Road information board information release safety management method, safety terminal, storage medium and program product

By introducing information encryption and publishing secure terminals in the road intelligence board system for identity screening and information encryption, the problems of illegal access and information leakage in the existing system are solved, and the security and standardization of information release are achieved.

CN120074907APending Publication Date: 2025-05-30NANJING MICROVIDEO TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510209308.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing road intelligence board system lacks identity identification methods in the control of information source, resulting in hidden dangers of illegal access and information leakage, and the transmission link lacks encryption mechanism and verification measures.

Method used

The security terminal uses information encryption to identify the intelligence board gateway, establishes a communication link and applies for a communication token, receives encrypted information and decrypts it through a symmetric password, and uses the audit model to detect the information and then sends it to the intelligence board gateway.

Benefits of technology

Through identity identification and information encryption, we will eliminate chaos in over-authorized release and cross-road section release, ensure that information release follows permission specifications, and reduce the hidden dangers of information leakage and incorrect release.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074907A_ABST
    Figure CN120074907A_ABST
Patent Text Reader

Abstract

The invention provides a road information board information release safety management method, a safety terminal, a storage medium and a program product, and relates to the technical field of road information encryption. In an identity discrimination link, verification is carried out on an operator behind the information board gateway, it is ensured that each piece of information is sent out from terminal equipment, and meanwhile, the information encryption and release safety terminal establishes a communication link among the information board gateway, the information encryption and release safety terminal, the information board front-end processor and the cloud platform server. Only when the identity verification is passed, the link can be constructed and a communication token is applied to the cloud platform server. And all terminals from different sources and different dispatching centers are standardized on the basis of an identity discrimination result. The information encryption publishing security terminal receives the encrypted information sent by the information board front-end processor, decrypts the published information by using a symmetric password and detects the published information by using an auditing model, ensures that the information publishing follows the authority specification, and reduces the hidden dangers of information leakage, wrong publishing and the like caused by illegal access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of road information encryption technology, and particularly to a method for secure management of road information board information release, a secure terminal, a storage medium, and a program product. Background Art

[0002] In the current booming development of the modern transportation system, highways, urban roads, and transportation hubs, as key nodes of the transportation network, carry a huge amount of personnel and material flows. Variable message signs have become an indispensable important platform for external information release and publicity in these scenarios. Like information beacons in the transportation field, they continuously transmit key guidance such as road conditions, instructions, and emergency notifications to passing vehicles and pedestrians in real time.

[0003] In the past, in terms of information source control, most variable message sign systems did not implement any identity screening measures for various terminal devices providing information. Whether it was internal devices of legitimate traffic management departments or external devices of unknown sources, they could all be casually connected to the information release link. In the information transmission link, the plaintext transmission method was adopted throughout, and no data encryption mechanism was applied. Information shuttled through the network in its original and exposed state. Moreover, in maintaining the integrity of the transmission link, there were no effective verification measures, neither verifying whether the data was tampered with during transmission nor monitoring and repairing transmission interruptions, errors, etc.

[0004] However, with the rapid popularization of information technology and the increasing complexity of the network environment, related technologies have also exposed many fatal defects. Hackers can use network sniffing tools to intercept and steal sensitive information at any time, which is likely to cause security risks. Summary of the Invention

[0005] This application provides a method for secure management of road information board information release, a secure terminal, a storage medium, and a program product, which are used to reduce potential risks such as information leakage and incorrect release caused by illegal access.

[0006] In a first aspect, the present application provides a security management method for road information board information publishing, which is applied to a road information board system. The road information board system includes a cloud platform server, an information board front-end machine, an information board gateway, and an information encryption and publishing security terminal located inside the information board, including: the information encryption and publishing security terminal conducts identity verification on the information board gateway; in the case where the identity verification is passed, the information encryption and publishing security terminal establishes communication links among the information board gateway, the information encryption and publishing security terminal, the information board front-end machine, and the cloud platform server, and applies for a communication token from the cloud platform server through the communication link; the information encryption and publishing security terminal receives the encrypted information sent by the cloud platform server through the information board front-end machine; the information encryption and publishing security terminal decrypts the encrypted information using the symmetric cipher used to encrypt the encrypted information to obtain the published information; the information encryption and publishing security terminal uses an audit model to detect and audit the published information; in the case where the audit is passed, the information encryption and publishing security terminal distributes the published information to the information board gateway.

[0007] By adopting the above technical solution, in the identity verification link, it abandons the original single sign-on mode of the dispatching cloud information board system and verifies the operators behind the information board gateway. It eliminates the chaos of unauthorized publishing or cross-section publishing from the source, ensuring that each piece of information is sent from the terminal device. At the same time, the information encryption and publishing security terminal establishes communication links among the information board gateway, itself, the information board front-end machine, and the cloud platform server. Only when the identity verification is passed can the link be constructed and a communication token be applied for from the cloud platform server, and unauthorized devices simply cannot reach the subsequent processes. Even if the dispatching center does not have a dedicated information board publishing computer and uses an open Internet to access the dispatching cloud information board system, external illegal devices cannot break through the identity verification and link construction links. It centrally manages all access requests. Based on the identity verification results, all terminals in the dispatching center from different sources are standardized. When receiving the encrypted information sent by the cloud platform server through the information board front-end machine, it decrypts the information using the symmetric cipher and detects and audits the published information using the audit model until the audited information is distributed to the information board gateway, ensuring that information publishing follows the permission specifications and reducing potential risks such as information leakage and incorrect publishing caused by illegal access.

[0008] Combined with some embodiments of the first aspect, in some embodiments, after the step of the information encryption and publishing security terminal conducting identity verification on the information board gateway, the method further includes: in the case where the identity verification fails, the information encryption and publishing security terminal determines whether it has been remotely logged in; in the case where the remote login passes the identity verification, the information encryption and publishing security terminal allows the information board gateway to directly connect to the cloud platform server for update; after the update is completed, the information encryption and publishing security terminal prohibits the information board gateway from directly connecting to the cloud platform server for update.

[0009] By adopting the above technical solution, when facing firmware upgrade or special font library update, if the remote login verification conditions are met, the information board gateway is allowed to directly connect to the cloud platform server for update, breaking through the blocking limit of the information encryption and publishing security terminal on the manufacturer's debugging tool, avoiding the inconvenience of only being able to upgrade on-site in the field, saving both manpower and material resources, and ensuring the safety and controllability of the upgrade operation.

[0010] Combined with some embodiments of the first aspect, in some embodiments, the symmetric cipher is as follows: during the encryption process, the information board front-end machine performs an exclusive OR operation on the published information; the information board front-end machine performs iterative operations on the calculation result through a round function to obtain the encrypted information; during the decryption process, the information encryption and publishing security terminal performs iterative operations on the encrypted information through the round function, where the iteration order and rules are opposite to those of the encryption process; the information encryption and publishing security terminal performs an exclusive OR operation on the calculation result to obtain the published information.

[0011] By adopting the above technical solution, the information board front-end machine and the information encryption and publishing security terminal cooperate, and use a specific symmetric cipher encryption and decryption process to greatly improve information security. During encryption, the information board front-end machine first performs an exclusive OR operation on the published information and then performs iterative operations through the round function, introducing complex transformations; during decryption, the information encryption and publishing security terminal processes according to the opposite iteration order and rules, effectively resisting the risk of being cracked. Compared with conventional encryption, the unique algorithm process makes the encrypted result more difficult to be reverse-derived. Even if part of the information is leaked, it is difficult for attackers to restore the complete content, maintaining the authority and credibility of the road information board information.

