Data transmission method and device, and quantitative loading method and device

By using encryption keys to encrypt and decrypt loading data between the information network and the control network, the problem of data transmission under physical isolation is solved, enabling fast and secure data transmission of loading operations, and improving loading efficiency and data transmission accuracy.

CN116248383BActive Publication Date: 2026-07-31SUPCON TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SUPCON TECH CO LTD
Filing Date
2023-02-23
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

In industrial control systems, there is a physical isolation between the information network and the control network, which makes it impossible to effectively transmit loading business data. Existing manual loading methods are inefficient and prone to errors.

Method used

The loading data is encrypted using an encryption key in the upstream system of the information network and entered into a target carrier (such as a QR code or smart card). The data is then transmitted to the downstream system of the control network for decryption and loading execution.

Benefits of technology

It enables rapid data transfer between the information network and the control network, improves loading efficiency, avoids errors caused by manual operation, and ensures the security and accuracy of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116248383B_ABST
    Figure CN116248383B_ABST
Patent Text Reader

Abstract

This application discloses a data transmission method and apparatus, and a quantitative loading method and apparatus. The method includes: acquiring first loading service data and a first encryption key from an upstream system within an information network; encrypting the first loading service data using the first encryption key to obtain first ciphertext data; inputting the first ciphertext data into a target carrier, and transmitting the first ciphertext data to a downstream system within a control network via the target carrier; the downstream system receiving the target carrier, wherein the target carrier further includes second ciphertext data corresponding to a first decryption key; determining a first decryption key based on the second ciphertext data, and decrypting the first ciphertext data using the first decryption key to obtain first plaintext data; and executing a first loading service based on the first plaintext data. This application solves the technical problem in related technologies where loading service data cannot be transmitted between an information network and a control network when there is physical isolation between them.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and more specifically, to a data transmission method and apparatus, and a quantitative loading method and apparatus. Background Technology

[0002] In recent years, with the continuous expansion of attack methods and target ranges by cyber attackers, computer system vulnerabilities have become frequent, and the cybersecurity situation is far from optimistic. Therefore, network boundary security is particularly important in industrial control systems. Typically, in industrial control systems, to prevent intrusions from external networks and non-critical internal networks into critical network areas, it is necessary to restrict and monitor unauthorized connections of devices to the internal network and unauthorized connections of internal users to external networks. However, the aforementioned methods of monitoring and controlling area communications cannot completely eliminate the risk of network intrusion.

[0003] When enterprises set up physical isolation between information networks and control networks, the relevant loading schemes are mainly set up manually on batch controllers or configuration software. However, the drawback of this method is that manual operation is cumbersome and inefficient, and it cannot pass strict system verification.

[0004] There is currently no effective solution to the above problems. Summary of the Invention

[0005] This application provides a data transmission method and apparatus, and a quantitative loading method and apparatus, to at least solve the technical problem that loading business data cannot be transmitted between the information network and the control network when there is physical isolation between the information network and the control network.

[0006] According to one aspect of the embodiments of this application, a data transmission method is provided, applied to an upstream system within an information network, comprising: acquiring first loading business data and a first encryption key generated by the upstream system; encrypting the first loading business data using the first encryption key to obtain first ciphertext data; recording the first ciphertext data into a target carrier, and transmitting the first ciphertext data to a downstream system through the target carrier, wherein the downstream system is located within a control network physically isolated from the information network, and the downstream system is used to execute quantitative loading business.

[0007] Optionally, the first loading business data in the upstream system is obtained, including: obtaining the first loading business in the upstream system and determining the first loading business data corresponding to the first loading business, wherein the first loading business data includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category.

[0008] Optionally, before encrypting the first loading business data using the first encryption key, the method further includes: compressing the first loading business data.

[0009] Optionally, before transmitting the first encrypted data to the downstream system via the target carrier, the method further includes: obtaining a first decryption key generated by the upstream system, and using the first decryption key to decrypt the first encrypted data in the target carrier to obtain first decrypted data; determining whether the carrier information of the target carrier is incorrect based on the first loading service data and the first decrypted data; if the first loading service data and the first decrypted data are consistent, determining that the carrier information is correct; if the first loading service data and the first decrypted data are inconsistent, determining that the carrier information is incorrect.

[0010] Optionally, after obtaining the first decrypted data, the method further includes: performing a decompression operation on the first decrypted data.

[0011] Optionally, after obtaining the first decryption key generated by the upstream system, the method further includes: obtaining the second encryption key used by the upstream system to encrypt the second loading business data, wherein the second loading business data is used to represent the business data corresponding to the previous loading business of the first loading business; encrypting the first decryption key with the second encryption key to obtain the second ciphertext data; recording the second ciphertext data into a target carrier, and transmitting the second ciphertext data to the downstream system through the target carrier.

[0012] Optionally, the first loading business data may also include: a first duration, wherein the first duration is used to reflect the effective duration of the first encrypted data within the target carrier.

[0013] Optionally, the target carrier includes a QR code and a smart card, wherein when the target carrier is a QR code, the first vehicle loading business data is entered into the QR code; when the target carrier is a smart card, the first vehicle loading business data is entered into the smart card.

[0014] According to another aspect of the embodiments of this application, a quantitative loading method is also provided, applied to a downstream system within a control network, comprising: receiving a target carrier transmitted from an upstream system, wherein the upstream system is located in an information network physically isolated from the control network, and the upstream system is used to generate loading service data, the target carrier including: first ciphertext data corresponding to the first loading service data and second ciphertext data corresponding to a first decryption key; determining a first decryption key based on the second ciphertext data, and using the first decryption key to decrypt the first ciphertext data in the target carrier to obtain first plaintext data; and performing a first loading service based on the first plaintext data.

[0015] Optionally, determining the first decryption key based on the second encrypted data includes: obtaining the second decryption key used by the downstream system to decrypt the second loading service data, wherein the second loading service data is used to represent the service data corresponding to the previous loading service of the first loading service; performing a decryption operation on the second encrypted data in the target carrier using the second decryption key to obtain the second decrypted data; and determining the first decryption key based on the second decrypted data.

