Method for security inspection based on Android mobile device without network
By using encrypted compressed packages and Android devices for data management in a network-free environment, the problems of poor data confidentiality and low work efficiency of mobile devices during security inspections are solved, and data security and efficiency are improved.
Patent Information
- Application Number
- CN202411860892.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-12-17
AI Technical Summary
In a network-free environment, mobile devices have poor data confidentiality and low work efficiency in security inspections.
By generating and transmitting encrypted inspection task compression packets on the inspection data processing server to mobile devices, and using Android devices to enter, encrypt, compress and digest the data to realize local encrypted storage and management of data.
It solves the problem that inspection data cannot be uploaded in a timely manner in a network-free environment, improves the flexibility and coverage of inspection, ensures the integrity and security of data, reduces equipment costs, and improves inspection efficiency.
Smart Images

Figure CN119961948A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of safety inspection, and is particularly applicable to a method for safety inspection based on an Android mobile device without a network. Background Art
[0002] During the engineering inspection process, some companies with encryption requirements need to use isolation technology to isolate inspection equipment from public networks such as the Internet to prevent confidential information leakage. At present, most enterprises and institutions use intranet management. Information is separated from the Internet through the intranet to prevent information leakage. For mobile inspection equipment, in order to prevent information leakage, VPN technology or inspection personnel filling out paper forms, taking photos with cameras, etc. are usually used to prevent information leakage of mobile inspection equipment. However, VPN technology cannot prevent the leakage of information already stored in mobile devices. Inspection personnel filling out paper forms, taking photos with cameras, etc. require the inspection personnel to return to the management, organize the forms or pictures, and then enter them into the system one by one. This method is complex, inefficient, and prone to data confusion. Summary of the invention
[0003] The present invention aims to provide a method for security inspection of an Android mobile device without a network, aiming to solve the problems of poor data confidentiality and low work efficiency of mobile devices during security inspection.
[0004] To achieve the above object, the present invention adopts the following technical solutions: The method for security inspection based on Android mobile device without network in the present invention comprises the following steps: S1, generating an inspection task compression package on the inspection data processing server; the inspection task compression package is asymmetrically encrypted using the Pretty Good Privacy library; S2, connecting the mobile device to the inspection data storage server via USB, and transmitting the inspection task compressed package to the mobile device; S3, decompress and decrypt the inspection task compressed package, and write the inspection task into the database of the mobile device; S4, obtaining the inspection point information by scanning the inspection point QR code, and calling up the inspection task list of the inspection point from the database; S5, after recording the inspection information item by item according to the inspection task list, encrypt and save it to the designated file; S6, repeat steps S4 and S5 until the inspection task is completed; S7, after compressing the designated file, transmits it to the inspection data storage server through USB connection for data decryption and storage.
[0005] Furthermore, step S1 specifically includes creating a temporary file, writing the serialized inspection task JSON data into the temporary file, encrypting and compressing the temporary file, and applying the SHA-256 algorithm to generate a digest.
[0006] Furthermore, after the inspection task compression package is transmitted to the mobile device in step S2, the temporary files on the inspection data storage server are deleted.
[0007] Furthermore, in step S3, the Apache Commons Compress technology is used to decompress the inspection task compressed package to a specified directory, and the SHA-256 algorithm is applied during decompression to generate a digest, and the digest is compared with the expected checksum provided by the inspection task compressed package. After decompression, the file size and attributes are checked.
[0008] Furthermore, in step S3, Pretty Good Privac is used to decrypt the decompressed file, a corresponding table structure is constructed using the SQLite database, and the decrypted data is written into the database in a predetermined format.
[0009] Furthermore, the inspection point QR code in S4 includes the name, number and location information of the equipment to be inspected at the inspection point; and the inspection task list of the inspection point is obtained by querying the database according to the name, number and location of the equipment to be inspected.
[0010] Furthermore, in step S4, an RFID tag may be used to obtain the inspection point information by scanning the RFID tag.