[0012] Combined with some embodiments of the first aspect, in some embodiments, before the step of the information encryption and publishing security terminal decrypting the encrypted information by using the symmetric cipher used for encrypting the encrypted information to obtain the published information, the method further includes: after receiving the published information to be released, the cloud platform server uses natural language processing to identify the punctuation marks and semantic logical breakpoints in the published information; the cloud platform server calculates the total length of the published information; the cloud platform server determines the number of divisions according to the preset division degree and the total length; the cloud platform server divides the published information at the punctuation marks or semantic logical breakpoints according to the number of divisions; the cloud platform server stores the divided paragraphs into the task queue according to the division; the cloud platform server takes out the paragraphs according to its computing power and performs encryption in parallel by using the symmetric cipher; the cloud platform server sends the encrypted paragraphs to the information encryption and publishing security terminal through the information board front-end machine.

[0013] By adopting the above technical solutions, the cloud platform server divides the published information according to punctuation marks and semantic breakpoints and encrypts it in parallel based on natural language processing and intelligent partitioning strategies, balancing the speed of information release and encryption requirements. On the one hand, according to the real-time and variable road conditions, the information is quickly processed. After the published information is subdivided, the computing power is used to encrypt it in parallel, greatly shortening the encryption time-consuming, so that the information can quickly reach the information board gateway from the source end through each node. On the other hand, the whole process encryption ensures the confidentiality of information. Even in the face of attacks by lawbreakers, the key traffic information can be protected and prevented from being leaked and exploited.

[0014] Combined with some embodiments of the first aspect, in some embodiments, the step of the information encryption and release security terminal decrypting the encrypted information by using the symmetric cipher for encrypting the encrypted information to obtain the published information specifically includes: the information encryption and release security terminal screening the buffer area to remove the buffer data with different symmetric ciphers; the information encryption and release security terminal retrieving according to the encrypted paragraphs in the buffer area; if there are encrypted paragraphs in the buffer data, the information encryption and release security terminal reads the corresponding decryption result from the buffer area according to the recorded storage address; if there are no encrypted paragraphs in the buffer data, the information encryption and release security terminal decrypts the encrypted paragraphs by using the symmetric cipher for encrypting the encrypted paragraphs; after all paragraphs are decrypted, the information encryption and release security terminal splices them in the order of paragraph identifiers to obtain the published information.

[0015] By adopting the above technical solutions, the information encryption and release security terminal optimizes the cache processing in the decryption link, improving the decryption efficiency. First, it screens and removes the buffer data with different symmetric ciphers, accurately locates the available cache, retrieves according to the encrypted paragraphs in the buffer area, directly reads the decryption result if there is a corresponding paragraph, and only starts the conventional decryption if there is no such paragraph. This avoids repeated decryption of the same information, reduces the consumption of computing resources, quickly restores the published information in the case of urgent release of traffic information, enables the information board to quickly display accurate content, and ensures the timeliness of information transmission.

[0016] Combined with some embodiments of the first aspect, in some embodiments, after the step of the information encryption and release security terminal splicing the paragraphs in the order of paragraph identifiers to obtain the published information after all paragraphs are decrypted, the method further includes: for the buffer data without encrypted paragraphs, the information encryption and release security terminal calculates the hash value of the encrypted paragraphs; the information encryption and release security terminal creates a cache data node including the encrypted paragraphs, the decrypted paragraphs, the data identifier, the storage time, and the initial access times of 0, and inserts the cache data node at the head of the linked list, and adds a key-value pair in the hash table; where the key-value pair includes the hash value and the encrypted paragraphs; for the buffer data with encrypted paragraphs, the corresponding cache data node is moved to the head of the linked list.

[0017] By adopting the above technical solution, after decrypting and splicing the published information, the information encryption and publishing security terminal finely manages the cached data, strengthening the system performance. For newly emerged encrypted paragraphs, calculate the hash value, create a cache node and insert it into the head of the linked list. At the same time, add a key-value pair in the hash table for subsequent quick retrieval. For existing ones, move them to the head of the linked list to update the access status. In this way, the cache area always efficiently stores the data most likely to be reused, with a higher hit rate during subsequent decryption queries, continuously improving the system operation efficiency and reducing the performance loss caused by poor cache management.

[0018] In combination with some embodiments of the first aspect, in some embodiments, before the information encryption and publishing security terminal creates an encrypted paragraph, a decrypted paragraph, a data identifier, a cached data node with a storage time and an initial access count of 0, inserts the cached data node into the head of the linked list, and adds a key-value pair in the hash table, the method further includes: the information encryption and publishing security terminal determines whether the linked list reaches a preset threshold; if it reaches the preset threshold, the information encryption and publishing security terminal removes the cached data node from the tail of the linked list and deletes the corresponding key-value pair in the hash table.

[0019] By adopting the above technical solution, before inserting the cached data node into the head of the linked list, the information encryption and publishing security terminal adds an operation to determine whether the linked list reaches a preset threshold, effectively optimizing the utilization of cache resources. Once the linked list reaches the threshold, remove the cached data node from the tail and delete the corresponding key-value pair to make room for new data, ensuring that the data stored in the cache area are the most valuable ones recently. This prevents resource waste caused by unlimited growth of the cache and enables the limited cache resources to focus on serving high-frequency encryption and decryption tasks.

[0020] In a second aspect, the present application provides an information encryption and publishing security terminal, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the information encryption and publishing security terminal to execute the method described in the first aspect and any possible implementation manner in the first aspect.

[0021] In a third aspect, the present application provides a computer program product containing instructions, which when running on the information encryption and publishing security terminal, enables the information encryption and publishing security terminal to execute the method described in the first aspect and any possible implementation manner in the first aspect.

[0022] Fourthly, the present application provides a computer-readable storage medium, including instructions, which, when running on an information encryption and publishing security terminal, cause the information encryption and publishing security terminal to execute the methods described in the first aspect and any possible implementation manner of the first aspect.

[0023] One or more technical solutions provided in the embodiments of the present application have at least the following technical effects or advantages: 1. In the identity verification link, it abandons the original single-point login mode of the dispatching cloud information board system and verifies the operators behind the information board gateway. It completely eliminates the chaos of unauthorized publishing or cross-section publishing from the source, ensuring that each piece of information sent from the terminal device, and at the same time, the information encryption and publishing security terminal establishes communication links between the information board gateway, itself, the information board front-end machine, and the cloud platform server. Only when the identity verification is passed can the link be constructed and a communication token be applied to the cloud platform server, and unauthorized devices simply cannot access the subsequent processes. Even if the dispatching center does not have a dedicated information board publishing computer and uses an open Internet to access the dispatching cloud information board system, external illegal devices cannot break through the identity verification and link construction links. It centrally controls all access requests. Based on the identity verification results, all terminals in the dispatching center from different sources are standardized. When receiving the encrypted information sent by the cloud platform server through the information board front-end machine, it decrypts the information using symmetric encryption and detects the published information through the audit model until the information passed the audit is sent down to the information board gateway, ensuring that the information publishing follows the permission specifications and reducing potential risks such as information leakage and incorrect publishing caused by illegal access.

[0024] 2. When encountering firmware upgrade or special font library update, if it meets the conditions of remote login verification, it allows the information board gateway to directly connect to the cloud platform server for update, breaking through the blocking limit of the information encryption and publishing security terminal on the manufacturer's debugging tools, avoiding the inconvenience of only being able to upgrade on-site in the field, saving both manpower and material resources, and ensuring that the upgrade operation is safe and controllable.

