Secure transmission method for port and wharf supply chain data

By subdividing data types, standardizing processing and encrypting data in the port terminal supply chain, combining hashing algorithms and support vector machines for data integrity verification, the problems of data transmission security and inefficiency in the existing technology are solved, and efficient and secure data transmission is achieved.

CN119921994AActive Publication Date: 2025-05-02SHANGHAI UNI SENTRY INTELLIGENT TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510033413.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-02
Estimated Expiration
2045-01-09

AI Technical Summary

Technical Problem

The existing technology lacks effective data classification and standardized processing in the data transmission of port terminal supply chain data, resulting in inefficient data processing, difficulty in dealing with complex network attacks, and lack of efficient data integrity verification mechanisms, which increases the security risks of port supply chain management.

Method used

By subdividing data types, generating data specification catalogs, standardizing data processing, using asymmetric encryption technology and software-defined networks for encryption and digital signatures, combining hashing algorithms and support vector machines for data integrity verification, ensuring the security and integrity of the data during transmission.

Benefits of technology

It significantly enhances the security of data transmission, reduces the risk of data tampering, improves the accuracy and reliability of data verification, reduces operational risks, and improves the efficiency and reliability of port operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119921994A_ABST
    Figure CN119921994A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data transmission, in particular to a port and wharf supply chain data secure transmission method, which comprises the following steps of: based on demand information of a port and wharf supply chain, subdividing data types including cargo tracking data and ship scheduling information, and identifying specific formats and processing rules of various types of data by classification; and generating a data specification directory. According to the method, the data packet is encrypted through the software defined network and the asymmetric encryption technology, the security of data transmission is remarkably enhanced, meanwhile, the risk that the data is tampered in the transmission process is reduced, additional symmetric encryption measures are taken for sensitive information fields, protection of important data is further enhanced, and the security of data transmission is improved. The data integrity verification is carried out by combining the support vector machine with the Hash algorithm, so that the data integrity is guaranteed, the accuracy and reliability of the data verification process are improved, the safety and efficiency of data transmission are enhanced, and the operation risk caused by data loss or damage is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data transmission, and in particular to a method for securely transmitting data in a port terminal supply chain. Background Art

[0002] The field of data transmission technology aims to develop and implement safe and efficient technical solutions to transmit data between different devices, systems and networks, ensure the security of data transmission, prevent unauthorized access, modification or leakage of data during transmission, improve transmission efficiency, reduce delays and increase data processing speed by optimizing network protocols and connection strategies, ensure the integrity of data during transmission, and prevent data loss or damage.

[0003] The purpose of the port terminal supply chain data security transmission method is to ensure the security of data during transmission in port supply chain management, prevent unauthorized access and tampering of data, protect data from malware and network attacks, improve the efficiency and reliability of port operations, reduce operational risks, and enhance the transparency and collaborative efficiency of the supply chain.

[0004] Existing technologies have significant deficiencies in data transmission security and efficiency improvement. The lack of effective data classification and standardized processing leads to inefficient data processing. Conventional data protection methods cannot fully cope with complex network attacks, making data vulnerable to unauthorized access and tampering during transmission. In addition, there is a lack of efficient data integrity verification mechanism, making it difficult to promptly detect and correct data modifications during transmission, increasing the security risks of port supply chain management. Summary of the invention

[0005] The purpose of the present invention is to solve the shortcomings of the prior art and to propose a method for secure transmission of port terminal supply chain data.

[0006] In order to achieve the above-mentioned purpose, the present invention adopts the following technical solution: a method for secure transmission of port terminal supply chain data, comprising the following steps: Step 1: Based on the demand information of the port terminal supply chain, subdivide the data types, including cargo tracking data and ship scheduling information, and generate a data specification catalog by classifying and identifying the specific format and processing rules of each type of data; Step 2: Based on the data specification directory, standardize the various types of data received, and encapsulate and integrate the data content in a unified format, package them into units that meet the standards, and obtain standardized data packets; Step 3: Encrypt the standardized data packet using asymmetric encryption technology, generate a key pair, and digitally sign the data packet using software-defined networking to verify the source and integrity of the data and generate an encrypted signature data packet; Step 4: Based on the encrypted signature data packet, additionally encrypt the fields containing sensitive information, use a symmetric encryption algorithm to encrypt the payment information and user identity, improve the protection level of sensitive data, and create a sensitive data protection package; Step 5: Use a hash algorithm combined with a support vector machine to hash the encrypted signature data packet, calculate the hash value and append it to the end of the data packet to generate an integrity verification data packet; Step 6: Send an integrity verification data packet through the network, recalculate the hash value of the data packet and compare it with the original hash value to confirm that the data has not been tampered with, decrypt and perform security checks on the data packet content, and obtain a data reception report; Step 7: Based on the results of the data reception report, evaluate the security of the data, confirm that the data is accepted, enter all verified data, complete data integration and storage, and form an access status confirmation record.

