Data security management method and device
The method optimizes energy and bandwidth usage by dynamically adjusting encryption strategies based on data sensitivity and environmental conditions, addressing resource constraints and ensuring secure data transmission for underwater pipeline monitoring.
Patent Information
- Application Number
- CN202510450494.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-11
AI Technical Summary
In the safety monitoring of underwater pipelines in remote sea areas, the existing technology is difficult to achieve differentiated data security protection under the harsh conditions of energy and bandwidth limitation, resulting in high power consumption of sensor nodes, delayed communication or failure, affecting the real-time and reliability of monitoring data.
By monitoring the remaining battery power of the underwater sensor node, data security level and congestion level of the wireless communication environment, dynamically adjust the energy consumption, bandwidth occupation and security strength of the encryption algorithm, select the encryption strategy with the best comprehensive performance, and perform differentiated management and encryption processing of hydrological monitoring data.
It realizes that while ensuring data security, it reduces energy consumption, saves bandwidth resources, extends the life of sensor nodes, improves the reliability and real-timeness of data transmission, and solves the problems of waste of resources and insufficient security protection.
Smart Images

Figure CN120321643A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technologies, and more particularly, to a data security management method and apparatus. Background Art
[0002] In the field of energy infrastructure, especially in the safety monitoring applications of underwater pipelines in remote waters, underwater sensor nodes powered by batteries are widely deployed. These nodes undertake crucial tasks, namely continuously collecting hydrological monitoring data closely related to the structural health of underwater pipelines. For example, monitoring key structural parameters such as the stress level and corrosion degree of pipelines, as well as basic environmental parameters such as water temperature and water pressure. The accuracy and integrity of these data are crucial for ensuring the safe and stable operation of underwater pipelines.
[0003] To ensure the security of these key monitoring data during wireless transmission, existing technical solutions usually adopt data encryption technologies. However, the complex and harsh underwater environment poses many challenges to sensor nodes. First, underwater sensor nodes usually rely on limited battery energy supply, and high-intensity encryption algorithms will significantly increase the computing power consumption of the nodes, which will undoubtedly shorten their working life. For application scenarios that require long-term continuous monitoring, this increase in energy consumption is extremely disadvantageous and may even lead to the interruption of monitoring tasks. Second, the underwater wireless communication environment itself is very complex, and the available communication bandwidth is very limited. If a large amount of encrypted data is transmitted, it will further exacerbate the already tight communication burden, and in severe cases, it may even lead to data transmission delays or complete failures, affecting the timeliness and reliability of monitoring data. In addition, in practical applications, the security sensitivity levels of different types of hydrological monitoring data also vary significantly. For example, basic environmental data such as water temperature and water pressure are relatively less sensitive, and the harm caused by their leakage may be small; while pipeline structure parameters directly reflecting the structural health of pipelines, such as stress and corrosion rate, contain highly sensitive pipeline safety information, and their leakage may directly threaten the safe operation of pipelines. However, existing data security management methods often lack consideration of the differentiated security requirements of data. If a unified high-intensity encryption strategy is adopted for all data, it will undoubtedly cause unnecessary energy waste and bandwidth occupation, further exacerbating the contradiction of resource constraints and making the already fragile underwater sensor network even worse.
[0004] Therefore, in the context of the long-term safety monitoring of underwater pipelines in energy infrastructure in remote waters, aiming at the harsh conditions of dual constraints on energy and bandwidth, and fully considering the differentiated security protection requirements for different data sensitivities, achieving efficient and secure management of hydrological monitoring data has become a key technical problem to be solved urgently. Especially on the premise of effectively ensuring the security of data wireless transmission, how to maximize the consideration of the low power consumption and long life operation of sensor nodes, and ultimately achieve differentiated data security protection, has become an important and urgent challenge faced by the current development of underwater pipeline monitoring technology.
[0005] In view of the above problems, there is an urgent need for improvement in the existing technologies. Summary of the Invention
[0006] The purpose of this application is to provide a data security management method and device, which have the advantages of reducing energy consumption, saving bandwidth resources, and achieving differentiated data security protection.
[0007] In a first aspect, this application provides a data security management method for securely managing hydrological monitoring data collected during the underwater pipeline safety monitoring of underwater sensor nodes. The steps of this method include:
[0008] A1. Monitor the remaining battery power of the underwater sensor node, and determine the energy consumption weight according to the comparison result between the remaining battery power and the preset power threshold.
[0009] A2. Group the hydrological monitoring data collected by the underwater sensor node, and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data.
[0010] A3. Determine the bandwidth occupancy weight according to the congestion degree of the underwater wireless communication environment.
[0011] A4. For each group of hydrological monitoring data, based on the determined energy consumption weight, corresponding data security weight, bandwidth occupancy weight, and the pre-evaluated energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms, calculate the comprehensive performance index values of different encryption algorithms.
[0012] A5. For each group of hydrological monitoring data, select the encryption algorithm with the optimal comprehensive performance index value, and encrypt this group of hydrological monitoring data.
[0013] A6. Transmit the encrypted hydrological monitoring data to the shore-based monitoring center through the underwater wireless communication link.
[0014] This method, by considering the energy consumption weight, data security weight, and bandwidth occupancy weight, and selecting a suitable encryption algorithm, has the advantages of reducing energy consumption, saving bandwidth resources, and achieving differentiated data security protection.
[0015] Preferably, step A1 includes:
[0016] A101. Real-time collect the battery voltage value of the underwater sensor node and convert the battery voltage value into the percentage of remaining battery power;
[0017] A102. Compare the percentage of remaining battery power with a preset high battery threshold and a low battery threshold; wherein, the high battery threshold is greater than the low battery threshold;
[0018] A103. If the percentage of remaining battery power is greater than the high battery threshold, set the energy consumption weight to a first preset value;
[0019] A104. If the percentage of remaining battery power is less than the low battery threshold, set the energy consumption weight to a second preset value;
[0020] A105. If the percentage of remaining battery power is between the high battery threshold and the low battery threshold, calculate the energy consumption weight according to a linear function, so that the energy consumption weight is between the first preset value and the second preset value.
[0021] Thus, the energy consumption weight can be adaptively adjusted according to the remaining battery power status, providing an important energy consumption reference basis for the selection of subsequent data encryption algorithms, and realizing the optimization of data security management in energy-constrained scenarios.
[0022] Preferably, step A101 includes:
[0023] Adopt a moving average filtering algorithm to smooth the battery voltage value of the underwater sensor node collected in real time to obtain a filtered battery voltage value;
[0024] Calculate the voltage change rate according to the filtered battery voltage value;
[0025] Evaluate the battery health status according to the change curve of the filtered battery voltage value and the voltage change rate to obtain a health status evaluation value;
[0026] Correct the filtered battery voltage value at the current moment according to the health status evaluation value, and convert the corrected battery voltage value into the percentage of remaining battery power.
[0027] Thus, the performance and reliability of the entire data security management method can be improved.