[0025] 3. Based on natural language processing and intelligent partitioning strategies, the cloud platform server divides the published information according to punctuation and semantic breakpoints and encrypts it in parallel, balancing the speed of information release and the encryption requirements. On the one hand, due to the real-time variability of road conditions, the information is processed quickly. After the published information is subdivided, the computing power is used to encrypt it in parallel, significantly shortening the encryption time-consuming, so that the information can quickly reach the information board gateway from the source through each node. On the other hand, the whole process of encryption ensures the confidentiality of information. Even in the face of attacks by lawbreakers, the key traffic information can be protected and leakage and exploitation can be avoided. The information encryption and release security terminal optimizes the cache processing in the decryption link, improving the decryption efficiency. First, it filters and removes the cache data with different symmetric ciphers, accurately locates the available cache, retrieves it in the buffer area according to the encrypted paragraph, directly reads the decryption result if the corresponding paragraph exists, and only starts the conventional decryption if it does not exist. This avoids repeated decryption of the same information, reduces the consumption of computing resources, and quickly restores the published information when the traffic information is urgently released, enabling the information board to quickly display accurate content and ensuring the timeliness of information transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is a flowchart of a method for secure management of road information board information release in an embodiment of the present application; Figure 2 is a circuit diagram of an information encryption and release security terminal in an embodiment of the present application; Figure 3 is a structural diagram of a road information board system in the related art; Figure 4 is a structural diagram of a road information board system in an embodiment of the present application; Figure 5 is another flowchart of a method for secure management of road information board information release in an embodiment of the present application; Figure 6 is another flowchart of a method for secure management of road information board information release in an embodiment of the present application; Figure 7 is an exemplary hardware structural diagram of an information encryption and release security terminal in an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification and appended claims of the present application, the singular forms "a", "an", "the", "above", "said", "this" are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in the present application refers to and includes any or all possible combinations of one or more of the listed items.

[0028] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and should not be construed as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present application, unless otherwise specified, the meaning of "a plurality" is two or more.

[0029] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a process for the security management of road information board information release in an embodiment of the present application; A method for the security management of road information board information release includes: S101. The information encryption and release security terminal verifies the identity of the information board gateway; It should be noted that the road information board system includes a cloud platform server, an information board front-end machine, an information board, and an information encryption and release security terminal located inside the information board. However, in this embodiment, the information encryption and release security terminal is used as the execution subject for description.

[0030] In some embodiments, when accessing the information board gateway, the information encryption and release security terminal immediately starts the identity verification process. It first requests the access device to send an access request data packet containing basic information such as its own identifier and the operator's account. Then, the security terminal preliminarily verifies this information according to the built-in identity verification rules. For example, it checks whether the MAC address of the device is in the pre-registered legal list. If not, it enters the in-depth verification link, combined with digital certificate verification. The digital certificate is issued by an authoritative certification institution and contains detailed identity information of the device and the operator, ensuring authenticity through complex encryption algorithms. Only when all verifications pass is the identity verification determined to be successful.

[0031] Please refer to Figure 2 , Figure 2 which is a schematic circuit diagram of the information encryption and release security terminal in an embodiment of the present application.

[0032] At the front-end on-site location of the variable message sign, a brand-new information encryption and publishing security terminal with high professionalism and security is deployed. Through a network cable with stable performance and strong anti-interference ability, this terminal establishes a close connection with the core control board of the original variable message sign, so as to achieve precise control of the underlying operation instructions of the message sign. At the same time, by using the network cable or optical fiber as a high-speed transmission link, it accesses the SD-WAN message sign gateway device that plays a hub role at the back end, and then comprehensively undertakes multiple key tasks of the message sign control system, including a rigorous identity authentication process, using cutting-edge encryption technology and multi-factor verification means to prevent illegal access; performing highly accurate integrity verification and secondary confirmation on the transmitted data, using technologies such as hash algorithms and digital signatures to ensure that the data is not tampered with and not omitted during the entire transmission process; once an abnormal situation is detected, immediately trigger a precise alarm mechanism, and alarm the operation and maintenance personnel in multiple forms such as sound, light, and pop-up windows; it can also present the detailed status information of the system in real time, such as network connection status, data transmission rate, device load situation, etc., providing a strong basis for operation and maintenance decisions, and fundamentally rejecting the unauthorized update of display information by stand-alone software to ensure the legality and authority of the information source of the message sign.

[0033] It should be noted that this information encryption and publishing security terminal is given the function of controlling the power supply of the entire message sign. When encountering scenarios that require power-off operations such as equipment maintenance, emergency troubleshooting, and system upgrade, authorized users can issue precise power-off instructions through this terminal to achieve safe and orderly power-off control of the message sign, effectively avoiding risks such as data loss and equipment damage caused by improper power-off, and greatly improving the stability and maintainability of the operation of the message sign system.

[0034] S102. When the identity verification is passed, the information encryption and publishing security terminal establishes communication links among the message sign gateway, the information encryption and publishing security terminal, the message sign front-end machine, and the cloud platform server, and applies for a communication token from the cloud platform server through the communication link; Among them, the communication link refers to the information transmission channel established among the key components of the message sign system, which is built based on a specific network protocol to ensure stable and high-speed data transmission.

[0035] In some embodiments, after identity verification is passed, the information encryption and publishing security terminal first sends a link establishment request to the intelligence board gateway front-end machine, carrying its own and the intelligence board's network configuration information, such as IP address, port number, etc. After receiving it, the intelligence board front-end machine interacts with the cloud platform server to confirm the network reachability of both parties and negotiates an appropriate network protocol and encryption method. For example, the SSL / TLS encryption protocol is used to ensure the security of the link. After the negotiation is completed, the information encryption and publishing security terminal formally establishes a communication link among the intelligence board gateway, itself, the intelligence board front-end machine, and the cloud platform server. Then, it applies for a communication token from the cloud platform server through this link. The communication token serves as a legitimate pass for subsequent data interaction and is generated and issued by the cloud platform server according to pre-set rules, considering factors such as the identity of the applying terminal and the current system load.

[0036] S103. The information encryption and publishing security terminal receives the encrypted information sent by the cloud platform server through the intelligence board front-end machine; Among them, the encrypted information refers to the ciphertext data obtained by the cloud platform server using a specific encryption algorithm, such as a symmetric cipher algorithm, to transform the originally plaintext published information to protect the confidentiality of traffic information, and outsiders cannot directly interpret its content.

[0037] In some embodiments, after the cloud platform server completes information encryption, it encapsulates the encrypted information into a data packet according to the established transmission protocol. The data packet header contains key metadata such as source address, destination address, and encryption algorithm identifier. Then, it sends the data packet through the reliable communication link established with the intelligence board front-end machine. After receiving it, the intelligence board front-end machine unpacks and verifies according to the data packet header information to ensure data integrity, and then repackages the encrypted information and forwards it through the communication link connecting the two parties according to the agreed manner with the information encryption and publishing security terminal. The information encryption and publishing security terminal is at the receiving end, constantly listening to the specified port. Once it detects a data packet from the intelligence board front-end machine, it starts the receiving process, stores the encrypted information completely in the local buffer area, and waits for subsequent processing.

[0038] S104. The information encryption and publishing security terminal decrypts the encrypted information using the symmetric cipher used to encrypt the encrypted information to obtain the published information; Among them, the symmetric cipher is a type of encryption algorithm, and its characteristic is that the same key is used for encryption and decryption.

[0039] In some embodiments, after receiving the encrypted information, the information encryption and release security terminal first reads the symmetric cipher key pre-stored in the local secure storage medium. This key has been securely configured and properly saved during the system initialization phase. Then, according to the selected symmetric cipher algorithm process, the encrypted information is decrypted. Taking the SM4 algorithm as an example, the encrypted information data is first divided into blocks, and an exclusive OR operation is performed with the initial vector. Then, it enters the round function iteration operation stage. According to the preset round key usage rules, multiple iterations are carried out to gradually restore the plaintext data, that is, the published information. During the entire decryption process, multiple error detection and correction mechanisms are set up, such as using checksum, hash function and other means to ensure the accuracy of the decryption result and prevent decryption failure caused by transmission errors or abnormal keys.

