0094] Statistical features in the frequency domain include:

[0095] 1. Spectral mean

[0096] 2. Spectral root mean square (R rms )

[0097] 3. Spectral value skewness (F l )

[0098] 4. Spectral maximum (R max ) R max =max{r(t)}

[0099] 5. Spectral minimum (R min ) R min =min{r(t)}

[0100] 6. Spectral frequency root mean square (F3)

[0101] 7. Spectral value variance (σ 2 )

[0102] 8. Spectral amplitude root square amplitude

[0103] Step 5: The edge computing system calculates the time from t1 to t m The equipment operation status data x(t i ) calculate the corresponding statistical characteristic values ​​and construct the equipment life cycle sequence T S ={T(t1), T(t2), T(t3),...T(t m )}, then T S The corresponding semantically encoded sensor signal X(t i ) performs data cleaning and desensitization processing to obtain desensitized data Qs, uses a general encryption algorithm to process Qs, generates device general data Ms, and stores Ms in the desensitized database DB3, so that the device general data Ms can be traded with external enterprises.

[0104] Example 2:

[0105] This embodiment provides a method for hierarchical management and storage of semantic data of industrial equipment using a trusted edge channel. Referring to FIG1 , the method includes:

[0106] Step 1: Real-time collection of equipment operating status data x(t i) and set the corresponding experience threshold;

[0107] For the vulnerable and consumable fault parts of different workshops and different types of industrial equipment in the enterprise, corresponding sensors are installed to collect real-time equipment operation status data x(t i ), t i The equipment operating status data x(t i ) is transmitted to the edge computing system; x(t i ) means t i The device operating status data at all times.

[0108] Some examples of sensor installation information are as follows:

[0109] 1) Bearing seat equipment: Install the acceleration sensor and set the acceleration experience threshold Z l ;

[0110] 2) Gearbox equipment: Install the acceleration sensor and set the acceleration experience threshold C l ;

[0111] 3) Flow pump equipment, install flow sensor, and set flow experience threshold L1;

[0112] 4) For boiler equipment, install a temperature sensor and set the temperature experience threshold T1;

[0113] The various experience threshold settings include:

[0114] Set the data processing period Δt;

[0115] Extract the equipment operation status data x(t i ) corresponding to the statistical eigenvalue T(t i )={T1(t i ), T2(t i ),…,T m (t i )}, m is the number of statistical features; statistical features are time domain features and frequency domain features, where the statistical features in the time domain include: absolute mean (AM), root mean square (RMS), root square magnitude (SMR), peak (Peak), skewness (Skewness), kurtosis (Kurtosis), variance (Var), kurtosis index (K f ), peak index (C), waveform index (S f ).

[0116] Among the above indicators, kurtosis index, peak index, pulse index, and waveform index represent dimensionless indicators, while absolute mean, root mean square, root square amplitude, peak, skewness, kurtosis, etc. are dimensional indicators.

[0117] Statistical features in the frequency domain include: spectrum mean Spectrum RMS (R rms ), spectrum value skewness (F l ), spectrum maximum (R max ), spectrum minimum (R min ), spectrum frequency root mean square (F3), spectrum value variance (σ 2 ) and the spectral root square amplitude.

[0118] An analysis of the proposed features revealed that some features could not express the degradation information of the equipment well, and the large number of features resulted in data redundancy. Therefore, principal component analysis was used to reduce the dimension of the features and obtain the principal component feature that best expressed the degradation law as the health indicator HI.

[0119] The principal component analysis method is used to analyze the above time domain features and frequency domain features, and q statistical features that can characterize the fault change characteristics are obtained as principal component features. The corresponding weights are set, and q principal component features are recorded as T p (t i ), the corresponding weight is recorded as a p , p=1,2,……,q;

[0120] Specifically, the purpose of principal component analysis is to compress multiple variables into a few comprehensive indicators (called principal components), so that the comprehensive indicators can contain the main information of the original multiple variables. The process of obtaining the principal component characteristics through principal component analysis is as follows:

[0121] Input feature data T={T1,T2,…,T m}

[0122] 1) Remove the mean value, subtract the mean value of each input feature;

[0123] 2) Calculate covariance

[0124] 3) Use the eigenvalue decomposition method to find the eigenvalues ​​and eigenvectors of the covariance;

[0125] 4) Sort the eigenvalues ​​of the covariance from largest to smallest and select the largest q as the principal element features. Then use their corresponding eigenvectors as the rows to form the eigenvector matrix P;

[0126] 5) The feature data is converted into a new space constructed by q feature vectors to obtain the converted feature vector, that is, Y = PT.

