A data encryption method and a marine radioactivity monitoring system
The data encryption method for oceanic buoys uses time-based sequencing, block division, and swapping techniques to enhance data security and transmission efficiency, addressing vulnerabilities in satellite communication.
Patent Information
- Application Number
- CN202210185456.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-28
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-02-28
AI Technical Summary
When marine radioactive buoys transmit data through Beidou satellites, data is easily stolen, resulting in insufficient data security and affecting the security of marine environmental monitoring and property losses.
Data encryption methods are adopted, including data difference, data inversion and data exchange processes, and different data sequences are formed using sampling time, and encrypted data is transmitted through Beidou satellites.
It improves the security and real-time nature of data transmission, reduces the possibility of data being stolen, ensures the timely and accurate marine environmental monitoring, and reduces system power consumption.
Smart Images

Figure CN114640987B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of marine environmental monitoring. Specifically, it relates to a Beidou data encryption method applicable to a marine radioactive monitoring system. Background Art
[0002] A marine radioactive buoy is a device used to monitor radionuclides in seawater. During its use, since the buoy is usually deployed in the open sea where there is no network for data communication, it is necessary to transmit the radioactive data monitored by the buoy to the monitoring center on the shore via Beidou satellites to meet the long-term monitoring requirements of staff for the marine environment.
[0003] The actual marine on-site monitoring environment is complex and changeable. This communication method of using Beidou satellites to transmit radioactive data has the problem that the data is easily deliberately stolen during communication. If the content can be easily cracked after the data is stolen, it will seriously affect the data security of the seawater radioactive buoy and cause huge property losses. Therefore, on the basis of ensuring the availability of Beidou data, encrypting the data before transmission is an effective method to improve data security and is also the core of the current development of domestic marine radioactive measurement technology. Summary of the Invention
[0004] The purpose of the present invention is to provide a data encryption method to improve the security of data transmission.
[0005] To solve the above technical problems, the present invention is implemented by adopting the following technical solutions:
[0006] In one aspect, the present invention proposes a data encryption method. The data is data with sampling time, and different data sequences are formed according to different sampling times. The data encryption method includes a data swapping process, and the data swapping process includes:
[0007] Extract the sampling time of the data sequence and calculate the sum T of the time components;
[0008] Taking T as the data block capacity, divide the data sequence into M data blocks;
[0009] After swapping the data in two adjacent data blocks, form an encrypted data sequence.
[0010] In some embodiments of the present application, if M is an odd number, there will be a situation where the last data block has no data block to pair and swap with. To improve the security of data transmission, it is preferably to swap the positions of each data in the last data block in the way of head-to-tail mirror swapping, so that each data in the data sequence has its position changed, thereby increasing the difficulty of cracking the data after it is stolen.
[0011] In some embodiments of the present application, if M is an even number and the number of data in the last data block is less than T, all the data in the last two data blocks can be swapped in position in a head-to-tail mirror image exchange manner to increase the cracking difficulty.
[0012] In some embodiments of the present application, the time component may only include year, month, day, hour, and minute to speed up the data encryption speed and improve the real-time performance of data transmission.
[0013] In some embodiments of the present application, in order to speed up the data transmission speed and reduce the possibility of data being stolen during transmission, a data difference process can be performed before the data exchange process. The data difference process includes:
[0014] In the data sequence, each data occupies four bytes, and the first data can be recorded with two bytes;
[0015] Starting from the second data, calculate the difference between each data and the previous data in turn to form a difference sequence;
[0016] If the absolute value of a certain difference in the difference sequence exceeds 65535, perform smoothing filtering on all the data in the data sequence, and then perform the above difference calculation process;
[0017] Perform one or more times of smoothing filtering on all the data in the data sequence until the absolute values of all differences in the difference sequence are less than 65535;
[0018] Record the first data in the data sequence and all the differences in the difference sequence in sequence in a way that one bit is used to record positive and negative and two bytes are used to record the value, forming a difference sequence for the above data exchange process, which can shorten the execution time of the data exchange process and improve the data encryption speed.
