Secure industrial data transmission method based on international data space

By building an industrial data management system and encryption processing method, the problem that data providers find it difficult to judge the trustworthiness of the requester is solved, and secure and trustworthy data transmission and enhanced privacy are achieved to ensure the secure use of data in the industrial Internet of Things.

WO2025148431A1PCT designated stage expired Publication Date: 2025-07-17CHONGQING UNIV OF POSTS & TELECOMM
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/123620
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-01-11
Filing Date
2024-10-09
Publication Date
2025-07-17

AI Technical Summary

Technical Problem

In the industrial Internet of Things, it is difficult for data providers to judge the credibility of data requesters, and there are security risks of data being improperly used and illegally invaded. There are potential vulnerabilities in the International Data Space (IDS) ecosystem, and it is difficult to rely entirely on it to provide a secure data sharing environment.

Method used

Build an industrial data management system in the production workshop, including MetaData Broker, industrial data providers and consumers, deploy IDS connectors, use AES encryption and Base64 encoding to process data, establish an end-to-end transmission channel through gRPC services, generate and manage keys, and follow IDS interactive contracts for data transmission.

Benefits of technology

Provide a secure and trustworthy data transmission environment, ensure data sovereignty and controllability, improve the difficulty of key theft and ciphertext deciphering, and enhance data privacy and use security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024123620_17072025_PF_FP_ABST
    Figure CN2024123620_17072025_PF_FP_ABST
Patent Text Reader

Abstract

A secure industrial data transmission method based on an international data space, which method belongs to the technical field of industrial Internet-of-Things data security. The method comprises: constructing a production workshop industrial data management system, receiving from MetaData Broker an industrial data request that is sent by an IDS connector of an industrial data consumer, and forwarding the industrial data request to a target IDS connector corresponding to a target industrial data provider; the target IDS connector performing identity authentication, and if the identity authentication is successful, the target industrial data provider calling a corresponding data resource on the basis of the industrial data request, and performing AES encryption processing and BASE64 code conversion on the called data resource, so as to obtain request resource data; and the IDS connector following a formulated interaction contract to complete data transmission, and the industrial data consumer performing reverse processing on the received request resource data, so as to obtain an original data resource. The method can provide a secure and trusted transmission environment.
Need to check novelty before this filing date? Find Prior Art

Description

A secure industrial data transmission method based on international data space Technical Field

[0001] The present invention belongs to the field of industrial Internet of Things data security technology, and specifically relates to an industrial data security transmission method based on international data space. Background Art

[0002] With the increasing adoption of Industrial IoT technology in production workshops, massive amounts of process data are being collected in real time and stored locally on edge nodes. To further unlock the value of this data, external data consumers often request data from data providers for secondary development and utilization. However, this process can pose security risks. For example, when a data request is made, it can be difficult for the data provider to determine whether the requester is trustworthy. Once a data connection is established, the data provider's data could be misused and the provider could be illegally hacked.

[0003] The International Data Space (IDS), an open-source technology proposed by Germany, provides an effective solution for the secure use of industrial data. IDS aims to build a secure and trusted data-sharing system where all authenticated participants can realize the full value of their data. As an emerging technology, IDS has been applied in some scenarios, but its ecosystem is still undergoing continuous optimization and updating, and potential vulnerabilities and risks may exist, making it difficult for users to fully rely on IDS services. Therefore, additional security measures are needed to further enhance the security of data use.

[0004] Summary of the Invention

[0005] In response to the shortcomings of the existing technology, the present invention proposes a method for secure industrial data transmission based on international data space, which can provide a secure and reliable transmission environment for both parties of data interaction, ensure the controllability of data sovereignty, and prevent improper use of data; optimize key generation and management measures, increase the difficulty of key theft and ciphertext deciphering; avoid the plaintext transmission of industrial sensitive data, and enhance data privacy and usage security.

[0006] The specific plan includes the following steps:

[0007] S1. Build an industrial data management system for production workshops, which includes industrial data providers, industrial data consumers, and an international data space;

[0008] Furthermore, step S1 of constructing a production workshop industrial data management system includes:

[0009] S11. Building an international data space based on production workshop industrial data, the international data space including MetaData Broker;

[0010] S12. Deploy IDS connectors at the industrial data provider and industrial data consumer, respectively. The IDS connectors of the industrial data provider and industrial data consumer register information with the MetaData Broker.

