Cloud data-based construction engineering supervision quality acceptance and archive management system

By introducing an edge-aware control layer, a mobile business interaction layer, and a cloud-based management and storage layer into the construction engineering supervision system, the problems of data and document disconnection and difficulty in constraining on-site equipment by acceptance results have been solved. This has enabled strong logical association of data and secure management of equipment, thereby improving the objectivity of acceptance and the strength of control.

CN122175465APending Publication Date: 2026-06-09ZHEJIANG QIUSHI ENG CONSULTING SUPERVISION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ZHEJIANG QIUSHI ENG CONSULTING SUPERVISION CO LTD
Filing Date
2026-05-12
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

In existing construction project supervision systems, the industrial data collected on-site and the electronic acceptance forms filled out by supervisors lack underlying logical connections, making them prone to disconnection or tampering. Furthermore, the acceptance results are difficult to directly constrain the operation of on-site equipment, resulting in insufficient objectivity and control over the acceptance conclusions.

Method used

By establishing an edge-aware control layer, a mobile business interaction layer, and a cloud-based management and storage layer, bidirectional anchoring, multi-dimensional verification, and device interlocking of data and documents are achieved, ensuring the integrity of data collection and the accuracy of acceptance results.

Benefits of technology

It has achieved a strong logical connection between the supervision files and the underlying industrial data, improved the objectivity of the acceptance judgment and the control of construction equipment, and ensured the integrity of quality traceability evidence and the safe operation of on-site equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122175465A_ABST
    Figure CN122175465A_ABST
Patent Text Reader

Abstract

The application relates to the field of building engineering supervision information technology, and discloses a building engineering supervision quality acceptance and archive management system based on cloud data, which comprises an edge perception control layer, a mobile service interaction layer and a cloud control and storage layer. The edge perception control layer collects sensor data and performs hardware-level encryption, and performs bidirectional anchoring of summaries and hashes of electronic acceptance documents generated by the mobile service interaction layer. The cloud control and storage layer receives the anchored data and performs multidimensional verification including BIM spatial position and physical working condition time sequence logic. After the verification is passed, the cloud generates an encrypted unlocking token and issues the token to the edge layer. The edge perception control layer analyzes the token and drives the next process associated equipment controller to be unlocked. Through the data bidirectional anchoring and cloud edge end interlocking mechanism, the application solves the problem that acceptance data and documents are disconnected, and realizes closed-loop management from quality acceptance to on-site equipment control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology in construction engineering supervision, specifically to a cloud-based construction engineering supervision quality acceptance and file management system. Background Technology

[0002] With the improvement of information technology in construction engineering, digital supervision systems have gradually replaced the traditional paper-based file management model, becoming an important tool for project quality control. Existing supervision systems mainly focus on the electronic flow of processes and cloud storage of data, allowing users to fill out acceptance forms and upload on-site photos or videos via mobile terminals to record and archive quality acceptance.

[0003] However, in practical applications, existing construction project supervision models still have certain limitations. First, the industrial data collected on-site (such as pressure and temperature monitored by sensors) and the electronic acceptance documents filled out by supervisors usually come from different data links, lacking an underlying cryptographic connection. This logical separation between data and documents leads to a loose chain of evidence in the archives, making it difficult to technically prevent data from being replaced or tampered with, and failing to ensure a strict correspondence between electronic records and actual on-site conditions.

[0004] Secondly, traditional quality acceptance often relies on manual visual inspection or single-point data sampling, lacking a systematic verification of the continuity of the process and the accuracy of spatial location. For processes that need to be maintained for a certain period of time (such as water tightness tests and pressure tests), discrete sampling data alone cannot fully reflect the stability of the process, and the lack of strict spatial positioning constraints can easily lead to acceptance location deviations or off-site acceptance, resulting in insufficient objectivity of the acceptance conclusions.

[0005] Furthermore, existing supervision systems are mostly information recording platforms and have not yet formed an effective control loop with the physical equipment on the construction site. Acceptance results are usually only stored in the server as a status identifier and cannot be directly converted into physical constraints on the equipment associated with the next process. When quality acceptance fails or the acceptance process is not completed, the equipment on site is still started manually, causing the unqualified process to flow downstream, making it difficult to implement the "no transfer of unqualified processes" control requirement at the physical level. Summary of the Invention

[0006] In response to the technical problems in existing construction engineering supervision processes, such as the lack of strong logical connection between on-site acceptance data and electronic archives, the risk of data tampering at the data collection source, and the difficulty in directly constraining on-site equipment operation with acceptance results, this invention provides a cloud-based construction engineering supervision quality acceptance and archive management system. By establishing the connection between supervision business flow and physical data flow, it achieves control from data perception, archive anchoring, multi-dimensional verification to equipment interlocking.

[0007] To achieve the above objectives, the present invention provides the following technical solution: A cloud-based construction project supervision quality acceptance and file management system includes an edge-aware control layer, a mobile business interaction layer, and a cloud-based management and storage layer.

[0008] The edge-aware control layer is deployed at the construction site, integrating edge control nodes and configured to collect sensor data. It then connects to the mobile service interaction layer via a communication network. The mobile service interaction layer runs mobile terminals, configured to generate electronic acceptance documents, perform data anchoring interaction with the edge-aware control layer, and upload the anchored data to the cloud management and storage layer. The cloud management and storage layer deploys a consistency verification engine and an interlock command generator, configured to perform multi-dimensional verification on the received data and generate an encrypted unlock token based on the verification result, feeding it back to the edge-aware control layer. The edge-aware control layer is configured to receive and parse the encrypted unlock token, thereby driving the controller of the associated equipment in the next process to perform unlocking.

