Traffic overload control data security protection system based on quantum encryption technology

The traffic overload control data security protection system, which combines quantum encryption technology with iris information verification and modular design, solves the high load and leakage risks in traffic overload control data transmission and achieves the coordinated optimization of data security and processing efficiency.

CN120825313AActive Publication Date: 2025-10-21ZHEJIANG DODINDZ ELECTRONICS CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510927806.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-10-21
Estimated Expiration
2045-07-07

AI Technical Summary

Technical Problem

Quantum encryption technology has a heavy load and high cost in the transmission of traffic overload control data, and there is a risk of pre-processing and post-processing leakage. It cannot respond in a timely manner to data leaks caused by the theft of non-key accounts or system attacks.

Method used

The traffic overload control data security protection system based on quantum encryption technology includes a modular design: a creation module receives data and creates static web pages, a monitoring module monitors network security, a verification module verifies data packet security through iris information, an instant access module intercepts and clears cached data, and an extraction module extracts and classifies stored data.

Benefits of technology

A full-process security closed loop is achieved, and data integrity and confidentiality are guaranteed through a multi-dimensional protection mechanism, improving system operation efficiency and preventing data leakage and illegal access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120825313A_ABST
    Figure CN120825313A_ABST
Patent Text Reader

Abstract

The invention discloses a traffic overload control data security protection system based on a quantum encryption technology, and relates to the field of data communication, and the system comprises a creation module which is used for receiving traffic overload control data, creating a static webpage and a static webpage hyperlink, and recording the traffic overload control data by applying the static webpage; the monitoring module is used for monitoring the security of a data transmission network, and controlling the data packet to be transmitted based on quantum encryption when the monitoring result is secure; quantum encryption transmission is combined with iris information dynamic verification, the security of data transmission and receiving scenes is ensured, the data retention risk is reduced by adopting a mode of removing and clearing a cache after instantaneous access of a static webpage, and the iris information management, data limit alignment, network disconnection extraction and other operations are matched, so that the security of the data transmission and receiving scenes is improved. And a whole-process safe closed loop from transmission to processing is formed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data communication technology, and in particular to a traffic overload control data security protection system based on quantum encryption technology. Background Art

[0002] Sub-encryption technology is based on the principles of quantum mechanics and transmits keys through quantum states. Its core advantage is that the key distribution process is eavesdroppable. If intercepted, the quantum state is altered, ensuring the absolute security of encrypted communications. It is suitable for scenarios with high confidentiality requirements.

[0003] The invention patent application with application number 202311609768.4 discloses a data security protection system, which aims to solve the problem of "marking system users as key monitoring users or ordinary monitoring users, and the system can focus on monitoring the network information data of key monitoring users based on the marking results, but because it only focuses on some users, when non-key accounts are stolen or the entire system is attacked, it cannot respond in time, resulting in data leakage."

[0004] However, when quantum encryption technology is applied to the transmission of traffic overload control data, due to the huge volume of traffic overload control data, the application load of quantum encryption technology is large and the cost is too high to control. In addition, there is still a risk of leakage in the pre-processing of traffic overload control data before transmission through quantum encryption technology and the post-processing after reception.

[0005] To this end, a traffic overload control data security protection system based on quantum encryption technology was proposed. Summary of the Invention

[0006] In response to the above-mentioned shortcomings of the existing technology, the present invention provides a traffic overload control data security protection system based on quantum encryption technology, which can effectively solve the problems of the existing technology.

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions:

[0008] The present invention discloses a traffic overload control data security protection system based on quantum encryption technology, comprising:

[0009] A creation module is used to receive traffic control data, create static web pages and static web page hyperlinks, and use static web pages to record traffic control data; a monitoring module is used to monitor the security of the data transmission network. When the monitoring result is safe, the control data packet is transmitted based on quantum encryption; a verification module is used to collect iris information of all online system users in the background of the receiving end after receiving and decrypting the data packet at the receiving end, compare the collected iris information of the online system users with the iris information in each data packet, and verify the security of the data packet receiving scenario based on the comparison result; an instantaneous access module is used to access the static web page hyperlinks in each received data packet, and after the static web pages corresponding to each hyperlink are loaded, the traffic control data presented on the static web page are intercepted, and after the interception operation is completed, the static web page is removed from the server and the static web page associated cache data is cleared; an extraction module is used to traverse the traffic control data image intercepted in the static web page, and extract the traffic control data from the traffic control data image.

[0010] Furthermore, the traffic control data includes: vehicle weighing data and vehicle image data, each traffic control data is marked with the license plate number of the source vehicle, and the amount of traffic control data recorded in each static web page is approximately equal;

[0011] The creation module is provided with an offline database at a lower level. The offline database is used to store the iris information of system users. Each iris information is marked with the corresponding system user name. After each static webpage and its hyperlink are created, the hyperlink and a randomly selected iris information with the mark are used as the quantum encryption transmission target to perform the transmission operation from the sending end to the receiving end.

