A method and system for dynamic encryption of geographic information data based on spatiotemporal characteristics
By generating a multi-dimensional access weight matrix and dynamic key seeds, combined with homomorphic encryption technology, the problems of poor encryption effect and low security in multi-institutional geographic information data sharing scenarios are solved, and the security and efficiency of dynamic permission control and cross-institutional data aggregation are achieved.
Patent Information
- Application Number
- CN202510883861.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2045-06-30
AI Technical Summary
In the scenario of multi-institutional geographic information data sharing, the existing technology has a mismatch between static segmentation and dynamic access requirements, rigid permission policies, and a lack of spatiotemporal awareness security mechanisms. It is difficult to adapt to the spatiotemporal changes of access hotspots and prevent attacks based on historical key or location impersonation, resulting in poor encryption and low security.
By generating a multi-dimensional access weight matrix, combining the time dimension attenuation factor and the space dimension distance factor, dynamically adjusting the encryption strategy, generating a dynamic key seed and performing homomorphic encryption, and embedding spatiotemporal feature identifiers, fine-grained permission control and cross-institutional data aggregation can be achieved.
It achieves dynamic matching of encryption strategies and user behaviors, improves the accuracy and efficiency of security control, prevents key reuse or static leakage, and ensures the security and efficiency of the data aggregation process.
Smart Images

Figure CN120415723B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data encryption technology, and in particular to a method and system for dynamic encryption of geographic information data based on spatiotemporal characteristics. Background Art
[0002] In multi-institutional geographic information data sharing scenarios, access requests from different users (such as government departments, enterprises, and research institutions) exhibit significant spatiotemporal dynamics, manifested by strong correlations between access frequency, location, and time. To ensure data security, dynamic permission control is required. This involves adjusting data encryption policies based on users' real-time access behavior (e.g., hotspots and time distribution), while also supporting cross-institutional ciphertext aggregation. This scenario requires encryption methods with spatiotemporal awareness, dynamic key generation mechanisms, and fine-grained access control to balance data security with sharing efficiency.
[0003] Currently, a representative solution to this problem is based on fixed grid partitioning combined with attribute-based encryption. This method divides geographic information data into fixed grids and generates access policies based on user attributes (such as organization and role). Using attribute-based encryption, data encryption and permission control are implemented. When data is shared, the system verifies user permissions based on predefined attribute policies, allowing only qualified users to decrypt specific grid data.
[0004] While this solution achieves basic access control, it suffers from the following issues: Static partitioning doesn't match dynamic access requirements: A fixed grid can't adapt to the spatiotemporal variations in access hotspots, leading to inefficient encryption or over-authorization. Its access policy is rigid: Attribute-based encryption relies on predefined attributes and can't dynamically adjust keys and permissions based on real-time access behavior (such as sudden, high-frequency requests). It also lacks spatiotemporal-aware security mechanisms: It doesn't account for time decay and spatial distance, making it difficult to prevent attacks based on historical key or location spoofing. This also makes access conflicts more likely when aggregating data across institutions.
[0005] In summary, the existing solutions are difficult to meet the dynamic security needs in multi-institutional geographic information sharing scenarios, and there is an urgent need for a dynamic encryption and permission control method that integrates spatiotemporal characteristics. Summary of the Invention
[0006] The present application provides a method and system for dynamic encryption of geographic information data based on spatiotemporal characteristics, which is used to solve the problems of poor encryption effect and low security of geographic information data in the prior art.
[0007] In a first aspect, the present application provides a method for dynamic encryption of geographic information data based on spatiotemporal characteristics, comprising:
[0008] Determine dynamic hotspots based on the timestamp data, geographic coordinate data, and access frequency data of user access requests in multi-institutional sharing scenarios;
[0009] Generate a multi-dimensional access weight matrix according to the time distribution density and spatial coverage radius of the dynamic hotspot area, wherein the multi-dimensional access weight matrix includes a time dimension attenuation factor and a space dimension distance factor;
[0010] parsing the access heat values of the spatial grids in the multidimensional access weight matrix, determining corresponding block granularity levels according to the numerical intervals of the access heat values, performing a spatial segmentation operation on the target geographic information data according to the block granularity levels, and generating a plurality of data blocks matching the spatial grids;
[0011] Generate a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor;
[0012] performing a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, performing a homomorphic encryption operation on the plurality of data blocks using the temporary encryption key, and embedding a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block;
[0013] When a cross-institutional data aggregation request is received, the permission level information in the spatiotemporal feature identifier is extracted from the encrypted data block, and a ciphertext superposition operation is performed on multiple encrypted data blocks based on the homomorphic encryption characteristics. At the same time, the matching degree between the user identity of the requesting party and the permission level information is verified to complete the secure aggregation operation.
[0014] Optionally, parsing the access heat values of the spatial grids in the multidimensional access weight matrix, determining the corresponding block granularity level according to the numerical range of the access heat values, performing a spatial segmentation operation on the target geographic information data according to the block granularity level, and generating a plurality of data blocks matching the spatial grids, includes:
[0015] Marking each spatial grid in the multidimensional access weight matrix with an initial access heat value within its coverage range, where the initial access heat value is the product of time distribution density and spatial coverage radius;
[0016] Building a heat diffusion window based on the adjacent relationship between spatial grids, and accumulating the initial access heat value horizontally within the heat diffusion window to obtain the access heat value;
[0017] Input the access heat value into a preset discretized step function, so as to divide the corresponding block granularity level according to each step interval through the discretized step function;
[0018] Determine the maximum number of blocks allowed in the spatial grid according to the block granularity level, and take the center point of the spatial grid as a reference, perform radial cutting at equal angle intervals along the longitude and latitude directions to form multiple initial data blocks;
[0019] When the multiple initial data blocks overlap with the cutting lines of adjacent spatial grids, the boundary of each initial data block is re-divided based on the center line of the overlapping area to generate multiple data blocks, and each data block belongs to a single spatial grid.
[0020] Optionally, generating a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor includes:
[0021] Performing a timestamp difference operation based on the time dimension decay factor to generate a time decay coefficient;
[0022] Performing geographic coordinate difference calculation based on the spatial dimension distance factor to generate a spatial distance coefficient;
[0023] The time decay coefficient and the space distance coefficient are input into a nonlinear transformation function to generate a dynamic key seed.
[0024] Optionally, performing a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, using the temporary encryption key to perform a homomorphic encryption operation on the multiple data blocks, and embedding a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block, including:
[0025] Performing a cyclic shift operation on the initial value of the dynamic key seed, performing an XOR operation on the element corresponding to each initial value and the shifted adjacent element to generate an extended key sequence, and selecting an element that meets a preset parity condition based on the parity distribution characteristics of the elements in the extended key sequence to generate a temporary encryption key;
[0026] Splitting the temporary encryption key into multiple subkey segments, each subkey segment corresponding to an encryption position of a data block, calculating a starting offset of the subkey segment in the temporary encryption key sequence based on the spatial grid coordinates of the data block, truncating a subkey segment of corresponding length according to the offset as an encryption parameter for the data block, and performing a homomorphic encryption operation on the multiple data blocks to generate an encrypted data block;
[0027] The time distribution density characteristic code and the space coverage radius characteristic code of the spatial grid are bit-cross-woven from the multi-dimensional access weight matrix to generate a spatiotemporal characteristic identifier, and the spatiotemporal characteristic identifier is embedded in the corresponding encrypted data block.
[0028] Optionally, when a cross-institutional data aggregation request is received, the permission level information in the spatiotemporal feature identifier is extracted, a ciphertext superposition operation is performed on multiple encrypted data blocks based on homomorphic encryption characteristics, and a matching degree between the user identity of the requesting party and the permission level information is verified to complete a secure aggregation operation, including:
[0029] When a cross-institutional data aggregation request is received, a spatiotemporal feature identifier is extracted from the encrypted data block, and permission level information consisting of a digital sequence is extracted from a fixed position of the spatiotemporal feature identifier. The permission level information is compared item by item with a pre-stored institution permission mapping table, and multiple target encrypted data blocks that are allowed to participate in the superposition operation are screened out from multiple encrypted data blocks;
[0030] The user identity of the requesting party carried in the cross-institutional data aggregation request is split into a header verification code and a tail permission identifier, wherein the header verification code is converted into a binary mask through a preset substitution rule and a bit coverage match is performed with the check area of the spatiotemporal feature identifier; the tail permission identifier is reversely deduced from the theoretical identity feature identifier through the permission level information, and when the number of consecutive matches between the theoretical identity feature identifier and the check bit of the user identity identifier reaches a preset threshold, the superposition operation channel is activated;
[0031] The multiple target encrypted data blocks are individually split into multiple ciphertext segments, and the ciphertext segments with the same position index in the multiple encrypted data blocks are input into an overlay operation channel, dynamic weight factors are generated based on the permission level information corresponding to the multiple encrypted data blocks, and weighted multiplication and accumulation are performed on the ciphertext segments in the same channel to generate the ciphertext segments at the corresponding positions in the aggregated ciphertext;
[0032] During the superposition process, the number of ciphertext segments superimposed on each encrypted data block in the aggregated ciphertext is counted in real time. If the number of superimposed segments of any target encrypted data block exceeds the maximum superimposed segment number threshold corresponding to the permission level information corresponding to the target encrypted data block, the superposition operation channel corresponding to the target encrypted data block is closed.
