Data security management method and device

By dynamically adjusting the encryption algorithm of underwater sensor nodes according to battery status, data security level and communication congestion, the problem of energy and bandwidth limitations in underwater pipeline monitoring is solved, differentiated data security protection and resource optimization are achieved, and the efficiency and reliability of underwater pipeline monitoring are improved.

CN120321643BActive Publication Date: 2025-09-30BEIJING RUIFENG YUNKE INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510450494.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-09-30
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

In the safety monitoring of underwater pipelines in remote sea areas, existing technologies cannot effectively solve the energy and bandwidth limitations of underwater sensor nodes. At the same time, there is a lack of differentiated security protection for different data sensitivities, resulting in resource waste and insufficient security.

Method used

By monitoring the remaining battery power, data security level and congestion level of the wireless communication environment of underwater sensor nodes, the energy consumption, bandwidth occupancy and security strength of the encryption algorithm are dynamically adjusted to achieve differentiated data security protection.

Benefits of technology

On the premise of ensuring data security, it reduces energy consumption, saves bandwidth resources, extends the life of sensor nodes, realizes differentiated data security management, and improves the efficiency and reliability of underwater pipeline monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321643B_ABST
    Figure CN120321643B_ABST
Patent Text Reader

Abstract

The present application belongs to the field of data security technology and discloses a data security management method and device, the method comprising: monitoring the remaining battery power of underwater sensor nodes to determine an energy consumption weight; grouping the hydrological monitoring data collected by the underwater sensor nodes to determine the data security weight of each group of data; determining the bandwidth occupancy weight according to the congestion level of the underwater wireless communication environment; for each group of hydrological monitoring data, calculating the comprehensive performance index values ​​of different encryption algorithms based on the energy consumption weight, data security weight, bandwidth occupancy weight, and the energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms; for each group of hydrological monitoring data, selecting the encryption algorithm with the optimal comprehensive performance index value and encrypting the group of hydrological monitoring data; transmitting the encrypted hydrological monitoring data to a shore-based monitoring center; thereby reducing energy consumption, saving bandwidth resources, and achieving differentiated data security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and more specifically, to a data security management method and device. Background Art

[0002] Battery-powered underwater sensor nodes are widely deployed in the energy infrastructure sector, particularly for underwater pipeline safety monitoring in remote waters. These nodes have a crucial mission: continuously collecting hydrological monitoring data closely related to the structural health of underwater pipelines. These data, for example, monitor key structural parameters such as pipeline stress levels and corrosion levels, as well as fundamental environmental parameters such as water temperature and pressure. The accuracy and integrity of this data are crucial to ensuring the safe and stable operation of underwater pipelines.

[0003] To ensure the security of these critical monitoring data during wireless transmission, existing solutions typically employ data encryption. However, the complex and harsh underwater environment presents numerous challenges for sensor nodes. First, underwater sensor nodes typically rely on limited battery power, and high-intensity encryption algorithms significantly increase the node's computational power consumption, which undoubtedly shortens its operating life. For applications requiring long-term, continuous monitoring, this increased energy consumption is extremely detrimental and may even lead to interruption of monitoring tasks. Second, the underwater wireless communication environment is inherently complex, with limited available bandwidth. Transmitting large amounts of encrypted data will further exacerbate the already strained communication burden and, in severe cases, may even cause data transmission delays or complete failure, impacting the real-time and reliability of the monitoring data. Furthermore, in practical applications, different types of hydrological monitoring data vary significantly in their security sensitivity. For example, basic environmental data such as water temperature and water pressure are relatively low in sensitivity, potentially causing minimal harm if leaked. However, pipeline structural parameters that directly reflect the health of the pipeline structure, such as stress and corrosion rate, contain highly sensitive pipeline safety information, and their leakage could directly threaten the safe operation of the pipeline. However, existing data security management methods often lack consideration of the differentiated security needs of data. If a unified high-intensity encryption strategy is adopted for all data, it will undoubtedly cause unnecessary energy waste and bandwidth occupation, further exacerbating the contradiction of limited resources and making the already fragile underwater sensor network worse.

