Efficient cross-network data security exchange method and system for traffic accident information

By adopting the national secret algorithm and dynamic hybrid encryption technology in the cross-network data exchange system of traffic accident information, the problem of safe transmission of traffic accident information between different network environments is solved, and fast, safe and reliable data exchange is achieved, which improves the efficiency and security of information processing.

CN120090836APending Publication Date: 2025-06-03TRAFFIC MANAGEMENT RES INST OF THE MIN OF PUBLIC SECURITY
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510228972.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

Cross-network data exchange between traffic accident information from the Internet to the public security network faces multiple technical and management challenges such as information security, system compatibility, processing efficiency and data reliability.

Method used

The State Secret algorithm is used to encrypt and encapsulate traffic accident data through dynamic hybrid encryption and digital signatures, and legality and integrity verification are carried out in the data exchange system. During the transmission process, the data is decrypted and restored using a dynamic key to ensure the secure transmission of data between different network environments.

Benefits of technology

It realizes the rapid, safe and reliable exchange of traffic accident information between different network environments, improves the efficiency and flexibility of information processing, ensures the confidentiality, integrity and authenticity of data, and complies with the national laws and regulations on information security and data protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090836A_ABST
    Figure CN120090836A_ABST
Patent Text Reader

Abstract

The invention relates to a traffic accident information efficient cross-network data security exchange method and system. The method comprises the steps that after a request end initiates a request, a traffic accident data message is encrypted and packaged; the data exchange system performs legality and integrity verification on the traffic accident data request message after encryption packaging processing; in response to verification success, the data exchange system packages the traffic accident data verified successfully according to a specified sequence and format, then performs cross-network transmission, and transmits the traffic accident data to the public security network end from the Internet end; the public security network end decrypts and restores the traffic accident data message transmitted across the network based on a dynamic secret key; and after decryption and restoration processing, the public security network end sends a result receipt carrying a processing state and result information to the Internet end through the data exchange system. According to the invention, cross-network safe exchange of accident information is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cross-network data exchange of traffic accident information, and in particular to a method and system for efficient cross-network data security exchange of traffic accident information. Background Art

[0002] Traffic accident information covers core elements such as the accident location, time, details of the vehicles and personnel involved, and casualties. It is highly sensitive and touches on multiple key areas such as personal privacy protection, public safety maintenance, and legal liability definition. Therefore, after completing the collection on the Internet, exchanging accident information safely and efficiently to the public security network has become a complex and crucial task. This process requires comprehensive consideration of multiple dimensions such as information security, system compatibility, processing efficiency, and data reliability, and faces many technical and management challenges.

[0003] The National Secret Algorithm, as a cryptographic technology system independently developed by my country, plays a vital role in the field of information security with its excellent security protection capabilities, efficient computing and processing performance, and independent and controllable core advantages. The algorithm has been widely used in many key industries such as finance, government, and military, and has achieved remarkable security protection results.

[0004] In view of the sensitivity and importance of traffic accident information, as well as the urgent needs and severe challenges faced by cross-network data exchange, the development of a cross-network data exchange method for traffic accident information based on a national secret algorithm is not only a positive response to current information security needs, but also a key step in promoting intelligent and efficient traffic management. The proposal and implementation of this method will provide strong support for the rapid, safe and reliable exchange of traffic accident information, and further promote the informatization and intelligent development of the field of traffic management. Summary of the invention

[0005] To this end, the present invention provides a method and system for efficient cross-network data security exchange of traffic accident information, aiming to solve multiple key issues such as information security, efficient transmission and data integrity in data transmission, and ensure the secure cross-network exchange of accident information.

[0006] In order to solve the above technical problems, the present invention provides a method for efficient cross-network data security exchange of traffic accident information, the method is applied to a system for efficient cross-network data security exchange of traffic accident information, the system comprising a requesting end, an Internet end and a public security network end which are interconnected through a data exchange system;

[0007] The method comprises:

[0008] After the request end initiates the request, the traffic accident data message is encrypted and encapsulated;

[0009] The data exchange system verifies the legality and integrity of the traffic accident data request message after encryption and encapsulation;

[0010] In response to successful verification, the data exchange system packages the successfully verified traffic accident data in a specified order and format, and transmits the data across the network from the Internet end to the public security network end;

[0011] The public security network terminal decrypts and restores the traffic accident data message transmitted across the network based on the dynamic secret key;

[0012] After the decryption and restoration process, the public security network terminal sends a result receipt carrying processing status and result information to the Internet terminal through the data exchange system.