[0009] Preferably, to ensure data integrity at the source, the edge sensing control layer performs hardware-level encryption through edge control nodes. After acquiring the raw data units collected by the sensors, the edge control node performs hardware-level encryption on the raw data units using a local dynamic root key, and generates encrypted data units using preset encryption logic. The encrypted data units are then written to a locally integrated encrypted circular buffer. This mechanism, through the combination of a hardware root of trust and a circular buffer, achieves solidified data storage.

[0010] Preferably, the system employs a dynamic sampling frequency switching mechanism to adapt to the acceptance scenario. The edge-aware control layer responds to the process acceptance start command issued by the mobile service interaction layer, using sampling frequency control logic to switch the sampling frequency to a high-frequency transparent transmission frequency, generating high-frequency encrypted data units. Simultaneously, the edge control node locks historical data within the encrypted circular buffer and, combined with the high-frequency encrypted data units, uses dataset construction logic to construct an evidence dataset, thereby ensuring that the evidence covers the complete temporal sequence before and after the process.

[0011] Preferably, to establish a strong association between data and documents, the edge-aware control layer and the mobile service interaction layer collaboratively perform a two-way anchoring operation. The edge-aware control layer calculates an industrial data summary from the evidence dataset and sends it; the mobile service interaction layer receives the industrial data summary and embeds it into the electronic acceptance document, generating a packaged acceptance document, then calculates the hash value of the packaged acceptance document to obtain the document file hash and returns it; the edge-aware control layer receives the document file hash and writes it into the external index tag area of ​​the evidence dataset. Through the above process, the data summary is embedded in the document, and the document hash is written back to the data header, forming a two-way logical chain.

[0012] Preferably, the consistency verification engine of the cloud management and storage layer performs data chain integrity verification. The system extracts industrial data summaries from the uploaded packaged acceptance documents and extracts document file hashes from the external index tag area of ​​the uploaded evidence dataset. It uses two-way anchored verification conditions to verify the extracted content, ensuring that the two sets of data uploaded to the cloud correspond and have not been altered.

[0013] Preferably, the system introduces spatial consistency verification based on Building Information Modeling (BIM). The cloud management and storage layer extracts the measured coordinate components uploaded by the mobile business interaction layer, obtains the theoretical coordinate components and geometric bounding box side lengths of the corresponding components in the BIM model, and combines them with the measured coordinate components. Spatial inclusion verification logic is used for calculation, and the calculation results determine whether the location where the acceptance action occurred is within the allowable range, thereby verifying the compliance of the acceptance location.

[0014] Preferably, the system introduces time-series logic verification based on physical operating condition rules. The cloud-based management and storage layer decrypts the evidence dataset to obtain the original data stream, and performs integral calculation on the original data stream using a time-series logic integration method based on the physical operating condition rule parameter set to obtain the effective compliance duration. The system determines whether the effective compliance duration is greater than or equal to the effective compliance duration threshold; wherein, the effective compliance duration threshold is defined as the minimum time required for the process to maintain a stable state as specified in the physical operating condition rule parameter set. This logic ensures that the acceptance process meets the integral compliance requirements of the process in the time domain.

[0015] Preferably, the interlock command generator uses a digital signature mechanism to ensure the security of control commands. After successful verification, the cloud management and storage layer uses the cloud root key private key to digitally sign the fields containing device identifier, operation command, and time information, and uses token generation logic to process the digital signature and the above fields to generate an encrypted unlock token and issue it.

[0016] Preferably, the edge-aware control layer achieves physical interlocking by parsing cloud commands. The edge-aware control layer receives the encrypted unlock token and performs signature verification using the cloud public key. It then uses the interlock control state transition logic to parse the encrypted unlock token to determine the control signal state and drives the next process associated with the equipment controller based on the control signal state, ensuring that the operation of the field equipment is controlled by the verification results from the cloud.

[0017] Preferably, the system has offline disaster recovery and security guidance functions. The edge-aware control layer monitors the communication network status and the current system time in real time; when the communication network status is faulty and the current system time exceeds the valid expiration time of the encryption unlock token, the system forcibly flips the control signal status according to the interlock control status transition logic, and cuts off the enable signal of the controller of the next process-related equipment according to the flipped control signal status, ensuring that the equipment automatically returns to a safe shutdown state when the monitoring connection is lost.

[0018] This invention constructs a closed-loop system based on spatiotemporal fingerprint coupling and archive interlocking feedback through the aforementioned technical solution. On the one hand, by utilizing a trusted execution environment and bidirectional anchoring technology, it solves the problem of the disconnect between electronic archives and underlying industrial data; on the other hand, by driving device interlocking on the edge side through multi-dimensional verification in the cloud, it transforms post-event data archiving into in-process process control, thereby enhancing the management and control capabilities of construction project supervision.

[0019] This invention provides a cloud-based construction project supervision quality acceptance and record management system. It has the following beneficial effects: 1. This invention ensures a strong logical connection between supervision files and underlying industrial data through hardware-level encryption and a two-way anchoring mechanism at the edge control nodes. The system uses a local dynamic root key to solidify the original data at the edge and constructs an indivisible two-way index chain by embedding industrial data summaries into acceptance documents and writing the document file hash back to the data header. This solution solves the problem of easy disconnection or tampering between electronic documents and on-site measured data in traditional acceptance processes, ensuring the integrity of quality traceability evidence.

