簡易檢索 / 詳目顯示

研究生: 黃威翔
Huang, Wei-Hsiang
論文名稱: 利用區塊鏈和容器開發製造數位孿生之安全防護機制
Development of Security Protection Mechanisms with Blockchain and Container for Manufacturing Digital Twins
指導教授: 謝昱銘
Hsieh, Yu-Ming
鄭芳田
Cheng, Fan-Tien
學位類別: 碩士
Master
系所名稱: 智慧半導體及永續製造學院 - 半導體封測學位學程
Program on Semiconductor Packaging and Testing
論文出版年: 2024
畢業學年度: 112
語文別: 中文
論文頁數: 116
中文關鍵詞: 區塊鏈 、容器技術 、製造數位孿生 、安全防護方案 、數據安全 、隱私保護 、系統彈性
外文關鍵詞: Blockchain, Container Technology, Manufacturing Digital Twin, Security Protection Scheme, Data Security, Privacy Protection, System Resilience
相關次數: 點閱:243  下載:0 
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 數位孿生(DT)技術對於工業4.0時代的智慧工廠至關重要,它將實體世界與數位模型連接起來以模擬現實世界的行為。DT可以提高製造業的生產效率和產品質量,使安全保護對於防止資料外洩、保護隱私和提高系統彈性至關重要。本研究參考NIST隱私框架和NIST IR 8496指南,基於區塊鏈和容器技術,為製造業提出了一種新穎的數位孿生安全保護方案(DTSPS)。DTSPS包括以下機制:(1)資料安全保護機制:透過標準化、清洗、將資料導入區塊鏈,確保資料的完整性和準確性;(2)資料隱私分級與隔離機制:根據NIST IR 8496對資料敏感度進行分級,採用平行傳輸技術,在平衡效率和安全性的同時防止隱私外洩;(3)雙鏈數據完整性監控機制:利用公有鏈和私有鏈監控數據完整性,隔離數據,防止篡改和洩露;(4)區塊鏈節點故障復原機制:利用節點備份並在私鏈上記錄雜湊表,在災難或攻擊發生後快速自動恢復資料儲存系統,增強安全彈性。實驗結果顯示,本論文所提出的DTSPS的綜合安全指數為0.9263,超過了現有文獻報告的0.6893,顯示增強了數位孿生的資料保護。 DTSPS將平均恢復時間(MTTR)從135分鐘減少到10分鐘,恢復時間變異性(RTV)從20分鐘減少到2分鐘,從而提高了系統的彈性。這些發現為製造業開發數位孿生安全解決方案提供了寶貴的參考。

    Digital Twin (DT) technology is crucial for smart factories in the Industry 4.0 era, connecting the physical world with digital models to simulate real-world behaviors. DT can enhance production efficiency and product quality in manufacturing, making security protection vital to prevent data breaches, protect privacy, and improve system resilience. This study proposes a novel digital twin security protection scheme (DTSPS) for the manufacturing industry, based on blockchain and container technology, using NIST Privacy Framework and NIST IR 8496 guidelines. The DTSPS includes the following mechanisms: (1) Data security protection mechanism: It ensures data integrity and accuracy by standardizing, cleaning, and importing data into the blockchain; (2) Data privacy classification and isolation mechanism: It classifies data sensitivity according to NIST IR 8496 and uses parallel transmission technology to prevent privacy leaks while balancing efficiency and security; (3) Dual-chain data integrity monitoring mechanism: It leverages public and private blockchains to monitor data integrity and isolate data, preventing tampering and leakage; (4) Blockchain node failure-recovery mechanism: It uses node backup and record hash tables on the private chain to quickly and automatically restore the data storage system, after a disaster or attach, enhancing security resilience. Experimental results show that the proposed DTSPS achieves a comprehensive security index of 0.9263, surpassing the 0.6893 reported in existing literature, indicating enhanced data protection for digital twins. DTSPS reduces the mean time to recovery (MTTR) from 135 minutes to 10 minutes and recovery time variability (RTV) from 20 minutes to 2 minutes, improving the system resilience. These findings offer valuable guidance for the manufacturing industry in developing digital twin security solutions.