[0004] Therefore, in the context of long-term safety monitoring of underwater pipelines for energy infrastructure in remote waters, achieving efficient and secure management of hydrological monitoring data, while addressing the demanding requirements of energy and bandwidth constraints and taking into account the differentiated security protection requirements of different data sensitivities, has become a key technical challenge that needs to be addressed. In particular, maximizing the low power consumption and long lifespan of sensor nodes, while effectively ensuring the security of wireless data transmission, and ultimately achieving differentiated data security protection, has become a critical and pressing challenge facing the development of underwater pipeline monitoring technology.

[0005] In view of the above problems, the existing technology is in urgent need of improvement. Summary of the Invention

[0006] The purpose of this application is to provide a data security management method and device, which has the advantages of reducing energy consumption, saving bandwidth resources, and achieving differentiated data security protection.

[0007] In a first aspect, the present application provides a data security management method for securely managing hydrological monitoring data collected by underwater sensor nodes when performing underwater pipeline safety monitoring. The method comprises the following steps:

[0008] A1. Monitor the remaining battery power of the underwater sensor node and determine the energy consumption weight based on the comparison result between the remaining battery power and the preset power threshold;

[0009] A2. Group the hydrological monitoring data collected by the underwater sensor nodes and determine the data security weight of each group of hydrological monitoring data based on its security level;

[0010] A3. Determine bandwidth occupancy weights based on the congestion level of the underwater wireless communication environment;

[0011] A4. For each set of hydrological monitoring data, calculate the comprehensive performance index values ​​of different encryption algorithms based on the determined energy consumption weight, the corresponding data security weight, the bandwidth usage weight, and the pre-assessed energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms;

[0012] A5. For each set of hydrological monitoring data, select the encryption algorithm with the best comprehensive performance index value and encrypt the hydrological monitoring data;

[0013] A6. Transmit the encrypted hydrological monitoring data to the shore-based monitoring center via an underwater wireless communication link.

[0014] This method, by considering the energy consumption weight, data security weight and bandwidth occupancy weight and selecting a suitable encryption algorithm, has the advantages of reducing energy consumption, saving bandwidth resources and achieving differentiated data security protection.

[0015] Preferably, step A1 includes:

[0016] A101. Collect the battery voltage value of the underwater sensor node in real time and convert the battery voltage value into a percentage of the remaining battery power;

[0017] A102. Compare the remaining battery power percentage with a preset high power threshold and a low power threshold; wherein the high power threshold is greater than the low power threshold;

[0018] A103. If the remaining battery power percentage is greater than the high power threshold, the energy consumption weight is set to a first preset value;

[0019] A104. If the remaining battery power percentage is less than the low power threshold, the energy consumption weight is set to a second preset value;

[0020] A105. If the remaining battery power percentage is between a high power threshold and a low power threshold, calculate the energy consumption weight according to a linear function so that the energy consumption weight is between a first preset value and a second preset value.

[0021] Therefore, the energy consumption weight can be adaptively adjusted according to the remaining battery power status, providing an important energy consumption reference basis for the subsequent selection of data encryption algorithms, and realizing data security management optimization in energy-constrained scenarios.

[0022] Preferably, step A101 includes:

[0023] The sliding average filtering algorithm is used to smooth the battery voltage value of the underwater sensor node collected in real time to obtain the filtered battery voltage value;

[0024] Calculate the voltage change rate based on the filtered battery voltage value;

[0025] Evaluate the battery health status based on the filtered battery voltage value and the voltage change rate curve to obtain a health status evaluation value;

[0026] The filtered battery voltage value at the current moment is corrected according to the health status evaluation value, and the corrected battery voltage value is converted into a percentage of the remaining battery power.

[0027] As a result, the performance and reliability of the entire data security management method can be improved.

[0028] Preferably, step A2 includes:

[0029] A201 extracts metadata of hydrological monitoring data collected by underwater sensor nodes, the metadata including a data type identifier;

[0030] A202. Based on the data type identifier, query and obtain the safety impact level of various types of hydrological monitoring data;

[0031] A203. Group various types of hydrological monitoring data according to the safety impact level, and calculate the safety level of each group of hydrological monitoring data based on the safety impact level of each type of hydrological monitoring data within the group;

[0032] A204. Determine the data security weight of each group of hydrological monitoring data based on the correspondence between the preset security level and the data security weight.