[0040] In some embodiments, the symmetric cipher is: S1041. During the encryption process, the front-end computer of the information board performs an exclusive OR operation on the published information; Among them, the exclusive OR operation is a logical operation that operates on two binary sequences of the same length bit by bit. When the bit values are the same, the result is 0, and when they are different, the result is 1. Its characteristic is that the original data can be restored by performing the exclusive OR operation again. It is often used in the initial confusion link of data encryption to simply and efficiently change the data characteristics.

[0041] In some embodiments, when new traffic information needs to be sent from the cloud platform server to the information board gateway and it is determined that symmetric cipher encryption is required to ensure information security, the encryption process is started. At this time, the front-end computer of the information board located at the key node of the transmission link receives the published information from the cloud platform server, and these information are stored in the memory buffer of the front-end computer in binary form. The front-end computer of the information board immediately calls the built-in exclusive OR operation module, reads the pre-generated and securely stored key, and performs an exclusive OR operation on each bit of the published information with the corresponding bit of the key according to the exclusive OR operation rule. For example, if a certain byte of the published information is 01010101 and the corresponding byte of the key is 10101010, the encrypted byte after the exclusive OR operation is 11111111. By performing this operation on each bit of the entire published information, the original characteristics of the information are initially disrupted, increasing the difficulty of cracking. The intermediate result after the exclusive OR operation is temporarily stored in another designated buffer of the front-end computer waiting for the next processing.

[0042] S1042. The front-end computer of the information board performs iterative operations on the calculation result through the round function to obtain the encrypted information; Among them, the round function is the core component in symmetric cryptography algorithms, usually composed of complex non-linear transformations and permutation operations. In each round of iteration, it deeply confuses and diffuses the data, making the characteristics of the original information hidden layer by layer, greatly enhancing the encryption strength; the iterative operation means repeatedly executing the same round function operation multiple times according to a predetermined rule. The input of each round is the output of the previous round, and through multiple rounds of iteration, the plaintext is gradually transformed into ciphertext, making it difficult for crackers to reverse deduce.

[0043] In some embodiments, after the information board front-end machine completes the exclusive OR operation on the published information, it immediately enters the round function iterative operation stage. At this time, the result of the exclusive OR operation is used as the input of the first round of the round function. According to the built-in algorithm logic, the round function first performs a non-linear transformation on the input data. For example, through a complex S-box substitution operation, the values in the data block are mapped to other seemingly irregular values, and then a permutation operation is performed to disrupt the data bit order. After completing the first round of transformation, an intermediate result is output. This intermediate result is used as the input of the next round of the round function, and so on. For example, for a 128-bit data after exclusive OR operation, it may become completely different 128-bit disordered data after the first round of round function operation. After 10 rounds or more of such iterations (the number of rounds depends on the encryption strength requirements), the encrypted information is finally obtained and stored in the secure storage area of the information board front-end machine dedicated to storing ciphertext, waiting to be transmitted to the information encryption and release security terminal.

[0044] S1043. During the decryption process, the information encryption and release security terminal performs iterative operations on the encrypted information through the round function. Among them, the iterative order and rules are opposite to those in the encryption process; In some embodiments, when the information encryption and release security terminal receives the encrypted information from the information board front-end machine, it starts the decryption process. First, it reads the corresponding symmetric key for encryption from the local secure storage medium. This key has been properly configured during the system initialization or key update stage. Then, using the encrypted information as the input of the first round of the reverse round function, according to the round function rules opposite to encryption, it first performs a reverse permutation operation to restore the disrupted data bit order during encryption, and then performs a reverse non-linear transformation, such as through an inverse S-box operation, to restore the previously mapped values. After each round of reverse iteration is completed, the output intermediate result is used as the input of the next round of the reverse round function, and the process continues. For example, for a 128-bit encrypted information, after the first round of reverse round function operation, the data characteristics begin to appear. After the same number of reverse rounds as the encryption rounds (such as 10 rounds) of iteration, an intermediate result close to the plaintext is gradually restored and temporarily stored in the internal buffer of the terminal, waiting for the final exclusive OR operation to restore the published information.

[0045] S1044. The information encryption and release security terminal performs an exclusive OR operation on the calculation result to obtain the published information.

[0046] In some embodiments, after the information encryption and release security terminal completes the decryption round function iteration operation and obtains the calculation result, it enters the final XOR decryption process. The symmetric key used during encryption is read from the local storage area, and each bit of the calculation result is XOR-operated with the corresponding bit of the key. The principle is the opposite of the XOR operation during encryption and is a reverse restoration process. For example, if a certain byte of the calculation result is 11111111 and the corresponding byte of the key is 10101010, after the XOR operation, 01010101 is obtained. By performing this operation on each bit of the entire calculation result, the published information is finally restored, such as traffic information like "The road ahead is temporarily restricted due to construction. Vehicles please take a detour." These information will then enter the review and distribution process to ensure accurate display on the information board.

[0047] It can be seen that the information board front-end machine and the information encryption and release security terminal cooperate to greatly improve information security by using a specific symmetric cipher encryption and decryption process. During encryption, the information board front-end machine first performs an XOR operation on the published information and then iterates the round function, introducing complex transformations. During decryption, the information encryption and release security terminal processes in the reverse iteration order and rules, effectively resisting the risk of being cracked. Compared with conventional encryption, the unique algorithm process makes the encryption result more difficult to be reverse-derived. Even if part of the information is leaked, it is difficult for attackers to restore the complete content, maintaining the authority and credibility of the road information board information.

[0048] S105. The information encryption and release security terminal uses the audit model to detect and audit the published information; In some embodiments, after the information encryption and release security terminal obtains the published information, it immediately inputs it into the audit model. The audit model first performs natural language processing operations such as word segmentation and part-of-speech tagging on the information to extract key information. Then, based on the built-in rule library, these key information are compared and verified one by one. Whether it contains sensitive vocabulary, etc.

[0049] In some specific embodiments, before running, the audit model first performs self-learning and updating, collecting traffic information, sensitive words, etc. from multiple channels; combining the rule-based model with the deep learning-based model to improve the audit accuracy, which is not limited here.

[0050] In some specific embodiments, a large amount of diverse traffic information samples and sensitive vocabulary are collected from multiple sources, and the collected samples are cleaned, labeled, and classified. The cleaning operation removes noise data in the information, such as garbled characters, incorrect punctuation marks, duplicate characters, etc. Then, the sensitive information features in the traffic field are labeled.

[0051] Taking the combination of convolutional neural network (CNN) and recurrent neural network (RNN) as an example, CNN utilizes its convolutional layer to extract local features of text or data sequences, and can accurately capture features such as key text or data segments, converting traffic data into a multi-dimensional feature matrix; RNN and its variants (LSTM, GRU) rely on their good memory of sequence information to effectively process sequential information with logical relationships before and after, such as traffic control time series and continuous construction processes on multiple road sections, avoiding problems of information logic confusion or time conflicts. The combination of the two enables the model to quickly locate key information and deeply understand its context logical relationship.

[0052] Input the training set data into the model, and based on the backpropagation algorithm, prompt the model to learn the feature patterns of sensitive information and normal traffic information, continuously adjust the internal parameters of the model, and gradually reduce the error between the model output and the labeled true result.

[0053] S106. In the case of successful review, the information encryption and release security terminal will send the released information to the information board gateway.

[0054] In some embodiments, when the information encryption and release security terminal receives the message of successful review, it will start to send the released information to the information board. First, it adapts the format of the released information according to parameters such as the display specifications and resolution of the information board, such as adjusting the font size and layout method to ensure that the information can be clearly and beautifully displayed on the information board. Then, according to the communication protocol agreed with the information board, the formatted released information is encapsulated into a transmission data packet, and the data packet header contains information such as display instructions and update time. Then, through the dedicated communication link connecting the two, the data packet is sent to the information board. After receiving the data packet, the information board immediately starts the update program according to the display instructions in the header and displays the new released information on the screen for passing vehicles and pedestrians to view, realizing the seamless connection from background processing to front-end display.

