An information transmission method and system based on an engineering supervision platform

Through the information transmission method of the engineering supervision platform, combined with technologies such as session management, adaptive traffic control, classified compression, dynamic key update and double-layer encryption, the security and efficiency of information transmission in engineering supervision projects are solved, the security and efficiency of data transmission is balanced, and network reliability and data integrity are improved.

CN119865381BActive Publication Date: 2025-07-04BEIJING NUO SHICHENG INT ENG PROJECT MANAGEMENT CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510343703.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-22
Publication Date
2025-07-04
Estimated Expiration
2045-03-22

AI Technical Summary

Technical Problem

In existing engineering supervision projects, there is a risk of increased network delay and information leakage. Traditional encryption technology is difficult to ensure data security and efficiency in complex network environments.

Method used

The information transmission method of the engineering supervision platform is adopted to ensure the security and efficiency of data transmission through strategies such as session management, adaptive traffic control, classified compression, dynamic key update, double-layer encryption, multi-level redundant backup and abnormal behavior detection.

Benefits of technology

It achieves a balance of security and efficiency of data transmission in different network environments, reduces the risk of key leakage, improves network reliability and data integrity, and enhances the ability to fight against network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119865381B_ABST
    Figure CN119865381B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of information transmission of engineering supervision platforms, and discloses an information transmission method and system based on an engineering supervision platform, including: obtaining construction data uploaded by on-site supervisors, implementing a classification compression preprocessing strategy to classify, compress, and perform robust coding on the construction data; according to an execution key and the construction data, implementing a double-layer encryption strategy to generate a digital signature, and encrypting the construction data, the execution key, and the digital signature; sending the encrypted construction data, execution key, and digital signature to project managers through a network transmission path; implementing a fault monitoring strategy for each node in the network transmission path to determine whether the node is faulty; if a faulty node is detected, implementing a multi-level redundant backup strategy to replace the faulty node with a backup node; implementing a hierarchical handling strategy for abnormal network behaviors to maintain the security of the network transmission path, improving the efficiency and security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of information transmission of engineering supervision platforms, and specifically provides an information transmission method and system based on an engineering supervision platform. Background Art

[0002] In modern engineering supervision projects, information transmission has become an essential part. Especially in large-scale engineering projects, a large amount of real-time transmitted data involves multiple aspects such as project progress, quality control, cost management, and safety management. Therefore, ensuring the security of information transmission is of crucial importance. Currently, the common practice is to use firewalls and intrusion detection systems at the network level to prevent external attacks, and use the SSL / TLS protocol for encryption and decryption communication during the transmission process to ensure the confidentiality and integrity of information.

[0003] The traditional SSL / TLS encryption mechanism may cause increased latency in case of network congestion, affecting the efficiency of information transmission. In addition, in the face of increasingly complex network attack means, it is difficult to completely avoid the risk of information leakage only relying on these general encryption technologies.

[0004] This solution proposes an information transmission method and system based on an engineering supervision platform to implement an optimized strategy for data transmission, which can not only improve the quality and efficiency of engineering supervision work, but also provide strong technical support for the successful implementation of the entire engineering project. Summary of the Invention

[0005] The present invention provides an information transmission method and system based on an engineering supervision platform, which helps to solve the problems mentioned in the above background art.

[0006] In a first aspect, the present application provides an information transmission method based on an engineering supervision platform, adopting the following technical solution: An information transmission method based on an engineering supervision platform includes: on-site supervision personnel send construction data to project management personnel through the engineering supervision platform, and the engineering supervision platform generates a session between the on-site supervision personnel and the project management personnel.

[0007] By generating a session, the system can effectively manage the context and authentication process of data transmission, ensuring the uniqueness and integrity of data transmission. Session records can trace historical operations, providing a basis for subsequent management and responsibility division. At the same time, through session management, session anomalies can be detected and processed in real time, improving the stability and security of data transmission.

[0008] During the session:

[0009] Obtain the current bandwidth of the transmission network of the engineering supervision platform and the packet loss rate ;

[0010] Execute an adaptive traffic control strategy according to the bandwidth and packet loss rate, and adjust the encryption strength of the construction data;

[0011] Obtain the construction data uploaded by on-site supervisors, execute a classification compression preprocessing strategy, and perform classification compression and robust coding on the construction data;

[0012] Set the master key and session key;

[0013] Execute a key update strategy according to the master key and session key to update the master key and session key;

[0014] Obtain the session key of this session, denoted as the execution key;

[0015] Execute a two-layer encryption strategy according to the execution key and construction data to generate a digital signature, and encrypt the construction data, execution key, and digital signature;

[0016] Obtain the network transmission path of this session, which consists of multiple nodes;

[0017] Send the encrypted construction data, execution key, and digital signature to the project management personnel through the network transmission path;

[0018] Execute a fault monitoring strategy for each node in the network transmission path to determine whether the node is faulty;

[0019] If a faulty node is detected, execute a multi-level redundant backup strategy and use the backup node to replace the faulty node;

[0020] Use AI intelligent detection for abnormal network behavior for each node in the network transmission path;

[0021] Execute a hierarchical disposal strategy for abnormal network behavior to maintain the security of the network transmission path;

[0022] Record this session using blockchain logs.