[0033] Optionally, performing a timestamp difference operation based on the time dimension decay factor to generate a time decay coefficient includes:
[0034] Using the same time measurement rule to record and obtain the first mark timestamp value of the event start time and the second mark timestamp value of the event current time;
[0035] Performing a timestamp difference operation on the first marking timestamp value and the second marking timestamp value to obtain an initial time difference, and dividing the initial time difference by a value corresponding to a preset basic time unit to obtain a standard time interval;
[0036] A predefined time dimension attenuation factor is extracted, and the time dimension attenuation factor is used as a base number and the standard time interval quantity is used as an exponent to perform an exponential power operation of the base number to generate a time attenuation coefficient.
[0037] Optionally, bit-interleaving the time distribution density feature code and the space coverage radius feature code of the spatial grid from the multidimensional access weight matrix to generate a spatiotemporal feature identifier, and embedding the spatiotemporal feature identifier into a corresponding encrypted data block, including:
[0038] Extracting a time distribution density feature code from a first predefined column of the multidimensional access weight matrix and extracting a spatial coverage radius feature code from a second predefined row;
[0039] The time distribution density feature code and the space coverage radius feature code are converted into fixed-length binary sequences respectively, and each bit of the two binary sequences is cross-joined in sequence according to the alternating arrangement rule to generate a spatiotemporal feature identifier;
[0040] An embedded area of fixed length is reserved in the header of the encrypted data block, and the spatiotemporal feature identifier is filled into the embedded area in bit order to cover the value of the original data bit.
[0041] In a second aspect, the present application provides a system for dynamically encrypting geographic information data based on spatiotemporal characteristics, including:
[0042] A determination module is used to determine dynamic hotspot areas based on the acquired timestamp data, geographic coordinate data, and access frequency data of user access requests in a multi-institution sharing scenario;
[0043] A first generating module is configured to generate a multi-dimensional access weight matrix according to the time distribution density and spatial coverage radius of the dynamic hotspot area, wherein the multi-dimensional access weight matrix includes a time dimension attenuation factor and a space dimension distance factor;
[0044] a second generation module configured to analyze the access heat values of the spatial grids in the multidimensional access weight matrix, determine a corresponding block granularity level according to a numerical range of the access heat values, perform a spatial segmentation operation on the target geographic information data according to the block granularity level, and generate a plurality of data blocks matching the spatial grids;
[0045] A third generating module is used to generate a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor;
[0046] an encryption module, configured to perform a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, perform a homomorphic encryption operation on the plurality of data blocks using the temporary encryption key, and embed a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block;
[0047] The processing module is used to extract the permission level information in the spatiotemporal feature identifier from the encrypted data block when receiving a cross-institutional data aggregation request, perform ciphertext superposition operations on multiple encrypted data blocks based on the homomorphic encryption characteristics, and verify the matching degree between the user identity of the requesting party and the permission level information to complete the security aggregation operation.
[0048] In a third aspect, an embodiment of the present application provides a computing device comprising a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a dynamic encryption method for geographic information data based on spatiotemporal characteristics as described in the first aspect above.
[0049] In a fourth aspect, an embodiment of the present application provides a computer storage medium storing a computer program. When the computer program is executed by a computer, it implements a dynamic encryption method for geographic information data based on spatiotemporal characteristics as described in the first aspect.
[0050] In an embodiment of the present application, dynamic hotspot areas are determined based on the timestamp data, geographic coordinate data, and access frequency data of user access requests obtained in a multi-institution sharing scenario. By analyzing the timestamps, geographic coordinates, and access frequencies, spatiotemporal areas with high access frequencies are identified in real time to ensure that encryption strategies are dynamically matched with user behaviors and to improve the accuracy of security control.
[0051] A multidimensional access weight matrix is generated based on the time distribution density and spatial coverage radius of the dynamic hotspot area. The multidimensional access weight matrix includes a time dimension attenuation factor and a space dimension distance factor. Combined with the time attenuation factor and the space distance factor, the spatiotemporal characteristics of the access behavior are quantified, providing a computable weight basis for dynamic encryption and enhancing the adaptability of key generation.
[0052] The access heat values of the spatial grids in the multidimensional access weight matrix are parsed, and the corresponding block granularity level is determined according to the numerical range of the access heat value. A spatial segmentation operation is performed on the target geographic information data according to the block granularity level to generate multiple data blocks matching the spatial grid. The data block granularity is adaptively adjusted according to the access heat. A finer-grained segmentation is adopted in the hotspot area to optimize storage and computing efficiency, while reducing the redundant overhead in the non-hotspot area.
[0053] Based on the time dimension attenuation factor and the space dimension distance factor, a dynamic key seed is generated. Based on the time-space factor, a dynamic key seed is generated to ensure that the key is updated as the access behavior changes, thereby preventing security risks caused by key reuse or static leakage.
[0054] A discrete logarithm operation is performed on the dynamic key seed to generate a temporary encryption key, the temporary encryption key is used to perform a homomorphic encryption operation on the multiple data blocks, and a spatiotemporal feature identifier associated with the multidimensional access weight matrix is embedded in the encrypted data block. The key irreversibility is enhanced through discrete logarithm operation, and ciphertext calculation is supported in combination with homomorphic encryption to meet the needs of cross-institutional data aggregation. At the same time, spatiotemporal identifiers are embedded to achieve fine-grained permission control.
[0055] When a cross-institutional data aggregation request is received, the permission level information in the spatiotemporal feature identifier is extracted from the encrypted data block, and a ciphertext superposition operation is performed on multiple encrypted data blocks based on the homomorphic encryption characteristics. At the same time, the matching degree between the user identity of the requester and the permission level information is verified to complete the secure aggregation operation. The requester's authority is verified through the spatiotemporal feature identifier, and the ciphertext data is directly superimposed using homomorphic encryption to ensure the security and efficiency of the aggregation process and avoid the risk of plaintext exposure.
[0056] Furthermore, by calculating the initial access heat value of the spatial grid (the product of time density and spatial radius), the final heat value is diffused and accumulated between adjacent grids. A discretized step function is used to divide the block granularity level. Radial cutting is performed at the grid center point to generate the initial data block, and the boundaries of the overlapping areas are re-divided along the center line to ensure that each data block belongs to only a single grid. Based on heat diffusion and step functions, this solution realizes intelligent hierarchical cutting of data blocks, balancing the fine processing of hot spots and resource conservation in non-hot spots. By re-dividing the center lines of overlapping areas, the ambiguity of data block ownership is avoided, the accuracy of spatial segmentation and the clarity of data management are improved.
[0057] These and other aspects of the present application will become more readily apparent from the description of the following embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0059] Figure 1 A flowchart of a method for dynamic encryption of geographic information data based on spatiotemporal characteristics provided by the present application is shown;
[0060] Figure 2 The present invention provides a schematic diagram of a dynamic encryption system for geographic information data based on spatiotemporal characteristics;
[0061] Figure 3A schematic structural diagram of a computing device provided by the present application is shown. DETAILED DESCRIPTION
[0062] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0063] In some of the processes described in the specification and claims of this application and the above-mentioned figures, multiple operations that appear in a specific order are included, but it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel. The serial numbers of the operations, such as 101, 102, etc., are only used to distinguish between different operations, and the serial numbers themselves do not represent any order of execution. In addition, these processes may include more or fewer operations, and these operations may be executed in sequence or in parallel. It should be noted that the descriptions of "first", "second", etc. in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to being different types.
[0064] Researchers have found that in multi-institutional geographic information data sharing scenarios, traditional static encryption methods struggle to adapt to dynamically changing access requirements, resulting in rigid key management, loose permission control, and insufficient security for cross-institutional data aggregation. Based on this, a dynamic encryption method for geographic information data based on spatiotemporal characteristics is proposed. This method dynamically adjusts encryption strategies based on the spatiotemporal characteristics of user access behavior, achieving fine-grained permission control and secure cross-institutional data aggregation.
[0065] The technical solution of this application can be applied to scenarios such as smart cities, emergency management, and traffic planning that require collaborative processing of geographic information data by multiple institutions, and is particularly suitable for application environments where access to hotspot areas changes dynamically and where data security and sharing efficiency are highly required.
[0066] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without making creative efforts are within the scope of protection of this application.
[0067] Figure 1 The present invention provides a flowchart of a method for dynamically encrypting geographic information data based on spatiotemporal characteristics, as shown in FIG. Figure 1 As shown, the method includes:
[0068] 101. Determine dynamic hotspot areas based on the acquired timestamp data, geographic coordinate data, and access frequency data of user access requests in a multi-institutional sharing scenario;
[0069] Timestamp data: records the exact time of user access requests and is used to analyze time distribution patterns.
[0070] Geographic coordinate data: user access location (latitude and longitude), supporting spatial distribution analysis.
[0071] Visit frequency data: The number of visits to the same area within a unit of time reflects the popularity of the area.
[0072] Dynamic hotspot area: an access-intensive area with dynamic changes in time, space, and frequency, and has spatiotemporal local characteristics.
[0073] In an embodiment of the present application, first, the timestamp data (e.g., 2023-10-01 08:30:00), geographic coordinate data (e.g., longitude 116.404, latitude 39.915), and access frequency data (e.g., 50 visits within 5 minutes) of the user's request are collected in real time through the access log interface of the multi-institutional shared platform. Secondly, the collected timestamp data, geographic coordinate data, and access frequency data are input into the improved spatiotemporal weighted DBSCAN clustering algorithm, where the time decay coefficient λ = 0.1 (decaying 10% per hour) and the spatial neighborhood radius ε = 500 meters are set. The access points within a continuous 1-hour time window are density clustered to obtain multiple clusters. Next, the boundary vertex coordinates of each cluster are calculated using the convex hull algorithm (e.g., generating a polygon vertex set {P1(116.402, 39.914), P2(116.405, 39.917)...}), and the total access frequency within the cluster is counted. Finally, cluster areas whose total visit frequency exceeds a threshold (e.g., 200 times / hour) are marked as dynamic hotspot areas, and a hotspot area list containing area boundary coordinates and real-time density is output, providing a spatial analysis basis for the weight matrix construction in step 102.
