Satellite navigation positioning reference station data transmission security auditing method and device

By auditing the data from satellite navigation and positioning reference stations in terms of protocols, coordinates, and positioning, and by using a hash consistency algorithm to process the data transmission of satellite navigation and positioning reference stations, the problems of data transmission security and accuracy are solved. This ensures the security and accuracy of data during the sharing process and meets the needs for real-time, long-term, and orderly data processing.

CN120238376BActive Publication Date: 2026-01-23BEIJING CNTEN SMART TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510717960.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2026-01-23
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

Existing technologies lack effective methods to ensure the security and accuracy of data transmission from satellite navigation and positioning reference stations. This can lead to errors or non-compliance with protocol standards during data sharing, affecting the reliability of positioning results and the normal operation of applications.

Method used

The base station observation data is divided into several sets using a hash consistency algorithm, and protocol auditing, coordinate auditing, and location auditing are performed. Data that meets the rules is filtered out and encoded into private protocol messages, which are then transmitted to the intranet environment through network isolation facilities and encoded into data messages in a preset format according to business requirements.

Benefits of technology

By employing rigorous data screening and hash consistency algorithms, we ensure the security and accuracy of data transmission, avoid data disorder and discontinuity issues, meet the needs of real-time, long-term, and ordered data processing, and promote the legal and secure sharing of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238376B_ABST
    Figure CN120238376B_ABST
Patent Text Reader

Abstract

The application discloses a satellite navigation positioning reference station data transmission security auditing method and device, and relates to the field of satellite navigation. The method strictly screens data by means of protocol auditing, coordinate auditing and positioning auditing, discards non-compliant data, prevents error or malicious data from entering the transmission link, guarantees the safety and accuracy of data transmission, and improves the quality of satellite navigation positioning data. At the same time, by using a hash consistency algorithm, the observation data of the same reference station is partitioned into the same data auditing software process for processing, so that data disorder and interruption are avoided, the real-time, long-time, ordered and continuous data processing requirements are met, and the data availability is guaranteed. In the above manner, the security and accuracy of the observation data of the declassified product in resource sharing are ensured, the satellite navigation positioning data is legally and safely shared, the overall security auditing of the reference station data transmission is realized, and the quality and security of the data in the resource sharing process are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of satellite navigation, and in particular to a method and apparatus for security auditing data transmission of a satellite navigation and positioning reference station. Background Technology

[0002] In the field of satellite navigation and positioning, reference stations continuously generate a large amount of observation data. This data is crucial for numerous applications such as geographic mapping and navigation. However, the transmission and use of reference station observation data must be conducted in a dedicated secure network environment to meet confidentiality requirements. In response to the principle of resource sharing, declassified product observation data has emerged, which can be shared as equivalent to reference station observation data while ensuring data quality. However, the security and accuracy of data transmission face challenges during data sharing.

[0003] Currently, there is a lack of effective methods to ensure that transmitted data conforms to relevant protocol standards, has accurate coordinates, and provides reliable positioning results. If the data does not meet requirements, it may lead to positioning errors, invalid data, and other problems, affecting the normal operation of related applications. Furthermore, base station data is generated in real-time, over long periods, in an ordered manner, and continuously. Traditional data processing methods struggle to guarantee data availability during auditing and transmission, often resulting in out-of-order or intermittent data transmission. Therefore, there is an urgent need for a method capable of comprehensively and securely auditing data transmission from satellite navigation and positioning base stations to ensure the quality and security of data during resource sharing. Summary of the Invention

[0004] This application provides a method and apparatus for security auditing data transmission of satellite navigation and positioning reference stations, so as to realize a method for comprehensive security auditing of data transmission of satellite navigation and positioning reference stations, so as to ensure the quality and security of data when sharing resources.

[0005] In a first aspect, this application provides a method for data transmission security auditing of a satellite navigation and positioning reference station. The method is applied to a data transmission security auditing system, which includes a network isolation environment, network isolation facilities, and an intranet environment. The method includes:

[0006] The network isolation environment uses a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains hash consistency sharding information corresponding to the several declassified product observation data sets; wherein, the declassified product observation data in each declassified product observation data set is collected from the same base station;

[0007] The network isolation environment performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set, and obtains the audit results of the declassified product observation data in each declassified product observation data set;

[0008] The network isolation environment encodes the declassified product observation data with a successful audit result into a private protocol data packet, and sends the private protocol data packet to the intranet environment through the network isolation facility;

[0009] The intranet environment decodes and encodes the private protocol data packets into data packets of a preset format, and pushes the data packets of the preset format to the devices corresponding to the business requirements according to the business requirements.

[0010] Secondly, this application provides a data transmission security auditing device for a satellite navigation and positioning reference station. The device is applied to a data transmission security auditing system, which includes a network isolation environment, network isolation facilities, and an intranet environment. The device includes:

[0011] The first unit is used in the network isolation environment to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets using the hash consistency algorithm, and to obtain the hash consistency sharding information corresponding to the several declassified product observation data sets; wherein the declassified product observation data in each declassified product observation data set is collected from the same base station;

[0012] The second unit is used to perform protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set in the network isolation environment, so as to obtain the audit results of the declassified product observation data in each declassified product observation data set;

[0013] The third unit is used in the network isolation environment to encode the declassified product observation data with the audit result of successful audit into a private protocol data packet, and to send the private protocol data packet to the intranet environment through the network isolation facility;

[0014] The fourth unit is used to decode and encode the private protocol data packets into data packets of a preset format in the intranet environment, and to push the data packets of the preset format to the device corresponding to the business requirement according to the business requirement.