[0016] Optionally, the first encrypted data in the target carrier is decrypted using the first decryption key to obtain the first plaintext data, including: the first encrypted data in the target carrier is decrypted using the first decryption key to obtain the first plaintext data, wherein the first plaintext data includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category.

[0017] Optionally, the first plaintext data may further include: a first duration, wherein the first duration is used to reflect the effective duration of the first ciphertext data within the target carrier.

[0018] Optionally, before performing the loading operation based on the first plaintext data, the method further includes: determining a second duration for which the downstream system obtains the first plaintext data, and a second crane position number when the downstream system performs the first loading operation; if the second duration does not exceed the first duration, and the second crane position number is the same as the first crane position number, the first plaintext data is determined to be correct; if the second duration exceeds the first duration, and / or the second crane position number is different from the first crane position number, the first plaintext data is determined to be incorrect.

[0019] According to another aspect of the embodiments of this application, a data transmission apparatus is also provided, applied to an upstream system within an information network, comprising: an acquisition module for acquiring first loading business data and a first encryption key generated by the upstream system; an encryption module for encrypting the first loading business data using the first encryption key to obtain first ciphertext data; and a transmission module for inputting the first ciphertext data into a target carrier and transmitting the first ciphertext data to a downstream system via the target carrier, wherein the downstream system is located within a control network physically isolated from the information network, and the downstream system is used to execute quantitative loading business.

[0020] According to another aspect of the embodiments of this application, a quantitative loading device is also provided, applied to a downstream system within a control network, comprising: a receiving module for receiving a target carrier transmitted from an upstream system, wherein the upstream system is located within an information network physically isolated from the control network, and the upstream system is used to generate loading business data, the target carrier including: first ciphertext data corresponding to the first loading business data and second ciphertext data corresponding to a first decryption key; a decryption module for determining a first decryption key based on the second ciphertext data, and using the first decryption key to decrypt the first ciphertext data in the target carrier to obtain first plaintext data; and an execution module for executing a first loading business based on the first plaintext data.

[0021] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored program, wherein the device where the non-volatile storage medium is located executes the above-described data transmission method or quantitative loading method by running the program.

[0022] According to another aspect of the embodiments of this application, an electronic device is also provided, the electronic device including: a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the above-described data transmission method or quantitative loading method through the computer program.

[0023] In this embodiment, first loading business data and a first encryption key generated by the upstream system are obtained; the first encryption key is used to encrypt the first loading business data to obtain first ciphertext data; the first ciphertext data is entered into a target carrier and transmitted to a downstream system via the target carrier. The downstream system is located within a control network physically isolated from the information network and is used to execute quantitative loading operations. This enables the rapid distribution of loading business data to the loading system even when there is physical isolation between the information network and the control network, improving loading efficiency. It also effectively avoids loading errors caused by manual setting of loading quantities on batch controllers or configuration software, thus solving the technical problem of being unable to transmit loading business data between the information network and the control network when there is physical isolation between them. Attached Figure Description

[0024] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0025] Figure 1 This is a hardware structure block diagram of an optional computer terminal for implementing a data transmission method according to an embodiment of this application;

[0026] Figure 2 This is a flowchart of an optional data transmission method according to an embodiment of this application;

[0027] Figure 3 This is a schematic diagram of an optional vehicle loading system according to an embodiment of this application;

[0028] Figure 4 This is a flowchart of an optional method for verifying the carrier information of a target carrier according to an embodiment of this application;

[0029] Figure 5 This is a flowchart of an optional decryption key transmission according to an embodiment of this application;

[0030] Figure 6 This is a flowchart of an optional quantitative loading method according to an embodiment of this application;

[0031] Figure 7 This is a flowchart of an optional verification of first plaintext data according to an embodiment of this application;

[0032] Figure 8 This is a schematic diagram of an optional data transmission device according to an embodiment of this application;

[0033] Figure 9 This is a schematic diagram of an optional quantitative loading device according to an embodiment of this application. Detailed Implementation

[0034] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0035] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0036] To better understand the embodiments of this application, the technical terms involved in the embodiments of this application are explained below:

[0037] Information network: refers to the local area network where upstream business systems and office staff computers are located, some of which can access the external network.

[0038] Control network: refers to the local area network where industrial control systems such as DCS (Distributed Control System), SIS (Safety Interlocking System), and PLC (Programmable Logic Controller) are located, and they are not allowed to access the external network.

[0039] Batch loading controller (hereinafter referred to as batch controller) is the lower-level machine of the liquid / gas quantitative loading control system. It boasts advantages such as flexible structure, wide application range, ease of setup and control, and user-friendly interface, enabling fast, safe, accurate, and scientific quantitative loading. Simultaneously, the batch controller can accurately transmit loading records and real-time system data to the upper-level computer via a communication network, utilizing management software for data storage, processing, analysis, statistics, and report printing.

[0040] Example 1

[0041] Currently, when there is physical isolation between an enterprise's information network and control network, preventing them from communicating with each other, the existing loading solution, which involves manually setting quantitative loading on the batch controller or configuration software, has the drawbacks of being cumbersome, inefficient, and prone to errors.

[0042] To address this issue, relevant solutions are provided in the embodiments of this application, which are described in detail below.

[0043] According to an embodiment of this application, an embodiment of a data transmission method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0044] The methods and embodiments provided in this application can be executed on mobile terminals, computer terminals, or similar computing devices. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a data transmission method is shown. Figure 1As shown, the computer terminal 10 (or mobile device 10) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) 102 (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0045] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in the embodiments of this application, the data processing circuits serve as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0046] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data transmission method in the embodiments of this application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby realizing the above-mentioned data transmission method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0047] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0048] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0049] Under the aforementioned operating environment, this application provides a data transmission method applied to an upstream system within an information network. Figure 2 This is a flowchart of an optional data transmission method according to an embodiment of this application, such as... Figure 2 As shown, the method includes at least steps S102-S106, wherein:

[0050] Step S102: Obtain the first loading business data from the upstream system and the first encryption key generated by the upstream system.