[0055] Please refer to Figure 3 , Figure 3 is a structural schematic diagram of a road information board system in the related art; the cloud platform server is connected to the information board through the main switch and the information board front-end switch, and at the same time, the information board control computer is also connected to the information board. Therefore, in the actual use process of the related technology, other problems will also occur, such as: It is difficult to verify the identity of information publishers. Currently, the information release work of variable information boards on each road section mostly relies on manual operations by dispatchers. The dispatching cloud information board system has long adopted a single-point login mode, which is like opening a hole in the fortress of information security, lacking a rigorous identity screening and fine-grained permission control mechanism for operators.

[0056] The scheduling center has shortcomings in the planning of equipment configuration and network access. On the one hand, there is no dedicated computer for information release of the information board, resulting in a variety of information release terminals and lack of unified specifications. On the other hand, an open Internet is used to access the scheduling cloud information board system, exposing traffic information to the network environment.

[0057] Within the scheduling center, no consensus was reached to uniformly use the scheduling cloud information board system, but instead there was a chaotic situation where the locally deployed system and the scheduling cloud information board system operated in parallel. When problems occurred, it became extremely difficult to trace back to the source of information release and find the root cause of the problems.

[0058] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of the road information board system in the embodiment of the present application; a cloud platform server, the cloud platform server is connected to the information board front-end machine through a main switch, then the information board front-end machine is connected to the information encryption and release security terminal, and then the information encryption and release security terminal is connected to the information board.

[0059] The road information board information release security management method provided by the present application aims precisely at these problems. In the identity verification link, it abandons the original single-point login mode of the scheduling cloud information board system and verifies the operators behind the information board gateway. It eliminates the chaos of unauthorized release or cross-section release from the source, ensures that each piece of information sent from the terminal device, and at the same time the information encryption and release security terminal establishes a communication link between the information board, itself, the information board front-end machine, and the cloud platform server. Only when the identity verification is passed can the link be constructed and a communication token be applied to the cloud platform server, and unauthorized devices simply cannot reach the subsequent processes. Even if the scheduling center does not have a dedicated information board release computer and uses an open Internet to access the scheduling cloud information board system, external illegal devices cannot break through the identity verification and link construction links. It centrally controls all access requests. Based on the identity verification results, all terminals in the scheduling center from different sources are standardized. When receiving the encrypted information sent by the cloud platform server through the information board front-end machine, it decrypts the information using symmetric cryptography and detects the published information through an audit model, and finally distributes the information that passes the audit to the information board, ensuring that the information release follows the permission specifications and reducing potential risks such as information leakage and incorrect release caused by illegal access.

[0060] In the actual use process, given the actual demand characteristics derived from the on-site management practice of the information board, there is an objective rigid demand for irregular firmware upgrades of the information board control system, or in specific application scenarios, there is an urgent need to update special types of fonts to adapt to the demands of diversified information display. However, such upgrade operations usually require the use of special debugging tools independently developed by the information board manufacturer. But the reality is that the debugging tools of each information board manufacturer are often blocked by the information encryption and release security terminal. The data interaction connection channel between them and the information board. This directly leads to the inefficient and cumbersome method of field upgrades, which undoubtedly introduces many inconveniences and obstacles to the management of information board equipment, and increases the cost of manpower and material resources.

[0061] See also Figure 5 , Figure 5 This is another flowchart of the road information board information release safety management method in the embodiment of the present application; Therefore, in some embodiments, after step S106, the following further includes: S107, in the case of identity verification failure, the information encryption publishing security terminal determines whether it is remotely logged in; In some embodiments, when there is an external access attempt and the information encryption publishing security terminal determines that the identity verification has not passed, the process is not terminated directly, but a subsequent investigation mechanism is quickly initiated to immediately determine whether the access is a remote login attempt. For example, after the information encryption publishing security terminal detects a signal of local identity verification failure, it will analyze the source IP address, port number and other characteristic information in the access request data packet, combined with the preset local network range whitelist, to determine whether the access is from a remote region, and then decide whether to enter the next step of the remote identity verification process.

[0062] S108. When the remote login passes the identity authentication, the information encryption release security terminal allows the information board to directly connect to the cloud platform server for updating; In some embodiments, once the information encryption and release security terminal determines that the access is a remote login and the authentication is passed, it immediately opens a direct connection and update shortcut for the information board. Here is a detailed description of the process of enabling the direct connection mode. When it is necessary to upgrade the outfield information board, for example, due to frequent commercial activities around the information board on a bustling road section, it is necessary to urgently update the special font library containing activity guidance signs to ensure accurate and efficient information guidance. At this moment, through multi-factor authentication such as entering the correct one-time dynamic password, accurate fingerprint recognition, and facial feature matching, the information encryption and release security terminal defense line is successfully breached. After the verification passes, the information encryption and release security terminal adjusts the network topology configuration. The operator first remotely logs in to the WEB configuration page of the information encryption and release security terminal. After passing the identity security verification, the network connection mode is set to the direct connection mode in the page operation. At this time, the management center can directly connect to the outfield information board through the network. The information board follows the update instruction pushed by the cloud platform server, and downloads and installs the latest font library file at full speed to ensure that the information display closely follows the on-site change rhythm.

[0063] S109. After the update is completed, the information encryption and release security terminal prohibits the information board from directly connecting to the cloud platform server for update.

[0064] In some embodiments, taking the major firmware upgrade of a highway information board as an example, after the system restarts, it presents a confirmation letter to the information encryption and release security terminal. After receiving it, the information encryption and release security terminal immediately clears the temporary network parameters preset for the direct connection update, including a series of operations such as deleting the temporary routing records in the routing table and shutting down the direct connection dedicated port. At this time, the operator needs to log in to the WEB configuration page of the information encryption and release security terminal again and restore the network connection mode to the encrypted communication mode to ensure the secure transmission of information during the subsequent normal operation of the information board.

[0065] It can be seen that when encountering firmware upgrades or special font library updates, if the remote login verification conditions are met, allowing the information board to directly connect to the cloud platform server for update breaks through the blocking limit of the information encryption and release security terminal on the manufacturer's debugging tools, avoids the inconvenience of only being able to upgrade on-site in the outfield, saves both manpower and material resources, and ensures the safety and controllability of the upgrade operation.

[0066] In the actual operation process of the road information board system, a dilemma is faced. When traffic information needs to be released externally, on the one hand, due to the real-time variability of traffic conditions, various situations may occur at any time on highways, etc., requiring the information to be presented on the information board lightning-fast from the information source end through each transmission node. On the other hand, such traffic information covers a high degree of content. Once leaked or maliciously tampered with, it is very likely to be exploited by lawbreakers, posing a serious threat to public safety. Therefore, encryption means must be adopted to ensure safety. However, encryption is not without cost. Whether it is the key generation and transformation operations in common symmetric encryption algorithms or the complex management and encryption / decryption operations of public and private keys in asymmetric encryption algorithms, they all inevitably consume a large amount of computing resources and significant time costs, slowing down the original information release rhythm, making the two key requirements of speed and encryption conflict with each other.

