Satellite navigation positioning base station data transmission security auditing method and device
By conducting protocol audits, coordinate audits and positioning audits on the satellite navigation positioning reference station data, and using hash consistency algorithm to screen and encode data, the security and accuracy problems in the data transmission of satellite navigation positioning reference station data are solved, and the security and accuracy of data in the resource sharing process are achieved.
Patent Information
- Application Number
- CN202510717960.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-05-30
AI Technical Summary
The existing technology lacks effective methods to ensure the security and accuracy of data transmission of satellite navigation positioning reference stations. Especially in the process of resource sharing, the data may not comply with the protocol standards and the coordinates are inaccurate, resulting in positioning errors and data invalidity, and traditional processing methods are difficult to ensure the real-time, long-term, orderly and continuous data.
The hash consistency algorithm is used to divide the observation data of the benchmark station into several sets, and protocol audits, coordinate audits and positioning audits are performed through the network isolation environment. The data that complies with the rules is selected and encoded as private protocol messages, transmitted to the intranet environment through the network isolation facility, and encoded into a preset format according to business needs to ensure the security and accuracy of the data.
Effectively prevent erroneous or malicious data from entering the transmission process, ensure the security and accuracy of data transmission, improve the quality of satellite navigation positioning data, meet real-time, long-term, orderly and continuous data processing needs, and ensure the security and accuracy of data in the resource sharing process.
Smart Images

Figure CN120238376A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of satellite navigation, and in particular, to a method and device for secure audit of satellite navigation positioning reference station data transmission. Background Art
[0002] In the field of satellite navigation positioning, reference stations continuously generate a large amount of observation data. This observation data is crucial for many applications such as geodetic surveying and navigation positioning. However, the transmission and use of reference station observation data need to be carried out in a dedicated secure network environment to meet confidentiality requirements. In response to the principle of resource sharing, decrypted product observation data has emerged, which can be used for resource sharing equivalent to reference station observation data while ensuring data quality. However, in the process of data sharing, the security and accuracy of data transmission face challenges.
[0003] Currently, there is a lack of effective methods to ensure that the transmitted data conforms to relevant protocol standards, the coordinates are accurate, and the positioning results are reliable. If the data does not meet the requirements, it may lead to problems such as positioning errors and data invalidation, affecting the normal operation of related applications. In addition, reference station data is generated in real-time, for a long time, orderly, and continuously. Traditional data processing methods are difficult to ensure the availability of data during audit and transmission, such as data disorder and intermittency. Therefore, there is an urgent need for a method that can comprehensively and securely audit the satellite navigation positioning reference station data transmission to ensure the quality and security of data during resource sharing. Summary of the Invention
[0004] This application provides a method and device for secure audit of satellite navigation positioning reference station data transmission to implement a method that can comprehensively and securely audit the satellite navigation positioning reference station data transmission to ensure the quality and security of data during resource sharing.
[0005] In a first aspect, this application provides a method for secure audit of satellite navigation positioning reference station data transmission. The method is applied to a secure audit system for data transmission. The system includes a network isolation environment, network isolation facilities, and an intranet environment. The method includes: The network isolation environment uses the hash consistency algorithm to divide the decrypted product observation data corresponding to the reference station into several decrypted product observation data sets, and obtains the hash consistency sharding information corresponding to the several decrypted product observation data sets. Among them, the decrypted product observation data in each decrypted product observation data set is collected from the same reference station. The network isolation environment respectively performs protocol audit, coordinate audit, and positioning audit on the decrypted product observation data in each decrypted product observation data set to obtain the audit results of the decrypted product observation data in each decrypted product observation data set. The network isolation environment encodes the decrypted product observation data with an audit result of audit success into private protocol data packets, and sends the private protocol data packets to the intranet environment through the network isolation facility; The intranet environment decodes the private protocol data packets and encodes them into data packets in a preset format, and pushes the data packets in the preset format to the devices corresponding to the service requirements according to the service requirements.
[0006] In a second aspect, the present application provides a satellite navigation positioning reference station data transmission security audit device, which is applied to a data transmission security audit system. The system includes a network isolation environment, a network isolation facility, and an intranet environment; the device includes: A first unit for the network isolation environment to divide the decrypted product observation data corresponding to the reference station into a plurality of decrypted product observation data sets by using a hash consistency algorithm, and obtain the hash consistency sharding information corresponding to the plurality of decrypted product observation data sets; wherein, the decrypted product observation data in each decrypted product observation data set are all collected by the same reference station; A second unit for the network isolation environment to perform protocol audit, coordinate audit, and positioning audit on the decrypted product observation data in each decrypted product observation data set respectively, and obtain the audit results of the decrypted product observation data in each decrypted product observation data set; A third unit for the network isolation environment to encode the decrypted product observation data with an audit result of audit success into private protocol data packets, and send the private protocol data packets to the intranet environment through the network isolation facility; A fourth unit for the intranet environment to decode the private protocol data packets and encode them into data packets in a preset format, and push the data packets in the preset format to the devices corresponding to the service requirements according to the service requirements.
[0007] In a third aspect, the present application provides a readable medium, including execution instructions. When a processor of an electronic device executes the execution instructions, the electronic device executes the method described in any one of the first aspects.