[0028] Preferably, step A2 includes:
[0029] A201. Extract the metadata of the hydrological monitoring data collected by the underwater sensor node, and the metadata includes a data type identifier;
[0030] A202. Query and obtain the security impact levels of various types of hydrological monitoring data according to the said data type identifier;
[0031] A203. Group various types of hydrological monitoring data according to the said security impact level, and calculate the security levels of the hydrological monitoring data in each group according to the security impact levels of various types of hydrological monitoring data within the group;
[0032] A204. Determine the data security weights of the hydrological monitoring data in each group according to the corresponding relationship between the preset security level and the data security weight.
[0033] Preferably, step A203 includes:
[0034] B1. Compare the security impact levels of various types of hydrological monitoring data with the preset security impact level threshold, and perform preliminary grouping on the hydrological monitoring data;
[0035] B2. Calculate the initial security level of the hydrological monitoring data in each group by using the weighted average algorithm according to the data volume and security impact level of various types of hydrological monitoring data within the group; the larger the data volume, the greater the weight of the corresponding hydrological monitoring data;
[0036] B3. Calculate the level deviation between the security impact level of each type of hydrological monitoring data within each group of hydrological monitoring data and the corresponding initial security level. If all the said level deviations within the group do not exceed the preset deviation threshold, then execute step B4 for the corresponding data group. Otherwise, split the corresponding data group into multiple groups of data, and execute step B2 and step B3 again for the split data groups;
[0037] B4. Take the said initial security level of each group of hydrological monitoring data as the security level of the corresponding data group.
[0038] Preferably, step A3 includes:
[0039] A301. Obtain the transmission delay of the underwater wireless communication link;
[0040] A302. Calculate the congestion degree of the underwater wireless communication link according to the said transmission delay;
[0041] A303. Calculate the bandwidth occupancy weight according to the said congestion degree.
[0042] Preferably, in step A301, obtain the transmission delays of multiple data packets on the underwater wireless communication link to form a delay sequence;
[0043] Step A302 includes:
[0044] Perform smoothing processing on the delay sequence by using a sliding window to obtain a smoothed delay sequence;
[0045] Calculate the delay jitter and average transmission delay of the calculated smooth delay sequence;
[0046] Calculate the congestion degree of the underwater wireless communication link according to the delay jitter and the average transmission delay.
[0047] Preferably, step A4 includes:
[0048] A401. For each group of hydrological monitoring data, according to the type identifier of various types of hydrological monitoring data in the group, screen a variety of encryption algorithms adapted to the hydrological monitoring data of this group from the preset encryption algorithm parameter library; wherein, the encryption algorithm parameter library stores the energy consumption, bandwidth overhead and security strength parameters of different encryption algorithms evaluated in advance;
[0049] A402. For each selected encryption algorithm, calculate the comprehensive performance index value of the corresponding encryption algorithm according to the corresponding energy consumption, bandwidth overhead and security strength parameters, as well as the energy consumption weight, the corresponding data security weight and the bandwidth occupancy weight.
[0050] Preferably, step A6 includes:
[0051] A601. Assign priorities to each group of hydrological monitoring data machines according to the security level; the higher the security level of the data, the higher the priority;
[0052] A602. According to the priority size, sequentially transmit each group of hydrological monitoring data to the shore-based monitoring center through the underwater wireless communication link, and during the transmission process, monitor the packet loss rate of the underwater wireless communication link;
[0053] A603. When it is detected that the packet loss rate exceeds the preset packet loss rate threshold, suspend the transmission of data with a priority not higher than the preset priority threshold, and preferentially retransmit data with a priority higher than the preset priority threshold until the packet loss rate resumes below the preset threshold, and then continue to transmit the remaining data.
[0054] In a second aspect, the present application provides a data security management device for performing security management on hydrological monitoring data collected during underwater pipeline safety monitoring of underwater sensor nodes. The device includes:
[0055] A power monitoring module, configured to monitor the remaining battery power of the underwater sensor node, and determine the energy consumption weight according to the comparison result between the remaining battery power and the preset power threshold;
[0056] A security level determination module, configured to group the hydrological monitoring data collected by the underwater sensor node, and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data;
[0057] A bandwidth evaluation module, configured to determine a bandwidth occupancy weight according to the congestion degree of the underwater wireless communication environment;
[0058] A performance calculation module, configured to calculate a comprehensive performance index value of different encryption algorithms for each group of hydrological monitoring data based on the determined energy consumption weight, corresponding data security weight, bandwidth occupancy weight, and pre-evaluated energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms;
[0059] A data encryption module, configured to select the encryption algorithm with the optimal comprehensive performance index value for each group of hydrological monitoring data and perform encryption processing on this group of hydrological monitoring data;
[0060] A data transmission module, configured to transmit the encrypted hydrological monitoring data to the shore-based monitoring center through an underwater wireless communication link.
[0061] Advantageous effects: A data security management method and device provided by the present application... Description of the Drawings
[0062] Figure 1 It is a flowchart of the data security management method provided by an embodiment of the present application.
[0063] Figure 2 It is a structural schematic diagram of the data security management device provided by an embodiment of the present application.
[0064] Reference numeral description: 1. Electric quantity monitoring module; 2. Security level determination module; 3. Bandwidth evaluation module; 4. Performance calculation module; 5. Data encryption module; 6. Data transmission module. Detailed Embodiments
[0065] Next, the technical solutions in the present application will be clearly and completely described in conjunction with the drawings in the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Usually, the components of the present application described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.
[0066] It should be noted that: Similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0067] Reference Figure 1 , this application proposes a data security management method for securely managing the hydrological monitoring data collected during the underwater pipeline safety monitoring of underwater sensor nodes. The steps of this method include:
[0068] A1. Monitor the remaining battery power of the underwater sensor node, and determine the energy consumption weight according to the comparison result between the remaining battery power and the preset power threshold;
[0069] A2. Group the hydrological monitoring data collected by the underwater sensor node, and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data;
[0070] A3. Determine the bandwidth occupancy weight according to the congestion degree of the underwater wireless communication environment;
[0071] A4. For each group of hydrological monitoring data, calculate the comprehensive performance index values of different encryption algorithms based on the determined energy consumption weight, corresponding data security weight, bandwidth occupancy weight, and the pre-evaluated energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms;
[0072] A5. For each group of hydrological monitoring data, select the encryption algorithm with the optimal comprehensive performance index value, and encrypt this group of hydrological monitoring data;
[0073] A6. Transmit the encrypted hydrological monitoring data to the shore-based monitoring center through the underwater wireless communication link.
[0074] Among them, in step A1, the energy consumption weight is used to characterize the sensitivity of the system to energy consumption. Specifically, it can be implemented in the following way: preset a high power threshold and a low power threshold. When the remaining battery power is higher than the high power threshold, it indicates that the battery power is sufficient. At this time, the energy consumption weight can be set to a smaller value, such as 0.2, to reduce the consideration of energy consumption. When the remaining battery power is lower than the low power threshold, it indicates that the battery power is insufficient. At this time, the energy consumption weight can be set to a larger value, such as 0.8, to increase the consideration of energy consumption. When the remaining battery power is between the high power threshold and the low power threshold, the energy consumption weight can be calculated according to a linear function, so that the energy consumption weight changes smoothly between 0.2 and 0.8. Thus, according to different levels of the remaining battery power, the energy consumption weight can be dynamically adjusted to achieve adaptive management of energy consumption.