[0074] A city's transportation management department, in collaboration with shared mobility platforms (e.g., Platform 1 and Platform 2), divided user ride request data (timestamps, GPS coordinates, and frequency of use) shared across multiple organizations into spatiotemporal grids with 30-minute time windows and a 1-kilometer radius. The number of rides within each grid was then counted. An improved ST-DBSCAN algorithm was used to identify high-frequency areas. For example, during the weekday morning rush hour (7:00-9:00 AM), in the city center's business district (latitude and longitude range E116.30°-116.35°, N39.90°-39.93°), where the frequency of rides exceeded 500 times per hour, adjacent grids were merged to create a dynamic hotspot. This dynamic hotspot was labeled the "morning rush hour core area" for subsequent resource scheduling optimization.
[0075] 102. Generate a multi-dimensional access weight matrix based on the time distribution density and spatial coverage radius of the dynamic hotspot area, wherein the multi-dimensional access weight matrix includes a time dimension attenuation factor and a spatial dimension distance factor;
[0076] Time distribution density: The rate of change in the access frequency of a hotspot area in different time periods, used to quantify time decay.
[0077] Spatial coverage radius: The geographical coverage of the hotspot area, used to quantify spatial attenuation.
[0078] Time dimension attenuation factor: time weight attenuation coefficient based on exponential function (such as e λt).
[0079] Spatial distance factor: Spatial weight attenuation coefficient based on Gaussian kernel function (such as e d2 / σ).
[0080] In the embodiment of the present application, the generation process of the multi-dimensional access weight matrix can be summarized as follows: first, dynamic hotspot area data is received, and the time distribution density (such as the visit volume during the morning peak period of 8:00-9:00 accounts for 65%) and the spatial coverage radius (minimum enclosing circle radius R = 550 meters) of each hotspot area is calculated; then a two-dimensional matrix framework of 24 (time slots) × 100 (spatial grids) is constructed, and the time dimension attenuation factor (Wt = e^(-0.1·Δt), Δt is the difference from the hotspot start time) and the spatial dimension distance factor (Ws = 1-d / R, d is the Euclidean distance from the grid to the hotspot centroid) are calculated for each grid cell, and the time and space attenuation effects are integrated through linear superposition (α=0.6 time weight, β=0.4 space weight) to generate an access heat value normalized to the [0,1] interval; the final output multi-dimensional access weight matrix provides a decision basis for subsequent data segmentation by integrating a two-dimensional quantitative model of exponential time decay and Gaussian spatial decay.
[0081] A dynamic hotspot area modeling method based on the attenuation of the time dimension attenuation factor and the space dimension distance factor is specifically implemented as follows: first, based on the dynamic hotspot data of the core area of the subway station during the morning peak, the time distribution density (the visit volume during the 8:00-9:00 period accounts for 65%) and the spatial coverage radius (1.2 kilometers) are extracted; then an exponential function including the time dimension attenuation factor (λ=0.15) is constructed, such as Wt=e^(-0.15 at 9:00). 1)≈0.8607) and a spatial distance factor (based on a Gaussian kernel function, e.g., Ws≈0.2105 at 500 meters from the core). A 24×400 multidimensional access weight matrix is generated (e.g., Wij≈0.1815 at 500 meters from the core at 9:00 AM) through the spatiotemporal dual-factor coupling calculation (Wij=Wt×W_s), and normalized to the interval [0,1]. This multidimensional access weight matrix accurately quantifies the access priority of different spatiotemporal units. High-weight regions (Wij≥0.3) correspond to core spatiotemporal hotspots, while low-weight regions (Wij<0.1) reflect marginal attenuation zones, providing a quantitative decision-making basis for dynamic resource scheduling.
[0082] 103. Analyze the access popularity values of the spatial grids in the multidimensional access weight matrix, determine the corresponding block granularity level according to the numerical range of the access popularity value, perform a spatial segmentation operation on the target geographic information data according to the block granularity level, and generate multiple data blocks matching the spatial grids;
[0083] Access heat value: the weighted sum of the element values in the grid weight matrix, reflecting the comprehensive access intensity in time and space.
[0084] Block granularity level: divide the data block size into different levels according to the heat value (such as fine granularity in high heat area and coarse granularity in low heat area).
[0085] In the embodiment of the present application, the multidimensional access weight matrix generated in step 102 is first parsed, and the access heat values of the spatial grids in the multidimensional access weight matrix are divided into three levels according to preset rules: high heat zone (≥0.8), medium heat zone (0.5~0.8) and low heat zone (<0.5). Secondly, differentiated block strategies are adopted for different heat zones: the high heat zone is recursively segmented to 100-meter accuracy using a quadtree (e.g., subdividing a 1km² grid into 100 100m×100m subgrids), the medium heat zone maintains the original 1km² grid, and the low heat zone is merged into a large 5km² block. Next, the target geographic information data (e.g., road network data) is spatially segmented based on Geohash coding to generate multiple data blocks that match the spatial grid (e.g., block B0231 corresponds to all road data within the longitude range of 116.400-116.450 and the latitude range of 39.900-39.950). Finally, an R-tree spatial index is established to accelerate data retrieval, and a structured geographic dataset after segmentation is output to provide data input for the dynamic key generation in step 104 .
[0086] The access heat value Hij of each grid is calculated based on a multidimensional access weight matrix. The central grid in the commercial area (heat value > 1.0) is divided into fine-grained blocks of 50m x 50m. The peripheral areas (heat value 0.6-1.0) are divided into medium-grained blocks of 100m x 100m. Remote areas (heat value < 0.6) are merged into coarse-grained blocks of 200m x 200m. A quadtree algorithm is used to recursively partition the city map, ensuring finer data blocks in high-heat areas (such as those around subway stations), supporting the accuracy of subsequent encryption and queries.
[0087] 104. Generate a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor;
[0088] Dynamic key seed: A random number that combines a time decay factor and a spatial distance factor, serving as the basis for key generation.
[0089] In this embodiment, the spatial dimension distance factors of the target spatial grid are first extracted from the multidimensional access weight matrix in step 102 (e.g., a heat value of 0.82 corresponds to W_t=0.85 and W_s=0.78). These are then quantized into 16-bit fixed-point numbers (0x85C0, 0x78F4) and binary concatenated (0x85C078F4). Next, a hash operation is performed on the concatenated spatiotemporal parameters using the organization's preset shared key K_shared as the key for the HMAC-SHA256 algorithm to generate an initial seed value (e.g., 0x5a3d...f209). Next, a Gaussian noise injection module (μ=0, σ=0.01) is used to add random perturbations to the seed value to enhance its anti-cracking capabilities. Finally, a 128-bit dynamic key seed (e.g., Dynamic_Seed=0x5a3d...f20a) is output, which serves as the basis for generating the temporary encryption key in step 105.
[0090] The time dimension attenuation factor λ = 0.15 and the spatial radius R = 1200 meters are encoded as the string "0.15_1200". This is then hashed using SHA-256 to generate an initial seed. Microsecond noise from the current system time (e.g., 2025-04-09 08:30:45.678) is then added to generate a dynamic key seed. For example, the hash result of "a1b2c3..." becomes "a1b2c3...d4e5f6" after adding noise, enhancing the key's unpredictability.
[0091] 105. Perform a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, use the temporary encryption key to perform a homomorphic encryption operation on the multiple data blocks, and embed a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block;
[0092] Discrete logarithm operation: Generate temporary keys based on k=H(s)modp of elliptic curve (ECC).
[0093] Spatiotemporal feature identifier: Metadata embedded in the ciphertext, including permission level, timestamp, and location hash.
[0094] In this embodiment of the present application, an elliptic curve discrete logarithm operation (using the secp256k1 curve) is first performed on the dynamic key seed output in step 104 to generate a temporary public key PK (0x03a5...c7e1) and a private key SK (0x8d2...f4b). Next, the Paillier homomorphic encryption algorithm is used to encrypt the multiple data blocks output in step 103 using PK (e.g., encrypting the 2MB of road data in block B0231 to generate the 3.2MB ciphertext C_B0231). Next, the time-dimension attenuation factor and the spatial-dimension distance factor corresponding to the grid in the multidimensional access weight matrix (e.g., timestamp "20231001T0800", grid ID "G32", and permission level "L2") are encrypted using AES-128 to generate a 128-bit spatiotemporal feature identifier. Finally, the identifier is embedded in the check bit at the end of the ciphertext using LSB steganography technology, and an encrypted data block with a spatiotemporal feature identifier (such as C_B0231') is output to ensure that the data source and access rights can be verified during cross-institutional data aggregation in the subsequent step 106.
[0095] Using the elliptic curve secp256k1, discrete logarithm operations are performed on the dynamic seed to generate a temporary private key k = 0x5A3D and a public key K = kG. The data block is encrypted using the Paillier homomorphic encryption algorithm, and a spatiotemporal identifier is embedded in the ciphertext, such as "L2_20250409_116.32E39.91N," where L2 represents the permission level (access only to traffic management departments), followed by a timestamp and a hash value of the center coordinates. This identifier allows for rapid matching of permissions and regions to encrypted data blocks.