[0008] In a fourth aspect, the present application provides an electronic device, including a processor and a memory storing execution instructions. When the processor executes the execution instructions stored in the memory, the processor executes the method described in any one of the first aspects.
[0009] As can be seen from the above technical solutions, in the network isolation environment described in this application, the decrypted product observation data corresponding to the reference station is divided into several decrypted product observation data sets by using the hash consistency algorithm, and the hash consistency sharding information corresponding to the several decrypted product observation data sets is obtained. Among them, the decrypted product observation data in each decrypted product observation data set is collected by the same reference station. The network isolation environment respectively performs protocol auditing, coordinate auditing, and positioning auditing on the decrypted product observation data in each decrypted product observation data set to obtain the auditing results of the decrypted product observation data in each decrypted product observation data set. The network isolation environment encodes the decrypted product observation data with successful auditing results into private protocol data packets, and sends the private protocol data packets to the internal network environment through the network isolation facility. The internal network environment decodes and encodes the private protocol data packets into data packets in a preset format, and pushes the data packets in the preset format to the devices corresponding to the service requirements according to the service requirements. In this way, this application strictly screens data through protocol auditing, coordinate auditing, and positioning auditing, discards data that does not conform to protocol encoding, coordinate rules, and positioning rules, effectively prevents incorrect or malicious data from entering the transmission link, ensures the security and accuracy of data transmission, and improves the quality of satellite navigation and positioning data. In addition, by using the hash consistency algorithm, the observation data collected by the same reference station is partitioned into the same data auditing software process for auditing processing, avoiding problems such as out-of-order data and intermittent data, ensuring the availability of the reference station observation data, and meeting the requirements for real-time, long-term, ordered, and continuous data processing. Therefore, the security and accuracy of the decrypted product observation data during the resource sharing process can be ensured, the legal and secure sharing of satellite navigation and positioning data is promoted, and strong data support is provided for the development of related industries. Furthermore, a method for comprehensively and securely auditing the data transmission of satellite navigation and positioning reference stations can be provided to ensure the quality and security of data during resource sharing.
[0010] The further effects of the above non-conventional preferred methods will be described in conjunction with specific embodiments below. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the embodiments of the present application or the existing technical solutions, the following will briefly introduce the drawings required for the description of the embodiments or the existing technical solutions. Obviously, the drawings described below are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0012] Figure 1 It is a schematic flowchart of a method for securely auditing the data transmission of a satellite navigation and positioning reference station provided by the present application; Figure 2 Schematic flowchart of a method for secure audit of satellite navigation and positioning reference station data transmission provided by this application; Figure 3 Schematic flowchart of a method for secure audit of satellite navigation and positioning reference station data transmission provided by this application; Figure 4 Schematic flowchart of a method for secure audit of satellite navigation and positioning reference station data transmission provided by this application; Figure 5 Schematic structural diagram of a device for secure audit of satellite navigation and positioning reference station data transmission provided by this application; Figure 6 Schematic structural diagram of an electronic device provided by this application. Detailed implementation manners
[0013] To make the objectives, technical solutions and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0014] The following will describe in detail various non-restrictive implementation manners of this application with reference to the drawings.
[0015] Refer to Figure 1 , which shows a method for secure audit of satellite navigation and positioning reference station data transmission in an embodiment of this application. The method is applied to a data transmission security audit system. As Figure 2 shown, the system includes a network isolation environment, network isolation facilities and an intranet environment.
[0016] Next, some terms related to this application will be explained. Reference station: It is set at a specific three-dimensional spatial position on the Earth's surface and continuously collects satellite observation data at this position at a frequency of once per second; the observation data it collects is a real-time monitoring record of the visible satellites over the location, providing basic data support for subsequent various applications. Observation data refers to the satellite observation information generated per second at each specific three-dimensional spatial position; this information covers the satellite data observable in each constellation (such as Beidou, GPS, Galileo, etc.) at the current position per second; since non-geostationary satellites orbit the Earth, only part of the satellites can be observed at any moment at a certain three-dimensional spatial position on the Earth, so the observation data reflects the state of the visible satellites at that moment at that position. Decrypted product observation data: According to the relevant management standards and confidentiality regulations formulated by the Ministry of Natural Resources for reference stations, the transmission and use of reference station observation data must be carried out in a dedicated secure network environment; on the premise of ensuring data quality, the decrypted product observation data is equivalent to the reference station observation data in function and application; the decrypted product observation data follows the general RTCM data protocol and provides data sharing services to customers through the data service push system. Broadcast ephemeris refers to the parameters broadcast by each constellation to which the satellite belongs at a fixed frequency for predicting the future trajectory of the satellite for a period of time; these parameters provide important basic information for satellite positioning and navigation and are one of the key data for realizing real-time positioning. Precise ephemeris is the more accurate satellite trajectory parameters in the past period obtained by post-processing satellite data; compared with the broadcast ephemeris, the precise ephemeris has higher accuracy and can provide strong support for high-precision positioning and other applications with higher requirements for satellite orbit accuracy. Single-point positioning is a technical means based on a specific single-point positioning algorithm, using a small amount of necessary observation data and the satellite ephemeris data corresponding to the data collection time to calculate the unique three-dimensional spatial position coordinates of the reference station; the single-point positioning algorithm is mainly divided