User travel data security management system and method based on cloud computing

Through technical means such as multi-source data acquisition, encrypted transmission, privacy protection and distributed storage, the shortcomings of traditional systems in data storage and permission control are solved, and the security management and efficient analysis of user travel data are realized, ensuring the security and reliability of data transmission and storage are ensured, and the system's response speed and user experience are improved.

CN120408577AActive Publication Date: 2025-08-01BEIJING TRAVEL INT TOURISM TECH CO LTD +1

Patent Information

Application Number
CN202510359647.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-25
Publication Date
2025-08-01
Estimated Expiration
2045-03-25

AI Technical Summary

Technical Problem

The traditional cloud-based user travel data security management system lacks flexibility in the data storage architecture, making it difficult to deal with the influx of massive data during peak periods, resulting in lag and data loss; the data processing process is lengthy and inefficient, and valuable travel insights cannot be promptly fed back; the authority control is extensive, and the abuse of internal personnel rights and illegal external access seriously threatens user privacy.

Method used

It adopts multi-source data acquisition adaptation module, hybrid encryption transmission channel module, privacy identification and desensitization module, distributed storage architecture module, permission control and audit module, and data backup and recovery scheduling module, combining quantum key distribution, AES encryption, deep learning model, distributed storage, blockchain technology and intelligent cache to achieve secure data collection, encrypted transmission, privacy protection, sharded storage, permission control and efficient recovery.

Benefits of technology

Ensure the confidentiality and integrity of data transmission, identify and protect privacy-sensitive content, provide efficient access and reliable storage, realize transparent control and traceability of data, and enhance the value of data analysis and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408577A_ABST
    Figure CN120408577A_ABST
Patent Text Reader

Abstract

The invention provides a user travel data safety management system and method based on cloud computing, and the system comprises a multi-source data collection and adaption module which is used for collecting user travel data from various types of travel equipment; the hybrid encryption transmission channel module is used for establishing a safe transmission link between the data acquisition terminal and the cloud computing platform; the privacy screening and desensitization module is used for identifying and processing privacy sensitive contents in the data received by the cloud computing platform; the distributed storage architecture module is used for reliably storing user travel data on the cloud computing platform; the authority control and auditing module is used for controlling the calling authority of the external main body to the user travel data and auditing the data access condition; the data backup and recovery scheduling module recovers data when data risks exist; and the data visualization and analysis auxiliary module is used for presenting the data in a visualization mode. According to the invention, confidentiality, integrity and availability of travel data transmission and transparency and traceability of data access are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data management, and particularly to a user travel data security management system and method based on cloud computing. Background Art

[0002] A user travel data security management system based on cloud computing is a system that uses cloud computing technology to collect, store, process, and analyze user travel data. This system provides powerful computing and storage capabilities through a cloud platform to ensure the security, privacy, and efficiency of data. It uses technologies such as encryption, desensitization, and access control to protect the security of user data, and at the same time uses intelligent algorithms to analyze travel data to provide personalized services.

[0003] In today's digital age, intelligent travel has developed vigorously, and various travel APPs have become indispensable tools for people's daily travel. A large amount of travel data, including users' real-time geographical locations, travel preferences, frequently visited locations, and accurate travel times, is centrally collected and stored. Once these data fall into the hands of lawbreakers, it is extremely easy to accurately locate users through means such as data mining and correlation analysis, and carry out harassment, fraud, or even more serious personal threat behaviors.

[0004] However, the storage architecture of traditional data security management systems lacks elasticity and is difficult to adapt to the influx of massive data during peak hours, frequently experiencing lags or even data loss; the data processing process is long and inefficient, unable to provide timely valuable travel insights and meet the business requirements of traffic operation real-time scheduling, precision marketing, etc.; the permission control is extensive, and the abuse of internal personnel permissions and external illegal access continue to occur, seriously threatening user privacy. Therefore, it is urgent to develop innovative security management systems and methods. Summary of the Invention

[0005] In order to solve the technical problem that in the process of vibration detection of a measured object by a traditional vibration measuring instrument in the prior art, whether the light beam is perpendicular to the surface of the measured object is not considered. Since the surfaces of measured objects are not all horizontal, it is difficult to ensure the perpendicular state, the quality of the reflected light cannot be ensured, affecting the stability of the interference signal, that is, the mixed-frequency light, resulting in a large deviation in the vibration measurement result and low measurement accuracy, the present invention provides a user travel data security management system and method based on cloud computing.

[0006] The technical solutions provided by the embodiments of the present invention are as follows:

[0007] First aspect:

[0008] A multi-source data acquisition adaptation module, configured to collect user travel data from various types of travel devices;

[0009] The hybrid encryption transmission channel module is used to establish a transmission link between the data collection terminal and the cloud computing platform;

[0010] The privacy screening and desensitization module is used to identify and process the privacy-sensitive content in the data received by the cloud computing platform;

[0011] The distributed storage architecture module is used to store user travel data on the cloud computing platform;

[0012] The permission control and auditing module is used to control the access permissions of external entities to user travel data and audit data access situations;

[0013] The data backup and recovery scheduling module restores data in case of data risks through backup strategies, backup task execution, monitoring processes, and recovery processes;

[0014] The data visualization and analysis assistance module is used to present user travel data in a visual manner, deeply analyze user travel data in combination with data analysis algorithms, and organize the analysis results into reports.

[0015] Second aspect:

[0016] A method for secure management of user travel data based on cloud computing provided by an embodiment of the present invention is applied to the secure management system of user travel data based on cloud computing in the first aspect, and includes:

[0017] S1: Monitor the changes in the user's travel status in real time at each access device end. When it is detected that the user performs travel-related behaviors, activate the data collection process of the corresponding device, accurately collect the user's travel data according to the adaptation strategy, and perform preliminary format standardization and error checking on the user's travel data;

[0018] S2: Use the quantum key distribution mechanism to obtain a symmetric key. According to the symmetric key, use the AES algorithm to perform transmission segmentation and parallel encryption on the verified user travel data to obtain multiple encrypted data packets. Attach a message authentication code to each encrypted data packet. After completing the encrypted packaging, transmit the encrypted data packets to the cloud computing platform at high speed through a dedicated network channel;

[0019] S3: After the cloud computing platform receives the encrypted data packets, the privacy screening and desensitization module scans each encrypted data packet line by line through a deep neural network model, identifies the privacy-sensitive content of each encrypted data packet based on the training and learning results, determines the privacy data, and performs real-time desensitization processing on the privacy data according to the desensitization rules;

[0020] S4: The distributed storage architecture module receives the desensitized privacy data, parallelly cuts the desensitized privacy data into multiple data segments according to the data sharding strategy, evenly disperses and stores them in the storage nodes of each geographical area, and synchronously generates redundant copies to ensure data security. Based on the high-frequency access requirements, the edge cache nodes are used to intelligently cache the popular data segments related to the high-frequency access requirements;

[0021] S5: The data backup and recovery scheduling module formulates multiple backup strategies according to the importance, update frequency and regulatory requirements of the gate data segments, and dynamically adjusts the priorities of the backup tasks; uses the distributed task scheduling framework to allocate the backup tasks to multiple computing nodes and storage resources for parallel processing; when data recovery is required, selects to recover specific data at a specific past time point according to the requirements, and recovers the data of a specific geographical area or user travel data in the specific data;

[0022] S6: The data visualization and analysis assistance module selects appropriate visualization chart types according to the characteristics of the user travel data and the user's analysis requirements; starts the built-in data analysis algorithm to run on the desensitized data, and mines the potential value of the data on the premise of protecting user privacy; automatically generates a standardized analysis report template according to the user's analysis tasks and visualization results;

[0023] S7: When an external entity initiates a data call request, the permission control and audit module receives the request information. The smart contract strictly examines the elements of the identity, permission scope and access purpose of the requester based on the permission ledger of the blockchain. If the verification passes, the corresponding data is retrieved and extracted from the storage node, decrypted and provided to the requester; if the verification fails, the request is rejected and a detailed audit log is recorded for subsequent traceability analysis.

[0024] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:

[0025] In the embodiments of the present invention, the hybrid encryption transmission channel module uses quantum key distribution and AES encryption to ensure the confidentiality, integrity, and availability of data transmission, effectively defending against hacker attacks, data theft, and tampering. The privacy identification and de-sensitization module uses deep learning models and de-sensitization rules to accurately identify privacy-sensitive content and protect personal identity information and high-precision geographical locations, while retaining the analytical value of the data. The distributed storage architecture module uses multi-dimensional sharding and redundant backup technologies to ensure the high availability, security, and efficient access of data. The permission control and auditing module uses blockchain technology to establish an immutable permission ledger and monitor the risk of data abuse to ensure the transparency and traceability of data access. The data backup and recovery scheduling module ensures the secure backup of critical data and supports efficient and flexible data recovery to ensure the integrity and consistency of the data. The data visualization and analysis assistance module provides rich charts and custom layouts, supports in-depth data analysis and user classification, and enhances data value mining and user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0027] Figure 1 is the principle block diagram of the user travel data security management system based on cloud computing of the present invention;

[0028] Figure 2 is the principle block diagram of the multi-source data acquisition and adaptation module of the present invention;

[0029] Figure 3 is the principle block diagram of the hybrid encryption transmission channel module of the present invention;

[0030] Figure 4 is the principle block diagram of the privacy identification and de-sensitization module of the present invention;

[0031] Figure 5 is the principle block diagram of the distributed storage architecture module of the present invention;

[0032] Figure 6 is the principle block diagram of the permission control and auditing module of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0033] The following will describe the technical solutions in the present invention with reference to the drawings.