[0023] Preferably, the executing an adaptive traffic control strategy according to the bandwidth and packet loss rate and adjusting the encryption strength of the construction data includes:

[0024] Set the bandwidth weight factor ;

[0025] Set the packet loss rate weight factor ;

[0026] Obtain the maximum bandwidth for data transmission on the project supervision platform ;

[0027] Execute the following formula to calculate the encryption strength ;

[0028] , wherein, , , .

[0029] By monitoring the network bandwidth and packet loss rate, the system can dynamically optimize the encryption strength, thereby improving the transmission efficiency while ensuring security. Reducing the encryption strength at low bandwidth can save transmission resources; while increasing the encryption strength under high bandwidth conditions can enhance data security and meet the requirements in different environments.

[0030] Preferably, obtaining the construction data uploaded by on-site supervisors, implementing a classification compression preprocessing strategy, and performing classification compression and robust coding on the construction data, including:

[0031] The construction data is divided into categories of project progress, quality control, cost management, and safety management;

[0032] For any category of construction data, obtaining the compression algorithm matched by the project supervision platform for this category of construction data, and obtaining the compression rate of this compression algorithm ;

[0033] Obtaining the file of the construction data ;

[0034] Implementing the classification compression preprocessing strategy to compress the construction data to ;

[0035] Robust coding:

[0036] Obtaining the standard parity-check matrix H;

[0037] Using Gaussian elimination to decompose the parity-check matrix H to obtain the first matrix P;

[0038] , wherein, is the transpose of the first matrix , is the identity matrix of;

[0039] Calculating the generator matrix , wherein, is the identity matrix of;

[0040] Calculating the codeword .

[0041] By classifying and compressing construction data, the optimal compression algorithm can be adopted for different types of data, improving the compression ratio and data transmission efficiency. At the same time, classified compression can reduce the storage requirements and transmission bandwidth load of the system, enhancing the overall performance and resource utilization rate of the platform.

[0042] Preferably, performing the key update strategy according to the master key and the session key to update the master key and the session key includes:

[0043] When the on-site supervisor uploads construction data to the project supervision platform each time, generate the session key for this session according to the current master key, specifically:

[0044] Obtain the session corresponding to the on-site supervisor's current upload of construction data to the project supervision platform ;

[0045] Obtain the current master key ;

[0046] Use algorithm to calculate the session key for this session ;

[0047] Set the master key update interval ;

[0048] Obtain the time of the last master key update ;

[0049] At time, update the master key, and use algorithm to obtain the updated master key .

[0050] By setting the master key and the session key and dynamically updating them, the security risks caused by the long-term use of the key can be prevented. The key update strategy ensures that each session has an independent key, reducing the possibility of the key being cracked or leaked, and further enhancing the security of the system.

[0051] Preferably, performing the double-layer encryption strategy according to the execution key and the construction data, generating a digital signature, and encrypting the construction data, the execution key, and the digital signature includes:

[0052] Obtain the codeword obtained after robust coding;

[0053] Obtain the private key of the on-site supervisor, and use the private key to perform asymmetric encryption on the codeword to obtain a digital signature;

[0054] Use the execution key to perform symmetric encryption on the codeword;

[0055] Obtain the public key of the project manager, and use the public key to perform asymmetric encryption on the execution key.

[0056] Through double - layer encryption and digital signature, it can effectively prevent the tampering and leakage of data during transmission. Asymmetric encryption provides an authentication function, while symmetric encryption ensures transmission efficiency. The combination of double - layer encryption further enhances the data protection ability.

[0057] Preferably, sending the encrypted construction data, execution key, and digital signature to the project manager through the network transmission path includes:

[0058] For any on - site supervisor:

[0059] Obtain the digital signature uploaded by the on - site supervisor , the encrypted codeword and the encrypted execution key ;

[0060] Calculate the encrypted hash value , to obtain the unique identifier of the on - site supervisor ;

[0061] Obtain the face recognition image of the on - site supervisor, and perform the Gaussian blur algorithm on the face recognition image for privacy protection. Specifically:

[0062] Establish a two - dimensional coordinate system at the center of the face recognition image, where the face recognition image is square, and the length = width = 2q;

[0063] Calculate the pixel value of each pixel on the face recognition image after performing the Gaussian blur algorithm: , where is the pixel value of the horizontal and vertical coordinates , is the blur intensity;

[0064] Obtain the face recognition image that has undergone the Gaussian blur algorithm ;

[0065] Obtain the identity information of the on - site supervisor , the time of uploading data and the location information of the on - site supervisor ;

[0066] Set the data block of the on - site supervisor ;

[0067] Obtain the data blocks of all on - site supervisors, execute the grouped upload strategy, and upload the data blocks to the blockchain network in groups. Specifically:

[0068] Set the group size ;

[0069] Divide all the obtained data blocks of on-site supervisors equally into groups, with each group containing data blocks;

[0070] Pack each group of data and calculate its overall hash value ,

[0071] where, store the calculated overall hash value in the blockchain network;

[0072] The blockchain aggregation node downloads all the data uploaded to the blockchain through distributed storage;

[0073] Project managers input in the blockchain the identity information of on-site supervisors, the time of uploading data, the location information of on-site supervisors, etc. to query the required data blocks.

[0074] By encrypting the construction data and the key separately, the system can decrypt and restore at the project manager's end to ensure the integrity and confidentiality of the data. Adopting a combination of asymmetric and symmetric encryption can balance security and efficiency.