into two types: single-point positioning (spp) and precise point positioning (ppp); among them, single-point positioning (spp) only needs to use observation data and broadcast ephemeris data to complete the calculation, and its positioning accuracy can be controlled within 10 meters; while precise point positioning (ppp) needs to use precise ephemeris data in addition to observation data and broadcast ephemeris data for calculation, and the positioning accuracy can reach within 10 centimeters. Protocol audit refers to decoding data packets with the RTCM protocol as the standard; during the decoding process, data packets that do not conform to the RTCM protocol coding rules will be directly discarded; only packets that conform to the protocol coding will enter the subsequent data processing process to ensure the standardization and availability of the data. Coordinate audit: The RTCM protocol packet contains data coordinate information.The process of coordinate audit is to calculate the spatial distance between the data coordinates in the message and the pre-set audit coordinates, and make a judgment based on the established audit rules; if the spatial distance does not meet the audit rules, the data will be discarded; if it meets the coordinate audit rules, the corresponding data message will be allowed to enter the next step of data processing. Positioning audit is to use RTCM protocol data and a single-point positioning algorithm to calculate and obtain the positioning coordinates; then, calculate the spatial distance between the positioning coordinates and the audit coordinates, and determine the data processing method based on whether the spatial distance meets the audit rules. If the spatial distance does not meet the positioning audit rules, the relevant data will be discarded; if it meets the rules, the data message can continue to proceed with subsequent data processing. Data protocol is to re-encode the data decoded by RTCM according to a specific private protocol, and then transmit data through the private protocol; this method helps to meet the data transmission requirements between different systems while ensuring data security and compatibility. The Consistent Hash algorithm is a special hash algorithm that is mainly used to solve the data partition problem in distributed systems. In view of the real-time, long-term, orderly and continuous characteristics of satellite observation data generated by the base station, the use of this algorithm in the data audit process can ensure that the observation data of the same base station is assigned to the same data audit software process for processing; this can effectively ensure the availability of the base station observation data and avoid invalid data such as disordered or intermittent data.
[0017] In this embodiment, the method may include the following steps: S101: The network isolation environment uses a hash consistency algorithm to divide the decrypted product observation data corresponding to the reference station into a number of decrypted product observation data sets, and obtains hash consistency sharding information corresponding to the number of decrypted product observation data sets.
[0018] Among them, the declassified product observation data in each declassified product observation data set are all collected by the same reference station.
[0019] In one implementation, Figure 2 As shown, the network isolation environment includes a service configuration system, a declassified data production system, a data audit cluster, and a data specification cluster.
[0020] In this embodiment, if Figure 4 As shown, the declassified data production system can obtain data audit cluster information, data specification cluster information, and network isolation facility information through the service configuration system.
[0021] Then, the decrypted data production system can use the hash consistency algorithm to divide the decrypted product observation data corresponding to the reference station into several decrypted product observation data sets, and obtain the hash consistency sharding information corresponding to the several decrypted product observation data sets. In addition, the decrypted data production system can start a scheduled task to periodically obtain other cluster information from the service configuration system. Figure 4 As shown, the declassified data production system obtains data audit cluster information, data specification cluster information, and network isolation facility information through the distributed service scheduling system, i.e., the service configuration system. The data audit cluster information may include the identifier of the data audit cluster, the data specification cluster information may include the identifier of the data specification cluster, and the network isolation facility information may include the identifier of the network isolation facility.
[0022] Then, the decrypted data production system can send each decrypted product observation data set, the data specification cluster information and the network isolation facility information to the data audit group corresponding to the decrypted product observation data set in the data audit cluster according to the data audit cluster information and the hash consistency sharding information corresponding to the several decrypted product observation data sets. Figure 4 As shown in the figure, the decrypted data production system uses the hash consistency algorithm to calculate, so that the decrypted product observation data corresponding to the base station is sharded to the data audit service process node by station; the decrypted data production system pushes the decrypted observation data to the data audit service process node according to the hash consistency sharding information. It should be noted that, Figure 2 As shown, each data audit group may include a protocol audit module, a coordinate audit module and a positioning audit module.
[0023] In this way, data availability can be improved. That is, by using the hash consistency algorithm, the observation data of the same base station can be partitioned into the same data audit software process for processing, avoiding problems such as data disorder and intermittent data, ensuring the availability of the base station observation data, and meeting the real-time, long-term, orderly and continuous data processing requirements.
[0024] S102: The network isolation environment performs protocol audit, coordinate audit and positioning audit on the decrypted product observation data in each decrypted product observation data set, and obtains the audit result of the decrypted product observation data in each decrypted product observation data set.
[0025] In this embodiment, the network isolation environment can perform protocol audit, coordinate audit and positioning audit on the declassified product observation data in each declassified product observation data set, respectively, to obtain the audit results of the declassified product observation data in each declassified product observation data set. It should be noted that in order to ensure the efficiency of data transmission, the data audit service is designed as synchronous processing for protocol audit, and asynchronous processing for coordinate audit, positioning audit and data transmission. The data audit service (i.e., data audit group) designs three memory variables based on stations: coordinate audit results, positioning audit results, and the last task execution timestamp. If the protocol audit result is an audit failure, the coordinate audit result and positioning audit result based on the station are defaulted to audit failure.
[0026] Specifically, after the data audit cluster and the data specification cluster are successfully registered in the service configuration system, the data audit cluster obtains the audit coordinate information and the audit rule information from the service configuration system.