[0034] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to give examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.

[0035] To make the technical problems to be solved, technical solutions and advantages of the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.

[0036] Refer to the attached Figure 1 to show the principle block diagram of a user travel data security management system based on cloud computing provided by the present invention.

[0037] Such as Figure 1 shown, the multi-source data collection and adaptation module 101 is used to collect user travel data from various types of travel devices, the hybrid encryption transmission channel module 102 is used to establish a secure transmission link between the data collection terminal and the cloud computing platform, the privacy screening and desensitization module 103 is used to identify and process privacy-sensitive content in the data received by the cloud computing platform, the distributed storage architecture module 104 is used to reliably store user travel data on the cloud computing platform, the permission control and auditing module 105 is used to control the call permission of external entities to user travel data and audit the data access situation, the data backup and recovery scheduling module 106 is used to recover data in case of data risks through backup strategies, backup task execution and monitoring, and recovery processes, and the data visualization and analysis assistance module 107 is used to present the data in a visual way, deeply analyze the travel data in combination with data analysis algorithms, and organize and report the analysis results.

[0038] Refer to the attached Figure 2 to show the principle block diagram of the multi-source data collection and adaptation module provided by the embodiments of the present invention.

[0039] Such as Figure 2, the device interface adaptation sub-module 1011 is used to configure exclusive interface drivers for devices including but not limited to smartphones, in-vehicle intelligent terminals, and wearable devices. For smartphones, it adapts various types of sensor interfaces at the iOS and Android system levels. For example, it precisely docks sensors such as GPS, accelerometers, and gyroscopes using the Core Motion framework (iOS) and the SensorManager class (Android) to ensure stable data acquisition. For in-vehicle intelligent terminals, it develops conversion programs that adapt to the OBD interface protocols of different vehicle models, covering common protocols such as CAN and LIN, to achieve lossless reading of vehicle operation parameters. For wearable devices, it customizes communication protocols based on low-energy Bluetooth (BLE) to ensure stable pairing and data transmission with the mobile phone APP.

[0040] The acquisition frequency optimization sub-module 1012 dynamically adjusts the acquisition frequency according to the device's battery level, network status, and user travel status. Through the built-in intelligent battery monitoring algorithm, when the device's battery level is lower than 20%, it automatically reduces the acquisition frequency of non-critical sensors by 50%. Combining with network signal strength detection, in a weak network environment (signal strength lower than -90dBm), it reduces the frequency of data uploads, preferentially caches locally, and performs batch transmission after the network recovers. By using a machine learning model to analyze the user's travel behavior pattern in real-time, if it is determined that the user is in a stationary or regular commuting state, it appropriately reduces the acquisition frequency of high-frequency sensors. Once it identifies that the user enters an emergency travel (such as catching a plane or train) or a special travel scenario (such as tourism and exploration), it immediately increases the acquisition frequency of key data.

[0041] The data preprocessing sub-module 1013 denoises and time-synchronizes the collected data on the device side, and encapsulates it into a unified data frame according to a preset format. It uses the Kalman filter algorithm to remove the noise of GPS positioning data. It time-synchronizes different sensor data and uses the NTP protocol to ensure that the clock error of each device is within milliseconds, ensuring the consistency of data timing. It encapsulates multi-source data into a unified data frame according to a preset format for convenient subsequent transmission and processing.

[0042] Refer to the attached reference manual Figure 3 , which shows the principle block diagram of the hybrid encryption transmission channel module provided by the present invention.

[0043] As Figure 3, the quantum key distribution sub-module 1021 deploys quantum key distribution (QKD) terminal devices in data acquisition-intensive areas (such as urban transportation hubs and large parking lots) and cloud computing data centers, and is equipped with a professional operation and maintenance management system. This sub-module is responsible for the initialization configuration of QKD devices, the adjustment of key generation parameters, and the management of key storage and update. Regularly monitor the bit error rate of the quantum channel. When the bit error rate exceeds 1%, automatically trigger the channel calibration program; at the same time, dynamically allocate quantum key resources according to data transmission requirements to ensure that high-priority data (such as real-time location information) can obtain key encryption first.

[0044] The AES encryption execution sub-module 1022 selects a high-performance encryption chip with hardware acceleration capabilities or uses the GPU acceleration module of the cloud computing platform to build a parallel encryption processing architecture. Optimize the calculation process of the round function of the AES algorithm, adopt pipeline technology to reduce calculation latency. For large data block transmission, divide the data into multiple sub-blocks of a fixed size (such as 128 bits) for parallel encryption to improve encryption efficiency; dynamically schedule cloud computing resources according to the real-time encryption task volume to ensure that encryption processing does not become a bottleneck in data transmission and ensure the confidentiality of data during public network transmission.

[0045] The authentication code processing sub-module 1023 uses the HMAC-SHA256 algorithm to implement the generation and verification of message authentication codes (MACs). At the data sending end, calculate and generate a 256-bit authentication tag for each data packet, and record the relevant key information and timestamp of tag generation at the same time; the receiving end uses the same key and algorithm to verify the received data. If the tags are inconsistent, immediately trigger the data retransmission mechanism and feedback the abnormal information to the security audit center to ensure data integrity and prevent data from being tampered with during transmission.

[0046] Refer to the attached description Figure 4 , which shows the principle block diagram of the privacy discrimination and desensitization module provided by the present invention.

[0047] Such as Figure 4 , the data sample management sub-module 1031 widely collects a large number of travel data samples from different regions, cultures, and industries around the world in cooperation with big data companies and research institutions in the joint travel industry. Build a sample database management system to classify, store, manage versions, and update samples regularly. Classify according to multiple dimensions such as travel mode (such as bus, subway, self-driving, cycling, etc.), travel scenario (commuting, tourism, business travel, etc.), user group (age, occupation, gender, etc.) to facilitate accurate selection of samples for subsequent model training; regularly obtain new samples from channels such as Internet public data and industry reports to update the sample library to ensure the timeliness and diversity of model training data.

[0048] The deep learning model construction sub-module 1032 selects the long short-term memory network (LSTM) suitable for processing sequential data as the basic architecture, and builds a multi-layer hybrid neural network model by combining the feature extraction advantages of the convolutional neural network (CNN). The CNN is used to extract the spatial features (such as geographical location distribution and regional travel hotspots) in the travel data, and then the feature map is input into the LSTM network to learn the time series features, so as to accurately judge the privacy-sensitive content. During the model training process, an adaptive learning rate adjustment strategy is adopted, the learning rate is dynamically optimized according to the change of training loss, and the early stopping method is combined to prevent overfitting, continuously improving the model recognition accuracy and desensitization accuracy.

[0049] The desensitization rule execution sub-module 1033 formulates a detailed desensitization rule library according to different privacy levels and data types, and embeds it at the model output end. For high-precision geographical location information, technologies such as regional blurring and coordinate offset are adopted to convert the precise coordinates into a geographical area description within a certain range or the coordinate values after random offset; for travel data associated with personal identity information, such as names and ID numbers, anonymization processing is carried out, and the real information is replaced with a unique identifier; for the access records of sensitive places, the specific place names are blurred, and only the place category information (such as medical institutions, religious places, etc.) is retained, which not only retains part of the analysis value of the data but also effectively protects the core content of user privacy.

[0050] Refer to the appendix of the specification Figure 5 , which shows the principle block diagram of the distributed storage architecture module provided by the present invention.

[0051] As Figure 5 , the data sharding management sub-module 1041 designs a composite sharding function based on multiple dimensions such as user ID, travel timestamp, and geographical area code. The consistent hashing algorithm is used to evenly shard the user travel data. For example, the national travel data is divided into large regions such as East China and South China according to geographical codes, and each large region is further subdivided according to the user ID to ensure that the data sharding is convenient for management and can balance the storage load; at the same time, a sharding index management system is established to track and record information such as the storage location and replica distribution of each shard in real time, facilitating rapid data retrieval and recovery.