[0015] Thirdly, this application provides a readable medium including executable instructions, which, when executed by a processor of an electronic device, cause the electronic device to perform any of the methods described in the first aspect.

[0016] Fourthly, this application provides an electronic device including a processor and a memory storing execution instructions, wherein when the processor executes the execution instructions stored in the memory, the processor performs the method as described in any of the first aspects.

[0017] As can be seen from the above technical solution, the network isolation environment described in this application utilizes a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains hash consistency sharding information corresponding to the several declassified product observation data sets; wherein, the declassified product observation data in each declassified product observation data set is collected from the same base station; the network isolation environment performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set respectively, and obtains the audit results of the declassified product observation data in each declassified product observation data set; the network isolation environment encodes the declassified product observation data with the audit result of successful auditing into a private protocol data packet, and sends the private protocol data packet to the intranet environment through the network isolation facility; the intranet environment decodes the private protocol data packet and encodes it into a data packet of a preset format, and pushes the data packet of the preset format to the device corresponding to the business requirement according to the business requirement. In this way, this application rigorously screens data through protocol auditing, coordinate auditing, and positioning auditing, discarding data that does not conform to protocol encoding, coordinate rules, and positioning rules. This effectively prevents erroneous or malicious data from entering the transmission process, ensuring the security and accuracy of data transmission and improving the quality of satellite navigation and positioning data. Furthermore, by utilizing a hash consistency algorithm, observation data collected from the same reference station is partitioned into the same data auditing software process for auditing, avoiding problems such as data disorder and intermittent transmission. This ensures the availability of reference station observation data and meets the requirements for real-time, long-term, orderly, and continuous data processing. Consequently, it can ensure the security and accuracy of declassified product observation data during resource sharing, promote the legal and secure sharing of satellite navigation and positioning data, provide strong data support for the development of related industries, and thus provide a method for comprehensive security auditing of satellite navigation and positioning reference station data transmission to ensure the quality and security of data during resource sharing.

[0018] The further effects of the aforementioned non-conventional preferred method will be explained below in conjunction with specific embodiments. Attached Figure Description

[0019] To more clearly illustrate the embodiments of this application or the existing technical solutions, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1A flowchart illustrating a satellite navigation and positioning reference station data transmission security auditing method provided in this application;

[0021] Figure 2 A flowchart illustrating a satellite navigation and positioning reference station data transmission security auditing method provided in this application;

[0022] Figure 3 A flowchart illustrating a satellite navigation and positioning reference station data transmission security auditing method provided in this application;

[0023] Figure 4 A flowchart illustrating a satellite navigation and positioning reference station data transmission security auditing method provided in this application;

[0024] Figure 5 A schematic diagram of a satellite navigation and positioning reference station data transmission security auditing device provided in this application;

[0025] Figure 6 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0027] The various non-limiting embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0028] See Figure 1 This application illustrates a method for data transmission security auditing of a satellite navigation and positioning reference station, as described in an embodiment of the present application. The method is applied to a data transmission security auditing system, such as... Figure 2 As shown, the system includes a network isolation environment, network isolation facilities, and an intranet environment.

[0029] Next, we will explain some terms used in this application. **Base Station:** Located at a specific three-dimensional spatial location on the Earth's surface, continuously collecting observational data about satellites at that location once per second. The collected observational data is a real-time monitoring record of visible satellites above that location, providing fundamental data support for various subsequent applications. **Observational Data:** This refers to the satellite observation information generated per second at each specific three-dimensional spatial location. This information covers the observable satellite data from various constellations (such as BeiDou, GPS, Galileo, etc.) at the current location per second. Because non-geostationary orbit satellites revolve around the Earth, only a portion of the satellites can be observed at any given moment at a given three-dimensional spatial location. Therefore, the observational data reflects the status of visible satellites at that moment. **Declassified Product Observational Data:** In accordance with the relevant management standards and confidentiality regulations formulated by the Ministry of Natural Resources for base stations, the transmission and use of base station observational data must be conducted in a dedicated secure network environment. Under the premise of ensuring data quality, declassified product observational data is functionally and application-wise equivalent to base station observational data. Declassified product observational data follows the common RTCM data protocol and provides data sharing services to customers through a data service push system. Broadcast ephemeris refers to the parameters broadcast by each satellite constellation at a fixed frequency to predict the satellite's trajectory over a future period. These parameters provide crucial foundational information for satellite positioning and navigation, and are one of the key data points for achieving real-time positioning. Precise ephemeris, on the other hand, is obtained through post-processing of satellite data, resulting in more accurate parameters of the satellite's trajectory over a past period. Compared to broadcast ephemeris, precise ephemeris offers higher accuracy and provides strong support for high-precision positioning and other applications requiring high satellite orbital accuracy. Point positioning (SPP) is a technique that uses a specific SPP algorithm and a small amount of necessary observation data and satellite ephemeris data corresponding to the data acquisition time to calculate and obtain the unique three-dimensional spatial coordinates of a base station. SPP algorithms are mainly divided into two types: SPP (Single Point Positioning) and Precise Point Positioning (PPP). SPP only requires observation data and broadcast ephemeris data to complete the calculation, and its positioning accuracy can be controlled within 10 meters. Precise Point Positioning (PPP), in addition to using observation data and broadcast ephemeris data, also requires precise ephemeris data for calculation, and its positioning accuracy can reach within 10 centimeters. Protocol auditing refers to the decoding operation of data packets according to the RTCM protocol standard. During the decoding process, data packets that do not conform to the RTCM protocol encoding rules will be directly discarded. Only packets that conform to the protocol encoding will enter the subsequent data processing flow, thereby ensuring the standardization and availability of data. Coordinate auditing: RTCM protocol packets contain data coordinate information.Coordinate auditing involves calculating the spatial distance between the data coordinates in the message and pre-defined audit coordinates, and then judging according to established audit rules. If the spatial distance does not meet the audit rules, the data is discarded; if it does, the data message is allowed to proceed to the next data processing stage. Location auditing uses RTCM protocol data and a single-point positioning algorithm to calculate the location coordinates. Then, it calculates the spatial distance between these coordinates and the audit coordinates, and determines the data processing method based on whether the spatial distance meets the audit rules. If the spatial distance does not meet the location audit rules, the relevant data is discarded; if it does, the data message can continue with subsequent data processing. Data protocol encoding involves re-encoding the data after RTCM decoding according to a specific proprietary protocol, and then transmitting the data through this proprietary protocol. This method helps to meet the data transmission needs between different systems while ensuring data security and compatibility. Consistent hashing is a special type of hashing algorithm primarily used to solve data partitioning problems in distributed systems. Given the real-time, long-term, ordered, and continuous characteristics of satellite observation data generated by base stations, using this algorithm during data auditing ensures that observation data from the same base station are assigned to the same data auditing software process for processing. This effectively guarantees the availability of base station observation data and avoids invalid data such as out-of-order or intermittent data.