[0020] 2. This invention employs a multi-dimensional verification technology based on BIM spatial constraints and physical condition temporal integration, enhancing the objectivity of acceptance judgment. The cloud-based consistency verification engine not only utilizes spatial inclusion verification formulas to check the compliance of acceptance locations but also quantifies the continuous stability of the process through temporal logical integration formulas. This verification method overcomes the limitations of traditional single-point sampling or manual visual inspection, ensuring that acceptance results meet the continuity requirements of process specifications in the spatiotemporal dimensions.

[0021] 3. This invention constructs a closed-loop interlocking system from cloud-based logical verification to on-site physical control, enhancing the control over construction equipment. By generating an encrypted unlock token containing a digital signature, the system directly converts the compliance verification results from the cloud into control signals for edge devices; simultaneously, combined with offline disaster recovery logic that automatically reverses after network outage timeouts, it ensures that equipment can automatically enter a safe state in the event of communication anomalies. This mechanism solves the technical problem that acceptance conclusions are difficult to constrain the operation of on-site production equipment in real time. Attached Figure Description

[0022] Figure 1This is a schematic diagram of the overall architecture of a closed-loop control system for building engineering quality based on spatiotemporal fingerprint coupling and archive interlocking feedback, according to an embodiment of the present invention. Figure 2 This is a schematic diagram of the overall process of a closed-loop quality control method for construction projects according to an embodiment of the present invention; Figure 3 This is a block diagram of the hardware structure of the electronic device of the present invention.

[0023] The components are as follows: 100, Edge Awareness Control Layer; 110, Edge Control Node; 111, Central Processing Unit; 112, Trusted Execution Environment Module; 113, Encrypted Ring Buffer; 114, Multi-Protocol Industrial Interface Unit; 120, Sensor Group; 130, Next Process Associated Equipment Controller; 200, Mobile Service Interaction Layer; 210, Mobile Terminal; 300, Cloud Management and Storage Layer; 310, Consistency Verification Engine; 320, WORM Compliant Storage Pool; 330, Key Management Service Module; 340, Interlock Instruction Generator; 400, Communication Network; 701, System Bus; 702, Processor; 703, Memory; 704, Communication Interface; 705, Input / Output Interface. Detailed Implementation

[0024] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] See attached document Figure 1 This invention provides a cloud-based construction project supervision quality acceptance and record management system. The system mainly consists of an edge-aware control layer 100, a mobile service interaction layer 200, and a cloud-based management and storage layer 300. Data interaction and command transmission between each layer are achieved through a communication network 400.

[0026] The edge-aware control layer 100 is located at the construction site and is responsible for the collection, caching, preprocessing, and control execution of industrial data and field equipment. The edge-aware control layer 100 includes several sensor groups 120 distributed at the construction site, controllers for the next process-related equipment 130, and the core edge control node 110.

[0027] Sensor group 120 is connected to edge control node 110 via industrial fieldbus or short-range wireless communication protocol to collect physical environmental parameters and equipment operating status data of the construction site in real time, forming raw SCADA data stream. The next process associated equipment controller 130 is physically connected to edge control node 110 to receive control commands and drive the start or stop of on-site construction equipment.

[0028] Edge control node 110 is a hardware gateway device deployed in the field, which integrates a central processing unit 111, a trusted execution environment module 112, an encrypted ring buffer 113, and a multi-protocol industrial interface unit 114.

[0029] The Trusted Execution Environment (TEE) module 112 is a hardware-isolated secure computing area that runs independently of the main operating system of the edge control node 110. The TEE module 112 is used to store local device private keys, perform cryptographic hash operations, and manage the locking status of data to prevent external malware or unauthorized users from tampering with the underlying data.

[0030] The encrypted circular buffer 113 is a fixed-size contiguous memory region or high-speed storage partition within the internal memory of the edge control node 110. The encrypted circular buffer 113 is configured in a first-in, first-out (FIFO) mode to temporarily store high-frequency raw data acquired by the sensor group 120. Data written to the encrypted circular buffer 113 is protected by the encryption key of the trusted execution environment module 112.

[0031] The multi-protocol industrial interface unit 114 includes an RS485 interface, an Ethernet interface, and an I / O control interface, which are used to adapt to different models of sensor groups 120 and the controller 130 of the next process associated equipment to realize data reading and control signal transmission.

[0032] The mobile service interaction layer 200 consists of a mobile terminal 210 held by the supervisor. The mobile terminal 210 is connected to the cloud control and storage layer 300 via the communication network 400. The mobile terminal 210 runs a dedicated application for sending process acceptance requests to the cloud control and storage layer 300, uploading multimedia attachments taken on-site, and submitting electronic acceptance documents containing digital signatures.

[0033] The cloud-based management and storage layer 300 is deployed on a remote server cluster or cloud computing platform, responsible for the logical verification of all data, file storage, and generation of interlock commands. The cloud-based management and storage layer 300 includes a consistency verification engine 310, a WORM compliant storage pool 320, a key management service module 330, and an interlock command generator 340.

[0034] The consistency verification engine 310 is configured to receive acceptance documents from the mobile terminal 210 and industrial data from the edge control node 110, and perform integrity comparison, spatial location comparison and physical condition logic comparison between the two, and output a Boolean type verification result.

[0035] WORM Compliance Storage Pool 320 is a write-once, read-many storage medium used to permanently store acceptance files and associated industrial evidence data after verification, ensuring that the stored data cannot be modified or deleted.

[0036] The key management service module 330 is used to generate, distribute and manage encryption key pairs within the system, and is responsible for verifying the identity credentials of each node.