    摘 要 II 誌 謝 XV 目 錄 XVI 表 目 錄 XIX 圖 目 錄 XX 第1章 緒論 22 1.1 研究背景 22 1.2 研究動機 22 1.3 研究目的 25 1.4 研究流程 26 1.5 研究貢獻 28 1.6 論文的組織結構 29 第2章 文獻探討與理論基礎 30 2.1 文獻探討 30 2.2 核心技術基礎 32 第3章 系統架構與系統運作流程設計 34 3.1 系統架構設計 34 3.1.1 物理層(Physical Layer) 34 3.1.2 邊緣層(Edge Layer) 35 3.1.3 雲端層(Edge Layer) 36 3.2 工作流程設計原理 37 第4章 核心機制設計 42 4.1 原始數據清洗安全防護機制 42 4.1.1原始數據清洗安全防護機制設計需求分析 42 4.1.2原始數據清洗安全防護機制設計 43 4.1.3原始數據清洗安全防護機制流程說明 48 4.2 數據隱私分類與隔離機制 50 4.2.1數據隱私分類與隔離機制設計需求分析 51 4.2.2數據隱私分類與隔離機制設計 51 4.2.3數據隱私分類與隔離機制流程說明 57 4.3 雙鏈數據完整性監控機制 60 4.3.1雙鏈數據完整性監控機制設計需求分析 60 4.3.2雙鏈數據完整性監控機制設計 61 4.3.3雙鏈數據完整性監控機制流程說明 64 4.4 區塊鏈節點災難回復機制 66 4.4.1區塊鏈節點災難回復機制設計需求分析 66 4.4.2區塊鏈節點災難回復機制設計 68 4.4.3區塊鏈節點災難回復機制流程說明 88 第5章 案例研究與整合測試結果 91 5.1 實驗環境 92 5.2 系統綜合安全性指標評估 93 5.2.1私有鏈安全性評估: 93 5.2.2公有鏈安全性評估: 95 5.2.3雙重區塊鏈安全性評估 96 5.2.4實驗一:數位孿生模型在應對數據篡改下的更新率與安全性驗證 97 5.3 系統韌性評估 101 5.3.1 系統恢復能力評估: 101 5.3.2 系統可用性評估: 102 5.3.3 實驗二:區塊鏈網路建置效率比較與系統韌性比較 103 5.4 合規性指標評估 106 5.4.1 系統合規性評估方法: 106 第6章 結論 109 6.1 總結與研究貢獻 109 6.2 未來工作 111 參考文獻 113