[0030] In this embodiment, the method may include, for example, the following steps:

[0031] S101: The network isolation environment uses the hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains the hash consistency sharding information corresponding to the several declassified product observation data sets.

[0032] In each declassified product observation dataset, the declassified product observation data were collected from the same base station.

[0033] In one implementation, such as Figure 2 As shown, the network isolation environment includes a service configuration system, a declassified data production system, a data audit cluster, and a data protocol cluster.

[0034] In this embodiment, as Figure 4 As shown, the declassified data production system can obtain data audit cluster information, data protocol cluster information, and network isolation facility information through the service configuration system.

[0035] Then, the declassified data production system can utilize a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtain hash consistency sharding information corresponding to the several declassified product observation data sets. Furthermore, the declassified data production system can initiate scheduled tasks to periodically retrieve other cluster information from the service configuration system. Figure 4 As shown, the declassified data production system obtains data audit cluster information, data protocol cluster information, and network isolation facility information through a distributed service scheduling system, i.e., a service configuration system. The data audit cluster information may include the identifier of the data audit cluster; the data protocol cluster information may include the identifier of the data protocol cluster; and the network isolation facility information may include the identifier of the network isolation facility.

[0036] Next, the declassified data production system can, based on the data audit cluster information and the hash consistency sharding information corresponding to the plurality of declassified product observation data sets, send each declassified product observation data set, the data specification cluster information, and the network isolation facility information to the data audit group in the data audit cluster corresponding to the declassified product observation data set. For example, ... Figure 4 As shown, the declassified data production system uses a hash consistency algorithm to calculate and distribute the declassified product observation data corresponding to the base station to the data audit service process nodes on a station-by-station basis. Based on the hash consistency sharding information, the declassified data production system pushes the declassified observation data to the data audit service process nodes. It should be noted that, as... Figure 2 As shown, each data audit group can include a protocol audit module, a coordinate audit module, and a location audit module.

[0037] This improves data availability. Specifically, by using the hash consistency algorithm, observation data from the same base station is partitioned and processed by the same data auditing software process, avoiding problems such as data out-of-order and intermittent processing. This ensures the availability of base station observation data and meets the requirements for real-time, long-term, ordered, and continuous data processing.

[0038] S102: The network isolation environment performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set, and obtains the audit results of the declassified product observation data in each declassified product observation data set.

[0039] In this embodiment, the network isolation environment can perform protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set, respectively, to obtain the audit results of the declassified product observation data in each set. It should be noted that, to ensure data transmission efficiency, the data auditing service designs protocol auditing as synchronous processing, while coordinate auditing, location auditing, and data transmission are designed as asynchronous processing. The data auditing service (i.e., the data audit group) designs three memory variables per station: coordinate audit result, location audit result, and the timestamp of the last task execution. If the protocol audit result is an audit failure, the coordinate audit result and location audit result at the station level are also considered audit failures by default.

[0040] Specifically, after the data audit cluster and the data specification cluster are successfully registered in the service configuration system, the data audit cluster obtains audit coordinate information and audit rule information from the service configuration system.