[0011] Furthermore, the pictures and videos in the inspection information in step S5 are automatically added with a timestamp and an inspector watermark, and are saved to a designated path in the mobile device after carrying the name, number, location, and inspection items of the equipment to be inspected at the inspection point.
[0012] Furthermore, step S5 also includes recording the digital signature, signature time and unique identification of the mobile device of the inspector.
[0013] Furthermore, the mobile device has a built-in GPS module, and an inspection route map is generated during the inspection process.
[0014] The advantages of the present invention are: 1. The present invention designs a mechanism for encrypting, storing and managing security inspection data locally in mobile devices in a network-free environment. This not only solves the problem that inspection data cannot be uploaded in a timely manner in remote water conservancy facility areas or areas with poor network coverage, but also improves the flexibility and coverage of inspections, ensures the integrity and security of data, and enables inspection tasks to be completed even when the network is unavailable.
[0015] 2. The present invention uses Android devices to implement functions such as data entry, encryption, compression and summary generation, thereby improving inspection efficiency and reducing equipment costs.
[0016] 3. In the entire process of data collection, the present invention uses Pretty Good Privacy to encrypt data and Apache Commons Compress to compress data, which can ensure the security and transmission efficiency of data in the data collection process.
[0017] 4. The present invention uses the SHA-256 algorithm to generate data digests, and combines the digital signature technology of KeyPairGenerator to ensure the integrity and source reliability of data, and effectively prevent data from being accidentally or maliciously modified during transmission.
[0018] 5. In the present invention, the mobile device and the data server directly transmit data, which does not require a network and also eliminates the need for manual data sorting and entry, thereby avoiding the complexity, inefficiency and data confusion risks caused by manual data entry. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 This is a flow chart of the method for security inspection of Android mobile devices without a network according to the present invention. DETAILED DESCRIPTION
[0020] The technical solutions in the embodiments of the present invention are described clearly and completely below. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0021] The method for security inspection based on Android mobile device without network described in the present invention is as follows: Figure 1 As shown, the following steps are included: S1, generate a compressed package of the inspection task on the inspection data processing server. The specific operations are: create a temporary file, write the serialized inspection task JSON data into the temporary file, use the Apache Commons Compress library to asymmetrically encrypt and compress the temporary file using the Pretty Good Privacy library, and apply the SHA-256 algorithm to generate a summary of the compressed package of the inspection task at the same time.
[0022] S2, connecting the mobile device to the inspection data storage server via USB, and transferring the inspection task compressed package to the mobile device.
[0023] In this process, before transmission, it is necessary to make sure that the inspection task compressed package is not locked by other processes, and the transmission protocol used (such as MTP or PTP) is compatible with the computer and mobile device to ensure that the file can be correctly identified and accessed; ensure that the file system of the inspection data processing server is compatible with the file system on the Android mobile device (such as FAT32, NTFS or exFAT) to avoid problems caused by file system mismatch. During the entire transmission process, the stability of the connection should be monitored, and the connection should be disconnected correctly after the transmission is completed to prevent file damage or data loss. After the inspection task compressed package is transferred to the mobile device, delete the temporary files on the inspection data storage server.
[0024] S3, decompress and decrypt the inspection task compressed package, and write the inspection task into the database of the mobile device.
[0025] Apache Commons Compress technology is used to decompress the inspection task compressed package, and the decompressed files are stored in a pre-specified directory. During the decompression process, the SHA-256 algorithm is used to generate a summary of the decompressed file. The summary is compared with the expected checksum provided by the inspection task compressed package to ensure that the file has not been damaged or tampered with during the decompression process. After the decompression is completed, the size and attributes of the decompressed file are checked to verify whether the file structure is correct, thereby ensuring the integrity and consistency of the file.