[0127] According to experience, the q principal element eigenvectors Y after transformation into the new space p (t i ) Set the corresponding weight a p .

[0128] Different data types have different statistical characteristics that characterize fault variations. For example, the root mean square (RMS) measures vibration intensity and is therefore more sensitive to bearing surface cracks, reflecting the overall bearing degradation trend. Peak effectively reflects the impact characteristics of bearing signals and is more sensitive to early-stage surface spalling. Skewness measures the symmetry of the probability density function. Kurtosis describes the degree of bearing failure. When Kurtosis = 3, the bearing is healthy. When Kurtosis > 3, the bearing has failed. The remaining indicators can demonstrate normal operating conditions from different perspectives.

[0129] Therefore, this application uses the principal component analysis method to analyze the above statistical features to obtain q statistical features that can characterize the fault change characteristics, and sets the corresponding weights based on experience. The value of q can be set by technical personnel.

[0130] The health index value HI corresponding to the equipment operating status data sequence within the data processing period Δt is calculated according to the following formula t ;

[0131] Among them, Y p (t i ) is the principal component feature T obtained by principal component analysis method to characterize the fault change characteristics p (t i ) corresponds to the transformed features.

[0132] The 3σ principle is used to determine each empirical threshold: (|HI t -μ|>4σ)&(|HI t-1 -μ|>3σ)&(|HI t-2 -μ|>3σ)

[0133] in,

[0134] μ——the average value of the health index of the equipment operation status data sequence from 0 to t-3;

[0135] σ——The standard deviation value of the health indicator of the equipment operating status data sequence from 0 to t-3.

[0136] Step 2: Use edge computing system to i The sensor signal x(t i ) constructs semantic structure data, and then obtains the semantically encoded sensor signal X(t i ).

[0137] Because edge computing systems access diverse data sources, the collected data may include vibration signals, temperature signals, flow signals, and other signals. These signals have different units and structures and come from different collection points. Edge computing system data typically also includes channel types and data source information. This complex information often requires professional interpretation.

[0138] To solve this problem, the present invention uses edge computing technology to analyze the collected data and the domain knowledge involved in this data, extract its concepts, attributes, and the relationship between concepts, and integrate the resources related to the data to provide a basis for the regular storage of data. Ontology is the basis for building an industrial data knowledge base and can store different data in different ways. The conceptual connections between ontologies can express the semantic relationship between data-related fields, and the efficient application of enterprise data domain knowledge can be achieved through the management of this semantics.

[0139] The edge computing system in this invention requires the pre-construction of a conceptual ontology and a design original database, and the establishment of a mapping relationship between the two. Taking bearing seat data as an example, the resource ontology model related to the extracted bearing vibration data is shown in Figure 2.

[0140] As shown in Figure 2, the resources involved in the industry are abstracted into four major categories: equipment, personnel, parts, and tools. Each major category lists several subcategories. Each ontology contains several entities, as shown in the first three columns of blocks in Figure 2. There are many instances in the corresponding entities. To save space, only a few instances are listed, as shown in the last column of blocks in Figure 2. Each entity has object attributes and data attributes. Object attributes refer to its relationship with other entities. For example, the object attributes of the entity represented by the bearing in Figure 2 include: being monitored by sensors, being installed on a bending machine, etc. Data attributes refer to the characteristics of the entity itself, such as name, size, and other information. As shown in Figure 3, for example, the data attributes of the bearing in Figure 2 include: speed, temperature, size, life, etc.

[0141] Taking the bearing entity as an example, in the ontology model, the data attributes of one of the instances are shown in Figure 4. The data attributes include basic information such as the id ZC_20231129, the size is 20 mm, the material is Q238, the manufacturer is Jiangnan Bearing Manufacturing Plant, the life is 80, and the temperature is 40 degrees Celsius. The object attributes include that the acceleration sensor corresponding to the bearing is fz acceleration sensor 001, that is, the data collected by fz acceleration sensor 001 is the acceleration information corresponding to the bearing; it also includes the equipment where it is located, including the total assembly machine, etc.

[0142] First, in order to facilitate storage and reuse in subsequent processes, the defined ontology model will be saved as a read-only file in the form of OWL (OWL is used to describe Resource Description Framework (RDF) data. It is essentially a collection of predefined vocabularies used to define similar classes and their properties for RDF) or XML. Each type of ontology element in the file has a specific URI for identification; in the bearing ontology, the entity ontology and the operation ontology have a non-overlapping relationship, while the diagnosis belongs to the operation ontology and the bearing belongs to the entity ontology.