[0041] Then, the data audit group in the data audit cluster performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in the declassified product observation data set corresponding to the data audit group, based on the audit coordinate information and the audit rule information, to obtain the audit result for each declassified product observation data in the declassified product observation data set. In this embodiment, the data audit service can use a hash consistency algorithm to calculate and distribute the declassified product observation data corresponding to the base station to the data specification service process node on a station-by-station basis. It should be noted that this step is processed by three asynchronous thread pools: a data transmission thread pool, a data coordinate audit thread pool, and a location audit thread pool. The data transmission task thread determines whether both the coordinate audit result and the location audit result have passed the audit. If both have passed the audit, data transmission is performed; otherwise, the data is discarded and an audit record is made.

[0042] Specifically, the protocol auditing module can decode the declassified product observation data according to the RTCM protocol to obtain the decoded data packets. For example... Figure 4 As shown, the data audit service uses the RTCM protocol to perform preliminary decoding of the declassified product observation data packets. Packets that do not conform to the RTCM protocol are discarded, while packets that conform to the RTCM protocol are processed further.

[0043] If the decoded data packet conforms to the RTCM protocol, the coordinate audit module determines whether the audit time of the declassified product observation data meets a preset first time condition, and the coordinate audit module determines whether the coordinate information corresponding to the decoded data packet meets a preset coordinate condition. The preset first time condition is that the time interval between the audit time of the declassified product observation data and the previous audit task exceeds a preset first threshold. The step of the coordinate audit module determining whether the coordinate information corresponding to the decoded data packet meets the preset coordinate condition specifically includes: if the coordinate audit module determines that the decoded data packet includes a data packet identifier containing coordinate information, the coordinate audit module determines the coordinate information corresponding to the decoded data packet based on the data packet identifier of the coordinate information; the coordinate audit module calculates the spatial distance between the coordinate information corresponding to the decoded data packet and the audit coordinate information, and determines whether the spatial distance meets the preset condition corresponding to the audit rule information. For example, Figure 4 As shown, the data coordinate audit task thread determines whether the interval between the current task and the previous task exceeds a threshold, such as 2 seconds (configurable). If the interval does not exceed the threshold, the current processing is abandoned; otherwise, further processing is performed. Based on the preliminary decoded data, it determines whether the data packet ID (i.e., data packet identifier) ​​contains coordinate information. If it does not contain coordinate information, this step is skipped. If it does contain coordinate information, further data decoding is performed to parse out the coordinate information and calculate the spatial distance with the audit coordinates. If the spatial distance does not conform to the coordinate audit rules, the coordinate audit result of the station to which the data belongs is set as audit failure and an audit record is made. If the spatial distance conforms to the coordinate audit rules, the coordinate audit result is set as audit success.

[0044] If the audit time of the declassified product observation data meets the preset first time condition, and the coordinate information corresponding to the decoded data packet meets the preset coordinate condition, then the positioning audit module determines whether the audit time of the declassified product observation data meets the preset second time condition, and determines whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information based on the audit coordinate information and the audit rule information. The preset second time condition is that the time interval between the audit time of the declassified product observation data and the previous audit task exceeds a preset second threshold. The step of determining whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information based on the audit coordinate information and the audit rule information specifically includes: the positioning audit module determines single-point positioning coordinate information based on the coordinate information corresponding to all the decoded data packets within a preset time period; the positioning audit module determines the spatial distance between the single-point positioning coordinate information and the audit coordinate information, and determines whether the spatial distance meets the preset condition corresponding to the audit rule information. For example, Figure 4 As shown, the data location audit task thread determines whether the interval between the current task and the previous task exceeds a threshold, such as 3 seconds (configurable). If the interval does not exceed the threshold, the current processing is abandoned; otherwise, further processing is performed. Data is continuously acquired for a period of time, such as 2 seconds (configurable). Single-point location coordinates are calculated using the data packet set. The spatial distance is calculated between this coordinate and the audit coordinates. If the spatial distance does not meet the location audit rules, the location audit result for the station to which the data belongs is set as audit failure and an audit record is made. If the spatial distance meets the location audit rules, the location audit result is set as audit success.

[0045] If the audit time of the declassified product observation data meets the preset second time condition, and the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information, then the audit result is determined to be successful.

[0046] Next, the data audit cluster, based on the hash consistency sharding information, sends the declassified product observation data with a successfully audited result and the network isolation facility information to the data protocol service in the data protocol set corresponding to the data protocol cluster information. For example, ... Figure 4 As shown, after the data audit service filters out the declassified observation data that meets the audit rules, it pushes the declassified observation data to the data specification service process node on a station-by-station basis according to the hash consistency sharding information.

[0047] S103: The network isolation environment encodes the declassified product observation data with the audit result of successful audit into a private protocol data packet, and sends the private protocol data packet to the intranet environment through the network isolation facility.

[0048] In this embodiment, the data protocol service in the network isolation environment can encode declassified observation data into private protocol data packets and push them to the network isolation facility according to the network isolation facility information. Specifically, the data protocol service in the data protocol set corresponding to the data protocol cluster information encodes the declassified product observation data with a successful audit result into private protocol data packets; and sends the private protocol data packets to the intranet environment through the network isolation facility corresponding to the network isolation facility information.

[0049] S104: The intranet environment decodes and encodes the private protocol data packets into data packets of a preset format, and pushes the data packets of the preset format to the device corresponding to the business requirement according to the business requirement.

[0050] As an example, such as Figure 4 As shown, the network isolation facility pushes data to a designated data protocol cluster in the intranet environment. The data protocol cluster decodes the private protocol data packets and encodes them into general RTCM data packets (i.e., the default format is RTCM), which are then transmitted to the data service push system in the intranet environment. The data service push system provides data push services according to business needs.