[0075] Among them, in step A2, the data security weight is used to represent the degree of emphasis of the system on data security. It can be specifically implemented in the following way: First, group the hydrological monitoring data. For example, divide the hydrological monitoring data into important data and non-important data. Then, assign different security levels to different groups of data. For example, the security level of important data is higher than that of non-important data. Next, according to the preset correspondence between the security level and the data security weight, determine the data security weights of each group of hydrological monitoring data. For example, it can be set that the higher the security level of the data group, the higher its data security weight. For example, for data groups with high, medium, and low security levels, their data security weights can be set to 0.8, 0.5, and 0.2 respectively. Thus, the data security weight can be dynamically adjusted according to different data security levels to achieve differentiated data security management.
[0076] Among them, in step A3, the bandwidth occupancy weight is used to represent the sensitivity of the system to bandwidth occupancy. It can be specifically implemented in the following way: Monitor the transmission delay of the underwater wireless communication link in real time. When the transmission delay is high, it indicates that the underwater wireless communication environment is relatively congested. At this time, the bandwidth occupancy weight can be set to a larger value, such as 0.7, to increase the consideration of bandwidth occupancy. When the transmission delay is low, it indicates that the underwater wireless communication environment is relatively unobstructed. At this time, the bandwidth occupancy weight can be set to a smaller value, such as 0.3, to reduce the consideration of bandwidth occupancy. Thus, the bandwidth occupancy weight can be dynamically adjusted according to the congestion degree of the underwater wireless communication environment to achieve adaptive management of bandwidth occupancy.
[0077] Among them, in step A4, the comprehensive performance index value is used to evaluate the comprehensive performance of different encryption algorithms in the current environment. It can be specifically implemented in the following way: Pre-evaluate the energy consumption, bandwidth overhead, and security strength parameters of multiple encryption algorithms and store these parameters in the encryption algorithm parameter library. For each group of hydrological monitoring data, select multiple available encryption algorithms from the encryption algorithm parameter library. Then, for each encryption algorithm, calculate its comprehensive performance index value according to the formula. For example, the comprehensive performance index value can be defined as the product of the data security weight and the security strength parameter, divided by the product of the energy consumption weight and the energy consumption parameter, and then divided by the product of the bandwidth occupancy weight and the bandwidth overhead parameter. At this time, the larger the comprehensive performance index value, the better. Thus, multiple factors such as energy consumption, data security, and bandwidth occupancy can be comprehensively considered to quantitatively evaluate the performance of different encryption algorithms.
[0078] Among them, in step A5, the optimal comprehensive performance index value refers to reaching the optimal level of the comprehensive performance index value according to the preset optimization goal. Specifically, if the optimization goal is to maximize the comprehensive performance index value (corresponding to the case where the larger the comprehensive performance index value, the better), the encryption algorithm with the largest comprehensive performance index value is selected. If the optimization goal is to minimize the comprehensive performance index value (corresponding to the case where the smaller the comprehensive performance index value, the better), the encryption algorithm with the smallest comprehensive performance index value is selected. Thus, according to the evaluation result of the comprehensive performance index value, the most suitable encryption algorithm can be adaptively selected to achieve the dynamic adjustment of the data encryption strategy.
[0079] Among them, in step A6, the underwater sensor node sends the encrypted hydrological monitoring data to the underwater wireless communication link in the form of acoustic signals through underwater wireless communication devices such as an underwater acoustic modem. The underwater wireless communication link transmits the received acoustic signal to the shore-based monitoring center. The shore-based monitoring center receives the data transmitted by the underwater wireless communication link through devices such as an underwater acoustic modem, and decrypts and processes the data to achieve the remote safety monitoring of the underwater pipeline. Thus, the secure and reliable transmission of hydrological monitoring data can be realized, providing data guarantee for the safety monitoring of the underwater pipeline.
[0080] Specifically, for the data security management method proposed in this application, first, through steps A1, A2, and A3, the energy consumption weight, data security weight, and bandwidth occupancy weight are obtained respectively. These three weights respectively reflect the energy state of the current underwater sensor node, the data security requirements, and the congestion degree of the underwater wireless communication environment. Then, in step A4, for each group of hydrological monitoring data, considering these three weights and the performance parameters of different encryption algorithms comprehensively, the comprehensive performance index values of different encryption algorithms are calculated. This comprehensive performance index value can quantitatively reflect the comprehensive performance of each encryption algorithm in the current environment. Next, in step A5, the encryption algorithm with the optimal comprehensive performance index value is selected to encrypt the data, which means that the system will adaptively select the most suitable encryption algorithm under the current conditions to achieve the best balance among data security, energy consumption, and bandwidth occupancy. Finally, in step A6, the encrypted data is transmitted to the shore-based monitoring center to complete the secure transmission of the data.
[0081] Through the above technical solution, this application can dynamically adjust the data encryption strategy according to the energy state of the underwater sensor node, the data security requirements, and the congestion degree of the underwater wireless communication environment. On the premise of ensuring the wireless transmission security of the underwater pipeline monitoring data, it takes into account the low power consumption and long-life operation of the sensor node, and finally realizes differential data security protection, effectively solving the problems of resource waste and insufficient security protection existing in the prior art, and providing a more efficient and reliable data security guarantee solution for the underwater pipeline safety monitoring application.
[0082] In some preferred embodiments, step A1 includes:
[0083] A101. Collect the battery voltage value of the underwater sensor node in real time, and convert the battery voltage value into the percentage of the remaining battery power;
[0084] A102. Compare the percentage of the remaining battery power with a preset high battery power threshold and a low battery power threshold; wherein, the high battery power threshold is greater than the low battery power threshold;
[0085] A103. If the percentage of the remaining battery power is greater than the high battery power threshold, set the energy consumption weight to a first preset value;
[0086] A104. If the percentage of the remaining battery power is less than the low battery power threshold, set the energy consumption weight to a second preset value;
[0087] A105. If the percentage of the remaining battery power is between the high battery power threshold and the low battery power threshold, calculate the energy consumption weight according to a linear function, so that the energy consumption weight is between the first preset value and the second preset value.
[0088] Among them, in step A101, the underwater sensor node is configured with a voltage sensor for real-time monitoring of the voltage across the battery. The analog voltage signal collected by the voltage sensor is converted into a digital signal by an analog-to-digital converter, and the digital signal represents the current battery voltage value. In order to convert the voltage value into a more intuitive percentage of the remaining battery power, a mapping relationship between the battery voltage and the remaining power can be established in advance. This mapping relationship can be non-linear, for example, obtained by fitting experimental data, or a linear approximation can be used within a certain voltage range. The conversion process uses a preset voltage-electricity percentage conversion model or a look-up table to convert the collected battery voltage value into the corresponding percentage of the remaining battery power.
