WO2024061380A1 - 一种工业互联网数据防护系统 - Google Patents

一种工业互联网数据防护系统 Download PDF

Info

Publication number
WO2024061380A1
WO2024061380A1 PCT/CN2023/127896 CN2023127896W WO2024061380A1 WO 2024061380 A1 WO2024061380 A1 WO 2024061380A1 CN 2023127896 W CN2023127896 W CN 2023127896W WO 2024061380 A1 WO2024061380 A1 WO 2024061380A1
Authority
WO
WIPO (PCT)
Prior art keywords
data
control unit
novelty
master control
uplink data
Prior art date
Application number
PCT/CN2023/127896
Other languages
English (en)
French (fr)
Inventor
李璇
王新霞
陈意
张睿
Original Assignee
山东省信息技术产业发展研究院(中国赛宝(山东)实验室)
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 山东省信息技术产业发展研究院(中国赛宝(山东)实验室) filed Critical 山东省信息技术产业发展研究院(中国赛宝(山东)实验室)
Publication of WO2024061380A1 publication Critical patent/WO2024061380A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • H04L67/125Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks involving control of end-device applications over a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/145Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/01Protocols
    • H04L67/12Protocols specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0209Architectural arrangements, e.g. perimeter networks or demilitarized zones
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0254Stateful filtering
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02PCLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
    • Y02P90/00Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
    • Y02P90/02Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]