[0037] The interlock instruction generator 340 is configured to generate an encrypted unlock token containing a digital signature using the private key provided by the key management service module 330, based on the pass result output by the consistency verification engine 310. This encrypted unlock token is sent to the edge control node 110 via the communication network 400 to unlock the associated device controller 130 for the next process step.

[0038] The communication network 400 uses a 5G or 4G mobile communication network as the primary transmission channel and fiber broadband as a backup channel to establish a high-speed encrypted data link between the edge sensing control layer 100, the mobile service interaction layer 200, and the cloud management and storage layer 300. Through the above hardware architecture and module division, the system realizes closed-loop management from on-site physical sensing to cloud logic verification and then to on-site physical control.

[0039] See attached document Figure 2 This invention provides a closed-loop management method for building engineering quality based on spatiotemporal fingerprint coupling and archiving interlock feedback, comprising the following steps: S1, in normal operation mode, the edge control node drives the sensor group to continuously collect data, writes the generated raw time series data into the local encrypted circular buffer in real time, and only uploads the downsampled status data to the cloud. S2, in response to the process acceptance start command issued by the mobile terminal, the edge control node locks the historical data in the preset backtracking window in the encrypted ring buffer, synchronously switches to the high-frequency transparent transmission acquisition mode, and routes the subsequently generated raw time series data as high-frequency evidence data to the pending storage area in the local trusted execution environment module. S3, at the end of the acceptance, the edge control node calculates the hash digest of the high-frequency evidence data in the pending storage area, the mobile terminal receives the hash digest and embeds it into the generated electronic acceptance document, and at the same time the edge control node receives the file hash value of the electronic acceptance document and attaches it as an index tag to the header of the high-frequency evidence data to establish a two-way anchor. S4, the edge control node maintains the temporary frozen state of high-frequency evidence data in the pending storage area, prohibits overwriting or deletion, and works with the mobile terminal to synchronously upload the electronic acceptance document and the high-frequency evidence data bidirectionally anchored to it to the cloud management and storage layer. S5, the consistency verification engine of the cloud management and storage layer, after receiving the data, performs multi-dimensional verification on the electronic acceptance documents and high-frequency evidence data, including integrity comparison, spatial location comparison and physical condition logic comparison, and outputs the verification result of Boolean type. S6. Based on the verification results, the cloud management and storage layer generates corresponding control commands and feeds them back to the edge control node. The edge control node then drives the controller of the next process-related equipment to perform physical unlocking start-up or safety locking shutdown operation.

[0040] To more clearly illustrate the key technical details and specific implementation logic involved in each step of the present invention, the edge-side data acquisition mechanism, bidirectional fingerprint coupling method, multidimensional verification algorithm and interlock control strategy in the above process will be described in detail below with reference to specific embodiments.

[0041] In this embodiment, the edge control node 110 integrates a trusted execution environment module 112 and an encrypted ring buffer 113 to achieve high-security data acquisition and temporary storage of industrial field data. The specific implementation process includes the following steps: S301, Construct an encrypted ring buffer 113 based on the Trusted Execution Environment module 112. During the system boot phase, the edge control node 110 allocates a contiguous fixed storage space in physical memory through the central processing unit 111 as the encrypted ring buffer 113. The logical structure of this encrypted ring buffer 113 is configured as a ring queue with its head and tail connected, and it has a fixed time span capacity. The capacity of this time span The set value is greater than the sum of the preset backtracking window duration and the maximum transmission delay duration for the mobile terminal 210 to send instructions to the edge control node 110. To ensure data confidentiality, the memory address mapping table of the encrypted ring buffer 113 is exclusively managed by the trusted execution environment module 112, and the external operating system cannot directly access this area through general memory addresses.

[0042] S302 performs hardware-level encrypted writing of the raw data. The analog signals acquired by sensor group 120 are converted from analog to digital to form discrete raw data streams. The raw data stream is defined as a sequence. Each data unit Includes collection timestamp and physical measurement values In the data unit Before writing to the encrypted circular buffer 113, the edge control node 110 invokes the encryption instruction set within the trusted execution environment module 112 to perform hardware encryption. The encrypted data unit is then calculated using an encryption calculation formula. The encryption formula is: ; In the formula: Represents a symmetric encryption algorithm function; Represents the original data unit; This indicates the local dynamic root key, which is stored in the security register of the Trusted Execution Environment module 112; This represents the encrypted data unit.

[0043] Encrypted data unit Data is written to the encrypted circular buffer 113 according to the first-in, first-out (FIFO) principle. When the buffer is full, new data units overwrite the oldest data units written.

[0044] S303 monitors process acceptance events and drives sampling frequency switching.

[0045] The edge control node 110 internally operates a sampling control state machine. This state machine includes a normal monitoring state and an acceptance pass-through state. The system defaults to the normal monitoring state, in which the edge control node 110 controls the multi-protocol industrial interface unit 114 to read data at a lower frequency.

[0046] When the edge control node 110 receives the process acceptance start command (event) from the mobile terminal 210 via the communication network 400 When the current time is determined to be the start time of the acceptance test, the current time is considered to be the start time of the acceptance test. And switch the state machine to the acceptance transparent transmission state.

[0047] During this process, the system adjusts the sampling frequency according to the sampling frequency control formula. The sampling frequency control formula is: ; In the formula: Indicates the system at time 10:00 The running status, among which This indicates the acceptance and transparent transmission status. This represents a state of routine monitoring. Indicates the high-frequency transparent transmission frequency; Indicates the low-frequency sampling frequency; This indicates the actual sampling frequency.

[0048] S304, executes pre-triggered backtracking window data locking and extraction.

