面向信创体系的煤矿安全监控数据加密与防篡改方案

Scheme for data encryption and tamper protection in coal mine safety monitoring within information technology application innovation ecosystem

  • 摘要: 针对工业安全监控场景下实施数据加密存在的密文环境下高效查询、存储空间膨胀控制、应用层侵入性、信创硬件适配、元数据语义泄露等问题,提出了一种面向信创体系的煤矿安全监控数据加密与防篡改方案。该方案采用业务接入层、密码学转换层、混淆策略引擎、元数据混淆器和密钥管理中心5层协同架构:业务接入层基于HarmonyLib的运行时拦截实现零代码改动的透明加密接入;密码学转换层采用SM4−GCM认证加密保障数据机密性与完整性,融合HMAC盲索引、保序分桶与比特位混淆标记,支持密文等值查询与范围查询;混淆策略引擎在真实数据中注入统计不可区分的模拟数据,增强抗分析能力;元数据混淆器利用.NET Source Generators在编译期将语义化表名和列名替换为确定性标志,并结合统一加密表结构的字段聚合抑制存储空间膨胀;密钥管理中心采用硬件指纹绑定的信封加密机制保障密钥安全。该方案在信创ARM平台上的测试结果表明,密文模式下等值查询、范围查询和批量插入的耗时分别为明文模式的2.25倍、1.6~4.4倍和1.94倍,密文数据大小不超过明文数据的2.82倍,SM4−GCM加解密耗时仅为2.30 μs/条,加密吞吐量超过66万次/s。所提方案满足《中华人民共和国密码法》与GB/T 22239—2019《信息安全技术 网络安全等级保护基本要求》对密码算法合规性的要求,兼顾工业监控实时性需求,具备工程可行性。

     

    Abstract: To address challenges in implementing data encryption for industrial safety monitoring, including efficient queries over ciphertext, control of storage expansion, application-layer intrusiveness, adaptation to information technology application innovation hardware, and semantic leakage from metadata, a scheme for data encryption and tamper protection in coal mine safety monitoring within the information technology application innovation ecosystem was proposed. The scheme adopted a collaborative five-layer architecture comprising a business integration layer, a cryptographic transformation layer, an obfuscation policy engine, a metadata obfuscator, and a key management center. The business integration layer used runtime interception with HarmonyLib to integrate transparent encryption without code changes. The cryptographic transformation layer employed SM4-GCM for authenticated encryption to ensure data confidentiality and integrity. It combined blind indexes based on HMAC, order-preserving bucketing, and obfuscation flags encoded in individual bits to support equality and range queries over ciphertext. The obfuscation policy engine injected statistically indistinguishable simulated data into genuine data to enhance resistance to analysis. The metadata obfuscator used .NET Source Generators to replace semantically meaningful table and column names with deterministic identifiers at compile time and combined this mechanism with field aggregation in a unified encrypted table schema to limit storage expansion. The key management center secured keys using envelope encryption bound to hardware fingerprints. Tests on an ARM platform within the information technology application innovation ecosystem showed that equality queries, range queries, and bulk inserts in ciphertext mode took 2.25, 1.6–4.4, and 1.94 times as long as those in plaintext mode, respectively. The ciphertext data size did not exceed 2.82 times the plaintext data size. The SM4-GCM encryption and decryption time was only 2.30 μs per record, and encryption throughput exceeded 660 000 operations/s. The proposed scheme meets the cryptographic algorithm compliance requirements of the Cryptography Law of the People's Republic of China and GB/T 22239-2019 Information security technology—Baseline for classified protection of cybersecurity, while accommodating the real-time requirements of industrial monitoring, and is feasible for engineering applications.

     

/

返回文章
返回