[0019] In some embodiments of the present application, for the case where the data in the data sequence is sampling data collected by a sensor, the smoothing filtering preferably adopts a five-point smoothing filtering method, and its calculation formula is:
[0020] u(i)=[-3×v(i - 2)+12×v(i - 1)+17×v(i)+12×v(i + 1)+(-3)×v(i + 2)] / 35;
[0021] Among them, v(i) represents the value of the i-th data in the data sequence, where i = 3, 4, ……, N - 2, and N is the total number of data in the data sequence; u(i) represents the value of v(i) after smoothing. Since the sampled data collected by the sensor may drift, the drifting channels are generally the data of 1 - 2 channels. If there is abnormal data at a certain point, it is very likely that the abnormal data is generated by the superposition of the data within the left and right two channels, and the contribution of the middle data is large, while the contribution of the data on both sides is small. If the five-point smoothing filter method is used to process the sampled data, the middle data and the data of the two channels on the left and right can be weighted and averaged, so as to achieve the purpose of eliminating the influence of data drift.
[0022] In some embodiments of the present application, in order to further improve the encryption complexity, all the data in the difference sequence can be represented in binary, and after inverting the binary value of each byte, a data sequence for the data exchange process is formed, so as to further increase the difficulty of data cracking.
[0023] In another aspect, the present invention also proposes an ocean radioactivity monitoring system, including a buoy, on which sensors, a data processor, and a Beidou communication module are arranged; among them, the sensor is used to measure the radionuclides in seawater and generate sampled data; the data processor receives the sampled data, forms different data sequences according to different sampling times, and then encrypts the data sequences to generate encrypted data sequences; the Beidou communication module establishes communication with Beidou satellites and sends the encrypted data sequences to the monitoring center on the shore through Beidou satellites. The data encryption method executed by the data processor includes a data exchange process, and the data exchange process includes: extracting the sampling time of the data sequence, calculating the sum T of the time components; taking T as the data block capacity, dividing the data sequence into M data blocks; after exchanging the data in two adjacent data blocks, an encrypted data sequence is formed.
[0024] Compared with the prior art, the advantages and positive effects of the present invention are at least reflected in the following aspects:
[0025] (1) The data encryption method of the present invention includes various processes such as data difference, data inversion, and data exchange, which increases the difficulty of data cracking with diverse encryption means, thereby enhancing the security of data transmission.
[0026] (2) The present invention performs difference processing on the data sequence to be encrypted, which can shorten the overall length of the data sequence, thereby accelerating the data transmission speed, reducing the difficulty and possibility of data being deliberately stolen during the transmission process, and can reduce the probability of data transmission failure caused by environmental interference during the transmission process. Furthermore, it can reduce the number of data retransmissions, improve the data sending efficiency, and reduce the system power consumption.
[0027] (3) In the data exchange process of the present invention, the sampling time of the data is used to determine the exchange positions of the data in the data sequence. Since the sampling times of each data sequence are different, the encryption methods are different. That is to say, the data encryption method each time is variable with the sampling time, which increases the variability and flexibility of the data encryption method. Compared with the encryption method in which all data sequences perform data exchange in a fixed order, it will undoubtedly double the difficulty of data cracking, thereby ensuring data security.
[0028] (4) The data encryption method of the present invention does not involve complex calculations, has a fast encryption speed, and can ensure the real-time performance of sampling data transmission.
[0029] (5) Applying the data encryption method of the present invention to the marine radioactivity monitoring system for Beidou satellite communication of the radioactive data collected by the marine buoy can not only ensure the security of long-distance transmission of radioactive data and reduce property losses caused by malicious data theft, but also ensure that the monitoring center on the shore can obtain the real situation of radioactive nuclides in seawater in real time and accurately, and realize timely and accurate early warning of changes in the marine environment.