[0049] In response to state machine transitions Upon receiving the status, edge control node 110 immediately triggers the backtracking mechanism.

[0050] Edge control node 110 first determines the backtracking start time. The calculation method is as follows ,in The preset backtracking window duration.

[0051] Subsequently, the trusted execution environment module 112 locates the corresponding backtracking start time in the encrypted circular buffer 113. The trusted execution environment module 112 will access all encrypted data units from this pointer up to the currently written pointer. The data is copied to the pending storage area within the Trusted Execution Environment module 112, thereby completing the physical locking and preventing the data from being overwritten due to subsequent circular writes to the encrypted circular buffer 113.

[0052] The system merges the data within the retrospective window with the real-time data generated during the subsequent acceptance process to construct an evidence dataset. The evidence dataset is defined using a dataset construction formula. The formula for constructing the dataset is: ; In the formula: This represents an evidence dataset that aggregates all encrypted data. This refers to the encrypted data unit generated in the aforementioned step S302; Indicates the start time of the acceptance process; Indicates the preset backtracking window duration; This indicates the timestamp of the data collection corresponding to the data unit; This indicates the end time of the acceptance process.

[0053] S305, route data to the pending storage area. During the acceptance pass-through state, edge control node 110 will transmit all newly acquired and encrypted data units. The data is synchronously appended to the pending storage area within the Trusted Execution Environment module 112. This data will serve as the basis for generating subsequent archive files.

[0054] This embodiment establishes a hash digest-based cross-embedding mechanism between the edge control node 110 and the mobile terminal 210 to achieve a strong logical association between business documents and industrial data. The specific implementation process includes the following steps: S401 performs serialization and digest calculation of industrial evidence data. This is done when the process acceptance procedure is at time [time missing]. At the end, edge control node 110 freezes the evidence dataset in the pending storage area within trusted execution environment module 112. To eliminate the impact of differences in binary storage formats across different computer architectures on hash calculations, the trusted execution environment module 112 first processes the evidence dataset. Binary serialization is performed to generate a standardized byte stream. Subsequently, the edge control node 110 invokes the hash operation unit within the trusted execution environment module 112 to calculate an industrial data summary from the serialized data. Calculate industrial data summaries using the data summary calculation formula. The formula for calculating the data summary is: ; In the formula: A unique digital fingerprint representing a summary of industrial data, i.e., a dataset of evidence; This represents a collision-resistant hash function; in this embodiment, the SHA-256 algorithm is used. This represents a binary serialization function; The evidence dataset is defined as follows: That is, a collection of encrypted data units, consistent with the steps described above.

[0055] S402, Construct an acceptance document that includes forward anchoring.

[0056] Edge control node 110 transmits the calculated industrial data summary via communication network 400 Send to mobile terminal 210.

[0057] Mobile terminal 210 generates basic acceptance document files based on the acceptance conclusions input by the supervisor, multimedia photos taken on site, and form information. The mobile terminal 210 will receive a summary of the industrial data. The extended attribute area (Metadata) of this file is written to form the packaged acceptance document. .

[0058] The document packaging formula is used to represent the packaged acceptance document. The structure and document encapsulation formula are as follows: ; In the formula: This indicates a packaged acceptance document that incorporates embedded data fingerprints; This refers to the basic acceptance document file containing form text and multimedia attachments; This indicates a dataset merging operation; This represents an extended metadata field in the file format; This represents a summary of industrial data.

[0059] S403 generates a digital signature and reverse index fingerprint for the document.

[0060] Mobile terminal 210 calls its built-in secure computing unit and uses a pre-set user private key to encapsulate the acceptance document. Digital signatures are used to protect the contents of documents (including embedded information). (The text has been altered.)

[0061] After signing is completed, the mobile terminal 210 calculates the document file hash of the final document file. .

[0062] Calculate the document file hash using the document hash calculation formula. The formula for calculating the hash of a document is: ; In the formula: This represents the document file hash, which serves as a unique index identifier for the document in the system. Represents a collision-resistant hash function; This indicates that the digitally signed packaging and acceptance document has been completed.

[0063] S404, Perform reverse anchoring of data header.

[0064] Mobile terminal 210 calculates the hash of the document file The data is sent back to the edge control node 110 via the communication network 400.

[0065] Edge control node 110 receives the hash value, and the trusted execution environment module 112 performs the write operation. The trusted execution environment module 112 hashes the document file. Write to evidence dataset The external index label area.

[0066] Special note: The external index label area is independent of the evidence dataset. The write operation does not change the evidence dataset within the content load area. Its own binary content, thus ensuring the industrial data summary calculated in S401. The effectiveness.

[0067] After this operation is completed, the evidence dataset With packaging acceptance documents They form an inseparable two-way cryptographic binding.

[0068] This binding relationship is described using two-way anchoring verification conditions, which are as follows: ; In the formula: This indicates the bidirectional coupling state between the evidence dataset and the packaged acceptance document; This indicates a read operation that extracts content from the document's metadata; Indicates the numerical equality determination; This represents a summary of industrial data. This indicates a read operation on the external index label area of ​​the evidence dataset; This indicates the hash of the document file.

[0069] This embodiment relies on the consistency verification engine 310 deployed in the cloud-based management and storage layer 300 to perform multi-dimensional verification on the uploaded data packets, including cryptographic integrity, BIM spatial constraints, and physical condition logic. The specific implementation process includes the following steps: S501 performs data integrity and tamper-proof hash comparison.

[0070] The consistency verification engine 310 parses the encapsulation acceptance document from the data packet uploaded by the mobile terminal 210. The evidence dataset was then parsed from the data stream uploaded by edge control node 110. .