[0052] The redundant backup control sub-module 1042 adopts the Reed-Solomon erasure code technology and sets different redundancy levels according to the importance and reliability requirements of the data. For general data, the redundancy is 2 times, and for key core data, the redundancy is 3 times. A redundant backup scheduling program is developed to distribute and store redundant replicas among storage nodes; the redundant replicas are regularly checked for consistency. When it is found that the replica data is inconsistent, the erasure code algorithm is used to recover the incorrect replica from other normal replicas to ensure the high availability of the data, ensuring that even if some nodes suffer physical damage or data loss, the original data can be quickly recovered based on the redundant information.

[0053] The distributed cache scheduling sub-module 1043 selects an open-source distributed cache system (such as Redis) and configures cache servers at edge nodes close to the user request side. Develop an intelligent cache scheduling algorithm, use a cache eviction algorithm (such as LRU) to dynamically manage the cache space, and intelligently determine the cache content according to factors such as data access popularity and timeliness; combine data prefetching technology, and based on the user's historical access behavior and real-time travel trend, cache the data that may be accessed in advance to the edge nodes, improve the access speed of popular data, optimize the user experience, and reduce the latency of data backhaul reading.

[0054] Refer to the attached Figure 6 , which shows the principle block diagram of the permission control and auditing module provided by the present invention.

[0055] Such as Figure 6 , the blockchain platform building sub-module 1051 selects a mainstream blockchain open-source framework (such as Hyperledger Fabric) to build an enterprise-level blockchain platform. Responsible for the deployment of blockchain nodes, network configuration, and the generation of the genesis block during initialization; create independent identity certificates for each data access subject, and use asymmetric encryption technology to ensure the security of the certificates; register detailed permission information on the blockchain, including key information such as the accessible data range, access timeliness, and usage purpose restrictions, and use the distributed ledger feature of the blockchain to ensure that the permission records cannot be tampered with.

[0056] The permission verification execution sub-module 1052, when there is a data call request, the smart contract automatically obtains the identity and permission information of the requester from the blockchain and compares it with the request details. The comparison content covers key indicators such as the accessible data time period, geographical area, and data type. If it matches exactly, it sends a data retrieval instruction to the storage module; if it does not match, it triggers an alarm to notify the system administrator through the blockchain event mechanism, and records the detailed request information in the audit log area on the blockchain, and strictly reviews elements such as the identity of the requester, permission scope, and access purpose.

[0057] The audit traceability analysis sub-module 1053 uses a blockchain browser tool to develop an audit data analysis system. The administrator can view all data access historical records at any time, including detailed information such as the requester, access time, and retrieved data content; analyze the audit data through data mining algorithms to detect potential data abuse risks, such as frequently accessing data beyond the scope of business requirements and concentrated access during abnormal time periods; regularly generate audit reports to provide a basis for system optimization and compliance management, and achieve the transparency and traceability of the data call history.

[0058] A cloud computing-based user travel data security management system provided by an embodiment of the present invention includes:

[0059] The multi-source data acquisition adaptation module 101 is used to collect user travel data from various types of travel devices;

[0060] The hybrid encryption transmission channel module 102 is used to establish a transmission link between the data acquisition terminal and the cloud computing platform;

[0061] The privacy screening and desensitization module 103 is used to identify and process privacy-sensitive content in the data received by the cloud computing platform;

[0062] The distributed storage architecture module 104 is used to store user travel data on the cloud computing platform;

[0063] The permission control and auditing module 105 is used to control the call permissions of external entities to user travel data and audit the data access situation;

[0064] The data backup and recovery scheduling module 106 restores data in case of data risks through backup strategies, backup task execution, monitoring processes, and recovery processes;

[0065] The data visualization and analysis assistance module 107 is used to present user travel data in a visual manner, deeply analyze the user travel data in combination with data analysis algorithms, and organize the analysis results into a report.

[0066] It should be noted that through device interface adaptation, dynamic adjustment of the acquisition frequency, and data preprocessing (such as denoising, time synchronization, and Kalman filtering), the data acquisition process is optimized, the device load and network pressure are reduced, and the accuracy and efficiency of the acquired data are ensured, thereby improving the performance of the system and the data quality.

[0067] In a possible implementation manner, the multi-source data acquisition adaptation module includes:

[0068] The device interface adaptation sub-module 1011 is used to configure exclusive interface driver programs for smartphones, in-vehicle intelligent terminals, and wearable devices;

[0069] The acquisition frequency optimization sub-module 1012 is used to dynamically adjust the acquisition frequency according to the device power, network status, and user travel status;

[0070] The data preprocessing sub-module 1013 is used to perform denoising and time synchronization calibration on the acquired data at the device end, encapsulate it into a unified data frame in a preset format, and use the Kalman filtering algorithm to remove GPS positioning data noise.

[0071] In a possible implementation manner, the hybrid encryption transmission channel module 102 includes:

[0072] The quantum key distribution sub-module 1021 is used to deploy quantum key distribution terminal devices in data acquisition intensive areas and cloud computing data centers, and is equipped with an operation and maintenance management system. The operation and maintenance management system is responsible for the initialization configuration of QKD devices, the adjustment of key generation parameters, key storage, and key update management.

[0073] The AES encryption execution sub-module 1022 is used to build a parallel encryption processing architecture, optimize the round function calculation process of the AES algorithm, perform transmission segmentation and parallel encryption on large data blocks, and after completing the verification of the integrity of the verifiable static data storage of cloud computing users, restore the data and dynamically schedule cloud computing resources according to the real-time encryption task volume.

[0074] The authentication code processing sub-module 1023 is used to calculate and generate 256-bit authentication tags for each data packet at the data sending end using the HMAC-SHA256 algorithm, and record the relevant key information and timestamp for generating the authentication tags at the same time. The receiving end uses the same key and algorithm for verification. If the tags are inconsistent, the data retransmission mechanism is immediately triggered, and the abnormal information is fed back to the security audit center.

[0075] Among them, the QKD device is an encryption technology based on the principles of quantum physics, used to securely distribute encryption keys, transmit keys through quantum bits (qubits), and utilize the characteristics of quantum mechanics (such as quantum superposition, quantum entanglement) to ensure the security of keys. AES (Advanced Encryption Standard) is a symmetric encryption algorithm and one of the most widely used encryption standards currently, using the same key for data encryption and decryption, and supporting different key lengths (128 bits, 192 bits, 256 bits). HMAC-SHA256 (Hash-based Message Authentication Code with SHA-256) is a message authentication code algorithm based on the SHA-256 hash function.

[0076] It should be noted that through quantum key distribution (QKD), AES encryption, and authentication code processing, multi-level encryption and authentication guarantees are provided to ensure the confidentiality and integrity of data during transmission. Quantum key distribution ensures the security of key transmission, AES encryption optimizes the encryption efficiency of large data blocks, and HMAC-SHA256 authentication code processing further enhances the verification and reliability of data, preventing data tampering and loss, and improving the security and efficiency of the entire system.

[0077] In a possible implementation manner, performing transmission segmentation and parallel encryption on large data blocks, and after completing the verification of the integrity of the verifiable static data storage of cloud computing users, restoring the data, specifically including:

[0078] Divide large data blocks into multiple fixed-size language sub-blocks according to the internal logical structure of the data or predefined rules, and use the AES algorithm to assign independent encryption keys to each data sub-block. Among them, the encryption keys are dynamically generated and distributed by the key management system.

[0079] After the data is stored in the cloud computing platform, adopt a verifiable storage integrity verification mechanism. Based on the message authentication code HMAC technology of the hash function, when storing the data, calculate the hash value of each data sub-block and store the hash value together with the data sub-block; when the data needs to be restored, recalculate the hash value of the stored data sub-block and compare it with the previously stored hash value; if the hash values are consistent, reassemble the divided sub-blocks in the original order through the data recovery program to restore them into a complete data file; if the hash values are inconsistent, trigger the data repair or alarm mechanism to notify the administrator that the data may have been damaged or tampered with.

[0080] In the present invention, large data blocks are divided into multiple fixed-size sub-blocks according to the internal logical structure of the data or predefined rules. For example, a data file with a capacity of 1GB is divided in units of 128MB. For each sub-block, utilize the multi-core processors or GPU acceleration resources provided by the cloud computing platform to start the encryption process in parallel. Select algorithms such as the Advanced Encryption Standard (AES) algorithm to assign independent encryption keys to each sub-block. The keys can be dynamically generated and distributed by the key management system to ensure the security of the encryption process. Through parallel encryption, make full use of the powerful computing power of the cloud computing, greatly improve the encryption efficiency, shorten the transmission preparation time of large data blocks, and meet the application scenarios with high real-time requirements.

[0081] After the data is stored in the cloud computing platform, in order to ensure the integrity of the data, adopt a verifiable storage integrity verification mechanism. For example, use the message authentication code (HMAC) technology based on the hash function. When storing the data, calculate the hash value of each data sub-block and store the hash value together with the data sub-block. When the data needs to be restored, first recalculate the hash value of the stored data sub-block and compare it with the previously stored hash value. If the hash values are consistent, it means that the data has not been tampered with during storage, and the divided sub-blocks are reassembled in the original order through the data recovery program to restore them into a complete data file. If the hash values are inconsistent, trigger the data repair or alarm mechanism to notify the administrator that the data may have been damaged or tampered with, and take corresponding measures in a timely manner to ensure the reliability and availability of the user data.