[0007] As a further solution of the present invention, the specific steps of generating the data specification directory are: Based on the port terminal supply chain demand information, collect demand information on cargo tracking and ship scheduling, record the types of data required and the frequency of use in detail, analyze the flow path of data in the supply chain, and generate demand analysis reports; Based on the demand analysis report, design data formats and processing rules, set JSON format for cargo tracking data, set XML format for ship scheduling information, and specify corresponding data processing processes to obtain data formats and process guidelines; Through data format and process guidelines, create a comprehensive document containing all data classification, format and processing rules to ensure consistency and standardization of data processing and generate a data specification catalog; The data specification directory includes data classification identification, data format definition and data processing rules.

[0008] As a further solution of the present invention, the specific steps of generating the standardized data packet are: Based on the data specification directory, format the data, convert the received text into a code, process the image in a unified format, compress the video data, and generate a formatted data set; Adopt formatted data sets to integrate all data types, use a unified data encapsulation format to integrate different data together, manage and transmit them in a unified manner, and obtain a data integration package; Through data integration packages, data is packaged using a unified data transmission protocol to generate standardized data packets; The standardized data packet includes encapsulated text data, image files, video streams and other multimedia elements.

[0009] As a further solution of the present invention, the specific steps of generating the encrypted signature data packet are: Based on the standardized data packet, initialize the key generation process, configure independent public keys and private keys for each data type, and generate a key configuration record; Based on the public key in the key configuration record, encrypt each item of data in the standardized data packet to generate an encrypted data set; Based on the encrypted data set, a software defined network is used to digitally sign each data packet using a corresponding private key to generate an encrypted signature data packet; The encrypted signature data includes a public key for decryption, encrypted data content, and a digital signature for verifying data integrity.

[0010] As a further solution of the present invention, the initialization key generation process specifies a key length of 2048 bits to ensure strong encryption. For different data types, keys of different strengths are configured according to the sensitivity level of the data. When key generation fails, the error status will be recorded and a security alarm will be triggered. The key generation process will be retried up to three times. If failures continue, the service will be suspended and the administrator will be notified to intervene.

[0011] As a further solution of the present invention, the specific steps of generating the sensitive data protection package are: Based on the encrypted signature data packet, identifying and marking data fields containing sensitive information, such as payment information and personal identity information, in preparation for subsequent encryption, and generating a sensitive information marking list; Using a unified symmetric encryption key, encrypt the sensitive data field according to the sensitive information tag list to generate an encrypted sensitive information set; Integrate the encrypted sensitive information set with the original encrypted signature data packet to ensure that all sensitive information is protected by an additional layer of protection, maintain the security and privacy of data transmission, and generate a sensitive data protection package; Among them, the sensitive data protection includes double-encrypted payment information, encrypted user identity data and other sensitive information fields.

[0012] As a further solution of the present invention, the specific steps of generating the integrity verification data packet are: Based on the encrypted signature data packet, hash generation is performed, and in combination with a support vector machine, an independent hash value calculation is performed on the content of each data packet to obtain an independent hash value set; Based on the independent hash value set, the hash value of each data packet is bound to its data content and attached to the end of each data packet to generate a bound hash data packet; Integrate the binding hash data packets into a unified data set, including all hashed data packets, to generate an integrity verification data packet; The integrity verification data packet includes a hash value of the data packet, original data content, and a hash algorithm type used for verification.

[0013] As a further solution of the present invention, the support vector machine is according to the formula: , in: is the decision function, is the input data point, is the support vector, For the The class labels of the data points, For the The Lagrange multiplier of the data points is, is the adjustment coefficient of the kernel function, is the kernel function, is the linear adjustment coefficient of the input data point, is the bias term.