[0011] S13. Deploy the gRPC server framework corresponding to the gRPC service at the industrial data provider, and deploy the client framework corresponding to the gRPC service at the industrial data consumer;

[0012] S2. The industrial data consumer sends an industrial data request to the MetaData Broker through the IDS connector. The MetaData Broker searches the industrial data request and, if the search is successful, executes step S3; otherwise, the industrial data request is rejected.

[0013] S3. MetaData Broker forwards the industrial data request to the target IDS connector corresponding to the target industrial data provider; the target IDS connector authenticates the industrial data request. If the authentication succeeds, step S4 is executed; otherwise, the industrial data request is rejected.

[0014] S4. The target industrial data provider calls the corresponding data resource according to the industrial data request, performs AES encryption on the called data resource, and performs Base64 encoding conversion on the encrypted data resource to obtain the requested resource data that complies with the IDS communication protocol;

[0015] S5. The target IDS connector at the target industrial data provider transmits the requested resource data to the IDS connector at the industrial data consumer according to the established interaction contract;

[0016] S6. The industrial data consumer uses the gRPC service to reverse process the received request resource data to obtain the original data resource.

[0017] Furthermore, the IDS connector at the industrial data provider follows the protocols and rules specified by the IDS and registers existing data resources with data templates that comply with the IDS transmission protocol; during the data transmission process, the IDS connector at the industrial data provider generates an interaction contract for IDS connector interaction between the industrial data provider and the industrial data consumer.

[0018] Furthermore, in step S2, MetaData Broker searches for the industrial data request, including: MetaData Broker queries its own IDS connector registry. If the IDS connector registry records the identification ID of the IDS connector of the industrial data consumer that sends the industrial data request, and records the identification ID of the target IDS connector of the target industrial data provider corresponding to the industrial data request, it indicates that the retrieval is successful; otherwise, it indicates that the retrieval fails.

[0019] Furthermore, step S4 also includes the target industrial data provider generating a key γ based on the identification ID of the target IDS connector and its own MAC value. The specific process is as follows:

[0020] S41. The target industrial data provider extracts the identification ID of the target IDS connector and denotes it as α;

[0021] S42. The target industrial data provider randomly generates a salt value, combines the salt value with its own MAC value, and processes the combined result using a hash function to obtain a salted MAC value, which is recorded as β;

[0022] S43. Calculation Processed using the SHA-256 algorithm Get the key γ.

[0023] Furthermore, in step S4, the AES encryption algorithm model is used to perform AES encryption processing on the called data resource. The AES encryption algorithm model is expressed as:

[0024] C=E(K,X)

[0025] Where C represents the encrypted data resource, E represents the encryption function, K represents the key γ, and X represents the data resource called by the target industrial data provider according to the industrial data request;

[0026] In step S4, the Base64 encoding model is used to perform Base64 encoding conversion on the called data resource. The Base64 encoding model is expressed as:

[0027] H=T(C)

[0028] Where H represents the requested resource data after Base64 encoding conversion, and T represents the Base64 encoding function.

[0029] Furthermore, in step S6, the industrial data consumer performs reverse processing on the received request resource data in conjunction with the gRPC service to obtain the original data resource, including:

[0030] S61. Get the key:

[0031] S611. The IDS connector of the industrial data consumer sends a query message to the MetaData Broker. The MetaData Broker searches the IDS connector registry for the identification ID of the target industrial data provider, records the identification ID as α, and then sends α to the IDS connector of the industrial data consumer.

[0032] S612. The industrial data consumer obtains the salted MAC value processed by the target industrial data provider through the request and response of the gRPC service, and records the salted MAC value as β;

[0033] S613. Use the SHA-256 algorithm to process α and β to generate the key γ;

[0034] S62. Ciphertext format conversion: Base64 de-encoding model is used to perform Base64 de-encoding conversion on the requested resource data. The Base64 de-encoding model is represented as follows:

[0035] C=T * (H)

[0036] Where H represents the requested resource data, T* represents the Base64 decompression function, and C represents the requested resource data after Base64 decompression conversion.