[0051] In one implementation, before the step of the data audit cluster obtaining audit coordinate information and audit rule information from the service configuration system after the data audit cluster and the data specification cluster have successfully registered with the service configuration system, the method may further include:

[0052] The data audit cluster and the data protocol cluster respectively register their respective cluster information with the service configuration system. Furthermore, both the data audit cluster and the data protocol cluster periodically report heartbeat data to the service configuration system to maintain the connection between the data audit cluster, the data protocol cluster, and the service configuration system.

[0053] Specifically, such as Figure 3As shown, after the data audit cluster and data specification cluster services are started, the data audit cluster and data specification cluster register cluster information with the distributed service scheduling system, i.e., the service configuration system, when starting the service. They also periodically report cluster information heartbeat data to the service configuration system. The data audit service simultaneously obtains audit coordinate information and audit rule information from the service configuration system. In addition, it can start a scheduled task to periodically obtain other cluster information from the service configuration system.

[0054] As can be seen from the above technical solution, the network isolation environment described in this application utilizes a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains hash consistency sharding information corresponding to the several declassified product observation data sets; wherein, the declassified product observation data in each declassified product observation data set is collected from the same base station; the network isolation environment performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set respectively, and obtains the audit results of the declassified product observation data in each declassified product observation data set; the network isolation environment encodes the declassified product observation data with the audit result of successful auditing into a private protocol data packet, and sends the private protocol data packet to the intranet environment through the network isolation facility; the intranet environment decodes the private protocol data packet and encodes it into a data packet of a preset format, and pushes the data packet of the preset format to the device corresponding to the business requirement according to the business requirement. In this way, this application rigorously screens data through protocol auditing, coordinate auditing, and positioning auditing, discarding data that does not conform to protocol encoding, coordinate rules, and positioning rules. This effectively prevents erroneous or malicious data from entering the transmission process, ensuring the security and accuracy of data transmission and improving the quality of satellite navigation and positioning data. Furthermore, by utilizing a hash consistency algorithm, observation data collected from the same reference station is partitioned into the same data auditing software process for auditing, avoiding problems such as data disorder and intermittent transmission. This ensures the availability of reference station observation data and meets the requirements for real-time, long-term, orderly, and continuous data processing. Consequently, it can ensure the security and accuracy of declassified product observation data during resource sharing, promote the legal and secure sharing of satellite navigation and positioning data, provide strong data support for the development of related industries, and thus provide a method for comprehensive security auditing of satellite navigation and positioning reference station data transmission to ensure the quality and security of data during resource sharing.

[0055] It is understood that this application employs methods such as protocol auditing, coordinate auditing, positioning auditing, and data specification to conduct security audits on the network transmission process during the sharing of base station data resources. Only data that complies with the security audit can be transmitted out of the network through network isolation facilities. Specifically, the beneficial effects of this application include the following:

[0056] Ensuring data security: Through protocol auditing, coordinate auditing, and positioning auditing, data is strictly screened, and data that does not conform to protocol encoding, coordinate rules, and positioning rules is discarded. This effectively prevents erroneous or malicious data from entering the transmission process, ensuring the security and accuracy of data transmission and improving the quality of satellite navigation and positioning data.

[0057] Improve data availability: By using the hash consistency algorithm, observation data from the same base station is partitioned into the same data auditing software process for processing, avoiding problems such as data disorder and intermittent processing, ensuring the availability of base station observation data, and meeting the requirements for real-time, long-term, ordered and continuous data processing.

[0058] Optimize data transmission process: Adopt a combination of synchronous and asynchronous processing methods. Synchronous protocol auditing ensures the efficiency of initial data screening, while coordinate auditing, location auditing, and data transmission are processed asynchronously, which improves the overall data processing efficiency, reduces the time overhead of data processing, and enhances the timeliness of data transmission.

[0059] Enhanced system adaptability: Parameters such as audit thresholds and time intervals are configurable, allowing for flexible adjustments based on different application scenarios and needs. This enhances the adaptability and versatility of the method in various environments, meeting diverse data processing requirements.

[0060] Improving the data sharing mechanism ensures the security and accuracy of declassified product observation data during resource sharing, promotes the legal and secure sharing of satellite navigation and positioning data, and provides strong data support for the development of related industries.

[0061] like Figure 5 The image shows a specific embodiment of a satellite navigation and positioning reference station data transmission security auditing device provided in this application. The device described in this embodiment is the physical device used to execute the method described in the above embodiments. Its technical solution is essentially the same as that of the above embodiments, and the corresponding descriptions in the above embodiments are also applicable to this embodiment. The device is applied to a data transmission security auditing system, which includes a network isolation environment, network isolation facilities, and an intranet environment; the device includes:

[0062] The first unit 501 is used in the network isolation environment to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets using the hash consistency algorithm, and to obtain the hash consistency sharding information corresponding to the several declassified product observation data sets; wherein the declassified product observation data in each declassified product observation data set is collected from the same base station;

[0063] The second unit 502 is used to perform protocol auditing, coordinate auditing and location auditing on the declassified product observation data in each declassified product observation data set in the network isolation environment, so as to obtain the audit results of the declassified product observation data in each declassified product observation data set;

[0064] The third unit 503 is used to encode the declassified product observation data with the audit result of successful audit into a private protocol data packet in the network isolation environment, and to send the private protocol data packet to the intranet environment through the network isolation facility;

[0065] The fourth unit 504 is used to decode and encode the private protocol data packets into data packets of a preset format in the intranet environment, and to push the data packets of the preset format to the device corresponding to the business requirement according to the business requirement.

