Data management method and system for ship-shore data interaction and collaborative decision
By combining layered encryption with improved Merkel tree in the ship-shore data interaction system, the shortcomings of existing systems in terms of encryption security, transmission reliability and real-time are solved, and the coordinated optimization of security, reliability and real-time data transmission is achieved.
Patent Information
- Application Number
- CN202510534891.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-04-27
AI Technical Summary
The existing ship-shore data interaction system has shortcomings in encryption security, transmission reliability and real-time performance, resulting in insufficient real-time and reliability of data interactions, affecting the accuracy and timeliness of collaborative decision-making.
The data management method combined with hierarchical encryption and improved Merkel tree is adopted, and the coordinated optimization of data transmission security, reliability and real-time through a hierarchical encryption strategy based on data type and security level, combined with an improved Merkel tree structure with forward error correction mechanism.
It effectively solves the problem that traditional unified encryption solutions are difficult to take into account real-time and security, improves the reliability and real-time nature of data transmission, and optimizes the efficiency of ship-shore data encryption and packet loss recovery capabilities.
Smart Images

Figure CN120200831A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data management, and in particular, to a data management method and system for ship-shore data interaction and collaborative decision-making. Background Art
[0002] With the rapid development of intelligent shipping technology, the demand for data interaction between ships and shore-based platforms has been increasing day by day, and it has become the key to realizing intelligent navigation, remote monitoring, and collaborative decision-making. Currently, ship-shore data interaction systems mainly rely on traditional encryption communication protocols to achieve data transmission between ships and shore-based platforms. Such systems usually adopt end-to-end encryption technology to ensure communication security and verify data integrity through check codes or digital signatures.
[0003] With the rapid development of intelligent shipping technology, data interaction between ships and shore-based platforms faces the following challenges: In terms of encryption security, existing systems use a unified encryption intensity to process all data types, resulting in high-timeliness dynamic data being affected by encryption delay and affecting real-time response, while highly sensitive static data has security risks due to insufficient encryption intensity; in terms of transmission reliability, traditional integrity verification mechanisms are difficult to effectively cope with data packet loss problems in complex marine communication environments. When partial data is lost, the entire data packet often needs to be retransmitted, causing serious bandwidth waste and transmission delay; in terms of real-time guarantee, the lack of an adaptive transmission strategy makes it difficult for the system to respond to network state changes in a timely manner and difficult to provide a stable low-latency channel for critical navigation instructions.
[0004] The above-mentioned defects lead to decision-making errors such as delays in ship collision avoidance instructions and port scheduling conflicts in actual collaborative operations due to insufficient real-time and reliability of data interaction; at the same time, the problem of inconsistent data versions causes deviations in the understanding of the navigation situation between the ship and the shore, seriously affecting the accuracy and timeliness of collaborative decision-making.
[0005] Therefore, there is an urgent need for a new ship-shore data interaction solution that can simultaneously optimize encryption efficiency, improve packet loss recovery ability, and ensure real-time transmission. Summary of the Invention
[0006] To solve the above-mentioned defects, this application provides a data management method and system for ship-shore data interaction and collaborative decision-making.
[0007] The first invention object of this application is achieved through the following technical solutions:
[0008] A data management method for ship-shore data interaction and collaborative decision-making, executed by a transmission end, includes the steps of:
[0009] Obtain ship-shore data, perform data chunking on the ship-shore data to obtain several ship-shore data chunks, and add a unique corresponding sequence identifier and a timeliness timestamp to the ship-shore data chunks;
[0010] Perform hierarchical encryption processing on the ship-shore data chunks and generate their corresponding error correction redundancy codes to obtain several encrypted data chunks;
[0011] Construct an improved Merkle tree based on the encrypted data chunks. The nodes of the improved Merkle tree include the composite hash values of the encrypted data chunks and the verification information of the forward error correction redundancy codes;
[0012] Generate a first transmission packet based on the encrypted data chunks and the improved Merkle tree, and match the corresponding transmission mode according to the network state;
[0013] Send the first transmission packet to the receiving end based on the matched transmission mode, so that the receiving end verifies and decrypts the first transmission packet based on the improved Merkle tree.
[0014] By adopting the above technical solutions, a ship-shore data interaction architecture combining hierarchical encryption and an improved Merkle tree is constructed to realize the coordinated optimization of data transmission security, reliability, and real-time performance: by adopting a hierarchical encryption strategy based on data types and security levels, the problem that the traditional unified encryption scheme is difficult to balance real-time performance and security is effectively solved; by introducing an improved Merkle tree structure integrating a forward error correction mechanism, error localization and local data recovery are supported during the data verification process, overcoming the defect that the traditional verification mechanism requires full-scale retransmission when some data is lost; through an intelligent matching mechanism adaptive to the network state, the selection of transmission strategies under different network environments is realized, and the transmission efficiency under complex communication conditions is significantly improved, having the effects of optimizing the ship-shore data encryption efficiency, enhancing the packet loss recovery ability, and improving the real-time transmission efficiency.
[0015] In a preferred example of the present application, it can be further configured that: the step of performing hierarchical encryption processing on the ship-shore data chunks and generating their corresponding error correction redundancy codes to obtain several encrypted data chunks includes the steps of:
[0016] Identify the data types of several ship-shore data chunks respectively, and obtain the corresponding security level requirements;
[0017] Match the corresponding encryption scheme based on the data type and the security level requirements;
[0018] Perform hierarchical encryption processing on several ship-shore data chunks based on the matched encryption scheme.
