A multi-level and multi-line ship lock control method and system based on encryption applications

Through the dual verification of distributed fault tolerance method and encrypted inspection matrix, the problem of low communication security between the cascade lock and the centralized control center is solved, and high security and high compatibility data transmission is achieved, and malicious tampering and increased hardware costs are avoided.

CN119892351BActive Publication Date: 2025-07-01GUANGXI XIJIANG DEV & INVESTMENT GRP CO LTD SHIP LOCK OPERATION MANAGEMENT BRANCH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510003050.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-07-01
Estimated Expiration
2045-01-02

AI Technical Summary

Technical Problem

In the prior art, the communication security between the cascade lock and the centralized control center is low, there is a risk of data leakage and malicious tampering, and the cost of increasing the hardware module is high and the compatibility is poor.

Method used

The distributed fault tolerance method is used to encrypt and transmit communication data, and the data channels between multiple cascade locks are initially checked and secondary confirmation is performed. The dedicated physical channels between multi-line locks are used for data verification, and the instruction encryption inspection matrix is ​​generated for double checking to ensure the correctness and security of the instructions.

Benefits of technology

Improve communication security, prevent malicious tampering, reduce hardware costs, enhance system compatibility and data transmission reliability, and avoid malicious consequences caused by tampering with instructions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892351B_ABST
    Figure CN119892351B_ABST
Patent Text Reader

Abstract

The present invention relates to a multi-step and multi-line ship lock control method and system based on an encrypted application. The method uses a distributed fault tolerance method to encrypt and transmit communication data, corrects the data issued by the centralized control center through the data channels between multi-step ship locks, completes the preliminary verification of the data, and uses the dedicated physical channels between multi-line ship locks for secondary confirmation of the data to ensure the correctness of the command data issued by the centralized control system. Finally, the ship lock receiving the data of the centralized control system responds with a distributed data response to complete the closed-loop of data transmission. Among them, when the centralized control center issues data instructions, the data is encrypted and transmitted in a distributed manner, and the controlled ship lock double-verifies the data. Compared with the prior art, the present invention has the advantage of high security, solves the problem that the controlled point cannot be timely separated from the control of malicious nodes, and prevents malicious consequences caused by the tampering and intrusion of the command information of the centralized control center.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication security control between cascade locks and a centralized control center, and particularly to a control method and system for multi-cascade and multi-line locks based on encryption applications. Background Art

[0002] There are generally three communication methods between cascade locks and a centralized control center: dedicated line communication, public network communication, and information service provider network dedicated line communication.

[0003] To achieve centralized control of inland river locks, it is first necessary to ensure the security of information communication between the locks and the centralized control center. Since the cascade locks in the basin and the centralized control center are generally far apart, and the distance between the locks far away and the centralized control center can be up to several hundred kilometers, building a dedicated data transmission channel is expensive. Although public network communication is cheap and convenient to use, its security is low. Considering comprehensively, the lock centralized control system usually uses the network dedicated line of a communication service provider to achieve communication between the locks and the centralized control center.

[0004] Using the network dedicated line of a communication service provider for communication between the locks and the centralized control center has wide applicability in China. Although using information service provider network dedicated line communication achieves the effect of centralized control, its disadvantages are as follows: Although the physical communication link within the lock centralized control center uses a dedicated line, which can ensure isolation from other data streams, the physical communication link outside the centralized control center uses the public physical channel of the communication service provider, and only technologies such as VLAN are used in the router to segment data, and complete data dedicated line dedicated use is not achieved on the physical channel. Since data is transmitted through the public physical channel of the communication service provider, there are uncontrollable risks such as external intrusion and data leakage.

[0005] Currently, the processing methods for solving the transmission risk of data transmitted through the information service provider network dedicated line are as follows: One method is to install encryption and decryption devices between the centralized control center and the locks to achieve encrypted data transmission. Although this method achieves a good display effect, its disadvantages are as follows: If the data in the centralized control center is stolen, there is a risk that all communication data can be reverse decrypted, and there is a risk that the control instructions of the centralized control center are stolen and modified; Another method is to add a data security module to the on-site control system of the locks, and then the asymmetric key method can be used to achieve data communication and ensure the security of data communication. The disadvantage is that a data security module needs to be added on-site, which has a high cost, and at the same time, due to the diversity of the on-site PLC control system, the compatibility requirements for the data security module are relatively high.