[0013] In one embodiment of the present invention, after the request end initiates the request, the traffic accident data message is encrypted and encapsulated, including:

[0014] The requesting end encapsulates the traffic accident data message information through methods including dynamic hybrid encryption and digital signature.

[0015] In one embodiment of the present invention, it also includes:

[0016] The data exchange system allocates the system unique identifier ui and encryption public key dp to the requesting end; at the same time, the requesting end generates a pair of public and private keys by itself; the public key rp is submitted to the data exchange system for storage and is bound and associated with the system unique identifier ui;

[0017] The requesting end uses the national SM4 block cipher algorithm to dynamically generate a 128-bit secret key m;

[0018] The request end assembles the system unique identifier ui and the business request data rd into the business request information r, encapsulates it into JSON format, and finally converts it into a byte stream r^;

[0019] The requester uses the ECB mode of the SM4 encryption algorithm and the PKCS5Padding filling method to encrypt the byte stream r^ with the secret key m to generate an encrypted message d;

[0020] The requester performs Base64 encoding on the encrypted message d to generate parameter d^;

[0021] The requesting end uses the encryption public key dp assigned by the data exchange system to encrypt the secret key m using the SM2 algorithm to generate the ciphertext m^;

[0022] The requesting end combines and encapsulates the interface ID, the system unique identifier ui, the parameter d^, and the ciphertext m^ into a request message in JSON format to generate a message λ to be transmitted;

[0023] The requesting end uses its own generated private key sp to sign the message λ using the SM2 algorithm, generating a signature string λ^. Then, the signature string λ^ and the message to be transmitted λ are combined into an overall object, and a data transmission request is initiated to the data exchange system through the HTTPS security protocol.

[0024] In an embodiment of the present invention, the data exchange system performs legality and integrity verification on the traffic accident data request message after encryption and encapsulation processing, including:

[0025] The data exchange system verifies whether the requesting end has been filed and whether the access address is in the whitelist;

[0026] The data exchange system performs SM2 signature verification on the request message;

[0027] After completing the exchange system authentication, writing data is allowed, and access is restricted if the authentication fails.

[0028] In an embodiment of the present invention, it further includes:

[0029] The data exchange system verifies whether the request message λ^ is a JSON string. If not, a general error message is returned;

[0030] The data exchange system verifies whether the necessary parameters of the request message λ^ are complete. If any are missing, a general error message is returned;

[0031] After the data exchange system de-JSONifies the request message λ^, it obtains the interface ID, the system unique identifier ui, the dynamic encryption key m^, and the request message d^;

[0032] The data exchange system determines whether the system unique identifier ui is configured in the system. If not, an error message is returned;

[0033] The data exchange system determines whether the request has relevant permissions, whether the access times are exceeded, whether the access time is exceeded, etc. based on the interface ID and the system unique identifier ui. If the conditions are not met, an error message is returned;

[0034] Based on the source IP obtained from the request, it is determined whether it is in the filing information. If the conditions are not met, an error message is returned;

[0035] Based on the system unique identifier ui, the public key rp filed by the requesting end in the data exchange system is obtained, and the public key rp is used to perform SM2 signature verification on the request message λ^. If the signature verification fails, an error message is returned;

[0036] After successful signature verification, the requesting end calls the interface to write the data to be transmitted.

[0037] In an embodiment of the present invention, the public security network side decrypts and restores the traffic accident data packet transmitted across the network based on a dynamic secret key, including:

[0038] The data exchange system obtains the private key dp that matches it according to the unique identifier ui of the requesting system;

[0039] The data exchange system uses the private key dp to perform SM2 decryption on the dynamic secret key m^ in the request packet λ^ to generate the plaintext dynamic secret key m;

[0040] Use the decrypted dynamic secret key m to perform SM2 decryption on the data packet λ^ to restore the original service data λ.

[0041] In an embodiment of the present invention, after the public security network side sends a result receipt carrying the processing status and result information to the Internet side through the data exchange system, it further includes:

[0042] The Internet side parses the result receipt to extract the processing result and status information;

[0043] The Internet side sends the parsed processing status and result information to the requesting side for the requesting side to view and confirm;

[0044] When there is abnormal information in the result receipt, the Internet side sends a notification to the requesting side to notify the requesting side to perform abnormal processing or investigation.