[0012] Among them, the offline database is integrated into a preset computer device. The user iris information stored in the offline database is only available when the computer device is in an offline state. The user who is authorized to operate the computer device has the right to change, upload, and delete the user iris information. The computer device is only in a network connected state during the iris information selection stage.

[0013] Furthermore, the traffic control data recorded in each of the static web pages are aligned based on the extreme alignment strategy so that the traffic control data recorded in each of the static web pages are approximately equal in amount;

[0014] The extreme alignment strategy of traffic overload control data is:

[0015] Set the maximum amount of data recorded in the static web page, and place the vehicle image data in the received traffic control data in the static web page first. Each time a vehicle image data is placed in the static web page, identify whether the cumulative amount of vehicle image data placed in the static web page exceeds the maximum amount of data recorded in the static web page. If it does not exceed the maximum value, continue to perform the placement operation of the vehicle image data. If it exceeds the preset value, delete the most recently placed vehicle image data in the static web page, and use the vehicle weighing data in the traffic control data as the placement target. Each time a vehicle weighing data is placed, identify whether the cumulative amount of data placed in the static web page exceeds the maximum amount of data recorded in the static web page. If it does not exceed the maximum value, continue to perform the placement operation of the vehicle weighing data. If it exceeds the preset value, end, and create a new static web page for recording the remaining traffic control data through the creation module.

[0016] Furthermore, the data packet consists of a static webpage hyperlink recording traffic control data and iris information. The data transmission network security monitoring logic in the monitoring module is expressed as follows:

[0017]

[0018] Where: S is the data transmission network security; A′ is the attack defense dynamic entropy index; T′ is the comprehensive transmission stability index; E′ is the device link time reliability index; M′ is the security management mechanism evolution index; S0 is the security judgment threshold;

[0019] When the data transmission network security S obtained based on equation (1) holds true in equation (2), the data transmission network is secure and the transmission operation is performed. Otherwise, the data transmission network security monitoring is performed again based on the specified period until the monitoring result is secure, and then the transmission operation is performed.

[0020] Furthermore, the verification module is provided with a hand-raising unit at a lower level, and the hand-raising unit is used for system users to electronically raise their hands;

[0021] The collection of iris information and electronic hand-raising operation of all online system users in the background of the receiving end are performed on the computer equipment and camera corresponding to each system user. After all online system users in the background of the receiving end raise their hands through the hand-raising unit, the collection operation of the system user's iris information is triggered synchronously, and all system users perform iris information collection synchronously;

[0022] After the iris information of all system users is collected, the receiving end decrypts the received data packets, obtains the iris information in each data packet, and simultaneously cleans the obtained iris information to remove duplicate iris information to obtain iris information set A. The iris information collected from system users is recorded as iris information set B. Iris information set A is used to perform a comparison operation with iris information set B.

[0023] When performing a cleaning operation on the iris information obtained in each data packet, the cleaning is performed based on the system user name marked with each iris information.

[0024] Furthermore, the comparison operation of the iris information set A and the iris information set B is to pick up one iris information from each of the two sets to perform similarity calculation, so that all iris information combinations picked up by all picking methods are subjected to a similarity calculation;

[0025] When each iris information in iris information set A finds a similar item in iris information set B, the verification module verifies that the data packet receiving scenario is safe. When any one or more iris information in iris information set A does not find a similar item in iris information set B, the process jumps to the hand-raising unit reset operation;

[0026] The verification module triggers the instantaneous access module to run when the verification result is safe.

[0027] Furthermore, the similarity calculation formula of two iris information is:

[0028] Iris information is iris image, and both iris images are evenly divided into n 2 image blocks;

[0029]

[0030] Where: d ij is the Euclidean distance between the feature vectors of the corresponding image blocks at position (i, j) in the two iris images; α is the adjustment coefficient of the influence of grayscale difference on similarity; D gray is the average grayscale value difference between the two iris images; β is the theoretical maximum sum of the distances between the feature points of all image blocks; γ is the theoretical maximum grayscale difference;

[0031] in, Where: m is the dimension of the feature vector; is the feature vector of the image block corresponding to the position (i, j) in the two iris images, α∈(0,1], β is obtained by pre-calculating the preset iris image samples, the image block feature point includes the pixel with the largest grayscale mean difference with the adjacent pixels in the image block, and when SIMM is greater than the preset threshold, it is determined that the iris image from the iris information set A is a similar item to the iris image from the iris information set B in the two iris images for which similarity calculation is performed.