[0096] 106. When a cross-institutional data aggregation request is received, the permission level information in the spatiotemporal feature identifier is extracted from the encrypted data block, and a ciphertext superposition operation is performed on multiple encrypted data blocks based on the homomorphic encryption characteristics. At the same time, the matching degree between the user identity of the requesting party and the permission level information is verified to complete the security aggregation operation.
[0097] Permission level information: The access rights defined in the identifier (e.g. L2 only allows access by the traffic management department).
[0098] Ciphertext superposition: Utilize Paillier's homomorphic additivity to combine multiple encrypted data blocks.
[0099] In this embodiment, a cross-organization data aggregation request is first received, containing the target region (e.g., longitude 116.40-116.45, latitude 39.90-39.95) and a user identity certificate (e.g., the digital certificate of Organization B). Next, the 128-bit LSB-steganographic spatiotemporal feature identifier is extracted from the encrypted data block generated in step 105. After decryption using AES-128, the original spatiotemporal feature data (e.g., timestamp "20231001T0800", grid ID "G32", and permission level "L2") is obtained.
[0100] Next, perform triple verification:
[0101] Timeliness verification: Check whether the request time is within the validity period of the identifier timestamp (e.g. ±2 hours);
[0102] Spatial authority verification: compare the inclusion relationship between the requested area and the identifier grid ID (for example, the requested area completely contains the G32 grid);
[0103] Institutional authority verification: Use a zero-knowledge proof protocol to verify whether the institution ID in the requester's certificate matches the identifier authority level (for example, verify whether institution B has L2 authority).
[0104] After verification, a Paillier homomorphic addition operation is performed on all encrypted data blocks within the target region (such as C_B0231', C_B0232', and so on) to generate the aggregated ciphertext C_sum. Finally, the aggregated ciphertext C_sum and the new spatiotemporal feature identifier (which integrates the permissions of each data block) are returned to the requester. The requester decrypts the aggregated data using the temporary private key SK generated in step 105. The system then automatically destroys the temporary key pair for this session. This entire process achieves secure aggregation without decrypting the original data and ensures that data usage complies with spatiotemporal permission constraints.
[0105] When the environmental protection department requests to aggregate morning rush hour ride data, the system extracts the identifier "L2" from the ciphertext to verify its authority (which must match the organization attribute in the digital certificate). It then performs a homomorphic addition operation on the 10 encrypted data blocks to obtain the aggregated ciphertext of the total number of rides. Decryption reveals a total of 12,345 morning rush hour rides, which is used to optimize shared bike scheduling. The blockchain also records the aggregation operation log (e.g., "2025-04-09 09:15:00 Environmental Protection Department - L2 - Aggregation Successful"), enabling full auditability of the entire process.
[0106] In some embodiments, parsing the access popularity values of the spatial grids in the multidimensional access weight matrix, determining the corresponding block granularity level according to the numerical range of the access popularity values, performing a spatial segmentation operation on the target geographic information data according to the block granularity level, and generating a plurality of data blocks matching the spatial grids includes:
[0107] 201. Mark each spatial grid in the multi-dimensional access weight matrix with an initial access popularity value within its coverage range, where the initial access popularity value is the product of time distribution density and spatial coverage radius;
[0108] Multidimensional access weight matrix: a set of spatial grids consisting of longitude, latitude, and time, each of which records data access characteristics.
[0109] Time distribution density: the statistical value of the number of times the grid is visited per unit time (such as the number of visits per hour).
[0110] Spatial coverage radius: the maximum geographical distance from the center point of a grid to its boundary (e.g., 500 meters).
[0111] Initial access heat value: a comprehensive indicator of grid access frequency and spatial influence. The calculation formula is: heat = time density × coverage radius.
[0112] In this embodiment, historical access logs are first obtained. Time distribution density for each grid is calculated using time series analysis (e.g., sliding window counting). The spatial coverage radius of the spatial grid is simultaneously calculated based on geographic coordinates (using the spherical distance formula). The time distribution density and the spatial coverage radius are multiplied together to generate an initial access popularity value. For example, the initial access popularity value for a 10 km × 10 km grid during peak hours (time density = 5 visits / minute) is 5 × 10 = 50.
[0113] 202. Construct a heat diffusion window based on the adjacent relationship between spatial grids, and perform horizontal propagation and accumulation of the initial access heat value within the heat diffusion window to obtain an access heat value;
[0114] Adjacency relationship: Adopt eight-neighborhood topology (including up, down, left, right, and diagonal grids).
[0115] Heat diffusion window: 3×3 convolution kernel, center weight is 0.5, and adjacent unit weight is 0.2.
[0116] Horizontal propagation accumulation: weighted superposition of heat values is achieved through spatial convolution.
[0117] In an embodiment of the present application, a heat diffusion window K=[[0.2,0.2,0.2],[0.2,0.5,0.2],[0.2,0.2,0.2]] is first constructed. The heat diffusion window is used to perform a two-dimensional convolution operation on the initial access heat value (using zero-filling boundary processing), and the new access heat value of each spatial grid is H'=Σ(K(i,j)×H_neighbor). For example, the initial access heat of a central spatial grid is 50, and the average initial access heat of its eight neighborhoods is 30. Then the access heat value after diffusion = 50×0.5 + 30×0.2×8=25+48=73. This process is iterated 3 times to finally generate a global access heat value.
[0118] 203. Input the access heat value into a preset discretized step function, so as to divide the access heat value into corresponding block granularity levels according to each step interval through the discretized step function.
[0119] Discretized step function: a nonlinear mapping function based on heat percentile partitioning.
[0120] Block granularity level: L1-L5, L1 is the coarsest granularity (allowing 1 block), L5 is the finest granularity (allowing 16 blocks).
[0121] In an embodiment of the present application, firstly, a distribution histogram of the global access heat value is statistically calculated, and a preset discretized step function is input to determine the threshold of the step interval. For example, the access heat value is divided into 5 step intervals: L1 level (0-20% percentile): ≤100, L2 level (20-40% percentile): 101-200... and so on. Each grid determines the corresponding block granularity level according to the step interval in which its own access heat value falls. For example, if the access heat value of a spatial grid is 250, it corresponds to level L3 (a maximum of 4 blocks are allowed). The block granularity level will control the cutting density of subsequent block operations.
[0122] 204. Determine the maximum number of blocks allowed in the spatial grid according to the block granularity level, and radially cut the spatial grid at equal angles along the longitude and latitude directions with the center point of the spatial grid as a reference to form multiple initial data blocks;
[0123] Radial cutting: With the center of the grid as the origin, radial cutting is generated at angular intervals.
[0124] Equal angle interval: Δθ = 360° / (N×2), where N is the maximum number of blocks.
[0125] In an embodiment of the present application, the block number comparison table is first queried according to the block granularity level (such as N=4 for level L3). Taking the center point (λ0, φ0) of the spatial grid as the reference, a cutting meridian is generated every Δθ=360 / (4×2)=45°. For example, for the L3 level spatial grid, 8 cutting lines of 0°, 45°, 90°...315° are generated, and the spatial grid is divided into 8 sectors. The boundary line equation of each sector adopts the azimuth calculation formula in the spherical coordinate system: φ = φ0 + tanθ×(λ-λ0). This process generates multiple initial data blocks, each of which is defined by its azimuth range.
[0126] 205. When the multiple initial data blocks and the cutting lines of adjacent spatial grids generate overlapping areas, the boundary of each initial data block is re-divided based on the center line of the overlapping area to generate multiple data blocks, and each data block belongs to a single spatial grid.
[0127] Overlap Area: The overlapping geographic area formed by adjacent grid cut lines at the boundary.
[0128] Centerline Re-division: Adjust the block boundaries based on the centerline of the overlapping area.
[0129] In an embodiment of the present application, the intersection of adjacent spatial grid cutting lines is first detected through a spatial index (R-tree). For each overlapping area, the intersection set of the two adjacent cutting line equations is calculated, and a perpendicular bisector is generated as the new boundary. For example, if the 45° cutting line of spatial grid A and the 30° cutting line of spatial grid B intersect at point P, then the boundary of each initial data block is redefined along the center line of the angle between the two lines with point P as the center to generate multiple data blocks. Ultimately, it is ensured that each data block belongs to only a single spatial grid and that the boundary line meets the topological closure requirements.
[0130] The following is a specific embodiment:
[0131] A smart warehouse is divided into 100m x 100m grids. Statistics show that forklifts visit grid A23 12 times per minute (time density), with a coverage radius of 100m. The initial access heat is 12 x 100 = 1200. Using a 3 x 3 Gaussian kernel diffusion algorithm, the access heat of grid A23 rises to 1800, corresponding to level L4 (allowing 8 blocks). The center of grid A23 is divided into eight sectors at 45° intervals. The cutting line of adjacent grid B15 intersects the 135° line of grid A23 at the warehouse aisle. By calculating the centerline of the overlapping area, the original sector boundaries are adjusted to follow the aisle centerline, ultimately generating eight independent shelf management blocks.
[0132] This solution achieves adaptive partitioning of multidimensional spatial data through dynamic calculation of heat values, spatial diffusion and transmission, discretized partitioning control, and boundary optimization. Compared to fixed partitioning methods, this approach improves partitioning accuracy in access hotspots, reduces overlap of data blocks across spatial grids, and dynamically adjusts the partitioning structure based on real-time access patterns. This approach is particularly suitable for scenarios such as logistics scheduling and meteorological grid computing, where spatial proximity and access popularity must be balanced.