[0071] The consistency verification engine 310 performs the following extraction operations: from the packaged acceptance document Extracting industrial data summaries from metadata extended attributes From evidence datasets Extracting document file hash from external index tag area .

[0072] Subsequently, the consistency verification engine 310 extracts the evidence dataset from the server's computing memory space. The external index tag area attached to the header only re-executes serialization and hashing operations on the original encrypted payload to obtain the calculated value. At the same time, the packaging acceptance documents Perform a hash operation to obtain the calculated value. .

[0073] The consistency verification engine 310 executes bidirectional comparison logic: [determine / adjust] Is it equal to ,and Is it equal to If any comparison result is negative, the data link is determined to be broken or tampered with, and a verification failure result is output.

[0074] S502, Perform spatial location constraint verification based on BIM model.

[0075] After passing the integrity check, the consistency check engine 310 retrieves the packaged acceptance document. Extract the unique component identifier of the acceptance object and the global positioning coordinates uploaded by the mobile terminal 210 at the time of acceptance.

[0076] The consistency verification engine 310 queries the associated Building Information Model (BIM) database to obtain the theoretical coordinates of the geometric center and the dimensions of the geometric bounding box corresponding to the unique identifier of the component.

[0077] The system uses a spatial inclusion verification formula to determine whether the location of the acceptance action is within the allowable range. The spatial inclusion verification formula is: ; In the formula: This represents the boolean result of the spatial verification; a value of True indicates that the position verification passed. This represents a logical AND operation, meaning that the conditions must be met simultaneously in all three dimensions: x, y, and z. Indicates the dimensions of the spatial coordinate axes; This indicates that the data uploaded by mobile terminal 210 is in... Measured coordinate components in the dimension; This represents the theoretical coordinate components of the geometric center of the component in the BIM model; Indicates that the component is in The side length of the geometric bounding box in a given dimension; This represents the preset spatial fault tolerance threshold, used to compensate for drift errors in the satellite positioning system.

[0078] S503 performs logical feature verification based on physical operating condition rules.

[0079] The consistency verification engine 310 requests the decryption key (i.e., the synchronized key) corresponding to the current session of the edge control node 110 from the key management service module 330. ), and use this key to pair the evidence dataset. Decrypt and extract the original data stream. The system is based on the packaging acceptance document. The system loads the corresponding physical condition rule parameter set based on the recorded process type. The system will then process the discrete raw data stream. Fit to a continuous function in the time domain The physical characteristics of the device within the entire acceptance time window are verified to conform to objective technological laws. The physical rule matching degree is calculated using a time-series logic integral formula. The time-series logic integral formula is: ; In the formula: This indicates the effective compliance duration, which is the cumulative time during the entire acceptance process when the physical parameters meet the specification requirements; Indicates the start time of the acceptance process; Indicates the end time of acceptance; This represents an indicator function that takes the value 1 when the internal logic condition is true, and 0 otherwise. Indicates the original data stream at time [time]. The physical measurement value (or the value fitted from the original data); This represents a set of physical operating condition rules parameters, including preset pressure thresholds, temperature thresholds, or rate of change thresholds. This represents the physical logic discrimination function.

[0080] Specific example: In a water pipe pressure test scenario. Defined as This means that the current pressure value must be greater than the minimum pressure threshold. Furthermore, the absolute value of the pressure change rate must be less than the stability threshold. ; S504 generates a comprehensive verification conclusion. The consistency verification engine 310 compares and calculates the effective compliance duration. Duration required by preset standard specifications If the conditions are met If the spatial location is legal and the physical parameters are compliant and the duration meets the standard, the consistency verification engine 310 determines that the acceptance is passed and sends a pass signal to the interlock instruction generator 340; otherwise, the acceptance is determined to fail and the cloud management and storage layer 300 triggers an abnormal alarm process.

[0081] This embodiment ensures that the actions of field devices are strictly controlled by the consistency verification results in the cloud through the collaborative work of a cryptographic token mechanism and a local state machine. The specific implementation process includes the following steps: S601 performs transient freezing and pending area management of transmission gaps.

[0082] The evidence dataset is stored at edge control node 110. During the process of uploading to the cloud management and storage layer 300, and during the transmission gap while waiting for cloud feedback instructions, the trusted execution environment module 112 implements write protection control on the designated storage area.

[0083] Specifically, the Trusted Execution Environment module 112 calls the Memory Management Unit (MMU) interface to set the physical memory page attribute corresponding to the pending storage area to read-only and starts a transient hold timer. During this period, the encrypted circular buffer 113 continues to process newly input sensor data in other memory address segments.

[0084] The Trusted Execution Environment Module 112 releases the lock on the pending storage area and releases the space only when the edge control node 110 receives an archive confirmation frame from the cloud management and storage layer 300. If no confirmation is received within the specified time or a verification failure notification is received, the system maintains the locked state and triggers a retransmission mechanism to ensure that the evidence data is not overwritten before persistent storage.

[0085] S602 generates a cloud-based encrypted unlock token.

[0086] When the consistency verification engine 310 outputs a "pass" verification result, the interlock instruction generator 340 is triggered. The interlock instruction generator 340 requests the key management service module 330 to call the private key of the cloud root key to generate an encrypted unlock token containing time-limited constraints and device-specific characteristics. The encryption / unlocking token is calculated using a token generation formula. The token generation formula is: ; In the formula: This indicates that the generated cryptographic unlock token is a string of binary data with a digital signature; This represents an asymmetric encryption signature function; This indicates a data concatenation operation; A unique hardware identifier code indicating the controller 130 of the equipment associated with the next process, used to define the subject executing the instruction; Indicates the operation instruction code; Indicates the expiration time of the token, used to limit the time window for instructions; This represents the document file hash, whose definition is consistent with that in step S403 above, and is used to bind physical actions to specific acceptance documents; This represents the root private key generated in the cloud. The data is transmitted to edge control node 110 via communication network 400.