[0032] Furthermore, during the operation phase of the instant access module, the computer device configured by the user of the system to which the iris information source camera of which similar items exist in the iris information set B belongs is used for access;

[0033] The operation of intercepting the traffic control data presented on the static web page is a screenshot operation, and the intercepted traffic control data is stored locally on the computer device that performs the interception operation;

[0034] The static web page associated cache data includes: browser cache, CDN cache, server cache, and proxy server cache;

[0035] Among them, after the creation module completes the creation of the static web page and the static web page hyperlink, it deletes the traffic control data corresponding to the traffic control data recorded in the static web page. When the monitoring module detects that the data transmission network is secure, the data packet executes the sending operation in the creation module.

[0036] Furthermore, during the operation phase of the extraction module, the vehicle image data is intercepted from the traffic overload control data, and the vehicle weighing data is obtained through text extraction. After the vehicle image data and the vehicle weighing data are intercepted and extracted, the vehicle image data and the vehicle weighing data are reorganized based on the marking information of the vehicle image data and the vehicle weighing data, so that the vehicle image data and the vehicle weighing data with the same marking information are combined with each other, and then based on the combination results, the vehicle image data and the vehicle weighing data are stored separately in the computer device;

[0037] The operation content of the extraction module is executed on the computer device, and the computer device is disconnected from the network during the static web page removal and cache data clearing phase of the instant access module.

[0038] Furthermore, the connection mode of each module in the system includes at least:

[0039] The creation module is interactively connected to an offline database via a wireless network, the creation module is interactively connected to a monitoring module and a verification module via a wireless network, the verification module is interactively connected to a hand-raising unit via a wireless network, and the verification module is interactively connected to an instant access module and an extraction module via a wireless network.

[0040] Compared with the prior art, the technical solution provided by the present invention has the following beneficial effects:

[0041] The present invention provides a traffic overload control data security protection system based on quantum encryption technology. During operation, the system ensures the security of data transmission and reception scenarios through quantum encryption transmission combined with dynamic verification of iris information. It reduces the risk of data retention by removing and clearing the cache after instantaneous access to static web pages. It cooperates with offline database management of iris information, data limit alignment, and network disconnection extraction to form a full-process security closed loop from transmission to processing. It not only ensures the integrity and confidentiality of traffic overload control data through a multi-dimensional protection mechanism, but also improves the system operation efficiency with the help of dynamic data processing strategies, realizes the coordinated optimization of data security and processing efficiency, and effectively prevents data leakage and illegal access. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] To more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. Those skilled in the art can also derive other drawings based on these drawings without inventive effort.

[0043] Figure 1 This is a schematic diagram of the structure of the traffic overload control data security protection system based on quantum encryption technology;

[0044] Figure 2 Schematic diagram of the system logic architecture in the present invention. DETAILED DESCRIPTION

[0045] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0046] The present invention will be further described below with reference to the embodiments.

[0047] Example:

[0048] The traffic overload control data security protection system based on quantum encryption technology in this embodiment is as follows: Figure 1 As shown, including:

[0049] Create a module for receiving traffic overload control data, creating a static web page and a hyperlink to the static web page, and using the static web page to record the traffic overload control data;

[0050] Traffic overload control data includes: vehicle weighing data and vehicle image data. Each traffic overload control data is marked with the license plate number of the source vehicle. The amount of traffic overload control data recorded in each static webpage is approximately equal.

[0051] The creation module is equipped with an offline database, which is used to store the iris information of system users. Each iris information is marked with the corresponding system user name. After each static web page and its hyperlink are created, the hyperlink and a randomly selected iris information with a mark are used as the quantum encryption transmission target to perform the transmission operation from the sender to the receiver.

[0052] The offline database is integrated into a preset computer device. The user iris information stored in the offline database is only available when the computer device is offline. The user who is authorized to operate the computer device has the right to change, upload, and delete the user's iris information. The computer device is only connected to the network during the iris information selection stage.

[0053] The traffic control data recorded in each static webpage is aligned based on the extreme alignment strategy, so that the traffic control data recorded in each static webpage is approximately equal;

[0054] The extreme alignment strategy for traffic overload control data is:

[0055] Set the maximum amount of data recorded in the static web page, and place the vehicle image data in the received traffic and overweight control data into the static web page first. Each time a vehicle image data is placed in the static web page, identify whether the cumulative amount of vehicle image data placed in the static web page exceeds the maximum amount of data recorded in the static web page. If it does not exceed the maximum value, continue to perform the placement operation of the vehicle image data. If it exceeds the preset value, delete the most recently placed vehicle image data in the static web page, and use the vehicle weighing data in the traffic and overweight control data as the placement target. Each time a vehicle weighing data is placed, identify whether the cumulative amount of data placed in the static web page exceeds the maximum amount of data recorded in the static web page. If it does not exceed the maximum value, continue to perform the placement operation of the vehicle weighing data. If it exceeds the preset value, end, and create a new static web page for recording the remaining traffic and overweight control data through the creation module;

[0056] A monitoring module is used to monitor the security of the data transmission network. When the monitoring result is safe, the control data packet is transmitted based on quantum encryption;