[0027] Then, the data audit group in the data audit cluster performs protocol audit, coordinate audit and positioning audit on the declassified product observation data in the declassified product observation data set corresponding to the data audit group according to the audit coordinate information and the audit rule information, and obtains the audit result of each declassified product observation data in the declassified product observation data set. In this embodiment, the data audit service can use the hash consistency algorithm to calculate so that the declassified product observation data corresponding to the reference station is sharded to the data specification service process node on a station basis. It should be noted that this step is divided into three asynchronous thread pools for processing: data transmission thread pool, data coordinate audit thread pool and positioning audit thread pool. The data transmission task thread determines whether both the coordinate audit result and the positioning audit result have passed the audit. If both have passed the audit, data transmission is performed, otherwise the data is discarded and an audit record is performed.
[0028] Specifically, the protocol audit module can decode the declassified product observation data according to the RTCM protocol to obtain the decoded data message. Figure 4 As shown, the data audit service uses the RTCM protocol to perform preliminary decoding of the declassified product observation data message, discards the message that does not comply with the RTCM protocol, and processes the message that complies with the RTCM protocol for the next step.
[0029] If the decoded data message is a message conforming to the RTCM protocol, the coordinate audit module determines whether the audit time of the decrypted product observation data meets a preset first time condition, and the coordinate audit module determines whether the coordinate information corresponding to the decoded data message meets a preset coordinate condition. The preset first time condition is that the time interval between the audit time of the decrypted product observation data and the time of the previous audit task exceeds a preset first threshold. The step in which the coordinate audit module determines whether the coordinate information corresponding to the decoded data message meets the preset coordinate condition specifically includes: If the coordinate audit module determines that the decoded data message includes a data message identifier of coordinate information, the coordinate audit module determines the coordinate information corresponding to the decoded data message according to the data message identifier of the coordinate information; The coordinate audit module calculates the spatial distance between the coordinate information corresponding to the decoded data message and the audit coordinate information, and determines whether the spatial distance meets the preset condition corresponding to the audit rule information. For example, as Figure 4 shown, the data coordinate audit task thread determines whether the interval from the previous task exceeds the threshold. For example, the interval is 2 s (configurable). If the interval from the previous task does not exceed the threshold, this processing is abandoned. If it exceeds the threshold, further processing is performed. According to the preliminarily decoded data, it is determined whether the data message ID (i.e., the data message identifier) is a data message ID containing coordinate information. If it is not a data message ID containing data coordinate information, this step is skipped. If it is a data message ID containing coordinate information, further data decoding is performed to parse out the coordinate information, and the spatial distance is calculated with the audit coordinate. If the spatial distance does not conform to the coordinate audit rule, the coordinate audit result of the station to which the data belongs is set to audit failure and an audit record is made. If the spatial distance conforms to the coordinate audit rule, the coordinate audit result is set to audit passed.
[0030] If the audit time of the declassified product observation data satisfies the preset first time condition, and the coordinate information corresponding to the decoded data message satisfies the preset coordinate condition, then the positioning audit module determines whether the audit time of the declassified product observation data satisfies the preset second time condition, and determines whether the coordinate information corresponding to the decoded data message satisfies the preset condition corresponding to the audit rule information based on the audit coordinate information and the audit rule information. The preset second time condition is that the time interval between the audit time of the declassified product observation data and the last audit task exceeds a preset second threshold. The step of judging whether the coordinate information corresponding to the decoded data message satisfies the preset condition corresponding to the audit rule information based on the audit coordinate information and the audit rule information specifically includes: the positioning audit module determines the single-point positioning coordinate information based on the coordinate information corresponding to all the decoded data messages within a preset time length; the positioning audit module determines the spatial distance between the single-point positioning coordinate information and the audit coordinate information, and determines whether the spatial distance satisfies the preset condition corresponding to the audit rule information. For example, if Figure 4 As shown, the data location audit task thread determines whether the interval with the last task exceeds the threshold, such as 3s (configurable). If the interval with the last task does not exceed the threshold, the current processing is abandoned. If it exceeds the threshold, further processing is performed. Continuously obtain data for a period of time, such as obtaining 2s (configurable) data, and obtain the single-point location coordinate information through the data packet collection single-point location calculation, and calculate the spatial distance with the audit coordinates. If the spatial distance does not meet the location audit rules, the location audit result of the station to which the data belongs is set to audit failure and an audit record is made. If the spatial distance meets the location audit rules, the location audit result is set to audit pass.
[0031] If the audit time of the declassified product observation data meets the preset second time condition, and the coordinate information corresponding to the decoded data message meets the preset condition corresponding to the audit rule information, the audit result is determined to be a successful audit.
[0032] Next, the data audit cluster sends the declassified product observation data and the network isolation facility information with the audit result of successful audit to the data specification service corresponding to the data specification cluster information in the data specification center according to the hash consistency sharding information. Figure 4 As shown in the figure, after the data audit service selects the decrypted observation data that meets the audit rules, it pushes the decrypted observation data to the data specification service process node in units of stations according to the hash consistency sharding information.
[0033] S103: The network isolation environment encodes the declassified product observation data with the audit result being a successful audit into a private protocol data message, and sends the private protocol data message to the intranet environment through the network isolation facility.