[0089] Among them, in step A102, the high battery power threshold and the low battery power threshold are two preset electricity percentage values. For example, the high battery power threshold is set to 80%, and the low battery power threshold is set to 20%. These two thresholds are used to divide different state intervals of the battery power.
[0090] Among them, in steps A103 and A104, the first preset value and the second preset value are two preset energy consumption weight values. The first preset value corresponds to the case of sufficient battery power and can be set to a smaller value, such as 0.3, indicating that the attention to energy consumption is lower at this time. The second preset value corresponds to the case of low battery power and can be set to a larger value, such as 0.8, indicating that the attention to energy consumption is higher at this time.
[0091] Among them, in step A105, a linear function is used to smoothly calculate the energy consumption weight when the percentage of the remaining battery power is between the high power threshold and the low power threshold. The linear function ensures that the energy consumption weight increases steadily as the battery power decreases, avoiding sudden changes in the weight value. For example, the linear function can be expressed as: w = (w1 - w2) * (Q - Q2) / (Q1 - Q2) + w2, where w is the energy consumption weight, Q is the percentage of the remaining battery power, w1 is the first preset value, w2 is the second preset value, Q1 is the high power threshold, and Q2 is the low power threshold.
[0092] Specifically, through the above steps, the energy consumption weight can be finely adjusted according to the remaining battery power. When the battery is fully charged, the energy consumption weight is set to a relatively low first preset value, indicating that the system can tolerate relatively high energy consumption at this time, so a higher security strength encryption algorithm can be selected to ensure data security. As the battery power gradually decreases, when the percentage of the battery power is between the high power threshold and the low power threshold, the energy consumption weight gradually increases through a linear function, reflecting that the system's attention to energy consumption is gradually increasing. When the battery power is lower than the low power threshold, the energy consumption weight is set to a relatively high second preset value, indicating that the system is highly sensitive to energy consumption at this time and will tend to select an encryption algorithm with relatively low energy consumption but moderate security strength to extend the working time of the node. Thus, the energy consumption weight can be adaptively adjusted according to the remaining battery power state, providing an important energy consumption reference basis for the subsequent selection of data encryption algorithms, and realizing the optimization of data security management in energy-constrained scenarios.
[0093] In some possible implementation manners, step A101 includes:
[0094] Using a moving average filtering algorithm to smooth the battery voltage value of the underwater sensor node collected in real time to obtain a filtered battery voltage value;
[0095] Calculating the voltage change rate according to the filtered battery voltage value;
[0096] Evaluating the battery health state according to the change curves of the filtered battery voltage value and the voltage change rate to obtain a health state evaluation value;
[0097] Correcting the filtered battery voltage value at the current moment according to the health state evaluation value and converting the corrected battery voltage value into a percentage of the remaining battery power.
[0098] Among them, the moving average filtering algorithm is used to smooth the battery voltage values of underwater sensor nodes collected in real time, in order to reduce the influence of noise on the voltage values. Specifically, a fixed-length moving window can be set, for example, the window length is set to 5 sampling points, or a variable-length moving window can be used, and the window length can be adaptively adjusted according to the noise level. The moving average filtering algorithm smooths the voltage signal by calculating the average value of the voltage values within the window, filters out the high-frequency noise components, and obtains a relatively stable filtered voltage value, providing a more reliable data basis for subsequent calculations.
[0099] Among them, calculating the voltage change rate based on the filtered battery voltage value is to understand the changing trend of the battery voltage over time. Specifically, the first-order difference method can be used to calculate the voltage change rate, that is, subtracting the filtered voltage value at the previous moment from the filtered voltage value at the current moment, and then dividing by the time interval to obtain the voltage change rate. The unit of the voltage change rate can be millivolts per second (mV / s). The voltage change rate can reflect the discharge rate of the battery and provide a reference for evaluating the battery health state.
[0100] Among them, evaluating the battery health state based on the change curves of the filtered battery voltage value and the voltage change rate to obtain the health state evaluation value means comprehensively considering the current level of the battery voltage and the rate of change of the voltage over time to judge the health status of the battery. Specifically, it can be achieved by constructing a battery health state evaluation model. For example, the voltage and voltage change rate data of the battery in different health states can be pre-collected, and the mapping relationship between the battery health state, voltage, and voltage change rate can be established to obtain the health state evaluation model. The evaluation model can be a multiple regression model or a neural network model. The health state evaluation value can be a numerical value between 0 and 1, and the higher the value, the better the battery health state.
[0101] Among them, correcting the filtered battery voltage value at the current moment according to the health state evaluation value and converting the corrected battery voltage value into the battery remaining power percentage means using the battery health state evaluation result to correct the current voltage value to improve the accuracy of converting the voltage value into the battery remaining power percentage. Specifically, the following correction method can be used: when the battery health state evaluation value is smaller, it indicates that the degree of battery aging or performance decline is higher. At this time, the actual remaining power of the battery is more likely to be lower than the power percentage directly converted from the voltage value. Therefore, the voltage value needs to be corrected downward. For example, the voltage value can be corrected by the following formula: V_c = V_f * (1 - k * (1 - H)), where V_c represents the corrected battery voltage value, V_f represents the filtered battery voltage value, k is the correction coefficient, for example, taking 0.1, and H is the health state evaluation value.
[0102] The corrected battery voltage value is then passed through a voltage - battery charge percentage conversion model or a lookup table to obtain the final remaining battery charge percentage. The voltage - battery charge percentage conversion model can be a linear model or a non - linear model, such as a piece - wise linear model or a curve fitting model.
[0103] Specifically, during the process of the underwater sensor node collecting hydrological monitoring data, in step A101, the battery voltage value is first collected in real - time. Due to the complex underwater environment, the voltage acquisition process is vulnerable to noise interference, and directly using the original voltage value for power assessment may not be accurate. Therefore, a moving average filtering algorithm is used to smooth the original voltage value, eliminate the random noise in the voltage signal, and obtain a stable filtered voltage value. Then, the voltage change rate of the filtered voltage value is calculated to reflect the battery discharge speed and health status. Combining the filtered voltage value and the voltage change rate, through a pre - established battery health status assessment model, the health status of the battery is comprehensively evaluated to obtain a health status assessment value. The health status assessment value can be used to characterize the actual performance level of the battery. Further, the filtered voltage value at the current moment is corrected using the health status assessment value. The correction process takes into account the health status of the battery, enabling the voltage value to more accurately reflect the actual remaining battery charge. Finally, the corrected voltage value is converted into a battery remaining charge percentage to obtain the final battery remaining charge assessment result. Through the above technical means, more accurate and reliable battery remaining charge information can be obtained. This accurate power assessment result can provide a more reliable basis for the determination of subsequent energy consumption weights and the reasonable selection of encryption algorithms, thereby enhancing the effectiveness and reliability of the entire data security management method.