[0057] The data packet consists of a static web page hyperlink that records traffic overload control data and iris information. The data transmission network security monitoring logic in the monitoring module is expressed as follows:

[0058]

[0059] Where: S is the data transmission network security; A′ is the attack defense dynamic entropy index; T′ is the comprehensive transmission stability index; E′ is the device link time reliability index; M′ is the security management mechanism evolution index; S0 is the security judgment threshold;

[0060] When the data transmission network security S obtained based on formula (1) is established in formula (2), the data transmission network is secure and the transmission operation is performed. Otherwise, the data transmission network security monitoring is performed again based on the specified period until the monitoring result is secure, and then the transmission operation is performed;

[0061] This formula integrates attack defense dynamic entropy, transmission stability, device link reliability, and security management evolution indicators, and compares them with security thresholds to determine network security. The process covers multiple types of risks, ensuring that transmission is only carried out when it is safe, thus safeguarding the basic environment.

[0062] The calculation formula of the attack defense dynamic entropy index A′ is:

[0063]

[0064] Where: H is the information entropy of the attack defense situation; n is the number of attack types; p i is the probability of successfully resisting the i-th attack;

[0065] The above formula is calculated based on the attack defense information entropy, the number of attack types, and the probability of successful defense of each attack, reflecting the ability to defend against multiple attacks;

[0066] The calculation formula for the comprehensive transmission stability index T′ is:

[0067]

[0068] Where: σ f is the flow standard deviation; is the mean flow rate; σ d is the standard deviation of delay; is the delayed mean; n is the total number of sample periods (historical period); w i is the weight; l i is the packet loss rate of the i-th cycle;

[0069] Among them, w i The greater the network load of the corresponding period, the larger the value;

[0070] This formula combines traffic, standard deviation and mean of delay, packet loss rate and load weight calculation to effectively reflect transmission stability;

[0071] The calculation formula of the equipment link time reliability index E′ is:

[0072]

[0073] Where: F n F is the number of equipment failures; t L is the total operating time of the device or link; b is the number of backup links; L m is the number of active links; λ is the dynamic attenuation factor; t is the current operating time of the device or link;

[0074] Among them, the dynamic attenuation factor λ takes a value of 0-1 and can be set according to the aging speed of the equipment, environmental factors, etc. f(·) is the constraint function. When the value of is non-zero, f(·) takes the value itself, in When the value of is zero, f(·) takes a preset minimum value;

[0075] The above formula calculates indicators based on the number of equipment failures, total operating time, the ratio of backup links to primary links, the dynamic attenuation factor, and the current operating time. It reflects the long-term reliable operation capability of the equipment and links. The calculation principle is that equipment reliability is inversely proportional to the failure frequency and directly proportional to the link redundancy (backup link), and it decays with operating time. The constraint function ensures that the calculation can still be performed when the backup link is zero. The rationale is that equipment and links are the hardware foundation of data transmission. Failures, aging, and insufficient redundancy directly affect transmission reliability. This formula integrates these hardware characteristics to accurately assess the reliability of the transmission carrier, providing hardware-level security for data transmission.

[0076] The calculation formula of the safety management mechanism evolution index M′ is:

[0077]

[0078] Where: U s , O s 、S s The number of correctly authenticated users, the number of compliant access operations, and the number of audited security events (under the current status); t , O t 、S t is the total number of authenticated users, the total number of access operations, and the total number of security events to be audited (corresponding to a specified time period); k is the management mechanism optimization coefficient; N is the number of management mechanism optimizations;

[0079] Among them, the management mechanism optimization coefficient k can be determined based on historical optimization data or expert evaluation;

[0080] The above formula calculates the indicators by comparing the current number of correctly authenticated users, the number of compliant access operations, and the number of audited security incidents to the corresponding total number, combined with the management mechanism optimization coefficient and the number of optimizations. This reflects the effectiveness and evolutionary capabilities of the security management mechanism. The operating principle is that the value of the management mechanism lies not only in its current operating performance (the correct operation ratio), but also in its iterative ability (the number of optimizations) as risks change. The rationale lies in the fact that traffic overload control data involves sensitive information, and the management mechanism (such as user authentication and access control) needs to dynamically adapt to new risks. The formula not only evaluates the current effect but also incorporates evolutionary capabilities, avoiding the one-sidedness of static evaluation and ensuring that the management mechanism continuously adapts to security needs.