[0019] By adopting the above technical solution, hierarchical encryption processing is performed on the ship-shore data block, achieving a dynamic balance between data security and processing efficiency, and having the effect of improving the overall performance of the ship-shore collaboration system; specifically, by identifying the data type of the ship-shore data block and obtaining its security level requirements, the characteristics of navigation data are captured; by establishing a two-dimensional matching mechanism for data type and security level, the most suitable encryption scheme is intelligently selected for each type of data, avoiding performance waste caused by unified encryption and preventing security risks caused by insufficient encryption intensity; by implementing hierarchical encryption processing, the overall encryption efficiency is optimized on the premise of ensuring the security of core data.
[0020] In a preferred example of the present application, it can be further configured as: the step of constructing an improved Merkle tree based on the encrypted data block, where the nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundancy code, and includes the steps of:
[0021] Generating a composite hash value for the encrypted data block by adopting a preset multi-level hash calculation strategy;
[0022] Constructing an improved Merkle tree based on the composite hash value, where the leaf nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundancy code;
[0023] Associating the constructed improved Merkle tree with the encrypted data block to form a verifiable data structure.
[0024] By adopting the above technical solution, a data verification system for an improved Merkle tree is constructed, achieving a coordinated improvement in the integrity verification and fault tolerance recovery capabilities of ship-shore data, and having the effect of optimizing data transmission reliability and verification efficiency; specifically, the composite hash value generated by the multi-level hash calculation strategy contains both data content characteristics and redundant code verification information, and through this composite verification mechanism, data tampering and transmission errors can be detected simultaneously; when constructing the improved Merkle tree, the composite hash value and the redundant code verification information are jointly embedded in the leaf nodes to form a data structure containing complete verification elements, enabling a single verification operation to complete the double inspection of data integrity and recoverability; by establishing an association mapping between the Merkle tree and the encrypted data block, a hierarchical verifiable data structure is constructed, which not only supports quick positioning of problem data blocks but also can perform local data repair according to the embedded redundant code information; the present application integrates multiple verification elements through the improved Merkle tree design, simplifies the verification process, and at the same time significantly reduces the data retransmission requirement through the built-in redundancy recovery mechanism, effectively improving the overall efficiency of ship-shore data interaction on the premise of ensuring verification reliability.
[0025] In a preferred example of the present application, it can be further configured as: the step of generating a composite hash value for the encrypted data block by adopting a preset multi-level hash calculation strategy includes the steps of:
[0026] Calculate the content hash value of the encrypted data block;
[0027] Perform combined hash value calculation on the content hash value and the verification information of the error correction redundancy code;
[0028] Add the corresponding sequence identifier and timeliness timestamp to the combined hash value for composite hash value calculation.
[0029] By adopting the above technical solution, a composite hash value is generated by using a hierarchical progressive multi-level hash calculation strategy, realizing triple guarantees of data integrity verification, fault tolerance verification, and spatio-temporal characteristic verification, and having the effect of constructing a multi-faceted data trusted verification system; specifically, calculating the content hash value of the encrypted data block establishes a basic data integrity verification benchmark, and then combining the content hash with the verification information of the error correction redundancy code to form a data recoverability verification layer. Finally, a spatio-temporal characteristic verification layer is constructed by integrating the sequence identifier and the timestamp. This hierarchical progressive calculation method enables the composite hash value to not only retain the data anti-tampering function of the traditional hash but also add the verification capabilities for the correctness of the data order and timeliness; through the structured composite hash calculation process, this application can not only accurately identify whether the data content has been tampered with but also synchronously verify whether the data transmission order is correct, whether it is received within the valid time window, and whether it has the error correction and recovery capabilities, providing a three-dimensional verification mechanism covering content, time sequence, and spatial dimensions for ship-shore data interaction, and having the effect of improving the reliability of data transmission and the timeliness of collaborative decision-making.
[0030] In a preferred example, this application can be further configured as: the encrypted data block includes a static navigation data block and a dynamic navigation data block, and the steps of constructing an improved Merkle tree based on the encrypted data block, where the nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundancy code, include the steps of:
[0031] Construct a full-scale Merkle tree for the static navigation data block and an incremental Merkle tree for the dynamic navigation data block;
[0032] Establish an improved tree structure association between the full-scale Merkle tree and the incremental Merkle tree, and the improved tree structure association includes version anchoring and spatio-temporal association.
[0033] By adopting the above technical solution, a full - scale Merkle tree and an incremental Merkle tree are respectively constructed for static and dynamic navigation data, and an improved tree - structure association is established, realizing the optimization of the efficiency and flexibility of the ship - shore data verification system, and having the effect of improving the heterogeneous data processing efficiency. Specifically, for the slowly - changing static navigation data, a full - scale Merkle tree structure is adopted to ensure the integrity and stability of the basic navigation information. For the dynamically - changing dynamic navigation data, an incremental Merkle tree structure is adopted, and only the changed data is subjected to hash calculation and verification, reducing the computational overhead. The full - scale tree and the incremental tree are spatio - temporally associated through the version anchoring mechanism, which not only maintains the benchmark verification function of the static data but also realizes the fast update verification of the dynamic data. At the same time, the spatio - temporal association ensures the consistency of the two types of data in the time dimension and the space dimension. Through the design of a hybrid tree structure that coordinates the full - scale tree and the incremental tree, the present application realizes both meeting the high - reliability requirements of the navigation basic data and adapting to the real - time requirements of the dynamic data. The collaborative verification of the two types of data is realized through version anchoring, providing a dual guarantee of both efficiency and safety for ship - shore collaborative decision - making, and effectively solving the problems of large computational resource consumption and low verification efficiency faced by traditional solutions when processing a large amount of heterogeneous navigation data.