[0006] No matter which method is adopted, it is closely related to data encryption. Therefore, a data encryption transmission method with high security and strong compatibility is needed for multi-cascade and multi-line lock control. Summary of the Invention

[0007] The object of the present invention is to provide a multi - cascade and multi - line ship lock control method and system based on encryption applications.

[0008] The object of the present invention can be achieved through the following technical solutions:

[0009] A multi - cascade and multi - line ship lock control method based on encryption applications. This method uses a distributed fault - tolerance method to encrypt and transmit communication data, corrects the data sent by the centralized control center through the data channels between multi - cascade ship locks to complete the preliminary verification of the data, and uses the dedicated physical channels between multi - line ship locks for secondary confirmation of the data to ensure the correctness of the command data sent by the centralized control system. Finally, the ship lock receiving the data from the centralized control system responds with a distributed data response to complete the closed - loop of data transmission. Among them, when the centralized control center issues a data command, the data is encrypted and transmitted distributively, and the controlled ship lock double - checks the data.

[0010] The data transmission process of the method includes the following steps:

[0011] Step 1) Initialize the operation process steps of the cascade multi - line ship lock, realize the mutual storage of operation data between multi - line ship locks, generate an instruction encryption check matrix, and realize the safe interaction of mutual verification and mutual locking of control instructions between multi - line ship locks;

[0012] Step 2) The centralized control center broadcasts a control pre - instruction and sends it to all slave nodes;

[0013] Step 3) After the multi - line ship locks of the cascade where the controlled ship lock is located and the cascade ship locks adjacent to all controlled ship locks receive the pre - instruction and verify it correctly, they send a response message to the centralized control center;

[0014] Step 4) The centralized control center determines whether the response message times out. If it times out, it returns to execute Step 3). If the timeout exceeds the preset number of times, no formal instruction is issued, and the control right of the controlled ship lock is transferred to the local area. If it does not time out, then execute Step 5);

[0015] Step 5) The centralized control center determines an adjacent cascade ship lock of a controlled ship lock as a data verification point according to the response message of the slave node;

[0016] Step 6) The centralized control center sends a control instruction to the data verification points of the controlled ship lock cascade and its adjacent cascade ship locks;

[0017] Step 7) After receiving the control instruction, the controlled ship lock sends a verification request to the data verification point of the adjacent cascade ship lock and the ship locks of the same cascade;

[0018] Step 8) The data verification points of adjacent lock chambers of the same cascade and the lock chambers of the same cascade send verification information to the controlled lock chamber. The controlled lock chamber verifies the correctness of the received verification information. If the verification is correct, proceed to Step 9); if the verification is incorrect, return to Step 2), and at the same time identify the centralized control center as a low-credibility node. If the number of times the centralized control center is continuously identified as a low-credibility point within the same time period exceeds the preset value, transfer the control right of the controlled lock chamber to the local area;

[0019] Step 9) The controlled lock chamber and the lock chambers of the same cascade perform a correctness verification of the control instructions. The lock chambers of the same cascade verify the instructions to be output by the controlled lock chamber according to the instruction encryption verification matrix, and verify the security of the instructions and the correctness of the control process. If the verification is correct, proceed to Step 10); if the verification is incorrect, the controlled lock chamber does not execute the instruction and proceeds to Step 11);

[0020] Step 10) The controlled lock chamber outputs control information according to the control instructions of the centralized control center;

[0021] Step 11) The controlled lock chamber sends the instruction execution status, which is whether the instruction is executed or not, to the centralized control center and all secondary nodes participating in the process. If the control instruction is executed, the lock chambers of the same cascade update the control chain points of the instruction encryption verification matrix.

[0022] In the above Step 1), an instruction encryption verification matrix is generated among the multi-line lock chambers of the cascade according to the lock operation control process and the interlock and blocking information, so as to privately verify the correctness of the instructions through the internal communication dedicated line.