[0081] The verification module is used to collect iris information of all online system users in the receiving end after receiving and decrypting the data packet, compare the collected iris information of online system users with the iris information in each data packet, and verify the security of the data packet receiving scenario based on the comparison results;

[0082] The verification module is provided with a hand-raising unit at the lower level, which is used for system users to electronically raise their hands;

[0083] The collection of iris information and electronic hand-raising operation of all online system users in the receiving end background are performed on the computer equipment and camera corresponding to each system user. After all online system users in the receiving end background raise their hands through the hand-raising unit, the collection operation of the system user's iris information is triggered synchronously, and all system users perform iris information collection synchronously;

[0084] After the iris information of all system users is collected, the receiving end decrypts the received data packets, obtains the iris information in each data packet, and simultaneously cleans the obtained iris information to remove duplicate iris information to obtain iris information set A. The iris information collected from system users is recorded as iris information set B. Iris information set A is used to perform a comparison operation with iris information set B.

[0085] Wherein, when performing the cleaning operation on the iris information obtained in each data packet, the cleaning is performed based on the system user name marked with each iris information;

[0086] The comparison operation of iris information set A and iris information set B is to pick up one iris information from each of the two sets to perform similarity calculation, so that all iris information combinations picked up by all picking methods are subjected to a similarity calculation;

[0087] When each iris information in iris information set A finds a similar item in iris information set B, the verification module verifies that the data packet receiving scenario is safe. When any one or more iris information in iris information set A does not find a similar item in iris information set B, the process jumps to the hand-raising unit reset operation;

[0088] Among them, the verification module triggers the instantaneous access module to run when the verification result is safe;

[0089] The similarity calculation formula of two iris information is:

[0090] Iris information is iris image, and both iris images are evenly divided into n 2 image blocks;

[0091]

[0092] Where: d ij is the Euclidean distance between the feature vectors of the corresponding image blocks at position (i, j) in the two iris images; α is the adjustment coefficient of the influence of grayscale difference on similarity; D gray is the average grayscale value difference between the two iris images; β is the theoretical maximum sum of the distances between the feature points of all image blocks; γ is the theoretical maximum grayscale difference;

[0093] in, Where: m is the dimension of the feature vector; is the feature vector of the image block corresponding to the position (i, j) in the two iris images, α∈(0,1], β is obtained by pre-calculating the preset iris image samples, the image block feature point includes the pixel with the largest grayscale average difference with the adjacent pixels in the image block, when SIMM is greater than the preset threshold, it is determined that the iris image from iris information set A is a similar item to the iris image from iris information set B in the two iris images for which similarity calculation is performed;

[0094] By calculating through the above logical formula and combining local features with grayscale distribution to determine similarity, the accuracy of iris matching is effectively improved, ensuring reliable identity authentication at the receiving end.

[0095] The instant access module is used to access the static web page hyperlinks in each received data packet, intercept the traffic control data presented on the static web page after the static web page corresponding to each hyperlink is loaded, and after the interception operation is completed, remove the static web page from the server and clear the cache data associated with the static web page;

[0096] During the instant access module operation phase, the computer device configured by the user of the system to which the iris information source camera of which similar items exist in the iris information set B belongs is used for access;

[0097] The operation of intercepting the traffic control data presented on the static web page is a screenshot operation, and the intercepted traffic control data is stored locally on the computer device that performs the interception operation;

[0098] Static web page associated cache data includes: browser cache, CDN cache, server cache, and proxy server cache;

[0099] Among them, after the creation module completes the creation of the static web page and the static web page hyperlink, it deletes the traffic control data corresponding to the traffic control data recorded in the static web page. When the monitoring module detects that the data transmission network is secure, the data packet executes the sending operation in the creation module;

[0100] An extraction module is used to traverse the traffic control data image intercepted in the static web page and extract the traffic control data from the traffic control data image;

[0101] During the extraction module operation phase, the vehicle image data is intercepted from the traffic overload control data, and the vehicle weighing data is obtained through text extraction. After the vehicle image data and vehicle weighing data are intercepted and extracted, the vehicle image data and vehicle weighing data are reorganized based on their tag information, so that vehicle image data and vehicle weighing data with the same tag information are combined with each other. Based on the combination results, the data are then stored separately in the computer device;

[0102] The operation content of the extraction module is executed on the computer device, and the computer device is disconnected from the network during the static web page removal and cache data clearing phase of the instant access module;

[0103] The connection methods of each module in the system include at least:

[0104] The creation module is interactively connected to the offline database via a wireless network, the creation module is interactively connected to the monitoring module and the verification module via a wireless network, the verification module is interactively connected to the hand-raising unit via a wireless network, and the verification module is interactively connected to the instantaneous access module and the extraction module via a wireless network.

[0105] In this embodiment, a creation module is executed to receive traffic control data, create a static web page and a static web page hyperlink, and use the static web page to record the traffic control data. A monitoring module is post-operated to monitor the security of the data transmission network. When the monitoring result is safe, the control data packet is transmitted based on quantum encryption. The verification module further receives and decrypts the data packet at the receiving end, collects the iris information of all online system users in the background of the receiving end, and compares the collected iris information of the online system users with the iris information in each data packet. The security of the data packet receiving scenario is verified based on the comparison result. The instant access module then accesses the static web page hyperlink in each received data packet. After the static web page corresponding to each hyperlink is loaded, the traffic control data presented on the static web page is intercepted. After the interception operation is completed, the static web page is removed from the server and the cache data associated with the static web page is cleared. Finally, the extraction module traverses the traffic control data image intercepted in the static web page to extract the traffic control data from the traffic control data image.