[0033] Preferably, step A203 includes:

[0034] B1. Compare the safety impact levels of various types of hydrological monitoring data with the preset safety impact level thresholds and preliminarily group the hydrological monitoring data;

[0035] B2. Calculate the initial safety level of each group of hydrological monitoring data using a weighted average algorithm based on the data volume and safety impact level of each type of hydrological monitoring data within the group. The greater the data volume, the greater the weight of the corresponding hydrological monitoring data.

[0036] B3. Calculate the level deviation between the safety impact level of each type of hydrological monitoring data within each group of hydrological monitoring data and the corresponding initial safety level. If all level deviations within the group do not exceed the preset deviation threshold, execute step B4 for the corresponding data group. Otherwise, split the corresponding data group into multiple groups of data and execute steps B2 and B3 again for the resulting split data groups.

[0037] B4. Using the initial security level of each set of hydrological monitoring data as the security level of the corresponding data set.

[0038] Preferably, step A3 includes:

[0039] A301. Obtain the transmission delay of the underwater wireless communication link;

[0040] A302. Calculate the degree of congestion of the underwater wireless communication link based on the transmission delay;

[0041] A303. Calculate the bandwidth occupancy weight according to the congestion level.

[0042] Preferably, in step A301, transmission delays of multiple data packets on the underwater wireless communication link are obtained to form a delay sequence;

[0043] Step A302 includes:

[0044] The time delay sequence is smoothed by using a sliding window to obtain a smoothed time delay sequence;

[0045] Calculate the delay jitter and average transmission delay of the smoothed delay sequence;

[0046] The congestion level of the underwater wireless communication link is calculated according to the delay jitter and the average transmission delay.

[0047] Preferably, step A4 includes:

[0048] A401. For each set of hydrological monitoring data, based on the type identifiers of the various types of hydrological monitoring data within the set, select multiple encryption algorithms that are compatible with the set of hydrological monitoring data from a preset encryption algorithm parameter library. The encryption algorithm parameter library stores pre-assessed energy consumption, bandwidth overhead, and security strength parameters for different encryption algorithms.

[0049] A402. For each selected encryption algorithm, calculate the comprehensive performance index value of the corresponding encryption algorithm based on the corresponding energy consumption, bandwidth overhead and security strength parameters, as well as the energy consumption weight, the corresponding data security weight and the bandwidth occupancy weight.

[0050] Preferably, step A6 includes:

[0051] A601. Prioritize each group of hydrological monitoring data units based on security level; data with higher security levels has higher priority.

[0052] A602. Transmit each set of hydrological monitoring data to the shore-based monitoring center via the underwater wireless communication link according to priority, and monitor the packet loss rate of the underwater wireless communication link during the transmission process;

[0053] A603. When it is detected that the packet loss rate exceeds the preset packet loss rate threshold, the transmission of data with a priority not higher than the preset priority threshold is suspended, and data with a priority higher than the preset priority threshold is retransmitted first until the packet loss rate returns to below the preset threshold, and the remaining data is transmitted.

[0054] In a second aspect, the present application provides a data security management device for securely managing hydrological monitoring data collected by underwater sensor nodes when performing underwater pipeline safety monitoring. The device includes:

[0055] The power monitoring module is used to monitor the remaining battery power of the underwater sensor node and determine the energy consumption weight based on the comparison result between the remaining battery power and the preset power threshold;

[0056] A security level determination module is used to group the hydrological monitoring data collected by the underwater sensor nodes and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data;

[0057] A bandwidth evaluation module is used to determine the bandwidth occupancy weight according to the congestion level of the underwater wireless communication environment;

[0058] A performance calculation module is used to calculate the comprehensive performance index values ​​of different encryption algorithms for each set of hydrological monitoring data based on the determined energy consumption weight, the corresponding data security weight, the bandwidth occupancy weight, and the pre-assessed energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms;

[0059] The data encryption module is used to select the encryption algorithm with the best comprehensive performance index value for each set of hydrological monitoring data and encrypt the hydrological monitoring data of this set;

[0060] The data transmission module is used to transmit the encrypted hydrological monitoring data to the shore-based monitoring center through an underwater wireless communication link.