Definitions

  • the invention relates to the field of data protection, and in particular to an industrial Internet data protection system.
  • Each data interface corresponds to a production device, so that it can complete the communication between each production equipment and the master control unit. interactions between.
  • a production plant there are often a large number of production equipment, and when each production equipment communicates with the master control unit respectively, it will cause the master control unit to occupy a large amount of operating space for receiving data, which can generally reach 35%. -60%, so that the general control unit has less running space to use when processing and analyzing data, generally only 40%-65%, which seriously slows down the running speed.
  • a large number of data interfaces are open at the same time, making it impossible to process and analyze each data. The data of a data interface must be carefully reviewed before the data is released, so that the security of the data entering the master control unit cannot be met.
  • the purpose of the present invention is to overcome the problems existing in the above-mentioned prior art and provide an industrial Internet data
  • the edge computing method reduces the computational load of the master control unit and reduces the data interface of the master control unit to ensure data security.
  • the present invention provides an industrial Internet data protection system, including a master control unit and a plurality of edge processing units that interact with signals of the master control unit respectively;
  • the edge processing unit is used to receive data from multiple production equipment, and count the space occupied by the uplink data each time it is to be sent to the main control unit, and send the uplink data before sending the uplink data.
  • the general control unit is used to respectively receive the space occupied by the uplink data sent by each edge processing unit, and obtain the actual occupied space according to the sum of the spaces occupied by each edge processing unit. According to the operating space of the general control unit Set the quantitative relationship between the proportion of data and the actual occupied space, and obtain the proportion and number of times that the master control unit receives each of the uplink data. According to the proportion of each of the uplink data and the number of times it is received, Receive each of the uplink data, and process the received uplink data.
  • the edge processing unit includes:
  • a data sorting module arranges the uplink data in sequence according to the logical order in which the uplink data is executed in the master control unit;
  • a data splitting module used for receiving the proportion of uplink data of the edge processing unit in the master control unit and the number of times of receiving, and splitting the uplink data according to the proportion of the uplink data, and arranging the uplink sub-data in sequence after the splitting;
  • the data sending module sends the sub-uplink data to the main control unit in sequence.
  • the overall control unit includes:
  • the data scanning interface is used to scan the working status of the data interfaces in sequence, and open the corresponding data interfaces in order and keep them open within the set time;
  • the data analysis module splits the received sub-uplink data to obtain each data to be processed, and marks each data to be processed according to the first novelty of each data to be processed;
  • the data release module releases the data to be processed marked with the first novelty to the data processing part of the general control unit, and starts receiving feedback from the data processing part;
  • the data deletion module when receiving feedback from the data processing unit, sends a copy of the first data to be processed with high novelty to the data processing unit;
  • the data processing part includes a method for sending a copy of the data to be processed according to the data deletion module, searching for the received data to be processed, and deleting the data to be processed.
  • the data processing part of the general control unit completes a feedback after the data scanning interface completes a scan of the data interface.
  • the feedback is true or false.
  • the data deletion module sends a copy of the first data to be processed with high novelty to the data processing part.
  • the edge processing unit also includes:
  • a data marking module that marks the second degree of novelty based on the sub-uplink data obtained by the data splitting module
  • the data sending module packages the sub-uplink data according to the second novelty mark corresponding thereto and sends the sub-uplink data to the master control unit;
  • the data analysis module of the general control unit splits the sub-uplink data whose second novelty degree reaches the set value, or splits the sub-uplink data whose second novelty degree does not reach the set value.
  • the rows are released to the data processing department.
  • the value of the first degree of novelty is 0 or 100%
  • the value of the second degree of novelty ranges from 0 to 100%.
  • the data marking module includes the following steps:
  • Each third degree of novelty is combined with the corresponding data level to perform a weighted operation to obtain the second degree of novelty.
  • the master control unit obtains the ratio of its operating space to the occupied operating space in real time, and stops receiving the uplink data when the ratio reaches a set ratio.
  • the present invention uses edge computing to reduce the amount of calculations of the master control unit and at the same time reduce the data interface of the master control unit to ensure data security.
  • the method of edge computing is to use multiple edge processing units to share some basic work of the master control unit.
  • Each edge processor is connected to the master control unit, and each edge processor is connected to multiple production equipment.
  • the edge processor collects the information of each production equipment it is responsible for, performs a preliminary deletion of the collected information, and finally transmits the data to the master control unit.
  • the edge processor collects the information of each production equipment it is responsible for, performs a preliminary deletion of the collected information, and finally transmits the data to the master control unit.
  • the edge processor collects the information of each production equipment it is responsible for, performs a preliminary deletion of the collected information, and finally transmits the data to the master control unit.
  • the edge processor collects the information of each production equipment it is responsible for, performs a preliminary deletion of the collected information, and finally transmits the data to the master control unit.
  • the edge processor
  • the invention enables the general control unit to scan the interface of the data in sequence, so that the data to be entered is sequentially split through the data analyzer for review, and the new data is analyzed according to the effect produced by the data after it is released. Determination of the tag, when the tag is a virus, start the corresponding anti-virus program to process the data;
  • the antivirus program and data analyzer of the present invention have a running space occupancy rate of less than 5%.
  • the data is processed through tags on the data, and tags are set on the data according to the structure of the data. , so that each edge processing unit can label and set the data in advance, saving the review work of data analysis, thereby improving the security and work efficiency of the master control unit.
  • Figure 1 is a schematic block diagram of the overall structure of an industrial Internet data protection system provided by the present invention
  • FIG. 2 is a schematic block diagram of system connection of the edge processing unit of the present invention.
  • Figure 3 is a schematic block diagram of system connection of the master control unit of the present invention.
  • embodiments of the present invention provide an industrial Internet data protection system.
  • the system includes a master control unit and a plurality of edge processing units that interact with signals of the master control unit respectively.
  • the main control unit and multiple edge processing units constitute the structural method of edge computing. Its purpose is to effectively reduce the computational load of the main control unit and share it with the main control unit.
  • the edge processing unit shares some of the basic work of the master control unit. Next, the edge processing unit and master control unit are introduced respectively.
  • the edge processing unit is used to receive data from multiple production devices, and count the space occupied by the uplink data each time it sends uplink data to the master control unit, and send the space occupied by the uplink data before sending the uplink data.
  • the work shared by the edge processing unit is to make preliminary statistics on the space occupied by the data when it is processed, to prevent the data from being congested in the master control unit due to the large amount of data, so that the master control unit can process the data in an orderly manner without causing data disorder, thus ensuring the security of the data.
  • the general control unit is used to respectively receive the space occupied by the uplink data sent by each edge processing unit, and obtain the actual occupied space according to the sum of the spaces occupied by each edge processing unit.
  • the operating space of the general control unit Set the quantitative relationship between the proportion of data and the actual occupied space, and obtain the proportion and number of times that the master control unit receives each of the uplink data.
  • the proportion of each of the uplink data and the number of times it is received Receive each of the uplink data, and process the received uplink data.
  • the overall control unit obtains the number of data receptions for each edge processing unit based on the quantitative relationship between the actual occupied space and the estimated occupied space. That is, at each time node, it receives the data sent by the edge processing unit once.
  • the edge processing unit also sends quantitative data at each time node in turn, provided that there is data to be sent.
  • the master control unit receives data at each time node, it will process the data sent by the edge processing unit in sequence. During processing, for some incomplete data, it will wait for the next one at the data port. After the data of the time node arrives, it is merged, and then the data is processed. For incomplete data, it is merged according to the data label and location relationship.
  • the edge processing unit performs preliminary calculations.