[0075] Preferably, the execution of the fault monitoring strategy for each node in the network transmission path to determine whether the node is faulty includes:

[0076] For each node in the network transmission path, set the health status of the node ;

[0077] Obtain the resource utilization rate of the node ;

[0078] Obtain the response time of the node ;

[0079] Obtain the load level of the node ;

[0080] Execute the following formula to calculate ;

[0081] , where, , and are the weights of the resource utilization rate, the response time, and the load level respectively, and ;

[0082] Set the health threshold ;

[0083] Compare the health status of the node with the health threshold;

[0084] If , the node is healthy;

[0085] If , the node fails.

[0086] By monitoring the health status of nodes, the system can identify potential faults in the network in real time, take timely measures, and reduce the risk of transmission interruption. This improves the reliability and availability of the network while reducing the impact of faults on the overall transmission efficiency.

[0087] Preferably, if a faulty node is detected, a multi-level redundant backup strategy is executed to replace the faulty node with a backup node, including:

[0088] Set the backup radius;

[0089] Obtain the node with monitored faults. The circle made with the position of the faulty node as the center and the backup radius as the radius is denoted as the backup area;

[0090] Obtain all the idle nodes in the backup area, calculate the distances from the faulty node, sort them by distance, and select the top 3 idle nodes, which are respectively denoted as the first node, the second node, and the third node;

[0091] Activate the first node to replace the faulty node;

[0092] Notify the second node to start the high-availability HA cluster;

[0093] Set the third node to enter the hot standby state.

[0094] Through the multi-level redundant backup strategy, the system can quickly replace faulty nodes, ensuring the continuity and stability of transmission. Enabling the HA cluster and the hot standby mechanism can further improve the disaster tolerance ability of the system and enhance the high availability of the platform.

[0095] Preferably, each node in the network transmission path is used to detect abnormal network behaviors using AI intelligence, and a hierarchical handling strategy is executed for abnormal network behaviors to maintain the security of the network transmission path, including:

[0096] Detect abnormal network behaviors based on the combined model of Transformer and Autoencoder:

[0097] Transformer encoding module:

[0098] Extract the features of the node transmission traffic , map the features to a high-dimensional space using the embedding layer, and the multi-head attention mechanism extracts key time-series features:

[0099] , where , , , , They are the three dimensions of query, key, and value vector, time step, and value respectively.

[0100] Capture high-dimensional features of global temporal dependencies;

[0101] Autoencoder decoding module:

[0102] Obtain high-dimensional features;

[0103] Use a fully connected layer to restore the high-dimensional features to the original space;

[0104] Minimize the reconstruction error: , where is the number of features, is the reconstructed feature;

[0105] Anomaly detection module:

[0106] Calculate the mean of the features of the extracted node transmission traffic and the standard deviation ;

[0107] Calculate , denoted as the anomaly score;

[0108] Set the anomaly threshold;

[0109] If the anomaly score ≥ anomaly threshold, the network behavior is abnormal;

[0110] If the anomaly score ≤ anomaly threshold, the network behavior is normal;

[0111] When detecting abnormal network behavior, generate an alarm message and upload the alarm message to the security management center of the project supervision platform;

[0112] Record the moment when abnormal network behavior is detected as the first moment;

[0113] Set the anomaly warning period;

[0114] Record the moment after the first moment at an interval of the warning period as the second moment;

[0115] Detect whether the abnormal network behavior has ended at the second moment. If the abnormal network behavior has not ended, automatically terminate the abnormal network behavior.

[0116] Through a hierarchical handling strategy, the system can take appropriate response measures according to the severity of the abnormal behavior, avoiding the network from being attacked or misused. This process can eliminate threats in a timely manner, maintain network security, and at the same time reduce the interference of false alarms to the system.

[0117] Second aspect, the present application provides a system for an information transmission method based on an engineering supervision platform, adopting the following technical solutions: A system for an information transmission method based on an engineering supervision platform, comprising:

[0118] A session management module that generates and maintains a session between on-site supervisors and project managers;

[0119] A network monitoring and traffic control module that monitors bandwidth and packet loss rate and dynamically adjusts the encryption strength;

[0120] A data classification and compression module that classifies construction data by category and executes corresponding compression algorithms;

[0121] A key management module that generates, updates the master key and session keys, and distributes execution keys;

[0122] A data encryption and signature module that implements double-layer encryption and digital signature to ensure data security;

[0123] A data transmission and fault handling module that manages encrypted data transmission, monitors node health, and executes fault redundancy backup;

[0124] An abnormal behavior detection and handling module that identifies abnormal access and unknown IPs and executes a hierarchical handling strategy;

[0125] A blockchain logging module that records session logs to ensure data immutability;

[0126] A user permission management module that controls user permissions to ensure data access security;

[0127] A security management center that processes network anomalies and fault alarms and provides system-level security protection.

[0128] The present invention has the following beneficial effects:

[0129] 1. For the information transmission method based on the engineering supervision platform, by obtaining the network bandwidth and packet loss rate in real time, the system can intelligently adjust the encryption strength, thereby achieving a balance between security and efficiency. When the network bandwidth is limited, reducing the encryption strength can reduce data processing and transmission time and avoid network congestion; while under high-bandwidth conditions, by increasing the encryption strength, the data protection ability can be enhanced to ensure the confidentiality of information. This dynamic adjustment strategy can not only adapt to the complex and changeable network environment, but also effectively optimize resource utilization, improving the efficiency and security of construction data transmission.