[0061] Beneficial effects: This application provides a data security management method and device. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 Flowchart of the data security management method provided in an embodiment of the present application.

[0063] Figure 2 A schematic diagram of the structure of the data security management device provided in an embodiment of the present application.

[0064] Explanation of reference numerals: 1. Power monitoring module; 2. Security level determination module; 3. Bandwidth evaluation module; 4. Performance calculation module; 5. Data encryption module; 6. Data transmission module. DETAILED DESCRIPTION

[0065] The technical solutions in this application will be clearly and completely described below in conjunction with the drawings in this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. The components of the present application generally described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application for which protection is claimed, but merely represents selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of this application.

[0066] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.

[0067] refer to Figure 1 This application proposes a data security management method for securely managing hydrological monitoring data collected by underwater sensor nodes when performing underwater pipeline safety monitoring. The method comprises the following steps:

[0068] A1. Monitor the remaining battery power of the underwater sensor node and determine the energy consumption weight based on the comparison result between the remaining battery power and the preset power threshold;

[0069] A2. Group the hydrological monitoring data collected by the underwater sensor nodes and determine the data security weight of each group of hydrological monitoring data based on its security level;

[0070] A3. Determine bandwidth occupancy weights based on the congestion level of the underwater wireless communication environment;

[0071] A4. For each set of hydrological monitoring data, calculate the comprehensive performance index values ​​of different encryption algorithms based on the determined energy consumption weight, the corresponding data security weight, the bandwidth usage weight, and the pre-assessed energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms;

[0072] A5. For each set of hydrological monitoring data, select the encryption algorithm with the best comprehensive performance index value and encrypt the hydrological monitoring data;

[0073] A6. Transmit the encrypted hydrological monitoring data to the shore-based monitoring center via an underwater wireless communication link.

[0074] Among them, in step A1, the energy consumption weight is used to characterize the sensitivity of the system to energy consumption. Specifically, it can be achieved in the following way: pre-set a high power threshold and a low power threshold. When the remaining battery power is higher than the high power threshold, it indicates that the battery power is sufficient. At this time, the energy consumption weight can be set to a smaller value, such as 0.2, to reduce the degree of consideration of energy consumption. When the remaining battery power is lower than the low power threshold, it indicates that the battery power is insufficient. At this time, the energy consumption weight can be set to a larger value, such as 0.8, to increase the degree of consideration of energy consumption. When the remaining battery power is between the high power threshold and the low power threshold, the energy consumption weight can be calculated according to a linear function so that the energy consumption weight varies smoothly between 0.2 and 0.8. In this way, the energy consumption weight can be dynamically adjusted according to different levels of remaining battery power to achieve adaptive management of energy consumption.

[0075] Among them, in step A2, the data security weight is used to characterize the degree of attention the system pays to data security. Specifically, it can be achieved in the following ways: First, the hydrological monitoring data is grouped, for example, the hydrological monitoring data is divided into important data and non-important data. Then, different security levels are assigned to different groups of data. For example, the security level of important data is higher than that of non-important data. Then, the data security weight of each group of hydrological monitoring data is determined according to the correspondence between the preset security level and the data security weight. For example, the higher the security level of the data group, the higher its data security weight. For example, the data security weight of the data group with high, medium and low security levels can be set to 0.8, 0.5 and 0.2 respectively. In this way, the data security weight can be dynamically adjusted according to the different data security levels to achieve differentiated data security management.

[0076] Among them, in step A3, the bandwidth occupancy weight is used to characterize the system's sensitivity to bandwidth occupancy. Specifically, it can be achieved in the following way: real-time monitoring of the transmission delay of the underwater wireless communication link. When the transmission delay is high, it indicates that the underwater wireless communication environment is relatively congested. At this time, the bandwidth occupancy weight can be set to a larger value, such as 0.7, to increase the degree of consideration of bandwidth occupancy. When the transmission delay is low, it indicates that the underwater wireless communication environment is relatively smooth. At this time, the bandwidth occupancy weight can be set to a smaller value, such as 0.3, to reduce the degree of consideration of bandwidth occupancy. In this way, the bandwidth occupancy weight can be dynamically adjusted according to the congestion level of the underwater wireless communication environment to achieve adaptive management of bandwidth occupancy.