[0082] It should be noted that by splitting large data blocks and assigning independent encryption keys to each sub-block, the encryption processing efficiency and security are improved. Combining the message authentication code (HMAC) technology of the hash function ensures the integrity and verifiability of data storage. When data is restored, through hash value verification, it is ensured that the data has not been tampered with during transmission or storage. If inconsistencies are found, the repair mechanism can be triggered in a timely manner to effectively prevent data corruption or loss, ensuring the high availability and reliability of the data.

[0083] In a possible implementation manner, the privacy screening and desensitization module 103 includes:

[0084] The data sample management sub-module 1031 is used to collect travel data samples under different geographical locations, cultures, and industry backgrounds, and build a sample database management system based on the travel data samples to classify and store, manage versions, and update regularly the user travel data samples, and conduct multi-dimensional classification according to travel modes, travel scenarios, and user groups.

[0085] The deep learning model construction sub-module 1032 is used to select a multi-layer hybrid neural network model by combining long short-term memory networks with convolutional neural networks, use the CNN to extract the spatial features of user travel data, determine the feature map, and input the feature map into the LSTM network to learn the time series features to determine the privacy-sensitive content.

[0086] Among them, using the CNN to extract the spatial features of user travel data, determining the feature map, and inputting the feature map into the LSTM network to learn the time series features to determine the privacy-sensitive content specifically includes:

[0087] Using the CNN to extract the spatial features of user travel data and determining the feature map:

[0088]

[0089] Among them, a i,j represents the activation value at the position (i, j) on the feature map after the convolution operation, f represents the activation function, w m,n represents the weight corresponding to the position (m, n) on the convolution kernel, x i+m,j+n represents the value at the position (i + m, j + n) in the input data, m = 1, 2,..., M, M represents the total number of rows of the convolution kernel, n = 1, 2,..., N, N represents the total number of columns of the convolution kernel, and b represents the bias.

[0090] Performing a flattening operation on the feature map:

[0091] x t = flatten(a i,j )

[0092] Among them, x tDenote the flattened feature map, and flatten represents the flattening operation.

[0093] Input the flattened feature map into the LSTM network to determine the hidden state:

[0094] i t = σ(w xi x t + w hi h t-1 + b i )

[0095] f t = σ(w xf x t + w hf h t-1 + b f )

[0096] o t = σ(w xo x t + w ho h t-1 + b o )

[0097]

[0098] h t = o t · tanh(c t )

[0099] Among them, i t represents the input gate, f t represents the forget gate, o t represents the output gate, represents the candidate memory state at time t, c t represents the determined memory cell state at time t, σ represents the Sigmoid function, w xi represents the weight matrix from the input data x t to the input gate, w hi represents the weight matrix from the hidden state h t-1 to the input gate, b i represents the bias vector of the input gate, w xf represents the weight matrix from the input data x t to the forget gate, w hf represents the weight matrix from the hidden state h t-1 to the forget gate, b f represents the bias vector of the forget gate, w xo represents the weight matrix from the input data x t to the output gate, w ho represents the weight matrix from the hidden state h t-1The weight matrix to the output gate, b o Represents the bias vector of the output gate, w xc Represents the input data x t to the weight matrix of the candidate memory state, w hc Represents the hidden state h t-1 to the weight matrix of the candidate memory state, b c represents the bias vector of the candidate memory state, and tanh represents the tanh activation function.

[0100] Determine the prediction score of privacy-sensitive content based on the hidden state:

[0101] y=W f ·h t +b s

[0102] Where y represents the predicted score of privacy-sensitive content, W f represents the weight matrix of the fully connected layer, b s represents the bias of the fully connected layer.

[0103] When the prediction score is greater than the preset prediction score, the privacy-sensitive content of the travel data is determined.

[0104] The desensitization rule execution submodule 1033 is used to develop a desensitization rule library based on different privacy levels and data types, and embed it into the model output. It uses regional fuzzification and coordinate offset for high-precision geographic location information, anonymizes personal identity information-linked travel data, and obfuscates the specific names of sensitive place entry and exit records.

[0105] The fuzzification is specifically as follows: the regional map is divided into geographical grids of uniform size according to certain rules. When a high-precision geographic location coordinate point is obtained, the grid unit to which the geographic location coordinate point belongs is determined, and the user's location information is fuzzily described as the grid area in which it is located; for high-precision latitude and longitude coordinates, coordinate offset is performed by adding randomly generated direction and position noise values.

[0106] The desensitization rule execution submodule uses regional fuzzification and coordinate offset for high-precision geographic location information, specifically:

[0107] The map is divided into uniformly sized geographical grids according to certain rules. For example, it can be divided based on the block divisions in urban planning, administrative area subdivisions, or according to longitude and latitude intervals (such as each 0.01 degrees × 0.01 degrees as a grid unit). When obtaining high-precision geographical location coordinate points, determine the grid unit to which the coordinate point belongs, and vaguely describe the user's location information as the grid area where they are located. For example, a coordinate point near Wangfujing Street in Beijing, after geographical grid division, is classified into the "Wangfujing Business District Grid Unit", and the location information displayed externally becomes "The user is located in the Wangfujing Business District", rather than being precise to the specific house number or store coordinates. The advantage of this method is that while retaining certain regional characteristics, it greatly hides the precise location details. Moreover, the finer the grid division, the more precise the description of the regional characteristics can be, which can not only meet the application requirements based on regional analysis, such as counting the pedestrian flow trend in a certain business district, but also protect user privacy.

[0108] For high-precision longitude and latitude coordinates, add randomly generated direction and position noise values to perform coordinate offset. For example, let the original coordinate be, the offset of longitude and the offset of latitude are generated by a random number generator and satisfy a certain distribution law, such as a normal distribution, with a mean of 0, and the standard deviation is set according to the required privacy protection level and the positioning accuracy requirements of the application scenario (if the application has low requirements for positioning accuracy and strong privacy needs, the standard deviation can be set relatively large). The new coordinate becomes, so that when storing data or sharing it externally, the offset coordinates are used. Even if the data is leaked, it is difficult for attackers to restore the true precise location. Another example is to randomly select an angle between 0 and 360 degrees, and then calculate the specific offsets of longitude and latitude through trigonometric functions according to the preset offset distance (also set according to privacy protection requirements, such as 100 meters, 500 meters, etc.).

[0109] It should be noted that by combining convolutional neural network (CNN) and long short-term memory network (LSTM), efficiently extract the spatial and temporal features of travel data, so as to accurately identify privacy-sensitive content. At the same time, use desensitization technologies such as regional fuzzification, coordinate offset, and anonymization processing to protect the security of user privacy data. Through multi-dimensional classification and regularly updated sample management, further improve the accuracy and adaptability of privacy recognition, effectively prevent privacy leakage, and ensure the security and compliance of data.

[0110] In a possible implementation manner, the distributed storage architecture module 104 includes:

[0111] The data sharding management sub-module 1041 is used to design a composite sharding function based on multiple dimensions including user ID, travel timestamp, and geographical area code, evenly shard user travel data using the consistent hashing algorithm, and establish a sharding index management system to track and record the sharding storage location and replica distribution information.

[0112] The redundant backup control sub-module 1042 is used to adopt the Reed-Solomon erasure code technology, develop a redundant backup scheduling program to distribute and store redundant replicas, regularly perform consistency verification on the redundant replicas, and use the Reed-Solomon erasure code technology to recover the error replicas.

[0113] Among them, the Reed-Solomon erasure code technology is an error-correcting coding technology widely used in data storage and transmission, mainly used to solve the problems of data loss and damage.

[0114] The distributed cache scheduling sub-module 1043 is used to select an open-source distributed cache system, configure cache servers at edge nodes close to the user request end, develop an intelligent cache scheduling algorithm, dynamically manage the cache space using an intelligent cache eviction algorithm, and pre-cache the data that may be accessed in advance by combining data prefetching technology.

[0115] It should be noted that through data sharding management, consistent hashing, and redundant backup technologies, the efficient storage and high availability of user travel data are ensured. The Reed-Solomon erasure code technology is used to achieve the recovery and consistency verification of data replicas, ensuring data reliability. Distributed cache scheduling improves data access speed, reduces the pressure on the main storage, and further enhances the performance and response efficiency of the system by optimizing cache space management and data prefetching.

[0116] In a possible implementation manner, the permission control and auditing module 105 is specifically as follows:

[0117] The blockchain platform building sub-module 1051 is used to select a blockchain open-source framework to build an enterprise-level blockchain platform, responsible for the deployment of blockchain nodes, network configuration, and initialization of the genesis block generation, create independent identity certificates for each data access subject, and register detailed permission information on the blockchain.