[0037] S63. Reverse decryption: AES decryption algorithm model is used to perform AES decryption processing on the requested resource data after the ciphertext format conversion. The AES decryption algorithm model is expressed as:

[0038] X=E * (K,C)

[0039] Among them, X represents the original data resource, E * Represents the AES decryption function, and K represents the key γ.

[0040] Furthermore, a gRPC transmission channel is constructed between the gRPC client deployed by the industrial data consumer and the gRPC server deployed by the target industrial data provider. In step S612, the gRPC client deployed by the industrial data consumer sends a gRPC service request, and the gRPC server deployed by the target industrial data provider receives the gRPC service request. If the gRPC server successfully responds to the gRPC service request, the target industrial data provider sends the salted MAC value β to the industrial data consumer through the gRPC transmission channel.

[0041] Beneficial effects of the present invention:

[0042] The present invention utilizes the unique and complete authentication and communication mechanism of IDS technology to provide a secure and reliable transmission environment for both data producers and data consumers, which can effectively ensure the controllability of data sovereignty and prevent improper use of data; based on the application of IDS technology, it adds encryption processing of transmission messages to improve the data interaction process of IDS; introduces end-to-end transmission technology to optimize key generation and management measures, increases the difficulty of key theft and ciphertext decryption, and further improves the security of data use. With the actual production and manufacturing workshop as the background, the present invention, based on existing industrial Internet of Things, IDS, end-to-end transmission and other technologies, proposes a method for enhancing the security of IDS data transmission, providing a secure and reliable data transmission environment for both the data source side and the data application side, with low deployment difficulty and good portability, and can be widely used in industrial scenarios where data security needs to be guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] FIG1 is a flowchart of a process for enhancing IDS data transmission security in the present invention;

[0044] FIG2 is a flow chart of IDS connector deployment in the present invention. DETAILED DESCRIPTION

[0045] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0046] The present invention provides a method for secure transmission of industrial data based on an international data space, as shown in FIG1 , comprising the following steps:

[0047] S1. Build an industrial data management system for production workshops, which includes industrial data providers (also called providers), industrial data consumers (also called consumers), and international data spaces (Industrial Data Space, IDS).

[0048] IDS has an open-source and mature technical framework, and its localized deployment must comply with specific rules and processes. IDS connectors are key functional controls for data interaction in IDS. To complete data requests and transmissions, IDS connectors need to be deployed in a distributed manner on both the consumer and provider sides for data management.

[0049] Furthermore, step S1 of constructing a production workshop industrial data management system includes:

[0050] S11. Construct an international data space based on the industrial data of the production workshop, wherein the international data space includes a MetaData Broker.

[0051] S12. Deploy IDS connectors at the industrial data provider and the industrial data consumer respectively. The IDS connector of the industrial data provider and the IDS connector of the industrial data consumer respectively register information with the MetaData Broker.

[0052] Specifically, as shown in FIG2 , step S12 deploys an IDS connector at the industrial data provider, including:

[0053] A121. Check the server and network environment;

[0054] A122. Create a data producer file directory and load the data file to be sent (i.e., existing data resources);

[0055] A123. Install and deploy the Docker environment;

[0056] A124. Pull the IDS image;

[0057] A125. Deploy the IDS developer project source code;

[0058] A126. Configure the docker-compose file for the industrial data provider;

[0059] A127. Create a hosts file and configuration data routing file for mounting to the container;

[0060] A128. Wait for the remote Consumer to start;

[0061] A129. Start third-party credit service and connector service.

[0062] Specifically, as shown in FIG2 , step S12 deploys an IDS connector at the industrial data consumer, including:

[0063] B121. Check the server and network environment;

[0064] B122. Create a data consumer file directory;

[0065] B123. Install and deploy the Docker environment;

[0066] B124. Pull the IDS image;

[0067] B125. Deploy the IDS developer project source code;

[0068] B126. Configure the docker-compose file for the industrial data provider;

[0069] B127. Configure the host name and data routing file;

[0070] B128. Start third-party credit service and connector service.