  • the data to be processed is received through the edge processing unit, and the space occupied by the data to be processed when the data is processed by the main control unit is obtained, and then the comprehensive occupied space counted by all the edge processing units is summarized.
  • the proportion of each uplink data received by the main control unit each time and the number of times it is received are obtained.
  • the edge processing unit needs to transmit the data separately, so that at each time node, when the main control unit processes the data, there will not be a large amount of data backlog, but all the data backlogs are distributed to each edge processing unit, so that the edge processing unit effectively shares the data processing pressure of the main control unit. From another perspective, the security and stability of the data are guaranteed by sharing the data.
  • the proportion of each uplink data received by the general control unit each time and the number of times it is received are obtained.
  • the present invention sets the ratio of the maximum data that the master control unit can receive (the operating space of the master control unit) (the setting ratio is to satisfy the requirement that the data received by the master control unit does not exceed the maximum reception amount, and retains the desired data as a system
  • the size relationship between the data (the space occupied by the necessary programs for protection) and the actual space occupied is the ratio of each uplink data, and the number of receptions is obtained based on this ratio.
  • the set ratio of the running space of the master control unit is 80, and the actual occupied space is 100, then there is an excess of 20, and the maximum ratio of the above data in the edge processing unit is 80 %, the number of times is 2 times, and the proportion of data that is still needed is also adjusted according to the importance level of the data of the edge processing unit.
  • the above-mentioned edge processing unit is optimized so that the edge processing unit processes data in a more orderly manner.
  • the edge processing unit includes: a data sorting module, a data splitting module and a data sending module. module. The following is a detailed introduction to each module.
  • the data sorting module arranges the uplink data in sequence according to the logical order executed by the master control unit; the function of this module is to improve the processing efficiency of the master control unit and prioritize important processing Therefore, the uplink data is arranged in sequence according to the logical sequence executed by the master control unit, so that when transmitting in sequence, if multiple transmissions are required, the master control unit can receive and process important data first. Thereby improving the efficiency of data processing.
  • the data splitting module is used to receive the proportion of the uplink data of the edge processing unit in the general control unit and the number of receptions, and split the uplink data according to the proportion of the uplink data.
  • the sub-uplink data are arranged in sequence; this module splits the data according to the proportion and frequency of the uplink data, and arranges the split sub-uplink data in sequence. When arranging, the data is arranged according to the above principles.
  • the data sending module sends the sub-uplink data to the main control unit in sequence.
  • This module is an execution module that arranges the above-mentioned split data and completes the sending.
  • the data to be uploaded by the edge processing unit is arranged in sequence, and the data to be split is arranged in sequence according to the logical sequence executed by the master control unit, so that the master control unit can receive it first And process important data, thereby improving the efficiency of data processing.
  • the master control unit includes: a data scanning interface, a data analysis module, a data release module and a data deletion module.
  • the data scanning interface is used to scan the working status of the data interface in sequence, and open the corresponding data interface in sequence and keep it open within the set time; in this way, the data sent by each edge processing unit can be received in sequence, so that when processing the data time, proceed in an orderly manner.
  • the data analysis module splits the received sub-uplink data to obtain each data to be processed, and marks each data to be processed according to the first novelty of each data to be processed; this module marks each data according to the newness of the data. , the data with the first high novelty is considered to be new data, that is, data that has not been processed by the master control unit before.
  • the data release module releases the data to be processed that has been marked with the first novelty to the data processing unit of the general control unit, and starts receiving feedback from the data processing unit; this module is to test new data Release to the data processing department of the master control unit, and test the feedback of data processing from the data processing department of the master control unit.
  • the data deletion module upon receiving feedback from the data processing unit, sends a copy of the first data to be processed with high novelty to the data processing unit; when the data processing unit of the master control unit When there is feedback, it means that the trial release data is abnormal and needs to be deleted. Therefore, a copy of the data is sent to the data processing department, which completes the deletion work.
  • the data processing part includes a method for sending a copy of the data to be processed according to the data deletion module, searching for the received data to be processed, and deleting the data to be processed.
  • the main function of the data processing department is that the master control unit is used for data processing. When data is processed normally, there is no feedback. When data processing is abnormal, feedback is provided.
  • the above-mentioned further optimization of the general control unit is carried out by processing the data according to the novelty of the data.
  • the data is judged based on the feedback from the data processing unit. Whether the data is obviously inconsistent with the data processing of the master control unit.
  • this program is a virus program and needs to be completely deleted.
  • the invention enables the general control unit to scan the interface of the data in sequence, so that the data to be entered is sequentially split through the data analyzer for review, and the new data is analyzed according to the effect produced by the data after it is released. Determine the label. When the label is a virus, start the corresponding anti-virus program to process the data.
  • the data processing part of the general control unit completes a feedback after the data scanning interface completes a scan of the data interface.
  • the feedback is true or false.
  • the data deletion module sends a copy of the first high novelty data to be processed. sent to the data processing department.
  • the feedback is true, no action is taken. Only when a fault occurs, feedback is obtained, which can save the operating program of the master control unit and accelerate the operating efficiency of the master control unit.
  • the data is processed from the edge processing unit, so that the master control unit receives as few or even no virus-like programs as possible.
  • the edge processing unit of the present invention also includes: a data marking module.
  • the data marking module of the present invention is used to mark the second novelty based on the sub-uplink data obtained by the data splitting module; in this way, the novelty of the data to be sent by the edge processing unit can be obtained, and subsequent processing only needs to be based on the edge processing The new data sent by the unit is enough, which saves the workload of the master control unit.
  • the data sending module packages and sends the sub-uplink data to the general control unit according to the second novelty mark corresponding to it; this module performs the sending process, and at the same time completes the edge processing unit's processing of Initial processing of data.
  • the data analysis module of the general control unit splits the sub-uplink data whose second novelty reaches the set value, or releases the sub-uplink data whose second novelty does not reach the set value. to the data processing section.
  • This module performs secondary novelty processing on the data that has been initially processed by the edge processing unit, so that data with low novelty can be released directly without secondary processing, thus improving the efficiency of data processing.
  • the first degree of novelty has a numerical value of 0 or 100%
  • the second novelty degree has a numerical value ranging from 0 to 100%.
  • the higher the values of the first novelty degree and the second novelty degree the newer the data.
  • the calculation is based on the similarity between the data to be sent and the data that has been sent before.
  • the calculation is based on the data. Determine the type.
  • the determination of the thresholds of the first degree of novelty and the second degree of novelty reflects the purpose of the present invention. It is understood that the level of data defense performance is determined by technicians themselves.
  • the first novelty degree uses 40% and the second novelty degree uses 60% values.
  • the data marking module when marking the degree of novelty, one of the methods is proposed.
  • the data marking module marks the second degree of novelty, it includes the following steps:
  • steps (1) to (3) are performed sequentially according to a logical sequence.
  • multiple preprocessed data are obtained after splitting, and the corresponding novelty is obtained according to the types of these preprocessed data. and data levels, and finally weighted to obtain the second degree of novelty.
  • This method is based on the data type of the uplink data when judging the second novelty. In this way, the second novelty of the uplink data is related to the data itself. The obtained data is more reliable and the most gradual. 2. How to judge novelty.
  • the general control unit obtains the ratio of its operating space to the occupied operating space in real time. When the ratio reaches the set ratio, it stops receiving the uplink data.
  • the antivirus program and data analyzer of the present invention have a running space occupancy rate of less than 5%.
  • processing data the data is processed through tags on the data, and tags are set on the data according to the structure of the data. , so that each edge processing unit can label and set the data in advance, saving the review work of data analysis, thereby improving the security and work efficiency of the master control unit.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Health & Medical Sciences (AREA)
  • General Health & Medical Sciences (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Medical Informatics (AREA)
  • Virology (AREA)
  • Small-Scale Networks (AREA)