[0118] The permission verification execution sub-module 1052 is used to, in the case of a data call request, automatically obtain the identity information and permission information of the requester from the blockchain through a smart contract, and compare the identity information and permission information with the request details, covering key indicators such as the accessible data time period, geographical area, and data type. If they match, a retrieval instruction is sent to the storage module. If they do not match, an alarm is triggered and the request information is recorded in the audit log area.

[0119] The audit traceback analysis sub-module 1053 is used to develop an audit data analysis system through a blockchain browser tool. The administrator can view the data access history records, mine for misused data through data mining algorithms, and generate an audit report.

[0120] Generating the audit report specifically includes:

[0121] Select the association rule mining algorithm to find frequently occurring request patterns, and use the clustering analysis algorithm to group data access requests according to similarity. When a strange IP address that has never had data access permission suddenly accesses sensitive travel data intensively, it indicates the existence of potential data misuse risks.

[0122] Using the execution results of the data mining algorithm as input, sort out potential data misuse clues, verify whether the true identity, permission scope, and access purpose of the relevant requester match the records. According to the verification results, generate an audit report according to a predetermined report template. The audit report includes an overview of potential problems discovered by data mining, a detailed description of problem clues, an explanation of the problem verification situation, and recommended measures for the discovered problems.

[0123] Among them, the data misuse clues include abnormal frequent access patterns and suspicious access clusters obtained by clustering analysis.

[0124] It should be noted that through blockchain technology, an independent identity certificate is provided for each data access subject, and smart contracts are used to automatically verify permissions to ensure the transparency and traceability of data access. Combining audit traceback and data mining algorithms, the system can monitor potential data misuse risks in real time, generate detailed audit reports, help administrators identify abnormal access patterns and misuse behaviors, enhance data security and compliance, and prevent illegal access and permission abuse.

[0125] In the present invention, the association rule mining algorithm, such as the Apriori algorithm or its improved version, is selected to analyze the data access logs. These logs record all data call requests, including detailed information such as the requester, access time, and data content obtained. Through association rule mining, attempts are made to find frequently occurring request patterns, such as a specific institution frequently accessing the travel data of users in a specific area within a short period of time, or the travel data of a certain user group always being called by certain specific third parties within a similar time period.

[0126] Meanwhile, the clustering analysis algorithm is used to group data access requests according to similarity. Clustering can be performed based on multiple dimensions such as the type of requester (e.g., enterprises, government departments, research institutions, etc.), the type of data accessed (e.g., high-precision geographical location data, travel trajectory data, travel habit data, etc.), and the access time distribution. This helps to identify abnormal access clusters. For example, a group of unfamiliar IP addresses that have never had data access rights suddenly access a certain type of sensitive travel data in a concentrated manner, which may imply potential data abuse risks.

[0127] Start the audit report generation task regularly (e.g., weekly or monthly). First, take the execution results of the data mining algorithm as input and sort out potential data abuse clues. These clues include abnormal frequent access patterns discovered through association rule mining, suspicious access clusters obtained from clustering analysis, etc. Conduct a detailed investigation and verification for each clue. Interact with the data access permission management system to verify whether the real identity, permission scope, and access purpose of the relevant requester match the records. For example, for an organization found to frequently access a certain type of data, check whether its originally applied data access permission exceeds the authorized scope of operation. According to the verification results, generate an audit report according to a pre-determined report template. The report content should include an overview of potential problems discovered through data mining, a detailed description of problem clues (such as the requester involved, access time, data type, etc.), a description of the problem verification situation, and proposed recommended measures for the discovered problems, such as suspending the data access permission of the violating requester and strengthening access control for specific data types. The audit report is presented in a clear and easy-to-understand format for reference by system administrators, compliance departments, and senior decision-makers, so as to take timely measures to prevent data abuse risks and ensure the data security and compliant operation of the system.

[0128] In a possible implementation manner, the data backup and recovery scheduling module specifically includes:

[0129] The backup strategy formulation sub-module is used to formulate different backup strategies according to the importance, update frequency, and regulatory requirements of the data, and dynamically adjust the backup priority based on the storage time and access popularity of the data.

[0130] Among them, the method of dynamically adjusting the backup priority based on the storage time and access popularity of the data specifically includes:

[0131] Determine the backup priority:

[0132] CP(x) = W1·UF(x) + W2·k(x) + W3·PC(x) + W4·evi(x) + W5·hotness(x)

[0133] Among them, CP() represents the priority of backup, W1, W2, W3, W4, and W5 all represent weights, UF() represents the update frequency of data, k() represents the criticality of data, PC() represents the access priority of data, evi() represents the validity period of data, and hotness() represents the popularity of data.

[0134] Dynamically adjust the priority of backup according to the storage time and access popularity:

[0135] CP(x)′=(α·CP(x)·e -λ t)+(1-α)·H

[0136] Among them, CP()′ represents the dynamically adjusted priority, α represents the weight coefficient, λ represents the attenuation coefficient, t represents the storage time, e represents the exponent, and H represents the number of accesses to the data.

[0137] The backup task execution and monitoring sub-module uses a distributed task scheduling framework to distribute backup tasks to multiple computing nodes and storage resources for parallel processing, and maintains real-time communication with storage nodes through a heartbeat detection mechanism to monitor the backup progress and status.

[0138] Among them, the specific method of distributing backup tasks to multiple computing nodes and storage resources for parallel processing using a distributed task scheduling framework is as follows:

[0139] Establish an objective function and constraint conditions regarding the information span of backup tasks.

[0140] Under the constraints of the constraint conditions, with the goal of minimizing the objective function, use the particle swarm optimization algorithm to determine the optimal scheduling plan.

[0141] Through the optimal scheduling plan, distribute backup tasks to multiple computing nodes and storage resources for parallel processing.

[0142] Among them, the objective function is specifically:

[0143] f(x)=MinimizeS,M low ≤S≤M up

[0144] M low =max(d1,d2,d3)

[0145]

[0146] d1=max(D i )

[0147]

[0148]

[0149] Among them, f(x) represents the objective function, Minimize represents minimization, S represents the information span of the backup task, M low represents the lower limit of the information span, M up represents the upper limit of the information span, max represents maximization, d1 represents the duration required for the backup task with the longest execution time, d2 represents the shortest total processing duration when processing all backup tasks according to the maximum computing throughput, d3 represents the shortest processing duration required when processing all backup tasks according to the maximum number of backup tasks that the server can synchronously process, D i represents the duration of the i-th backup task, T i represents the computing requirement of the i-th backup task, i = 1, 2,..., n, n represents the total number of backup tasks, m represents the total number of servers, sunT represents the maximum computing throughput of the server, and mmsDA represents the maximum number of backup tasks that each server synchronously processes.

[0150] The constraint conditions specifically include:

[0151]

[0152] R ijt ≥P ij +Q it -1

[0153] Among them, P ij represents whether the i-th backup task is assigned to the j-th server, i = 1, 2,..., n, n represents the total number of backup tasks, j = 1, 2,..., m, m represents the total number of servers, Q it represents whether the i-th backup task starts at time t, R ijt′ represents whether the i-th backup task is processed by the j-th server at time t′, t′ represents the start time of the execution of the i-th backup task, Q it′ represents whether the i-th backup task starts at time t′.

[0154] Adopting the particle swarm optimization algorithm, the method for determining the optimal scheduling scheme is specifically as follows:

[0155] Initialize the particle swarm, and set the inertia weight range, learning factor, maximum number of iterations, population size, particle position, particle velocity, individual optimal value, and population global optimal value.

[0156] Calculate the non-linear weight of each particle:

[0157]

[0158] Among them, ω(t) represents the inertia weight of the iteration at time t, ωmax represents the initial maximum value of the inertia weight, ω min represents the initial minimum value of the inertia weight, T represents the maximum number of iterations, and t represents the current number of iterations.

[0159] It should be noted that by dynamically adjusting the inertia weight, the global search and local search capabilities can be effectively balanced. In the initial stage of iteration, a larger inertia weight helps the particles conduct a more extensive global search to cover the entire solution space. In the later stage of iteration, a smaller inertia weight enhances the local search ability of the particles and accelerates the convergence to the optimal solution. The non-linear decreasing method is more flexible than the linear decreasing method and can improve the convergence efficiency and optimization accuracy of the algorithm in complex optimization problems.

[0160] Update the velocity and position of each particle according to the non-linear weight:

[0161] v i (t + 1) = ω(t)·v i (t) + c1r1(P i -x i ) + c2r2(G - x i )

[0162] x i (t + 1) = x i (t) + v i (t + 1)

[0163] where, v i (t + 1) represents the velocity of the i-th particle at the (t + 1)-th iteration, v i (t) represents the velocity of the i-th particle at the t-th iteration, c1 represents the individual learning factor, r1 and r2 represent random numbers, P i represents the historical optimal position of the i-th particle, x i represents the position of the i-th particle at the t-th iteration, c2 represents the swarm learning factor, G represents the global optimal position, x i (t + 1) represents the position of the i-th particle at the (t + 1)-th iteration.