[0014] As a further solution of the present invention, the specific steps of generating the data reception report are: Based on the integrity verification data packet, a secure network channel is configured, the data packet is serialized and sent to a predetermined network address, and the sending status of each packet is monitored during the operation to ensure the transmission efficiency and security of the data and obtain a data transmission record; Based on the data transmission record, a hash value comparison program is started to recalculate the hash value of each received data packet and compare it with the hash value bound before transmission to verify the data integrity and non-tampering of each packet and generate a hash verification record; Based on the hash verification record, if the hash values ​​of all data packets match, the data content is decrypted and a security check is performed, the security status of the data is reviewed and recorded, and finally all the reception and verification details are collated to generate a data reception report; The data reception report includes the hash value verification result, the decryption status of the data packet and the security check details after reception.

[0015] As a further solution of the present invention, the specific steps of generating the access status confirmation record are: Based on the data reception report, the verification results in the reception report are analyzed one by one, the data packet records marked as passed are extracted, and the status of the data packet is confirmed by checking the attached security indicators to generate a data security assessment list; Based on the data security assessment list, perform a database entry operation on each data packet marked as passed, implement data storage by allocating storage paths, adding classification tags, and creating indexes, and generate a data entry log; Based on the data entry log, the entered data records are integrated, the contents of multiple data sources are archived uniformly, the database status is updated and backed up, and an access status confirmation record is generated; The access status confirmation record includes the final confirmation of data access, system entry results and data storage status.

[0016] Compared with the prior art, the advantages and positive effects of the present invention are: 1. In this invention, the data packets are encrypted by software-defined networking and asymmetric encryption technology, which significantly enhances the security of data transmission and reduces the risk of data being tampered with during transmission. Additional symmetric encryption measures are taken for sensitive information fields, further strengthening the protection of important data. 2. In the present invention, the data integrity verification is performed by combining the support vector machine with the hash algorithm, which ensures the integrity of the data, improves the accuracy and reliability of the data verification process, enhances the security and efficiency of data transmission, and reduces the operational risks caused by data loss or damage. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 It is a schematic diagram of the main steps of the present invention. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.

[0019] See also Figure 1 The present invention provides a technical solution: a method for securely transmitting data from a port terminal supply chain, comprising the following steps: Step 1: Based on the demand information of the port terminal supply chain, subdivide the data types, including cargo tracking data and ship scheduling information, and generate a data specification catalog by classifying and identifying the specific format and processing rules of each type of data; Step 2: Based on the data specification directory, standardize the various types of data received, and use a unified format to encapsulate and integrate the data content, package it into units that meet the standards, and obtain a standardized data package; Step 3: Use asymmetric encryption technology to encrypt the standardized data packet, generate a key pair, and use software-defined networking to digitally sign the data packet to verify the source and integrity of the data and generate an encrypted signature data packet; Step 4: Based on the encrypted signature data packet, additional encryption is performed on the fields containing sensitive information, and the payment information and user identity are encrypted using a symmetric encryption algorithm to increase the protection level of sensitive data and create a sensitive data protection package; Step 5: Use the hash algorithm combined with the support vector machine to hash the encrypted signature data packet, calculate the hash value and append it to the end of the data packet to generate an integrity verification data packet; Step 6: Send an integrity verification data packet through the network, recalculate the hash value of the data packet and compare it with the original hash value to confirm that the data has not been tampered with, decrypt and perform security checks on the data packet content, and obtain a data reception report; Step 7: Based on the results of the data reception report, evaluate the security of the data, confirm that the data has been accepted, enter all verified data, complete data integration and storage, and form an access status confirmation record.