[0143] Next, we designed the original database and used the D2RQ tool to conveniently map the original database tables to ontology concepts. The mapping rule is that each table corresponds to an entity, column names are mapped to entity attributes, and table data corresponds to an instance. The specific mapping principle is shown in Figure 5. For example, the bearing table corresponds to the bearing entity. The field names in the bearing table, such as size, temperature, and weight, correspond to the data attributes of the bearing entity. The relationship between the bearing table and the equipment table corresponds to the relationship between the entities.

[0144] When t i The sensor signal x(t i ) is collected and entered into the edge computing system. When the event occurs, the mapping relationship between the concept ontology and the original database in the edge computing system of the present invention is activated, and then the semantic structure data is automatically constructed in the edge computing system, and the semantic structure data is encapsulated in json and defined as the semantically encoded sensor signal X(t i ).

[0145] Taking bearing entity data as an example, the encapsulation rules are as follows:

[0146] Step 3: The edge computing system calculates X(t i ) executes the core encryption algorithm to generate the device core data Y(t i ), and Y(t i ) is stored in the original database DB1, and the database is supervised by the enterprise data responsible person. i ) When supervised by the enterprise data responsible person, it is necessary to deploy the relevant configuration and decryption program on the receiving side.

[0147] The present invention uses the RSA algorithm encryption and decryption process shown in Figures 6A and 6B to encrypt the device core data.

[0148] The steps of the RSA algorithm are as follows:

[0149] Step 1 Generate a key

[0150] Select two large prime numbers p and q, p≠q. Calculate the product

[0151] N=p×q

[0152] Get the Euler function

[0153] Choose a random integer e such that and

[0154] calculate

[0155] d is the modulus of e The multiplicative inverse of

[0156] The public key is (e,n) and the private key is (d,n).

[0157] Step 2 Encrypted Information

[0158] The sender encrypts the message X(t i ): Y(t i )=X(t i ) e Mod(n)

[0159] Where Y(t i ) is the ciphertext generated after encryption.

[0160] Step 3: Decrypt the information

[0161] The receiver decrypts the ciphertext Y(t i ): X(t i )=Y(t i ) d Mod(n)

[0162] Where X(t i ) is the information before encryption.

[0163] The symbols and variables involved in the steps of the RSA algorithm are defined as follows:

[0164] (1) Modulo operation

[0165] For any positive integer n and integer x, there exist integers r and t such that x = tn + r, which can be expressed in modular form as r = x Mod n. For example, suppose x = 15 and n = 7. Since x = tn + r, 15 = 2*7 + 1, so t = 2, r = 1, and r = x Mod n, the modular form is 15 Mod 7 = 1.

[0166] (2)Co-prime GCD

[0167] Suppose t is a common factor of two integers n and x. There exists an expression GCD(n,x)=t. The meaning of the expression is that any common factor of n and x must be a factor of t. If GCD(n,x)=1, that is, t=1, the integers n and x are called coprime numbers.

[0168] (3) Euler function

[0169] The Euler function is defined in the range of positive integers. The value of the function is equal to the number of numbers from 0 to n-1 that are prime to n. This series of positive integers is called the Euler function of n, which is denoted by Euler's Theorem: For positive integers n and x, GCD(n,x) = 1, that is, the greatest common divisor of n and x is 1, n and x are coprime numbers, there must exist Here It is called the Euler function, which is the number of numbers that are less than x and coprime to x. Another equivalent formula of the Euler function is:

[0170] Step 4: The edge computing system collects the equipment operation status data x(t i ) performs calculations and extracts the corresponding statistical eigenvalues ​​T(t i ), and the statistical eigenvalue T(t i ) is compared with the corresponding empirical threshold for diagnosis. When the statistical characteristic value T(t i ) is higher than the threshold, the edge computing system processes the device operation status data x(t i ) corresponding to X(t i ) executes important encryption algorithm processing to generate important device data G(t i ), and G(t i ) is stored in the fault database DB2, and then the blockchain technology is combined to automatically publish the evidence information on the chain to the enterprise shared cloud. The data responsible person of the department to which the equipment belongs accesses the fault database DB2 through the enterprise shared cloud. When the manual diagnosis is t m =t i When a fault occurs, t m The fault label at the moment is recorded in the original database, and when the manual diagnosis is t i When the fault is a false fault, delete the data in the enterprise shared cloud. i The corresponding on-chain evidence information at the moment, and delete the corresponding encrypted data G(t i ).