[0164] Calculate the fitness value of each particle according to the updated position and velocity:

[0165] F(X) = wf(x)

[0166] where, F(X) represents the fitness value, w represents the weight coefficient, and f(X) represents the objective function.

[0167] Judge whether the particle position meets the constraint conditions according to the fitness value; if so, update the individual optimal value and the population global optimal value of the particle, otherwise, re-initialize the particle swarm.

[0168] Determine whether the maximum number of iterations is reached; if so, output the optimal position of the particles and the global optimal position of the population; otherwise, update the velocities and positions of each particle again.

[0169] The recovery process management sub-module restores specific data at a specific past time point according to requirements, and restores the specific geographical area data or user travel data of the specific data, and performs integrity and consistency verification on the restored specific data.

[0170] It should be noted that by dynamically adjusting the backup priority, allocating backup tasks, and processing backup tasks in parallel, the backup efficiency and resource utilization rate are significantly improved. At the same time, the recovery process management sub-module can restore data at a specific time point or area on demand, ensuring the integrity and consistency of data recovery, reducing the risk of data loss, and improving the reliability and flexibility of the system.

[0171] In a possible implementation manner, the data visualization and analysis assistance module specifically includes:

[0172] The data visualization tool integration sub-module is used to provide visualization chart types according to the characteristics of travel data and the analysis needs of users.

[0173] The data analysis algorithm library embedding sub-module has common data analysis algorithms built in, including clustering analysis algorithms and path planning algorithms; among them, the clustering analysis algorithm classifies user groups with similar travel behaviors, and the path planning algorithm can provide users with optimal travel route suggestions based on the user's historical travel data and real-time traffic information.

[0174] In the present invention, when the clustering analysis algorithm classifies user groups with similar travel behaviors, it will comprehensively consider various travel behavior characteristics, such as travel frequency, travel time pattern, travel distance, travel destination, etc. When the path planning algorithm uses the user's historical travel data and real-time traffic information, it will consider more traffic factors, such as the time of traffic lights, traffic control information, etc. The algorithm will perform path planning according to the user's travel time, traffic rules, and the characteristics of different traffic modes (such as the stop sites and timetables of buses).

[0175] The analysis report generation sub-module is used to automatically generate a standardized analysis report template according to the user's analysis tasks and visualization results, including data overview, key indicator analysis, visualization chart display, data insight conclusions, and recommended measures based on the analysis results, and output the report in the forms of PDF and HTML.

[0176] It should be noted that by integrating data visualization tools and common analysis algorithms, providing intuitive display and in-depth analysis of travel data, it can effectively identify users' travel patterns and optimize route planning, automatically generate standardized analysis reports, facilitate users to quickly obtain key data insights and suggestions, improve decision-making efficiency and user experience, and at the same time ensure the convenience and systematization of the data analysis process.

[0177] A method for managing the security of user travel data based on cloud computing, which is applied to the above-mentioned system for managing the security of user travel data based on cloud computing. The method includes:

[0178] S1: Real-time monitor the changes in the user's travel status at each access device end. When it detects that the user performs travel-related behaviors, activate the data collection process of the corresponding device, accurately collect the user's travel data according to the adaptation strategy, and perform preliminary format standardization and error checking on the user's travel data.

[0179] It should be noted that by real-time monitoring the changes in the user's travel status, it ensures that the data collection process is activated in a timely manner when the user starts traveling, improving the accuracy and timeliness of data collection. Combining the adaptation strategy and error checking ensures the high quality and consistency of the collected data, reduces data omission and errors, and optimizes the subsequent data processing process.

[0180] S2: Use the quantum key distribution mechanism to obtain a symmetric key. According to the symmetric key, use the AES algorithm to perform transmission segmentation and parallel encryption on the verified user travel data to obtain multiple encrypted data packets. Attach a message authentication code to each encrypted data packet. After completing the encrypted packaging, transmit the encrypted data packets to the cloud computing platform at high speed through a dedicated network channel.

[0181] It should be noted that combining the quantum key distribution mechanism and the AES encryption algorithm provides strong security protection for data transmission. The quantum key distribution ensures the unbreakability of key transmission, while the AES encryption and message authentication code enhance the confidentiality and integrity of the data. Transmitting data efficiently and securely through a dedicated network channel effectively prevents the risks of data leakage and tampering.

[0182] S3: After the cloud computing platform receives the encrypted data packets, the privacy screening and desensitization module scans each encrypted data packet line by line through a deep neural network model, identifies the privacy-sensitive content of each encrypted data packet based on the training and learning results, determines the private data, and performs real-time desensitization processing on the private data according to the desensitization rules.

[0183] It should be noted that by automatically identifying and processing privacy-sensitive content through a deep neural network model, ensuring that data meets privacy protection requirements during transmission and storage, real-time desensitization processing safeguards user privacy security, while retaining the analytical value of the data, improving the compliance and security of the data, and reducing the risk of privacy leakage.

[0184] S4: The distributed storage architecture module receives the desensitized privacy data, parallelly cuts the desensitized privacy data into multiple data segments according to the data sharding strategy, evenly disperses and stores them in the storage nodes of each geographical region, and synchronously generates redundant copies to ensure data security. Based on the high-frequency access demand, using edge cache nodes, intelligently caches the popular data segments related to the high-frequency access demand.

[0185] It should be noted that by parallelly cutting the data and dispersing it for storage in the storage nodes of multiple geographical regions, the storage efficiency and security of the data are improved. The generation of redundant copies ensures the availability of the data in case of any node failure. At the same time, the edge cache nodes optimize the data reading speed for high-frequency access, improve the response speed and overall performance of the system, and ensure the high availability and fast access of the data.

[0186] S5: The data backup and recovery scheduling module formulates multiple backup strategies according to the importance, update frequency, and regulatory requirements of the data segments, and dynamically adjusts the priorities of the backup tasks; uses a distributed task scheduling framework to allocate the backup tasks to multiple computing nodes and storage resources for parallel processing; when data recovery is required, selects to recover specific data at a specific past time point according to the demand, and recovers the data of a specific geographical region or user travel data in the specific data.

[0187] It should be noted that by dynamically adjusting the backup priority according to the importance and demand of the data, ensuring that critical data is backed up first, the risk of data loss is reduced. Using distributed task scheduling to achieve efficient parallel processing of backup tasks improves the backup efficiency and flexibility of the system. In addition, supporting the recovery of data at a specific time point or region on demand ensures the accuracy and pertinence of data recovery.

[0188] S6: The data visualization and analysis assistance module selects appropriate visualization chart types according to the characteristics of the user travel data and the user's analysis requirements; starts the built-in data analysis algorithm to run on the desensitized data, and mines the potential value of the data on the premise of protecting user privacy; automatically generates a standardized analysis report template according to the user's analysis tasks and visualization results.

[0189] It should be noted that by selecting appropriate visualization charts according to the characteristics of travel data and user needs, and combining common data analysis algorithms, it is ensured that while protecting user privacy, the data value is deeply mined, standardized reports are automatically generated, the efficiency and accuracy of data analysis are improved, it is convenient for users to intuitively understand data insights, and support is provided for decision-making.

[0190] S7: When an external entity initiates a data call request, the permission control and audit module receives the request information. The smart contract strictly examines the elements of the identity, permission scope, and access purpose of the requester based on the permission ledger of the blockchain. If the verification passes, the corresponding data is retrieved and extracted from the storage node, decrypted, and provided to the requester; if the verification fails, the request is rejected and a detailed audit log is recorded for subsequent traceability analysis.

[0191] It should be noted that by implementing permission control through blockchain technology, the security and transparency of data access are ensured. The smart contract automatically verifies the identity, permissions, and access purpose of the requester, avoiding unauthorized access. At the same time, the audit log is recorded for easy traceability, enhancing the protection and traceability of data, ensuring compliance, and effectively preventing data abuse.

[0192] The beneficial effects brought by the technical solution provided by the embodiments of the present invention at least include:

[0193] In the embodiments of the present invention, the hybrid encryption transmission channel module ensures the confidentiality, integrity, and availability of data transmission through quantum key distribution and AES encryption, effectively defending against hacker attacks, data theft, and tampering. The privacy screening and desensitization module uses deep learning models and desensitization rules to accurately identify privacy-sensitive content, protect personal identity information and high-precision geographical locations, while retaining the analysis value of the data. The distributed storage architecture module adopts multi-dimensional sharding and redundant backup technologies to ensure the high availability, security, and efficient access of data. The permission control and audit module establishes an immutable permission ledger through blockchain technology and monitors the risk of data abuse to ensure the transparency and traceability of data access. The data backup and recovery scheduling module ensures the secure backup of critical data and supports efficient and flexible data recovery to ensure the integrity and consistency of the data. The data visualization and analysis assistance module provides rich charts and custom layouts, supports in-depth data analysis and user classification, and enhances the mining of data value and user experience.