[0106] Through the system in the above embodiments, through multiple protections such as quantum encryption transmission and iris verification, the safety of traffic overload control data is guaranteed. The static web page is deleted immediately after instantaneous access, reducing the risk of data leakage; the iris information is managed in an offline database, enhancing the security of user information; the data extraction is accurate and classified for storage, ensuring both the security of data transmission and reception and the integrity and availability of data, and efficiently protecting the security of the entire process of traffic overload control data.

[0107] See Figure 2 As shown, this figure further demonstrates the operating logic architecture of the system in this embodiment.

[0108] The following are examples of the application of the system in the above embodiments:

[0109] To strengthen the cross-regional secure transmission and management of traffic overload control data on the xx Expressway, a "Traffic Overload Control Data Security Protection System Based on Quantum Encryption Technology" has been deployed to achieve encrypted transmission, security verification, and closed-loop management of traffic overload control data between 13 prefecture-level traffic overload control stations and the provincial traffic data center. The system covers the entire process security protection of vehicle weighing data and vehicle image data, effectively preventing risks such as data transmission leakage and unauthorized access.

[0110] Application process:

[0111] 1. Traffic overload control data collection and static web page creation (the creation module works)

[0112] The weighing equipment at each prefecture-level traffic overload control station real-time collects the weighing data of passing vehicles (such as "truck with license plate number Ji A·12345, total weight 52 tons"), and the high-definition camera synchronously captures the vehicle image data (including license plate number and full view of the vehicle body). All data is marked with the license plate number of the source vehicle.

[0113] After the system creation module receives the above data, it distributes the data based on the "extreme alignment strategy": setting the maximum data volume of a single static web page to 10MB, preferentially placing vehicle image data (about 2MB per piece). When the data volume reaches the 10MB upper limit after placing 5 images, the remaining data is automatically allocated to a new static web page; if the image data is insufficient, vehicle weighing data (about 0.1MB per piece) is supplemented to ensure that the data volume of each static web page is approximately equal.

[0114] After the static web page is created, the system randomly selects 1 piece of iris information marked with the user name (such as the iris information of "Administrator Zhang San of the provincial data center") from the offline database, and binds the hyperlink of the static web page to this iris information as the target identifier for quantum encryption transmission.

[0115] The offline database is deployed in a dedicated computer. Only when the computer is disconnected from the network can the administrator update the iris information; when selecting the iris information, the computer is temporarily connected to the network and automatically disconnects after completion to ensure the security of the iris information.

[0116] 2. Network security monitoring and quantum encryption transmission (monitoring module operation)

[0117] The monitoring module of the overweight vehicle control station monitors the transmission network between the station and the provincial data center in real time. By calculating parameters such as "dynamic entropy for attack resistance" and "comprehensive index of transmission stability" (referring to the system's built-in security judgment formula), it confirms that there are no abnormal attacks on the network and the link is stable.

[0118] When the monitoring result is "safe", the system triggers the quantum encryption mechanism, encrypts the data packet containing the static web page hyperlink and bound iris information, and transmits it to the provincial data center through quantum key distribution technology.

[0119] 3. Receiver scenario security verification (verification module + hand-raising unit work)

[0120] After the provincial data center receives the data packet, three administrators online in the background (Zhang San, Li Si, and Wang Wu) initiate an electronic hand-raising operation through the terminal "hand-raising unit", triggering the cameras of their respective terminals to synchronously collect iris information, forming an iris information set B (including the iris data of Zhang San, Li Si, and Wang Wu).

[0121] The system decrypts the data packet, extracts the iris information set A (i.e. the iris information of "Zhang San" bound when the traffic control station sends it), and cleans set A by user name (removes duplicates and only retains the iris information of "Zhang San").

[0122] The system compares the iris information in set A and set B: each iris image is divided into 256 image blocks, the Euclidean distance and grayscale difference of the corresponding blocks are calculated, and the similarity formula is used to determine whether "Zhang San"'s iris has a high similarity in set B (similarity > preset threshold 90%), verifying the safety of the receiving scene.

[0123] 4. Instant access and data interception (instant access module operation)

[0124] After the verification is passed, the system triggers the instant access module and accesses the static web page hyperlink in the data packet through Zhang San's terminal.

[0125] After the static web page is loaded (displaying "weighing data and images of 5 trucks including Ji A·12345"), the terminal automatically performs a screenshot operation and saves the data image.

[0126] After the screenshot is completed, the system immediately deletes the static web page from the server and clears the browser cache, CDN cache and server-side cache to ensure that no data is left.