[0051] In the technical solution provided by step S102 of the present invention, during the quantitative loading and unloading of petrochemical liquid products, in order to improve the operational efficiency of the automatic quantitative loading system, first loading business data from the upstream system can be obtained. The upstream system can be a metering system, ERP (Enterprise Resource Planning), logistics system, or document generation software, etc., which generates source data for operational orders. Furthermore, the upstream system can generate key pairs using an asymmetric encryption algorithm. Each key pair includes a public key and a private key, and the public and private keys are a pair. If the public key is used to encrypt the data, it can only be decrypted using the corresponding private key. Since the encryption and decryption keys are generated by the upstream system in this application, the first encryption key generated by the upstream system in this embodiment is a private key.

[0052] For example, Figure 3 This is a schematic diagram of an optional loading system according to an embodiment of this application, wherein, Figure 3 The upstream systems include: QR code printers, metering servers, etc.

[0053] As an optional implementation, in the technical solution provided by step S102 of the present invention, the method may include: obtaining the first loading business in the upstream system and determining the first loading business data corresponding to the first loading business, wherein the first loading business data includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category.

[0054] In this embodiment, by acquiring the first loading business generated by the upstream system and determining the corresponding first loading business data, the downstream system can quickly and safely complete the quantitative loading operation according to the first loading business data. Specifically, the first loading business data includes: a business order number (usually composed of letters and numbers); a vehicle license plate number (usually composed of letters, numbers, and Chinese characters); a first loading arm position number (usually a number representing the location of the loading / unloading riser); a material code (usually a number representing the unique identifier of the loaded / unloaded product); a planned quantity (usually a decimal place); and a unit of measurement (usually a letter representing the unit of measurement for the loading business).

[0055] Considering that loading business data has a certain time limit, in this embodiment of the application, the first loading business data may further include a first duration, wherein the first duration is used to reflect the effective duration of the first encrypted data in the target carrier. For example, if the loading business of a certain order needs to be completed within the same day, the first duration of the loading business data corresponding to the loading business can be set to 24 hours.

[0056] Step S104: Encrypt the first loading business data using the first encryption key to obtain the first ciphertext data.

[0057] In the technical solution provided by step S104 of the present invention, since the data needs to be transmitted with security and correctness in order to prevent external parties from easily reading and tampering with the transmitted business data, in this application, the first encryption key can be used to encrypt the first loading business data to obtain the first ciphertext data.

[0058] In addition, considering that the data stored in the target carrier is limited, and that the data will become larger after asymmetric encryption, or that the data may be used in situations such as trains and cars, the embodiments of this application may also compress the first loading business data before encrypting the first loading business data with the first encryption key.

[0059] Specifically, the first loading operation data can be encoded to compress the data length, or directly use its string form to reduce the number of bytes stored in the target carrier. In the embodiments of the present application, the encoding method and byte length of each point in the first loading operation data are specifically specified, as shown in Table 1.

[0060] Table 1

[0061]

[0062] Among them, the order number is of string type, which can be compressed using the ASCII encoding method and stored in 18 bytes; the license plate number is of string type, which can be encoded by looking up a table index. The table lookup index is defined as: "\00123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz-京津沪渝冀晋辽吉黑苏浙皖闽赣鲁豫鄂湘粤琼川贵云秦甘青藏桂蒙宁新陕甲乙丙己庚辛壬寅辰戍午未申兰沈济广成南北海空军消边通金电森警使挂学试", and it can be stored in eight bytes; the first crane position number and the material code are both of integer type, and each is stored in one byte; the planned quantity is of floating-point type, which can be stored in 4 bytes; since the number of enumerations of the measurement unit and the business type is small, the whole is stored in 1 byte; the format of the first duration is "yyMMddhhmmss". For the "year", only the last two digits need to be obtained. Therefore, each two digits can be converted into one byte, and a total of six bytes are used to store the first duration.

[0063] After converting the first loading operation data into a string as described above, the GZip compression algorithm with a high compression ratio and compression speed can be used to compress the encoded byte array to ensure that the compressed data is small; at the same time, the compression algorithm自带CRC (Cyclic Redundancy Check) check, so the data check can be omitted. Thus, without exposing the first encryption key, the first loading operation data cannot be tampered with during the transmission process, effectively ensuring the security of enterprise operations.

[0064] Step S106, enter the first ciphertext data into the target carrier, and transmit the first ciphertext data to the downstream system through the target carrier. Among them, the downstream system is in a control network physically isolated from the information network, and the downstream system is used to execute the quantitative loading operation.

[0065] Optionally, the target carrier includes but is not limited to: two-dimensional codes and smart cards. Among them, when the target carrier is a two-dimensional code, the first loading operation data is entered into the two-dimensional code; when the target carrier is a smart card, the first loading operation data is entered into the smart card.

[0066] As an optional implementation method, Figure 4 This is a flowchart of an optional verification of the carrier information of the target carrier according to an embodiment of this application. In order to ensure that the corresponding first loading service data can be obtained by decrypting the first encrypted data in the target carrier transmitted to the downstream system, before transmitting the first encrypted data to the downstream system through the target carrier, the carrier information in the target carrier can be detected according to the method of steps S1061-S1064 to determine whether it is correct (i.e., valid):

[0067] Step S1061: Obtain the first decryption key generated by the upstream system, and use the first decryption key to decrypt the first ciphertext data in the target carrier to obtain the first decrypted data.

[0068] The first decryption key is a public key generated by the upstream system. Therefore, the first ciphertext data obtained by encrypting the first loading business data with the private key (the first encryption key) can be decrypted using the public key to obtain the first decrypted data.

[0069] Optionally, after obtaining the first decrypted data, the first decrypted data can also be decompressed.

[0070] Specifically, if the amount of data in the first loading operation is large, it needs to be compressed before encryption. Therefore, after decrypting the first ciphertext data to obtain the first decrypted data, the first decrypted data can be decompressed accordingly. If the amount of data in the first loading operation is small, it can be directly encrypted. In this case, after decrypting the first ciphertext data using the first decryption key to obtain the first decrypted data, no further decompression is required.

[0071] Step S1062: Determine whether the carrier information of the target carrier is incorrect based on the first loading business data and the first decryption data.

[0072] Specifically, the first loading business data is matched with the first decrypted data to determine whether they are the same in order to verify whether the carrier information in the target carrier is incorrect.

[0073] Step S1063: If the first loading business data and the first decryption data are consistent, the carrier information is determined to be correct.