[0133] In some embodiments, generating a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor includes:
[0134] 301. Perform a timestamp difference operation based on the time dimension attenuation factor to generate a time attenuation coefficient;
[0135] Time dimension decay factor: a dynamic parameter that characterizes the validity period of the key and is negatively correlated with the time difference.
[0136] Timestamp difference calculation: Calculate the difference between the current time and the key reference time (unit: seconds).
[0137] Time decay coefficient: the time weight value after being processed by the exponential decay function.
[0138] In an embodiment of the present application, a timestamp difference operation is first performed to calculate the time difference Δt (unit: second) between the current timestamp (T_now) and the preset key reference time (T0); Δt is then input into an exponential decay function constructed based on a time-dimensional decay factor (the mathematical form is α = e^(-λ·Δt), where λ is a preset decay rate) to generate a time decay coefficient α, which decreases exponentially as Δt increases; finally, the key validity is dynamically determined based on the comparison result of the time decay coefficient α with the preset threshold, thereby realizing a protection mechanism in which the key security strength automatically decays over time.
[0139] 302. Performing a geographic coordinate difference operation based on the spatial dimension distance factor to generate a spatial distance coefficient;
[0140] Spatial distance factor: A dynamic parameter that characterizes the reliability of device location and is negatively correlated with coordinate deviation.
[0141] Geographic coordinate difference calculation: calculate the spherical distance between the current location and the registered location.
[0142] Spatial distance coefficient: the spatial weight value after normalization.
[0143] In an embodiment of the present application, a geographic coordinate difference operation is first performed, and the actual distance d between the current location and the registered location is calculated based on the spherical distance formula (such as the Haversine formula); then the actual distance d is input into a normalized function constructed by a spatial dimension distance factor (such as β = 1 / [1 + (d / D_max)^k], where D_max is the maximum allowable deviation distance and k is the curvature factor) to generate a spatial distance coefficient β; the spatial distance coefficient decreases nonlinearly as the actual distance d increases (such as β = 1 when d = 0, and β ≈ 0.5 when d = D_max), thereby dynamically mapping the geographic deviation into a security weight parameter of the spatial dimension, which is used together with the time decay coefficient to constrain key generation.
[0144] 303. Input the time attenuation coefficient and the spatial distance coefficient into a nonlinear transformation function to generate a dynamic key seed.
[0145] Nonlinear transformation function: an irreversible computational model.
[0146] Dynamic key seed: A 128-bit random number used to derive encryption keys.
[0147] In an embodiment of the present application, the time attenuation coefficient α and the spatial distance coefficient β are spliced into an input data stream, and the constructed nonlinear transformation function is input. An irreversible dynamic key seed (128-bit random number) is generated through iterative calculation and post-processing (such as taking the binary mantissa and performing a hash operation). The final output result has the dynamic constraint characteristics of both time and space dimensions, ensuring that the key cannot be cracked through reverse deduction or parameter tampering.
[0148] The following is a specific embodiment:
[0149] In the shared bicycle smart lock system, the dynamic key generation scheme achieves security authentication through the following complete process: the system first records the initial timestamp (T0=2024-03-10 12:00:00) and the registered location (central Beijing). When the user requests to unlock the lock 30 minutes later (T1=12:30:00) within a range of 500 meters (β≈0.995), the time decay coefficient (α≈0.368) and spatial distance coefficient (β) are calculated, and a key seed (S=0.712) is generated through a chaotic map mixture. Ultimately, the AES-256 key is derived. If the bicycle is moved 10 kilometers away (β→0) or the timeout exceeds 1 hour (α→0), the key immediately becomes invalid, triggering the lock protection.
[0150] This solution achieves real-time adaptive key updates through the dynamic coupling of the time decay coefficient and the spatial distance coefficient. This approach enforces periodic expiration in the time dimension, prevents cross-border use in the spatial dimension, and, combined with nonlinear transformations, ensures unpredictable key seeds. In shared bike scenarios, this effectively prevents key cracking, device cloning, and cross-regional theft, reduces key change response time, and improves key expiration rates in displacement or timeout scenarios, significantly enhancing the security of IoT devices.
[0151] In some embodiments, performing a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, using the temporary encryption key to perform a homomorphic encryption operation on the multiple data blocks, and embedding a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block includes:
[0152] 401. Perform a cyclic shift operation on the initial value of the dynamic key seed, perform an XOR operation on the element corresponding to each initial value and the shifted adjacent element to generate an extended key sequence, and select an element that meets a preset parity condition based on the parity distribution characteristics of the elements in the extended key sequence to generate a temporary encryption key;
[0153] Dynamic key seed: A random number sequence generated by the system, used as a basic encryption parameter.
[0154] Circular shift operation: connect the seed sequence end to end to form a ring structure and then perform displacement calculation.
[0155] Parity distribution characteristics: the parity statistics of the number of binary bits 1 in the extended key sequence.
[0156] In this embodiment, a 32-bit dynamic key seed is first subjected to a circular shift operation, shifted left by 3 bits. Each original element is then bitwise XORed with the corresponding shifted element to generate a 64-bit extended key sequence. The parity distribution characteristics of each byte are then calculated, and bytes containing an odd number of 1s are selected. This is then compressed using SHA-256 hashing to generate a 128-bit temporary encryption key. This process enhances key randomness through shift diffusion and feature selection.
[0157] 402. Split the temporary encryption key into multiple subkey segments, each subkey segment corresponding to the encryption position of a data block, calculate the starting offset of the subkey segment in the temporary encryption key sequence based on the spatial grid coordinates of the data block, and truncate the subkey segment of corresponding length according to the offset as the encryption parameter of the data block to perform homomorphic encryption operation on the multiple data blocks to generate an encrypted data block.
[0158] Subkey segment: An encrypted segment formed by dividing the temporary key into equal parts according to the number of data blocks.
[0159] Spatial grid coordinates: The (x, y) position identifier of a data block in a two-dimensional matrix.
[0160] Starting offset: The starting position of the subkey truncation calculated based on the coordinates.
[0161] In this embodiment, the 128-bit temporary encryption key is divided into 16 8-bit subkey segments. The offset of each data block is calculated as offset = (x × y mod 8) × 16, where (x, y) are the spatial grid coordinates. Based on the starting offset, 16 consecutive bits are intercepted as encryption parameters. The data block is encrypted using the Paillier homomorphic algorithm to generate an encrypted data block, maintaining the computability of the ciphertext. This step achieves dynamic binding of the key to the spatial location.
[0162] 403. Interleave the time distribution density feature code and the space coverage radius feature code of the spatial grid from the multi-dimensional access weight matrix to generate a spatiotemporal feature identifier, and embed the spatiotemporal feature identifier into a corresponding encrypted data block.
[0163] Spatiotemporal feature identifier: a 128-bit digital fingerprint that integrates temporal and spatial features.
[0164] Bit cross weaving: an encoding method that alternately combines two signature codes according to the odd and even bits.
[0165] In this embodiment, a 64-bit time distribution density code and a 64-bit spatial coverage radius code are extracted from a multidimensional access weight matrix. A spatiotemporal feature identifier is generated by using odd bits for the time code and even bits for the space code. This identifier is then embedded into the redundant bits of an encrypted data block using LSB steganography, creating a spatiotemporally labeled encrypted data block. This process associates the encrypted data with the characteristics of the business scenario.
[0166] The following is a specific embodiment:
[0167] A dynamic key seed 0x3A7F is generated based on real-time vehicle GPS data. After a cyclic shift and XOR operation, the extended sequence 0xB2E4... is obtained. Parity-even distribution characteristic bytes are filtered to generate a temporary encryption key. Traffic flow data is divided into a 4×4 spatial grid. A starting offset of 18 is calculated for the (2,3) location data block, and the subkey 0x5C... is truncated for homomorphic encryption. The morning rush hour distribution density characteristic code (08:00 code) and the commercial district spatial coverage radius characteristic code (500m code) are combined to generate a spatiotemporal feature identifier 0xAE... and embed it into the encrypted data block.
[0168] This solution ensures basic encryption security through dynamic key seed generation, implements fine-grained access control through spatially adaptive key distribution, and ultimately builds a traceable encrypted data system through the fusion of spatiotemporal feature identifiers. These three steps are linked in sequence to form a closed loop: the output temporary key is used for data block encryption, and the spatiotemporal feature tagging is completed using the spatial grid coordinate information before processing. In spatiotemporal-sensitive scenarios such as smart cities, this can not only prevent the risk of key leakage, but also support the retrieval of spatiotemporal features of encrypted data, thereby improving data security and business relevance.
[0169] In some embodiments, when a cross-organization data aggregation request is received, the permission level information in the spatiotemporal feature identifier is extracted, a ciphertext superposition operation is performed on multiple encrypted data blocks based on homomorphic encryption characteristics, and a match between the user identity of the requesting party and the permission level information is verified to complete a secure aggregation operation, including:
[0170] 501. When a cross-organization data aggregation request is received, extract the spatiotemporal feature identifier from the encrypted data block, extract the permission level information consisting of a digital sequence from a fixed position of the spatiotemporal feature identifier, compare the permission level information with the pre-stored organization permission mapping table item by item, and select multiple target encrypted data blocks that are allowed to participate in the overlay operation from the multiple encrypted data blocks;
[0171] Spatiotemporal feature identifier: A 128-bit feature code embedded in the encrypted data block, containing spatiotemporal attributes and permission information.
[0172] Permission level information: A 4-digit sequence of data access rights, embedded in bits 32-35 of the identifier.