[0034] In a preferred example, the present application can be further configured as follows: The first transmission packet includes a full - scale mode transmission packet and an incremental mode transmission packet. The step of generating the first transmission packet based on the encrypted data block and the improved Merkle tree and matching the corresponding transmission mode according to the network state includes the steps of:
[0035] Generating a full - scale mode transmission packet and an incremental mode transmission packet respectively based on the full - scale Merkle tree and the incremental Merkle tree;
[0036] Evaluating the current network state and matching the corresponding transmission mode based on the evaluation result. The transmission modes include a full - scale mode, an incremental mode, and an emergency mode.
[0037] By adopting the above technical solution, a multi-mode adaptive transmission mechanism is established to achieve the optimal transmission strategy selection for ship-shore data interaction under different network conditions, which has the effect of improving the reliability of data transmission and the efficiency of resource utilization. Specifically, full-mode transmission packets and incremental-mode transmission packets are generated based on the full Merkle tree and the incremental Merkle tree respectively, providing differentiated transmission solutions for different network states. By real-time evaluating the network state and intelligently matching the optimal transmission mode, the full mode is adopted under good network conditions to ensure data integrity, the incremental mode is adopted under normal network conditions to improve transmission efficiency, and the emergency mode is switched to when the network is abnormal to ensure the transmission of critical data. Through the dynamically adjusted multi-mode adaptive transmission mechanism, this application not only makes full use of network resources but also ensures the reliability of data transmission in different network environments, effectively solving the problem that the traditional single transmission mode cannot adapt to the changes in the complex marine communication environment and providing a stable and efficient data transmission guarantee for ship-shore collaborative decision-making.
[0038] The second above-mentioned inventive object of this application is achieved through the following technical solutions:
[0039] A data management system for ship-shore data interaction and collaborative decision-making, deployed at the transmission end, includes:
[0040] A processing module, used to obtain ship-shore data, perform data chunking processing on the ship-shore data to obtain a number of ship-shore data chunks, and add a uniquely corresponding sequence identifier and a timeliness timestamp to the ship-shore data chunks;
[0041] An encryption module, used to perform hierarchical encryption processing on the ship-shore data chunks and generate their corresponding error correction redundancy codes to obtain a number of encrypted data chunks;
[0042] A construction module, used to construct an improved Merkle tree based on the encrypted data chunks, and the nodes of the improved Merkle tree include the composite hash value of the encrypted data chunks and the verification information of the forward error correction redundancy codes;
[0043] A matching module, used to generate a first transmission packet based on the encrypted data chunks and the improved Merkle tree, and match the corresponding transmission mode according to the network state;
[0044] A transmission module, used to send the first transmission packet to the receiving end based on the matched transmission mode, so that the receiving end verifies and decrypts the first transmission packet based on the improved Merkle tree.
[0045] By adopting the above technical solution, a processing module is configured to obtain ship-shore data, perform data chunking on the ship-shore data to obtain a number of ship-shore data chunks, and add a uniquely corresponding sequence identifier and a timeliness timestamp to the ship-shore data chunks; an encryption module is configured to perform hierarchical encryption processing on the ship-shore data chunks and generate corresponding error correction redundancy codes thereof to obtain a number of encrypted data chunks; a construction module is configured to construct an improved Merkle tree based on the encrypted data chunks, where the nodes of the improved Merkle tree include the composite hash values of the encrypted data chunks and the verification information of the forward error correction redundancy codes; a matching module is configured to generate a first transmission packet based on the encrypted data chunks and the improved Merkle tree, and match a corresponding transmission mode according to the network state; a transmission module is configured to send the first transmission packet to a receiving end based on the matched transmission mode, so that the receiving end verifies and decrypts the first transmission packet based on the improved Merkle tree.
[0046] In a preferred example of the present application, it can be further configured that: the encryption module includes:
[0047] a data type acquisition sub-module, configured to respectively identify the data types of a number of ship-shore data chunks and obtain corresponding security level requirements;
[0048] an encryption scheme matching sub-module, configured to match a corresponding encryption scheme based on the data type and the security level requirements;
[0049] a hierarchical encryption processing sub-module, configured to perform hierarchical encryption processing on a number of ship-shore data chunks based on the matched encryption scheme.
[0050] By adopting the above technical solution, the encryption module includes: a data type acquisition sub-module, configured to respectively identify the data types of a number of ship-shore data chunks and obtain corresponding security level requirements; an encryption scheme matching sub-module, configured to match a corresponding encryption scheme based on the data type and the security level requirements; a hierarchical encryption processing sub-module, configured to perform hierarchical encryption processing on a number of ship-shore data chunks based on the matched encryption scheme.