Abstract

本发明公开了一种工业互联网数据防护系统,包括总控单元和多个分别与所述总控单元信号交互的边缘处理单元。本发明使用边缘计算的方式使得减小总控单元的运算量,同时减少总控单元的数据接口,保证数据的安全性。边缘计算的方式是使用多个边缘处理单元分担总控单元的一些基础工作,每一个边缘处理器分别与总控单元连接,每一个边缘处理器分别与多个生产设备连接,在工作的的时候,边缘处理器收集所负责的每一个生产设备的信息,并将收集到的信息进行初步的删选,最后将数据传输到总控单元,同时根据总控单元的指令,完成对于各个生产设备的信息传达,在这样的方式下,总控单元用于处理数据的运行空间有效提升。

Description

一种工业互联网数据防护系统 技术领域
本发明涉及数据防护领域,特别涉及一种工业互联网数据防护系统。
背景技术
在目前的信息化时代,现代的信息技术在各个行业和领域产生了广泛的应用。在工业生产领域,信息化的应用也亦是如此。在现在的工业生产中,随着信息技术的发展与应用,在生产厂中使用大型的生产设备已经是屡见不鲜,同时,各个生产设备之间的数据还通过无线传输的方式分别与总控单元的进行数据交互,从而实现生产厂中的信息化。
在总控单元与各个生产设备进行数据的交互的时候,一般是通过数据接口的方式,完成对于数据的传输,每个数据接口分别对应一个生产设备,使之完成各个生产设备与总控单元之间的交互。而在一个生产厂中,往往具有大量的生产设备,而每一个生产设备分别与总控单元进行数据通信的时候,会造成总控单元占有大量的运行空间用于接收数据,一般可以达到35%-60%,使得总控单元在对数据进行处理分析的时候,可以使用的运行空间较少,一般只有40%-65%,严重拖慢运行速度,同时大量数据接口同时开放,则无法对每一个数据接口的数据进行细致的审核就对数据进行放行,从而使得进入总控单元的数据安全性无法得到满足。
发明内容
本发明的目的是克服上述现有技术中存在的问题,提供一种工业互联网数 据防护系统,边缘计算的方式使得减小总控单元的运算量,同时减少总控单元的数据接口,保证数据的安全性。
为此,本发明提供一种工业互联网数据防护系统,包括总控单元和多个分别与所述总控单元信号交互的边缘处理单元;
所述边缘处理单元,用于接收多个生产设备的数据,并在每一次要给所述总控单元发送上行数据的时候统计的上行数据所占用的空间,并在发送上行数据前发送该上行数据所占用的空间;
所述总控单元,用于分别接收每一个所述边缘处理单元发送的上行数据所占用的空间,根据每一个边缘处理单元所占用空间的总和得到实际占用空间,根据总控单元的运行空间的设定比例的数据与实际占用空间之间的数量关系,得到总控单元每次接收每一个所述上行数据的比例以及所接收的次数,根据每一个所述上行数据的比例以及所接收的次数接收每一个所述上行数据,对接收的上行数据进行处理。
进一步,所述边缘处理单元包括:
数据梳理模块,将所述上行数据按照其在所述总控单元所执行的逻辑顺序依次进行排列;
数据拆分模块,用于接收所述总控单元中该边缘处理单元的上行数据的比例以及所述接收的次数,并根据上行数据的比例将所述上行数据进行拆分,拆分后的各个子上行数据依次排列;
数据发送模块,将所述子上行数据按照排列的顺序依次发送到所述总控单元。
更进一步,所述总控单元包括:
数据扫描接口,用于依次扫描数据接口的工作状态,并且根据顺序依次开启对应的数据接口在设定时间内保持开放状态;
数据分析模块,将接收的所述子上行数据根据进行拆分得到各个待处理数据,根据各个待处理数据的第一新颖度,对各个待处理数据进行标记;
数据放行模块,将所述标记好所述第一新颖度的待处理数据放行至所述总控单元的数据处理部,并开启接收所述数据处理部的反馈;
数据删选模块,在接收到所述数据处理部的反馈的时候,将所述第一新颖度高的待处理数据的副本发送给所述数据处理部;
所述数据处理部,包括用于根据所述数据删选模块发送待处理数据的副本,查找接收的待处理数据,并将该待处理数据删除。
更进一步,所述总控单元的所述数据处理部在所述数据扫描接口完成一次所述数据接口的扫描之后,完成一次反馈,所述反馈为真或假,当所述反馈为假的时候,所述数据删选模块,将所述第一新颖度高的待处理数据的副本发送给所述数据处理部。
更进一步,所述边缘处理单元还包括:
数据标记模块,根据所述数据拆分模块得到的子上行数据进行第二新颖度的标记;
所述数据发送模块,将所述子上行数据按照和其对应的所述第二新颖度标记打包发送到所述总控单元;
所述总控单元的数据分析模块,将所述第二新颖度达到设定数值的子上行数据进行拆分,或者将所述第二新颖度没有达到所述设定数值的子上行数据进 行放行至所述数据处理部。
更进一步,所述第一新颖度的数值为0或者100%,所述第二新颖度的数值范围为0到100%。
更进一步,所述数据标记模块模块在标记所述第二新颖度的时候,包括如下步骤:
将所述子上行数据进行拆分,得到多个预处理数据;
分别根据每一个预处理数据的类型,在对应类型的数据库中查找,并标记对应的第三新颖度以及数据等级;
将每一个第三新颖度结合对应的数据等级进行加权运算,得到所述第二新颖度。
进一步,所述总控单元实时的得到其运行空间和已占用的运行空间的比例,当该比例达到设定比例的时候,停止接收所述上行数据。
本发明提供的一种工业互联网数据防护系统,具有如下有益效果:
本发明使用边缘计算的方式使得减小总控单元的运算量,同时减少总控单元的数据接口,保证数据的安全性。边缘计算的方式是使用多个边缘处理单元分担总控单元的一些基础工作,每一个边缘处理器分别与总控单元连接,每一个边缘处理器分别与多个生产设备连接,在工作的的时候,边缘处理器收集所负责的每一个生产设备的信息,并将收集到的信息进行初步的删选,最后将数据传输到总控单元,同时根据总控单元的指令,完成对于各个生产设备的信息传达,在这样的方式下,总控单元用于处理数据的运行空间可以提升至75%-85%;