[0074] Step S1064: If the first loading service data and the first decryption data are inconsistent, determine that the carrier information is incorrect.

[0075] Furthermore, Figure 5This is a flowchart of an optional decryption key transmission according to an embodiment of this application. Considering that the decryption key in the downstream system is a unified key, improper management of the decryption key in the downstream system could lead to the loss or tampering of loading business data. Therefore, in this embodiment of the application, after obtaining the first decryption key generated by the upstream system, the decryption key in the downstream system can be updated according to steps S11-S13.

[0076] Step S11: Obtain the second encryption key used by the upstream system when encrypting the second loading business data;

[0077] Among them, the second loading business data is used to represent the business data corresponding to the previous loading business of the first loading business;

[0078] Step S12: Encrypt the first decryption key with the second encryption key to obtain the second ciphertext data;

[0079] Step S13: The second encrypted data is entered into the target carrier, and the second encrypted data is transmitted to the downstream system through the target carrier.

[0080] Specifically, the system can obtain the second encryption key generated by the upstream system during the last transmission and loading service, and encrypt the newly generated decryption key by the upstream system using the second encryption key to obtain the corresponding second ciphertext data. The second ciphertext data is then entered into the target device, and the second ciphertext data corresponding to the first decryption key is transmitted to the downstream system through the target device, thereby ensuring the security and reliability of the decryption key.

[0081] Similarly, each time the upstream system transmits the decryption key, it needs to be encrypted using the encryption key used in the previous encryption operation.

[0082] In this embodiment, first loading business data and a first encryption key generated by the upstream system are obtained; the first encryption key is used to encrypt the first loading business data to obtain first ciphertext data; the first ciphertext data is entered into a target carrier and transmitted to a downstream system via the target carrier. The downstream system is located within a control network physically isolated from the information network, and is used to execute quantitative loading operations. This enables the rapid distribution of loading business data to the loading system even when there is physical isolation between the information network and the control network, improving loading efficiency and solving the technical problem that related technologies cannot transmit loading business data between the information network and the control network when there is physical isolation.

[0083] Example 2

[0084] This application provides a quantitative loading method for downstream systems within a control network. Figure 6 This is a flowchart of an optional quantitative loading method according to an embodiment of this application, such as... Figure 6 As shown, the method includes at least steps S602-S606, wherein:

[0085] Step S602: Receive the target carrier transmitted from the upstream system, wherein the upstream system is located in an information network that is physically isolated from the control network, and the upstream system is used to generate loading service data. The target carrier includes: first ciphertext data corresponding to the first loading service data and second ciphertext data corresponding to the first decryption key.

[0086] In the technical solution provided in step S602 of the present invention, the upstream system can be a metering system, ERP (Enterprise Resource Planning), logistics system, or a work order source data generation system such as document processing software; the downstream system can be a loading system or a batch controller, wherein the batch controller is a quantitative loading and unloading controller, such as... Figure 3 In the diagram shown, the batch controller is connected to the engineering workstation, operator workstation, and OPC (OLE for Process Control) server via an industrial switch, and includes a scanning terminal. Additionally, the first encryption key generated in the upstream system encrypts the first loading business data in the upstream system and records it into the target carrier. Simultaneously, the first decryption key generated in the upstream system is also encrypted and recorded into the target carrier. Therefore, the target carrier includes the first ciphertext data corresponding to the first loading business data and the second ciphertext data corresponding to the first decryption key.

[0087] Step S604: Determine the first decryption key based on the second ciphertext data, and use the first decryption key to decrypt the first ciphertext data in the target carrier to obtain the first plaintext data.

[0088] In the technical solution provided by step S604 of the present invention, the first decryption key for decrypting the first ciphertext data can be determined based on the second ciphertext data corresponding to the first decryption key, thereby performing a decryption operation on the first ciphertext data in the target carrier through the first decryption key to obtain the corresponding first plaintext data.

[0089] As an optional implementation, in the technical solution provided in step S604 of the present invention, the method may include: using a first decryption key to decrypt the first ciphertext data in the target carrier to obtain the first plaintext data, wherein the first plaintext data includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category.

[0090] Optionally, the first plaintext data may further include: a first duration, wherein the first duration is used to reflect the effective duration of the first ciphertext data within the target carrier.

[0091] As another optional implementation, in the technical solution provided in step S604 of the present invention, the method may include: obtaining a second decryption key used by the downstream system to decrypt the second loading service data, wherein the second loading service data is used to represent the service data corresponding to the previous loading service of the first loading service; performing a decryption operation on the second ciphertext data in the target carrier using the second decryption key to obtain the second decrypted data; and determining a first decryption key based on the second decrypted data.

[0092] In this embodiment, the second decryption key used by the downstream system during the last transmission loading service is obtained, and the second ciphertext data corresponding to the first decryption key in the target carrier is decrypted using the second decryption key to obtain the second decrypted data, thereby obtaining the first decryption key.

[0093] It should be noted that if the upstream system compresses the first decryption key in the target carrier and then encrypts the first decryption key with the second encryption key, the downstream system will use the second decryption key to decrypt the second ciphertext data corresponding to the first decryption key. After obtaining the second decrypted data, the downstream system will need to decompress the second decrypted data in order to obtain the corresponding first decryption key.

[0094] Similarly, each time a downstream system obtains a decryption key, it needs to use the decryption key used in the previous decryption operation to decrypt the key.

[0095] Step S606: Execute the first loading operation based on the first plaintext data.

[0096] In the technical solution provided by step S606 of the present invention, the corresponding first loading business can be executed within the effective time according to the order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category in the first plaintext data.

[0097] As an optional implementation method, Figure 7 This is a flowchart of an optional verification of the first plaintext data according to an embodiment of this application. Before performing the corresponding first loading operation based on the first plaintext data, it can also be performed according to... Figure 7 Steps S6061-S6063 shown here verify the validity of the first plaintext data:

[0098] Step S6061: Determine the second duration for which the downstream system obtains the first plaintext data, and the second crane position number when the downstream system executes the first loading service.

[0099] Step S6062: If the second duration does not exceed the first duration and the second crane position number is the same as the first crane position number, then the first plaintext data is determined to be correct.

[0100] Step S6063: If the second duration exceeds the first duration, and / or the second crane position number is different from the first crane position number, it is determined that the first plaintext data is incorrect.