[0030] After reading the detailed description of the embodiments of the present invention in conjunction with the drawings, other features and advantages of the present invention will become clearer. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0032] Figure 1 It is the overall architecture diagram of an embodiment of the marine radioactivity system proposed by the present invention;
[0033] Figure 2 It is the overall flowchart of an embodiment of the data encryption method proposed by the present invention;
[0034] Figure 3 is Figure 2 The data processing flowchart of an embodiment of the data successive difference process in;
[0035] Figure 4 is Figure 2 The data processing flowchart of an embodiment of the data exchange process in;
[0036] Figure 5 It is the curve diagram of a set of radioactive sampling data collected by the marine radioactivity buoy;
[0037] Figure 6 is the curve graph after the first-order difference calculation is performed on the sampling data in Figure 5 ;
[0038] Figure 7 is the curve graph after the five-point smoothing filtering process is performed on the sampling data in Figure 5 ;
[0039] Figure 8 is the curve graph after the difference calculation is performed on the data after the five-point smoothing filtering process in Figure 7 ;
[0040] Figure 9 is the curve graph after the inversion is performed on the difference data in Figure 8 ;
[0041] Figure 10 is the curve graph after the data swapping process is performed on the inverted difference data in Figure 9 ; Specific Embodiment
[0042] The following describes the specific embodiments of the present invention in detail with reference to the accompanying drawings.
[0043] The data encryption method of this embodiment designs a method for data with sampling time, and different encryption rules can be formulated according to different sampling times, thereby effectively improving the diversity and flexibility of the data encryption process, increasing the cracking difficulty after data theft, and ensuring data security.
[0044] This embodiment is described by taking the marine radioactivity monitoring system as an example. Refer to Figure 1 . In the marine radioactivity monitoring system of this embodiment, a buoy is configured, and the buoy is a large buoy suitable for the open sea environment. Various types of sensors, data processors, Beidou communication modules and other main components are provided on the buoy. Among them, the sensor for measuring radionuclides in seawater usually generates sampling data where each data occupies four bytes. For example, 1024 data will occupy 4096 bytes. The data of the start channel is relatively small at first, and then the energy spectrum value gradually increases. If there are radionuclides, the energy spectrum value may exceed two bytes and has the shape of a peak. If there are multiple radionuclides, there may be multiple peaks. However, each time the Beidou satellite communication method is used for transmission, only 78 bytes can be transmitted. Therefore, for radioactive data, a relatively long data transmission time is required, and there is a possibility that the data is easily stolen during the transmission process. Therefore, before the marine buoy transmits radioactive data through the Beidou satellite, encrypting the radioactive data collected by the sensor before transmission is the key to ensuring data security.
[0045] In this embodiment, a data encryption method is designed according to the characteristics of the sampled data, and a corresponding application program is written into the data processor on the buoy. After receiving the sampled data output by the sensor, the data processor runs the encryption program to encrypt the sampled data, and then sends it to the Beidou communication module. A communication link with the Beidou satellite is established through the Beidou communication module, and then the encrypted data is sent to the monitoring center on the shore. After receiving the encrypted data, the monitoring center performs reverse and opposite processing on the data according to the known encryption rules to complete data decryption, and realizes real-time, long-term, and remote monitoring of the marine environment based on the obtained data content.
[0046] See Figure 2 , the data encryption method of this embodiment mainly includes three processes: data successive difference process S100, data bitwise inversion process S200, and data swapping process S300.
[0047] Among them, the data successive difference process S100 can not only change the value of the original data to achieve its encryption, but also shorten the overall length of the data sequence and reduce the data transmission time. By accelerating the data transmission speed and shortening the data transmission time, the possibility of data being stolen during transmission can be reduced from another level, thereby achieving the purpose of ensuring data security.
[0048] As Figure 3 shown, the data successive difference process S100 of this embodiment mainly includes the following steps:
[0049] S101. Form different data sequences for the sampled data according to different sampling times.
[0050] In this embodiment, the data in each data sequence has the same sampling time, which can be accurate to seconds, minutes or hours, that is, the sampled data within a period of time. These original data each occupy four bytes, and each original data is an unsigned integer data. Moreover, the value of the first original data in the sequence is relatively small (in line with the actual situation of the data collected by the radioactive sensor), and two bytes can be used to record it.