[0066] Optionally, the network isolation environment includes a service configuration system, a declassified data production system, a data audit cluster, and a data protocol cluster; the first unit 501 is used for:

[0067] The declassified data production system obtains data audit cluster information, data protocol cluster information, and network isolation facility information through the service configuration system.

[0068] The declassified data production system uses a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains the hash consistency sharding information corresponding to the several declassified product observation data sets.

[0069] The declassified data production system, based on the data audit cluster information and the hash consistency sharding information corresponding to the several declassified product observation data sets, sends each declassified product observation data set, the data specification cluster information, and the network isolation facility information to the data audit group in the data audit cluster corresponding to the declassified product observation data set.

[0070] Optionally, each data audit group includes a protocol audit module, a coordinate audit module, and a location audit module.

[0071] Optionally, the second unit 502 is used for:

[0072] After the data audit cluster and the data specification cluster are successfully registered in the service configuration system, the data audit cluster obtains audit coordinate information and audit rule information from the service configuration system.

[0073] The data audit group in the data audit cluster performs protocol audit, coordinate audit and location audit on the declassified product observation data in the declassified product observation data set corresponding to the data audit group, based on the audit coordinate information and the audit rule information, to obtain the audit result of each declassified product observation data in the declassified product observation data set.

[0074] The data audit cluster, based on the hash consistency sharding information, sends the declassified product observation data and the network isolation facility information that have been audited successfully to the data protocol service in the data protocol set corresponding to the data protocol cluster information.

[0075] Optionally, the third unit 503 is used for:

[0076] The data protocol service corresponding to the data protocol cluster information in the data protocol set encodes the declassified product observation data with a successful audit result into a private protocol data message; and sends the private protocol data message to the intranet environment through the network isolation facility corresponding to the network isolation facility information.

[0077] Optionally, the device further includes a fifth unit, configured to register cluster information corresponding to each of the data audit cluster and the data protocol cluster with the service configuration system before the step of the data audit cluster obtaining audit coordinate information and audit rule information from the service configuration system after the data audit cluster and the data protocol cluster have successfully registered with the service configuration system, and before the step of the data audit cluster obtaining audit coordinate information and audit rule information from the service configuration system, and the data audit cluster and the data protocol cluster periodically report heartbeat data to the service configuration system to maintain the connection status between the data audit cluster, the data protocol cluster and the service configuration system.

[0078] Optionally, the second unit 502 is specifically used for:

[0079] The protocol auditing module decodes the declassified product observation data according to the RTCM protocol to obtain the decoded data packets;

[0080] If the decoded data packet is a packet conforming to the RTCM protocol, the coordinate audit module determines whether the audit time of the declassified product observation data meets the preset first time condition, and the coordinate audit module determines whether the coordinate information corresponding to the decoded data packet meets the preset coordinate condition;

[0081] If the audit time of the declassified product observation data meets the preset first time condition, and the coordinate information corresponding to the decoded data packet meets the preset coordinate condition, then the positioning audit module determines whether the audit time of the declassified product observation data meets the preset second time condition, and determines whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information based on the audit coordinate information and the audit rule information.

[0082] If the audit time of the declassified product observation data meets the preset second time condition, and the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information, then the audit result is determined to be successful.

[0083] Optionally, the preset first time condition is that the time interval between the audit time of the declassified product observation data and the previous audit task exceeds a preset first threshold.

[0084] Optionally, the second unit 502 is specifically used for:

[0085] If the coordinate auditing module determines that the decoded data packet includes a data packet identifier containing coordinate information, then the coordinate auditing module determines the coordinate information corresponding to the decoded data packet based on the data packet identifier containing the coordinate information.

[0086] The coordinate auditing module calculates the spatial distance between the coordinate information corresponding to the decoded data packet and the audit coordinate information, and determines whether the spatial distance meets the preset conditions corresponding to the audit rule information.

[0087] Optionally, the preset second time condition is that the time interval between the audit time of the declassified product observation data and the previous audit task exceeds a preset second threshold.

[0088] Optionally, the second unit 502 is specifically used for:

[0089] The location audit module determines the single-point location coordinate information based on the coordinate information corresponding to all the decoded data packets within a preset time period.

[0090] The positioning audit module determines the spatial distance between the single-point positioning coordinate information and the audit coordinate information, and determines whether the spatial distance meets the preset conditions corresponding to the audit rule information.

[0091] In this way, the device can perform a comprehensive security audit of data transmission from satellite navigation and positioning reference stations, thereby ensuring the quality and security of data during resource sharing.

[0092] Figure 6This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. At the hardware level, the electronic device includes a processor, and optionally also includes an internal bus, a network interface, and a memory. The memory may include RAM, such as high-speed random-access memory (RAM), or non-volatile memory, such as at least one disk storage device. Of course, the electronic device may also include other hardware required for other services.

[0093] The processor, network interface, and memory can be interconnected via an internal bus, which can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 6 The symbol is represented by a single double-headed arrow, but this does not mean that there is only one bus or one type of bus.