[0101] For example, the first duration in the first plaintext data is set to 24 hours, and the second crane position number when the downstream system executes the first loading service is 2-24. If the batch controller scans and identifies the target carrier and obtains the first plaintext data at a time of 32 hours, the first encrypted data corresponding to the first loading service data stored in the target carrier becomes invalid, thus making it impossible to obtain the corresponding first loading service data by identifying the target carrier through the batch controller. If the batch controller scans and identifies the target carrier and obtains the first plaintext data at a time of 14 hours, but the first crane position number obtained by identifying the first encrypted data in the target carrier is 1-10, then the second crane position number does not match the first crane position number, indicating that the first plaintext data is incorrect and the loading service cannot be executed according to the first plaintext data.

[0102] In this embodiment, a target carrier transmitted from an upstream system is received. The upstream system is located within an information network physically isolated from the control network and is used to generate loading service data. The target carrier includes: first encrypted data corresponding to the first loading service data and second encrypted data corresponding to a first decryption key. A first decryption key is determined based on the second encrypted data, and the first encrypted data within the target carrier is decrypted using the first decryption key to obtain first plaintext data. The corresponding first loading service is then executed based on the first plaintext data. This effectively avoids loading errors caused by manual setting of loading quantities on the batch controller or configuration software, thereby improving loading efficiency and security.

[0103] Example 3

[0104] According to an embodiment of this application, a data transmission apparatus for implementing the data transmission method of Embodiment 1 described above is also provided. Figure 8 This is a schematic diagram of an optional data transmission device according to an embodiment of this application, such as... Figure 8 As shown, the data transmission device includes at least: an acquisition module 81, an encryption module 82, and a transmission module 83, wherein:

[0105] The acquisition module 81 is used to acquire the first loading business data from the upstream system and the first encryption key generated by the upstream system.

[0106] Specifically, in the process of quantitative loading and unloading of petrochemical liquid products, in order to improve the operational efficiency of the automated quantitative loading system, the first loading business data from the upstream system can be obtained. The upstream system can be a data generation system for operational data sources such as metering systems, ERP systems, logistics systems, and document generation software. Furthermore, the upstream system can generate key pairs using an asymmetric encryption algorithm. Each key pair includes a public key and a private key, and these two keys are a pair. If the data is encrypted using the public key, it can only be decrypted using the corresponding private key. Since the encryption and decryption keys are generated by the upstream system in this application, the first encryption key generated by the upstream system in this embodiment is the private key.

[0107] As an optional implementation, the acquisition module 81 can acquire the first loading business data in the following way: acquire the first loading business in the upstream system, and determine the first loading business data corresponding to the first loading business, wherein the first loading business data includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category.

[0108] In this embodiment, by acquiring the first loading business generated by the upstream system and determining the corresponding first loading business data, the downstream system can quickly and safely complete the quantitative loading operation according to the first loading business data. Specifically, the first loading business data includes: a business order number (usually composed of letters and numbers); a vehicle license plate number (usually composed of letters, numbers, and Chinese characters); a first loading arm position number (usually a number representing the location of the loading / unloading riser); a material code (usually a number representing the unique identifier of the loaded / unloaded product); a planned quantity (usually a decimal place); and a unit of measurement (usually a letter representing the unit of measurement for the loading business).

[0109] Considering that loading business data has a certain time limit, in this embodiment of the application, the first loading business data may further include a first duration, wherein the first duration is used to reflect the effective duration of the first encrypted data in the target carrier. For example, if the loading business of a certain order needs to be completed within the same day, the first duration of the loading business data corresponding to the loading business can be set to 24 hours.

[0110] The encryption module 82 is used to encrypt the first loading business data using the first encryption key to obtain the first ciphertext data.

[0111] Since the security and correctness of data transmission need to be considered during the transmission process to prevent external parties from easily reading and tampering with the transmitted business data, in this application, the encryption module 82 can use the first encryption key to encrypt the first loading business data to obtain the first ciphertext data.

[0112] In addition, considering that the data stored in the target carrier is limited, and that the data will become larger after being encrypted by the asymmetric encryption algorithm, or considering the universality of applying the implementation scheme of this application to trains, automobiles, etc., the first loading business data can also be compressed before encrypting the first loading business data with the first encryption key.

[0113] First, the initial loading data can be converted into a string, and then the encoded byte array is compressed using the GZip compression algorithm, which has a high compression ratio and compression speed, to ensure that the compressed data is small. At the same time, the compression algorithm has a built-in CRC check, so the data verification can be omitted. Thus, the initial loading data can be protected from tampering during transmission while ensuring that the initial encryption key is not disclosed, effectively ensuring the security of the enterprise's business.

[0114] The transmission module 83 is used to input the first encrypted data into the target carrier and transmit the first encrypted data to the downstream system through the target carrier. The downstream system is located in a control network that is physically isolated from the information network and is used to perform quantitative loading operations.

[0115] Optionally, the target carrier includes, but is not limited to, QR codes and smart cards, wherein when the target carrier is a QR code, the first vehicle loading business data is entered into the QR code; when the target carrier is a smart card, the first vehicle loading business data is entered into the smart card.

[0116] As an optional implementation, to ensure that the corresponding first loading service data can be obtained by decrypting the first encrypted data in the target carrier transmitted to the downstream system, before transmitting the first encrypted data to the downstream system via the target carrier, the transmission module 83 can detect the carrier information in the target carrier to determine its correctness (i.e., validity) in the following manner: obtain the first decryption key generated by the upstream system, and use the first decryption key to decrypt the first encrypted data in the target carrier to obtain the first decrypted data; determine whether the carrier information of the target carrier is incorrect based on the first loading service data and the first decrypted data; if the first loading service data and the first decrypted data are consistent, determine that the carrier information is correct; if the first loading service data and the first decrypted data are inconsistent, determine that the carrier information is incorrect.

[0117] The first decryption key is a public key generated by the upstream system. Therefore, the first ciphertext data obtained by encrypting the first loading business data with the private key (the first encryption key) can be decrypted using the public key to obtain the first decrypted data.

[0118] Optionally, after obtaining the first decrypted data, the first decrypted data can also be decompressed.