[0045] In an embodiment of the present invention, it further includes:

[0046] If the Internet side does not receive the result receipt after exceeding the preset time limit, it resends the data file to the specified directory of the Internet FTP;

[0047] In the case where the public security network side fails to correctly receive or crashes in the business microservice, if the data file is marked as to be processed and does not exceed the preset number of processing times, the data file is re-pushed to the business microservice at a set time interval.

[0048] The present invention also provides an efficient cross-network data security exchange system for traffic accident information, including a requesting side, an Internet side, and a public security network side that are communicatively connected to each other through a data exchange system; the system is used to execute the efficient cross-network data security exchange method for traffic accident information.

[0049] The above technical solution of the present invention has the following advantages compared with the prior art:

[0050] The efficient cross-network data security exchange method and system for traffic accident information according to the present invention have the following advantages: First, high security. The national cryptographic algorithm is adopted to ensure the confidentiality, integrity, and authenticity of data during transmission and storage, effectively preventing information leakage and tampering. Second, high efficiency. Optimized according to the characteristics of traffic accident information, while ensuring security, rapid data processing and transmission are achieved, meeting the requirements for rapid response to accident information in emergency situations. Third, cross-network compatibility. It can support secure data exchange between different networks (such as public security networks, the Internet, etc.), realizing seamless docking and sharing of traffic accident information, and improving the efficiency and flexibility of information processing. Fourth, easy integration. Standardized interfaces and protocols are provided, facilitating integration with existing traffic accident information management systems, and reducing the costs of system upgrade and transformation. Fifth, manageability and traceability. Through the cross-network platform, the data access process is monitored and managed, recording the source, destination, and processing process of data, providing strong support for data security and traceability. Sixth, compliance. Adopting the national cryptographic algorithm complies with the national laws and regulations on information security and data protection, helping to enhance the compliance and security of information transmission. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to make the content of the present invention easier to be clearly understood, the present invention will be further described in detail below according to specific embodiments of the present invention in conjunction with the accompanying drawings.

[0052] Figure 1 It is a flowchart of the efficient cross-network data security exchange method for traffic accident information provided by the present invention.

[0053] Figure 2 It is a flowchart of the accident data packet request encapsulation algorithm based on dynamic encryption provided by the present invention.

[0054] Figure 3 It is a flowchart of the accident data packet request verification algorithm based on the filing mechanism provided by the present invention.

[0055] Figure 4 It is a flowchart of the accident data packet decryption algorithm based on dynamic secret keys provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0056] The present invention will be further described below in conjunction with the accompanying drawings and specific embodiments, so that those skilled in the art can better understand the present invention and be able to implement it, but the embodiments cited are not intended to limit the present invention.

[0057] Refer to Figure 1As shown, a method for efficient cross-network data security exchange of traffic accident information of the present invention is applied to a system for efficient cross-network data security exchange of traffic accident information, wherein the system includes a requesting end, an Internet end, and a public security network end that are interconnected through a data exchange system;

[0058] The method comprises:

[0059] S1. After the requesting end initiates the request, the traffic accident data message is encrypted and encapsulated, and the encapsulated information is transmitted to the data exchange system.

[0060] Specifically, the requesting end initiates a request and first encapsulates the data message request. Dynamic hybrid encryption technology is used to encrypt the message using a key generated in real time. After encryption is completed, the encrypted message is digitally signed using the asymmetric encryption algorithm SM2. The encrypted and signed message and necessary metadata (such as timestamp, request type, etc.) are then encapsulated into a format that meets the requirements according to a predetermined protocol or standard.

[0061] It should be noted that the data exchange system uses the HTTPS protocol POST request mechanism to achieve data docking with other request subsystems. The cross-network data exchange system sets up a dedicated database to store the authorization information and request records of other request subsystems. The database contains key fields required for docking with other subsystems, such as system unique identification, interface identification, public key and private key, authorized service address, authorization validity period, operator, operation time and other basic information. In addition, the database also records the specific information of each request in detail, such as system unique identification, interface identification, request target address, request initiation time, request message content, request result, etc., to ensure the traceability and integrity of the data exchange process.