[0104] Through the above technical solutions, this application can more accurately and reliably evaluate the remaining battery charge of the underwater sensor node. Through moving average filtering, the voltage noise interference is effectively eliminated, ensuring the smoothness of the voltage data; through the voltage change rate and battery health status assessment, the health status of the battery is comprehensively reflected; through the correction of the voltage using the health status assessment value, the accuracy of the voltage value and even the final charge percentage is further improved. Thus, a more reliable power basis can be provided for the determination of subsequent energy consumption weights and the selection of encryption algorithms, thereby enhancing the overall performance of the data security management method.
[0105] In some embodiments, step A2 includes:
[0106] A201. Extract the metadata of the hydrological monitoring data collected by the underwater sensor node, where the metadata includes a data type identifier;
[0107] A202. According to the data type identifier, query to obtain the security impact level of various types of hydrological monitoring data;
[0108] A203. Group various types of hydrological monitoring data according to the security impact level, and calculate the security level of each group of hydrological monitoring data according to the security impact level of various types of hydrological monitoring data within the group;
[0109] A204. Determine the data security weight of each group of hydrological monitoring data according to the corresponding relationship between the preset security level and the data security weight.
[0110] Among them, in step A201, the metadata can be included in the header part of the data packet. The data type identifier, as the key information in the metadata, is used to distinguish different types of hydrological monitoring data. For example, the data type identifier can be in the form of a digital code or a string.
[0111] Among them, in step A202, the security impact level of various types of hydrological monitoring data is obtained by querying the preset security level database or lookup table. The security level database or lookup table stores the mapping relationship between various data type identifiers and the corresponding security impact levels. The security impact level can be predefined as three levels: high, medium, and low, or can be quantitatively represented by a numerical value.
[0112] Among them, in step A203, based on the security impact level obtained in step A202, various types of hydrological monitoring data are grouped. The grouping principle can be to group according to the similarity of the security impact level. For example, data with similar security impact levels are divided into the same group. After the data grouping is completed, the security level of various types of hydrological monitoring data within the group is calculated. As an implementation method, the group security level can be set to the highest security impact level within the group, or obtained by calculating the weighted average of the security impact levels of various types of data within the group.
[0113] Among them, in step A204, the data security weight of each group of hydrological monitoring data is determined according to the corresponding relationship between the preset security level and the data security weight. The preset corresponding relationship can be a linear function, a non-linear function, a piecewise function, or a mapping relationship, etc. The higher the security level of the data group, the higher the data security weight assigned.
[0114] Specifically, step A2 aims to solve the problems of differentiating the security levels and reasonably grouping different types of hydrological monitoring data. In the application of underwater pipeline safety monitoring, different types of hydrological data, such as water temperature, water pressure, stress, corrosion rate, etc., have different security sensitivities. By extracting the data type identifier in step A201, the identification of different types of hydrological data is realized. Step A202 queries the security impact level based on the data type identifier, providing a level standard for subsequent data grouping and differential security management. Step A203 performs data grouping according to the security impact level, so that data with similar security levels are aggregated together, facilitating the formulation of unified security policies for the subsequent data groups. Step A204 converts the abstract security level into a quantifiable data security weight, providing a quantitative basis for the calculation of subsequent comprehensive performance indicators and the selection of encryption algorithms. Thus, through steps A201 to A204, a set of methods for data security level division and weight determination is established, realizing the differentiated management of hydrological monitoring data with different security sensitivities, and providing a data basis for subsequent adoption of differential data security management strategies.
[0115] In some preferred embodiments, step A203 includes:
[0116] B1. Compare the security impact levels of various hydrological monitoring data with a preset security impact level threshold, and perform preliminary grouping on the hydrological monitoring data;
[0117] B2. According to the data volume and security impact level of various hydrological monitoring data within the group, use the weighted average algorithm to calculate the initial security level of the hydrological monitoring data in each group; the larger the data volume, the greater the weight of the corresponding hydrological monitoring data;
[0118] B3. Calculate the level deviation between the security impact level of each type of hydrological monitoring data within each group of hydrological monitoring data and the corresponding initial security level. If all the level deviations within the group do not exceed the preset deviation threshold, then perform step B4 for the corresponding data group. Otherwise, split the corresponding data group into multiple groups of data, and perform steps B2 and B3 again for the split data groups;
[0119] B4. Take the initial security level of each group of hydrological monitoring data as the security level of the corresponding data group.
[0120] Among them, in step B1, a set security impact level threshold can be used as a division standard. The hydrological monitoring data with a security impact level higher than this security impact level threshold is divided into one group, and the hydrological monitoring data with a security impact level lower than or equal to this security impact level threshold is divided into another group, thereby realizing the preliminary grouping of hydrological monitoring data.
[0121] Among them, in step B2, hydrological monitoring data with a larger data volume has a greater weight when calculating the group security level. Conversely, data with a smaller data volume has a smaller weight. Through this weighted average method, the overall security situation of the data group can be more accurately reflected. For example, assuming that a group of data contains a large amount of data with a higher security impact level, then the initial security level of this group will be correspondingly higher, and vice versa.
[0122] Among them, in step B3, after obtaining the initial security levels of each group of hydrological monitoring data, the rationality of the grouping and the uniformity of the security levels within the group are further evaluated. The specific method is to calculate the deviation between the security impact level of each type of hydrological monitoring data within the group and the initial security level of the group. If the level deviations of all data within a group are controlled within the preset deviation threshold range, then the grouping is considered reasonable and the subsequent step B4 can be executed; conversely, if there is data within the group with a level deviation exceeding the threshold, it indicates that the grouping is not fine enough, and the data in this group needs to be further split into multiple small groups, and steps B2 and B3 are re-executed for the split small groups. Through iterative optimization, the rationality of the grouping and the uniformity of the security levels within the group are ensured. When splitting, after sorting according to the security impact level, the data group can be divided into two groups according to the number of categories of the hydrological monitoring data within the group. If the number of categories is even, it is evenly divided into two groups. If the number of categories is odd, one of the divided groups will have one more category than the other.
[0123] Among them, step B4 means that after the deviation verification and iterative optimization in step B3, the initial security level of each data group is finally determined, and this initial security level is used as the final security level of the data group. This means that each data group has obtained a security level score that can comprehensively reflect the security situation of the data within the group, providing a quantitative basis for the formulation of subsequent data security management strategies.
[0124] Further, in step B1, by comparing the security impact levels of various hydrological monitoring data with the preset security impact level thresholds, preliminary data classification based on the security impact levels is achieved, laying a foundation for subsequent refined security level calculation. In step B2, the scheme does not simply average the security levels of various data, but introduces a weighted average algorithm and takes into account the factor of data volume. The larger the data volume, the greater the weight, which is more in line with the actual application scenario, because data types with large data volumes often have a greater impact on overall security. This weighted average method can more accurately reflect the overall security situation of the data group. In step B3, a verification mechanism for level deviation is introduced. By calculating the deviation between the security impact level of each type of data within the group and the initial security level, and setting a deviation threshold, if the deviation is too large, it indicates that the grouping may not be reasonable enough. The data group needs to be further split, and the weighted average calculation and deviation verification are carried out again. The iterative optimization process can effectively improve the accuracy of grouping and the uniformity of the security levels within the group. In step B4, the verified initial security level is used as the final security level of the data group, ensuring the accuracy and reliability of the determination of the security level, providing strong support for subsequent data security management strategies based on the security level, and making data security management more refined and effective. There is a sequential and progressive relationship among steps B1 to B4 above. Step B1 is for preliminary grouping, step B2 calculates the initial security level based on the preliminary grouping, step B3 conducts deviation verification and grouping optimization on the initial security level, and step B4 obtains the final security level. Through the above steps, accurate calculation and reasonable grouping of the security levels of hydrological monitoring data are achieved, providing a more reliable basis for subsequent differentiated data security management strategies.