[0171] The present invention uses the DES encryption process shown in Figure 7 to encrypt important device data. The DES algorithm has three input parameters: Key, Data, and Mode. The Key is 8 bytes, totaling 64 bits, and is the working key of the DES algorithm. 8 bits of it are used as check bits, so the actual key is 56 bits. The Data is also 8 bytes and is the data to be encrypted or decrypted. The Mode is the DES working mode, encryption or decryption. At both ends of the communication network, both parties agree on a consistent Key, which is encrypted using DES at the source. The data then arrives at the communication endpoint in the form of ciphertext, and the ciphertext is then decrypted using the Key.

[0172] The steps of the DES algorithm are as follows:

[0173] Step 1: Generation of subkeys

[0174] The 64-bit key is permuted, ignoring the 8th bit of each byte. The DES key is reduced from 64 bits to 56 bits. The 56-bit key is divided into two parts. The first 28 bits C0 = K 57 K 49 ………K 52 K 44 K 36 , the last 28 bits D0 = K 63 K 55 ...K 20 K 12 K4. Then, according to the round number i (which is an integer between 1 and 16), C i and D i Experience LS i Circular left shift 1 or 2 bits, according to the left shift rules in Table 1, a total of 16 circular shifts. i and D i After compression and permutation, the subkey K is obtained i .

[0175] Table 1 Left shift rules

[0176] Step 2 Iteration process

[0177] The iterative process divides the result obtained in the previous step into L i and R i , let each round of encryption key be K i The iterative process is shown in Figure 8. Among them, the round key K i is 48 bits, and the round input is R i-1 is 32 bits, R i-1 First it is expanded to 48 bits, where R i-1 The 16 bits of the subkey K are repeated once. The expanded 48 bits are then combined with the subkey K iAn XOR operation is performed, and then processed through an encryption function F (the function is to convert 6-bit data into 4-bit data) to produce a 32-bit output.

[0178] Step 3: Inverse permutation

[0179] After 16 iterations, we get L 16 and R 16 , take this as input, perform inverse permutation, and get the ciphertext output M. The expression of M is as follows: M=D1D2…………………D 63 D 64

[0180] Step 4 Decryption

[0181] The decryption process is the reverse process of the encryption process, swapping the initial and final transposition tables: the first time using the subkey K 16 , the second time with K 15 , and so on, the ciphertext can be decrypted.

[0182] Step 5: The edge computing system performs the following operations on t1 to t m The equipment operation status data x(t i ) calculate the corresponding statistical characteristic values ​​and construct the equipment life cycle sequence T S ={T(t1), T(t2), T(t3),...T(t m )}, then T S After completing the data cleaning process of seven steps (selecting subsets, renaming column names, deleting duplicate values, handling missing values, consistency processing, data sorting processing, and outlier processing), and performing desensitization processing to remove sensitive information, the data Qs is obtained. The general encryption algorithm is then used to process Qs to generate the general device data Ms, which is then stored in the desensitized database DB3. Finally, after the data exchange confirms the asset ownership of Ms, it is uploaded to the platform transaction cloud to achieve docking with external companies and data transactions.

[0183] According to the equipment operation status data x(t i ) respectively calculate the corresponding statistical eigenvalues ​​T(t i ), specifically, the corresponding statistical characteristic value T(t i ), and then construct the equipment life cycle sequence T S ={T(t1), T(t2), T(t3),...T(t m )}, for T SAfter completing the data cleaning process of the seven steps, desensitization processing is performed to remove sensitive information to obtain data Qs. Qs is processed using a general encryption algorithm to generate device general data Ms, and Ms is stored in the desensitized database DB3.

[0184] The present invention uses the general encryption algorithm Base64 to encrypt the general data of the device after cleaning and desensitization. This algorithm is a relatively simple encryption algorithm and is suitable for situations where the confidentiality strength is not high.

[0185] The steps of the Base64 algorithm are as follows:

[0186] Step 1: Convert the given data Qs into the corresponding character code (ASCII) in characters.