    [1] M. Eckhart and A. Ekelhart, “A specification-based state replication approach for Digital Twins,” Proceedings of the 2018 Workshop on Cyber-Physical Systems Security and PrivaCy, Jan. 2018. doi:10.1145/3264888.3264892
    [2] R. Bitton, T. Gluck, O. Stan, M. Inokuchi, Y. Ohta, and Y. Yamada, “Deriving a Cost-Effective Digital Twin of an ICS to Facilitate Security Evaluation,” in Computer Security, Springer International Publishing, 2018, pp. 533–554.
    [3] P. Laplante, “Trusting digital twins,” Computer, vol. 55, no. 7, pp. 73–77, 2022. doi:10.1109/mc.2022.3149448
    [4] M. -H. Hung, Y. -C. Lin, H. -C. Hsiao, C. -C. Chen, K. -C. Lai, and Y. -M. Hsieh, “A Novel Implementation Framework of Digital Twins for Intelligent Manufacturing Based on Container Technology and Cloud Manufacturing Services,” IEEE Transactions on Automation Science and Engineering, vol. 19, no. 3, pp. 1614-1630, Jul. 2022, doi: 10.1109/TASE.2022.3143832.
    [5] M. Javaid, A. Haleem, R. Pratap Singh, S. Khan, and R. Suman, “Blockchain technology applications for Industry 4.0: A literature-based review,” Blockchain: Research and Applications, vol. 2, no. 4, p. 100027, Dec. 2021. doi:10.1016/j.bcra.2021.100027
    [6] U. Bodkhe, S. Tanwar, K. Parekh, P. Khanpara, S. Tyagi, and N. Kumar, “Blockchain for Industry 4.0: A Comprehensive Review,” IEEE Access, vol. 8, pp. 79764-79800, 2020, doi: 10.1109/ACCESS.2020.2988579.
    [7] W. R. Huang, J. Geiping, L. Fowl, G. Taylor, and T. Goldstein, “Metapoison: Practical general-purpose clean-label data poisoning,” arXiv.org, https://arxiv.org/abs/2004.00225
    [8] I. Pittaras and G. C. Polyzos, "Secure and Efficient Web of Things Digital Twins using Permissioned Blockchains," 2022 7th International Conference on Smart and Sustainable Technologies (SpliTech), Split / Bol, Croatia, 2022, pp. 1-5, doi: 10.23919/SpliTech55088.2022.9854219.
    [9] V. Divya, S. Arunarani, U. Hemamalini and A. Bharathi, "Blockchain Based Digital Twins for Authorization and Remote Resource Sharing," 2023 10th International Conference on Computing for Sustainable Global Development (INDIACom), New Delhi, India, 2023, pp. 382-385.
    [10] Z. Lv, “Digital Twins in industry 5.0,” Research, vol. 6, Jan. 2023. doi:10.34133/research.0071
    [11] P. Plebani, D. Rossetto, and F. Tiezzi, “Empowering trusted data sharing for data analytics in a federated environment: A Blockchain-based approach,” Frontiers in Blockchain, vol. 6, Apr. 2023. doi:10.3389/fbloc.2023.1141760
    [12] A. Dwivedi, A. Mishra, and D. Singh, “Cybersecurity and privacy issues of Blockchain technology,” Blockchain for Information Security and Privacy, pp. 69–94, Oct. 2021. doi:10.1201/9781003129486-4
    [13] W. Newhouse, M. Souppaya, J. Kent, K. Sandlin, and K. Scarfone, “Data classification concepts and considerations for improving data protection,” National Institute of Standards and Technology, Gaithersburg, MD, United States, Nov. 2023. doi:10.6028/nist.ir.8496.ipd
    [14] L. Wan, D. Eyers, and H. Zhang, “Evaluating the impact of network latency on the safety of blockchain transactions,” 2019 IEEE International Conference on Blockchain (Blockchain), Jul. 2019. doi:10.1109/blockchain.2019.00033
    [15] B. W. Tuinema, J. L. Rueda Torres, A. I. Stefanov, F. M. Gonzalez-Longatt, and M. A. van der Meijden, “Cyber-physical system modeling for assessment and enhancement of power grid cyber security, resilience, and reliability,” Probabilistic Reliability Analysis of Power Systems, pp. 237–270, 2020. doi:10.1007/978-3-030-43498-4_8.
    [16] N. Lefkovitz and K. Boeckl, “NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management,” Version 1.0," National Institute of Standards and Technology, Gaithersburg, MD, United States. doi:10.6028/nist.cswp.10.may
    [17] A. Johnson, K. Dempsey, R. Ross, S. Gupta, and D. Bailey, “Guide for security-focused configuration management of Information Systems,” Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, United States, Oct. 2019. doi:10.6028/nist.sp.800-128
    [18] R. Ross, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy”, National Institute of Standards and Technology, Gaithersburg, MD, United States, Dec. 2018. doi:10.6028/nist.sp.800-37r2
    [19] S. Suhail, R. Hussain, R. Jurdak, A. Oracevic, K. Salah, and C. S. Hong, “Blockchain-Based Digital Twins: Research Trends, Issues, and Future Challenges,” ACM Computing Surveys, vol. 54, no. 11s, pp. 240:1-240:34, Sep. 2022, doi: 10.1145/3517189.
    [20] V. Wylde, N. Rawindaran, J. Lawrence, R. Balasubramanian, E. Prakash, and A. Jayal, “Cybersecurity, Data Privacy and Blockchain: A Review,” SN Computer Science, vol. 3, no. 2, p. 127, Jan. 2022, doi: 10.1007/s42979-022-01020-4.
    [21] D. Chatziamanetoglou and K. Rantos, “Blockchain-based security configuration management for ICT Systems,” Electronics, vol. 12, no. 8, p. 1879, Apr. 2023. doi:10.3390/electronics12081879
    [22] M. Doger and S. Ulukus, “Transaction capacity, security and latency in blockchains,” arXiv.org, https://arxiv.org/abs/2402.10138
    [23] Č. Stefanović, “Industry 4.0 from 5G perspective: Use-cases, requirements, challenges and approaches,” 2018 11th CMI International Conference: Prospects and Challenges Towards Developing a Digital Economy within the EU, Copenhagen, Denmark, 2018, pp. 44-48, doi: 10.1109/PCTDDE.2018.8624728.
    [24] S. Cuñat Negueroles, R. Reinosa Simón, M. Julián, A. Belsa, I. Lacalle, and R. S-Julián, “A Blockchain-based Digital Twin for IoT deployments in logistics and transportation,” Future Generation Computer Systems, vol. 158, pp. 73-88, 2024, doi: 10.1016/j.future.2024.04.011.

    下載圖示
    2026-08-29公開
    QR CODE