[0077] Among them, in step A4, the comprehensive performance index value is used to evaluate the comprehensive performance of different encryption algorithms in the current environment. Specifically, it can be achieved in the following way: pre-evaluate the energy consumption, bandwidth overhead and security strength parameters of multiple encryption algorithms, and store these parameters in the encryption algorithm parameter library. For each set of hydrological monitoring data, select a variety of available encryption algorithms from the encryption algorithm parameter library. Then, for each encryption algorithm, calculate its comprehensive performance index value according to the formula. For example, the comprehensive performance index value can be defined as the product of the data security weight and the security strength parameter, divided by the product of the energy consumption weight and the energy consumption parameter, and then divided by the product of the bandwidth occupancy weight and the bandwidth overhead parameter. At this time, the larger the comprehensive performance index value, the better. In this way, multiple factors such as energy consumption, data security and bandwidth occupancy can be comprehensively considered to quantitatively evaluate the performance of different encryption algorithms.

[0078] In step A5, the optimal comprehensive performance index value refers to the value at which the comprehensive performance index reaches the optimal level according to the preset optimization goal. Specifically, if the optimization goal is to maximize the comprehensive performance index value (corresponding to the case where a larger comprehensive performance index value is better), the encryption algorithm with the largest comprehensive performance index value is selected. If the optimization goal is to minimize the comprehensive performance index value (corresponding to the case where a smaller comprehensive performance index value is better), the encryption algorithm with the smallest comprehensive performance index value is selected. In this way, the most appropriate encryption algorithm can be adaptively selected based on the evaluation results of the comprehensive performance index value, thereby achieving dynamic adjustment of the data encryption strategy.

[0079] In step A6, the underwater sensor node transmits the encrypted hydrological monitoring data as acoustic signals to an underwater wireless communication link via underwater wireless communication equipment such as an underwater acoustic modem. The underwater wireless communication link then transmits the received acoustic signals to a shore-based monitoring center. The shore-based monitoring center receives the data transmitted by the underwater wireless communication link using equipment such as an underwater acoustic modem, decrypts it, and processes the data, enabling remote safety monitoring of underwater pipelines. This ensures secure and reliable transmission of hydrological monitoring data, providing data assurance for underwater pipeline safety monitoring.

[0080] Specifically, the data security management method proposed in this application first obtains the energy consumption weight, data security weight and bandwidth occupancy weight through steps A1, A2 and A3 respectively. These three weights reflect the energy status of the current underwater sensor node, the data security requirements and the congestion level of the underwater wireless communication environment respectively. Then, in step A4, for each set of hydrological monitoring data, the three weights and the performance parameters of different encryption algorithms are comprehensively considered to calculate the comprehensive performance index values ​​of different encryption algorithms. This comprehensive performance index value can quantitatively reflect the comprehensive performance of each encryption algorithm in the current environment. Then, in step A5, the encryption algorithm with the best comprehensive performance index value is selected to encrypt the data, which means that the system will adaptively select the most appropriate encryption algorithm under the current conditions to achieve the best balance between data security, energy consumption and bandwidth occupancy. Finally, in step A6, the encrypted data is transmitted to the shore-based monitoring center to complete the secure transmission of the data.

[0081] Through the above technical solution, the present application can dynamically adjust the data encryption strategy according to the energy status of the underwater sensor node, the data security requirements and the congestion level of the underwater wireless communication environment. On the premise of ensuring the wireless transmission security of underwater pipeline monitoring data, it takes into account the low power consumption and long life operation of the sensor nodes, and ultimately achieves differentiated data security protection, effectively solving the problems of resource waste and insufficient security protection in the existing technology, and providing a more efficient and reliable data security protection solution for underwater pipeline safety monitoring applications.

[0082] In some preferred embodiments, step A1 includes:

[0083] A101. Collect the battery voltage value of the underwater sensor node in real time and convert the battery voltage value into a percentage of the remaining battery power;

[0084] A102. Compare the remaining battery power percentage with a preset high power threshold and a low power threshold; wherein the high power threshold is greater than the low power threshold;

[0085] A103. If the remaining battery power percentage is greater than the high power threshold, the energy consumption weight is set to a first preset value;

[0086] A104. If the remaining battery power percentage is less than the low power threshold, the energy consumption weight is set to a second preset value;

[0087] A105. If the remaining battery power percentage is between a high power threshold and a low power threshold, calculate the energy consumption weight according to a linear function so that the energy consumption weight is between a first preset value and a second preset value.