[0051] In summary, the present application includes at least one of the following beneficial technical effects:
[0052] 1. This application realizes the collaborative optimization of data transmission security, reliability, and real-time performance by constructing a ship-shore data interaction architecture that combines hierarchical encryption and an improved Merkle tree. By adopting a hierarchical encryption strategy based on data types and security levels, it effectively solves the problem that traditional unified encryption schemes are difficult to balance real-time performance and security. By introducing an improved Merkle tree structure that incorporates a forward error correction mechanism, it supports error localization and partial data recovery during the data verification process, overcoming the defect that traditional verification mechanisms require full retransmission when some data is lost. Through an intelligent matching mechanism that adapts to network status, it realizes the selection of transmission strategies under different network environments, significantly improving the transmission efficiency under complex communication conditions, and has the effects of optimizing the ship-shore data encryption efficiency, enhancing the packet loss recovery ability, and improving the real-time transmission efficiency.
[0053] 2. Through the structured composite hash calculation process, this application can not only accurately identify whether the data content has been tampered with, but also synchronously verify whether the data transmission order is correct, whether it is received within the valid time window, and whether it has the error correction and recovery ability, providing a three-dimensional verification mechanism covering content, time sequence, and spatial dimensions for ship-shore data interaction, and having the effects of enhancing the reliability of data transmission and the timeliness of collaborative decision-making.
[0054] 3. Through the design of a hybrid tree structure that coordinates full trees and incremental trees, this application realizes both meeting the high-reliability requirements of navigation basic data and adapting to the real-time performance needs of dynamic data. Through version anchoring, it realizes the collaborative verification of the two types of data, providing a dual guarantee of both efficiency and security for ship-shore collaborative decision-making, and effectively solving the problems of high computational resource consumption and low verification efficiency faced by traditional schemes when dealing with massive heterogeneous navigation data. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] Figure 1 is a flowchart of an embodiment of a data management method for ship-shore data interaction and collaborative decision-making in this application;
[0056] Figure 2 is an implementation flowchart of step S20 in an embodiment of a data management method for ship-shore data interaction and collaborative decision-making in this application;
[0057] Figure 3 is an implementation flowchart of step S30 in an embodiment of a data management method for ship-shore data interaction and collaborative decision-making in this application;
[0058] Figure 4 is an implementation flowchart of step S31 in an embodiment of a data management method for ship-shore data interaction and collaborative decision-making in this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0059] The following is combined with the attached Figures 1-4Further detailed description of the present application is provided as follows.
[0060] In one embodiment, as Figure 1 shown, the present application discloses a data management method for ship-shore data interaction and collaborative decision-making, which is executed by a transmission end and specifically includes the following steps:
[0061] S10: Obtain ship-shore data, perform data chunking processing on the ship-shore data to obtain a number of ship-shore data chunks, and add a uniquely corresponding sequence identifier and a timeliness timestamp to the ship-shore data chunks;
[0062] In this embodiment, the ship-shore data is various data exchanged between a ship and a shore-based system, including but not limited to navigation status data, meteorological information, cargo information, equipment status, etc. Its characteristics are that it has spatio-temporal attributes (such as timestamps, location information) and business attributes (such as data types, priorities); data chunking processing is to divide continuous ship-shore data into several independent data chunks according to a fixed or dynamic size. After data chunking processing, each obtained ship-shore data chunk can be processed independently, which is convenient for parallel encryption, transmission, and verification. Among them, the chunk size can be dynamically adjusted according to the data type or network conditions; the sequence identifier is a unique serial number assigned to each ship-shore data chunk, which is used to identify the transmission order of the ship-shore data chunks. The sequence identifier usually has continuity (such as an increasing ID), and can be used to detect data loss, out-of-order, or duplicate reception; the timeliness timestamp is a time mark that records the exact time (such as UTC time) when the ship-shore data chunk is generated or processed, which is used to verify the timeliness of the data. The timestamp can set an effective window (such as ±5 minutes), and the data that times out will be regarded as invalid;
[0063] Specifically, ship-shore data such as the ship's position, speed, heading, cargo information, and equipment status are collected through devices such as the Automatic Identification System (AIS), Electronic Chart Display and Information System (ECDIS), and Voyage Data Recorder (VDR). The original data is divided into several ship-shore data chunks by using a fixed-size chunking strategy, and each ship-shore data chunk is assigned an increasing serial number and a timeliness timestamp accurate to the second to ensure that the data is traceable and has timeliness constraints.
[0064] S20: Perform hierarchical encryption processing on the ship-shore data chunks and generate their corresponding error correction redundancy codes to obtain a number of encrypted data chunks;
[0065] In this embodiment, the hierarchical encryption process adopts different encryption strategies according to data types or security levels. For example, it may include: using high-strength encryption (such as AES-256) for core navigation data, standard encryption (such as AES-128) for ordinary data, lightweight encryption (such as ChaCha20) for metadata, etc.; the error correction redundancy code is redundant data generated based on the forward error correction (FEC) technology (such as Reed-Solomon code), which can restore the original content when part of the data is lost during transmission, and the redundancy degree of the error correction redundancy code can be dynamically adjusted according to network stability; the encrypted data block is a data unit after hierarchical encryption and adding error correction redundancy code, including the encrypted original data content, error correction redundancy code, encrypted metadata (such as algorithm identifier, key index), etc.;
[0066] Specifically, differential encryption is implemented for ship-shore data blocks. For example: critical data such as navigation warnings is encrypted using AES-256, log data uses AES-128, and a Reed-Solomon error correction code accounting for 15% of the original data is generated for each encrypted block, etc.; each encrypted data block after processing contains encrypted content, error correction code, and encrypted algorithm identifier.