[0034] In this embodiment, the data protocol service in the network isolation environment can encode the declassified observation data into a private protocol data message, and push it to the network isolation facility according to the network isolation facility information. Specifically, the data protocol service corresponding to the data protocol cluster information in the data protocol set encodes the declassified product observation data with the audit result of successful audit into a private protocol data message; and sends the private protocol data message to the intranet environment through the network isolation facility corresponding to the network isolation facility information.
[0035] S104: The intranet environment decodes the private protocol data message and encodes it into a data message in a preset format, and pushes the data message in the preset format to a device corresponding to the business demand according to the business demand.
[0036] As an example, Figure 4 As shown, the network isolation facility pushes data to the specified data protocol cluster in the intranet environment, decodes the private protocol data message through the data protocol cluster and encodes it into a universal RTCM data message (that is, the preset format is RTCM), and transmits it to the data service push system in the intranet environment. The data service push system performs data push services according to business needs.
[0037] In one implementation, after the data audit cluster and the data specification cluster are successfully registered in the service configuration system, before the step of the data audit cluster acquiring the audit coordinate information and the audit rule information from the service configuration system, the method may further include: The data audit cluster and the data specification cluster respectively register the cluster information corresponding to the data audit cluster and the data specification cluster with the service configuration system, and the data audit cluster and the data specification cluster both periodically report heartbeat data to the service configuration system to maintain the connection status of the data audit cluster, the data specification cluster and the service configuration system.
[0038] Specifically, Figure 3 As shown, after the data audit cluster and data specification cluster services are started, the data audit cluster and data specification cluster register cluster information with the distributed service scheduling system, i.e., the service configuration system, when starting the service, and regularly report cluster information heartbeat data to the service configuration system. The data audit service also obtains audit coordinate information and audit rule information from the service configuration system, and can enable scheduled tasks to periodically obtain other cluster information from the service configuration system.
[0039] As can be seen from the above technical solution, in the network isolation environment described in this application, the decrypted product observation data corresponding to the reference station is divided into several decrypted product observation data sets by using the hash consistency algorithm, and the hash consistency sharding information corresponding to the several decrypted product observation data sets is obtained; among them, the decrypted product observation data in each decrypted product observation data set are all collected by the same reference station; the network isolation environment respectively performs protocol auditing, coordinate auditing, and positioning auditing on the decrypted product observation data in each decrypted product observation data set to obtain the auditing results of the decrypted product observation data in each decrypted product observation data set; the network isolation environment encodes the decrypted product observation data with the auditing result of successful auditing into a private protocol data packet, and sends the private protocol data packet to the intranet environment through the network isolation facility; the intranet environment decodes and encodes the private protocol data packet into a data packet in a preset format, and pushes the data packet in the preset format to the device corresponding to the service requirement according to the service requirement. In this way, this application strictly screens data through protocol auditing, coordinate auditing, and positioning auditing, discards data that does not conform to protocol encoding, coordinate rules, and positioning rules, effectively prevents incorrect or malicious data from entering the transmission link, ensures the security and accuracy of data transmission, and improves the quality of satellite navigation and positioning data; and, by using the hash consistency algorithm, the observation data collected by the same reference station is partitioned into the same data auditing software process for auditing and processing, avoiding problems such as out-of-order and intermittent data, ensuring the availability of the reference station observation data, and meeting the real-time, long-term, orderly, and continuous data processing requirements; thus, it can ensure the security and accuracy of the decrypted product observation data during the resource sharing process, promote the legal and secure sharing of satellite navigation and positioning data, provide strong data support for the development of related industries, and furthermore, be able to comprehensively and securely audit the data transmission of satellite navigation and positioning reference stations to ensure the quality and security of data during resource sharing.
[0040] It can be understood that this application performs security auditing on the network transmission process during the resource sharing of reference station data resources through methods such as protocol auditing, coordinate auditing, positioning auditing, and data reduction, and only the data that meets the security auditing can go out of the network through the network isolation facility. Specifically, the beneficial effects of this application include the following: Guarantee data security: Through protocol auditing, coordinate auditing, and positioning auditing, strictly screen data, discard data that does not conform to protocol encoding, coordinate rules, and positioning rules, effectively prevent incorrect or malicious data from entering the transmission link, ensure the security and accuracy of data transmission, and improve the quality of satellite navigation and positioning data.
[0041] Improve data availability: By using the hash consistency algorithm, the observed data of the same reference station is partitioned into the same data audit software process for processing, avoiding problems such as out-of-order data and intermittent data, ensuring the availability of the observed data of the reference station, and meeting the requirements for real-time, long-term, ordered, and continuous data processing.
[0042] Optimize the data transmission process: Adopt a processing method that combines synchronization and asynchrony. The protocol audit is synchronized to ensure the efficiency of preliminary data screening, and the coordinate audit, positioning audit, and data transmission are processed asynchronously, improving the overall data processing efficiency, reducing the time overhead of data processing, and enhancing the timeliness of data transmission.
[0043] Enhance system adaptability: Parameters such as the audit threshold and time interval are configurable and can be flexibly adjusted according to different application scenarios and requirements, enhancing the adaptability and generality of this method in different environments and meeting diverse data processing requirements.
[0044] Improve the data sharing mechanism: Ensure the security and accuracy of the observed data of the decryption-free products during the resource sharing process, promote the legal and secure sharing of satellite navigation and positioning data, and provide strong data support for the development of related industries.