[0071] Specifically, the identification ID of the IDS connector is generated during the deployment phase. The identification ID is unique and different between IDS connectors.

[0072] Specifically, after successful deployment, IDS connectors cannot directly interact with each other or establish data transmission channels. They must be registered with the MetaData Broker and have it forward requests before communication can proceed. The MetaData Broker is an essential functional module within the IDS, primarily responsible for forwarding, registering, and querying information. In this technical solution, the key element α, which constitutes the key γ, can be obtained from the MetaData Broker, the identifier of the IDS connector on the Proviser side.

[0073] Specifically, the IDS connector of the industrial data provider registers information with the MetaData Broker, including:

[0074] The industrial data provider sends the relevant attribute information of the IDS connector to the MetaData Broker through a POST request. The MetaData Broker reviews the relevant attribute information. If the review is passed, the registration is successful, and some information of the IDS connector will be saved in the MetaData Broker, including the identification ID of the IDS connector. If the review fails, the MetaData Broker will return a failure value.

[0075] S13. Deploy the gRPC server-side framework corresponding to the gRPC service at the industrial data provider, and deploy the gRPC service client-side framework corresponding to the gRPC service at the industrial data consumer.

[0076] By deploying the server-side framework and client-side framework corresponding to the gRPC service on the industrial data provider and industrial data consumer respectively, an end-to-end gRPC transmission channel is established. The salted MAC value β is transmitted through the gRPC transmission channel to assist in the transmission and management of the key γ. In this technical solution, the gRPC service implementation steps are as follows:

[0077] 1) Define a service interface. For example, you can define a product service with two methods: add product and get product. The product corresponds to the MAC value processed by the provider in this technical solution, that is, β;

[0078] 2) Generate server and client, compile the code used to generate gRPC server and gRPC client, including data types, network pipelines, etc.

[0079] 3) Implement the service and implement all the methods previously defined in the service interface on the gRPC server side, that is, how to load β into the gRPC framework and how the gRPC client obtains β;

[0080] 4) Start the gRPC server. After it starts successfully, the client can connect, access, and request data.

[0081] 5) Create a gRPC client, call the corresponding service of the server through the gRPC client, and obtain the key component β from the provider side through the gRPC transmission link.

[0082] Specifically, IDS has its own unique communication standards. To ensure uniformity during data transmission, the provider-side IDS connector must register local data resources as data templates that conform to the IDS transmission protocol. Data transmission requests that do not conform to the template will be rejected. Furthermore, the provider-side IDS connector generates an interaction contract for inter-connector interaction. Providers and consumers can complete resource exchange within the terms of this interaction contract.

[0083] S2. The industrial data consumer sends an industrial data request to the MetaData Broker through the IDS connector. The MetaData Broker searches the industrial data request. If the search is successful, step S3 is executed; otherwise, the industrial data request is rejected.

[0084] Specifically, based on actual production and processing needs, the Consumer sends the industrial data request to the MetaData Broker via the IDS connector. The MetaData Broker searches the industrial data request, including: MetaData Broker queries its own IDS connector registry. If the IDS connector registry records the identification ID of the industrial data requester and the target industrial data provider's IDS connector, it means that the retrieval is successful; otherwise, it means that the retrieval fails.

[0085] Specifically, if the identification ID of the data requester's IDS connector is retrieved, it means that the requester's IDS connector has been successfully registered, that is, it has successfully joined the IDS ecosystem, so MetaData Broker will process this request. If MetaData Broker does not retrieve the identification ID of the requester's connector, it means that the requester's IDS connector has not been successfully registered and is equivalent to a "stranger" to MetaData Broker, and MetaData Broker will not process its related requests. Similarly, if MetaData Broker retrieves the identification ID of the target party's IDS connector, it means that the target party's IDS connector has been successfully registered, that is, the data consumer's data request is valid, and the object data source of the data requested by the data consumer actually exists. If MetaData Broker does not retrieve the identification ID of the target party's IDS connector, it means that the target IDS connector does not exist or has not been successfully registered, then the data consumer's data request will naturally fail because there is no data source. In summary, the identification IDs of two IDS connectors need to be retrieved for the retrieval to be successful.