[0023] The method for generating the instruction encryption verification matrix is as follows:

[0024] Initialize and generate the main blocking condition verification matrix of the controlled lock chamber and the safety condition verification matrix of another lock chamber of the same cascade. Both the main blocking condition verification matrix of the controlled lock chamber and the safety condition verification matrix of another lock chamber of the same cascade are fixed data and the data is not publicly disclosed;

[0025] Randomly generate a first data matrix and a second data matrix based on the on-site clock device. The size of the first data matrix is the same as that of the main blocking condition verification matrix of the controlled lock chamber, and the size of the second data matrix is the same as that of the safety condition verification matrix of another lock chamber of the same cascade;

[0026] Multiply the first data matrix by the main blocking condition verification matrix of the controlled lock chamber to obtain the instruction encryption verification matrix of the controlled lock chamber; multiply the second data matrix by the safety condition verification matrix of another lock chamber of the same cascade to obtain the instruction encryption verification matrix of another lock chamber of the same cascade.

[0027] The first element in each row of the main locking condition verification matrix of the controlled lock represents different operating states of the lock operation. The elements other than the first element in each row represent the operation locking conditions corresponding to the operating state of the first element. In the operating state corresponding to the first element in the row, when all the operation locking conditions in the row are met, the main locking condition verification matrix of the controlled lock opens the operation instruction outlet for execution.

[0028] The first element in each row of the safety condition verification matrix of the other lock in the same cascade represents different operating states of the lock operation. The elements other than the first element in each row represent the operable operations, interlocks, and safety conditions corresponding to the operating state of the first element. In the operating state corresponding to the first element in the row, when all the operable operations, interlocks, and safety conditions in the row are met, the safety condition verification matrix of the other lock in the same cascade sends an allow - execution command to the main locking condition verification matrix of the controlled lock.

[0029] In step 5), a lock in the adjacent cascade of the controlled lock is randomly determined as the data verification point.

[0030] In step 9), the lock in the same cascade verifies the correctness of the verification instruction of the matrix according to its own non - publicly disclosed instruction, and uses an internal dedicated network for the transmission of verification information, without relying on external communication.

[0031] After the control right of the controlled lock is transferred to the local area, it does not accept the instructions of the centralized control center. After the cause of the fault is manually investigated, it is then re - incorporated into the centralized control system.

[0032] A multi - cascade multi - line lock control system based on encryption application is used to implement the method as described above.

[0033] Compared with the prior art, the present invention has the following beneficial effects:

[0034] (1) Since the relationship between the lock and the centralized control center is a controlled - and - controlling relationship, the present invention introduces a reputation system for the centralized control center, performs specific processing on the high - reputation and low - reputation centralized control centers, solves the problem that the controlled point cannot be timely separated from the control of malicious nodes, and prevents malicious consequences caused by the tampering and intrusion of the instruction information of the centralized control center.

[0035] (2) The data verification points determined by the present invention are random. The correctness of the data not only depends on the encryption and decryption facilities and algorithms of the centralized control center and the controlled node, but also the data will be distributed for verification to reach a consensus on the correctness of the instruction.

[0036] (3) Since the multi-line ship locks of the same flight can each collect the control process status of the other, they can each generate an encrypted verification matrix for commands not made public, perform safety, locking, and interlocking safety verifications on the commands to be executed by the other, and transmit the verification results through the private network communication between the ship locks of the same flight. This can ensure that even if the controlled ship lock receives tampered data commands, the execution of the tampered commands can still be carried out in accordance with on-site safety without causing harm to the ships passing through the lock and the lock facilities.

[0037] (4) The data verification and encryption between the nodes of the present invention adopt mature algorithms and have high reliability. The instruction safety verification between the ship locks of the same flight adopts a private algorithm to verify the final correctness of the control instructions, which can effectively avoid the malicious consequences caused by human misoperations and tampering of control instructions.

[0038] (5) The present invention does not require adding hardware at the controlled end. It uses the private dedicated communication channel between the multi-line ship locks to check the correctness of the instructions and has high compatibility. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 is the flowchart of the method of the present invention;

[0040] Figure 2 is the flowchart of the instruction issuance of the centralized control center of the present invention;

[0041] Figure 3 is the schematic diagram of the instruction correctness verification between the multi-line ship locks of the same flight of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] The present invention will be described in detail below with reference to the drawings and specific embodiments. This embodiment is implemented on the premise of the technical solution of the present invention, and gives detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to the following embodiments.