[0045] As Figure 5 shown, it is a specific embodiment of a satellite navigation and positioning reference station data transmission security audit device provided by this application. The device in this embodiment is the physical device used to execute the method described in the above embodiment. Its technical solution is essentially the same as that of the above embodiment, and the corresponding descriptions in the above embodiment also apply to this embodiment. The device is applied to a data transmission security audit system, and the system includes a network isolation environment, network isolation facilities, and an intranet environment; the device includes: The first unit 501 is used for the network isolation environment to divide the observed data of the decryption-free products corresponding to the reference station into several sets of observed data of decryption-free products by using the hash consistency algorithm, and obtain the hash consistency sharding information corresponding to the several sets of observed data of decryption-free products; among them, the observed data of the decryption-free products in each set of observed data of decryption-free products are all collected by the same reference station; The second unit 502 is used for the network isolation environment to perform protocol audit, coordinate audit, and positioning audit on the observed data of the decryption-free products in each set of observed data of the decryption-free products respectively, and obtain the audit results of the observed data of the decryption-free products in each set of observed data of decryption-free products; The third unit 503 is used for the network isolation environment to encode the observed data of the decryption-free products with successful audit results into private protocol data packets, and send the private protocol data packets to the intranet environment through the network isolation facilities; The fourth unit 504 is used for decoding the private protocol data message in the intranet environment and encoding it into a data message in a preset format, and pushing the data message in the preset format to a device corresponding to the business demand according to the business demand.
[0046] Optionally, the network isolation environment includes a service configuration system, a decrypted data production system, a data audit cluster, and a data specification cluster; the first unit 501 is used to: The declassified data production system obtains data audit cluster information, data specification cluster information, and network isolation facility information through the service configuration system; The decrypted data production system uses a hash consistency algorithm to divide the decrypted product observation data corresponding to the reference station into a number of decrypted product observation data sets, and obtains hash consistency sharding information corresponding to the number of decrypted product observation data sets; The decrypted data production system sends each decrypted product observation data set, the data specification cluster information and the network isolation facility information to the data audit group corresponding to the decrypted product observation data set in the data audit cluster based on the data audit cluster information and the hash consistency sharding information corresponding to the several decrypted product observation data sets.
[0047] Optionally, each data audit group includes a protocol audit module, a coordinate audit module and a positioning audit module.
[0048] Optionally, the second unit 502 is configured to: After the data audit cluster and the data specification cluster are successfully registered in the service configuration system, the data audit cluster obtains audit coordinate information and audit rule information from the service configuration system; The data audit group in the data audit cluster performs protocol audit, coordinate audit and positioning audit on the declassified product observation data in the declassified product observation data set corresponding to the data audit group according to the audit coordinate information and the audit rule information, and obtains the audit result of each declassified product observation data in the declassified product observation data set; The data audit cluster sends the declassified product observation data with an audit result of successful audit and the network isolation facility information to the data specification service corresponding to the data specification cluster information in the data specification center according to the hash consistency sharding information.
[0049] Optionally, the third unit 503 is used to: The data reduction service in the data reduction set corresponding to the data reduction cluster information encodes the decrypted product observation data with an audit result of successful audit into a private protocol data packet; and sends the private protocol data packet to the intranet environment through the network isolation facility corresponding to the network isolation facility information.
[0050] Optionally, the device further includes a fifth unit, configured to, before the step that the data audit cluster obtains audit coordinate information and audit rule information from the service configuration system after the data audit cluster and the data reduction cluster are successfully registered in the service configuration system, the data audit cluster and the data reduction cluster respectively register the cluster information corresponding to the data audit cluster and the data reduction cluster with the service configuration system, and the data audit cluster and the data reduction cluster both regularly report heartbeat data to the service configuration system to maintain the connection status between the data audit cluster, the data reduction cluster and the service configuration system.
[0051] Optionally, the second unit 502 is specifically configured to: The protocol audit module decodes the decrypted product observation data according to the RTCM protocol to obtain a decoded data packet; If the decoded data packet is a packet conforming to the RTCM protocol, the coordinate audit module determines whether the audit time of the decrypted product observation data meets a preset first time condition, and the coordinate audit module determines whether the coordinate information corresponding to the decoded data packet meets a preset coordinate condition; If the audit time of the decrypted product observation data meets the preset first time condition, and the coordinate information corresponding to the decoded data packet meets the preset coordinate condition, the positioning audit module determines whether the audit time of the decrypted product observation data meets a preset second time condition, and determines whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information according to the audit coordinate information and the audit rule information; If the audit time of the decrypted product observation data meets the preset second time condition, and the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information, it is determined that the audit result is successful audit.
[0052] Optionally, the preset first time condition is that the time interval between the audit time of the decrypted product observation data and the time of the previous audit task exceeds a preset first threshold.
[0053] Optionally, the second unit 502 is specifically configured to: If the coordinate auditing module determines that the decoded data packet includes a data packet identifier with coordinate information, the coordinate auditing module determines the coordinate information corresponding to the decoded data packet according to the data packet identifier with coordinate information; The coordinate auditing module calculates the spatial distance between the coordinate information corresponding to the decoded data packet and the auditing coordinate information, and determines whether the spatial distance meets the preset conditions corresponding to the auditing rule information.