[0062] When the request system sends data to the terminal service through the cross-network data exchange system, the cross-network data exchange system will execute the data verification algorithm to verify the authorization of the request interface, determine whether the consumer-side service has been registered, whether it has obtained authorization to access specific functions and IP address authorization, etc. Only if the authorization verification is passed can the interface be called normally to write accident data; if the verification fails, the system will deny access. Authorization verification mainly includes the following contents:

[0063] Identity authentication: Verify the identity of the requesting system to ensure that the requesting system is within the configuration allowed range.

[0064] Permission verification: Verify whether the requesting system has the authority to perform a specific action or access a specific resource.

[0065] Role management: define different roles and their permissions to simplify permission management.

[0066] Multi-factor authentication: Provides multi-factor authentication mechanism to increase security.

[0067] Access Control List (ACL): Use ACL to control user access to specific resources.

[0068] Secure communication: Ensure the security of data transmission during the authentication and authorization processes, usually achieved through HTTPS.

[0069] Specifically, referring to Figure 2 As shown, when the requester initiates a cross-network data exchange request, it is necessary to perform dynamic hybrid encryption, digital signature, etc. on the accident data packet information, and generate a request packet that complies with the secure access specification to ensure that the data will not be illegally intercepted and tampered with during the transmission process. The main steps are as follows:

[0070] Step 101: The request end initiates a data exchange request, uses algorithms such as SM4, ECB, and PKCS5Padding to dynamically encrypt the unique identifier of the requester, the request interface ID, the allocated encryption public key, the private key generated by the system itself, and the service request data, and encapsulates them into a JSON string;

[0071] Step S102: Sign the JSON string using the SM2 algorithm;

[0072] Step S103: Transmit the above information as a request input to the cross-network data exchange system. After receiving the request parameters, the cross-network data exchange system needs to verify and check the request parameters.

[0073] In one embodiment, the data packet request encapsulation algorithm includes the following steps:

[0074] Step S1001: The data exchange system assigns a unique system identifier ui and an encryption public key dp to the request end; at the same time, the request end also needs to generate a pair of public and private keys by itself, where the public key rp is submitted to the data exchange system for storage and is bound and associated with the unique system identifier ui;

[0075] Step S1002: The request end dynamically generates a 128-bit secret key m using the national cipher SM4 block cipher algorithm;

[0076] Step S1003: The request end assembles the unique system identifier ui and the service request data rd into service request information r according to the system secure access specification, encapsulates it in JSON format, and finally converts it into a byte stream r^;

[0078] Step S1004: The request end encrypts the byte stream r^ using the ECB mode of the SM4 encryption algorithm and the PKCS5Padding filling method with the secret key m to generate an encrypted packet d;

[0079] Step S1005: The requesting end performs Base64 encoding on the encrypted message d to generate a parameter d^;

[0080] Step S1006: The requesting end uses the encryption public key dp assigned by the data exchange system to perform SM2 algorithm on the secret key m to generate a ciphertext m^;

[0081] Step S1007: The requesting end combines and encapsulates the interface ID, the system unique identifier ui, the parameter d^, and the ciphertext m^ into a request message in JSON format to generate a message λ to be transmitted;

[0082] Step S1008: The requesting end uses the private key sp generated by itself to sign the message λ using the SM2 algorithm to generate a signature string λ^, then combines the signature string λ^ and the message λ to be transmitted into an overall object, and initiates a data transmission request to the data exchange system through the HTTPS security protocol.

[0083] S2. After receiving the request, the data exchange system uses the filing mechanism and authority identification means to verify the legality and integrity of the encrypted and encapsulated traffic accident data request message; those that pass the verification are allowed to write data, and those that fail the verification are denied access.

[0084] It should be noted that after receiving the request, the data exchange system will perform security verification: first, verify whether the system is registered; second, verify whether the encryption or signature of the information data matches; third, verify whether the data size exceeds the limit; fourth, verify whether the system's sending frequency is too high per unit time. If the requesting end's permissions meet the requirements, it is allowed to write data; if the requesting end's permissions do not meet the requirements, the system denies access and records relevant error information. In addition, the system will also record detailed logs of request verification, including request time, requesting end IP address, verification results, etc., for subsequent audits and troubleshooting.