[0043] This embodiment provides a multi-cascade multi-line ship lock control method based on encryption applications. This method uses a distributed fault tolerance method to encrypt and transmit communication data, corrects the data issued by the centralized control center through the data channel between the multi-cascade ship locks, completes the preliminary verification of the data, and uses the dedicated physical channel between the multi-line ship locks for secondary confirmation of the data to ensure the correctness of the instruction data issued by the centralized control system. Finally, the ship lock receiving the data of the centralized control system responds with a distributed data response to complete the closed-loop of data transmission; among them, when the centralized control center issues data instructions, the data is encrypted and transmitted in a distributed manner, the controlled ship lock double-checks the data, does not require adding hardware at the controlled end, and uses the private dedicated communication channel between the multi-line ship locks to check the correctness of the instructions, with high security.

[0044] Specifically, as Figure 1 shown, the data transmission process of this method includes the following steps:

[0045] Step 1) Initialize the operation process steps of the cascaded multi-line ship lock, implement mutual storage of operation data between multi-line ship locks, generate an instruction encryption verification matrix, and achieve secure interaction of mutual verification and mutual locking of control instructions between multi-line ship locks;

[0046] Step 2) The centralized control center broadcasts a control pre-instruction and sends it to all slave nodes;

[0047] Step 3) After the multi-line ship locks of the cascade where the controlled ship lock is located and the adjacent cascade ship locks of all controlled ship locks receive the pre-instruction and verify it correctly, they send a response message to the centralized control center;

[0048] Step 4) The centralized control center determines whether the response message times out. If it times out, return to execute Step 3). If it times out three times, do not issue a formal instruction, and transfer the control right of the controlled ship lock to the local area. If it does not time out, execute Step 5);

[0049] Step 5) The centralized control center randomly determines an adjacent cascade ship lock of a controlled ship lock as a data verification point according to the response message of the slave node;

[0050] Step 6) The centralized control center sends a control instruction to the data verification point of the controlled ship lock cascade and its adjacent cascade ship locks;

[0051] Step 7) After receiving the control instruction, the controlled ship lock sends a verification request to the data verification point of the adjacent cascade ship lock and the ship locks of the same cascade;

[0052] Step 8) The data verification point of the adjacent cascade ship lock and the ship locks of the same cascade send verification information to the controlled ship lock. The controlled ship lock verifies the correctness of the received verification information. If the verification is correct, execute Step 9); if the verification is incorrect, return to execute Step 2), and at the same time identify the centralized control center as a low-reputation node once. If the centralized control center is continuously identified as a low-reputation point three times within the same time period, transfer the control right of the controlled ship lock to the local area;

[0053] Step 9) Conduct a correctness verification of the control instruction between the ship locks of the same cascade of the controlled ship lock. The ship locks of the same cascade verify the instruction to be output by the controlled ship lock according to the instruction encryption verification matrix, verify the security of the instruction and the correctness of the control process. If the verification is correct, execute Step 10); if the verification is incorrect, the controlled ship lock does not execute the instruction and executes Step 11);

[0054] Step 10) The controlled ship lock outputs control information according to the control instruction of the centralized control center;

[0055] Step 11) The controlled lock sends the instruction execution status to the centralized management and control center and all sub-nodes participating in the process. The instruction execution status is whether the instruction is executed or not. If the control instruction is executed, the instruction encryption verification matrix control points of the same cascade locks are updated.

[0056] In Step 1), an instruction encryption verification matrix is generated among the cascade multi-line locks according to the lock operation control process and the interlock and blocking information, so as to privately verify the correctness of the instruction through the internal communication dedicated line.

[0057] In Step 5), the determined data verification points are random to ensure the security of communication verification.

[0058] In Step 7), the controlled lock synchronously requests other nodes to perform data verification, and the function is to synchronously verify the correctness of the instruction.

[0059] In Step 8), if the controlled lock determines that the centralized management and control center is a low-credibility point in the same time period, it directly transfers the control right to the local area and does not accept the instructions of the centralized management and control center, so as to ensure the high credibility of the main nodes participating in the control process.