[0094] Memory is used to store instructions for execution. Specifically, instructions for execution are computer programs that can be executed. Memory can include main memory and non-volatile memory, and it provides the processor with execution instructions and data.

[0095] In one possible implementation, the processor reads the corresponding execution instructions from non-volatile memory into main memory and then executes them. Alternatively, it may obtain the corresponding execution instructions from other devices to form a satellite navigation and positioning reference station data transmission security audit device at the logical level. The processor executes the execution instructions stored in the memory to implement the satellite navigation and positioning reference station data transmission security audit method provided in any embodiment of this application.

[0096] The above is as stated in this application. Figure 1The method executed by the satellite navigation and positioning reference station data transmission security audit device provided in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor.

[0097] The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0098] This application also proposes a readable medium that stores execution instructions. When the stored execution instructions are executed by the processor of an electronic device, the electronic device can execute the satellite navigation and positioning reference station data transmission security audit method provided in any embodiment of this application, and specifically be used to perform the above-mentioned evaluation method.

[0099] The electronic devices described in the foregoing embodiments may be computers.

[0100] Those skilled in the art will understand that the embodiments of this application can be provided as methods or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or a combination of software and hardware.

[0101] The various embodiments in this application are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0102] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0103] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for security auditing of data transmission from a satellite navigation and positioning reference station, characterized in that, The method is applied to a data transmission security auditing system, the system including a network isolation environment, network isolation facilities, and an intranet environment; the method includes: The network isolation environment uses a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains hash consistency sharding information corresponding to the several declassified product observation data sets; wherein, the declassified product observation data in each declassified product observation data set is collected from the same base station; The network isolation environment performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set, and obtains the audit results of the declassified product observation data in each declassified product observation data set; The network isolation environment encodes the declassified product observation data with a successful audit result into a private protocol data packet, and sends the private protocol data packet to the intranet environment through the network isolation facility; The intranet environment decodes and encodes the private protocol data packets into data packets of a preset format, and pushes the data packets of the preset format to the devices corresponding to the business requirements according to the business requirements. The network isolation environment includes a service configuration system, a declassified data production system, a data audit cluster, and a data specification cluster. The network isolation environment utilizes a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains hash consistency sharding information corresponding to the several declassified product observation data sets, including: The declassified data production system obtains data audit cluster information, data protocol cluster information, and network isolation facility information through the service configuration system. The declassified data production system uses a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains the hash consistency sharding information corresponding to the several declassified product observation data sets. The declassified data production system sends each declassified product observation data set, the data protocol cluster information, and the network isolation facility information to the data audit group corresponding to the declassified product observation data set in the data audit cluster, based on the data audit cluster information and the hash consistency sharding information corresponding to the plurality of declassified product observation data sets. Each data audit group includes a protocol audit module, a coordinate audit module, and a location audit module; The network isolation environment performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set, respectively, to obtain the audit results of the declassified product observation data in each declassified product observation data set, including: After the data audit cluster and the data specification cluster are successfully registered in the service configuration system, the data audit cluster obtains audit coordinate information and audit rule information from the service configuration system. The data audit group in the data audit cluster performs protocol audit, coordinate audit and location audit on the declassified product observation data in the declassified product observation data set corresponding to the data audit group, based on the audit coordinate information and the audit rule information, to obtain the audit result of each declassified product observation data in the declassified product observation data set. The data audit cluster, based on the hash consistency sharding information, sends the declassified product observation data with a successful audit result and the network isolation facility information to the data protocol service in the data protocol set corresponding to the data protocol cluster information; The data audit group in the data audit cluster performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in the declassified product observation data set corresponding to the data audit group, based on the audit coordinate information and the audit rule information, to obtain the audit results for each declassified product observation data in the declassified product observation data set, including: The protocol auditing module decodes the declassified product observation data according to the RTCM protocol to obtain the decoded data packets; If the decoded data packet is a packet conforming to the RTCM protocol, the coordinate audit module determines whether the audit time of the declassified product observation data meets the preset first time condition, and the coordinate audit module determines whether the coordinate information corresponding to the decoded data packet meets the preset coordinate condition; If the audit time of the declassified product observation data meets the preset first time condition, and the coordinate information corresponding to the decoded data packet meets the preset coordinate condition, then the positioning audit module determines whether the audit time of the declassified product observation data meets the preset second time condition, and determines whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information based on the audit coordinate information and the audit rule information. If the audit time of the declassified product observation data meets the preset second time condition, and the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information, then the audit result is determined to be successful.

2. The method according to claim 1, characterized in that, The network isolation environment encodes the declassified product observation data with a successful audit result into a private protocol data packet, and sends the private protocol data packet to the intranet environment through the network isolation facility, including: The data protocol service corresponding to the data protocol cluster information in the data protocol set encodes the declassified product observation data with a successful audit result into a private protocol data message; and sends the private protocol data message to the intranet environment through the network isolation facility corresponding to the network isolation facility information.

3. The method according to claim 1, characterized in that, Before the step of the data audit cluster obtaining audit coordinate information and audit rule information from the service configuration system after the data audit cluster and the data specification cluster have successfully registered with the service configuration system, the method further includes: The data audit cluster and the data protocol cluster respectively register their respective cluster information with the service configuration system. Furthermore, both the data audit cluster and the data protocol cluster periodically report heartbeat data to the service configuration system to maintain the connection between the data audit cluster, the data protocol cluster, and the service configuration system.