[0119] Specifically, if the amount of data in the first loading operation is large, it needs to be compressed before encryption. Therefore, after decrypting the first ciphertext data to obtain the first decrypted data, the first decrypted data can be decompressed accordingly. If the amount of data in the first loading operation is small, it can be directly encrypted. In this case, after decrypting the first ciphertext data using the first decryption key to obtain the first decrypted data, no further decompression is required.

[0120] Furthermore, considering that the decryption key in the downstream system is a unified key, improper management of the decryption key in the downstream system could lead to the loss or tampering of loading business data.

[0121] Therefore, in this embodiment of the application, the decryption key in the downstream system can also be updated as follows: obtain the second encryption key used by the upstream system when encrypting the second loading business data; encrypt the first decryption key with the second encryption key to obtain the second ciphertext data; record the second ciphertext data into the target carrier, and transmit the second ciphertext data to the downstream system through the target carrier.

[0122] The aforementioned second loading business data is used to represent the business data corresponding to the previous loading business of the first loading business.

[0123] Specifically, the system can obtain the second encryption key generated by the upstream system during the last transmission and loading service, and encrypt the newly generated decryption key by the upstream system using the second encryption key to obtain the corresponding second ciphertext data. The second ciphertext data is then entered into the target device, and the second ciphertext data corresponding to the first decryption key is transmitted to the downstream system through the target device, thereby ensuring the security and reliability of the decryption key.

[0124] Similarly, each time the upstream system transmits the decryption key, it needs to be encrypted using the encryption key used in the previous encryption operation.

[0125] It should be noted that each module in the above-mentioned data transmission device can be a program module (for example, a set of program instructions that implement a certain function) or a hardware module. For the latter, it can be manifested in the following forms, but is not limited to them: each of the above modules is manifested as a processor, or the functions of each of the above modules are implemented by a processor.

[0126] In addition, each module in the data transmission device in this application corresponds one-to-one with each implementation step of the data transmission method in Embodiment 1. Since Embodiment 1 has been described in detail, some details not shown in this embodiment can be referred to Embodiment 1, and will not be elaborated further here.

[0127] Example 4

[0128] According to an embodiment of this application, a quantitative loading device for implementing the quantitative loading method in Embodiment 2 above is also provided. Figure 9 This is a schematic diagram of an optional quantitative loading device according to an embodiment of this application, as shown below. Figure 9 As shown, the quantitative loading device includes at least: a receiving module 91, a decryption module 92, and an execution module 93, wherein:

[0129] The receiving module 91 is used to receive the target carrier transmitted from the upstream system, wherein the upstream system is located in an information network that is physically isolated from the control network, and the upstream system is used to generate loading business data. The target carrier includes: first ciphertext data corresponding to the first loading business data and second ciphertext data corresponding to the first decryption key.

[0130] The upstream system can be a metering system, ERP system, logistics system, or document processing software, etc., which generates work order source data. The downstream system can be a loading system or a batch controller, where the batch controller is a quantitative loading and unloading controller, such as... Figure 3 In the diagram shown, the batch controller is connected to the engineer station, operator station, and OPC server via an industrial switch, and includes a scanning terminal. Additionally, the first encryption key generated in the upstream system encrypts the first loading business data in the upstream system and records it into the target carrier. Simultaneously, the first decryption key generated in the upstream system is also encrypted and recorded into the target carrier. Therefore, the target carrier includes the first ciphertext data corresponding to the first loading business data and the second ciphertext data corresponding to the first decryption key.

[0131] The decryption module 92 is used to determine the first decryption key based on the second ciphertext data, and use the first decryption key to decrypt the first ciphertext data in the target carrier to obtain the first plaintext data.

[0132] Specifically, the decryption module 92 can determine the first decryption key for decrypting the first ciphertext data based on the second ciphertext data corresponding to the first decryption key, and then use the first decryption key to decrypt the first ciphertext data in the target carrier to obtain the corresponding first plaintext data.

[0133] As an optional implementation, the first encrypted data in the target carrier is decrypted using the first decryption key to obtain the first plaintext data, which includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category.

[0134] Optionally, the first plaintext data may further include: a first duration, wherein the first duration is used to reflect the effective duration of the first ciphertext data within the target carrier.

[0135] As another optional implementation, the decryption module 92 can obtain the first decryption key in the following way: obtain the second decryption key used by the downstream system to decrypt the second loading business data, wherein the second loading business data is used to represent the business data corresponding to the previous loading business of the first loading business; perform a decryption operation on the second ciphertext data in the target carrier using the second decryption key to obtain the second decrypted data; and determine the first decryption key based on the second decrypted data.

[0136] In this embodiment, the second decryption key used by the downstream system during the last transmission loading service is obtained, and the second ciphertext data corresponding to the first decryption key in the target carrier is decrypted using the second decryption key to obtain the second decrypted data, thereby obtaining the first decryption key.

[0137] It should be noted that if the upstream system compresses the first decryption key in the target carrier and then encrypts the first decryption key with the second encryption key, the downstream system will use the second decryption key to decrypt the second ciphertext data corresponding to the first decryption key. After obtaining the second decrypted data, the downstream system will need to decompress the second decrypted data in order to obtain the corresponding first decryption key.

[0138] Similarly, each time a downstream system obtains a decryption key, it needs to use the decryption key used in the previous decryption operation to decrypt the key.

[0139] Execution module 93 is used to execute the first loading operation based on the first plaintext data.

[0140] Specifically, the execution module 93 can execute the corresponding first loading operation within the effective time according to the order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category in the first plaintext data.

[0141] As an optional implementation, before executing the corresponding first loading service based on the first plaintext data, the execution module 93 may also verify the validity of the first plaintext data in the following manner: determine the second duration for which the downstream system obtains the first plaintext data, and the second crane position number when the downstream system executes the first loading service; if the second duration does not exceed the first duration, and the second crane position number is the same as the first crane position number, the first plaintext data is determined to be correct; if the second duration exceeds the first duration, and / or the second crane position number is different from the first crane position number, the first plaintext data is determined to be incorrect.