[0067] Please refer to Figure 6 , Figure 6 which is another process schematic diagram of the road information board information release security management method in the embodiments of the present application; Therefore, in some embodiments, before step S105, it further includes: S201. After receiving the announcement information to be released, the cloud platform server uses natural language processing to identify the punctuation marks and semantic logical breakpoints in the announcement information; In some embodiments, when the traffic command center enters new road condition information or the automatic acquisition system uploads real-time traffic dynamics, after the cloud platform server receives this announcement information to be released, it immediately starts the natural language processing process. It calls the built-in natural language processing module, which is based on a deep learning framework, such as constructed based on recurrent neural networks (RNN) and its variants long short-term memory networks (LSTM), gated recurrent units (GRU), and can effectively capture text sequence information. The module scans the input announcement information character by character, and based on the language rules learned in the pre-trained model, identifies the punctuation marks, and combines semantic understanding to judge semantic logical breakpoints such as causal relationships and parallel relationships, records the position information of these breakpoints, prepares for subsequent information division, updates the information status after processing, and waits for the next operation.

[0068] S202. The cloud platform server calculates the total length of the announcement information; In some embodiments, the cloud platform server then starts the process of calculating the total length. It traverses the processed announcement information, counts the characters one by one, starting from the first character at the starting position of the information. Each time a new character is read, the built-in counter is incremented by 1 until the end of the information is read. At this time, the value recorded by the counter is the total length of the announcement information.

[0069] S203. The cloud platform server determines the number of divisions according to the preset division degree and the total length; In some embodiments, after obtaining the total length of the published information, the cloud platform server immediately determines the number of divisions according to a preset division degree. Suppose the preset division degree is set such that the average length of each segment does not exceed 50 characters (including punctuation). If the total length of the current published information is 150 characters, through simple division calculation (150÷50 = 3), the number of divisions is obtained as 3 segments. However, the actual algorithm may be more complex and will comprehensively consider factors such as information structure and logical coherence. For example, for a text containing multiple parallel sub-information, even if the length does not exceed the limit, the number of division segments may be appropriately increased to improve the display clarity. After determining the number of divisions, it is recorded in the system configuration parameter area to provide a basis for the next division.

[0070] S204. The cloud platform server divides the published information at punctuation marks or semantic logical breakpoints according to the number of divisions; In some embodiments, after obtaining the number of divisions, the cloud platform server starts to divide the published information starting from the recorded punctuation mark and semantic logical breakpoint position information.

[0071] S205. The cloud platform server stores the divided paragraphs into the task queue according to the divisions; In some embodiments, after the cloud platform server completes the division of the published information, it immediately starts the process of storing the paragraphs into the task queue. It sequentially reads each of the divided paragraphs, starting from the first paragraph, and adds it as an independent data item to the end of the task queue, and so on for subsequent paragraphs.

[0072] S206. The cloud platform server retrieves paragraphs according to its computing power and performs parallel encryption using symmetric cryptography; In some embodiments, after the task queue is ready and the cloud platform server understands its own computing power, it starts to execute the parallel encryption process using symmetric cryptography. It first evaluates the number of encryption threads that can be simultaneously enabled according to the computing power. Suppose the server CPU has 8 cores and the GPU has a certain parallel computing capacity. After evaluation, 6 encryption threads can be simultaneously enabled. Then, paragraphs are sequentially retrieved from the head of the task queue, and each paragraph is assigned to an idle encryption thread. Each thread starts simultaneously and calls the built-in symmetric cryptography encryption module to encrypt the paragraph using a symmetric cryptography algorithm such as SM4. For example, the two retrieved paragraphs are "Section A is closed due to construction" and "Please detour to Section B". Two threads encrypt them respectively. The encryption process includes reading the pre-generated symmetric key and performing encryption operations such as exclusive OR operation and round function iteration on the paragraph text (the principle is the same as the previous symmetric cryptography encryption steps). After encryption, the encrypted paragraphs are temporarily stored in the server's dedicated encrypted result storage area waiting to be sent.

[0073] S207. The cloud platform server sends the encrypted paragraphs to the information encryption and publishing security terminal through the information board front-end machine.

[0074] It can be seen that the cloud platform server divides and encrypts the published information in parallel according to punctuation and semantic breakpoints based on natural language processing and intelligent partitioning strategies, balancing the speed of information publishing and encryption requirements. On the one hand, according to the real-time and variable road conditions, the information is quickly processed, and the published information is subdivided and encrypted in parallel using computing power, greatly shortening the encryption time-consuming, so that the information can quickly reach the information board from the source through each node; on the other hand, the whole process encryption ensures the confidentiality of information. Even in the face of attacks by lawbreakers, it can also protect the key traffic information and prevent it from being leaked and exploited.

[0075] Step S105 specifically includes: S208. The information encryption and publishing security terminal screens the buffer area and removes the buffer data with different symmetric passwords; In some embodiments, when the information encryption and publishing security terminal successively receives the encrypted paragraph data from the information board front-end machine and stores it in the buffer area, it starts the screening process. Its built-in password recognition module scans each piece of encrypted data in the buffer area, reads the password identification information at the head or attached to the data, and compares it with the standard symmetric password currently set by the system (such as the password algorithm identification corresponding to the pre-configured and regularly updated SM4 key). For example, if the system standard adopts the SM4 encryption algorithm, and some of the data in the buffer area carry the password identification corresponding to the old version key or suspected incorrect identification, these data are determined to be buffer data with different symmetric passwords, and the information encryption and publishing security terminal will isolate and mark them separately to prevent subsequent misoperations, ensure that the decryption process is based on the correct password system, and maintain the accuracy and security of information processing.

[0076] S209. The information encryption and publishing security terminal retrieves according to the encrypted paragraphs in the buffer area; In some embodiments, after the information encryption and publishing security terminal completes the screening of the buffer area to ensure the consistency of data passwords, it immediately starts the process of retrieving according to the encrypted paragraphs in the buffer area. It first reads the pre-stored decryption task list, which details the key identification information of each encrypted paragraph received from the cloud platform server, including the paragraph number, encryption algorithm type, and the corresponding expected decryption order, etc. Then, based on these identifications, the information encryption and publishing security terminal uses the built-in efficient retrieval algorithm to traverse and search the buffer area. For example, if the decryption task list indicates that the current paragraph number to be decrypted is 3 and the SM4 encryption algorithm is used, the information encryption and publishing security terminal quickly searches the buffer area for the encrypted data with this paragraph number and the password identification of SM4. Once found, it immediately locks its storage address to prepare for the next decryption operation.

[0077] S210. If there is an encrypted paragraph in the cached data, the information encryption and publishing security terminal reads the corresponding decryption result from the buffer according to the recorded storage address; In some embodiments, after the information encryption and publishing security terminal successfully retrieves a qualified encrypted paragraph from the buffer, it immediately queries the corresponding storage address index, which has been carefully established and maintained during the previous decryption process or data reception. For example, if the paragraph "The road ahead is congested due to an accident, please detour" has been successfully restored during a previous decryption operation and its decryption result is stored at the buffer address 0x1234, when the information encryption and publishing security terminal receives the decryption task of the same encrypted paragraph again, it quickly locates 0x1234 based on the index, directly reads the plaintext information stored at this address, and then temporarily stores it in a dedicated area for splicing, waiting to be uniformly spliced after all paragraphs are decrypted.

[0078] S211. If there is no encrypted paragraph in the cached data, the information encryption and publishing security terminal decrypts the encrypted paragraph using the symmetric cipher used to encrypt the encrypted paragraph; After the information encryption and publishing security terminal fails to retrieve the encrypted paragraph from the buffer, it immediately starts to prepare for decryption. It first reads the symmetric cipher key that matches the encrypted paragraph from the local secure storage medium. This key has been synchronized and configured with the cloud platform server during system initialization or key update to ensure consistency. For example, if the encrypted paragraph is encrypted using the SM4 algorithm, the information encryption and publishing security terminal accurately locates the corresponding SM4 key storage location, reads the key, and then uses the built-in decryption algorithm module to decrypt the encrypted paragraph bit by bit according to the symmetric cipher decryption steps mentioned above, such as first performing the reverse iterative operation of the round function and then performing the XOR operation (the principle is the same as steps S1043 and S1044), restoring the ciphertext to plaintext, and storing the obtained decryption result in a dedicated area for splicing, waiting for subsequent unified processing. The whole process is rigorous and orderly, ensuring that the information is restored safely and accurately.