4. The method according to claim 1, characterized in that, The preset first time condition is that the time interval between the audit time of the declassified product observation data and the previous audit task exceeds a preset first threshold. The step of the coordinate auditing module in determining whether the coordinate information corresponding to the decoded data packet meets the preset coordinate conditions includes: If the coordinate auditing module determines that the decoded data packet includes a data packet identifier containing coordinate information, then the coordinate auditing module determines the coordinate information corresponding to the decoded data packet based on the data packet identifier containing the coordinate information. The coordinate auditing module calculates the spatial distance between the coordinate information corresponding to the decoded data packet and the audit coordinate information, and determines whether the spatial distance meets the preset conditions corresponding to the audit rule information.

5. The method according to claim 1, characterized in that, The preset second time condition is that the time interval between the audit time of the declassified product observation data and the previous audit task exceeds a preset second threshold. The step of determining whether the coordinate information corresponding to the decoded data packet satisfies the preset conditions corresponding to the audit rule information based on the audit coordinate information and the audit rule information includes: The location audit module determines the single-point location coordinate information based on the coordinate information corresponding to all the decoded data packets within a preset time period. The positioning audit module determines the spatial distance between the single-point positioning coordinate information and the audit coordinate information, and determines whether the spatial distance meets the preset conditions corresponding to the audit rule information.

6. A satellite navigation and positioning reference station data transmission security auditing device, characterized in that, The device is used in a data transmission security auditing system, the system including a network isolation environment, network isolation facilities, and an intranet environment; the device includes: The first unit is used in the network isolation environment to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets using the hash consistency algorithm, and to obtain the hash consistency sharding information corresponding to the several declassified product observation data sets; wherein the declassified product observation data in each declassified product observation data set is collected from the same base station; The second unit is used to perform protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set in the network isolation environment, so as to obtain the audit results of the declassified product observation data in each declassified product observation data set; The third unit is used in the network isolation environment to encode the declassified product observation data with the audit result of successful audit into a private protocol data packet, and to send the private protocol data packet to the intranet environment through the network isolation facility; The fourth unit is used to decode and encode the private protocol data packets into data packets of a preset format in the intranet environment, and to push the data packets of the preset format to the device corresponding to the business requirements according to the business requirements. The network isolation environment includes a service configuration system, a declassified data production system, a data audit cluster, and a data specification cluster. The network isolation environment utilizes a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains hash consistency sharding information corresponding to the several declassified product observation data sets, including: The declassified data production system obtains data audit cluster information, data protocol cluster information, and network isolation facility information through the service configuration system. The declassified data production system uses a hash consistency algorithm to divide the declassified product observation data corresponding to the base station into several declassified product observation data sets, and obtains the hash consistency sharding information corresponding to the several declassified product observation data sets. The declassified data production system sends each declassified product observation data set, the data protocol cluster information, and the network isolation facility information to the data audit group corresponding to the declassified product observation data set in the data audit cluster, based on the data audit cluster information and the hash consistency sharding information corresponding to the plurality of declassified product observation data sets. Each data audit group includes a protocol audit module, a coordinate audit module, and a location audit module; The network isolation environment performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in each declassified product observation data set, respectively, to obtain the audit results of the declassified product observation data in each declassified product observation data set, including: After the data audit cluster and the data specification cluster are successfully registered in the service configuration system, the data audit cluster obtains audit coordinate information and audit rule information from the service configuration system. The data audit group in the data audit cluster performs protocol audit, coordinate audit and location audit on the declassified product observation data in the declassified product observation data set corresponding to the data audit group, based on the audit coordinate information and the audit rule information, to obtain the audit result of each declassified product observation data in the declassified product observation data set. The data audit cluster, based on the hash consistency sharding information, sends the declassified product observation data with a successful audit result and the network isolation facility information to the data protocol service in the data protocol set corresponding to the data protocol cluster information; The data audit group in the data audit cluster performs protocol auditing, coordinate auditing, and location auditing on the declassified product observation data in the declassified product observation data set corresponding to the data audit group, based on the audit coordinate information and the audit rule information, to obtain the audit results for each declassified product observation data in the declassified product observation data set, including: The protocol auditing module decodes the declassified product observation data according to the RTCM protocol to obtain the decoded data packets; If the decoded data packet is a packet conforming to the RTCM protocol, the coordinate audit module determines whether the audit time of the declassified product observation data meets the preset first time condition, and the coordinate audit module determines whether the coordinate information corresponding to the decoded data packet meets the preset coordinate condition; If the audit time of the declassified product observation data meets the preset first time condition, and the coordinate information corresponding to the decoded data packet meets the preset coordinate condition, then the positioning audit module determines whether the audit time of the declassified product observation data meets the preset second time condition, and determines whether the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information based on the audit coordinate information and the audit rule information. If the audit time of the declassified product observation data meets the preset second time condition, and the coordinate information corresponding to the decoded data packet meets the preset condition corresponding to the audit rule information, then the audit result is determined to be successful.

Citation Information

Patent Citations

  • Information checking system and method

    CN108132475A

  • File transmission behavior auditing method and device, electronic equipment and storage medium

    CN113746925A