[0026] The encrypted file is then decrypted using the corresponding JcaPGPObjectFacto, JcePublicKeyDataDecryptorFactory and implicit public key in the Pretty Good Privacy library. By configuring the same key and algorithm, the decryption process is ensured to match the encryption process. The decrypted data is read in the form of a stream and processed line by line or block by block. Subsequently, a database is created or opened using the SQLite database operation interface (such as SQLiteOpenHelper) and the corresponding table structure is constructed. The decrypted data is inserted into the inspection record table in a predetermined format to ensure the integrity and accuracy of the data. In this way, the encrypted file is successfully decrypted and stored in the SQLite database.
[0027] S4, obtain the inspection point information by scanning the inspection point QR code, and call out the inspection task list of the inspection point from the database.
[0028] Specifically, after the inspectors arrive at the inspection point, they use the camera of the Android mobile device to start the QR code scanning function. The Android mobile device uses image acquisition technology to identify the inspection point QR code image, and then uses image processing and decoding technology to identify the positioning mark in the inspection point QR code and determine its direction. The built-in decoding algorithm is used to decode and correct the feature information, and finally the identification information in the inspection point QR code is extracted. The entire process does not require a network connection, achieving fast and accurate recognition in a non-network environment.
[0029] For areas where it is relatively difficult to scan the QR code at the inspection point (for example, high-altitude collection equipment, etc.), RFID tags can be used to identify equipment information and obtain inspection point information. RFID tags can be identified over a certain distance. The tag chip stores a unique electronic code, which represents the specific information of the object to which the tag is attached. The RFID reader is used to identify the information carried by the RFID tag and transmit it to the Android mobile device.
[0030] The inspection point QR code contains the name, number, and location information of the equipment to be inspected at the inspection point; the name, number, and location information of the equipment to be inspected are parsed from the inspection point QR code and used as the keywords for querying the database. The SQLite database query statement is used to retrieve the inspection task list corresponding to the inspection point matching the keyword in the local database of the Android mobile device. The search results contain the basic information of the inspection point equipment, historical inspection records, and key points to be paid attention to in this inspection, for inspection personnel to view and refer to when performing inspection tasks.
[0031] S5, after recording the inspection information item by item according to the inspection task list, encrypt and save it to a designated file in the mobile device.
[0032] Inspectors can take relevant pictures or videos to record the inspection site. To ensure that each picture or video is closely related to a specific inspection item, the name, number, location, inspection items and other information of the equipment to be inspected at the current inspection point will be embedded in the information carried by the picture or video. Subsequently, these pictures and videos are saved to the storage path specified by the Android mobile device. The detailed information of the inspection items at the inspection point and their corresponding picture or video paths are then stored in the local SQLite database to ensure the comprehensiveness and accuracy of the inspection work.
[0033] When recording images and video information, Android's Canvas and Bitmap classes are used to embed the current time, the inspector's name or unique ID, the unique ID of the Android mobile device, etc. in the image drawing process, and automatically add a timestamp and inspector watermark to each image to prevent tampering and denial. Time information is obtained through System.currentTimeMillis() to ensure accuracy; inspector information is preset based on the login account. The watermark content is superimposed on the corner of the image in a semi-transparent form, which does not affect the recognition of the original image content.
[0034] Meanwhile, a personal digital certificate is installed on the Android mobile device of the present invention, and the inspection personnel can sign and confirm the inspection information of each inspection point.
[0035] This technology is based on the public key infrastructure (PKI). When the inspector signs, he calls the Android KeyPairGenerator instance to obtain the private key in the KeyStore API, encrypts the inspection information summary, and generates a digital signature. At the same time, the timestamp of the signature and the unique identifier of the Android mobile device are recorded to enhance the non-repudiation of the signature. The signature data is stored in the local SQLite database together with the inspection information to ensure that the information is complete, authentic, and traceable. This process does not require a network connection, ensuring security confirmation in a network-free environment.
[0036] After all inspection task orders for the inspection point are completed, the inspection data in the inspection task order is encrypted using the Pretty Good Privacy library to ensure data security.