[0187] Step 2 converts the obtained character code into binary code;

[0188] Step 3: Group the obtained binary codes into groups of three 8-bit binary codes, and convert them into groups of four 6-bit binary codes (if the number is less than 6, the low bit is padded with 0);

[0189] Step 4: Fill the obtained 4-6 binary code by adding two high-order 0s to the 6-bit binary code to form four 8-bit binary codes;

[0190] Step 5: Convert the obtained 4-8 binary code into decimal code;

[0191] Step 6 converts the obtained decimal code into the data Ms of the corresponding character in the Base64 character table;

[0192] Step 7 stores the encrypted data Ms into the desensitized database DB3 to facilitate subsequent transaction transmission.

[0193] Before the transaction, the data will be created as a trusted resource. Data shared as a trusted resource can guarantee the data sovereignty of the data owner. The creation and transaction process is shown in Figure 9.

[0194] Step 1: Create a resource offer as a data carrier. The created offer will have a unique href id, for example:

[0195] After creating the resource carrier corresponding to the bearing, the system will give a successful creation response. The response contains the basic properties of the resource carrier, such as creation date, title, description, etc. The most important of these is the unique ID of the resource carrier, which is stored in:

[0196] "_links":{

[0197] "self":{

[0198] "href":"https: / / localhost:8080 / api / offers / 619266ed-11b7-46b9-8033-4396f6a7b2e9"

[0199] }, through the id, the resource carrier can be searched in the resource system to obtain the corresponding data.

[0200] After creating an offer, create a catalog and link it to the offer to facilitate resource retrieval.

[0201] Step 2: Create a resource contract:

[0202] First, create a policy. A policy is a data access policy, which includes usage times, usage time, and whether to charge. Different usage rules can be selected by using different strings. The details are as follows:

[0203] [CONNECTOR_RESTRICTED_USAGE,DURATION_USAGE,N_TIMES_USAGE,PROHIBIT_ACCESS,PROVIDE_ACCESS,PatternDesc,SECURITY_PROFILE_RESTRICTED_USAGE,USAGE_DURING_INTERVAL,USAGE_LOGGING,USAGE_NOTIFICATION,USAGE_UNTIL_DELETION];

[0204] For example, if you select "type":"N_TIMES_USAGE" and "value":"5" when creating a policy, the "ids:constraint" in the response contains the usage restriction policy specified by the policy. Its rightPerand is 5, indicating that the policy stipulates that the resource can only be accessed five times.

[0205] Create a contract. This contract requires negotiation before data can be retrieved. The contract is then linked to the policy, linking the contract to the corresponding offer. There are many other types of restrictions, such as usage duration restrictions: "type": "USAGE_DURING_INTERVAL", "start": "2020-07-11T00:00:00Z", "end": "2020-07-11T00:00:00Z", etc.

[0206] Step 3 Add data and data description

[0207] After linking the offer and contract together in Step 2, a complete offer is formed. However, this offer is not bound to any data. We need to add the data we need to trade to the offer.

[0208] First, create an artifact. The transaction data can be bound to the artifact. The data can be a specified value, a URL resource, or an address in the database (a SQL access statement needs to be specified).

[0209] After the artifact is created, the corresponding data can be found by searching the href of the offer.

[0210] After completing all steps, update the offer in the system and share it with the data pool. The recipient can obtain the data carried in the offer by negotiating the contract.

[0211] Some steps in the embodiments of the present invention may be implemented using software, and the corresponding software program may be stored in a readable storage medium, such as a CD or a hard disk.

[0212] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for hierarchical management and storage of semantic data of industrial equipment using a trusted edge channel, characterized in that The method includes: Step 1, collect the real-time operation status data x(t i ), and set the corresponding empirical threshold; Step 2: Use an edge computing system to process the device operation status data x(t i transmitted at time t i ) to construct semantic structure data, and then obtain the sensor signal X(t i ) after semantic encoding; Step 3, the edge computing system performs core encryption algorithm processing on X(t i ) to generate device core data Y(t i ), and stores Y(t i ) in the original database DB1; Step 4, the edge computing system performs operation processing on the collected device operation status data x(t i ) to extract the corresponding statistical feature value T(t i ), and performs principal component analysis on the statistical feature value T(t i ) to obtain the corresponding health index value. The health index value is compared with a pre-set empirical threshold for diagnosis. When the health index value is higher than the threshold, the edge computing system performs important encryption algorithm processing on X(t i ) to generate the important device data G(t i ), and stores G(t i ) in the fault database DB2; Step 5: The edge computing system performs the calculation from t1 to t m The equipment operation status data x(t i ) calculate the corresponding statistical characteristic values ​​and construct the equipment life cycle sequence T S ={T(t1), T(t2), T(t3),...T(t m )}, then T S The corresponding semantically encoded sensor signal X(t i ) performs data cleaning and desensitizing processing to obtain desensitized data Qs, uses a general encryption algorithm to process Qs, generates device general data Ms, and stores Ms in a desensitizing database DB3 so that the device general data Ms can be traded with external enterprises.