[0130] 2. The information transmission method based on the project supervision platform can significantly improve the compression efficiency by classifying and compressing construction data, enabling the system to select the optimal compression algorithm according to the data type. For example, project progress data may require a high-precision compression algorithm, while image data is more suitable for lossless or lossy compression. This preprocessing method can reduce the volume of transmitted data, lower the occupancy of network bandwidth, and relieve the storage pressure on the server. In addition, classification processing can also specifically optimize the processing effect of specific types of data, further improving the stability and accuracy of data transmission.

[0131] 3. The information transmission method based on the project supervision platform can significantly reduce the risk of key leakage or being cracked by setting a master key and session keys and dynamically updating them. Each session generates an independent session key to ensure the uniqueness of data encryption and effectively prevent replay attacks or other malicious behaviors. The regular update of the master key can reduce the security risks brought by long-term use and maintain the forefront and reliability of the encryption mechanism. This dynamic key management strategy not only guarantees the security of data transmission but also enhances the protection ability of the system in complex scenarios.

[0132] 4. The information transmission method based on the project supervision platform can meet the security and efficiency requirements simultaneously by implementing a two-layer encryption strategy, combining the identity authentication function of asymmetric encryption with the high-efficiency transmission performance of symmetric encryption. In addition, the generated digital signature can verify the integrity and source of the data to prevent the data from being tampered with during transmission. This combined strategy can not only resist various security threats but also provide reliable encryption protection at each link of data transmission, fully protecting the privacy and credibility of construction data.

[0133] 5. The information transmission method based on the project supervision platform can quickly identify potential faults and take emergency measures by real-time monitoring the health status of each node in the transmission path. For faulty nodes, the multi-level redundant backup strategy allows the system to select alternative nodes from nearby idle nodes and simultaneously start the high-availability cluster and hot backup mechanism. This mechanism can minimize the impact of network interruption and ensure the continuous transmission and processing ability of construction data. The combination of fault management and backup strategy significantly improves the reliability of the network and the high availability of the platform.

[0134] 6. The information transmission method based on the engineering supervision platform can take targeted security measures according to the severity of events by classifying and handling abnormal network behaviors. For example, minor abnormal access can be handled by warnings or temporary restrictions, while serious threats will trigger an automatic blocking mechanism. This classification strategy ensures that security events can be efficiently responded to, while reducing the interference of false alarms on normal operations. Combined with the automatic detection of abnormal behaviors and the upload of alarms, the system can continuously maintain the security of the transmission path and avoid the impact of external threats on data transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0135] Figure 1 It is a schematic flow chart of the method of the present invention.

[0136] Figure 2 It is a schematic diagram of the system modules of the present invention.

[0137] Figure 3 It is a schematic diagram of the system modules of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0138] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0139] Embodiment 1. Refer to Figure 1 . An information transmission method based on an engineering supervision platform, including:

[0140] On-site supervision personnel send construction data to project management personnel through the engineering supervision platform, and the engineering supervision platform generates a session between the on-site supervision personnel and the project management personnel;

[0141] By creating a session between on-site supervision personnel and project management personnel, the system realizes the whole-process tracking and recording of data transmission, ensuring that data interaction has a clear context. This mechanism can effectively avoid the problems of confusion or omission of data in multi-party interaction, and at the same time assigns a unique identifier to each transmission. Session-based management also allows real-time monitoring of the data flow and status. Once abnormal situations occur, such as data loss or repeated transmission, the system can quickly respond and locate the problem. This session management mechanism not only provides strong support for data transmission, but also provides a reliable basis for subsequent process management and auditing.

[0142] During the session:

[0143] Obtain the current bandwidth of the transmission network of the engineering supervision platform and packet loss rate ;

[0144] Execute an adaptive traffic control strategy according to the bandwidth and packet loss rate, and adjust the encryption intensity of the construction data;

[0145] Obtain the construction data uploaded by on-site supervisors, execute a classification compression preprocessing strategy, and perform classification compression and robust coding on the construction data;

[0146] Set the master key and session key;

[0147] Execute a key update strategy according to the master key and session key to update the master key and session key;

[0148] Obtain the session key of this session, denoted as the execution key;

[0149] Execute a two-layer encryption strategy according to the execution key and construction data, generate a digital signature, and encrypt the construction data, execution key, and digital signature;

[0150] Obtain the network transmission path of this session, which consists of multiple nodes;

[0151] Send the encrypted construction data, execution key, and digital signature to the project management personnel through the network transmission path;

[0152] Execute a fault monitoring strategy for each node in the network transmission path to determine whether the node is faulty;

[0153] If a faulty node is detected, execute a multi-level redundant backup strategy and use the backup node to replace the faulty node;

[0154] Use AI to intelligently detect abnormal network behaviors for each node in the network transmission path;

[0155] Execute a hierarchical disposal strategy for abnormal network behaviors to maintain the security of the network transmission path;

[0156] Record this session using blockchain logs.

[0157] By recording the key information of each session on the blockchain, the system realizes the immutability and permanent traceability of data. This function not only enhances the credibility of data storage but also provides technical support for the operation transparency of the platform. In scenarios such as data auditing, legal disputes, and compliance inspections, blockchain logs can serve as authoritative evidence to ensure the integrity and authenticity of data. Through this decentralized recording mechanism, the overall trust and reliability of the platform are further improved, laying a solid foundation for the digital development of project supervision.