[0037] First, create a PGPSecretKeyRingCollection instance to read the key ring file according to the encryption algorithm (such as ECC). Then, use the key ring of the inspector to initialize the PGPSecretKeyDecryptor object for asymmetric encryption. Next, create a FileOutputStream to point to the file storing the encrypted data. Combine PGP with FileOutputStream to write the inspection data through FileOutputStream and automatically complete the encryption process. After encryption is completed, close all stream resources.
[0038] S6, repeat steps S4 and S5 until the inspection task is completed.
[0039] When all tasks on the inspection task list of a patrol point are completed (including data encryption, signature, image watermarking, etc.), it will automatically advance to the next patrol point. Repeat the entire process of steps S4 and S5. The patrol personnel arrive at the patrol point and start the QR code scanning function. The device information and patrol information are obtained through scanning. During the patrol process, the patrol item information is recorded, and the image information and video information are recorded. The patrol personnel sign and confirm the patrol information. After the patrol task list is completed, the data is encrypted to ensure data security.
[0040] S7, after compressing the designated file, transmits it to the inspection data storage server through USB connection for data decryption and storage.
[0041] Using the Java Apache Commons Compress library, the files storing all the inspection information of this inspection task on the Android mobile device are compressed to generate a compressed package containing all the inspection information, so as to save storage space, prevent information confusion and improve data transmission efficiency. During the compression process, the Android mobile device simultaneously uses the SHA-256 hash algorithm to calculate the contents of the compressed package to generate a unique information summary. This summary is used as the digital fingerprint of the compressed package for subsequent data integrity verification to ensure that the information has not been tampered with during transmission or storage.
[0042] Return to the management office, transfer the compressed package to the inspection data storage server via USB connection, and verify the data encryption result and summary information.
[0043] On the inspection data storage server, the compressed package is decompressed. Then, the SHA-256 algorithm is used to regenerate the information summary of the decompressed data and compare it with the summary information generated by the device and transmitted with the compressed package. If the two are completely consistent, the verification is passed, confirming that the data has not been tampered with or damaged during the transmission process, ensuring the integrity and authenticity of the inspection data. After completing data transmission and summary verification, the data is decrypted and parsed. First, the encrypted data in the compressed package is decrypted through the JcePublicKeyDataDecryptorFactory decryption factory using the decryption algorithm corresponding to the encryption to restore the original inspection data. During the decryption process, the integrity of the data will be verified to ensure that the decryption operation does not introduce any errors or data loss. After decryption is completed, the decrypted data is parsed to extract specific contents such as inspection records, trajectory information, pictures and videos. Finally, the decrypted and parsed inspection data are securely submitted to the data storage management system on the inspection data storage server.
[0044] After receiving the submitted inspection data, the data storage management system on the inspection data storage server first performs a secondary verification of data integrity. This step recalculates the hash value of the data and compares it with the previously submitted summary information to ensure that the data has not been tampered with or damaged during transmission to the server. After the verification is passed, the system writes the data into the database according to the preset data structure for subsequent data storage, analysis, report generation and decision support, thereby completing the entire water conservancy industry safety inspection process based on Android devices in a network-free environment.
[0045] At the same time, in order to ensure that the source of the data is reliable and non-repudiable, the data storage management system on the inspection data storage server will check and verify the digital signature generated by the KeyPairGenerator submitted with the data. This signature is generated by the Android mobile device using a private key before the data is submitted and attached to the data packet. The inspection data storage server verifies the signature using the corresponding public key to confirm that the data is indeed sent by a legitimate inspection device and has not been maliciously tampered with by a third party. Only when the data integrity verification and digital signature verification are passed, the data storage management system on the inspection data storage server will finally store the data securely in the database, providing reliable protection for subsequent data analysis and application.
[0046] When data integrity verification and digital signature verification are successfully completed and the data has been securely written to the database, the system will perform a cleanup of the original data. This step involves completely deleting the original inspection data and its encrypted compressed package from the temporary storage area of the Android mobile device and the inspection data storage server to prevent the leakage or improper retention of sensitive information.