[0051] This embodiment takes the data sequence containing 1024 data as an example for illustration, as Figure 5 shown. These 1024 data have the same sampling time, and the sampling time is accurate to minutes. For example, it can be the data collected by the radioactive sensor within 1 minute. Figure 5 The shown data curve graph, the abscissa represents the number of the data in the sequence, and the ordinate represents the value. As Figure 5 can be seen, the first data is 0, and two bytes can be used to record it.
[0052] S102. Starting from the second data, calculate the difference between each data and the previous data in turn to form a difference sequence.
[0053] In this embodiment, starting from the second data in the data sequence, traverse to the last data at a time, calculate the difference between each data and the previous data, that is, obtain N - 1 differences to form a difference sequence, as Figure 6 shown. Here, N represents the total number of data in the data sequence.
[0054] S103. Traverse all the differences in the difference sequence, and determine whether there is a difference whose absolute value exceeds 65535. If so, execute step 104; if not, execute step 105.
[0055] The value 65535 is the maximum value that two bytes can store. If it exceeds 65535, it means that the difference between the previous and the next data is too large, and it is very likely that there are abnormal data or data drift. At this time, it is necessary to perform smoothing filtering on the original data in the sequence to eliminate the interference effect.
[0056] S104. Perform smoothing filtering on the original data, and then return to step S102.
[0057] In this embodiment, if it is necessary to perform smoothing filtering on the data multiple times, the data for the first smoothing filtering is the original data in the data sequence, and the original data for subsequent smoothing filtering is the value obtained after the previous smoothing filtering.
[0058] As a preferred embodiment, for the case where the original data in the data sequence is sampling data collected by a sensor, the five - point smoothing filtering method can be used to filter the sampling data, and its calculation formula is:
[0059] u(i)=[-3×v(i - 2)+12×v(i - 1)+17×v(i)+12×v(i + 1)+(-3)×v(i + 2)] / 35;
[0060] In the formula, v(i) represents the value of the i - th data in the data sequence, and i = 3, 4, ……, N - 2, that is, traverse from the third data to the third - last data, and substitute into the above smoothing filtering formula in turn for data filtering; u(i) represents the value of v(i) after smoothing.
[0061] Since the sampled data collected by the sensor may drift, and the drifted channels are generally the data of 1 to 2 channels. If abnormal data appears at a certain point, it is very likely that the abnormal data is generated by the superposition of the data within the left and right two channels, and the contribution of the middle data is large, while the contribution of the data on both sides is small. If the five-point smoothing filter method is used to process the sampled data, the middle data can be weighted-averaged with the data of the left and right two channels respectively, so as to achieve the purpose of eliminating the influence of data drift.
[0062] Figure 7 The data curve shown is for Figure 5 The data curve shown after five-point smoothing filtering process.
[0063] S105. Use the first data in the data sequence and all the differences in the difference sequence to form a successive difference sequence.
[0064] After the absolute values of all the differences in the difference sequence are less than 65535, as Figure 8 shown, the first data in the data sequence and all the differences in the difference sequence can be used to form a successive difference sequence for the subsequent data inversion process S200.
[0065] For example, if the original data is 1024, and each data occupies four bytes, then a total of 1024 * 4 = 4096 bytes are required. After performing the above data successive difference process, each data only needs to occupy two bytes, so 1024 * 2 = 2048 bytes are required. Then, assign a bit to each successive difference data to record the positive and negative, which requires 1024 bits, that is, 1024 / 8 = 128 bytes. In this way, the successive difference sequence only needs to occupy 2048 + 128 = 2176 bytes, and the data compression rate can reach about 53% (that is, 2176 / 4096 = 53.125%).
[0066] The data encryption method of this embodiment designs the data successive difference process. On the one hand, it encrypts the Beidou data; on the other hand, it can effectively shorten the length of the data sequence and improve the data transmission speed on the basis of ensuring the data availability, solves the problem that the Beidou data is easy to be lost during the operation of the buoy in the far sea, and avoids the system power consumption caused by the need to retransmit the data due to loss.