[0158] Execute an adaptive traffic control strategy according to the bandwidth and packet loss rate, and adjust the encryption intensity of construction data, including:

[0159] Set the bandwidth weight factor ;

[0160] Set the packet loss rate weight factor ;

[0161] Obtain the maximum bandwidth of the data transmitted by the project supervision platform ;

[0162] Execute the following formula to calculate the encryption intensity ;

[0163] , where , , .

[0164] By real-time detecting the bandwidth and packet loss rate of the transmission network, the system dynamically adjusts the encryption intensity of the data, achieving a balance between security and efficiency. When the network load is large, reducing the encryption intensity can reduce the data processing time, thus ensuring that important data is delivered in a timely manner; while when the network conditions are good, increasing the encryption intensity can provide higher security protection. This strategy not only significantly optimizes the utilization rate of network resources, but also adapts to different network environments and application scenarios. Through this dynamic adjustment mechanism, the system can achieve the best balance between security and performance, improving the transmission efficiency and stability of the entire project supervision platform.

[0165] Obtain the construction data uploaded by on-site supervisors, and execute a classification compression preprocessing strategy to classify, compress and robustly encode the construction data, including:

[0166] The construction data is divided into categories of project progress, quality control, cost management and safety management;

[0167] For any category of construction data, obtain the compression algorithm matched by the project supervision platform for this category of construction data, and obtain the compression rate of this compression algorithm ;

[0168] Obtain the file of the construction data ;

[0169] Execute the classification compression preprocessing strategy to compress the construction data to ;

[0170] Robust encoding:

[0171] Obtain the standard parity-check matrix H;

[0172] Use Gaussian elimination to decompose the parity-check matrix H to obtain the first matrix P;

[0173] , where is the transpose of the first matrix , is the identity matrix of

[0174] Calculate the generator matrix , where is the identity matrix of

[0175] Calculate the codeword after robust coding.

[0176] By classifying the construction data and adopting a targeted compression algorithm, the system can significantly reduce the data volume and relieve the network bandwidth pressure. For example, for project progress data, an efficient compression algorithm is used to ensure the content accuracy, while for multimedia data, a lossy compression method that balances quality and volume is selected. This classification compression strategy not only improves the data transmission efficiency but also reduces the storage space occupancy, providing support for the long-term stable operation of the project supervision platform. In addition, data classification compression can further enhance the usability of different types of data, ensuring that key information can be quickly restored and utilized when necessary.

[0177] According to the master key and the session key, execute the key update strategy to update the master key and the session key, including:

[0178] When the on-site supervisor uploads construction data to the project supervision platform each time, generate the session key for this session according to the current master key, specifically:

[0179] Obtain the session corresponding to the on-site supervisor's upload of construction data to the project supervision platform this time;

[0180] Obtain the current master key ;

[0181] Use algorithm to calculate the session key for this session;

[0182] Set the master key update interval ;

[0183] Obtain the time of the last master key update ;

[0184] At time, update the master key and use algorithm to obtain the updated master key .

[0185] In this embodiment, the dynamic key update mechanism automatically replaces the master key every 12 hours, and each replacement of the master key will trigger the system to automatically notify all participating parties to update the local key library.

[0186] The blockchain log management system will record in detail the timestamps, initiator IDs, and operation results of each encryption and decryption operation, forming an immutable log chain to provide a basis for post-event auditing.

[0187] Through the dynamic management of the master key and session keys, the system effectively reduces the risk of key leakage. Each session generates an independent session key, so that even if the key of a certain session is stolen, it will not affect the data security of other sessions. At the same time, the regular update of the master key can reduce the security risks brought by long-term use and maintain the forefront and high strength of the encryption policy. Through the key update strategy, the system improves the ability to resist external attacks while ensuring data confidentiality, providing stronger security protection for the transmission of construction data.

[0188] According to the execution key and construction data, a two-layer encryption policy is executed to generate a digital signature, and the construction data, execution key, and digital signature are encrypted, including:

[0189] Obtain the codeword obtained after robust coding;

[0190] Obtain the private key of the on-site supervisor, and use the private key to perform asymmetric encryption on the codeword to obtain a digital signature;

[0191] Use the execution key to perform symmetric encryption on the codeword;

[0192] Obtain the public key of the project manager, and use the public key to perform asymmetric encryption on the execution key.

[0193] In this embodiment, for the transmission of video surveillance information at the construction site, the project supervision platform will first perform H.265 encoding and compression on the video stream, then use the AES-256 algorithm for encryption processing, and at the same time generate a corresponding RSA digital signature to ensure a high transmission rate even under poor network conditions, and the project manager can ensure that the data has not been tampered with by verifying the digital signature.

[0194] By combining symmetric encryption and asymmetric encryption, the system achieves a good balance between security and efficiency. First, the generation of the digital signature verifies the authenticity of the data source, preventing malicious tampering and impersonation operations; second, the fast encryption feature of symmetric encryption ensures the efficient transmission of a large amount of data, while asymmetric encryption is used to protect the confidentiality of the session key. This two-layer encryption mechanism can effectively defend against various security threats such as replay attacks and man-in-the-middle attacks, thus comprehensively ensuring the confidentiality and reliability of construction data during transmission.