本发明使得总控单元依次扫描数据的接口,使得要进入的数据依次的通过数据分析器拆分开来进行审核,并且将新的数据在释放之后根据数据所产生的效果,对新的数据进行标签的确定,当标签为病毒的时候,启动对应的杀毒程序对数据进行处理;
本发明的杀毒程序和数据分析器具有的运行空间占有率为5%以下,在对数据进行处理的时候,通过数据上的标签对数据进行处理,并根据数据的结构对数据进行标签的设定,从而可以通过每一个边缘处理单元提前对于数据进行数据的标签与设定,节约数据分析的审核工作,从而提升总控单元的安全性和工作效率。
附图说明
图1为本发明提供的一种工业互联网数据防护系统的整体结构示意框图;
图2为本发明的边缘处理单元的系统连接示意框图;
图3为本发明的总控单元的系统连接示意框图。
具体实施方式
下面结合附图,对本发明的一个具体实施方式进行详细描述,但应当理解本发明的保护范围并不受具体实施方式的限制。
在本申请文件中,未经明确的部件型号以及结构,均为本领域技术人员所公知的现有技术,本领域技术人员均可根据实际情况的需要进行设定,在本申请文件的实施例中不做具体的限定。
具体的,如图1-3所示,本发明实施例提供了一种工业互联网数据防护系 统,包括总控单元和多个分别与所述总控单元信号交互的边缘处理单元。总控单元和多个边缘处理单元构成了边缘计算的结构方式,其目的是有效的减小总控单元的运算量,为总控单元进行分担。边缘处理单元就是分担了总控单元的部分基础工作。下面,分别对边缘处理单元和总控单元进行介绍。
所述边缘处理单元,用于接收多个生产设备的数据,并在每一次要给所述总控单元发送上行数据的时候统计的上行数据所占用的空间,并在发送上行数据前发送该上行数据所占用的空间。边缘处理单元所分担的工作是对数据在处理的时候所占用的空间进行初步的统计,防止由于数据量过大,使得数据一下子全部涌入总控单元而导致总控单元的数据拥堵,进而使得总控单元的在处理数据的时候有序进行,不会产生数据的紊乱,保证数据的安全性。
所述总控单元,用于分别接收每一个所述边缘处理单元发送的上行数据所占用的空间,根据每一个边缘处理单元所占用空间的总和得到实际占用空间,根据总控单元的运行空间的设定比例的数据与实际占用空间之间的数量关系,得到总控单元每次接收每一个所述上行数据的比例以及所接收的次数,根据每一个所述上行数据的比例以及所接收的次数接收每一个所述上行数据,对接收的上行数据进行处理。总控单元是根据实际的占用空间和预计所述占用的空间之间的数量关系,得到对于各个边缘处理单元的数据的接收的次数,就是在每一个时间节点,都会接收一次边缘处理单元所发送的数据,边缘处理单元也是依次在每一个时间节点都进行数据的定量发送,前提是在有数据要发送的时候。总控单元在每一个时间节点接收到数据的时候,就会对边缘处理单元所述发送的数据进行依次的处理,在处理的时候,对于一些不全面的数据,会在数据口出等待下一个时间节点的数据到来之后,与其进行合并之后,在对数据进行处理,对于不全面的数据,根据数据标签以及位置关系进行合并。
上述技术方案中,通过边缘计算的结构方式,将对于数据的基本处理放置 边缘处理单元进行初步的计算,在进行计算的时候,通过边缘处理单元接收要处理的数据,并且得到要处理的数据在总控单元处理的时候所述占用的空间,进而汇总全部的边缘处理单元所统计的占用的空间的综合,根据总控单元的运行空间的设定比例的数据与实际占用空间之间的数量关系,得到总控单元每次接收每一个所述上行数据的比例以及所接收的次数,边缘处理单元需要分开进行数据的传递,这样就是使得在每一个时间节点,总控单元在处理数据的时候,不会具有大量的数据积压,而将数据积压全部分摊到各个边缘处理单元,使得边缘处理单元有效的分担了总控单元的数据处理压力,从另一个方面来看,就是通过分担数据的方式,保证了数据的安全稳定性。
对于根据总控单元的运行空间的设定比例的数据与实际占用空间之间的数量关系,得到总控单元每次接收每一个所述上行数据的比例以及所接收的次数。本发明是将总控单元可以接收的最大的数据(总控单元的运行空间)的设定比例(设定比例是为了满足总控单元接收的数据不超过最大的接收量,保留出所要作为系统防护的必备程序所需要占用的空间)的数据,与实际做占用空间之间的大小关系,得到各个上行数据的比例,在根据这个比例得到接收的次数。例如,总控单元的运行空间的设定比列的数据做占用的空间梁为80,而实际所占用的量为100,则多出来20,则该边缘处理单元的上述数据的比例最大为80%,次数为2次,而这个尚需数据的比例,还根据边缘处理单元的数据的重要等级程度进行调整。
在本发明的实施例中,对上述的边缘处理单元进行优化,使得边缘处理单元在处理数据的时候更加的依次有序,所述边缘处理单元包括:数据梳理模块、数据拆分模块以及数据发送模块。下面是各个模块的详细介绍。
数据梳理模块,将所述上行数据按照其在所述总控单元所执行的逻辑顺序依次进行排列;该模块的功能是为了提升总控单元的处理效率,优先处理重要 的数据,因此,将上行数据按照总控单元所执行的逻辑顺序依次进行排列,这样在依次进行传输的时候,如果需要多次传输,那么总控单元就可以优先收到并处理重要的数据,进而提升数据处理的效率。
数据拆分模块,用于接收所述总控单元中该边缘处理单元的上行数据的比例以及所述接收的次数,并根据上行数据的比例将所述上行数据进行拆分,拆分后的各个子上行数据依次排列;该模块是根据上行数据的比例和次数,对数据进行拆分,并将拆分后的子上行数据依次排列,在进行排列的时候,根据上述的原则对数据进行排列。
数据发送模块,将所述子上行数据按照排列的顺序依次发送到所述总控单元。该模块是执行的模块,是将上述的拆分的数据进行排列,并且完成发送。