[0142] For example, the first duration in the first plaintext data is set to 24 hours, and the second crane position number when the downstream system executes the first loading service is 2-24. If the batch controller scans and identifies the target carrier and obtains the first plaintext data at a time of 32 hours, the first encrypted data corresponding to the first loading service data stored in the target carrier becomes invalid, thus making it impossible to obtain the corresponding first loading service data by identifying the target carrier through the batch controller. If the batch controller scans and identifies the target carrier and obtains the first plaintext data at a time of 14 hours, but the first crane position number obtained by identifying the first encrypted data in the target carrier is 1-10, then the second crane position number does not match the first crane position number, indicating that the first plaintext data is incorrect and the loading service cannot be executed according to the first plaintext data.

[0143] It should be noted that each module in the above-mentioned quantitative assembly can be a program module (for example, a set of program instructions to implement a certain function) or a hardware module. For the latter, it can be expressed in the following forms, but is not limited to these: each of the above modules is expressed as a processor, or the functions of each of the above modules are implemented by a processor.

[0144] In addition, each module in the quantitative loading device in this embodiment corresponds one-to-one with each implementation step of the quantitative loading method in Embodiment 2. Since Embodiment 2 has been described in detail, some details not shown in this embodiment can be referred to Embodiment 2, and will not be elaborated further here.

[0145] Example 5

[0146] According to an embodiment of this application, a non-volatile storage medium is also provided, which includes a stored program, wherein the device containing the non-volatile storage medium executes the data transmission method in Embodiment 1 or the quantitative loading method in Embodiment 2 by running the program.

[0147] Optionally, the device containing the non-volatile storage medium executes the following steps by running the program: acquiring the first loading business data and the first encryption key generated by the upstream system; encrypting the first loading business data using the first encryption key to obtain the first ciphertext data; recording the first ciphertext data into the target carrier and transmitting the first ciphertext data to the downstream system through the target carrier, wherein the downstream system is located in a control network physically isolated from the information network, and the downstream system is used to execute quantitative loading business.

[0148] Optionally, the device containing the non-volatile storage medium executes the following steps by running the program: receiving a target carrier transmitted from an upstream system, wherein the upstream system is located in an information network physically isolated from the control network, and the upstream system is used to generate loading service data. The target carrier includes: first ciphertext data corresponding to the first loading service data and second ciphertext data corresponding to the first decryption key; determining the first decryption key based on the second ciphertext data, and using the first decryption key to decrypt the first ciphertext data in the target carrier to obtain first plaintext data; and executing the first loading service based on the first plaintext data.

[0149] According to an embodiment of this application, a processor is also provided for running a program, wherein the program executes the data transmission method in Embodiment 1 or the quantitative loading method in Embodiment 2 during runtime.

[0150] Optionally, the program executes the following steps during runtime: obtaining the first loading business data and the first encryption key generated by the upstream system; encrypting the first loading business data using the first encryption key to obtain the first ciphertext data; inputting the first ciphertext data into the target carrier and transmitting the first ciphertext data to the downstream system through the target carrier, wherein the downstream system is located in a control network physically isolated from the information network, and the downstream system is used to execute quantitative loading business.

[0151] Optionally, the program executes the following steps during runtime: receiving a target carrier transmitted from an upstream system, wherein the upstream system is located in an information network physically isolated from the control network, and the upstream system is used to generate loading service data. The target carrier includes: first ciphertext data corresponding to the first loading service data and second ciphertext data corresponding to the first decryption key; determining the first decryption key based on the second ciphertext data, and using the first decryption key to decrypt the first ciphertext data in the target carrier to obtain first plaintext data; and executing the first loading service based on the first plaintext data.

[0152] According to an embodiment of this application, an electronic device is also provided, comprising: a memory and a processor, wherein the memory stores a computer program, and the processor is configured to execute the data transmission method in Embodiment 1 or the quantitative loading method in Embodiment 2 through the computer program.

[0153] Optionally, the processor is configured to execute the following steps via a computer program: acquiring first loading business data and a first encryption key generated by the upstream system; encrypting the first loading business data using the first encryption key to obtain first ciphertext data; inputting the first ciphertext data into a target carrier and transmitting the first ciphertext data to a downstream system via the target carrier, wherein the downstream system is located in a control network physically isolated from the information network, and the downstream system is used to execute quantitative loading business.

[0154] Optionally, the processor is configured to execute the following steps via a computer program: receiving a target carrier transmitted from an upstream system, wherein the upstream system is located in an information network physically isolated from the control network, and the upstream system is used to generate loading service data, the target carrier including: first ciphertext data corresponding to the first loading service data and second ciphertext data corresponding to the first decryption key; determining the first decryption key based on the second ciphertext data, and using the first decryption key to decrypt the first ciphertext data in the target carrier to obtain first plaintext data; and executing the first loading service based on the first plaintext data.

[0155] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0156] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0157] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0158] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0159] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0160] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0161] The above are merely preferred embodiments of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A data transmission method, characterized by, Upstream systems applied within information networks include: Obtain the first vehicle loading business data from the upstream system, and the first encryption key generated by the upstream system; The first loading business data is encrypted using the first encryption key to obtain the first ciphertext data. The system obtains the second encryption key used by the upstream system to encrypt the second loading service data, wherein the second loading service data represents the service data corresponding to the previous loading service of the first loading service; the system encrypts the first decryption key with the second encryption key to obtain the second ciphertext data; the system records the second ciphertext data into a target carrier and transmits the second ciphertext data to the downstream system through the target carrier; The first encrypted data is entered into the target carrier and transmitted to the downstream system via the target carrier. The target carrier includes a QR code and a smart card. The downstream system is located in a control network physically isolated from the information network and is used to execute a quantitative loading operation. The downstream system decrypts the first encrypted data to obtain first plaintext data. The first plaintext data includes a first crane position number and is used to determine a second duration for the downstream system to obtain the first plaintext data and a second crane position number when the downstream system executes the first loading operation. If the second duration does not exceed the first duration and the second crane position number is the same as the first crane position number, the first plaintext data is determined to be correct. If the second duration exceeds the first duration and / or the second crane position number is different from the first crane position number, the first plaintext data is determined to be incorrect. The first plaintext data is used to execute the first loading operation.

2. The method of claim 1, wherein, Obtaining the first vehicle loading service data from the upstream system includes: Obtain the first loading service in the upstream system and determine the first loading service data corresponding to the first loading service, wherein the first loading service data includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and service category.