[0194] It should be understood that the processor in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0195] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM).

[0196] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0197] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context before and after.

[0198] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0199] It should be understood that in various embodiments of the present invention, the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.

[0200] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0201] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described devices, apparatuses, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0202] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.

[0203] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0204] In addition, the functional units in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0205] If a function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0206] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method for secure management of user travel data based on cloud computing as in the method embodiment.

[0207] The computer-readable storage medium provided by the present invention can implement the steps and effects of the method for secure management of user travel data based on cloud computing in the above method embodiment. To avoid repetition, the present invention will not elaborate further.

[0208] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

[0209] The following points need to be explained:

[0210] (1) The accompanying drawings of the embodiments of the present invention only relate to the structures involved in the embodiments of the present invention, and other structures can refer to the general design.

[0211] (2) For clarity, in the accompanying drawings used to describe the embodiments of the present invention, the thickness of layers or regions is enlarged or reduced, that is, these drawings are not drawn according to the actual scale. It can be understood that when an element such as a layer, a film, a region, or a substrate is referred to as being "on" or "under" another element, the element can be "directly" on or under another element or there can be intermediate elements.

[0212] (3) Without conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other to obtain new embodiments.

[0213] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. The protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A user travel data security management system based on cloud computing, characterized in that, Including: A multi-source data acquisition adaptation module for collecting user travel data from various types of travel devices; A hybrid encryption transmission channel module for establishing a transmission link between the data acquisition terminal and the cloud computing platform; A privacy screening and desensitization module for identifying and processing privacy-sensitive content in the data received by the cloud computing platform; A distributed storage architecture module for storing user travel data on the cloud computing platform; A permission control and auditing module for controlling the access permissions of external entities to user travel data and auditing data access situations; A data backup and recovery scheduling module for restoring data in case of data risks through backup strategies, backup task execution, monitoring processes, and recovery processes; A data visualization and analysis assistance module for presenting user travel data in a visual manner, deeply analyzing user travel data in combination with data analysis algorithms, and organizing the analysis results into reports.

2. The user travel data security management system based on cloud computing according to claim 1, characterized in that, The multi-source data acquisition adaptation module includes: A device interface adaptation sub-module for configuring exclusive interface driver programs for smartphones, in-vehicle intelligent terminals, and wearable devices; An acquisition frequency optimization sub-module for dynamically adjusting the acquisition frequency according to the device battery level, network status, and user travel status; A data preprocessing sub-module for denoising and time synchronization calibration of the collected data at the device end, encapsulating it into a unified data frame in a preset format, and using the Kalman filter algorithm to remove GPS positioning data noise.

3. The cloud computing-based user travel data security management system according to claim 1, characterized in that The hybrid encryption transmission channel module includes: A quantum key distribution sub-module for deploying quantum key distribution terminal devices in data acquisition intensive areas and cloud computing data centers, and supporting an operation and maintenance management system, which is responsible for the initialization configuration of QKD devices, key generation parameter adjustment, key storage, and key update management; An AES encryption execution sub-module for building a parallel encryption processing architecture, optimizing the round function calculation process of the AES algorithm, performing transmission segmentation and parallel encryption on large data blocks, and after completing the verification of the integrity of the verifiable static data storage of cloud computing users, restoring the data and dynamically scheduling cloud computing resources according to the real-time encryption task volume; An authentication code processing sub-module for calculating and generating a 256-bit authentication tag for each data packet at the data sending end using the HMAC-SHA256 algorithm, and simultaneously recording the relevant key information and timestamp for generating the authentication tag. The receiving end uses the same key and algorithm for verification. If the tags are inconsistent, the data retransmission mechanism is immediately triggered, and the abnormal information is fed back to the security audit center.

4. The user travel data security management system based on cloud computing according to claim 3, characterized in that, The performing transmission segmentation and parallel encryption on large data blocks, and after completing the verification of the integrity of the verifiable static data storage of cloud computing users, restoring the data specifically includes: Dividing the large data block into multiple fixed-size data sub-blocks according to the internal logical structure or predetermined rules of the data, and using the AES algorithm to allocate independent encryption keys for each of the data sub-blocks, wherein the encryption keys are dynamically generated and distributed by the key management system; After the data is stored in the cloud computing platform, a verifiable storage integrity verification mechanism is adopted. Based on the message authentication code HMAC technology of the hash function, when the data is stored, the hash values of each data sub-block are calculated and stored together with the data sub-blocks; when the data needs to be restored, the hash values of the stored data sub-blocks are recalculated and compared with the previously stored hash values; if the hash values are the same, the split data sub-blocks are reassembled in the original order through a data recovery program to restore the complete data file; if the hash values are different, a data repair or alarm mechanism is triggered to notify the administrator that the data has been damaged or tampered with.

5. The cloud computing-based user travel data security management system according to claim 1, wherein, The privacy screening and desensitization module includes: A data sample management sub-module, which is used to collect user travel data samples under different geographical regions, cultures, and industry backgrounds, and build a sample database management system based on the user travel data samples, classify and store, manage versions, and update regularly the user travel data samples, and perform multi-dimensional classification according to travel modes, travel scenarios, and user groups; A learning model construction sub-module, which is used to select a multi-layer hybrid neural network model by combining a long short-term memory network and a convolutional neural network, use the CNN to extract the spatial features of user travel data, determine the feature map, and input the feature map into the LSTM network to learn the time series features to determine the privacy-sensitive content; Among them, using the CNN to extract the spatial features of user travel data, determining the feature map, and inputting the feature map into the LSTM network to learn the time series features to determine the privacy-sensitive content specifically includes: Using the CNN to extract the spatial features of user travel data and determining the feature map: Among them, a i,j represents the activation value at the position (i, j) on the feature map after the convolution operation, f represents the activation function, and w m,n represents the corresponding weight at the position (m, n) of the convolution kernel, x i+m,j+n represents the value at the position (i + m, j + n) in the input data, where m = 1, 2,..., M, M represents the total number of rows of the convolution kernel, n = 1, 2,..., N, N represents the total number of columns of the convolution kernel, and b represents the bias; Performing a flattening operation on the feature map: x t = flatten(a i,j ) where x t represents the flattened feature map, and flatten represents the flattening operation; Inputting the flattened feature map into the LSTM network to determine the hidden state: i t = σ(w xi x t + w hi h t-1 + b i ) f t = σ(w xf x t + w hf h t-1 + b f ) o t = σ(w xo x t + w ho h t-1 + b o ) h t = o t ·tanh(c t ) Among them, i t represents the input gate, f t represents the forget gate, o t represents the output gate, represents the candidate memory state at time t, c t represents the determined memory cell state at time t, σ represents the Sigmoid function, w xi represents the input data x t to the weight matrix of the input gate, w hi represents the hidden state h t-1 to the weight matrix of the input gate, b i represents the bias vector of the input gate, w xf represents the input data x t to the weight matrix of the forget gate, w hf represents the hidden state h t-1 to the weight matrix of the forget gate, b f represents the bias vector of the forget gate, w xo represents the input data x t to the weight matrix of the output gate, w ho represents the hidden state h t-1 to the weight matrix of the output gate, b o represents the bias vector of the output gate, w xc represents the input data x t to the weight matrix of the candidate memory state, w hc represents the hidden state h t-1 to the weight matrix of the candidate memory state, b c represents the bias vector of the candidate memory state, tanh represents the tanh activation function; Determining the prediction score of the privacy-sensitive content according to the hidden state: y = W f ·h t +b s Among them, y represents the predicted score of privacy-sensitive content, and W f represents the weight matrix of the fully connected layer, and b s represents the bias of the fully connected layer; When the prediction score is greater than the preset prediction score, determining the privacy-sensitive content of the user travel data; A desensitization rule execution sub-module, which is used to formulate a desensitization rule library according to different privacy levels and data types and embed it at the model output end, perform regional blurring and coordinate offset on high-precision geographical location information, anonymize the travel data associated with personal identity information, and blur the specific venue names of the access records of sensitive venues; Among them, the blurring specifically is: dividing the regional map into uniformly sized geographical grids according to certain rules. When obtaining high-precision geographical location coordinate points, determining the grid unit to which the geographical location coordinate points belong, and vaguely describing the user's location information as the grid area where they are located; for high-precision longitude and latitude coordinates, adding randomly generated direction and position noise values for coordinate offset.

6. The user travel data security management system based on cloud computing according to claim 1, characterized in that The distributed storage architecture module includes: A data sharding management sub-module, which is used to design a composite sharding function in multiple dimensions based on user ID, travel timestamp, and geographical area code, evenly shard the user travel data using the consistent hashing algorithm, establish a sharding index management system, and track and record the sharding storage location and replica distribution information; The redundant backup control sub-module is used to develop a redundant backup scheduler to store redundant copies in a distributed manner by adopting the Reed-Solomon erasure code technology, regularly perform consistency checks on the redundant copies, and use the Reed-Solomon erasure code technology to recover the error copies; The distributed cache scheduling sub-module is used to select an open-source distributed cache system, configure cache servers at edge nodes close to the user request end, develop an intelligent cache scheduling algorithm, and use the intelligent cache scheduling algorithm to dynamically manage the cache space, and pre-cache the data that may be accessed in advance by combining data prefetching technology.