[0085] Specifically, refer to Figure 3 As shown, when the cross-network data exchange system receives the encrypted request message, it needs to perform security checks such as filing and permissions on the message, and then transmit it after passing the check to ensure the security, reliability and integrity of the data. It mainly includes the following steps:

[0086] Step S201: The data exchange system sequentially verifies the legitimacy of the request, parameter integrity, system configuration information, etc.;

[0087] Step S202: The data exchange system verifies whether the requesting end has been registered and whether the access address is in the whitelist;

[0088] Step S203: The data exchange system performs SM2 signature verification on the request message;

[0089] Step S204: Allow data writing after the exchange system authentication is completed; restrict access in case of authentication failure.

[0090] In one embodiment, the data packet request verification algorithm includes the following steps:

[0091] Step S2001: The data exchange system verifies whether the request packet λ^ is a JSON string. If not, a general error message is returned.

[0092] Step S2002: The data exchange system verifies whether the necessary parameters of the request packet λ∧ are complete. If any are missing, a general error message is returned.

[0093] Step S2003: After the data exchange system de-JSONifies the request packet λ^, it obtains the interface ID, the system unique identifier ui, the dynamic encryption key m^, and the request packet d^.

[0094] Step S2004: The data exchange system determines whether the system unique identifier ui is configured in the system. If not, an error message is returned.

[0095] Step S2005: The data exchange system determines whether the request has relevant permissions, whether the access times are exceeded, whether the access time is exceeded, etc. based on the interface ID and the system unique identifier ui. If the conditions are not met, an error message is returned.

[0096] Step S2006: Obtain the source IP according to the request and determine whether it is in the record information. If the conditions are not met, an error message is returned.

[0097] Step S2007: Obtain the public key rp filed by the request system in the data exchange system according to the system unique identifier ui, and use the public key rp to perform SM2 signature verification on the request packet λ^. If the signature verification fails, an error message is returned.

[0098] Step S2008: After the signature verification is successful, the request system calls the interface to write the data to be transmitted.

[0099] S3. In response to successful verification, the data exchange system packs the successfully verified traffic accident data in a specified order and format and performs cross-network transmission, from the Internet side to the public security network side.

[0100] The encapsulated and successfully verified accident data packet will be packed into a file format that meets the transmission requirements and uploaded to the specified directory of the Internet FTP. This directory is set with strict access control and encryption measures to ensure the security of the data before transmission.

[0101] S4. The public security network side decrypts and restores the traffic accident data packet transmitted across the network based on the dynamic key.

[0102] It should be noted that cross-network transmission is carried out through an exchange device (such as an optical switch, an optical disc ferry, etc.), and the packaged data is ferried from the Internet side to the FTP receiving directory of the public security network. During the transmission process, the system will monitor the transmission status in real time and record key information such as the transmission time and transmission result to ensure the integrity of the data and the success rate of the transmission. The decrypted service data is passed to the background microservice system through an internal interface, and the system stores it in the corresponding service database table according to the business logic.

[0103] In one embodiment, referring to Figure 4 as shown, the data packet decryption algorithm includes the following steps:

[0104] Step S401: The data exchange system obtains the private key dp that matches it according to the unique identifier ui of the requesting system.

[0105] Step S402: The data exchange system uses the private key dp to perform SM2 decryption on the dynamic key m^ in the request packet λ^ to generate the plaintext dynamic key m.

[0106] Step S403: Use the decrypted dynamic key m to perform SM2 decryption on the data packet λ^ to restore the original service data λ.

[0107] S5. After the decryption and restoration process, the public security network side sends a result receipt carrying the processing status and result information (as well as necessary metadata) to the Internet side through the data exchange system.

[0108] It should be noted that the public security network side pushes the decrypted and restored data to a specified microservice for processing. The microservice performs operations such as data analysis, storage, or forwarding according to business requirements, generates processing results and status information, and then transmits them to the Internet side.

[0109] After the public security network side obtains the data packet from the FTP receiving directory, it uses the SM2 algorithm to decrypt the data packet. During the decryption process, the system will verify the integrity and authenticity of the encrypted data to ensure that the data has not been tampered with or damaged during the transmission process. If the decryption is successful, the subsequent data processing will continue; if the decryption fails, the error information will be recorded and corresponding exception handling will be performed. The decrypted data will be stored in a secure location waiting for further processing and analysis.