[0086] S3. MetaData Broker forwards the industrial data request to the target IDS connector corresponding to the target industrial data provider; the target IDS connector performs identity authentication on the industrial data request. If the identity authentication passes, step S4 is executed; otherwise, the industrial data request is rejected.

[0087] S4. The target industrial data provider calls the corresponding data resource according to the industrial data request, performs AES encryption on the called data resource, and performs Base64 encoding conversion on the encrypted data resource to obtain the requested resource data that complies with the IDS communication protocol.

[0088] Specifically, step S4 also includes the target industrial data provider generating a key γ according to the identification ID of the target IDS connector and its own MAC value. The specific process is as follows:

[0089] S41. The target industrial data provider extracts the identification ID of the target IDS connector and records it as α; the identification ID of the IDS connector is its identity credential for interacting with other components in the IDS ecosystem. The identification ID is a valid, persistent and unique identifier and must never be reused for any other resource within the IDS ecosystem. In the present invention, the length of the identification ID is 320 bits and the representation is 80 hexadecimal characters. In the present invention, the identification ID is also called α. The following is an example of the identification ID of an IDS connector: connector_id = DD:CB:FD:0B:93:84:33:01:11:EB:5D:94:94:88:BE:78:7D:57:FC:4A:CB:8C:C7:B6:85:79:A8:23:A6:CB:15:AB:17:50:2F:E6:65:43:5D:E8

[0090] S42. The target industrial data provider randomly generates a salt value, combines the salt value with its own MAC value, and processes the combined result using a hash function to obtain a salted MAC value, which is recorded as β;

[0091] Specifically, the MAC value is 48 bits long and is displayed as 12 hexadecimal characters. An example MAC value is shown below:

[0092] MAC=00:50:56:3C:11:04

[0093] Because of the MAC value, the random string generated by the target industrial data provider, that is, the salt value, is also represented by 12 random characters, as shown below:

[0094] random_data=49:0C:29:DC:29:FD

[0095] Combine the MAC value and the salt value. Add the salt by inserting the salt value into the MAC value bit by bit. This generates a 24-character hexadecimal string with a length of 96. The combined value is as follows:

[0096] MAC_salt=04:09:50:0C:52:69:3D:CC:12:19:0F:4D

[0097] Use a suitable hash function on the combined value to generate β. This solution selects the MD5 algorithm, that is, β = MD5 (MAC_salt).

[0098] S43. Calculation Processed using the SHA-256 algorithm Get a 256-bit hash value, called the key γ, The key γ is used for subsequent encryption. The key γ is not directly transmitted over a data link. In this method, the key elements α and β used to generate the key γ are transmitted through two channels: the IDS ecosystem and the gRPC service.

[0099] Specifically, in step S4, the AES encryption algorithm model is used to perform AES encryption processing on the called data resource. The AES encryption algorithm model is expressed as:

[0100] C = E(K, X), where C represents the encrypted data resource, E represents the encryption function, K represents the key γ, and X represents the data resource accessed by the target industrial data provider in response to the industrial data request. Within the encryption function E, a round function is executed 10 times during the encryption process. The first nine rounds of execution are identical; only the tenth round differs, meaning that a single plaintext packet undergoes 10 rounds of encryption.

[0101] Using the AES encryption algorithm to encrypt transmitted data improves data security and confidentiality, preventing data leakage. However, the data after AES encryption is in byte string format, which does not meet the transmission protocol requirements of the IDS. Base64 encoding is required to convert the data into a string format.

[0102] In step S4, the Base64 encoding model is used to perform Base64 encoding conversion on the called data resource. The Base64 encoding model is expressed as:

[0103] H=T(C), where H represents the requested resource data after Base64 encoding conversion, and T represents the Base64 encoding function.

[0104] S5. The IDS connectors at the target industrial data provider and the industrial data consumer complete data transmission in accordance with the established interaction contract.

[0105] Specifically, based on the interaction contract established by the IDS connector at the industrial data consumer, the target industrial data provider transmits the requested resource data, namely the encrypted data H, to the industrial data consumer through the IDS transmission channel.