[0127] 5. Data extraction and secure storage (extraction module work)

[0128] Zhang San's terminal disconnects from the network. The extraction module extracts vehicle image data from the screenshot image and extracts weighing data through optical character recognition technology (such as "Ji A·12345, 52 tons").

[0129] The system recombines the vehicle image and the weighing data according to the license plate number (such as binding "the image of Ji A·12345 + 52 tons of data"), and stores them classified by license plate number on the local hard disk of the terminal, completing the secure landing of overloading control data.

[0130] In summary, during the operation of the system in the above embodiments, through quantum encryption transmission combined with dynamic verification of iris information, the security of data transmission and reception scenarios is ensured. The risk of data retention is reduced by removing and clearing the cache immediately after instantaneous access to the static web page. With the cooperation of offline database management of iris information, data limit alignment, and extraction in the case of network disconnection, a full-process security closed-loop from transmission to processing is formed. It not only ensures the integrity and confidentiality of traffic overloading control data through a multi-dimensional protection mechanism, but also improves the system operation efficiency with the help of dynamic data processing strategies, achieving the coordinated optimization of data security and processing efficiency, and effectively preventing data leakage and illegal access.

[0131] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements will not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. The traffic overload control data security protection system based on quantum encryption technology is characterized by: include: Create a module for receiving traffic overload control data, creating a static web page and a hyperlink to the static web page, and using the static web page to record the traffic overload control data; A monitoring module is used to monitor the security of the data transmission network. When the monitoring result is safe, the control data packet is transmitted based on quantum encryption; The verification module is used to collect iris information of all online system users in the receiving end after receiving and decrypting the data packet, compare the collected iris information of online system users with the iris information in each data packet, and verify the security of the data packet receiving scenario based on the comparison results; The instant access module is used to access the static web page hyperlinks in each received data packet, intercept the traffic control data presented on the static web page after the static web page corresponding to each hyperlink is loaded, and after the interception operation is completed, remove the static web page from the server and clear the cache data associated with the static web page; The extraction module is used to traverse the traffic control data image intercepted in the static web page and extract the traffic control data from the traffic control data image.

2. The traffic overload control data security protection system based on quantum encryption technology according to claim 1 is characterized in that: The traffic control data includes: vehicle weighing data and vehicle image data, each traffic control data is marked with the license plate number of the source vehicle, and the amount of traffic control data recorded in each static webpage is approximately equal; The creation module is provided with an offline database at a lower level. The offline database is used to store the iris information of system users. Each iris information is marked with the corresponding system user name. After each static webpage and its hyperlink are created, the hyperlink and a randomly selected iris information with the mark are used as the quantum encryption transmission target to perform the transmission operation from the sending end to the receiving end. Among them, the offline database is integrated into a preset computer device. The user iris information stored in the offline database is only available when the computer device is in an offline state. The user who is authorized to operate the computer device has the right to change, upload, and delete the user iris information. The computer device is only in a network connected state during the iris information selection stage.

3. The traffic overload control data security protection system based on quantum encryption technology according to claim 2 is characterized in that: The traffic overload control data recorded in each of the static web pages are aligned based on the extreme alignment strategy so that the traffic overload control data recorded in each of the static web pages are approximately equal in amount; The extreme alignment strategy of traffic overload control data is: Set the maximum amount of data recorded in the static web page, and place the vehicle image data in the received traffic control data in the static web page first. Each time a vehicle image data is placed in the static web page, identify whether the cumulative amount of vehicle image data placed in the static web page exceeds the maximum amount of data recorded in the static web page. If it does not exceed the maximum value, continue to perform the placement operation of the vehicle image data. If it exceeds the preset value, delete the most recently placed vehicle image data in the static web page, and use the vehicle weighing data in the traffic control data as the placement target. Each time a vehicle weighing data is placed, identify whether the cumulative amount of data placed in the static web page exceeds the maximum amount of data recorded in the static web page. If it does not exceed the maximum value, continue to perform the placement operation of the vehicle weighing data. If it exceeds the preset value, end, and create a new static web page for recording the remaining traffic control data through the creation module.

4. The traffic overload control data security protection system based on quantum encryption technology according to claim 1 is characterized in that: The data packet consists of a static webpage hyperlink that records traffic and overweight vehicle control data and iris information. The data transmission network security monitoring logic in the monitoring module is expressed as follows: Where: S is the data transmission network security; A′ is the attack defense dynamic entropy index; T′ is the comprehensive transmission stability index; E′ is the device link time reliability index; M′ is the security management mechanism evolution index; S0 is the security judgment threshold; When the data transmission network security S obtained based on equation (1) holds true in equation (2), the data transmission network is secure and the transmission operation is performed. Otherwise, the data transmission network security monitoring is performed again based on the specified period until the monitoring result is secure, and then the transmission operation is performed.