[0079] S212. When all paragraphs are decrypted, the information encryption and publishing security terminal splices them in the order of paragraph identifiers to obtain the published information.

[0080] In some embodiments, when the information encryption and publishing security terminal confirms that all paragraphs have been decrypted and temporarily stored in the splicing area, it starts the splicing process. It reads and concatenates the content of each paragraph in sequence according to the paragraph identification number carried by each paragraph, starting from the paragraph with the smallest serial number. For example, if there are three paragraphs with identification numbers 1, 2, and 3 respectively, and the paragraph contents are "The road ahead is congested due to an accident", "Traffic police are on the scene to direct traffic", and "Please slow down for passing vehicles", the information encryption and publishing security terminal concatenates the three paragraphs in the order of 1-2-3 to form "The road ahead is congested due to an accident, traffic police are on the scene to direct traffic, please slow down for passing vehicles". The published information after concatenation then enters the subsequent review and distribution processes to ensure that it can be accurately and timely displayed on the information board to provide accurate traffic guidance for passing vehicles.

[0081] It can be seen that the information encryption and publishing security terminal optimizes the cache processing in the decryption link, improving the decryption efficiency. First, it filters out the cache data with different symmetric passwords, accurately locates the available cache, retrieves it according to the encrypted paragraph in the cache area, directly reads the decryption result if the corresponding paragraph exists, and only starts the conventional decryption if it does not exist. This avoids repeated decryption of the same information, reduces the consumption of computing resources, quickly restores the published information in the case of urgent traffic information release, enables the information board to quickly display accurate content, and ensures the timeliness of information transmission.

[0082] S213. For the encrypted paragraph that does not exist in the cache data, the information encryption and publishing security terminal calculates the hash value of the encrypted paragraph; In some embodiments, when the information encryption and publishing security terminal fails to retrieve the encrypted paragraph in the cache area and determines that it needs to decrypt the newly received encrypted paragraph, it immediately calls the hash calculation function. It reads the encrypted paragraph to be processed and inputs it completely into the selected hash function. The function performs operations on each character and byte information in the paragraph according to complex mathematical transformation rules, and finally outputs a hash value with a fixed length (such as 256 bits). For example, for the encrypted paragraph "Traffic control is implemented on the road ahead due to an accident, please detour", after calculation by the SHA-256 algorithm, a hash value similar to "5d41402abc4b2a76b9719d911017c592" is obtained. This value will be used as the key index of the encrypted paragraph in the subsequent cache management process and stored in a specific data structure to provide support for the subsequent steps.

[0083] S214. The information encryption and publishing security terminal creates a cache data node for the encrypted paragraph, the decrypted paragraph, the data identifier, the storage time, and the initial access count of 0, inserts the cache data node into the head of the linked list, and adds a key-value pair to the hash table; the key-value pair includes the hash value and the encrypted paragraph; In some embodiments, after calculating the hash value of the encrypted paragraph, the information encryption and publishing security terminal immediately proceeds to create a cache data node and perform a series of associated operations. First, a data identifier is generated according to the established system rules. For example, by combining information such as the current timestamp, paragraph serial number, and information source IP address, an identifier like "20250115_03_192.168.1.100" is generated to ensure uniqueness. Then, the current storage time accurate to milliseconds is recorded, such as "2025-01-15 10:30:25.123", and the position of the decrypted paragraph is left empty. Next, a cache data node structure containing the above information and an initial access count of 0 is created, and the encrypted paragraph and its corresponding hash value are filled in. After that, the node is inserted into the head of the linked list so that this new data can be processed preferentially during subsequent retrieval, improving efficiency; at the same time, a key-value pair with the just calculated hash value as the key and the encrypted paragraph as the value is added to the hash table. For example, if the hash value is "5d41402abc4b2a76b9719d911017c592" and the encrypted paragraph is "Traffic control is implemented on the forward section due to an accident. Please detour.", this key-value pair is newly added to the hash table to facilitate subsequent lightning positioning of the encrypted paragraph based on the hash value. After completing this series of delicate operations, the cache data management system is further improved, laying a solid foundation for subsequent information processing.

[0084] S215. The information encryption and publishing security terminal determines whether the linked list has reached a preset threshold. In some embodiments, after performing cache management tasks such as node movement (precursor operations related to step S215), the information encryption and publishing security terminal periodically checks the status of the linked list to determine whether it has reached the preset threshold. For example, based on past experience and hardware configuration, the system sets the preset threshold to 100 nodes. The information encryption and publishing security terminal obtains the number of nodes in the current linked list in real time through a built-in linked list length counter. Every certain time interval (such as 5 minutes), the counter value is read and compared with the preset threshold of 100 to determine whether the linked list is at full load or approaching saturation. If it is found that the number of nodes is about to exceed the threshold, subsequent cleaning preparations are made in advance to ensure the orderly operation of cache management and not affect the efficient flow of information on the information board.

[0085] S216. If the preset threshold is reached, the information encryption and publishing security terminal removes the cache data node from the tail of the linked list and deletes the corresponding key-value pair in the hash table.

[0086] In some embodiments, once the information encryption and publishing security terminal confirms that the linked list reaches a preset threshold, it immediately starts the cleaning process. It first locates the cached data node at the end of the linked list, quickly accesses this node through the tail pointer of the linked list, and reads the key information stored in the node, such as data identifiers, hash values, etc., so as to accurately locate the corresponding key-value pair in the hash table subsequently. Then, this node is removed from the linked list, and the memory space it occupies is released. This process involves adjusting the pointer relationship of adjacent nodes in the linked list to ensure the continuity of the linked list structure. For example, if there are 101 nodes in the linked list and after reaching the preset threshold of 100, the information encryption and publishing security terminal finds the node at the end of the linked list, and the encrypted paragraph stored in it is "Information on the early completion of construction on a certain section of the road". The information encryption and publishing security terminal disconnects this node, updates the pointer of the previous node to point to null, and at the same time reclaims the memory of this node. Subsequently, according to the previously read hash value, the corresponding key-value pair is searched for and deleted in the hash table. For example, if the hash value is "abcdef1234567890", the key-value pair with this hash value as the key and the corresponding encrypted paragraph as the value is found and deleted in the hash table. After completing this series of operations, the linked list and the hash table return to a relatively reasonable storage state, providing space guarantee for subsequent operations such as storing and retrieving cached data, and ensuring the smooth flow of the information processing process on the information display board.

[0087] It can be seen that before inserting the cached data node into the head of the linked list, the information encryption and publishing security terminal adds an operation to judge whether the linked list reaches the preset threshold, effectively optimizing the utilization of cache resources. Once the linked list reaches the threshold, the cached data node is taken out from the tail and the corresponding key-value pair is deleted to make room for new data, ensuring that the data stored in the buffer are all the most valuable recent data. This prevents the cache from growing without limit and causing resource waste, enabling the limited cache resources to focus on serving high-frequency encryption and decryption tasks.

[0088] S217. For the cached data with an encrypted paragraph, move the corresponding cached data node to the head of the linked list.