[0020] The specific steps to generate a data specification directory are: Based on the port terminal supply chain demand information, collect demand information on cargo tracking and ship scheduling, record the types of data required and the frequency of use in detail, analyze the flow path of data in the supply chain, and generate demand analysis reports; Based on the demand analysis report, design data formats and processing rules, set JSON format for cargo tracking data, set XML format for ship scheduling information, and stipulate the corresponding data processing process to obtain data format and process guidelines; Through data format and process guidelines, create a comprehensive document containing all data classification, format and processing rules to ensure consistency and standardization of data processing and generate a data specification catalog; Based on the demand information of the port terminal supply chain, collect the demand information on cargo tracking and ship scheduling, record the data types and usage frequency in detail, use the data flow analysis tool, the parameters include data input point and output point, the data input point receives cargo tracking and ship scheduling information, the output point summarizes the data to the center, map the flow path of the data in the supply chain, and generate a demand analysis report; Based on the demand analysis report, design data format and processing rules, set cargo tracking data in JSON format, operations include defining data structure, involving cargo ID, location and timestamp, using key-value pair storage, ship scheduling information is set in XML format, operations include defining data nodes, involving ship ID, estimated arrival time and cargo type, using elements and attributes to represent data, and specifying data processing procedures, including data validation scripts, parameters involving data integrity rules and format consistency rules, data integrity rules ensure that all fields are filled, format consistency rules ensure that data conforms to JSON or XML specifications, and obtain data format and process guidelines; Through the data format and process guidelines, create a comprehensive document containing all data classification, format and processing rules. Use a document generation tool with parameters including document templates and content indexes. The document template is based on the data format and process guidelines. The content index is used to quickly access the content of each part to ensure the consistency and standardization of data processing and generate a data specification catalog; Among them, the data specification directory includes data classification identification, data format definition and data processing rules.

[0021] The specific steps to generate a standardized data package are: Based on the data specification directory, data is formatted, the received text is converted into code, images are processed in a unified format, video data is compressed, and a formatted data set is generated; Adopt formatted data sets to integrate all data types, use a unified data encapsulation format to integrate different data together, manage and transmit them in a unified manner, and obtain a data integration package; Through data integration packages, data is packaged using a unified data transmission protocol to generate standardized data packets; Based on the data specification directory, data is formatted and the received text is converted into UTF-8 encoding format. The operation includes converting text in ASCII or other encoding formats into UTF-8 to ensure the compatibility of text between different systems. The image is processed in a unified format. The JPEG format is used. The operation includes converting images in PNG, BMP and other formats into JPEG to reduce storage space and unify image processing standards. The video data is compressed. The H.264 encoding is used. The operation includes reducing the bit rate and resolution of the video to reduce transmission bandwidth and storage requirements, and generating a formatted data set. Adopt formatted data sets, integrate all data types, and use a unified data encapsulation format to integrate different data together. Specifically, the JSON format is adopted. The operation includes encapsulating text, image links, and video links into JSON objects to ensure structured storage and easy processing of data, and to achieve unified management and transmission to obtain a data integration package. Through the data integration package, the data is packaged using a unified data transmission protocol, specifically the TCP / IP protocol. The operation includes encapsulating the data integration package into a TCP / IP data packet to ensure reliable transmission of the data in the network and generate a standardized data packet; Among them, standardized data packets include encapsulated text data, image files, video streams and other multimedia elements.

[0022] The specific steps to generate an encrypted signature data packet are: Initialize the key generation process based on the standardized data packet, configure independent public and private keys for each data type, and generate key configuration records; Based on the public key in the key configuration record, encrypt each data item in the standardized data packet to generate an encrypted data set; Based on the encrypted data set, a software-defined network is used to digitally sign each data packet with the corresponding private key to generate an encrypted signature data packet; Initialize the key generation process based on the standardized data packet, specifically using the RSA algorithm, with parameters including the key length set to 2048 bits, and operations including configuring independent public and private keys for each data type, generating and managing public and private key pairs respectively, ensuring the encryption independence and security of each type of data, and generating key configuration records; Based on the public key in the key configuration record, encrypt each data item in the standardized data packet, specifically using the AES algorithm, with parameters including the key length set to 256 bits, and operations including using the public key to perform AES encryption, ensuring the encryption quality and difficulty of the data packet, and generating an encrypted data set; Based on the encrypted data set, a software-defined network is used, and the SSL protocol is used for network transmission. The operation includes digitally signing each data packet with the corresponding private key to ensure the source verification and integrity check of the data packet, and generate an encrypted signature data packet; The encrypted signature data packet includes a public key for decryption, encrypted data content, and a digital signature for verifying data integrity.