[0067] In order to further increase the cracking difficulty of the encrypted data, this embodiment also designs a data inversion process S200 in the data encryption method, that is, invert all the data in the successive difference sequence. The specific process is as follows: represent each data in the successive difference sequence in the form of a binary number, and invert the binary value in each byte, that is, change each bit data in each byte from 1 to 0 and from 0 to 1, as Figure 9As shown, an inverse code data sequence is formed for use in the subsequent data exchange process S300.
[0068] In the data exchange process S300 of this embodiment, to increase the difficulty of cracking encrypted data, the sampling time of each data in the data sequence is used to calculate the exchange position of the data. Since different data sequences have completely different sampling times for their data, this enables each data sequence to have different data exchange rules. Compared with traditional positioning exchange rules, this is obviously more random and confusing. Even if the encrypted data is stolen, it is very difficult to discover the transposition rule and crack the data. Therefore, using the data exchange method of this embodiment to encrypt the sampled data can greatly enhance the security of the data.
[0069] The following combines Figure 4 , and specifically elaborates on the main steps involved in the data exchange process S300 of this embodiment:
[0070] S301. Extract the sampling time of the data sequence and calculate the sum T of the time components.
[0071] In this embodiment, the time components include year, month, day, hour, minute, and second. When calculating the sum T of the time components, all or part of the values of the time components can be selected for addition to obtain the T.
[0072] This embodiment takes the selection of the five time components of year, month, day, hour, and minute as an example to calculate the sum T of the time components to obtain a positive integer. That is, assuming that in a data sequence, the sampling time of the data is 8:00 on December 2, 2021, then the sum T of the time components = 21 + 12 + 2 + 8 + 0 = 43.
[0073] S302. Divide the data sequence into M data blocks with T as the data block capacity.
[0074] Taking the data sequence containing N data as an example for illustration, then M = N / T, and when N / T cannot be divided evenly, M is equal to the integer part of N / T plus 1.
[0075] For example, if the data sequence contains 1024 data, that is, N = 1024, T = 43, then M = 1024 / 43 = 24, that is, with 43 as the data block capacity, the data sequence is divided into 24 data blocks.
[0076] S303. Determine the data exchange position.
[0077] If M is odd, for the first M - 1 data blocks, the data in adjacent two data blocks can be encrypted by swapping their positions. For example, the first data in the first data block can be swapped with the first data in the second data block, the second data in the first data block can be swapped with the second data in the second data block, and so on, until the T-th data in the first data block is swapped with the T-th data in the second data block. Similarly, each data in the third data block is swapped with the corresponding data in the fourth data block, and so on, until the data in the (M - 2)-th data block and the data in the (M - 1)-th data block are swapped bit by bit. For the M-th data block, since there is no data block to swap with, the data in the M-th data block can be rearranged by swapping the data at the head and the tail in a mirror image manner. That is, the first data in the M-th data block is swapped with the last data in the M-th data block, the second data in the M-th data block is swapped with the second last data in the M-th data block, and so on.
[0078] If M is even and the number of data in the last data block is less than T, for the first M - 2 data blocks, the data in adjacent two data blocks can be encrypted by swapping their positions. For the data in the last two data blocks, since the number of data in the two data blocks is not equal, the data in the last two data blocks can be rearranged by swapping the data at the head and the tail in a mirror image manner. That is, the first data in the (M - 1)-th data block is swapped with the last data in the M-th data block, the second data in the (M - 1)-th data block is swapped with the second last data in the M-th data block, and so on.
[0079] If M is even and the number of data in each data block is T, the data in adjacent two data blocks can be directly encrypted by swapping their positions.
[0080] For example, if the data sequence contains 1024 data and T = 43, the data sequence is divided into 24 data blocks, and the 24th data block contains only 35 data. The data in the first 22 data blocks are encrypted by swapping the data in adjacent two data blocks, that is, the data in the 1st and 2nd data blocks are swapped, such as DATA[0] and DATA
[43] are swapped, ……, DATA
[42] and DATA
[85] are swapped; the data in the 3rd and 4th data blocks are swapped; ……; the data in the 21st and 22nd data blocks are swapped. The 43 data in the 23rd data block and the 35 data in the 24th data block are swapped in the head and tail mirror image manner to swap the position of each data, such as replacing the data DATA
[946] to DATA
[1023] with DATA
[1023] to DATA
[946] , so as to determine the swapped position of each data in the data sequence. The data curve after the position swap is as Figure 10 shown.