[0106] S6. The industrial data consumer performs reverse processing on the received requested resource data to obtain the original data resource.

[0107] Specifically, the data obtained by the Consumer has been processed by encryption and other means and cannot be used directly. It is necessary to follow specific steps and rules to perform reverse processing to obtain the original data. Step S6: The industrial data consumer performs reverse processing on the received request resource data to obtain the original data resource, including:

[0108] S61. Get the key:

[0109] S611. The IDS connector of the industrial data consumer sends a query message to the MetaData Broker. The MetaData Broker searches the IDS connector registry for the identification ID of the target industrial data provider, records the identification ID as α, and then sends α to the IDS connector of the industrial data consumer.

[0110] S612. The industrial data consumer obtains the salted MAC value processed by the target industrial data provider through the request and response of the gRPC service, and records the salted MAC value as β;

[0111] Specifically, the industrial data consumer sends a gRPC service request through the deployed gRPC client, and the gRPC server deployed by the target industrial data provider receives the gRPC service request. If the gRPC server successfully responds to the gRPC service request, the target industrial data provider retrieves the data β and sends it to the industrial data consumer through the gRPC transmission channel constructed between the gRPC client and the gRPC server.

[0112] S613. Use the SHA-256 algorithm to process α and β to generate the key γ;

[0113] S62. Ciphertext format conversion: The received ciphertext needs to be converted from a string format to a byte string format to meet the data format requirements of the decryption algorithm. The Base64 decoding model is used to perform Base64 decoding conversion on the requested resource data. The Base64 decoding model is represented as:

[0114] C=T * (H)

[0115] Among them, H represents the requested resource data, T * Represents the Base64 de-encoding function, and C represents the requested resource data after Base64 de-encoding conversion;

[0116] S63. Reverse decryption: AES decryption algorithm model is used to perform AES decryption processing on the requested resource data after the ciphertext format conversion. The AES decryption algorithm model is expressed as:

[0117] X=E * (K, C) where X represents the original data resource, E * Represents the AES decryption function, and K represents the key γ.

[0118] Consumers can subsequently develop and apply the acquired raw data.

[0119] In the present invention, unless otherwise clearly specified and limited, terms such as "installation", "setting", "connection", "fixation", and "rotation" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integrated connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be the internal connection of two elements or the interaction relationship between two elements. Unless otherwise clearly specified and limited, ordinary technicians in this field can understand the specific meanings of the above terms in the present invention according to specific circumstances.

[0120] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. An industrial data security transmission method based on the International Data Space, characterized in that It includes the following steps: S1. Build an industrial data management system for the production workshop, which includes industrial data providers, industrial data consumers, and the International Data Space; Furthermore, step S1 of building the industrial data management system for the production workshop includes: S11. Build the International Data Space based on the industrial data of the production workshop. The International Data Space includes a MetaData Broker; S12. Deploy IDS connectors at the industrial data provider and the industrial data consumer respectively. The IDS connectors of the industrial data provider and the industrial data consumer register information with the MetaData Broker respectively; S13. Deploy the gRPC server-side framework corresponding to the gRPC service at the industrial data provider, and deploy the gRPC client-side framework corresponding to the gRPC service at the industrial data consumer at the same time; S2. The industrial data consumer sends an industrial data request to the MetaData Broker through the IDS connector. The MetaData Broker retrieves the industrial data request. If the retrieval is successful, step S3 is executed; otherwise, the industrial data request is rejected; S3. The MetaData Broker forwards the industrial data request to the target IDS connector corresponding to the target industrial data provider; the target IDS connector authenticates the industrial data request. If the authentication is passed, step S4 is executed; otherwise, the industrial data request is rejected; S4. The target industrial data provider calls the corresponding data resources according to the industrial data request, performs AES encryption processing on the called data resources, and performs Base64 encoding conversion on the encrypted data resources to obtain request resource data that conforms to the IDS communication protocol; S5. The target IDS connector at the target industrial data provider transmits the request resource data to the IDS connector at the industrial data consumer according to the established interaction contract; S6. The industrial data consumer performs reverse processing on the received request resource data in combination with the gRPC service to obtain the original data resources.