[0060] In Step 9), the same-cascade locks verify the correctness of the instruction according to their own non-public instruction encryption verification matrix, and use the internal dedicated line network to transmit the verification information, without relying on external communication, to ensure the security of the final instruction output.

[0061] After the control right of the controlled lock is transferred to the local area, it does not accept the instructions of the centralized management and control center. After manually checking the cause of the failure, it is then re-incorporated into the centralized management and control system.

[0062] The above process steps are applicable to the multi-line multi-cascade locks in the basin, including that all locks in the basin participate in the verification of control instructions and the same-cascade locks execute private encryption matrix verification. Through distributed instruction verification and dual instruction verification, it is avoided that data is invaded and tampered with during the transmission in the public network. At the same time, the abnormal transfer measure of the control right is executed. When an instruction anomaly is found in the first time, the controlled lock is separated from the management and control of the management and control center and transferred to local control.

[0063] Figure 2 This is the flowchart of the instruction issuance of the centralized management and control center of the present invention, which completes the process of issuing the management and control instructions of the centralized management and control center to the controlled lock. Taking the multi-cascade multi-line locks in the basin as an example below, combined with Figure 2 The following instruction issuance process steps are described in detail:

[0064] In Figure 2 C represents the centralized management and control center, 1 represents the controlled lock, 2 represents another lock of the same cascade as the controlled lock, 3 represents the cascade lock adjacent to the controlled lock, and 4 represents another cascade lock adjacent to the controlled lock.

[0065] In the initialization step, 1 and 2 generate an instruction encryption verification matrix and confirm the matrix generation through internal communication between the two parties; then the centralized control center executes the pre-instruction step;

[0066] In the pre-instruction step, C sends pre-control instructions to 1, 2, 3, and 4, simultaneously receives feedback information from the nodes of 1, 2, 3, and 4, randomly selects 3 points as the data verification points of 1, and executes the formal instruction issuance step;

[0067] In the formal instruction issuance step, C sends formal execution instructions to 1, 2, and 3. After receiving the formal execution instructions, 1 executes the formal instruction verification step;

[0068] In the formal instruction verification step, 1 sends verification information to 2 and 3, and 2 and 3 feedback the verification results. If the instruction verification is correct, the same-step lock verification is performed; if the instruction verification is incorrect, 1 sends a message to C to reissue the instruction, and at the same time records C as a low-reputation node once. If C is recorded as a low-reputation node 3 times within the same time period, the control authority of 1 is switched to the local area, and it no longer receives instructions from C. After manual confirmation of the troubleshooting, it is included in the centralized control scope again;

[0069] In the same-step verification, 1 and 2 send control instructions to their respective instruction encryption verification matrices. The instruction correctness and security are verified through the private communication network between the respective instruction encryption verification matrices, and it is determined by the instruction encryption verification matrix of the controlled lock whether to execute the control instruction and the result is fed back to 1, and then the system executes the instruction response step;

[0070] In the instruction response step, 1 sends a message to C and 2 whether the instruction is executed, and the process ends.

[0071] As Figure 3 shown, the present invention utilizes the characteristics of having a private communication network between locks of the same step and the characteristics of the lock operation step process to generate an instruction encryption verification matrix for each lock to check the instructions to be executed to ensure whether the instructions are correct.

[0072] The lock passing operation can only normally execute two operations in a certain state. There are usually only 8 cyclic operations in the general rules of the lock passing operation. Using this special rule, a control verification matrix can be generated.

[0073] During initialization, the main locking condition verification matrix F() of the controlled lock and the safety condition verification matrix K() of another lock of the same step are generated. The F() and K() matrices are fixed data and will be solidified in the on-site control device during system initialization, and the matrix data is not publicly announced:

[0074]

[0075]

[0076] Among them, f 11 to f 81 represent 8 operating states of the lock operation. f i2 to f im represent the operation locking conditions of the lock in the f i1 state, such as conditions like prohibiting valve opening operation, prohibiting discontinuous operation, and prohibiting simultaneous operation of the lock gates in the same lock head. In the f i1 state, only when f i2 to f im conditions are all met, will F() open the execution operation instruction outlet.