[0054] Optionally, the preset second time condition is that the time interval between the auditing time of the decryption product observation data and the time of the previous auditing task exceeds a preset second threshold.
[0055] Optionally, the second unit 502 is specifically configured to: The positioning auditing module determines the single-point positioning coordinate information according to the coordinate information corresponding to all the decoded data packets within a preset duration; The positioning auditing module determines the spatial distance between the single-point positioning coordinate information and the auditing coordinate information, and determines whether the spatial distance meets the preset conditions corresponding to the auditing rule information.
[0056] In this way, the present device can implement a method for comprehensively and securely auditing the data transmission of a satellite navigation positioning reference station, so as to ensure the quality and security of data during resource sharing.
[0057] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. Among them, the memory may include a memory, such as a high-speed random access memory (Random-Access Memory, RAM), and may also include a non-volatile memory (non-volatile memory), such as at least one disk memory, etc. Of course, the electronic device may also include other hardware required for other services.
[0058] The processor, network interface, and memory can be interconnected through an internal bus, and the internal bus can be an ISA (Industry Standard Architecture, industrial standard architecture) bus, a PCI (Peripheral Component Interconnect, peripheral component interconnect standard) bus, or an EISA (Extended Industry Standard Architecture, extended industrial standard architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 6It is represented only by a bidirectional arrow in the figure, but it does not mean that there is only one bus or one type of bus.
[0059] A memory for storing executable instructions. Specifically, the executable instructions are computer programs that can be executed. The memory may include a memory and a non-volatile memory, and provide the executable instructions and data to the processor.
[0060] In a possible implementation, the processor reads the corresponding executable instructions from the non-volatile memory into the memory and then runs them, or can obtain the corresponding executable instructions from other devices to form a satellite navigation and positioning reference station data transmission security audit device at the logical level. The processor executes the executable instructions stored in the memory to implement the satellite navigation and positioning reference station data transmission security audit method provided in any embodiment of the present application through the executed executable instructions.
[0061] As described above in the present application Figure 1 The method executed by the satellite navigation and positioning reference station data transmission security audit device provided in the embodiments shown in the present application can be applied to or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor or by instructions in software form. The above processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0062] The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being completed by the execution of the hardware decoding processor, or completed by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0063] The embodiments of the present application also propose a readable medium. When the execution instructions stored in the readable storage medium are executed by the processor of the electronic device, the electronic device can execute the satellite navigation positioning reference station data transmission security auditing method provided in any embodiment of the present application, and is specifically used to execute the above-mentioned evaluation method.
[0064] The electronic device described in each of the foregoing embodiments may be a computer.
[0065] Those skilled in the art should understand that the embodiments of the present application may be provided as a method or a computer program product. Therefore, the present application may adopt a completely hardware embodiment, a completely software embodiment, or a form combining software and hardware.
[0066] The embodiments in the present application are all described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiments.
[0067] It should also be noted that the term "including", "comprising" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent in such process, method, commodity or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, commodity or device including the said element.
[0068] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application may have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A method for secure audit of satellite navigation and positioning reference station data transmission, characterized in that, The method is applied to a data transmission security audit system, the system comprising a network isolation environment, a network isolation facility and an intranet environment; the method comprises: The network isolation environment uses a hash consistency algorithm to divide the decrypted product observation data corresponding to the reference station into a number of decrypted product observation data sets, and obtains hash consistency sharding information corresponding to the number of decrypted product observation data sets; wherein the decrypted product observation data in each decrypted product observation data set are all collected by the same reference station; The network isolation environment performs protocol audit, coordinate audit and positioning audit on the decrypted product observation data in each decrypted product observation data set, respectively, to obtain the audit results of the decrypted product observation data in each decrypted product observation data set; The network isolation environment encodes the declassified product observation data whose audit result is a successful audit into a private protocol data message, and sends the private protocol data message to the intranet environment through the network isolation facility; The intranet environment decodes and encodes the private protocol data message into a data message in a preset format, and pushes the data message in the preset format to a device corresponding to the business demand according to the business demand.
2. The method according to claim 1, wherein The network isolation environment includes a service configuration system, a decrypted data production system, a data audit cluster, and a data specification cluster; the network isolation environment uses a hash consistency algorithm to divide the decrypted product observation data corresponding to the reference station into a plurality of decrypted product observation data sets, and obtains hash consistency sharding information corresponding to the plurality of decrypted product observation data sets, including: The declassified data production system obtains data audit cluster information, data specification cluster information, and network isolation facility information through the service configuration system; The decrypted data production system uses a hash consistency algorithm to divide the decrypted product observation data corresponding to the reference station into a number of decrypted product observation data sets, and obtains hash consistency sharding information corresponding to the number of decrypted product observation data sets; The decrypted data production system sends each decrypted product observation data set, the data specification cluster information and the network isolation facility information to the data audit group corresponding to the decrypted product observation data set in the data audit cluster based on the data audit cluster information and the hash consistency sharding information corresponding to the several decrypted product observation data sets.
3. The method according to claim 2, wherein Each data audit group includes a protocol audit module, a coordinate audit module and a positioning audit module.