2. The industrial data security transmission method based on the International Data Space according to claim 1, characterized in that, The IDS connector at the industrial data provider follows the protocols and rules stipulated by the IDS and registers the existing data resources as data templates that conform to the IDS transmission protocol; During the data transmission process, the IDS connector at the industrial data provider generates an interaction contract for the interaction between the IDS connectors of the industrial data provider and the industrial data consumer.

3. A method for secure industrial data transmission based on the International Data Space according to claim 1, characterized in that, In step S2, the MetaData Broker retrieves the industrial data request, including: the MetaData Broker queries its own IDS connector registry. If the IDS connector registry records the identification ID of the IDS connector of the industrial data consumer that sends the industrial data request, and records the identification ID of the target IDS connector of the target industrial data provider corresponding to the industrial data request, it means the retrieval is successful; otherwise, it means the retrieval fails.

4. The industrial data security transmission method based on the international data space according to claim 1, characterized in that, Step S4 also includes that the target industrial data provider generates a key γ according to the identification ID of the target IDS connector and its own MAC value. The specific process is as follows: S41. The target industrial data provider extracts the identification ID of the target IDS connector and denotes it as α; S42. The target industrial data provider randomly generates a salt value, combines the salt value with its own MAC value, and processes the combined result using a hash function to obtain a salted MAC value, which is denoted as β; S43. Calculation Processed using the SHA-256 algorithm The key γ is obtained.

5. A method for secure industrial data transmission based on the International Data Space according to claim 1, characterized in that, In step S4, the AES encryption algorithm model is used to perform AES encryption processing on the called data resources. The AES encryption algorithm model is expressed as: C = E(K, X) where C represents the data resource after encryption processing, E represents the encryption function, K represents the key γ, and X represents the data resource called by the target industrial data provider according to the industrial data request; In step S4, the Base64 encoding model is used to perform Base64 encoding conversion on the called data resources, and the Base64 encoding model is expressed as: H = T(C) where H represents the requested resource data after Base64 encoding conversion, and T represents the Base64 encoding function.

6. The industrial data security transmission method based on the International Data Space according to claim 1, characterized in that, In step S6, the industrial data consumer performs reverse processing on the received requested resource data in combination with the gRPC service, including: S61. Obtain the key: S611. The IDS connector of the industrial data consumer sends query information to the MetaData Broker. The MetaData Broker queries the identification ID of the target IDS connector of the target industrial data provider in the IDS connector registry according to the query information, denotes the identification ID as α, and then sends α to the IDS connector of the industrial data consumer; S612. The industrial data consumer obtains the salted MAC value processed by the target industrial data provider through the gRPC service, and denotes the salted MAC value as β; S613. Use the SHA-256 algorithm to process α and β to generate the key γ; S62. Ciphertext format conversion: Perform Base64 decoding conversion on the requested resource data using the Base64 decoding model. The Base64 decoding model is expressed as: C = T * (H) Among them, H represents the requested resource data, T * represents the Base64 decoding function, and C represents the requested resource data after Base64 decoding conversion; S63. Reverse decryption: Perform AES decryption processing on the requested resource data after ciphertext format conversion using the AES decryption algorithm model. The AES decryption algorithm model is expressed as: X = E * (K, C) Among them, X represents the original data resource, and E * represents the AES decryption function, and K represents the key γ.

7. A method for secure industrial data transmission based on the International Data Space according to claim 6, characterized in that A gRPC transmission channel is built between the gRPC client deployed by the industrial data consumer and the gRPC server deployed by the target industrial data provider. In step S612, the gRPC client deployed by the industrial data consumer sends a gRPC service request, and the gRPC server deployed by the target industrial data provider receives the gRPC service request. If the gRPC server successfully responds to the gRPC service request, the target industrial data provider sends the salted MAC value β to the industrial data consumer through the gRPC transmission channel.

Citation Information

Patent Citations

  • Privacy protection transaction method based on blockchain technology in electronic commerce

    CN108389046A

  • Industrial data services platform

    CN113075909A

  • Industrial data secure transmission method based on international data space

    CN117880324A

  • Security and confidentiality protection method and system for data transmission

    WO2021218885A1