[0067] S30: Construct an improved Merkle tree based on the encrypted data block. The nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundancy code;
[0068] In this embodiment, the improved Merkle tree is a data structure enhanced on the basis of the traditional Merkle tree. Its features may include: leaf nodes store the composite hash value of the encrypted data block, non-leaf nodes store the aggregated value of the sub-node hashes, each node is appended with the verification status of the redundancy code, supporting fast verification of data integrity and recoverability, etc.; the composite hash value is a comprehensive check value generated through multi-level hash calculation;
[0069] Specifically, construct an improved Merkle tree for each encrypted data block, where the nodes of the improved Merkle tree store the composite hash value of the encrypted data block and the verification information of the forward error correction redundancy code.
[0070] S40: Generate a first transmission packet based on the encrypted data block and the improved Merkle tree, and match the corresponding transmission mode according to the network status;
[0071] In this embodiment, the first transmission packet is a packaged transmission data set generated from the encrypted data block and the improved Merkle tree; the transmission mode matching is to select the optimal or most suitable transmission strategy according to real-time network evaluation (such as bandwidth, latency, packet loss rate);
[0072] Specifically, serialize the encrypted data block and the improved Merkle tree into the first transmission packet, and select the transmission strategy according to the real-time network detection result.
[0073] S50: Send the first transport packet to the receiving end based on the matching transport mode, so that the receiving end verifies and decrypts the first transport packet based on the improved Merkle tree.
[0074] In this embodiment, the receiving end verifies and decrypts the first transport packet in the following manner: check the matching of the composite hash value with the nodes of the improved Merkle tree, verify the continuity of the sequence identifier and the validity of the timeliness timestamp, repair the damaged data blocks using the error correction redundancy code, and decrypt the data blocks that pass the verification.
[0075] Among them, the transmitting end is a device or system responsible for collecting, processing, encrypting, packaging, and sending ship-shore data; the receiving end is a device or system for receiving, verifying, decrypting, and processing ship-shore data; in this embodiment, both the ship end and the shore-based end can be used as the transmitting end, and the end that receives the data sent by the transmitting end is used as the receiving end.
[0076] Specifically, the first transport packet is sent to the receiving end based on the matching transport mode, and the receiving end verifies and decrypts the received first transport packet in the following manner: check the matching of the composite hash value with the nodes of the improved Merkle tree, verify the continuity of the sequence identifier and the validity of the timeliness timestamp, repair the damaged data blocks using the error correction redundancy code, and decrypt the data blocks that pass the verification.
[0077] In one embodiment, as Figure 2 shown, step S20 includes the steps:
[0078] S21: Identify the data types of several ship-shore data blocks respectively, and obtain the corresponding security level requirements.
[0079] S22: Match the corresponding encryption scheme based on the data type and the security level requirements.
[0080] S23: Perform hierarchical encryption processing on several ship-shore data blocks based on the matching encryption scheme.
[0081] In this embodiment, the ship-shore data block is a ship-shore interaction data unit after block processing, containing structured data such as navigation status, equipment parameters, and cargo information. Each ship-shore data block has a fixed size and a clear boundary identifier; the data type is a category divided according to the characteristics of the data content, including but not limited to: dynamic navigation data (such as GPS positioning, speed), static configuration data (such as ship certificates, cargo lists), control instruction data (such as course adjustment commands), and multimedia data (such as surveillance videos), etc.; the security level requirement is a protection level defined based on data sensitivity, for example: top secret level (such as navigation control instructions), confidential level (such as ship position data), secret level (such as equipment operation logs), and general level (such as meteorological broadcast information), etc.; the encryption scheme is a combination of encryption policies configured for specific data types and security levels, including: encryption algorithm, key length, working mode, key update period, etc.
[0082] Specifically, through predefined data feature recognition rules (such as data source port, message header identifier, content format, etc.), the data type of each ship-shore data block is automatically determined. At the same time, the security policy library is queried to obtain the corresponding security level standard and security level requirement for this data type. For example, radar data is recognized as the "dynamic navigation data" type and matches the "confidential level" security requirement; according to the combined conditions of the data type and security level requirement, the optimal encryption scheme configuration is selected from the encryption scheme library, and the ship-shore data block is subjected to hierarchical encryption processing according to the matching encryption scheme.
[0083] In one embodiment, as Figure 3 shown, step S30 includes the steps of:
[0084] S31: Generate a composite hash value for the encrypted data block using a preset multi-level hash calculation strategy;
[0085] S32: Construct an improved Merkle tree based on the composite hash value. The leaf nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundancy code;
[0086] S33: Associate the constructed improved Merkle tree with the encrypted data block to form a verifiable data structure.