[0077] k 11 to k 81 represent 8 operating states of the lock operation. k i2 to k im represent the operable operations, interlocks, and safety conditions of the lock in the k i1 state, such as operable devices, prohibiting simultaneous filling and emptying of the lock and the approach channel, prohibiting rapid filling and emptying of the lock during the dry season, activating the anti - ship - pinching system and detecting normal status, activating the anti - ship - crossing - line system and detecting normal status, activating the anti - collision device system and detecting normal status, etc. In the k i1 state, only when k i2 to k im conditions are all met, will K() send an execution permission command to F(), and the output instruction of F() will be officially output to the controlled device.

[0078] To ensure the security of data transmission, the on - site clock device will randomly generate data matrices S1() and S2(). The size of the S1() matrix is the same as that of the F() matrix, and the size of the S2() matrix is the same as that of the K() matrix. The values in the S1() and S2() matrices are all randomly generated positive - integer - type data. By multiplying the S1() matrix with the F() matrix, the F1() encryption matrix is obtained, and by multiplying the S2() matrix with the K() matrix, the K1() encryption matrix is obtained to ensure the security of the matrix data communication between the two parties. The data of the S1() and S2() matrices are sent to the two locks by the on - site clock device through the internal network.

[0079] After the control instruction verification of the controlled lock is correct, the instruction is sent to the instruction encryption verification matrix F1() of this lock. After receiving the control instruction, another lock at the same cascade sends the instruction to the instruction encryption verification matrix K1() of that lock. The F1() matrix verifies that the instruction meets the locking condition and opens the instruction outlet. After the K1() matrix verifies that the instruction meets the safety condition, it sends an execution permission command to F1(). After the F1() matrix obtains the operating condition of K1() after opening the instruction outlet, it will officially send a command to the controlled device. In this way, even if the data of the controlled lock is tampered with, through the mutual verification of the data between the locks at the same cascade, the security of the output instruction can still be guaranteed.

[0080] This embodiment also provides a multi-cascade multi-line lock control and management system based on encryption application for implementing the method described above.

[0081] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative labor. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field based on the concept of the present invention through logical analysis, reasoning, or limited experiments on the basis of the prior art should be within the protection scope determined by the claims.

Claims

1. A multi-level multi-line ship lock control method based on encryption application, characterized in that: The method uses a distributed fault-tolerant method to encrypt and transmit communication data, corrects the data sent by the centralized control center through the data channel between the multi-step ship locks, completes the preliminary verification of the data, and uses the dedicated physical channel between the multi-line ship locks to perform secondary confirmation of the data to ensure the correctness of the instruction data sent by the centralized control system. Finally, the ship locks that receive the data from the centralized control system respond to the distributed data to complete the closed loop of data transmission. When the centralized control center sends the data instruction, the data is distributed and encrypted for transmission, and the controlled ship locks perform double verification of the data. The data transmission process of the method comprises the following steps: Step 1) Initialize the operation flow steps of the cascade multi-line ship lock, realize the mutual storage of operation data between the multi-line ship locks, generate the instruction encryption verification matrix, and realize the safe interaction of mutual verification and mutual locking of control instructions between the multi-line ship locks; Step 2) The centralized control center broadcasts the control pre-instructions to all slave nodes; Step 3) After receiving the pre-instruction and verifying that it is correct, the multi-line ship lock of the cascade where the controlled ship lock is located and the adjacent cascade ship locks of all the controlled ship locks send a response message to the centralized control center; Step 4) The centralized control center determines whether the response message has timed out. If so, it returns to step 3). If the timeout exceeds the preset number of times, no formal instruction is issued, and the control of the controlled ship lock is transferred to the local area. If not, it executes step 5); Step 5) The centralized control center determines an adjacent cascade ship lock of the controlled ship lock as a data verification point according to the response message of the secondary node; Step 6) The centralized control center sends control instructions to the controlled lock step and its adjacent lock step data verification points; Step 7) After receiving the control instruction, the controlled ship lock sends a verification request to the data verification point of the adjacent cascade ship lock and the ship lock of the same cascade; Step 8) The data checkpoints of the adjacent cascade ship locks and the ship locks of the same cascade ship locks send check information to the controlled ship locks, and the controlled ship locks check the correctness of the received check information. If the check is correct, step 9) is executed; if the check is incorrect, the process returns to step 2) and the centralized control center is identified as a low-credibility node. If the number of consecutive identifications of the centralized control center as a low-credibility point in the same time period exceeds a preset value, the control of the controlled ship lock is transferred to the local site; Step 9) The correctness of the control instructions is checked between the controlled ship lock and the cascade ship lock. The cascade ship lock checks the instructions to be output by the controlled ship lock according to the instruction encryption check matrix to check the security of the instructions and the correctness of the control process. If the verification is correct, step 10) is executed; if the verification is incorrect, the controlled ship lock does not execute the instruction and step 11) is executed; Step 10) The controlled ship lock outputs control information according to the control instruction of the centralized control center; Step 11) The controlled ship lock sends the instruction execution status to the centralized control center and all the sub-nodes participating in the process. The instruction execution status is to execute or not execute the instruction. If the control instruction is executed, the control chain point of the instruction encryption inspection matrix is ​​updated at the same level ship lock.