[0023] Initialize the key generation process and specify a key length of 2048 bits to ensure strong encryption. For different data types, configure keys of different strengths according to the sensitivity level of the data. When key generation fails, the error status will be recorded and a security alert will be triggered. At the same time, the key generation process will be retried up to three times. Continuous failures will suspend the service and notify the administrator to intervene.

[0024] The specific steps to generate a sensitive data protection package are: Based on the encrypted signature data packet, identify and mark data fields containing sensitive information, such as payment information and personal identity information, in preparation for subsequent encryption, and generate a sensitive information marking list; Using a unified symmetric encryption key, encrypt sensitive data fields according to the sensitive information tag list to generate an encrypted sensitive information set; Integrate the encrypted sensitive information set with the original encrypted signature data package to ensure that all sensitive information is protected by an additional layer of protection, maintain the security and privacy of data transmission, and generate a sensitive data protection package; Based on the encrypted signature data packet, identify and mark data fields containing sensitive information, such as payment information and personal identity information, using data classification algorithms, specifically custom label assignment, operations include scanning keywords and data patterns in the data packet, automatically identifying sensitive information, preparing for subsequent encryption, and generating a sensitive information label list; Using a unified symmetric encryption key, encrypt the sensitive data field according to the sensitive information tag list, the parameters include setting the key length to 256 bits, and the operation includes encrypting the identified sensitive data using a preset symmetric key to ensure the security of the sensitive information and generate an encrypted sensitive information set; Integrate the encrypted sensitive information set with the original encrypted signature data packet, using a data merging tool, specifically a data packet integrator, the operation includes merging the encrypted sensitive information set with the encrypted signature data packet through a specified data structure, ensuring that all sensitive information is protected by an additional layer of protection, maintaining the security and privacy of data transmission, and generating a sensitive data protection package; Among them, sensitive data protection includes double-encrypted payment information, encrypted user identity data and other sensitive information fields.

[0025] The specific steps to generate an integrity verification data packet are: Hash generation is performed based on the encrypted signature data packet, and combined with the support vector machine, an independent hash value calculation is performed on the content of each data packet to obtain an independent hash value set; Based on the independent hash value set, the hash value of each data packet is bound to its data content and attached to the end of each data packet to generate a bound hash data packet; Integrate the bound hash data packets into a unified data set, including all hashed data packets, to generate integrity verification data packets; Hash generation is performed based on encrypted signature data packets. The parameters include data input as a complete data packet. The operation includes independent hash value calculation for the content of each data packet to ensure the uniqueness and integrity verification of the data. In combination with support vector machines, the LIBSVM library is specifically used for model training. The operation includes training the model to identify and verify the consistency of hash values ​​to obtain an independent hash value set. Based on the independent hash value set, the hash value of each data packet is bound to its data content, using a data binding tool, specifically a custom binding script, with parameters including the original content of the data packet and the hash value. The operation includes appending the hash value to the end of each data packet to ensure that the integrity of the data packet can be verified when it is received, and generating a bound hash data packet; Integrate the bound hash data packets into a unified data set using a data integration tool, specifically a collection integrator. The operation includes collecting all hashed data packets and combining them according to a specific data structure to ensure that the hash value of each data packet in the data set can be accessed and verified individually to generate an integrity verification data packet. The integrity verification data packet includes the hash value of the data packet, the original data content, and the type of hash algorithm used for verification.

[0026] Support vector machine, according to the formula: , in: is the decision function, is the input data point, is the support vector, For the The class labels of the data points, For the The Lagrange multiplier of the data points is, is the adjustment coefficient of the kernel function, is the kernel function, is the linear adjustment coefficient of the input data point, is the bias term; Execution process: Each supply chain data packet is processed through a cryptographic hash function to generate a unique hash value for each data packet and serve as the input data point , and then select the characterized packet hash values ​​from the known training dataset as support vectors , marked as safe or potential threat categories, the corresponding class labels Represents classification, Lagrange multiplier It is determined by solving an optimization problem during the model training phase, measuring the importance of each support vector in forming the decision boundary. The kernel function Adjustment factor Optimize through cross-validation method to improve the adaptability and classification accuracy of the model to new data, and input the linear adjustment coefficient of the data point It is also optimized to improve the responsiveness of the model to the linear characteristics of the data. Finally, the bias term Adjusting the decision boundary of the entire model effectively classifies each data packet as safe or potential threat, ensuring the security of port terminal supply chain data during transmission, ensuring the safe transmission of data, and improving the efficiency of predicting and responding to potential threats.