[0087] S603, execute the edge-side device interlock state machine determination.

[0088] The edge control node 110 maintains an interlocked control state machine internally and has pre-performed secure time synchronization (such as NTP or PTP protocol) with the cloud management and storage layer 300 via the communication network 400. This state machine controls the level signals output by the multi-protocol industrial interface unit 114 to the next process-related equipment controller 130.

[0089] The system determines the current output state based on the interlock control state transition formula. The interlock control state transition formula is: ; In the formula: Indicates at time The control signal output status, In active state, The machine is in a stopped state. This represents a signature verification function used to verify whether the digital signature of a token is valid. Indicates the expiration time of the parsed token; Indicates the target device identifier specified in the token; This indicates the actual identifier of the next process associated device controller 130 in the local connection; ≡ indicates a value equality determination.

[0090] S604 performs offline disaster recovery and security-oriented control.

[0091] The system implements offline disaster recovery logic based on time leases through the above interlock control state transition formula.

[0092] When a communication network 400 fails and a new token cannot arrive, according to the current system time... The shift, the conditions in the formula It will change to False. At this point, regardless of the state at the previous moment, the output state of the interlock control state machine will change. All will automatically flip to .

[0093] Edge control node 110 cuts off the enable signal of the controller 130 of the next process-related equipment through multi-protocol industrial interface unit 114, forcing the equipment to enter a safe shutdown mode. This mechanism ensures that the field equipment has the ability to automatically shut down in abnormal operating conditions where cloud monitoring is lost.

[0094] See attached document Figure 3 This electronic device is designed to support the aforementioned industrial data evidence, bidirectional fingerprint coupling, and interlocking control methods at the hardware level. In this embodiment, the electronic device, depending on its deployment location, can be an edge control node 110 deployed at the construction site, a computing server deployed in the cloud management and storage layer 300, or a mobile terminal 210 held by the supervisor.

[0095] like Figure 3 As shown, the electronic device mainly includes a processor 702, a memory 703, a communication interface 704, and an input / output interface 705 that are interconnected via a system bus 701.

[0096] The processor 702 is the computing core of the electronic device, responsible for executing computer program instructions stored in the memory 703 to implement the various method steps in the foregoing embodiments.

[0097] When the electronic device is implemented as edge control node 110, processor 702 corresponds to the aforementioned central processing unit 111. To support the operation of the trusted execution environment module 112, processor 702 employs an industrial-grade chip that supports hardware-level isolation technology (such as TrustZone or SGX). Processor 702 is configured to divide the execution environment into a secure computing partition and a general computing partition at the hardware level. Specifically, the hash digest calculation in step S401, the data encryption operation in step S302, and the token verification operation in step S603 are forcibly confined to execution within the secure computing partition, and a hardware interrupt isolation mechanism prevents processes in the general computing partition from illegally accessing sensitive data.

[0098] When the electronic device is implemented as a server in the cloud management and storage layer 300, the processor 702 is configured as a high-performance computing unit to perform large-scale time-series data integration operations involved in the consistency verification engine 310 in step S503.

[0099] The memory 703 is used to store non-transitory computer-readable instructions, system parameters, and business data.

[0100] In the architecture of edge control node 110, memory 703 uses the physical address mapping mechanism of memory management unit (MMU) to partition a contiguous physical memory region as the aforementioned encrypted ring buffer 113. The read and write permissions of this region are hardware locked, allowing only processor 702 in secure computing partition mode to access it, thereby implementing tamper-proof caching of the original data in step S301 on the physical circuit.

[0101] In addition, the memory 703 stores a computer program that, when executed by the processor 702, performs operations including but not limited to: performing time window segmentation and data freezing in S303; performing industrial evidence data serialization and summary calculation in S401; and performing interlock control state machine decision logic in S603.

[0102] Communication interface 704 is used to enable data interaction between electronic devices and external networks or other devices. For edge control node 110, communication interface 704 corresponds to multi-protocol industrial interface unit 114, which integrates a fieldbus controller for connecting sensor group 120 and a network baseband chip for connecting communication network 400. Communication interface 704 is responsible for receiving encryption and unlocking tokens. The data packet is sent to the processor 702 for verification; at the same time, the communication interface 704 is responsible for outputting control level or register instructions to the next process-related equipment controller 130.

[0103] System bus 701 includes an address bus, a data bus, and a control bus, used for transmitting information between these components. Those skilled in the art will understand that... Figure 3 The structure shown is for illustrative purposes only; electronic devices may also include other components such as power modules and watchdog circuits.

[0104] Furthermore, embodiments of the present invention also provide a computer-readable storage medium. This storage medium is a non-volatile storage medium, such as a hard disk drive, a solid-state drive (SSD), or a flash memory chip.

[0105] The storage medium stores a computer program or instruction code. When the computer program is loaded and executed by one or more processors, it causes the processor to implement the method steps of any of the foregoing embodiments of this specification.

[0106] Specifically, the computer program includes data evidence acquisition module code for executing S301-S304, bidirectional fingerprint coupling module code for executing S401-S404, multidimensional spatiotemporal consistency verification module code for executing S501-S504, and interlocking feedback control module code for executing S601-S604.