7. The user travel data security management system based on cloud computing according to claim 1, characterized in that, The permission control and auditing module is specifically: The blockchain platform building sub-module is used to select a blockchain open-source framework to build an enterprise-level blockchain platform, responsible for the deployment of blockchain nodes, network configuration and initialization of the genesis block generation, create independent identity certificates for each data access subject, and register detailed permission information on the blockchain; The permission verification execution sub-module is used to automatically obtain the identity information and permission information of the requester from the blockchain through a smart contract in the case of a data call request, and compare the identity information and the permission information with the request details, covering key indicators such as the accessible data time period, geographical area, and data type. If they match, a retrieval instruction is sent to the storage module. If they do not match, an alarm is triggered and the request information is recorded in the audit log area; The audit traceability analysis sub-module is used to develop an audit data analysis system through a blockchain browser tool. The administrator can view the data access history, mine the misused data through data mining algorithms, and generate an audit report.

8. The user travel data security management system based on cloud computing according to claim 1, characterized in that The data backup and recovery scheduling module specifically includes: The backup strategy formulation sub-module is used to formulate different backup strategies according to the importance, update frequency and regulatory requirements of the data, and dynamically adjust the backup priority according to the storage time and access popularity of the data; Among them, the method of dynamically adjusting the backup priority according to the storage time and access popularity of the data specifically includes: Determine the backup priority: CP(x) = W1·UF(x) + W2·k(x) + W3·PC(x) + W4·evi(x) + W5·hotness(x) Among them, CP() represents the backup priority, W1, W2, W3, W4 and W5 all represent weights, UF() represents the update frequency of the data, k() represents the criticality of the data, PC() represents the access priority of the data, evi() represents the validity period of the data, and hotness() represents the popularity of the data; Dynamically adjust the backup priority according to the storage time and the access popularity: CP(x)' = (α · CP(x) · e -λt ) + (1 - α) · H Among them, CP( )′ represents the dynamically adjusted priority, α represents the weight coefficient, λ represents the attenuation coefficient, t represents the storage time, e represents the exponential, and H represents the number of accesses to the data; The backup task execution and monitoring sub-module is used to use a distributed task scheduling framework to allocate backup tasks to multiple computing nodes and storage resources for parallel processing, maintain real-time communication with storage nodes through a heartbeat detection mechanism, and monitor the backup progress and status; Among them, the method of using a distributed task scheduling framework to allocate backup tasks to multiple computing nodes and storage resources for parallel processing specifically includes: Establish an objective function and constraint conditions regarding the information span of backup tasks; Under the constraints of the said constraint conditions, with the goal of minimizing the objective function, adopt a particle swarm optimization algorithm to determine the optimal scheduling plan; Through the said optimal scheduling plan, allocate backup tasks to multiple computing nodes and storage resources for parallel processing; Among them, the specific form of the said objective function is: f(x) = Minimize S, M low ≤ S ≤ M up M low = max(d1, d2, d3) d1 = max(D i ) Among them, f(x) represents the objective function, Minimize represents minimization, S represents the information span of the backup tasks, M low represents the lower limit of the information span, M up represents the upper limit of the information span, max represents maximization, d1 represents the duration required for the backup task with the longest execution time, d2 represents the shortest total processing duration when processing all backup tasks according to the maximum computing throughput, d3 represents the shortest processing duration required when processing all backup tasks according to the maximum number of backup tasks that the server can synchronously process, D i represents the duration of the i-th backup task, T i represents the computing requirement of the i-th backup task, i = 1, 2,..., n, n represents the total number of backup tasks, m represents the total number of servers, sunT represents the maximum computing throughput of the server, mmsDA represents the maximum number of backup tasks that each server synchronously processes; The said constraint conditions specifically include: R ijt ≥P ij +Q it -1 Among them, P ij indicates whether the i-th backup task is assigned to the j-th server, where i = 1, 2,..., n (n represents the total number of backup tasks) and j = 1, 2,..., m (m represents the total number of servers), Q it indicates whether the i-th backup task starts at time t, R ijt′ indicates whether the i-th backup task is processed by the j-th server at time t', where t' represents the start time of the execution of the i-th backup task, Q it′ indicates whether the i-th backup task starts at time t'. The recovery process management sub-module selects specific data to be restored to a specific past time point according to requirements, and restores the specific geographical area data or user travel data of the specific data, and performs integrity and consistency verification on the restored specific data.

9. The cloud computing-based user travel data security management system according to claim 1, characterized in that, The said data visualization and analysis assistance module specifically includes: The data visualization tool integration sub-module is used to provide visualization chart types according to the characteristics of user travel data and the analysis needs of users; The data analysis algorithm library embedding sub-module has commonly used data analysis algorithms built in, including clustering analysis algorithms and path planning algorithms; among them, the said clustering analysis algorithm classifies user groups with similar travel behaviors, and the said path planning algorithm can provide users with optimal travel route suggestions based on users' historical travel data and real-time traffic information; The analysis report generation sub-module is used to automatically generate a standardized analysis report template according to the analysis tasks and visualization results of users, including data overview, key indicator analysis, visualization chart display, data insight conclusions, and recommended measures based on the analysis results, and output the report in the form of PDF and HTML.

10. A method for secure management of user travel data based on cloud computing, which is applied to the system for secure management of user travel data based on cloud computing according to any one of claims 1-9, characterized in that, It includes the following steps: S1: Real-time monitor the changes in the user travel status at each access device end. When it is detected that the user performs travel-related behaviors, activate the data collection process of the corresponding device, accurately collect user travel data according to the adaptation strategy, and perform preliminary format standardization and error verification on the said user travel data; S2: Use the quantum key distribution mechanism to obtain a symmetric key. According to the said symmetric key, use the AES algorithm to perform transmission segmentation and parallel encryption on the verified user travel data to obtain multiple encrypted data packets. Attach a message authentication code to each of the said encrypted data packets. After completing the encrypted packaging, transmit the said encrypted data packets to the cloud computing platform at high speed through a dedicated network channel; S3: After the cloud computing platform receives the said encrypted data packets, the privacy screening and desensitization module scans each of the said encrypted data packets line by line through a deep neural network model, identifies the privacy-sensitive content of each of the said encrypted data packets based on the training and learning results, determines the privacy data, and performs real-time desensitization processing on the said privacy data according to the desensitization rules; S4: The distributed storage architecture module receives the desensitized private data and, based on the data sharding strategy, divides the desensitized private data into multiple data segments in parallel. The data segments are evenly distributed and stored in storage nodes in various geographical areas. Redundant copies are simultaneously generated to ensure data security. Based on high-frequency access needs, the edge cache nodes are used to intelligently cache popular data segments related to the high-frequency access needs. S5: The data backup and recovery scheduling module formulates multiple backup strategies based on the importance, update frequency and regulatory requirements of the popular data segments, and dynamically adjusts the priority of the backup tasks; Using a distributed task scheduling framework, the backup tasks are distributed to multiple computing nodes and storage resources for parallel processing. When data recovery is required, specific data at a specific point in the past can be restored as needed, and specific geographic area data or user travel data within the specific data can be restored. S6: The data visualization and analysis auxiliary module selects an appropriate visualization chart type according to the characteristics of the user's travel data and the user's analysis needs; Launch the built-in data analysis algorithm and run it on the desensitized data to explore the potential value of the data while protecting user privacy; automatically generate standardized analysis report templates based on the user's analysis tasks and visualization results; S7: When an external entity initiates a data call request, the permission control and audit module receives the request information. The smart contract strictly examines the identity, permission scope, and access purpose of the requester based on the permission ledger of the blockchain. If the verification passes, the smart contract retrieves and extracts the corresponding data from the storage node, decrypts it, and provides it to the requester. If the verification fails, the request will be rejected and a detailed audit log will be recorded for subsequent retrospective analysis.

Citation Information

Patent Citations

  • Highway section-level data middle station system

    CN112687097A

  • Enterprise-level data backup and recovery method and system for power field

    CN117234798A

  • Cloud computing electronic information security storage system

    CN118075029A

  • Michelson interference vibration testing system and vibration testing method

    CN119309665A

  • Aviation converter fault detection method based on information fusion algorithm

    CN119622648A

Cited By

  • System and method for constructing trusted secure digital storage space

    CN120995487A

  • Intelligent analysis and identification method for resident travel characteristics based on multi-source data fusion

    CN121167328A

  • Distributed partition storage security method and system for new energy truck carbon data

    CN121502821A

  • A distributed partition storage security method and system for carbon data of new energy trucks

    CN121502821B