[0125] Through the above technical solution, the present application can more accurately determine the security levels of each group of hydrological monitoring data, fully considering the differences in data volume and security impact levels of different types of data, avoiding the problem of security level deviation that may be caused by simple average calculation, ensuring the rationality of grouping and the uniformity of security levels within the group, providing a more reliable and refined security level basis for the formulation of subsequent data security strategies, and enabling more targeted security management measures to be taken for data groups with different security levels.
[0126] In some embodiments, step A3 includes:
[0127] A301. Obtain the transmission delay of the underwater wireless communication link;
[0128] A302. Calculate the congestion degree of the underwater wireless communication link according to the transmission delay;
[0129] A303. Calculate the bandwidth occupancy weight according to the congestion degree.
[0130] Among them, in step A301, the acquisition of the transmission delay can be implemented as follows: at the underwater sensor node, when a data packet is sent to the shore-based monitoring center, the sending timestamp is recorded; when the shore-based monitoring center receives the data packet, the receiving timestamp is recorded and returned to the underwater sensor node; the transmission delay of the data packet is calculated by the difference between the receiving timestamp and the sending timestamp. Further, in order to improve the accuracy of the delay measurement, the method of taking the average of multiple measurements can be adopted, or filtering algorithms such as Kalman filtering can be used to smooth the delay measurement value to reduce noise interference.
[0131] Among them, in step A302, the calculation of the congestion degree can be implemented as follows: First, a reference transmission delay is set, which can be the measured value of the transmission delay in the idle state of the underwater wireless communication link or a preset empirical value. Then, the current transmission delay obtained in step A301 is compared with the reference transmission delay. If the current transmission delay is significantly higher than the reference transmission delay, it is determined that the underwater wireless communication link is in a congested state, and the congestion degree is positively correlated with the degree to which the current transmission delay exceeds the reference transmission delay. Specifically, the congestion degree can be quantified as a congestion factor, which can be obtained by normalizing the ratio or difference between the current transmission delay and the reference transmission delay.
[0132] Among them, in step A303, the calculation of the bandwidth occupancy weight can be implemented as follows: According to the congestion degree obtained in step A302, a linear function, a non-linear function or a look-up table is used to determine the bandwidth occupancy weight. As a preferred implementation, when the congestion degree is high, the bandwidth occupancy weight is set to a high value, indicating that the bandwidth resource is relatively scarcer and more important than the energy resource at this time; when the congestion degree is low, the bandwidth occupancy weight is set to a low value, indicating that the consideration of the bandwidth resource can be relatively relaxed at this time.
[0133] Specifically, through the above steps, this solution defines the specific calculation method of the bandwidth occupancy weight. Through this method, the bandwidth occupancy weight can be dynamically adjusted according to the actual congestion condition of the underwater wireless communication link, thereby affecting the selection of the encryption algorithm, so that the data security management method can better adapt to the changes in the underwater wireless communication environment.
[0134] In some possible implementation manners, in step A301, the transmission delays of multiple data packets on the underwater wireless communication link are acquired to form a delay sequence;
[0135] Step A302 includes:
[0136] The delay sequence is smoothed by using a sliding window to obtain a smoothed delay sequence;
[0137] Calculate the delay jitter and average transmission delay of the smoothed delay sequence;
[0138] Calculate the congestion degree of the underwater wireless communication link according to the delay jitter and average transmission delay.
[0139] Among them, in step A301, the acquisition of the transmission delays of multiple data packets can be achieved by the underwater sensor node recording the sending timestamp when sending the data packet and recording the receiving timestamp when receiving the confirmation information returned by the shore-based monitoring center. Thus, the transmission delay of each data packet can be calculated by the difference between the receiving timestamp and the sending timestamp. Further, in order to form a delay sequence, the transmission delays of a predetermined number of consecutive data packets can be acquired. For example, the size of the sliding window can be set to 10, that is, a delay sequence is acquired every 10 data packets.
[0140] In step A302, the sliding window smoothing process can specifically be to average the delay sequence data within the sliding window and use the average value as the smoothed delay value, thereby obtaining the smoothed delay sequence. The delay jitter can be calculated as the standard deviation of the delay values in the smoothed delay sequence, reflecting the degree of delay fluctuation. The average transmission delay can be directly obtained by calculating the average value of all delay values in the smoothed delay sequence, reflecting the average delay level of the link. The calculation of the congestion degree can be implemented as a weighted sum of the delay jitter and average transmission delay, and the weight coefficients can be adjusted according to the actual application scenario and empirical data. For example, the weights of the delay jitter and average transmission delay can be set to be equal, or according to the characteristics of the underwater environment, a higher weight can be given to the delay jitter to more sensitively reflect the congestion changes of the link.
[0141] Specifically, by introducing the delay sequence, the accidental error of single-delay data is overcome, making the evaluation of the congestion degree more comprehensive. The adoption of the sliding window smoothing process effectively eliminates the noise and mutations in the delay sequence, extracts the stable delay change trend, and ensures the reliability of the congestion evaluation. The calculation of the delay jitter and average transmission delay comprehensively characterizes the congestion state of the underwater wireless communication link. The delay jitter reflects the network instability, and the average transmission delay reflects the average delay level. The combined use of the two makes the evaluation of the congestion degree more accurate. Finally, based on the accurate congestion degree evaluation result, a reliable basis can be provided for the subsequent calculation of the bandwidth occupancy weight, thereby optimizing the overall performance of the data security management method and taking into account the low power consumption and long lifespan operation of the sensor node while ensuring data security.
[0142] In some embodiments, step A4 includes:
[0143] A401. For each set of hydrological monitoring data, according to the type identifiers of various types of hydrological monitoring data within the set, select multiple encryption algorithms that are adapted to the hydrological monitoring data of this set from a preset encryption algorithm parameter library; among them, the encryption algorithm parameter library stores the energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms that have been pre-evaluated.
[0144] A402. For each selected encryption algorithm, calculate the comprehensive performance index value of the corresponding encryption algorithm according to the corresponding energy consumption, bandwidth overhead, and security strength parameters, as well as the energy consumption weight, the corresponding data security weight, and the bandwidth occupancy weight.