[0110] It should be noted that after the request data is encrypted and passes the verification, it is written to the Internet side. The Internet side packages it into a file in the specified format and uploads it to the specified directory of the Internet FTP. The file in the specified directory of the FTP is ferried to the receiving directory of the public security network FTP by the exchange device at regular intervals. The data exchange platform on the public security network side fetches the file from the FTP receiving directory at regular intervals, decrypts it and parses it into the specified format, and pushes it to the specified microservice for processing. After the processing is completed, the microservice will send a processing result receipt to the data exchange platform on the public security network side, and the receipt file will be exchanged to the data exchange platform on the Internet side. Thus, through this interaction process, the system can effectively monitor whether the transmitted file is processed successfully.

[0111] S6. The Internet side parses the result receipt to extract the processing result and status information;

[0112] The Internet side sends the parsed processing status and result information to the request side for the request side to view and confirm;

[0113] When there is abnormal information in the result receipt, the Internet side sends a notice to the request side to notify the request side to perform abnormal handling or investigation.

[0114] During this process, the Internet side provides a file retransmission function to prevent problems such as file loss or slow reception. That is, when the receipt file has not been received after a certain time limit, the data file will be resent to the specified directory of the Internet FTP. The data exchange platform on the public security network side also provides a file retransmission function to prevent the business microservice from receiving errors or crashing. That is, when the data file is marked as pending processing and the number of processing times has not been exceeded, the data file will be pushed to the business microservice again at regular intervals. Through monitoring and retransmission, efficient, reliable and secure transmission of data files can be achieved, effectively improving the efficiency of data exchange between the internal and external networks of the system.

[0115] Throughout the process, each executing entity will record detailed log information, including key data such as request time, request content, processing result, error information, etc. The system regularly monitors and analyzes the logs to identify potential security threats, performance bottlenecks or abnormal situations. Through log analysis, problems in the system are discovered and repaired and optimized in a timely manner. In addition, the system will also perform security audits and performance optimizations to ensure the stability and security of the system. For important data, regular backup and recovery drills are carried out to ensure the reliability and availability of the data.

[0116] The present invention utilizes dynamic hybrid encryption and security authentication technologies to establish a data transmission channel between the Internet side and the public security network side, and constructs a secure and reliable cross-network data docking link. This technology adopts a dynamic encryption and filing mechanism, significantly improving the transmission efficiency and security of data in different network environments. It not only ensures the timeliness and accuracy of traffic accident information, but also effectively avoids the risk of data leakage during transmission, providing stronger information support for traffic management departments, providing powerful technical support for promoting the intelligent and refined development of traffic management, and being of great significance for enhancing public safety levels and promoting the sustainable development of the traffic industry.

[0117] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0118] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0119] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0120] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing the functions in Figure 1 one process or multiple processes and / or blocksFigure 1 Steps of the functions specified in one or more boxes.

[0121] Finally, it should be noted that the above specific embodiments are only used to illustrate the technical solutions of the present invention rather than to limit them. Although the present invention has been described in detail with reference to the examples, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A method for efficient cross-network data security exchange of traffic accident information, characterized in that: The method is applied to a traffic accident information efficient cross-network data security exchange system, the system comprising a request end, an Internet end and a public security network end that are interconnected through a data exchange system; The method comprises: After the request end initiates the request, the traffic accident data message is encrypted and encapsulated; The data exchange system verifies the legality and integrity of the traffic accident data request message after encryption and encapsulation; In response to successful verification, the data exchange system packages the successfully verified traffic accident data in a specified order and format, and transmits the data across the network from the Internet end to the public security network end; The public security network terminal decrypts and restores the traffic accident data message transmitted across the network based on the dynamic secret key; After the decryption and restoration process, the public security network terminal sends a result receipt carrying processing status and result information to the Internet terminal through the data exchange system.

2. A method for efficiently exchanging traffic accident information across networks for secure data exchange according to claim 1, characterized in that: After the request end initiates the request, the traffic accident data message is encrypted and encapsulated, including: The requesting end encapsulates the traffic accident data message information through methods including dynamic hybrid encryption and digital signature.