[0047] After the deletion operation is completed, the connection between the Android device and the intranet server is safely disconnected to ensure the closure of the communication link and further protect the security of the data. At the same time, the entire process log of data submission, verification and deletion will be recorded for subsequent auditing and tracking to ensure the traceability and compliance of the entire data processing process.
[0048] At this point, the security inspection process based on Android devices in a networkless environment has been completed, and we are ready for the next inspection task. In addition, the Android mobile device of the present invention has a built-in GPS module, which collects and records all location information during the inspection process, including longitude and latitude, timestamp, etc. These data are encrypted and stored locally on the device to ensure information security. At the same time, these location points will be used to generate an inspection route map to intuitively display the movement trajectory of the inspection personnel. Users can view the trajectory summary in a non-network environment.
Claims
1. A method for security inspection of Android mobile devices without a network, characterized in that: The following steps are involved: S1, generating an inspection task compression package on the inspection data processing server; the inspection task compression package is asymmetrically encrypted using the PrettyGood Privacy library; S2, connecting the mobile device to the inspection data storage server via USB, and transmitting the inspection task compressed package to the mobile device; S3, decompress and decrypt the inspection task compressed package, and write the inspection task into the database of the mobile device; S4, obtaining the inspection point information by scanning the inspection point QR code, and calling up the inspection task list of the inspection point from the database; S5, after recording the inspection information item by item according to the inspection task list, encrypt and save it to the designated file; S6, repeat steps S4 and S5 until the inspection task is completed; S7, after compressing the designated file, transmits it to the inspection data storage server through USB connection for data decryption and storage.
2. According to the method of claim 1, the method is characterized by: Step S1 specifically includes creating a temporary file, writing the serialized inspection task JSON data into the temporary file, encrypting and compressing the temporary file, and applying the SHA-256 algorithm to generate a digest.
3. According to the method of claim 2, the method is characterized in that: After the inspection task compression package is transmitted to the mobile device in step S2, the temporary files on the inspection data storage server are deleted.
4. According to a method for security inspection of an Android mobile device without a network as described in claim 1, it is characterized in that: In step S3, the Apache Commons Compress technology is used to decompress the inspection task compressed package to the specified directory. The SHA-256 algorithm is applied during decompression to generate a digest, and the digest is compared with the expected checksum provided by the inspection task compressed package. After decompression, the file size and attributes are checked.
5. According to a method for security inspection of an Android mobile device without a network as described in claim 1, it is characterized in that: In step S3, Pretty Good Privac is used to decrypt the decompressed file, the corresponding table structure is constructed using the SQLite database, and the decrypted data is written into the database in a predetermined format.
6. The method for security inspection of an Android mobile device without a network according to claim 1, characterized in that: The inspection point QR code in S4 includes the name, number and location information of the equipment to be inspected at the inspection point; the database is queried according to the name, number and location of the equipment to be inspected to obtain the inspection task list of the inspection point.
7. The method for security inspection of an Android mobile device without a network according to claim 1, characterized in that: In step S4, RFID tags can also be used to obtain inspection point information by scanning the RFID tags.
8. The method for security inspection of an Android mobile device without a network according to claim 1, characterized in that: The pictures and videos in the inspection information described in step S5 are automatically added with a timestamp and an inspector watermark, and are saved to a specified path with the name, number, location, and detection items of the equipment to be inspected at the inspection point.
9. The method for security inspection of an Android mobile device without a network according to claim 1, characterized in that: Step S5 also includes recording the digital signature, signature time and unique identification of the mobile device of the inspector.
10. The method for security inspection of an Android mobile device without a network according to claim 1, characterized in that: The mobile device has a built-in GPS module, which generates an inspection route map during the inspection process.
Citation Information
Patent Citations
Polling system and polling method based on NFC (noise feedback coding) mobile terminal
CN103268645A
Universal patrol system and patrol method thereof
CN104751532A
Polling management system and method based on Internet of things
CN106056281A
Offline operation mode for portable terminal
CN108712377A
Database security protection method and device
CN111008205A