[0173] Organization permission mapping table: a table that records the correspondence between organization ID and permitted access permission levels
[0174] In this embodiment, the LSB of an encrypted data block is first parsed to extract the spatiotemporal signature identifier and intercept the permission level information at a fixed location. Next, the permission range of the requesting organization for the cross-organization data aggregation request is queried in a pre-stored organization permission mapping table, and multiple target encrypted data blocks with permission level information within the permitted range are selected. For example, if organization A has permission level information of "1100," only encrypted data blocks with the first two digits of the permission level information code being "11" are selected.
[0175] 502. The user identity identifier of the requesting party carried in the cross-institutional data aggregation request is split into a header verification code and a tail permission identifier. The header verification code is converted into a binary mask using a preset substitution rule and a bit-coverage match is performed with the check area of the spatiotemporal feature identifier. The tail permission identifier is reversely deduced from the theoretical identity feature identifier using the permission level information. When the number of consecutive matches between the theoretical identity feature identifier and the check bit of the user identity identifier reaches a preset threshold, an overlay operation channel is activated.
[0176] User identity: 64-bit identity certificate, including a 16-bit header verification code and a 48-bit tail permission identifier.
[0177] Binary mask: A 16-bit mask (such as 0xF0A3) obtained by converting the header verification code through a permutation table.
[0178] Theoretical identity feature identification: standard identity features calculated in reverse based on the authority level.
[0179] In this embodiment, the user identity identifier is split into a header verification code and a tail permission identifier. The header verification code generates a binary mask using preset permutation rules (such as parity bit swapping), and is then ANDed with the spatiotemporal identifier check field to verify its match. The tail permission identifier uses permission level information to infer the theoretical identity signature. The channel is activated when eight consecutive check bits match. For example, if permission "1101" corresponds to the theoretical identity signature "1011_xxxx," the corresponding bits of the identifier must be matched.
[0180] 503. Split the multiple target encrypted data blocks into multiple ciphertext segments, input the ciphertext segments at the same position index in the multiple encrypted data blocks into an overlay operation channel, generate dynamic weight factors based on the permission level information corresponding to the multiple encrypted data blocks, perform weighted multiplication and accumulation on the ciphertext segments in the same channel, and generate the ciphertext segments at the corresponding positions in the aggregated ciphertext;
[0181] Ciphertext segment: Divide the 256-bit encrypted data block into eight 32-bit segments.
[0182] Dynamic weight factor: A multiplier used in the permission level calculation (e.g., level 3 corresponds to a weight of 0.7).
[0183] Multiply-accumulate: A homomorphic operation that adds weighted ciphertext segments at the same position.
[0184] In this embodiment, after each target encrypted data block is split into ciphertext segments, a dynamic weighting factor is assigned based on the permission level (e.g., 0.3, 0.5, 0.7, and 1.0 for levels 1-4, respectively). The ciphertext segments are then multiplied and accumulated using the Paillier homomorphic encryption system to generate the ciphertext segments at the corresponding positions in the aggregated ciphertext segment. Target encrypted data with higher permissions receives a greater weighting effect on the results.
[0185] 504. During the superposition process, the number of ciphertext segments superimposed on each encrypted data block in the aggregated ciphertext is counted in real time. If the number of superimposed segments of any target encrypted data block exceeds the maximum superimposed segment number threshold corresponding to the permission level information corresponding to the target encrypted data block, the superimposed operation channel corresponding to the target encrypted data block is closed.
[0186] Maximum overlap segment threshold: The maximum number of data segments allowed to be contributed by the permission level.
[0187] Channel closed: terminates the aggregation operation of subsequent segments of the data block.
[0188] In this embodiment, the number of ciphertext segments superimposed on each encrypted data block in the aggregated ciphertext is counted in real time. When the number of segments contributed by a target encrypted data block (e.g., permission level 2) reaches the threshold corresponding to the permission level (e.g., 3 segments), transmission of the remaining ciphertext segments is immediately terminated. This counter implements dynamic circuit breaking to prevent low-privilege target encrypted data from excessively influencing the results.
[0189] The following is a specific embodiment:
[0190] When Hospital A, with permission level 3, initiates a cross-institutional data aggregation request, the system first selects CT image data with permission level code "11xx" from the encrypted medical record data blocks. It then verifies the user identity 0xE53D... provided by Hospital A. By matching the binary mask of the header verification code and inversely deducing the permission identifier at the end, it successfully activates the superposition operation channel for three eligible target data blocks. After splitting the eight CT data blocks into ciphertext segments, homomorphically encrypted multiplication and accumulation are performed with a weight of 0.7, corresponding to Hospital A's permission level 3. During the aggregation process, the contribution of each data block is monitored in real time. If a target encrypted data block reaches the maximum contribution threshold of five segments allowed by permission level 3, the superposition operation channel for that data block is immediately closed. This example fully demonstrates the entire process from permission verification and identity authentication to dynamic weighted aggregation, enabling secure and compliant sharing and analysis of medical data while ensuring patient privacy.
[0191] This solution ensures data access compliance through hierarchical permission screening and two-factor authentication, and implements fine-grained data fusion using dynamic weighted aggregation and contribution control. In scenarios such as joint medical analysis, this approach protects patient privacy (low-privilege institutions only have access to limited data) while maintaining the value of data analysis (high-privilege institutions receive more complete aggregated results). Homomorphic encryption ensures data integrity throughout the entire process. These four steps form a closed-loop control system, establish a secure access mechanism, and implement controlled aggregation, ultimately achieving secure, compliant, and effective utilization of cross-institutional data.
[0192] In some embodiments, performing a timestamp difference operation based on the time dimension decay factor to generate a time decay coefficient includes:
[0193] 601. Using the same time measurement rule, record and obtain a first timestamp value of the event start time and a second timestamp value of the event current time;
[0194] Time measurement rules: refers to the use of standardized time representations such as UTC timestamps and Unix timestamps to ensure consistency in time measurement units (such as millisecond-level accuracy).
[0195] First marker timestamp: the initial time record when the event is triggered (such as the moment when the user clicks the action).
[0196] Second mark timestamp: current system time or event processing time (such as system time during data analysis).
[0197] In an embodiment of the present application, the original timestamp when the event is triggered is obtained through the system clock service (such as calling Java's System.currentTimeMillis()), and it is stored as the first marked timestamp value; when the attenuation coefficient needs to be calculated, the same clock service is called again to obtain the second marked timestamp value. The first marked timestamp value and the second marked timestamp value need to be normalized by the time zone (such as converted to the UTC+0 time zone) to ensure the accuracy of the subsequent difference calculation. The first marked timestamp value serves as a reference anchor point, and the second marked timestamp value serves as a dynamic variable, which together constitute the basic input for the time difference calculation.
[0198] 602. Perform a timestamp difference operation on the first marked timestamp value and the second marked timestamp value to obtain an initial time difference, and divide the initial time difference by a value corresponding to a preset basic time unit to obtain a standard time interval;
[0199] Initial time difference: the original arithmetic difference between two timestamps (the unit is consistent with the timestamp precision, such as millisecond difference 3600000).
[0200] Basic time unit: A standardized unit set according to business requirements (for example, 1 hour = 3600000 milliseconds).
[0201] Standard time interval quantity: a dimensionless, standardized time span (e.g., initial difference 3600000ms / 3600000ms = 1.0 time unit).
[0202] In this embodiment of the present application, an arithmetic subtraction operation is first performed on the first and second marked timestamp values (second marked timestamp value minus first marked timestamp value), resulting in an initial difference value in milliseconds. This initial difference value is then divided by a preset unit time length (e.g., the number of milliseconds corresponding to an hour) using a divider. This process uses fixed-point arithmetic to ensure accuracy. For example, if the initial difference value is 3.6e6 milliseconds, dividing it by 3.6e6 yields a standard time interval of 1.0. This normalization process allows for uniform comparison of time differences of different granularities (e.g., seconds / minutes).
[0203] 603. Extract a predefined time dimension attenuation factor, use the time dimension attenuation factor as a base, use the standard time interval as an exponent, perform an exponential power operation on the base, and generate a time attenuation coefficient.
[0204] Time dimension decay factor: a predefined decay rate parameter (e.g. 0.5 means 50% decay per time unit).
[0205] Exponential power operation: mathematical power function calculation (such as 0.5^1.0=0.5).
[0206] In this embodiment, a preset time dimension attenuation factor λ (typically a floating-point number between 0 and 1) is read from the system configuration library and used as the base of the exponentiation operation. The initial time difference is divided by the value corresponding to the preset base time unit to obtain a standard time interval. Using this standard time interval t as the exponent, a mathematical library (such as the C++ pow function) calculates λ^t. When t = 1.5 and λ = 0.6, the calculated result, 0.6^1.5 ≈ 0.465, is the time attenuation coefficient. This time attenuation coefficient decays exponentially with increasing time intervals.
[0207] The following is a specific embodiment:
[0208] In an e-commerce user behavior analysis scenario, when user A clicks a product at 2024-03-01 02:00:00 UTC (timestamp 1709287200000 milliseconds), the system records this moment as the first marker timestamp. When calculating the decay coefficient at 2024-03-01 04:30:00 UTC (timestamp 1709296200000 milliseconds), the system first calculates the initial time difference of 9,000,000 milliseconds (2.5 hours), divides this by the base time unit of 3,600,000 milliseconds (1 hour), and obtains the standard time interval of 2.5. Finally, the system performs an exponential operation using a predefined decay factor of 0.7 to generate a time decay coefficient of 0.7^2.5≈0.379. This coefficient reduces the original weight of the user's click behavior to 37.9%, allowing the recommendation algorithm to dynamically reduce the influence of historical behavior and more accurately reflect recent changes in user interests.