[0145] Among them, in step A401, the preset encryption algorithm parameter library is used to store the parameters of multiple encryption algorithms, and the parameters at least include energy consumption, bandwidth overhead, and security strength. For each set of hydrological monitoring data, the identification of the data type is first completed, and the type identifier is used to retrieve and select the adapted encryption algorithm from the encryption algorithm parameter library. For example, if the hydrological monitoring data includes types such as temperature and salinity, the selected encryption algorithm needs to be able to effectively process these types of data. The data types that each encryption algorithm can effectively process can be pre-recorded in the encryption algorithm parameter library in the form of an encryption algorithm capability query table, so that the corresponding encryption algorithm can be selected by querying this query table. Through the screening of the type identifier, the selection range of the encryption algorithm can be narrowed, improving the efficiency and accuracy of subsequent performance evaluation.
[0146] Among them, in step A402, for each selected encryption algorithm, the calculation of the comprehensive performance index value is performed. The calculation process comprehensively considers the energy consumption parameter, bandwidth overhead parameter, and security strength parameter of the encryption algorithm, and combines the energy consumption weight, data security weight, and bandwidth occupancy weight determined in the previous step. The role of the weight here is to adjust the relative importance of the three factors of energy consumption, data security, and bandwidth occupancy in the comprehensive performance evaluation. For example, when the battery power is low, the energy consumption weight can be set higher, so that when selecting an encryption algorithm, the algorithm with lower energy consumption is given priority. Through the calculation of the comprehensive performance index value, the comprehensive performance of each encryption algorithm can be quantified, providing a numerical basis for subsequent selection of the optimal encryption algorithm.
[0147] Specifically, step A401 performs a preliminary screening of encryption algorithms to ensure that the encryption algorithms subsequently evaluated and selected match the current monitoring data type. This avoids invalid evaluations of inappropriate algorithms and improves the efficiency of algorithm selection. Step A402, based on the screening of step A401, calculates the comprehensive performance index value to achieve a quantitative performance evaluation of multiple adaptive encryption algorithms. The calculation of the comprehensive performance index value comprehensively considers energy consumption, bandwidth overhead and security strength, and adjusts the influence of each factor through weights, so that the selection of the algorithm can better adapt to the needs of the actual application environment. For example, in energy-limited or bandwidth-limited scenarios, the weights can be adjusted so that the algorithm selection focuses more on low power consumption or low bandwidth overhead. Therefore, through the screening of step A401 and the calculation of the index value of step A402, the encryption algorithm with the best comprehensive performance can be selected for each group of hydrological monitoring data, thereby taking into account the energy efficiency and bandwidth utilization of underwater sensor nodes while ensuring data security.
[0148] In some embodiments, step A6 comprises:
[0149] A601. Priority is assigned to each group of hydrological monitoring data machines according to the security level; the higher the security level of the data, the higher the priority;
[0150] A602. Transmit each group of hydrological monitoring data to the shore-based monitoring center through the underwater wireless communication link in turn according to the priority, and monitor the packet loss rate of the underwater wireless communication link during the transmission process;
[0151] A603. When it is detected that the packet loss rate exceeds the preset packet loss rate threshold, the transmission of data with a priority not higher than the preset priority threshold is suspended, and data with a priority higher than the preset priority threshold is retransmitted first until the packet loss rate returns to below the preset threshold, and the remaining data is continued to be transmitted.
[0152] Among them, in step A601, a priority allocation operation is performed for hydrological monitoring data with different security levels. Data with a high security level is assigned a higher transmission priority, and data with a low security level is assigned a lower transmission priority, thereby ensuring that important data enjoys priority during the transmission process.
[0153] Among them, in step A602, the data is transmitted to the shore-based monitoring center through the underwater wireless communication link according to the priority order determined in step A601. During the data transmission process, the packet loss rate of the underwater wireless communication link is continuously monitored for real-time evaluation of the channel quality.
[0154] Among them, in step A603, when it is monitored that the packet loss rate exceeds the preset packet loss rate threshold, the system determines that the quality of the current underwater wireless communication link deteriorates. At this time, the data transmission operation is adjusted, and the transmission of data with a priority not higher than the preset priority threshold is suspended, and instead, the data with a priority higher than the preset priority threshold is preferentially processed and retransmitted, so as to ensure the reliability of high-security-level data transmission. Until the monitored packet loss rate recovers below the preset threshold, indicating that the channel quality has improved, the system resumes transmitting the low-priority data that was previously suspended.
[0155] Specifically, for hydrological monitoring data of different security levels, priority division is first performed. During the data transmission stage, the system first transmits high-priority data and then low-priority data. During the data transmission process, the packet loss rate monitoring module continuously monitors the packet loss situation of the underwater wireless communication link. For example, the packet loss rate is calculated by counting the difference between the total number of sent data packets and the total number of received acknowledgment data packets. The preset packet loss rate threshold is preset. For example, it can be set to 10%. The preset priority threshold is also preset. For example, it can be set to medium priority. When the monitored packet loss rate exceeds 10%, the system determines that the channel quality has deteriorated, immediately suspends the transmission of low-priority data, and preferentially retransmits high-priority and medium-priority data to ensure that high-security-level data is preferentially delivered to the shore-based monitoring center. When the packet loss rate recovers below 10%, the system resumes transmitting the low-priority data that was previously suspended. Through this priority scheduling and packet loss rate monitoring mechanism, the transmission reliability of high-security-level data can be effectively ensured under the condition of fluctuating quality of the underwater wireless communication link.
[0156] Reference Figure 2 , this application provides a data security management device for securely managing hydrological monitoring data collected during underwater pipeline safety monitoring of underwater sensor nodes. The device includes:
[0157] A battery power monitoring module 1 for monitoring the remaining battery power of the underwater sensor node and determining the energy consumption weight according to the comparison result between the remaining battery power and the preset power threshold (the specific process refers to step A1 in the previous text);
[0158] A security level determination module 2 for grouping the hydrological monitoring data collected by the underwater sensor node and determining the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data (the specific process refers to step A2 in the previous text);
[0159] A bandwidth evaluation module 3 for determining the bandwidth occupancy weight according to the congestion degree of the underwater wireless communication environment (the specific process refers to step A3 in the previous text);
[0160] A performance calculation module 4, which is configured to calculate the comprehensive performance index values of different encryption algorithms for each group of hydrological monitoring data based on the determined energy consumption weight, corresponding data security weight, bandwidth occupancy weight, and the pre-evaluated energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms (for the specific process, refer to step A4 in the previous text);
[0161] A data encryption module 5, which is configured to select the encryption algorithm with the optimal comprehensive performance index value for each group of hydrological monitoring data and perform encryption processing on this group of hydrological monitoring data (for the specific process, refer to step A5 in the previous text);
[0162] A data transmission module 6, which is configured to transmit the encrypted hydrological monitoring data to the shore-based monitoring center through an underwater wireless communication link (for the specific process, refer to step A6 in the previous text).
[0163] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some communication interfaces. The indirect coupling or communication connection of the devices or units can be in an electrical, mechanical or other form.
[0164] In addition, the units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units. They can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0165] Furthermore, in each embodiment of the present application, the functional modules can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.