[0027] The specific steps to generate a data reception report are: Verify data packets based on integrity, configure secure network channels, serialize data packets and send them to a predetermined network address. Monitor the sending status of each packet during operation to ensure data transmission efficiency and security, and obtain data transmission records. Based on the data transmission record, the hash value comparison program is started to recalculate the hash value of each received data packet and compare it with the hash value bound before transmission to verify the data integrity and non-tampering of each packet and generate a hash verification record; Based on the hash verification record, if the hash values ​​of all data packets match, the data content is decrypted and a security check is performed. The security status of the data is reviewed and recorded. Finally, all the reception and verification details are collated to generate a data reception report. Verify the data packet based on integrity, configure a secure network channel, specifically use the TLS protocol, parameters include version 1.2, operations include establishing an encrypted connection, serialize the data packet, specifically use the JSON serialization method, operations include converting the data structure into a JSON format string, and sending it to a predetermined network address, monitor the sending status of each packet during the operation, use a network monitoring tool, operations include real-time capture and analysis of outgoing data packets, ensure data transmission efficiency and security, and generate data transmission records; Based on the data transmission record, a hash value comparison program is started, specifically, the SHA-256 algorithm is used to recalculate the hash value of each received data packet, the operation includes parsing the data packet content and applying the hash function, and comparing it with the hash value bound before transmission, using a comparison tool, specifically a built-in hash comparison function, the operation includes automatically matching and marking data packets that do not match the hash, verifying the data integrity and non-tampering of each packet, and generating a hash verification record; Based on the hash verification record, if the hash values ​​of all data packets match, the data content is decrypted using the AES algorithm. The parameters include using a 256-bit key for decryption. The operation includes applying the key to the encrypted data and restoring the original state. A security check is performed using a data security audit tool, specifically a custom security audit script. The operation includes checking the integrity and privacy protection standards of the data, reviewing and recording the security status of the data, and finally collating all the details of the reception and verification to generate a data reception report; The data reception report includes the hash value verification result, the decryption status of the data packet and the security check details after reception.

[0028] The specific steps for generating an access status confirmation record are: Based on the data receiving report, analyze the verification results in the receiving report one by one, extract the data packet records marked as passed, and confirm the status of the data packet by checking the attached security indicators to generate a data security assessment list; Based on the data security assessment list, perform database entry operations for each data packet marked as passed, implement data storage by allocating storage paths, adding classification tags, and creating indexes, and generate data entry logs; Based on the data entry log, the data records after entry are integrated, the contents of multiple data sources are archived uniformly, the database status is updated and backed up, and the access status confirmation record is generated; Based on the data receiving report, analyze the verification results in the receiving report one by one, and use data analysis tools to parse the data. The operations include reading the report file, screening the records marked as passed, and checking the attached security indicators. Specifically, regular expressions are used to match the security indicators. The operations include identifying and verifying the relevant fields of the data packet status and generating a data security assessment list. Based on the data security assessment list, perform database entry operations for each data packet marked as passed, using a database management system. The operations include allocating storage paths, adding classification tags, creating indexes, setting the storage path, classification tags and indexes of each data packet for fast retrieval, and generating data entry logs; Based on the data entry log, the entered data records are integrated, and database query and update tools, specifically SQL query statements, are used. Operations include querying the entered data packets, archiving the contents of multiple data sources in a unified manner, completing database status updates, performing backup storage, ensuring that all data is secure and traceable, and generating access status confirmation records; Among them, the access status confirmation record includes the final confirmation of data access, system entry results and data storage status.

[0029] The above are only preferred embodiments of the present invention and are not intended to limit the present invention in other forms. Any technician familiar with the profession may use the technical contents disclosed above to change or modify them into equivalent embodiments with equivalent changes and apply them to other fields. However, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention without departing from the technical solution of the present invention still falls within the protection scope of the technical solution of the present invention.