3. A method for efficiently exchanging traffic accident information across networks according to claim 2, characterized in that: Also includes: The data exchange system allocates the system unique identifier ui and encryption public key dp to the requesting end; at the same time, the requesting end generates a pair of public and private keys by itself; The public key rp is submitted to the data exchange system for storage and is bound to the system's unique identifier ui; The requesting end uses the national SM4 block cipher algorithm to dynamically generate a 128-bit secret key m; The request end assembles the system unique identifier ui and the business request data rd into the business request information r, encapsulates it into JSON format, and finally converts it into a byte stream r^; The requester uses the ECB mode of the SM4 encryption algorithm and the PKCS5Padding filling method to encrypt the byte stream r^ with the secret key m to generate an encrypted message d; The requester performs Base64 encoding on the encrypted message d to generate parameter d^; The requesting end uses the encryption public key dp assigned by the data exchange system to encrypt the secret key m using the SM2 algorithm to generate the ciphertext m^; The requesting end combines and encapsulates the interface ID, the system unique identifier ui, the parameter d^, and the ciphertext m^ into a request message in JSON format to generate a message λ to be transmitted; The requesting end uses the private key sp generated by itself to sign the message λ using the SM2 algorithm to generate a signature string λ^, then combines the signature string λ^ and the message λ to be transmitted into a whole object, and initiates a data transmission request to the data exchange system through the HTTPS security protocol.

4. A method for efficiently exchanging traffic accident information across networks for secure data exchange according to claim 1, characterized in that: The data exchange system performs a legality and integrity check on the encrypted and encapsulated traffic accident data request message, including: The data exchange system verifies whether the requesting end has been registered and whether the access address is in the whitelist; The data exchange system performs SM2 signature verification on the request message; After completing the exchange system authentication, data writing is allowed, and access is restricted if authentication fails.

5. A method for efficiently exchanging traffic accident information across networks for secure data exchange according to claim 4, characterized in that: Also includes: The data exchange system verifies whether the request message λ^ is a JSON string. If not, a general error message is returned. The data exchange system verifies whether the necessary parameters of the request message λ^ are complete. If they are missing, a general error message is returned; The data exchange system de-JSONs the request message λ^ to obtain the interface ID, the system unique identifier ui, the dynamic encryption key m^ and the request message d^; The data exchange system determines whether the system unique identifier ui is configured in the system. If not, an error message is returned. The data exchange system determines whether the request has relevant permissions, whether the number of accesses has been exceeded, whether the access time has been exceeded, etc. based on the interface ID and the system unique identifier UI. If the conditions are not met, an error message is returned; Obtain the source IP address based on the request and determine whether it is in the record information. If the conditions are not met, an error message is returned. According to the system unique identifier ui, the public key rp registered by the requesting end in the data exchange system is obtained, and the public key rp is used to perform SM2 signature verification on the request message λ^. If the signature verification fails, an error message is returned; After the signature verification is successful, the requesting end calls the interface to write the data to be transmitted.

6. A method for efficiently exchanging traffic accident information across networks for secure data exchange according to claim 5, characterized in that: The public security network terminal decrypts and restores the traffic accident data message transmitted across the network based on the dynamic secret key, including: The data exchange system obtains the private key dp matching the requesting system unique identifier ui; The data exchange system uses the private key dp to perform SM2 decryption on the dynamic key m^ in the request message λ^ to generate a plaintext dynamic key m; Use the decrypted dynamic key m to perform SM2 decryption on the data message λ^ to restore the original business data λ.

7. A method for efficiently exchanging traffic accident information across networks for secure data exchange according to claim 1, characterized in that: After the public security network terminal sends a result receipt carrying processing status and result information to the Internet terminal through the data exchange system, the method further includes: The Internet end parses the result receipt to extract the processing result and status information; The Internet end sends the processing status and result information obtained by parsing to the request end for the request end to view and confirm; When there is abnormal information in the result receipt, the Internet end sends a notification to the requesting end to notify the requesting end to handle or investigate the abnormality.

8. A method for efficiently exchanging traffic accident information across networks for secure data exchange according to claim 7, characterized in that: Also includes: If the Internet end has not received the result receipt within the preset time limit, the data file will be resent to the Internet FTP designated directory; When the business microservice fails to receive the data correctly or crashes on the public security network, if the data file is marked as pending and has not exceeded the preset number of processing times, the data file will be pushed to the business microservice again at the set time interval.

9. A traffic accident information efficient cross-network data security exchange system, characterized in that: It includes a request end, an Internet end and a public security network end which are interconnected through a data exchange system; the system is used to execute the efficient cross-network data security exchange method for traffic accident information as described in any one of claims 1-8.

Citation Information

Cited By

  • Subway line network power equipment control right transfer method and system

    CN120909174A