2. The method according to claim 1, wherein Step 2 includes: Step 2.1, construct an industrial concept ontology and design an original database; the concept ontology includes four categories: equipment, personnel, parts, and tools. Each ontology includes several entities, and each entity has object properties and data properties; the object properties refer to its relationships with other entities, and the data properties refer to the characteristics of the entity itself; the original database stores the object properties and data properties corresponding to each entity; Step 2.2, determine the mapping relationship between the industrial concept ontology and the original database; Step 2.3, construct semantic structure data for the device operating state data x(t i at time i ), perform JSON encapsulation, and define it as the sensed signal X(t i ) after semantic encoding.

3. The method according to claim 1, characterized in that When the method conducts data transactions on the general equipment data Ms with external enterprises, it includes: Step S1, create the desensitized data Qs as a trusted resource, create a resource offer for the desensitized data Qs as a data carrier, and assign a unique id to the resource offer; Step S2, create a data access policy, and the data access policy includes the number of uses, usage time, and whether to charge; Step S3, establish the correspondence between the id of each resource offer and the data access policy; Step S4, according to the id, access the data in the resource offer according to the corresponding data access policy.

4. The method according to claim 1, wherein In step 1, setting the corresponding empirical threshold includes: Set the data processing period Δt; Extract the device operation status data x(t i ) corresponding to the statistical eigenvalue T(t i ) = {T1(t i ), T2(t i ), …, T m (t i ), where m is the number of types of statistical features; The principal component analysis method is used to analyze T(t i ) to obtain q statistical features that can characterize the fault change characteristics as the principal component features, and the corresponding weights are set. The q principal component features are denoted as T p (t i ), and the corresponding weights are denoted as a p , where p = 1, 2, …, q; Calculate the health index value HI corresponding to the device operation status data sequence within the data processing period Δt according to the following formula t ; Among them, Y p (t i ) is the principal component feature T that can characterize the fault change characteristics obtained by the principal component analysis method p (t i ) corresponding to the transformed feature; Adopt the 3σ principle to determine each empirical threshold: (|HI t -μ|>4σ)&(|HI t-1 -μ|>3σ)&(|HI t-2 -μ|>3σ) Wherein, μ — the average value of the health indicators of the equipment operation status data sequence in the 0 - t - 3 segment; σ — the standard deviation value of the health indicators of the equipment operation status data sequence in the 0 - t - 3 segment.

5. The method according to claim 1, characterized in that In step 5, for T S Performing data cleaning processing includes subset selection, column name renaming, duplicate value deletion, missing value handling, normalization processing, data sorting processing, and outlier handling.

6. The method according to claim 1, characterized in that In step 5, the general encryption algorithm is the Base64 algorithm.

7. The method according to claim 1, characterized in that In step 3, the core encryption algorithm is the asymmetric encryption algorithm RSA.

8. The method according to claim 4, wherein In step 4, perform arithmetic processing on X(t i ) to extract the corresponding statistical feature value T(t i ), including: Step 4.1, obtain the device operation status data x(t) collected within the data processing period Δt i ); Step 4.2, calculate the corresponding statistical feature values according to each statistical feature formula; Step 4.3, store the calculated statistical feature value T(t i ).

9. The method according to claim 1, characterized in that, In step 4, the important encryption algorithm is the DES algorithm.

10. A hierarchical management and storage method for heterogeneous data, characterized in that, The method adopts the method described in any one of claims 1 - 9 for management and storage.

Citation Information

Patent Citations

  • Intelligent service application platform and method for multi-source heterogeneous data fusion

    CN107193858A

  • Semantic data lake construction method for multi-source heterogeneous data

    CN111221785A

  • Fusion management architecture for multi-source heterogeneous industrial data

    CN114911870A

  • Unified ontology connection query method, medium and system based on multi-source heterogeneous data

    CN116541414A

  • Industrial equipment semantic data hierarchical management storage method adopting trusted edge channel

    CN117827947A

Cited By

  • Industrial scene-oriented multi-protocol compatible IoT (Internet of Things) acquisition and intelligent operation and maintenance system

    CN121567745A