[0087] In this embodiment, the multi-level hash calculation strategy calculates the hash value level by level to obtain a composite hash value; the composite hash value is a comprehensive hash check value including the fingerprint of the data content, the redundancy verification mark, and the time sequence identifier, and has anti-collision property and time sequence correlation; the verification information of the forward error correction redundancy code is the check status information recording the redundancy code, including: repairable identifier, redundancy level, last check timestamp, etc.; the verifiable data structure is a verification chain formed by associating encrypted data blocks with improved Merkle tree nodes through pointers, which supports: independent verification of single data blocks, fast verification of batch data, and positioning and recovery of damaged data.
[0088] Specifically, an improved Merkle tree data verification system is constructed to achieve the coordinated improvement of the ship-shore data integrity verification and fault tolerance recovery capabilities, and has the effect of optimizing the data transmission reliability and verification efficiency; specifically, the composite hash value generated by the multi-level hash calculation strategy not only includes the data content characteristics but also integrates the redundancy code verification information. Through this composite verification mechanism, data tampering and transmission errors can be detected simultaneously; when constructing the improved Merkle tree, the composite hash value and the redundancy code verification information are jointly embedded into the leaf nodes to form a data structure containing complete verification elements, so that a single verification operation can complete the double checks of data integrity and recoverability; by establishing an associated mapping between the Merkle tree and the encrypted data blocks, a hierarchical verifiable data structure is constructed, which not only supports quickly locating the problem data blocks but also can perform local data repair according to the embedded redundancy code information.
[0089] In one embodiment, as Figure 4 shown, step S31 includes the steps:
[0090] S311: Calculate the content hash value of the encrypted data block;
[0091] S312: Perform combined hash value calculation on the content hash value and the verification information of the error correction redundancy code;
[0092] S313: Add the corresponding sequence identifier and timeliness timestamp to the combined hash value for composite hash value calculation.
[0093] In this embodiment, the content hash value is a unique fingerprint value with a fixed length calculated by a specific algorithm (such as SHA-256) for the original content of the encrypted data block. The content hash value is used to verify whether the data content has been tampered with, and has collision resistance (the probability of different contents generating the same hash value is extremely low) and irreversibility (it is impossible to reverse the original data through the hash value); the combined hash value is an intermediate result generated by re-hashing the content hash value and the error correction redundancy code verification information through a specific algorithm (such as SHA-256). The combined hash value simultaneously bears the dual functions of data integrity verification and fault tolerance verification; the composite hash value is the finally generated verification value, which is calculated by a specific algorithm (such as SHA-3) from the combined hash value, the sequence identifier, and the timestamp. Its characteristics include: simultaneously containing triple verification information of content, fault tolerance, and time sequence, supporting fast comparison, and anti-replay attack, etc.;
[0094] Specifically, calculating the content hash value of the encrypted data block establishes a basic data integrity verification benchmark. Subsequently, the content hash and the error correction redundancy code verification information are combined and calculated to form a data recoverability verification layer. Finally, a spatio-temporal characteristic verification layer is constructed by fusing the sequence identifier and the timestamp. This hierarchical and progressive calculation method enables the composite hash value to not only retain the data anti-tampering function of traditional hashing, but also newly add the verification capabilities for the correctness of data order and timeliness.
[0095] In one embodiment, the encrypted data block includes a static navigation data block and a dynamic navigation data block. Step S30 includes the steps of:
[0096] S301: Construct a full Merkle tree for the static navigation data block and an incremental Merkle tree for the dynamic navigation data block;
[0097] S302: Establish an improved tree structure association between the full Merkle tree and the incremental Merkle tree. The improved tree structure association includes version anchoring and spatio-temporal association;
[0098] In this embodiment, the static navigation data block is a data block obtained by block-dividing the relatively fixed basic data during the ship's navigation, including ship registration information, structural parameters, fixed route planning, equipment technical specifications, etc. The static navigation data has a low update frequency, but as the navigation reference data, it needs to be stored and verified for a long time. The dynamic navigation data block is a data block obtained by block-dividing the real-time changing navigation state data, including high-frequency updated information such as GPS positioning, speed and heading, engine conditions, meteorology and hydrology, etc. Its characteristic is strong timeliness, which requires quick verification but does not need long-term storage. The full Merkle tree is a complete verification tree structure constructed for static data, and its features include: containing verification nodes of all historical data blocks, storing the complete life cycle information of the data in the nodes, recalculating and signing the root hash every preset time, supporting the traceability verification of all historical data, etc. The incremental Merkle tree is a lightweight verification structure designed specifically for dynamic data, and its features are: only recording the data changes in the most recent preset time (such as 48 hours, 72 hours, etc.), using a sliding window mechanism to manage the nodes, generating an incremental root hash every preset time (such as 15 minutes), supporting the quick pruning of expired data nodes, etc. The version anchor is a reference mechanism that associates the full tree with the incremental tree. The specific implementation includes: using each version of the full tree as an "anchor point" to divide the association interval of the incremental tree by time, and using a blockchain-style hash chain to ensure the version continuity of the full tree and the incremental tree. The spatio-temporal association is the spatio-temporal dimension information embedded in the verification nodes, which includes: spatial coordinates, time stamps, and spatio-temporal relationship verification algorithms.