上述的技术方案中,将边缘处理单元要上传的数据依次进行排列,将拆分都的数据进行排列,并且按照总控单元所执行的逻辑顺序依次进行排列,使得总控单元就可以优先收到并处理重要的数据,进而提升数据处理的效率。
同时,我们还对总控单元的处理进行优化,在本发明中,所述总控单元包括:数据扫描接口、数据分析模块、数据放行模块以及数据删选模块。
数据扫描接口,用于依次扫描数据接口的工作状态,并且根据顺序依次开启对应的数据接口在设定时间内保持开放状态;这样可以依次接收每一个边缘处理单元所发送的数据,使得在处理数据的时候,依次有序的进行。
数据分析模块,将接收的所述子上行数据根据进行拆分得到各个待处理数据,根据各个待处理数据的第一新颖度,对各个待处理数据进行标记;该模块是根据数据的新旧进行标记,对于第一新颖度高的数据,认为是新的数据,即是总控单元之前没有处理过的数据。
数据放行模块,将所述标记好所述第一新颖度的待处理数据放行至所述总控单元的数据处理部,并开启接收所述数据处理部的反馈;该模块是将新的数据试放行到总控单元的数据处理部,测试总控单元的数据处理部对于数据处理的反馈。
数据删选模块,在接收到所述数据处理部的反馈的时候,将所述第一新颖度高的待处理数据的副本发送给所述数据处理部;当总控单元的数据处理部对数据有反馈的时候,说明该试放行的数据异常,需要删除,因此,使用该数据的副本发送到数据处理部,由数据处理部完成删除工作。
所述数据处理部,包括用于根据所述数据删选模块发送待处理数据的副本,查找接收的待处理数据,并将该待处理数据删除。数据处理部的主要功能是总控单元用于数据处理的,在正常处理数据的时候,没有反馈,在数据处理异常的时候,进行反馈。
上述对总控单元进行进一步的优化,通过根据数据的新颖程度对数据进行处理,在对新的数据(即第一新颖度高的数据)进行处理的时候,根据数据处理部的反馈,判断该数据是否对于总控单元的数据处理具有明显的不协调。一般的,该程序为病毒程序,需要彻底删除。
本发明使得总控单元依次扫描数据的接口,使得要进入的数据依次的通过数据分析器拆分开来进行审核,并且将新的数据在释放之后根据数据所产生的效果,对新的数据进行标签的确定,当标签为病毒的时候,启动对应的杀毒程序对数据进行处理。
作为优选的,所述总控单元的所述数据处理部在所述数据扫描接口完成一次所述数据接口的扫描之后,完成一次反馈,所述反馈为真或假,当所述反馈为假的时候,所述数据删选模块,将所述第一新颖度高的待处理数据的副本发 送给所述数据处理部。当所述反馈为真的时候,不做任何操作。只在出现故障的时候,得到反馈,这样可以节约总控单元的运行程序,加速总控单元的运行效率。
对于上述方案的进一步优化,从边缘处理单元就对数据进行处理,使得总控单元尽可能的少接收甚至不接接收类似病毒的程序,本发明的所述边缘处理单元还包括:数据标记模块。本发明的数据标记模块,用于根据所述数据拆分模块得到的子上行数据进行第二新颖度的标记;这样就可以得到边缘处理单元所要发送的数据的新颖度,后续仅仅需要根据边缘处理单元所发送的新的数据即可,节约了总控单元的工作量。
所述数据发送模块,将所述子上行数据按照和其对应的所述第二新颖度标记打包发送到所述总控单元;该模块执行的是发送的过程,同时完成的是边缘处理单元对于数据的初步处理。
所述总控单元的数据分析模块,将所述第二新颖度达到设定数值的子上行数据进行拆分,或者将所述第二新颖度没有达到所述设定数值的子上行数据进行放行至所述数据处理部。该模块将边缘处理单元已经完成的初步处理的数据进行二次新颖度的处理,这样就可以使得新颖度低的数据直接放行,不进行二次的处理,进而提升了数据处理的效率。
本发明中,所述第一新颖度的数值为0或者100%,所述第二新颖度的数值范围为0到100%。第一新颖度和第二新颖度的数值越高,数据越新。对于第一新颖度和第二新颖度的数值,根据要发送的数据和之前已经发送的数据之间的相似程度进行计算,对于要发送的数据和之前已经发送的数据之间的选择,根据数据的类型进行确定。
一般的,在本发明中,第一新颖度和第二新颖度的阈值的确定体现了本发 明对于数据防御性能的高低,由技术人员自行进行认定,在本发明中,第一新颖度使用40%和第二新颖度使用60%的数值。
在本发明中,对于新颖度标记的时候,提出其中的一种方式,所述数据标记模块模块在标记所述第二新颖度的时候,包括如下步骤:
(一)将所述子上行数据进行拆分,得到多个预处理数据;
(二)分别根据每一个预处理数据的类型,在对应类型的数据库中查找,并标记对应的第三新颖度以及数据等级;
(三)将每一个第三新颖度结合对应的数据等级进行加权运算,得到所述第二新颖度。
上述技术方案中,步骤(一)至步骤(三)根据逻辑顺序依次进行,通过将数据拆分之后,得到拆分后的多个预处理数据,根据这些预处理数据的类型得到对应的新颖度以及数据等级,最后加权得到所述的第二新颖度。这样的方式对于在进行第二新颖度判断的时候,是根据上行数据的数据类型,这样所得到的上行数据的第二新颖度与数据本身相关,得到的数据更加的可靠,也是最为渐变的第二新颖度的判断方式。
在本发明的实施例中,所述总控单元实时的得到其运行空间和已占用的运行空间的比例,当该比例达到设定比例的时候,停止接收所述上行数据。本发明的杀毒程序和数据分析器具有的运行空间占有率为5%以下,在对数据进行处理的时候,通过数据上的标签对数据进行处理,并根据数据的结构对数据进行标签的设定,从而可以通过每一个边缘处理单元提前对于数据进行数据的标签与设定,节约数据分析的审核工作,从而提升总控单元的安全性和工作效率。
以上公开的仅为本发明的几个具体实施例,但是,本发明实施例并非局限 于此,任何本领域的技术人员能思之的变化都应落入本发明的保护范围。