[0089] In some embodiments, when the information encryption and publishing security terminal detects that there is an encrypted paragraph in the cached data, that is, when there is a corresponding cached data node in the linked list for the previously processed data, it starts the node moving operation. First, based on the characteristics of the encrypted paragraph, such as paragraph number, hash value, etc., it quickly locates the corresponding cached data node in the linked list. By traversing the linked list nodes and comparing the key information stored in the nodes, once a matching node is found, it disconnects the node from its current position and then reinserts it at the head of the linked list. For example, if there are three nodes in the linked list, storing different encrypted paragraphs respectively, and it is found that an encrypted paragraph that was frequently accessed before is retrieved again, the information encryption and publishing security terminal quickly locates its node, removes it from the middle position of the linked list, and reinserts it at the head of the linked list. In this way, the next time it is retrieved, the node and its data will be processed first, improving the overall response speed of the system, making the management of cached data more intelligent and efficient, and meeting the real-time update requirements of the information on the information board.

[0090] It can be seen that after completing the decryption, splicing, and publishing of information, the fine management of cached data by the information encryption and publishing security terminal strengthens the system performance. For newly emerging encrypted paragraphs, it calculates the hash value, creates a cached node, and inserts it at the head of the linked list. At the same time, it adds a key-value pair to the hash table for convenient subsequent quick retrieval. For existing ones, it moves them to the head of the linked list to update the access status. In this way, the cache area always efficiently stores the data that is most likely to be reused, with a higher hit rate during subsequent decryption queries, continuously improving the system operation efficiency and reducing performance losses caused by poor cache management.

[0091] The following introduces the exemplary information encryption and publishing security terminal 700 provided by the embodiments of the present application. Figure 7 It is an exemplary hardware structure diagram of the information encryption and publishing security terminal 700 provided by the embodiments of the present application.

[0092] In some embodiments, the information encryption and publishing security terminal 700 is a computer device or the information encryption and publishing security terminal 700 includes a computer device. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The network interface of the computer device is used to communicate with other external terminals or servers through a network connection. In some embodiments, the network interface can be a wired network interface, and in some embodiments, the network interface can also be a wireless network interface. The computer program, when executed by the processor, implements the method in the embodiments of the present application.

[0093] Those skilled in the art can understand that Figure 7 The structure shown in Figure 7 is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.

[0094] As mentioned above, the above embodiments are only used to illustrate the technical solutions of this application, rather than to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0095] In the above embodiments, according to the context, the term "when..." can be interpreted to mean "if...", or "after...", or "in response to determining...", or "in response to detecting...". Similarly, according to the context, the phrase "when determining..." or "if detecting (the stated condition or event)" can be interpreted to mean "if determining...", or "in response to determining...", or "when detecting (the stated condition or event)", or "in response to detecting (the stated condition or event)".

[0096] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that the computer can access, or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state drive), etc.

[0097] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above-described embodiments can be completed by hardware instructed by a computer program. This program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the above-described method embodiments. The foregoing storage media include: various media that can store program codes, such as ROM, random access memory (RAM), magnetic disks, or optical discs.

Claims

1. A road information board information release security management method, applied to a road information board system, characterized in that: The road information board system includes a cloud platform server, an information board front-end, an information board gateway, and an information encryption and release security terminal located inside the information board, including: The information encryption and release security terminal performs identity verification on the information board gateway; When the identity verification is passed, the information encryption publishing security terminal establishes a communication link among the information board gateway, the information encryption publishing security terminal, the information board front-end processor, and the cloud platform server, and applies for a communication token from the cloud platform server through the communication link; The information encryption publishing security terminal receives the encrypted information sent by the cloud platform server through the information board front-end; The information encryption and release security terminal uses the symmetric cipher encrypted with the encrypted information to decrypt the encrypted information to obtain the published information; The information encryption and release security terminal audits the published information using an audit model detection; If the review is passed, the information encryption publishing security terminal will send the published information to the information board gateway.

2. The method according to claim 1, characterized in that After the step of the information encryption publishing security terminal performing identity verification on the information board gateway, the method further comprises: In the case of identity verification failure, the information encryption publishing security terminal determines whether it is remotely logged in; In the case of remote login passing identity verification, the information encryption publishing security terminal allows the information board gateway to directly connect to the cloud platform server for updating; After the update is completed, the information encryption publishing security terminal prohibits the information board gateway from directly connecting to the cloud platform server for updating.

3. The method according to claim 1, characterized in that The symmetric cipher is: During the encryption process, the information board front-end performs an XOR operation on the published information; The information board front-end processor performs iterative operation on the calculation result into the round function to obtain the encrypted information; During the decryption process, the information encryption and publishing security terminal performs iterative operations on the encrypted information entering the round function, wherein the iteration order and rules are opposite to those of the encryption process; The information encryption and release security terminal performs an XOR operation on the calculation result to obtain the published information.

4. The method according to claim 1, characterized in that: Before the step of decrypting the encrypted information using the symmetric cipher encrypted with the encrypted information to obtain the published information, the method further comprises: After receiving the published information to be published, the cloud platform server uses natural language processing to identify punctuation marks and semantic logic breakpoints in the published information; The cloud platform server calculates the total length of the published information; The cloud platform server determines the number of divisions according to a preset division degree and the total length; The cloud platform server divides the published information at the punctuation marks or the semantic logic breakpoints according to the number of divisions; The cloud platform server stores the divided sections into task queues; The cloud platform server retrieves the paragraphs according to computing power and encrypts them in parallel using the symmetric cipher; The cloud platform server sends the encrypted paragraphs to the information encryption and publishing security terminal through the information board front-end.

5. The method according to claim 4, characterized in that The step of the information encryption and release security terminal decrypting the encrypted information using the symmetric cipher encrypted with the encrypted information to obtain the published information specifically includes: The information encryption and publishing security terminal screens the cache area to remove cache data with different symmetric ciphers; The information encryption and publishing security terminal searches the cache area according to the encrypted paragraphs; If the cached data contains an encrypted segment, the information encryption publishing security terminal reads the corresponding decryption result from the cache area according to the recorded storage address; If the encrypted paragraph does not exist in the cached data, the information encryption publishing security terminal decrypts the encrypted paragraph using the symmetric cipher used to encrypt the encrypted paragraph; When all paragraphs are decrypted, the information encryption and publishing security terminal splices them in the order of paragraph identification to obtain the published information.

6. The method according to claim 5, characterized in that After the step of the information encryption and release security terminal splicing the published information in the order of paragraph identification after all paragraphs have been decrypted, the method further comprises: For cached data that does not contain an encrypted paragraph, the information encryption publishing security terminal calculates a hash value of the encrypted paragraph; The information encryption publishing security terminal creates an encrypted paragraph and a decrypted paragraph, a data identifier, a storage time, and a cache data node with an initial access count of 0, inserts the cache data node into the head of the linked list, and adds a key-value pair in the hash table; wherein the key-value pair includes a hash value and an encrypted paragraph; For encrypted segments of cached data, the corresponding cached data node is moved to the head of the linked list.

7. The method according to claim 6, characterized in that The information encryption publishing security terminal creates an encrypted paragraph and a decrypted paragraph, a data identifier, a storage time, and a cache data node with an initial access count of 0, and inserts the cache data node into the head of the linked list, and before the step of adding a key-value pair in the hash table, the method further includes: The information encryption and publishing security terminal determines whether the linked list reaches a preset threshold; If the preset threshold is reached, the information encryption publishing security terminal takes out the cache data node from the tail of the linked list and deletes the corresponding key-value pair in the hash table.

8. A secure terminal for information encryption and release, characterized in that: The information encryption publishing security terminal includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to enable the information encryption publishing security terminal to execute the method described in any one of claims 1-7.

9. A computer program product comprising instructions, characterized in that When the computer program product runs on an information encryption publishing security terminal, the information encryption publishing security terminal executes the method as described in any one of claims 1-7.

10. A computer-readable storage medium comprising instructions, characterized in that: When the instruction is executed on the information encryption publishing security terminal, the information encryption publishing security terminal executes the method as described in any one of claims 1-7.