[0195] Send the encrypted construction data, execution key, and digital signature to the project management personnel through the network transmission path, including:

[0196] For any on-site supervisor:

[0197] Obtain the digital signature uploaded by the on-site supervisor , the encrypted codeword and the encrypted execution key ;

[0198] Calculate the encrypted hash value to obtain the unique identifier of the on-site supervisor ;

[0199] Obtain the face recognition image of the on-site supervisor and perform the Gaussian blur algorithm on the face recognition image for privacy protection. Specifically:

[0200] Establish a two-dimensional coordinate system at the center of the face recognition image. Among them, the face recognition image is square, and the length = width = 2q;

[0201] Calculate the pixel value of each pixel on the face recognition image after performing the Gaussian blur algorithm: , where is the pixel value of the horizontal and vertical coordinates , is the blur intensity;

[0202] Obtain the face recognition image that has performed the Gaussian blur algorithm ;

[0203] Obtain the identity information of the on-site supervisor , the time of uploading data and the location information of the on-site supervisor ;

[0204] Set the data block of the on-site supervisor ;

[0205] Obtain the data blocks of all on-site supervisors, execute the grouped upload strategy, and upload the data blocks to the blockchain network in groups. Specifically:

[0206] Set the group size ;

[0207] Divide all the obtained data blocks of on-site supervisors into groups, with each group containing data blocks;

[0208] Pack each group of data, calculate its overall hash value ,

[0209] Among them, the calculated overall hash value is stored in the blockchain network;

[0210] The blockchain summary node downloads all the data uploaded to the blockchain through distributed storage;

[0211] Project managers input in the blockchain the identity information of on-site supervisors, the time of uploading data, the location information of on-site supervisors, etc. to query the required data blocks.

[0212] Execute a fault monitoring strategy for each node in the network transmission path to determine whether the node is faulty, including:

[0213] For each node in the network transmission path, set the health status of the node ;

[0214] Obtain the resource utilization rate of the node ;

[0215] Obtain the response time of the node ;

[0216] Obtain the load level of the node ;

[0217] Execute the following formula to calculate ;

[0218] where , and are the weights of resource utilization rate, response time, and load level respectively, and ;

[0219] Set the health threshold ;

[0220] Compare the health status of the node with the health threshold;

[0221] If , the node is healthy;

[0222] If , the node is faulty.

[0223] If a faulty node is detected, execute a multi-level redundant backup strategy to replace the faulty node with a backup node, including:

[0224] Set the backup radius;

[0225] Obtain the node with detected fault, and take the circle with the position of the faulty node as the center and the backup radius as the radius as the backup area;

[0226] Obtain all the idle nodes in the backup area, calculate the distances to the faulty node, sort them from the nearest to the farthest, and select the first 3 idle nodes, denoted as the first node, the second node, and the third node respectively;

[0227] Activate the first node to replace the faulty node;

[0228] Notify the second node to start the high-availability HA cluster;

[0229] Set the third node to enter the hot backup state.

[0230] By continuously monitoring the health status of network nodes, the system can quickly detect potential faults and take remedial measures in a timely manner. For faulty nodes, the system activates standby nodes through a multi-level redundant backup strategy to ensure the continuous and stable operation of the network. At the same time, the hierarchical design of backup nodes includes primary, secondary, and hot backup states, further improving the fault tolerance of the system. Through this fault management and backup mechanism, the risks of network interruption and data loss are significantly reduced, and the transmission efficiency and data availability are significantly improved.

[0231] Use AI to intelligently detect abnormal network behaviors for each node in the network transmission path and execute a hierarchical disposal strategy for abnormal network behaviors to maintain the security of the network transmission path, including:

[0232] Detect abnormal network behaviors based on the combined model of Transformer and Autoencoder:

[0233] Transformer encoding module:

[0234] Extract the features of the node transmission traffic , map the features to a high-dimensional space using the embedding layer, and use the multi-head attention mechanism to extract key temporal features:

[0235] , where , , , , are the three dimensions of query, key, and value vectors, time step, and value respectively;

[0236] Capture high-dimensional features of global temporal dependencies;

[0237] Autoencoder decoding module:

[0238] Obtain high-dimensional features;

[0239] Use the fully connected layer to restore the high-dimensional features to the original space;

[0240] Minimize the reconstruction error: , where is the number of features is the reconstructed feature;

[0241] Anomaly detection module:

[0242] Calculate the mean value and standard deviation ;

[0243] Calculate , denoted as the anomaly score;

[0244] Set the anomaly threshold;

[0245] If the anomaly score ≥ the anomaly threshold, the network behavior is abnormal;

[0246] If the anomaly score ≤ the anomaly threshold, the network behavior is normal;

[0247] When detecting abnormal network behavior, generate an alarm message and upload the alarm message to the security management center of the project supervision platform;

[0248] Record the moment when abnormal network behavior is detected as the first moment;

[0249] Set the anomaly warning period;

[0250] Record the moment after the first moment at an interval of the warning period as the second moment;

[0251] Detect whether the abnormal network behavior ends at the second moment. If the abnormal network behavior does not end, automatically terminate the abnormal network behavior.

[0252] Through intelligent monitoring and hierarchical response, the system can accurately identify abnormal network behaviors, such as frequent access and unknown IP access. For different levels of threats, the system takes targeted disposal measures. Minor anomalies are reminded to the administrator through alarms, while major threats trigger an automatic blocking mechanism to prevent malicious behaviors from affecting the system operation. Through this hierarchical disposal strategy, the platform can achieve efficient management of security incidents, while minimizing interference with normal business operations and providing lasting security protection for the transmission path.

[0253] Embodiment 2. A system for an information transmission method based on a project supervision platform, including:

[0254] In this embodiment, refer to Figure 2 .