[0099] Specifically, the full Merkle tree structure is adopted for the slowly changing static navigation data to ensure the integrity and stability of the basic navigation information; the incremental Merkle tree structure is adopted for the real-time changing dynamic navigation data, and only the changed data is hashed and verified, reducing the calculation overhead. The full tree and the incremental tree are spatio-temporally associated through the version anchor mechanism, which not only maintains the reference verification function of the static data but also realizes the quick update verification of the dynamic data. At the same time, the spatio-temporal association ensures the consistency of the two types of data in the time dimension and the space dimension.
[0100] In one embodiment, the first transmission packet includes a full-mode transmission packet and an incremental-mode transmission packet, and step S40 includes the steps of:
[0101] S41: Generating a full-mode transmission packet and an incremental-mode transmission packet based on the full Merkle tree and the incremental Merkle tree respectively;
[0102] S42: Evaluating the current network state and matching the corresponding transmission mode based on the evaluation result. The transmission modes include the full mode, the incremental mode, and the emergency mode.
[0103] In this embodiment, the full - volume mode transmission packet is a transmission packet containing a complete data block and a full - volume Merkle tree, which is applicable to high - bandwidth and low - latency network environments to ensure data integrity and verifiability; the incremental mode transmission packet is a transmission packet containing only the changed data block and an incremental Merkle tree, which is applicable to bandwidth - constrained or intermittent network environments to reduce the data transmission volume and improve the transmission efficiency; the emergency mode transmission packet is a streamlined transmission packet enabled in case of network anomalies (such as high packet loss rate, low bandwidth), which contains only critical data and high - priority error - correcting redundancy codes to ensure the minimum data availability; the network state assessment is a decision - making process of real - time monitoring of network performance metrics (such as bandwidth, latency, packet loss rate) and dynamically adjusting the transmission strategy based on preset thresholds; the transmission mode matching is a mechanism for automatically selecting the optimal transmission strategy according to the network state to ensure that data can be transmitted efficiently and reliably under various network conditions. The transmission modes include the full - volume mode, the incremental mode, and the emergency mode. Among them, the full - volume mode can be selected to be enabled when the network is stable and the bandwidth is sufficient to ensure data integrity and quick verification; the incremental mode can be selected to be enabled when the network bandwidth is constrained or fluctuates greatly to reduce the data volume and improve the transmission success rate; the emergency mode can be selected to be enabled when the network deteriorates severely (such as packet loss rate > 20%, bandwidth < 1 Mbps), and only critical data and high - redundancy error - correcting codes are transmitted to ensure the minimum data availability;
[0104] Specifically, the full - volume mode transmission packet and the incremental mode transmission packet are generated based on the full - volume Merkle tree and the incremental Merkle tree respectively, providing a differentiated transmission solution for different network states; by real - time evaluating the network state and intelligently matching the optimal transmission mode, the full - volume mode is adopted in good network conditions to ensure data integrity, the incremental mode is adopted in ordinary network conditions to improve the transmission efficiency, and the emergency mode is switched to in case of network anomalies to ensure the transmission of critical data.
[0105] It should be understood that the magnitudes of the sequence numbers of the steps in the above - mentioned embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0106] In one embodiment, a data management system for ship - shore data interaction and collaborative decision - making is provided. This data management system for ship - shore data interaction and collaborative decision - making corresponds one - to - one with the data management method for ship - shore data interaction and collaborative decision - making in the above - mentioned embodiment. This data management system for ship - shore data interaction and collaborative decision - making is deployed at the transmission end and includes:
[0107] A processing module, which is used to obtain ship - shore data, perform data chunking processing on the ship - shore data to obtain a number of ship - shore data chunks, and add a uniquely corresponding sequence identifier and a timeliness timestamp to the ship - shore data chunks;
[0108] An encryption module, which is used to perform hierarchical encryption processing on ship-shore data blocks and generate corresponding error correction redundancy codes for them, so as to obtain a number of encrypted data blocks;
[0109] A construction module, which is used to construct an improved Merkle tree based on the encrypted data blocks. The nodes of the improved Merkle tree include the composite hash values of the encrypted data blocks and the verification information of the forward error correction redundancy codes;
[0110] A matching module, which is used to generate a first transmission packet based on the encrypted data blocks and the improved Merkle tree, and match the corresponding transmission mode according to the network state;
[0111] A transmission module, which is used to send the first transmission packet to the receiving end based on the matched transmission mode, so that the receiving end can verify and decrypt the first transmission packet based on the improved Merkle tree;
[0112] Optionally, the encryption module includes:
[0113] A data type acquisition sub-module, which is used to respectively identify the data types of a number of ship-shore data blocks and obtain the corresponding security level requirements;
[0114] An encryption scheme matching sub-module, which is used to match the corresponding encryption scheme based on the data type and the security level requirements;
[0115] A hierarchical encryption processing sub-module, which is used to perform hierarchical encryption processing on a number of ship-shore data blocks based on the matched encryption scheme.
[0116] For the specific limitations of a data management system for ship-shore data interaction and collaborative decision-making, reference can be made to the limitations of a data management method for ship-shore data interaction and collaborative decision-making in the above text, which will not be elaborated here. Each module in the above-mentioned data management system for ship-shore data interaction and collaborative decision-making can be implemented in whole or in part by software, hardware and their combinations. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above-mentioned modules.