[0166] In this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.
[0167] The above are only the embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various modifications and changes can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A data security management method for securely managing the hydrological monitoring data collected during the underwater pipeline safety monitoring of underwater sensor nodes, characterized in that, The steps of the method include: A1. Monitor the remaining battery power of the underwater sensor node, and determine the energy consumption weight according to the comparison result between the remaining battery power and the preset power threshold; A2. Group the hydrological monitoring data collected by the underwater sensor node, and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data; A3. Determine the bandwidth occupancy weight according to the congestion degree of the underwater wireless communication environment; A4. For each group of hydrological monitoring data, calculate the comprehensive performance index values of different encryption algorithms based on the determined energy consumption weight, the corresponding data security weight, the bandwidth occupancy weight, and the energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms evaluated in advance; A5. For each group of hydrological monitoring data, select the encryption algorithm with the optimal comprehensive performance index value, and encrypt the hydrological monitoring data of this group; A6. Transmit the encrypted hydrological monitoring data to the shore-based monitoring center through the underwater wireless communication link.
2. The data security management method according to claim 1, wherein Step A1 includes: A101. Real-time collect the battery voltage value of the underwater sensor node, and convert the battery voltage value into a percentage of the remaining battery power; A102. Compare the percentage of the remaining battery power with the preset high power threshold and low power threshold; where the high power threshold is greater than the low power threshold; A103. If the percentage of the remaining battery power is greater than the high power threshold, set the energy consumption weight to the first preset value; A104. If the percentage of the remaining battery power is less than the low power threshold, set the energy consumption weight to the second preset value; A105. If the percentage of the remaining battery power is between the high power threshold and the low power threshold, calculate the energy consumption weight according to a linear function, so that the energy consumption weight is between the first preset value and the second preset value.
3. The data security management method according to claim 2, characterized in that Step A101 includes: Adopt a moving average filtering algorithm to smooth the battery voltage value of the underwater sensor node collected in real time to obtain a filtered battery voltage value; Calculate the voltage change rate according to the filtered battery voltage value; Evaluate the battery health status according to the change curves of the filtered battery voltage value and the voltage change rate to obtain a health status evaluation value; Correct the filtered battery voltage value at the current moment according to the health status evaluation value, and convert the corrected battery voltage value into a percentage of the remaining battery power.
4. A data security management method according to claim 1, characterized in that, Step A2 includes: A201. Extract the metadata of the hydrological monitoring data collected by the underwater sensor node, and the metadata includes a data type identifier; A202. Query the security impact level of various hydrological monitoring data according to the data type identifier; A203. Group various hydrological monitoring data according to the security impact level, and calculate the security level of each group of hydrological monitoring data according to the security impact level of various hydrological monitoring data within the group; A204. Determine the data security weight of each group of hydrological monitoring data according to the corresponding relationship between the preset security level and the data security weight.
5. A data security management method according to claim 4, characterized in that, Step A203 includes: B1. Compare the security impact level of various hydrological monitoring data with the preset security impact level threshold, and conduct a preliminary grouping of the hydrological monitoring data; B2. Calculate the initial security level of each group of hydrological monitoring data using a weighted average algorithm according to the data volume and security impact level of various types of hydrological monitoring data within the group; the larger the data volume, the greater the weight of the corresponding hydrological monitoring data. B3. Calculate the level deviation between the security impact level of each type of hydrological monitoring data within each group of hydrological monitoring data and the corresponding initial security level. If all the level deviations within the group do not exceed the preset deviation threshold, then execute step B4 for the corresponding data group; otherwise, split the corresponding data group into multiple data groups, and execute step B2 and step B3 again for the split data groups. B4. Take the initial security level of each group of hydrological monitoring data as the security level of the corresponding data group.
6. A data security management method according to claim 1, characterized in that, Step A3 includes: A301. Obtain the transmission delay of the underwater wireless communication link. A302. Calculate the congestion degree of the underwater wireless communication link according to the transmission delay. A303. Calculate the bandwidth occupancy weight according to the congestion degree.
7. A data security management method according to claim 6, characterized in that, In step A301, obtain the transmission delays of multiple data packets on the underwater wireless communication link to form a delay sequence. Step A302 includes: Perform smoothing processing on the delay sequence using a sliding window to obtain a smoothed delay sequence. Calculate the delay jitter and average transmission delay of the smoothed delay sequence. Calculate the congestion degree of the underwater wireless communication link according to the delay jitter and the average transmission delay.
8. A data security management method according to claim 1, characterized in that Step A4 includes: A401. For each group of hydrological monitoring data, according to the type identifier of various types of hydrological monitoring data within the group, screen multiple encryption algorithms adapted to this group of hydrological monitoring data from the preset encryption algorithm parameter library; among them, the encryption algorithm parameter library stores the energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms evaluated in advance. A402. For each screened encryption algorithm, calculate the comprehensive performance index value of the corresponding encryption algorithm according to the corresponding energy consumption, bandwidth overhead, and security strength parameters, as well as the energy consumption weight, the corresponding data security weight, and the bandwidth occupancy weight.
9. A data security management method according to claim 1, characterized in that, Step A6 includes: A601. Perform priority allocation on each group of hydrological monitoring data machines according to the security level; the higher the security level of the data, the higher the priority. A602. According to the priority size, sequentially transmit each group of hydrological monitoring data to the shore-based monitoring center through the underwater wireless communication link, and during the transmission process, monitor the packet loss rate of the underwater wireless communication link. A603. When it is detected that the packet loss rate exceeds the preset packet loss rate threshold, suspend the transmission of data with a priority not higher than the preset priority threshold, and preferentially retransmit data with a priority higher than the preset priority threshold until the packet loss rate returns below the preset threshold, and then continue to transmit the remaining data.
10. A data security management device is used for securely managing the hydrological monitoring data collected during the underwater pipeline safety monitoring of underwater sensor nodes. It is characterized in that, The device includes: A battery power monitoring module, used to monitor the remaining battery power of the underwater sensor node, and determine the energy consumption weight according to the comparison result between the remaining battery power and the preset power threshold. A security level determination module, used to group the hydrological monitoring data collected by the underwater sensor node, and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data. A bandwidth evaluation module, which is used to determine the bandwidth occupancy weight according to the congestion degree of the underwater wireless communication environment; A performance calculation module, which is used to calculate the comprehensive performance index values of different encryption algorithms for each group of hydrological monitoring data based on the determined energy consumption weight, corresponding data security weight, bandwidth occupancy weight, and the pre-evaluated energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms; A data encryption module, which is used to select the encryption algorithm with the optimal comprehensive performance index value for each group of hydrological monitoring data and perform encryption processing on this group of hydrological monitoring data; A data transmission module, which is used to transmit the encrypted hydrological monitoring data to the shore-based monitoring center through the underwater wireless communication link.
Citation Information
Patent Citations
Method for encryption in sensor network, encryption device and sensor network
CN103297959A
Secure communication method of Internet of Things equipment data
CN118523934A
Electric energy meter data security management method and system
CN119293827A