[0255] A session management module that generates and maintains a session between on-site supervision personnel and project management personnel;

[0256] A network monitoring and traffic control module that monitors the bandwidth and packet loss rate and dynamically adjusts the encryption strength;

[0257] A data classification and compression module classifies construction data by category and executes corresponding compression algorithms;

[0258] A key management module generates and updates the master key and session keys, and distributes execution keys;

[0259] A data encryption and signature module implements double-layer encryption and digital signatures to ensure data security;

[0260] A data transmission and fault handling module manages encrypted data transmission, monitors node health, and executes fault redundancy backup;

[0261] In this embodiment, refer to Figure 3 ;

[0262] An abnormal behavior detection and handling module identifies abnormal access and unknown IPs and executes a hierarchical disposal strategy;

[0263] A blockchain logging module records session logs to ensure the immutability of data;

[0264] A user permission management module controls user permissions to ensure data access security;

[0265] A security management center processes network anomalies and fault alarms and provides system-level security guarantees.

[0266] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device.

[0267] The above are only the preferred embodiments of the present invention. It should be pointed out that for those of ordinary skill in the art, without departing from the technical principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. An information transmission method based on an engineering supervision platform, characterized in that, Including: On-site supervision personnel send construction data to project management personnel through the project supervision platform, and the project supervision platform generates a session between the on-site supervision personnel and the project management personnel. During the session: Obtain the current bandwidth B and packet loss rate L of the transmission network of the project supervision platform. According to the bandwidth and packet loss rate, execute an adaptive traffic control strategy to adjust the encryption intensity of the construction data. Obtain the construction data uploaded by the on-site supervision personnel, execute a classification compression preprocessing strategy, and perform classification compression and robust coding on the construction data. Set the master key and session key. According to the master key and session key, execute a key update strategy to update the master key and session key. Obtain the session key of this session, denoted as the execution key. According to the execution key and the construction data, execute a double-layer encryption strategy to generate a digital signature, and encrypt the construction data, the execution key, and the digital signature. Obtain the network transmission path of this session, and the network transmission path consists of multiple nodes. Send the encrypted construction data, the execution key, and the digital signature to the project management personnel through the network transmission path, including: For any on-site supervision personnel: Obtain the digital signature C1, the encrypted codeword C2, and the encrypted execution key C3 uploaded by the on-site supervision personnel. Calculate the encrypted hash value H(C1||C2||C3) to obtain the unique identifier F0 of this on-site supervision personnel. Obtain the face recognition image of the on-site supervision personnel, and perform a Gaussian blur algorithm on the face recognition image for privacy protection. Specifically: Establish a two-dimensional coordinate system at the center of the face recognition image, where the face recognition image is square, and the length = width = 2q. Calculate the pixel values after performing the Gaussian blur algorithm on each pixel of the face recognition image: where f(x, y) is the pixel value of the horizontal and vertical coordinates x and y, and σ is the blur intensity; Obtain the face recognition image F1 after performing the Gaussian blur algorithm. Obtain the ID number F2 of the on-site supervision personnel, the time F3 of uploading data, and the location information F4 of the on-site supervision personnel. Set the data block S of the on-site supervision personnel = {F0, F1, F2, F3, F4}. Obtain the data blocks of all on-site supervision personnel, execute a grouped upload strategy, and upload the data blocks to the blockchain network in groups. Specifically: Set the group size b1. Divide all the obtained data blocks of on-site supervision personnel into b1 groups, and each group contains b2 data blocks. Pack each set of data and calculate its overall hash value Among them, S i,j is a set of data blocks, where i = 1, 2, 3... b2 and j = 1, 2, 3... b1, and the calculated overall hash value is stored in the blockchain summary node; The blockchain aggregation node downloads all the data uploaded to the blockchain through distributed storage. The project management personnel query the required data blocks in the blockchain by inputting the identity information of the on-site supervision personnel, the time of uploading data, and the location information of the on-site supervision personnel. Execute a fault monitoring strategy for each node in the network transmission path to determine whether the node is faulty. If a faulty node is detected, execute a multi-level redundant backup strategy and use the backup node to replace the faulty node. Use AI intelligence to detect abnormal network behaviors for each node in the network transmission path, and execute a hierarchical disposal strategy for the abnormal network behaviors to maintain the security of the network transmission path. Record this session using the blockchain log.

2. The information transmission method based on the engineering supervision platform according to claim 1, characterized in that The step of according to the bandwidth and packet loss rate, executing an adaptive traffic control strategy to adjust the encryption intensity of the construction data includes: Set the bandwidth weight factor β B ; Set the packet loss rate weight factor β L ; Obtain the maximum bandwidth B of the data transmitted by the project supervision platform max ; Execute the following formula to calculate the encryption intensity α(B, L); Among them, β B + β L = 1, β B ≥ 0, β L ≥ 0.

3. The information transmission method based on the engineering supervision platform according to claim 1, characterized in that Obtaining the construction data uploaded by on-site supervisors, implementing a classification compression preprocessing strategy, and performing classification compression and robust coding on the construction data, including: The construction data is divided into categories of project progress, quality control, cost management, and safety management; For any category of construction data, obtain the compression algorithm matched by the engineering supervision platform for this category of construction data, and obtain the compression ratio η of this compression algorithm; Obtain the file D0 of the construction data; Implement the classification compression preprocessing strategy and compress the construction data to D1 = D0×η; Robust coding: Obtain the standard parity-check matrix H; Decompose the parity-check matrix H using Gaussian elimination to obtain the first matrix P; Among them, P T is the transpose of the first matrix P, and I r is an r×r identity matrix; Calculate the generating matrix G = [I k | P], where I k is the k×k identity matrix; Calculate the coded word G×D1 after robust coding.