[0117] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A data management method for ship-shore data interaction and collaborative decision-making, characterized in that: Executed by the transmission end, including the steps: Obtain ship-shore data, perform data block processing on the ship-shore data to obtain a number of ship-shore data blocks, and add unique corresponding sequence identifiers and timeliness timestamps to the ship-shore data blocks; Performing hierarchical encryption processing on the ship-shore data blocks and generating corresponding error correction redundant codes to obtain a number of encrypted data blocks; Constructing an improved Merkle tree based on the encrypted data block, wherein the nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundant code; Generate a first transmission packet based on the encrypted data block and the improved Merkle tree, and match a corresponding transmission mode according to a network state; The first transmission packet is sent to the receiving end based on the matched transmission mode, so that the receiving end verifies and decrypts the first transmission packet based on the improved Merkle tree.
2. A data management method for ship-shore data interaction and collaborative decision-making according to claim 1, characterized in that: The step of performing hierarchical encryption processing on the ship-shore data blocks and generating corresponding error correction redundant codes to obtain a plurality of encrypted data blocks comprises the following steps: Identify the data types of several ship-shore data blocks respectively, and obtain the corresponding security level requirements; Match the corresponding encryption scheme based on the data type and security level requirements; A layered encryption process is performed on several ship-shore data blocks based on a matching encryption scheme.
3. A data management method for ship-shore data interaction and collaborative decision-making according to claim 1, characterized in that: The step of constructing an improved Merkle tree based on the encrypted data block, wherein the nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundant code, comprises the steps of: A pre-set multi-level hash calculation strategy is used to generate a composite hash value for the encrypted data block; Constructing an improved Merkle tree based on the composite hash value, wherein a leaf node of the improved Merkle tree includes the composite hash value of the encrypted data block and verification information of the forward error correction redundant code; The constructed improved Merkle tree is associated with the encrypted data block to form a verifiable data structure.
4. A data management method for ship-shore data interaction and collaborative decision-making according to claim 3, characterized in that: The step of using a preset multi-level hash calculation strategy to generate a composite hash value for an encrypted data block comprises the following steps: Calculate the content hash value of the encrypted data block; Calculate a combined hash value of the content hash value and the verification information of the error correction redundant code; The corresponding sequence identifier and time validity timestamp are added to the combined hash value to calculate the composite hash value.
5. The data management method for ship-shore data interaction and collaborative decision-making according to claim 1 is characterized by: The encrypted data blocks include static navigation data blocks and dynamic navigation data blocks, and the step of constructing an improved Merkle tree based on the encrypted data blocks, wherein the nodes of the improved Merkle tree include the composite hash value of the encrypted data blocks and the verification information of the forward error correction redundant code, comprises the steps of: Build a full Merkle tree for static navigation data blocks, and build an incremental Merkle tree for dynamic navigation data blocks; An improved tree structure association between the full Merkle tree and the incremental Merkle tree is established, wherein the improved tree structure association includes version anchoring and time-space association.
6. A data management method for ship-shore data interaction and collaborative decision-making according to claim 5, characterized in that: The first transmission packet includes a full mode transmission packet and an incremental mode transmission packet. The step of generating the first transmission packet based on the encrypted data block and the improved Merkle tree, and matching the corresponding transmission mode according to the network state, includes the steps of: Generate a full mode transmission package and an incremental mode transmission package based on the full Merkle tree and the incremental Merkle tree respectively; Evaluate the current network status and match the corresponding transmission mode based on the evaluation result, wherein the transmission mode includes full mode, incremental mode and emergency mode.
7. A data management system for ship-shore data interaction and collaborative decision-making, characterized by: Deployed on the transmission side, including: A processing module is used to obtain ship-shore data, perform data block processing on the ship-shore data to obtain a number of ship-shore data blocks, and add a unique corresponding sequence identifier and time validity timestamp to the ship-shore data blocks; An encryption module is used to perform hierarchical encryption processing on the ship-shore data blocks and generate corresponding error correction redundant codes to obtain a number of encrypted data blocks; A construction module, used to construct an improved Merkle tree based on the encrypted data block, wherein the nodes of the improved Merkle tree include the composite hash value of the encrypted data block and the verification information of the forward error correction redundant code; A matching module, used to generate a first transmission packet based on the encrypted data block and the improved Merkle tree, and match a corresponding transmission mode according to a network state; The transmission module is used to send the first transmission packet to the receiving end based on the matched transmission mode, so that the receiving end verifies and decrypts the first transmission packet based on the improved Merkle tree.
8. A data management system for ship-shore data interaction and collaborative decision-making according to claim 7, characterized in that: The encryption module comprises: The data type acquisition submodule is used to identify the data types of several ship-shore data blocks and obtain the corresponding safety level requirements; The encryption scheme matching submodule is used to match the corresponding encryption scheme based on the data type and security level requirements; The layered encryption processing submodule is used to perform layered encryption processing on a plurality of ship-shore data blocks based on a matching encryption scheme.
Citation Information
Patent Citations
Ship-shore data transmission method based on Internet of Things mode
CN116095114A
Ocean data access authorization control method based on block chain and certificate verification
CN117714199A
Data processing method, device and system, electronic equipment and storage medium
CN119227106A
Intelligent integrated monitoring and analysis method based on multi-dimensional data fusion
CN119357999A
Parallel synchronization method and system for unstructured files
CN119513057A