[0209] This solution dynamically adjusts behavior weights by using a standardized time difference and exponential decay model. In e-commerce scenarios, the weight of clicks made before the initial user time is reduced, ensuring that the recommendation system prioritizes recent behavior (e.g., clicks with shorter time differences retain higher weights). This approach addresses the problem of traditional fixed weights failing to reflect timeliness. Furthermore, through unified UTC time zones and millisecond-level calculation accuracy, it avoids errors caused by cross-time zone or unit confusion, significantly improving recommendation accuracy.
[0210] In some embodiments, bit-interleaving the time distribution density feature code and the spatial coverage radius feature code of the spatial grid from the multidimensional access weight matrix to generate a spatiotemporal feature identifier, and embedding the spatiotemporal feature identifier into the corresponding encrypted data block includes:
[0211] 701. Extract a time distribution density feature code from a first predefined column of the multi-dimensional access weight matrix, and extract a spatial coverage radius feature code from a second predefined row;
[0212] Multidimensional access weight matrix: A matrix composed of statistical features such as time access frequency and spatial location coordinates. The first predefined column stores time distribution density features (such as the statistical distribution of time intervals), and the second predefined row stores spatial coverage radius features (such as the maximum coverage range of access locations).
[0213] Time distribution density signature: A code that reflects the time concentration of data access, usually generated using entropy coding or quantization coding.
[0214] Spatial coverage radius characteristic code: a code that describes the spatial range of data access, usually generated by polar coordinate conversion or grid division and quantization.
[0215] In an embodiment of the present application, the time distribution density feature is first extracted from the first column of the multidimensional access weight matrix, compressed using Huffman coding or arithmetic coding, and a time distribution density feature code is generated; at the same time, the spatial coverage radius feature is extracted from the second row, and a spatial coverage radius feature code is generated through polar coordinate conversion or grid quantization. Finally, the time density feature code and the spatial coverage radius feature code are used as numerical arrays to prepare for further processing.
[0216] 702. Convert the temporal distribution density feature code and the spatial coverage radius feature code into fixed-length binary sequences respectively, cross-join each bit of the two binary sequences in sequence according to an alternating arrangement rule, and generate a spatiotemporal feature identifier.
[0217] Fixed-length binary sequence: The variable-length signature is unified into a fixed number of bits (such as 16 or 32 bits) through zero-padding or truncation.
[0218] Alternating arrangement rule: a bitwise cross-splicing strategy, for example, bit 0 of the time code, bit 0 of the space code, bit 1 of the time code, bit 1 of the space code, and so on, until a complete identifier is generated.
[0219] In an embodiment of the present application, the time distribution density feature code and the space coverage radius feature code are first converted into binary sequences of fixed length respectively. If the length of the binary sequence is insufficient, the high bits are padded with zeros; then, according to the alternating arrangement rule, bit operations (such as shifting, bitwise OR operations) are used to cross-splice the converted binary sequences bit by bit, and finally a compact and unique spatiotemporal feature identifier is generated for embedding into the encrypted data block in the next step.
[0220] 703. Reserve an embedded area of fixed length in the header of the encrypted data block, and fill the embedded area with the spatiotemporal feature identifier in bit order, overwriting the value of the original data bit.
[0221] Embedded area: A fixed-length storage area reserved in the encrypted data block header, used to store spatiotemporal feature identifiers, usually 32 bits or 64 bits.
[0222] Overwrite the value of the original data bit: adopt the in-situ replacement strategy, and ensure the recoverability of the original data through backup or verification mechanism.
[0223] In the embodiment of the present application, a fixed-length embedding area (e.g., 32 bits) is first precalculated and reserved in the header of the encrypted data block. This embedding area is achieved by modifying the encryption algorithm's padding strategy or by extending the data block structure. The spatiotemporal feature identifier generated in the previous step is then written into this area in bit order, using atomic write operations to ensure data consistency while retaining the recoverability of the original data through an exclusive-or operation. Finally, a lightweight checksum algorithm (e.g., CRC8) is used to verify the correctness of the embedding, and the checksum result is stored in the metadata area at the end of the encrypted data block, forming a complete embedding verification mechanism. This process is performed as a preprocessing step in the data encryption process to ensure seamless integration of the spatiotemporal feature identifier and the encrypted data block.
[0224] The following is a specific embodiment:
[0225] In a smart city video surveillance system, this solution's practical application begins by extracting the spatiotemporal feature data for a specific camera from a multidimensional access weight matrix. For example, the code "1101" from the third column indicates that the camera receives 80% of its traffic during peak hours, while the code "011" from the fifth row represents a 150-meter radius of surveillance coverage. This spatiotemporal feature data is then converted to 8-bit binary format and interleaved, ultimately generating a 16-bit spatiotemporal feature identifier (0x6A57). During video data encryption, the system embeds the spatiotemporal feature identifier in a reserved area within the H.264 video stream header. The original header information is then backed up to the extended SEI area, with a CRC-8 checksum appended to ensure data integrity.
[0226] This solution offers significant benefits on three levels: In terms of coding efficiency, the Huffman compression algorithm reduces the storage space required for spatiotemporal features; in terms of security, the spatiotemporal feature identifiers generated through bit-interleaving are highly tamper-resistant, enhancing their security strength; and in terms of actual performance, the innovative header embedding design results in only a minimal increase in latency, barely impacting the smoothness of real-time monitoring. Actual deployment data demonstrates that this solution can improve the accuracy of identifying abnormal access behaviors, including security risks such as video access during unauthorized periods. It also seamlessly supports dynamic access control strategies based on location, providing reliable data security for key areas such as smart city management and border security.
[0227] Figure 2 The present invention provides a schematic diagram of a dynamic encryption system for geographic information data based on spatiotemporal characteristics. Figure 2 As shown, the system includes:
[0228] A determination module 21 is configured to determine a dynamic hotspot area based on the acquired timestamp data, geographic coordinate data, and access frequency data of user access requests in a multi-institution sharing scenario;
[0229] A first generating module 22 is configured to generate a multi-dimensional access weight matrix according to the time distribution density and spatial coverage radius of the dynamic hotspot area, wherein the multi-dimensional access weight matrix includes a time dimension attenuation factor and a space dimension distance factor;
[0230] A second generation module 23 is configured to analyze the access popularity values of the spatial grids in the multidimensional access weight matrix, determine a corresponding block granularity level according to the numerical range of the access popularity values, perform a spatial segmentation operation on the target geographic information data according to the block granularity level, and generate a plurality of data blocks matching the spatial grids;
[0231] A third generating module 24 is configured to generate a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor;
[0232] an encryption module 25 configured to perform a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, perform a homomorphic encryption operation on the plurality of data blocks using the temporary encryption key, and embed a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block;
[0233] The processing module 26 is used to extract the permission level information in the spatiotemporal feature identifier from the encrypted data block when receiving a cross-institutional data aggregation request, perform ciphertext superposition operations on multiple encrypted data blocks based on the homomorphic encryption characteristics, and verify the matching degree between the user identity of the requesting party and the permission level information to complete the security aggregation operation.
[0234] Figure 2 The said geographic information data dynamic encryption system based on spatiotemporal characteristics can be executed Figure 1 The implementation principle and technical effects of the method for dynamic encryption of geographic information data based on spatiotemporal characteristics described in the illustrated embodiment will not be elaborated on here. The specific manner in which each module and unit performs operations in the above-mentioned embodiment of a dynamic encryption system for geographic information data based on spatiotemporal characteristics has been described in detail in the embodiments of the method and will not be elaborated on here.
[0235] In one possible design, Figure 2 The embodiment shown is a geographic information data dynamic encryption system based on spatiotemporal characteristics that can be implemented as a computing device, such as Figure 3 As shown, the computing device may include a storage component 31 and a processing component 32;
[0236] The storage component 31 stores one or more computer instructions, wherein the one or more computer instructions are called and executed by the processing component 32 .
[0237] The processing component 32 is used for the above Figure 1 The embodiment provides a method for dynamically encrypting geographic information data based on spatiotemporal characteristics.
[0238] The processing component 32 may include one or more processors to execute computer instructions to complete all or part of the steps in the above method. Of course, the processing component may also be implemented as one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above method.
[0239] The storage component 31 is configured to store various types of data to support operations at the terminal. The storage component can be implemented by any type of volatile or non-volatile memory device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0240] Of course, a computing device may also include other components, such as input / output interfaces, display components, communication components, etc.
[0241] The input / output interface provides an interface between the processing component and the peripheral interface module, which can be an output device, an input device, etc.
[0242] The communication component is configured to facilitate, among other things, wired or wireless communications between the computing device and other devices.
[0243] Among them, the computing device can be a physical device or an elastic computing host provided by a cloud computing platform, etc. In this case, the computing device can refer to a cloud server, and the above-mentioned processing components, storage components, etc. can be basic server resources rented or purchased from the cloud computing platform.
[0244] The present application also provides a computer storage medium storing a computer program, wherein the computer program can achieve the above-mentioned Figure 1 The illustrated embodiment is a method for dynamically encrypting geographic information data based on spatiotemporal characteristics.
[0245] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0246] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.