[0081] S304. Swap the positions of the data in the data sequence to form an encrypted data sequence.
[0082] After swapping the positions of all the data in the data sequence, the encryption process is completed, and an encrypted data sequence is formed for transmission.
[0083] In this embodiment, all data are completed according to the rule transformation, and the decryption process can be completed according to the inverse operation of the encryption process to restore the data content.
[0084] The data encryption method of this embodiment has a fast encryption speed, no complex calculations, simple program writing, and is easy to implement. After encrypting the sampling data generated by the ocean buoy by using the encryption method of this embodiment and then performing Beidou satellite transmission, it is not restricted by the position where the ocean buoy is located, nor by the interference of the ocean environment, and can complete the safe and complete transmission of the encrypted data within an effective time, reducing the risk and power consumption of the ocean radioactivity monitoring system.
[0085] Certainly, the above is only a preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A data encryption method, wherein the data is radionuclide sampling data with sampling time, and different data sequences are formed according to different sampling times; characterized in that, Including: Data successive difference process: In the said data sequence, each data occupies four bytes; Starting from the second data, calculate the difference between each data and the previous data in turn to form a difference sequence; If the absolute value of a certain difference in the difference sequence exceeds 65535, perform smoothing filtering on all the data in the data sequence, and then execute the previous difference calculation process; Perform one or more times of smoothing filtering on all the data in the data sequence until the absolute values of all differences in the difference sequence are less than 65535; Record the first data in the data sequence and all the differences in the difference sequence in sequence in the way of using one bit to record positive or negative and two bytes to record the value to form a successive difference sequence for the data exchange process; The said data exchange process determines the exchange positions of the data in the data sequence by using the sampling time of the data, so that the data encryption method varies with the sampling time each time. It includes: Extract the sampling time of the data sequence and calculate the sum T of the time components. The time components include year, month, day, hour, and minute; Taking T as the data block capacity, divide the successive difference sequence into M data blocks; exchange the data in two adjacent data blocks; If the said M is odd, exchange the positions of each data in the data block in the way of head-tail mirror image exchange for the data in the last data block; If the said M is even and the number of data in the last data block is less than T, exchange the positions of each data in the way of head-tail mirror image exchange for all the data in the last two data blocks; Form an encrypted data sequence; Transmit the encrypted data sequence through Beidou satellite.
2. The data encryption method according to claim 1, characterized in that, The said smoothing filtering is five-point smoothing filtering, and its calculation method is: u(i)=[-3×v(i - 2)+12×v(i - 1)+17×v(i)+12×v(i + 1)+(-3)×v(i + 2)] / 35; Wherein, v(i) represents the value of the i-th data in the data sequence, i = 3, 4,..., N - 2, and N is the total number of data in the data sequence; u(i) represents the value of v(i) after smoothing.
3. The data encryption method according to claim 1 or 2, characterized in that Perform binary representation on all the data in the successive difference sequence, and invert the binary value of each byte to form a data sequence for the data exchange process.
4. An ocean radioactive monitoring system, comprising a buoy; characterized in that, On the said buoy, there are arranged: A sensor, which is used to measure the radionuclide in seawater and generate sampling data; A data processor, which receives the said sampling data, forms different data sequences according to different sampling times, and executes the data encryption method as described in any one of claims 1 to 3 to encrypt the data sequence to generate an encrypted data sequence; A Beidou communication module, which establishes communication with Beidou satellite and sends the encrypted data sequence to the monitoring center on the shore through Beidou satellite.
Citation Information
Patent Citations
Data encryption communication method
CN108243001A
Distance estimation method and system for suppressing complex indoor RSSI fluctuation
CN113296052A
Robust smooth filtering method, system and device and storage medium
CN113569686A
Data encryption method, data decryption method, data encryption device, data decryption device, equipment, and medium
CN113761554A