2. A multi-level multi-line ship lock control method based on encryption application according to claim 1, characterized in that: In the step 1), the cascade multi-line ship locks generate a command encryption check matrix according to the ship lock operation control process and interlocking information, so as to privately check the correctness of the command through the internal communication line.

3. A multi-level multi-line ship lock control method based on encryption application according to claim 1, characterized in that: The method for generating the instruction encryption check matrix is: Initialize and generate a main locking condition check matrix of a controlled ship lock and a safety condition check matrix of another ship lock at the same level, wherein the main locking condition check matrix of the controlled ship lock and the safety condition check matrix of another ship lock at the same level are fixed data and the data are not disclosed to the public; Based on the on-site clock device, a first data matrix and a second data matrix are randomly generated, wherein the first data matrix has the same size as the main locking condition check matrix of the controlled ship lock, and the second data matrix has the same size as the safety condition check matrix of another ship lock at the same level; The first data matrix is ​​multiplied by the main locking condition check matrix of the controlled lock to obtain the command encryption check matrix of the controlled lock; the second data matrix is ​​multiplied by the safety condition check matrix of another lock of the same level to obtain the command encryption check matrix of another lock of the same level.

4. A multi-level multi-line ship lock control method based on encryption application according to claim 3, characterized in that: The first element of each row of the main locking condition check matrix of the controlled lock represents different operating states of the lock operation, and the elements of each row except the first element represent the operating locking conditions corresponding to the operating state of the first element. Under the operating state corresponding to the first element of the row, when all the operating locking conditions of the row are met, the main locking condition check matrix of the controlled lock opens the execution operation instruction exit.

5. The multi-level multi-line ship lock control method based on encryption application according to claim 3 is characterized in that: The first element of each row of the safety condition check matrix of another ship lock at the same level represents different operating states of the ship lock operation, and the elements of each row except the first element represent operable operations, interlocks and safety conditions corresponding to the operating state of the first element. Under the operating state corresponding to the first element of the row, when all operable operations, interlocks and safety conditions of the row are met, the safety condition check matrix of another ship lock at the same level sends an execution permission command to the main locking condition check matrix of the controlled ship lock.

6. A multi-level multi-line ship lock control method based on encryption application according to claim 1, characterized in that: In the step 5), a cascade ship lock adjacent to the controlled ship lock is randomly determined as a data verification point.

7. A multi-level multi-line ship lock control method based on encryption application according to claim 1, characterized in that: In the step 9), the same-level ship lock encrypts and checks the correctness of the instruction according to the instruction encryption check matrix which is not disclosed to the outside, and uses the internal dedicated line network to transmit the verification information without relying on external communication.

8. The multi-level multi-line ship lock control method based on encryption application according to claim 1 is characterized in that: After the control of the controlled ship lock is transferred to the local site, it will not accept instructions from the centralized control center and will be reintegrated into the centralized control system after the cause of the fault is manually found.

9. A multi-level multi-line ship lock control system based on encryption application, characterized in that: Used to implement the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Distributed management and control device suitable for continuous multistage ship locks

    CN112859732A

  • Method and system for controlling ship to pass through multistage hub ship lock based on big data deduction

    CN115629548A