5. The traffic overload control data security protection system based on quantum encryption technology according to claim 1 is characterized in that: The verification module is provided with a hand-raising unit at the lower level, which is used for system users to electronically raise their hands; The collection of iris information and electronic hand-raising operation of all online system users in the background of the receiving end are performed on the computer equipment and camera corresponding to each system user. After all online system users in the background of the receiving end raise their hands through the hand-raising unit, the collection operation of the system user's iris information is triggered synchronously, and all system users perform iris information collection synchronously; After the iris information of all system users is collected, the receiving end decrypts the received data packets, obtains the iris information in each data packet, and simultaneously cleans the obtained iris information to remove duplicate iris information to obtain iris information set A. The iris information collected from system users is recorded as iris information set B. Iris information set A is used to perform a comparison operation with iris information set B. When performing a cleaning operation on the iris information obtained in each data packet, the cleaning is performed based on the system user name marked with each iris information.

6. The traffic overload control data security protection system based on quantum encryption technology according to claim 5 is characterized in that: The comparison operation of the iris information set A and the iris information set B is to pick up one iris information from each of the two sets to perform similarity calculation, so that all iris information combinations picked up by all picking methods are subjected to a similarity calculation; When each iris information in iris information set A finds a similar item in iris information set B, the verification module verifies that the data packet receiving scenario is safe. When any one or more iris information in iris information set A does not find a similar item in iris information set B, the process jumps to the hand-raising unit reset operation; The verification module triggers the instantaneous access module to run when the verification result is safe.

7. The traffic overload control data security protection system based on quantum encryption technology according to claim 5 is characterized in that: The similarity calculation formula of two iris information is: Iris information is iris image, and both iris images are evenly divided into n 2 image blocks; Where: d ij is the Euclidean distance between the feature vectors of the corresponding image blocks at position (i, j) in the two iris images; α is the adjustment coefficient of the influence of grayscale difference on similarity; D gray is the average grayscale value difference between the two iris images; β is the theoretical maximum sum of the distances between the feature points of all image blocks; γ is the theoretical maximum grayscale difference; in, Where: m is the dimension of the feature vector; is the feature vector of the image block corresponding to the position (i, j) in the two iris images, α∈(0,1], β is obtained by pre-calculating the preset iris image samples, the image block feature point includes the pixel with the largest grayscale mean difference with the adjacent pixels in the image block, and when SIMM is greater than the preset threshold, it is determined that the iris image from the iris information set A is a similar item to the iris image from the iris information set B in the two iris images for which similarity calculation is performed.

8. The traffic overload control data security protection system based on quantum encryption technology according to claim 1 is characterized in that: During the instant access module operation phase, the user configures a computer device configured by a system user to which the iris information source camera of which similar items exist in the iris information set B belongs to access the iris information; The operation of intercepting the traffic control data presented on the static web page is a screenshot operation, and the intercepted traffic control data is stored locally on the computer device that performs the interception operation; The static web page associated cache data includes: browser cache, CDN cache, server cache, and proxy server cache; Among them, after the creation module completes the creation of the static web page and the static web page hyperlink, it deletes the traffic control data corresponding to the traffic control data recorded in the static web page. When the monitoring module detects that the data transmission network is secure, the data packet executes the sending operation in the creation module.

9. The traffic overload control data security protection system based on quantum encryption technology according to claim 1 is characterized in that: During the operation phase of the extraction module, the vehicle image data is intercepted from the traffic overload control data, and the vehicle weighing data is obtained through text extraction. After the vehicle image data and the vehicle weighing data are intercepted and extracted, the vehicle image data and the vehicle weighing data are reorganized based on the marking information of the vehicle image data and the vehicle weighing data, so that the vehicle image data and the vehicle weighing data with the same marking information are combined with each other, and then based on the combination results, the vehicle image data and the vehicle weighing data are stored separately in the computer device; The operation content of the extraction module is executed on the computer device, and the computer device is disconnected from the network during the static web page removal and cache data clearing phase of the instant access module.

10. The traffic overload control data security protection system based on quantum encryption technology according to claim 1 is characterized in that: The connection method of each module in the system includes at least: The creation module is interactively connected to an offline database via a wireless network, the creation module is interactively connected to a monitoring module and a verification module via a wireless network, the verification module is interactively connected to a hand-raising unit via a wireless network, and the verification module is interactively connected to an instant access module and an extraction module via a wireless network.

Citation Information

Patent Citations

  • Data security protection system

    CN117592041A

  • Data security protection method and device and service equipment

    CN110769008A

  • Smart city Internet of Things information integration and sharing system

    CN118660022A

  • Industrial database protection method based on multi-mode authentication and encryption

    CN120050122A

  • Vehicular fleet management system and methods of monitoring and improving driver performance in a fleet of vehicles

    US20140226010A1