[0107] Specifically, to support the algorithm's execution, the storage medium also stores key algorithm logic and data structure definitions, including: Used to define the evidence dataset Data structure parameter configuration; Used for calculating industrial data summaries SHA-256 algorithm library; Used to perform two-way anchoring verification conditions The logical judgment code; Used to calculate effective compliance duration Numerical analysis algorithm for the time-series logic integral formula; Used to determine the output state of control signals The decision logic table for the interlock control state transition formula.

[0108] Through the cooperation of the aforementioned hardware devices and storage media, this invention solidifies the abstract consistency verification algorithm into specific equipment actions, ensuring that the start and stop of the next process-related equipment controller 130 are strictly controlled by the logical closed loop of cloud management and storage layer 300.

Claims

1. A cloud-based construction project supervision quality acceptance and file management system, characterized in that, include: The edge perception and control layer is deployed at the construction site, integrating edge control nodes to collect sensor data and communicating with the mobile service interaction layer through a communication network. The mobile service interaction layer runs a mobile terminal, generates electronic acceptance documents, performs data anchoring interaction with the edge perception control layer, and uploads the anchored data to the cloud management and storage layer. The cloud management and storage layer deploys a consistency verification engine and an interlock instruction generator to perform multi-dimensional verification on the received data and generate an encrypted unlock token based on the verification result to feed back to the edge-aware control layer. The edge-aware control layer receives and parses the encrypted unlock token, thereby driving the next process associated device controller to perform unlocking.

2. The cloud-based construction project supervision quality acceptance and file management system according to claim 1, characterized in that, The edge-aware control layer performs the following steps: The edge control node acquires the raw data units collected by the sensor and performs hardware-level encryption on the raw data units using a local dynamic root key; The original data unit is calculated using the encryption formula to generate an encrypted data unit; The encrypted data unit is written into the locally integrated encrypted ring buffer.

3. The cloud-based construction project supervision quality acceptance and file management system according to claim 2, characterized in that, The edge-aware control layer performs the following steps: In response to the process acceptance start command issued by the mobile service interaction layer, the sampling frequency is switched to a high-frequency transparent transmission frequency using the sampling frequency control formula to generate the high-frequency encrypted data unit. Historical data within the encrypted circular buffer is locked, and combined with the high-frequency encrypted data units, an evidence dataset is constructed using a dataset construction formula.

4. The cloud-based construction project supervision quality acceptance and file management system according to claim 3, characterized in that, The edge-aware control layer and the mobile service interaction layer work together to perform the following steps: The edge-aware control layer uses the data digest calculation formula to calculate a digest of the evidence dataset, obtains an industrial data digest, and sends it. The mobile service interaction layer receives the industrial data summary and embeds the electronic acceptance document, and generates a packaged acceptance document using the document encapsulation formula. The hash value of the packaged acceptance document is calculated using the document hash calculation formula to obtain the document file hash and return it. The edge-aware control layer receives the document file hash and writes the document file hash into the external index label area of ​​the evidence dataset.

5. The cloud-based construction project supervision quality acceptance and file management system according to claim 4, characterized in that, The cloud-based management and storage layer performs the following steps: Extract the industrial data summary from the uploaded packaging and acceptance document; Extract the document file hash from the external index label area of ​​the uploaded evidence dataset; The extracted industrial data summary is compared with the document file hash using a two-way anchoring verification condition to verify the integrity of the data chain.

6. The cloud-based construction project supervision quality acceptance and file management system according to claim 5, characterized in that, The cloud-based management and storage layer performs the following steps: Extract the measured coordinate components uploaded by the mobile service interaction layer; Obtain the theoretical coordinate components and geometric bounding box side length of the corresponding component in the BIM model, and calculate using the spatial inclusion verification formula in combination with the measured coordinate components; Based on the calculation results, determine whether the location where the acceptance action occurred is within the allowable range.

7. The cloud-based construction project supervision quality acceptance and file management system according to claim 6, characterized in that, The cloud-based management and storage layer performs the following steps: Decrypt the evidence dataset to obtain the original data stream; Based on the physical operating condition rule parameter set, the original data stream is integrally calculated using the time-series logic integral formula to obtain the effective compliance duration; Determine whether the effective compliance duration is greater than or equal to the effective compliance duration threshold; The effective compliance time threshold is defined as the minimum time required for the process to maintain a stable state as specified in the physical operating condition rule parameter set.

8. The cloud-based construction project supervision quality acceptance and file management system according to claim 1, characterized in that, The cloud-based management and storage layer performs the following steps: After verification, the root key private key in the cloud is used to perform a digital signature on the field containing the device identifier, operation instructions and time information; The digital signature and the field are processed using a token generation formula to generate and issue the encrypted unlock token.

9. The cloud-based construction project supervision quality acceptance and file management system according to claim 1, characterized in that, The edge-aware control layer performs the following steps: Receive the encrypted unlock token and perform signature verification using the cloud public key; The encrypted unlock token is parsed using the interlock control state transition formula to determine the control signal state; The controller of the next process-related equipment is driven according to the state of the control signal.

10. The cloud-based construction project supervision quality acceptance and file management system according to claim 9, characterized in that, The edge-aware control layer performs the following steps: Monitor the status of the communication network and the current system time; When the communication network is in a fault state and the current system time exceeds the valid expiration time of the encryption unlock token, the control signal state is forcibly flipped according to the interlock control state transition formula. Based on the state of the control signal after the flip, the enable signal of the controller of the next process-related equipment is cut off.