Claims (8)

  1. 一种工业互联网数据防护系统,其特征在于,包括总控单元和多个分别与所述总控单元信号交互的边缘处理单元;
    所述边缘处理单元,用于接收多个生产设备的数据,并在每一次要给所述总控单元发送上行数据的时候统计的上行数据所占用的空间,并在发送上行数据前发送该上行数据所占用的空间;
    所述总控单元,用于分别接收每一个所述边缘处理单元发送的上行数据所占用的空间,根据每一个边缘处理单元所占用空间的总和得到实际占用空间,根据总控单元的运行空间的设定比例的数据与实际占用空间之间的数量关系,得到总控单元每次接收每一个所述上行数据的比例以及所接收的次数,根据每一个所述上行数据的比例以及所接收的次数接收每一个所述上行数据,对接收的上行数据进行处理。
  2. 如权利要求1所述的一种工业互联网数据防护系统,其特征在于,所述边缘处理单元包括:
    数据梳理模块,将所述上行数据按照其在所述总控单元所执行的逻辑顺序依次进行排列;
    数据拆分模块,用于接收所述总控单元中该边缘处理单元的上行数据的比例以及所述接收的次数,并根据上行数据的比例将所述上行数据进行拆分,拆分后的各个子上行数据依次排列;
    数据发送模块,将所述子上行数据按照排列的顺序依次发送到所述总控单元。
  3. 如权利要求2所述的一种工业互联网数据防护系统,其特征在于,所 述总控单元包括:
    数据扫描接口,用于依次扫描数据接口的工作状态,并且根据顺序依次开启对应的数据接口在设定时间内保持开放状态;
    数据分析模块,将接收的所述子上行数据根据进行拆分得到各个待处理数据,根据各个待处理数据的第一新颖度,对各个待处理数据进行标记;
    数据放行模块,将所述标记好所述第一新颖度的待处理数据放行至所述总控单元的数据处理部,并开启接收所述数据处理部的反馈;
    数据删选模块,在接收到所述数据处理部的反馈的时候,将所述第一新颖度高的待处理数据的副本发送给所述数据处理部;
    所述数据处理部,包括用于根据所述数据删选模块发送待处理数据的副本,查找接收的待处理数据,并将该待处理数据删除。
  4. 如权利要求3所述的一种工业互联网数据防护系统,其特征在于,所述总控单元的所述数据处理部在所述数据扫描接口完成一次所述数据接口的扫描之后,完成一次反馈,所述反馈为真或假,当所述反馈为假的时候,所述数据删选模块,将所述第一新颖度高的待处理数据的副本发送给所述数据处理部。
  5. 如权利要求3所述的一种工业互联网数据防护系统,其特征在于,所述边缘处理单元还包括:
    数据标记模块,根据所述数据拆分模块得到的子上行数据进行第二新颖度的标记;
    所述数据发送模块,将所述子上行数据按照和其对应的所述第二新颖度标 记打包发送到所述总控单元;
    所述总控单元的数据分析模块,将所述第二新颖度达到设定数值的子上行数据进行拆分,或者将所述第二新颖度没有达到所述设定数值的子上行数据进行放行至所述数据处理部。
  6. 如权利要求5所述的一种工业互联网数据防护系统,其特征在于,所述第一新颖度的数值为0或者100%,所述第二新颖度的数值范围为0到100%。
  7. 如权利要求5所述的一种工业互联网数据防护系统,其特征在于,所述数据标记模块模块在标记所述第二新颖度的时候,包括如下步骤:
    将所述子上行数据进行拆分,得到多个预处理数据;
    分别根据每一个预处理数据的类型,在对应类型的数据库中查找,并标记对应的第三新颖度以及数据等级;
    将每一个第三新颖度结合对应的数据等级进行加权运算,得到所述第二新颖度。
  8. 如权利要求1所述的一种工业互联网数据防护系统,其特征在于,所述总控单元实时的得到其运行空间和已占用的运行空间的比例,当该比例达到设定比例的时候,停止接收所述上行数据。
PCT/CN2023/127896 2022-11-01 2023-10-30 一种工业互联网数据防护系统 WO2024061380A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202211356569.2 2022-11-01
CN202211356569.2A CN115412375B (zh) 2022-11-01 2022-11-01 一种工业互联网数据防护系统

Publications (1)

Publication Number Publication Date
WO2024061380A1 true WO2024061380A1 (zh) 2024-03-28

Family

ID=84169426

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2023/127896 WO2024061380A1 (zh) 2022-11-01 2023-10-30 一种工业互联网数据防护系统

Country Status (3)