4. The method according to claim 3, wherein The network isolation environment performs protocol audit, coordinate audit and positioning audit on the decrypted product observation data in each decrypted product observation data set, and obtains the audit results of the decrypted product observation data in each decrypted product observation data set, including: After the data audit cluster and the data specification cluster are successfully registered in the service configuration system, the data audit cluster obtains audit coordinate information and audit rule information from the service configuration system; The data audit group in the data audit cluster performs protocol audit, coordinate audit and positioning audit on the declassified product observation data in the declassified product observation data set corresponding to the data audit group according to the audit coordinate information and the audit rule information, and obtains the audit result of each declassified product observation data in the declassified product observation data set; The data audit cluster sends the declassified product observation data with an audit result of successful audit and the network isolation facility information to the data specification service corresponding to the data specification cluster information in the data specification center according to the hash consistency sharding information.
5. The method according to claim 4, wherein The network isolation environment encodes the declassified product observation data whose audit result is a successful audit into a private protocol data message, and sends the private protocol data message to the intranet environment through the network isolation facility, including: The data specification service corresponding to the data specification cluster information in the data specification set encodes the declassified product observation data with the audit result of successful audit into a private protocol data message; and sends the private protocol data message to the intranet environment through the network isolation facility corresponding to the network isolation facility information.
6. The method according to claim 4, wherein After the data audit cluster and the data specification cluster are successfully registered in the service configuration system, before the step of the data audit cluster acquiring audit coordinate information and audit rule information from the service configuration system, the method further includes: The data audit cluster and the data specification cluster respectively register the cluster information corresponding to the data audit cluster and the data specification cluster with the service configuration system, and the data audit cluster and the data specification cluster both periodically report heartbeat data to the service configuration system to maintain the connection status of the data audit cluster, the data specification cluster and the service configuration system.
7. The method according to claim 4, wherein The data audit group in the data audit cluster performs protocol audit, coordinate audit and positioning audit on the declassified product observation data in the declassified product observation data set corresponding to the data audit group according to the audit coordinate information and the audit rule information, and obtains the audit result of each declassified product observation data in the declassified product observation data set, including: The protocol audit module decodes the declassified product observation data according to the RTCM protocol to obtain a decoded data message; If the decoded data message is a message that complies with the RTCM protocol, the coordinate audit module determines whether the audit time of the declassified product observation data meets the preset first time condition, and the coordinate audit module determines whether the coordinate information corresponding to the decoded data message meets the preset coordinate condition; If the audit time of the decrypted product observation data meets the preset first time condition, and the coordinate information corresponding to the decoded data packet meets the preset coordinate condition, then the positioning audit module determines whether the audit time of the decrypted product observation data meets the preset second time condition, and determines whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information according to the audit coordinate information and the audit rule information; If the audit time of the decrypted product observation data meets the preset second time condition, and the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information, then it is determined that the audit result is audit success.
8. The method according to claim 7, wherein The preset first time condition is that the time interval between the audit time of the decrypted product observation data and the time of the previous audit task exceeds a preset first threshold; The step in which the coordinate audit module determines whether the coordinate information corresponding to the decoded data packet meets the preset coordinate condition includes: If the coordinate audit module determines that the decoded data packet includes the data packet identifier of the coordinate information, then the coordinate audit module determines the coordinate information corresponding to the decoded data packet according to the data packet identifier of the coordinate information; The coordinate audit module calculates the spatial distance between the coordinate information corresponding to the decoded data packet and the audit coordinate information, and determines whether the spatial distance meets the preset condition corresponding to the audit rule information.
9. The method according to claim 7, characterized in that, The preset second time condition is that the time interval between the audit time of the decrypted product observation data and the time of the previous audit task exceeds a preset second threshold; The step of determining whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information according to the audit coordinate information and the audit rule information includes: The positioning audit module determines the single-point positioning coordinate information according to the coordinate information corresponding to all the decoded data packets within a preset duration; The positioning audit module determines the spatial distance between the single-point positioning coordinate information and the audit coordinate information, and determines whether the spatial distance meets the preset condition corresponding to the audit rule information.
10. A satellite navigation and positioning reference station data transmission security audit device, characterized in that, The device is applied to a data transmission security audit system, and the system includes a network isolation environment, network isolation facilities, and an intranet environment; the device includes: A first unit for the network isolation environment to divide the decrypted product observation data corresponding to the reference station into several decrypted product observation data sets by using the hash consistency algorithm, and obtain the hash consistency shard information corresponding to the several decrypted product observation data sets; wherein, the decrypted product observation data in each decrypted product observation data set is collected by the same reference station; A second unit for the network isolation environment to respectively perform protocol audit, coordinate audit, and positioning audit on the decrypted product observation data in each decrypted product observation data set to obtain the audit results of the decrypted product observation data in each decrypted product observation data set; The third unit is used to encode the decryption product observation data with successful audit results in the network isolation environment into private protocol data packets, and send the private protocol data packets to the intranet environment through the network isolation facility; The fourth unit is used to decode the private protocol data packets in the intranet environment and encode them into data packets in a preset format, and push the data packets in the preset format to the devices corresponding to the service requirements according to the service requirements.
Citation Information
Patent Citations
Information checking system and method
CN108132475A
File transmission behavior auditing method and device, electronic equipment and storage medium
CN113746925A
Method and device for desensitizing observation data of satellite navigation and positioning base station
CN115032668A
Cluster-based security audit management method and device, medium and product
CN118410036A
Method for storing database security audit records
US20210203487A1