[0247] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0248] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for dynamic encryption of geographic information data based on spatiotemporal characteristics, characterized in that: include: Determine dynamic hotspots based on the timestamp data, geographic coordinate data, and access frequency data of user access requests in multi-institutional sharing scenarios; A multidimensional access weight matrix is generated according to the time distribution density and spatial coverage radius of the dynamic hotspot area, and the multidimensional access weight matrix includes a time dimension attenuation factor and a space dimension distance factor; wherein the multidimensional access weight matrix is a two-dimensional matrix, whose row dimension is the time slot and the column dimension is the space grid; each access heat value in the matrix is calculated by multiplying the time dimension attenuation factor and the space dimension distance factor; the time dimension attenuation factor is a time weight attenuation coefficient based on an exponential function; the space dimension distance factor is a space weight attenuation coefficient based on a Gaussian kernel function; parsing the access heat values of the spatial grids in the multidimensional access weight matrix, determining corresponding block granularity levels according to the numerical intervals of the access heat values, performing a spatial segmentation operation on the target geographic information data according to the block granularity levels, and generating a plurality of data blocks matching the spatial grids; Generate a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor; performing a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, performing a homomorphic encryption operation on the plurality of data blocks using the temporary encryption key, and embedding a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block; When a cross-institutional data aggregation request is received, the authority level information in the spatiotemporal feature identifier is extracted from the encrypted data block, a ciphertext superposition operation is performed on multiple encrypted data blocks based on the homomorphic encryption property, and the matching degree between the user identity of the requesting party and the authority level information is verified to complete the secure aggregation operation; The step of analyzing the access heat values of the spatial grids in the multi-dimensional access weight matrix and determining the corresponding block granularity level according to the numerical range of the access heat values includes: Mark each spatial grid in the multidimensional access weight matrix with the initial access heat value within its coverage range, where the initial access heat value is the product of the time distribution density and the spatial coverage radius; construct a heat diffusion window based on the adjacent relationship between the spatial grids, and horizontally propagate and accumulate the initial access heat value within the heat diffusion window to obtain the access heat value; input the access heat value into a preset discretized step function to divide the corresponding block granularity level according to each step interval through the discretized step function.
2. The method according to claim 1, characterized in that The performing of a spatial segmentation operation on the target geographic information data according to the block granularity level to generate a plurality of data blocks matching the spatial grid includes: Determine the maximum number of blocks allowed in the spatial grid according to the block granularity level, and take the center point of the spatial grid as a reference, perform radial cutting at equal angle intervals along the longitude and latitude directions to form multiple initial data blocks; When the multiple initial data blocks overlap with the cutting lines of adjacent spatial grids, the boundary of each initial data block is re-divided based on the center line of the overlapping area to generate multiple data blocks, and each data block belongs to a single spatial grid.
3. The method according to claim 1, characterized in that Generating a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor includes: Performing a timestamp difference operation based on the time dimension decay factor to generate a time decay coefficient; Performing geographic coordinate difference calculation based on the spatial dimension distance factor to generate a spatial distance coefficient; The time decay coefficient and the space distance coefficient are input into a nonlinear transformation function to generate a dynamic key seed.
4. The method according to claim 1, wherein Performing a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, using the temporary encryption key to perform a homomorphic encryption operation on the multiple data blocks, and embedding a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block, including: Performing a cyclic shift operation on the initial value of the dynamic key seed, performing an XOR operation on the element corresponding to each initial value and the shifted adjacent element to generate an extended key sequence, and selecting an element that meets a preset parity condition based on the parity distribution characteristics of the elements in the extended key sequence to generate a temporary encryption key; Splitting the temporary encryption key into multiple subkey segments, each subkey segment corresponding to an encryption position of a data block, calculating a starting offset of the subkey segment in the temporary encryption key sequence based on the spatial grid coordinates of the data block, truncating a subkey segment of corresponding length according to the offset as an encryption parameter for the data block, and performing a homomorphic encryption operation on the multiple data blocks to generate an encrypted data block; The time distribution density characteristic code and the space coverage radius characteristic code of the spatial grid are bit-cross-woven from the multi-dimensional access weight matrix to generate a spatiotemporal characteristic identifier, and the spatiotemporal characteristic identifier is embedded in the corresponding encrypted data block.
5. The method according to claim 1, wherein When a cross-institutional data aggregation request is received, the permission level information in the spatiotemporal feature identifier is extracted, a ciphertext superposition operation is performed on multiple encrypted data blocks based on homomorphic encryption characteristics, and the matching degree between the user identity of the requesting party and the permission level information is verified to complete the secure aggregation operation, including: When a cross-institutional data aggregation request is received, a spatiotemporal feature identifier is extracted from the encrypted data block, and permission level information consisting of a digital sequence is extracted from a fixed position of the spatiotemporal feature identifier. The permission level information is compared item by item with a pre-stored institution permission mapping table, and multiple target encrypted data blocks that are allowed to participate in the superposition operation are screened out from multiple encrypted data blocks; The user identity of the requesting party carried in the cross-institutional data aggregation request is split into a header verification code and a tail permission identifier, wherein the header verification code is converted into a binary mask through a preset substitution rule and a bit coverage match is performed with the check area of the spatiotemporal feature identifier; the tail permission identifier is reversely deduced from the theoretical identity feature identifier through the permission level information, and when the number of consecutive matches between the theoretical identity feature identifier and the check bit of the user identity identifier reaches a preset threshold, the superposition operation channel is activated; The multiple target encrypted data blocks are individually split into multiple ciphertext segments, and the ciphertext segments with the same position index in the multiple encrypted data blocks are input into an overlay operation channel, dynamic weight factors are generated based on the permission level information corresponding to the multiple encrypted data blocks, and weighted multiplication and accumulation are performed on the ciphertext segments in the same channel to generate the ciphertext segments at the corresponding positions in the aggregated ciphertext; During the superposition process, the number of ciphertext segments superimposed on each encrypted data block in the aggregated ciphertext is counted in real time. If the number of superimposed segments of any target encrypted data block exceeds the maximum superimposed segment number threshold corresponding to the permission level information corresponding to the target encrypted data block, the superposition operation channel corresponding to the target encrypted data block is closed.
6. The method according to claim 3, characterized in that Performing a timestamp difference operation based on the time dimension decay factor to generate a time decay coefficient includes: Using the same time measurement rule to record and obtain the first mark timestamp value of the event start time and the second mark timestamp value of the event current time; Performing a timestamp difference operation on the first marking timestamp value and the second marking timestamp value to obtain an initial time difference, and dividing the initial time difference by a value corresponding to a preset basic time unit to obtain a standard time interval; A predefined time dimension attenuation factor is extracted, and the time dimension attenuation factor is used as a base number and the standard time interval quantity is used as an exponent to perform an exponential power operation of the base number to generate a time attenuation coefficient.
7. The method according to claim 4, characterized in that: The method comprises: performing bit cross-weaving on the time distribution density characteristic code and the space coverage radius characteristic code of the spatial grid from the multi-dimensional access weight matrix to generate a spatiotemporal characteristic identifier, and embedding the spatiotemporal characteristic identifier into a corresponding encrypted data block, comprising: Extracting a time distribution density feature code of the spatial grid from a first predefined column of the multidimensional access weight matrix, and extracting a spatial coverage radius feature code of the spatial grid from a second predefined row; The time distribution density feature code and the space coverage radius feature code are converted into fixed-length binary sequences respectively, and each bit of the two binary sequences is cross-joined in sequence according to the alternating arrangement rule to generate a spatiotemporal feature identifier; An embedded area of fixed length is reserved in the header of the encrypted data block, and the spatiotemporal feature identifier is filled into the embedded area in bit order to cover the value of the original data bit.
8. A geographic information data dynamic encryption system based on spatiotemporal characteristics, used to execute a geographic information data dynamic encryption method based on spatiotemporal characteristics according to any one of claims 1 to 7, characterized in that: include: A determination module is used to determine dynamic hotspot areas based on the acquired timestamp data, geographic coordinate data, and access frequency data of user access requests in a multi-institution sharing scenario; A first generating module is configured to generate a multi-dimensional access weight matrix according to the time distribution density and spatial coverage radius of the dynamic hotspot area, wherein the multi-dimensional access weight matrix includes a time dimension attenuation factor and a space dimension distance factor; a second generation module configured to analyze the access heat values of the spatial grids in the multidimensional access weight matrix, determine a corresponding block granularity level according to a numerical range of the access heat values, perform a spatial segmentation operation on the target geographic information data according to the block granularity level, and generate a plurality of data blocks matching the spatial grids; A third generation module is used to generate a dynamic key seed based on the time dimension attenuation factor and the space dimension distance factor; an encryption module, configured to perform a discrete logarithm operation on the dynamic key seed to generate a temporary encryption key, perform a homomorphic encryption operation on the plurality of data blocks using the temporary encryption key, and embed a spatiotemporal feature identifier associated with the multidimensional access weight matrix in the encrypted data block; The processing module is used to extract the permission level information in the spatiotemporal feature identifier from the encrypted data block when receiving a cross-institutional data aggregation request, perform ciphertext superposition operations on multiple encrypted data blocks based on the homomorphic encryption characteristics, and verify the matching degree between the user identity of the requesting party and the permission level information to complete the security aggregation operation.
9. A computing device, characterized in that It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are used to be called and executed by the processing component to implement a dynamic encryption method for geographic information data based on spatiotemporal characteristics as described in any one of claims 1 to 7.
10. A computer storage medium, characterized in that A computer program is stored, and when the computer program is executed by a computer, a method for dynamically encrypting geographic information data based on spatiotemporal characteristics as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Cross-domain access control method for multiple Internet-of-things domains in smart city environment
CN110933033A
Medical data privacy protection method and system based on artificial intelligence
CN119577841A