Claims

1. A method for secure transmission of port terminal supply chain data, characterized in that: The following steps are involved: Step 1: Based on the demand information of the port terminal supply chain, subdivide the data types, including cargo tracking data and ship scheduling information, and generate a data specification catalog by classifying and identifying the specific format and processing rules of each type of data; Step 2: Based on the data specification directory, standardize the various types of data received, and encapsulate and integrate the data content in a unified format, package them into units that meet the standards, and obtain standardized data packets; Step 3: Encrypt the standardized data packet using asymmetric encryption technology, generate a key pair, and digitally sign the data packet using software-defined networking to verify the source and integrity of the data and generate an encrypted signature data packet; Step 4: Based on the encrypted signature data packet, additionally encrypt the fields containing sensitive information, use a symmetric encryption algorithm to encrypt the payment information and user identity, improve the protection level of sensitive data, and create a sensitive data protection package; Step 5: Use a hash algorithm combined with a support vector machine to hash the encrypted signature data packet, calculate the hash value and append it to the end of the data packet to generate an integrity verification data packet; Step 6: Send an integrity verification data packet through the network, recalculate the hash value of the data packet and compare it with the original hash value to confirm that the data has not been tampered with, decrypt and perform security checks on the data packet content, and obtain a data reception report; Step 7: Based on the results of the data reception report, evaluate the security of the data, confirm that the data is accepted, enter all verified data, complete data integration and storage, and form an access status confirmation record.

2. The method for secure transmission of port terminal supply chain data according to claim 1 is characterized in that: The data specification directory includes data classification identification, data format definition and data processing rules.

3. The method for secure transmission of port terminal supply chain data according to claim 1 is characterized in that: The standardized data packets include encapsulated text data, image files, video streams and other multimedia elements.

4. The method for secure transmission of port terminal supply chain data according to claim 1 is characterized in that: The specific steps of generating the encrypted signature data packet are: Based on the standardized data packet, initialize the key generation process, configure independent public keys and private keys for each data type, and generate a key configuration record; Based on the public key in the key configuration record, encrypt each item of data in the standardized data packet to generate an encrypted data set; Based on the encrypted data set, a software defined network is used to digitally sign each data packet using a corresponding private key to generate an encrypted signature data packet; The encrypted signature data includes a public key for decryption, encrypted data content, and a digital signature for verifying data integrity.

5. The method for secure transmission of port terminal supply chain data according to claim 4 is characterized in that: The initialization key generation process specifies a key length of 2048 bits to ensure strong encryption. For different data types, keys of different strengths are configured according to the sensitivity level of the data. When key generation fails, the error status will be recorded and a security alert will be triggered. The key generation process will be retried up to three times. If failures continue, the service will be suspended and the administrator will be notified to intervene.

6. The method for secure transmission of port terminal supply chain data according to claim 1 is characterized in that: The sensitive data protection includes double encrypted payment information, encrypted user identity data and other sensitive information fields.

7. The method for secure transmission of port terminal supply chain data according to claim 1 is characterized in that: The specific steps of generating the integrity verification data packet are: Based on the encrypted signature data packet, hash generation is performed, and in combination with a support vector machine, an independent hash value calculation is performed on the content of each data packet to obtain an independent hash value set; Based on the independent hash value set, the hash value of each data packet is bound to its data content and attached to the end of each data packet to generate a bound hash data packet; Integrate the binding hash data packets into a unified data set, including all hashed data packets, to generate an integrity verification data packet; The integrity verification data packet includes a hash value of the data packet, original data content, and a hash algorithm type used for verification.

8. The method for secure transmission of port terminal supply chain data according to claim 7 is characterized in that: The support vector machine is based on the formula: , in: is the decision function, is the input data point, is the support vector, For the The class labels of the data points, For the The Lagrange multiplier of the data points is, is the adjustment coefficient of the kernel function, is the kernel function, is the linear adjustment coefficient of the input data point, is the bias term.

9. The method for secure transmission of port terminal supply chain data according to claim 1 is characterized in that: The data reception report includes the hash value verification result, the decryption status of the data packet and the security check details after reception.

10. The method for secure transmission of port terminal supply chain data according to claim 1, characterized in that: The access status confirmation record includes the final confirmation of data access, system entry results and data storage status.

Citation Information

Patent Citations

  • Message sending method, signature information generation method and equipment

    CN114978519A

  • Real-time data processing method and system and computer readable storage medium

    CN118381664A

  • Data security transmission method and system based on autonomous security interaction protocol

    CN118784337A

  • DNS based PKI system

    WO2016202397A1