4. The information transmission method based on an engineering supervision platform according to claim 1, wherein According to the master key and session key, implementing a key update strategy to update the master key and session key, including: When on-site supervisors upload construction data to the engineering supervision platform each time, generate the session key for this session according to the current master key, specifically: Obtain the session ID of this session; Obtain the current master key k0; Use the HMAC algorithm to calculate the session key k1 = HMAC(k0, ID) for this session; Set the master key update interval Δt; Obtain the time t0 when the master key was last updated; Update the master key at the time t0 + Δt, and use the PRNG algorithm to obtain the updated master key k′0 = PRNG(k0, t0 + Δt).

5. The information transmission method based on the engineering supervision platform according to claim 3, wherein According to the execution key and construction data, implementing a two-layer encryption strategy to generate a digital signature, and encrypting the construction data, execution key, and digital signature, including: Obtain the coded word obtained after robust coding; Obtain the private key of the on-site supervisor, and use the private key to perform asymmetric encryption on the coded word to obtain a digital signature; Use the execution key to perform symmetric encryption on the coded word; Obtain the public key of the project manager, and use the public key to perform asymmetric encryption on the execution key.

6. The information transmission method based on the engineering supervision platform according to claim 1, wherein Implementing a fault monitoring strategy for each node in the network transmission path to determine whether the node is faulty, including: For each node in the network transmission path, set the health status L of the node; Obtain the resource utilization rate U of the node; Obtain the response time R of the node; Obtain the load level V of the node; Execute the following formula to calculate L; L = w1×U + w2×R + w3×V, where w1, w2, and w3 are the weights of resource utilization rate, response time, and load level respectively, and w1 + w2 + w3 = 1; Set the health threshold θ; Compare the health status of the node with the health threshold; If L≥θ, the node is healthy; If L<θ, the node is faulty.

7. The information transmission method based on the engineering supervision platform according to claim 6, characterized in that, If a faulty node is detected, implementing a multi-level redundant backup strategy to replace the faulty node with a backup node, including: Set the backup radius; Obtain the node detected with a fault. The circle with the position of the faulty node as the center and the backup radius as the radius is denoted as the backup area; Obtain all the idle nodes in the backup area, calculate the distances from the faulty node, and sort them according to the distances. Select the top 3 idle nodes, denoted as the first node, the second node, and the third node respectively; Activate the first node to replace the faulty node; Notify the second node to start the high-availability HA cluster; Set the third node to enter the hot standby state.

8. The information transmission method based on the engineering supervision platform according to claim 1, characterized in that For each node in the network transmission path, use AI intelligence to detect abnormal network behaviors and execute a hierarchical disposal strategy to maintain the security of the network transmission path, including: Detect abnormal network behaviors based on the joint model of Transformer and Autoencoder: Transformer encoding module: Extract the feature X of the node transmission traffic feature , use the embedding layer to map the feature into a high-dimensional space, and the multi-head attention mechanism extracts the key temporal features: Among them, Q softmax , K softmax , d softmax , T softmax , V softmax are the query, key, value vector dimension, time step, and value respectively; Capture high-dimensional features of global temporal dependencies; Autoencoder decoding module: Obtain high-dimensional features; Use a fully connected layer to restore the high-dimensional features to the original space; Minimize the reconstruction error: where N feature is the number of features, and X′ feature [i] is the reconstructed feature; Abnormal detection module: Calculate the mean μ of the features of the node transmission traffic extracted feature and the standard deviation σ feature ; Calculation Be recorded as an abnormal score; Set an abnormal threshold. If the abnormal score ≧ the abnormal threshold, the network behavior is abnormal; When an abnormal network behavior is detected, generate an alarm message and upload the alarm message to the security management center of the project supervision platform; Record the moment when the abnormal network behavior is detected as the first moment; Set an abnormal alarm period; Record the moment after the first moment at an interval of the alarm period as the second moment; Detect whether the abnormal network behavior ends at the second moment. If the abnormal network behavior has not ended, automatically terminate the abnormal network behavior.

9. A system for implementing the information transmission method based on an engineering supervision platform according to any one of claims 1 to 8, characterized in that, Including: Session management module, generating and maintaining the session between on-site supervisors and project managers; Network monitoring and traffic control module, monitoring the bandwidth and packet loss rate, and dynamically adjusting the encryption intensity; Data classification and compression module, classifying construction data by category and executing the corresponding compression algorithm; Key management module, generating and updating the main key and session key, and distributing the execution key; Data encryption and signature module, implementing double-layer encryption and digital signature to ensure data security; Data transmission and fault handling module, managing encrypted data transmission, monitoring node health, and executing fault redundancy backup; Abnormal behavior detection and handling module, identifying abnormal access and unknown IPs, and executing a hierarchical disposal strategy; Blockchain log recording module, recording session logs to ensure data immutability; User privilege management module, controlling user privileges to ensure data access security; Security management center, handling network anomalies and fault alarms, and providing system-level security guarantees.

Citation Information

Patent Citations

  • Construction data storage sharing method and system based on BIM + GIS

    CN118965452A

  • Data encryption method and device, computer program product and data encryption system

    CN119449479A