[0088] In step A101, the underwater sensor node is equipped with a voltage sensor for real-time monitoring of the voltage across the battery. The analog voltage signal collected by the voltage sensor is converted into a digital signal by an analog-to-digital converter, which represents the current battery voltage. To convert the voltage value into a more intuitive percentage of remaining battery charge, a mapping relationship between battery voltage and remaining charge can be pre-established. This mapping relationship can be nonlinear, such as obtained by fitting experimental data, or it can use a linear approximation within a certain voltage range. The conversion process uses a preset voltage-to-charge percentage conversion model or lookup table to convert the collected battery voltage value into the corresponding remaining battery charge percentage.

[0089] In step A102, the high battery threshold and the low battery threshold are two pre-set battery percentage values, for example, the high battery threshold is set to 80% and the low battery threshold is set to 20%. These two thresholds are used to divide the battery power into different state intervals.

[0090] In steps A103 and A104, the first preset value and the second preset value are two pre-set energy consumption weight values. The first preset value corresponds to a sufficient battery level and can be set to a smaller value, such as 0.3, indicating that the focus on energy consumption is low at this time. The second preset value corresponds to a low battery level and can be set to a larger value, such as 0.8, indicating that the focus on energy consumption is high at this time.

[0091] Among them, in step A105, a linear function is used to smoothly calculate the energy consumption weight when the battery remaining power percentage is between a high power threshold and a low power threshold. The linear function ensures that the energy consumption weight increases smoothly as the battery power decreases, avoiding sudden changes in the weight value. For example, the linear function can be expressed as: w = (w1-w2)*(Q-Q2) / (Q1-Q2)+w2, where w is the energy consumption weight, Q is the battery remaining power percentage, w1 is the first preset value, w2 is the second preset value, Q1 is the high power threshold, and Q2 is the low power threshold.

[0092] Specifically, through the above steps, the energy consumption weight can be finely adjusted according to the remaining battery power. When the battery power is sufficient, the energy consumption weight is set to a lower first preset value, indicating that the system can relatively tolerate higher energy consumption at this time, so that an encryption algorithm with higher security strength can be selected to ensure data security. As the battery power gradually decreases, when the battery power percentage is between the high power threshold and the low power threshold, the energy consumption weight gradually increases through a linear function, reflecting that the system's attention to energy consumption is gradually increasing. When the battery power is lower than the low power threshold, the energy consumption weight is set to a higher second preset value, indicating that the system is highly sensitive to energy consumption at this time, and will tend to select an encryption algorithm with lower energy consumption but moderate security strength to extend the working time of the node. As a result, the energy consumption weight can be adaptively adjusted according to the remaining battery power status, providing an important energy consumption reference basis for the subsequent selection of data encryption algorithms, and realizing data security management optimization in energy-constrained scenarios.

[0093] In some possible implementations, step A101 includes:

[0094] The sliding average filtering algorithm is used to smooth the battery voltage value of the underwater sensor node collected in real time to obtain the filtered battery voltage value;

[0095] Calculate the voltage change rate based on the filtered battery voltage value;

[0096] Evaluate the battery health status based on the filtered battery voltage value and the voltage change rate curve to obtain a health status evaluation value;

[0097] The filtered battery voltage value at the current moment is corrected according to the health status evaluation value, and the corrected battery voltage value is converted into a percentage of the remaining battery power.

[0098] A sliding average filter algorithm is used to smooth the battery voltage values ​​collected in real time from underwater sensor nodes to reduce the impact of noise on the voltage values. This can be done using a fixed-length sliding window, such as five sampling points, or a variable-length sliding window whose length can be adaptively adjusted based on the noise level. The sliding average filter algorithm calculates the average voltage value within the window to smooth the voltage signal, filter out high-frequency noise components, and obtain a relatively stable filtered voltage value, providing a more reliable data foundation for subsequent calculations.