Country Link
CN (1) CN115412375B (zh)
LU (1) LU505584B1 (zh)
WO (1) WO2024061380A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN115412375B (zh) * 2022-11-01 2023-04-18 山东省信息技术产业发展研究院(中国赛宝(山东)实验室) 一种工业互联网数据防护系统

Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018121742A1 (zh) * 2016-12-30 2018-07-05 北京奇虎科技有限公司 一种流数据的传输方法和装置
CN109992964A (zh) * 2019-04-12 2019-07-09 广东电网有限责任公司 一种基于工业互联网的数据防护方法、装置及存储介质
US20200159195A1 (en) * 2018-11-16 2020-05-21 General Electric Company Selective data feedback for industrial edge system
CN113298498A (zh) * 2021-05-31 2021-08-24 安徽国防科技职业学院 一种基于工业物联网平台的管理系统
CN114020848A (zh) * 2021-11-18 2022-02-08 北京航空航天大学 一种用于工业现场边云协同的数据分析系统及实现方法
CN114416013A (zh) * 2022-01-04 2022-04-29 深圳Tcl新技术有限公司 数据发送方法、装置、电子设备及计算机可读存储介质
CN114462623A (zh) * 2022-02-10 2022-05-10 电子科技大学 基于边缘计算的数据分析方法、系统及平台
CN114688009A (zh) * 2022-04-07 2022-07-01 北京雅丹石油技术开发有限公司 一种游梁式抽油机智能间抽控制系统及其控制方法
CN115412375A (zh) * 2022-11-01 2022-11-29 山东省电子信息产品检验院(中国赛宝(山东)实验室) 一种工业互联网数据防护系统

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108170845B (zh) * 2018-01-17 2020-10-13 腾讯音乐娱乐科技(深圳)有限公司 多媒体数据处理方法、装置及存储介质
CN111212106B (zh) * 2019-12-09 2022-07-22 中国科学院计算机网络信息中心 一种工业互联网环境中边缘计算任务处理与调度方法及装置
CN112415972B (zh) * 2020-11-24 2022-06-07 汉锦科技(北京)有限公司 一种多传感器逻辑及控制核心系统
CN115016918B (zh) * 2022-03-31 2024-06-11 中国科学院计算技术研究所 一种用于数据流架构的计算设备的数据处理方法

Patent Citations (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018121742A1 (zh) * 2016-12-30 2018-07-05 北京奇虎科技有限公司 一种流数据的传输方法和装置
US20200159195A1 (en) * 2018-11-16 2020-05-21 General Electric Company Selective data feedback for industrial edge system
CN109992964A (zh) * 2019-04-12 2019-07-09 广东电网有限责任公司 一种基于工业互联网的数据防护方法、装置及存储介质
CN113298498A (zh) * 2021-05-31 2021-08-24 安徽国防科技职业学院 一种基于工业物联网平台的管理系统
CN114020848A (zh) * 2021-11-18 2022-02-08 北京航空航天大学 一种用于工业现场边云协同的数据分析系统及实现方法
CN114416013A (zh) * 2022-01-04 2022-04-29 深圳Tcl新技术有限公司 数据发送方法、装置、电子设备及计算机可读存储介质
CN114462623A (zh) * 2022-02-10 2022-05-10 电子科技大学 基于边缘计算的数据分析方法、系统及平台
CN114688009A (zh) * 2022-04-07 2022-07-01 北京雅丹石油技术开发有限公司 一种游梁式抽油机智能间抽控制系统及其控制方法
CN115412375A (zh) * 2022-11-01 2022-11-29 山东省电子信息产品检验院(中国赛宝(山东)实验室) 一种工业互联网数据防护系统

Also Published As

Publication number Publication date
CN115412375A (zh) 2022-11-29
LU505584B1 (en) 2024-04-08
CN115412375B (zh) 2023-04-18

Similar Documents

Publication Publication Date Title
WO2024061380A1 (zh) 一种工业互联网数据防护系统
CN107220892B (zh) 一种应用于海量p2p网贷金融数据智能预处理工具及方法
CN106506283B (zh) 银行和企业对接系统的业务测试方法和装置
CN110765464B (zh) 漏洞检测方法、装置、设备及计算机存储介质
CN108600195B (zh) 一种基于增量学习的快速工控协议格式逆向推断方法
CN110941553A (zh) 一种代码检测方法、装置、设备及可读存储介质
WO2020259034A1 (zh) 下线源代码的识别方法、装置、设备及存储介质
US11349730B2 (en) Operation device and operation method
CN116257427A (zh) 联邦学习任务的异构测试方法、系统、设备及存储介质
CN116645082A (zh) 一种系统巡检方法、装置、设备以及存储介质
CN108874646A (zh) 分析数据的方法和装置
CN112688947B (zh) 基于互联网的网络通信信息智能监测方法及系统
CN114598547A (zh) 应用于网络攻击识别的数据分析方法及电子设备
CN114329450A (zh) 数据安全处理方法、装置、设备及存储介质
CN107707492B (zh) 一种上报和下发报文的方法及装置
CN112905493A (zh) 一种基于转换测试的结构化模糊测试方法
CN107391404A (zh) 一种基于硬件端口的数据传输方法及装置
CN111800296B (zh) 实时系统网络数据捕获与分析方法、系统、设备及存储介质
CN101877874B (zh) 性能数据的发送及输出方法、系统和设备
CN112612621B (zh) 数据处理方法及相关设备
CN112866044B (zh) 网络设备状态信息采集方法及装置
CN116938934B (zh) 一种基于报文的任务切换控制方法及系统
CN114465812B (zh) 一种压测流量控制方法及装置
CN106598756A (zh) 不同应用程序之间的数据交互方法
CN117950760A (zh) 基于日志染色的接口调用情况分析方法、装置及设备

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 23867665

Country of ref document: EP

Kind code of ref document: A1