3. The method of claim 1, wherein, Before encrypting the first loading data using the first encryption key, the method further includes: The first loading data is compressed.

4. The method of claim 1, wherein, Before transmitting the first ciphertext data to the downstream system via the target carrier, the method further includes: Obtain the first decryption key generated by the upstream system, and use the first decryption key to decrypt the first ciphertext data in the target carrier to obtain the first decrypted data; Based on the first loading business data and the first decryption data, determine whether the carrier information of the target carrier is incorrect; If the first loading data and the first decryption data are consistent, the carrier information is determined to be correct; If the first vehicle loading data and the first decryption data are inconsistent, the carrier information is determined to be incorrect.

5. The method of claim 4, wherein, After obtaining the first decrypted data, the method further includes: The first decrypted data is decompressed.

6. The method of claim 1, wherein, The first loading service data also includes: a first duration, wherein the first duration is used to reflect the effective duration of the first encrypted data in the target carrier.

7. The method according to claim 1, characterized in that: When the target carrier is the QR code, the first loading business data is entered into the QR code; When the target carrier is the smart card, the first vehicle loading service data is entered into the smart card.

8. A method of quantitatively loading a truck, characterized by, Downstream systems applied within the control network include: The system receives a target carrier transmitted from an upstream system, wherein the upstream system is located in an information network physically isolated from the control network, and the upstream system is used to generate loading business data. The target carrier includes a QR code and a smart card, and the target carrier includes a first encrypted data corresponding to the first loading business data and a second encrypted data corresponding to the first decryption key. The process involves determining a first decryption key based on the second ciphertext data, and using the first decryption key to decrypt the first ciphertext data in the target carrier to obtain first plaintext data. This includes: obtaining a second decryption key used by the downstream system to decrypt the second loading service data, wherein the second loading service data represents the service data corresponding to the previous loading service of the first loading service; decrypting the second ciphertext data in the target carrier using the second decryption key to obtain second decrypted data; and determining a first decryption key based on the second decrypted data. The first plaintext data includes a first crane position number. The system determines the second duration for which the downstream system receives the first plaintext data, and the second crane position number when the downstream system executes the first loading service; if the second duration does not exceed the first duration, and the second crane position number is the same as the first crane position number, the system determines that the first plaintext data is correct; if the second duration exceeds the first duration, and / or the second crane position number is different from the first crane position number, the system determines that the first plaintext data is incorrect. The first loading service is executed based on the first plaintext data.

9. The method of claim 8, wherein, The first ciphertext data within the target carrier is decrypted using the first decryption key to obtain the first plaintext data, including: The first encrypted data in the target carrier is decrypted using the first decryption key to obtain the first plaintext data, which includes: order number, license plate number, first crane position number, material code, planned quantity, unit of measurement and business category.

10. The method of claim 9, wherein, The first plaintext data further includes a first duration, wherein the first duration is used to reflect the effective duration of the first ciphertext data within the target carrier.

11. A data transmission apparatus, characterized by comprising: Upstream systems applied within information networks include: The acquisition module is used to acquire the first loading business data in the upstream system and the first encryption key generated by the upstream system. An encryption module is configured to: encrypt the first loading service data using the first encryption key to obtain first ciphertext data; obtain the second encryption key used by the upstream system to encrypt the second loading service data, wherein the second loading service data represents the service data corresponding to the previous loading service of the first loading service; encrypt the first decryption key using the second encryption key to obtain second ciphertext data; input the second ciphertext data into a target carrier, and transmit the second ciphertext data to the downstream system through the target carrier; A transmission module is used to input the first encrypted data into a target carrier and transmit the first encrypted data to a downstream system through the target carrier. The target carrier includes a QR code and a smart card. The downstream system is located within a control network physically isolated from the information network and is used to execute a quantitative loading operation. The downstream system is used to decrypt the first encrypted data to obtain first plaintext data. The first plaintext data includes a first crane position number and is used to determine a second duration for which the downstream system obtains the first plaintext data, and a second crane position number when the downstream system executes the first loading operation. If the second duration does not exceed the first duration and the second crane position number is the same as the first crane position number, the first plaintext data is determined to be correct. If the second duration exceeds the first duration, and / or the second crane position number is different from the first crane position number, the first plaintext data is determined to be incorrect. The first plaintext data is used to execute the first loading operation.

12. A loadout device characterized by, Downstream systems applied within the control network include: A receiving module is used to receive a target carrier transmitted from an upstream system, wherein the upstream system is located in an information network physically isolated from the control network, and the upstream system is used to generate loading business data. The target carrier includes a QR code and a smart card, and the target carrier includes a first encrypted data corresponding to the first loading business data and a second encrypted data corresponding to the first decryption key. The decryption module is used to determine a first decryption key based on the second ciphertext data, and to decrypt the first ciphertext data in the target carrier using the first decryption key to obtain first plaintext data. This includes: obtaining a second decryption key used by the downstream system to decrypt the second loading service data, wherein the second loading service data represents the service data corresponding to the previous loading service of the first loading service; decrypting the second ciphertext data in the target carrier using the second decryption key to obtain second decrypted data; and determining a first decryption key based on the second decrypted data. The first plaintext data includes a first crane position number. The execution module is used to execute the first loading operation based on the first plaintext data; The quantitative loading device is further configured to determine the second duration for which the downstream system obtains the first plaintext data, and the second crane position number when the downstream system performs the first loading service; if the second duration does not exceed the first duration, and the second crane position number is the same as the first crane position number, the first plaintext data is determined to be correct; if the second duration exceeds the first duration, and / or the second crane position number is different from the first crane position number, the first plaintext data is determined to be incorrect.

13. A non-volatile storage medium, comprising: The non-volatile storage medium stores a program, wherein when the program is executed, it controls the device containing the non-volatile storage medium to perform the data transmission method according to any one of claims 1 to 7 or the quantitative loading method according to any one of claims 8 to 10.

14. An electronic device, comprising: include: A memory and a processor, the processor being configured to run a program stored in the memory, wherein the program, when running, executes the data transmission method according to any one of claims 1 to 7 or the quantitative loading method according to any one of claims 8 to 10.