[0099] Calculating the voltage change rate based on the filtered battery voltage value is intended to understand the changing trend of the battery voltage over time. Specifically, the voltage change rate can be calculated using the first-order difference method: subtract the filtered voltage value at the previous moment from the current moment, and divide the result by the time interval to obtain the voltage change rate. The voltage change rate can be expressed in millivolts per second (mV / s). The voltage change rate reflects the battery's discharge rate and provides a reference for battery health assessment.

[0100] Among them, evaluating the battery health status based on the filtered battery voltage value and the voltage change rate change curve to obtain the health status assessment value means comprehensively considering the current level of the battery voltage and the speed of voltage change over time to judge the health status of the battery. Specifically, this can be achieved by constructing a battery health status assessment model. For example, the voltage and voltage change rate data of the battery under different health states can be collected in advance, and a mapping relationship between the battery health status and the voltage and voltage change rate can be established to obtain the health status assessment model. The assessment model can be a multivariate regression model or a neural network model. The health status assessment value can be a value between 0 and 1, and the higher the value, the better the battery health status.

[0101] Among them, correcting the filtered battery voltage value at the current moment according to the health status assessment value and converting the corrected battery voltage value into the battery remaining power percentage means using the battery health status assessment result to correct the current voltage value to improve the accuracy of converting the voltage value into the battery remaining power percentage. Specifically, the following correction method can be adopted: when the battery health status assessment value is smaller, it indicates that the battery is aged or the performance degradation is higher. At this time, the actual remaining power of the battery is more likely to be lower than the power percentage directly converted from the voltage value, so the voltage value needs to be corrected downward. For example, the voltage value can be corrected by the following formula: V_c = V_f*(1-k*(1-H)), where V_c represents the corrected battery voltage value, V_f represents the filtered battery voltage value, k is the correction coefficient, for example, 0.1, and H is the health status assessment value.

[0102] The corrected battery voltage is then converted to a voltage-to-capacity percentage using a conversion model or lookup table to determine the remaining battery capacity. The voltage-to-capacity percentage conversion model can be a linear model or a nonlinear model, such as a piecewise linear model or a curve fitting model.

[0103] Specifically, during the hydrological monitoring data collection process at the underwater sensor node, step A101 first collects the battery voltage value in real time. Due to the complex underwater environment, the voltage collection process is susceptible to noise interference, and directly using the raw voltage value for battery charge estimation may be inaccurate. Therefore, a sliding average filtering algorithm is used to smooth the raw voltage value, eliminating random noise in the voltage signal and obtaining a smooth filtered voltage value. The voltage change rate of the filtered voltage value is then calculated to reflect the battery's discharge rate and health status. Combining the filtered voltage value and the voltage change rate, a pre-established battery health assessment model is used to comprehensively assess the battery's health status, resulting in a health assessment value. The health assessment value can be used to represent the battery's actual performance level. Furthermore, the health assessment value is used to correct the filtered voltage value at the current moment. This correction process takes the battery's health into account, ensuring that the voltage value more accurately reflects the battery's actual remaining charge. Finally, the corrected voltage value is converted into a percentage of the remaining battery charge, resulting in the final remaining battery charge assessment result. Through these technical approaches, more accurate and reliable battery remaining charge information can be obtained. This precise power assessment result can provide a more reliable basis for the subsequent determination of energy consumption weights and the reasonable selection of encryption algorithms, thereby improving the effectiveness and reliability of the entire data security management method.

[0104] Through the above technical solution, this application can more accurately and reliably assess the remaining battery power of underwater sensor nodes. Sliding average filtering effectively eliminates voltage noise interference and ensures the stability of voltage data. The voltage change rate and battery health status assessment comprehensively reflect the health of the battery. Correcting the voltage using the health status assessment value further improves the accuracy of the voltage value and even the final battery percentage. This can provide a more reliable basis for determining the subsequent energy consumption weight and selecting the encryption algorithm, thereby improving the overall performance of the data security management method.

[0105] In some embodiments, step A2 comprises:

[0106] A201. Extract metadata of hydrological monitoring data collected by underwater sensor nodes, where the metadata includes a data type identifier;

[0107] A202. Query and obtain the safety impact level of various types of hydrological monitoring data based on the data type identifier;

[0108] A203. Group various types of hydrological monitoring data according to their safety impact levels, and calculate the safety level of each group of hydrological monitoring data based on the safety impact levels of each type of hydrological monitoring data within the group.

[0109] A204. Determine the data security weight of each group of hydrological monitoring data based on the correspondence between the preset security level and the data security weight.

[0110] In step A201, the metadata may be included in the header of the data packet. The data type identifier is key information in the metadata and is used to distinguish different hydrological monitoring data types. For example, the data type identifier may be in the form of a digital code or a string.

[0111] In step A202, the safety impact level of each type of hydrological monitoring data is obtained by querying a preset safety level database or lookup table. The safety level database or lookup table stores a mapping relationship between various data type identifiers and corresponding safety impact levels. The safety impact levels can be predefined as high, medium, and low, or quantified using numerical values.

[0112] In step A203, the various types of hydrological monitoring data are grouped based on the safety impact levels obtained in step A202. The grouping principle can be based on the similarity of safety impact levels; for example, data with similar safety impact levels are grouped together. After the data are grouped, the safety levels of the various types of hydrological monitoring data within the group are calculated. In one embodiment, the group safety level can be set to the highest safety impact level within the group, or calculated by calculating the weighted average of the safety impact levels of the various types of data within the group.

[0113] In step A204, the data security weight of each group of hydrological monitoring data is determined based on a preset relationship between security levels and data security weights. The preset relationship can be a linear function, a nonlinear function, a piecewise function, or a mapping relationship. Data groups with higher security levels are assigned higher data security weights.

[0114] Specifically, step A2 aims to solve the problem of distinguishing and reasonably grouping the security levels of different types of hydrological monitoring data. In underwater pipeline safety monitoring applications, different types of hydrological data, such as water temperature, water pressure, stress, corrosion rate, etc., have different security sensitivities. By extracting the data type identifier through step A201, the identification of different types of hydrological data is realized. Step A202 queries the security impact level based on the data type identifier, providing a level standard for subsequent data grouping and differentiated security management. Step A203 performs data grouping according to the security impact level, so that data with similar security levels are aggregated together, which facilitates the subsequent formulation of a unified security policy for the data group. Step A204 converts the abstract security level into a quantifiable data security weight, providing a quantitative basis for the subsequent calculation of comprehensive performance indicators and the selection of encryption algorithms. Therefore, through steps A201 to A204, a set of data security level division and weight determination methods are established, which realizes the differentiated management of hydrological monitoring data with different security sensitivities and provides a data basis for the subsequent adoption of differentiated data security management strategies.

[0115] In some preferred embodiments, step A203 includes:

[0116] B1. Compare the safety impact levels of various types of hydrological monitoring data with the preset safety impact level thresholds and preliminarily group the hydrological monitoring data;

[0117] B2. Calculate the initial safety level of each group of hydrological monitoring data using a weighted average algorithm based on the data volume and safety impact level of each type of hydrological monitoring data within the group. The greater the data volume, the greater the weight of the corresponding hydrological monitoring data.

[0118] B3. Calculate the level deviation between the safety impact level of each type of hydrological monitoring data within each group and the corresponding initial safety level. If all level deviations within the group do not exceed the preset deviation threshold, execute step B4 for the corresponding data group. Otherwise, split the corresponding data group into multiple groups and execute steps B2 and B3 again for the resulting split data groups.

[0119] B4. The initial safety level of each set of hydrological monitoring data shall be used as the safety level of the corresponding data group.

[0120] Among them, in step B1, the set safety impact level threshold can be used as a division standard to divide the hydrological monitoring data with a safety impact level higher than the safety impact level threshold into one group, and the hydrological monitoring data with a safety impact level lower than or equal to the safety impact level threshold into another group, thereby realizing the preliminary grouping of the hydrological monitoring data.

[0121] In step B2, hydrological monitoring data with larger volumes of data are given greater weight when calculating the group's safety level. Conversely, data with smaller volumes of data are given less weight. This weighted average approach more accurately reflects the overall safety status of the data group. For example, if a group of data contains a large amount of data with a high safety impact level, then the initial safety level of the group will also be higher, and vice versa.

[0122] Among them, in step B3, after obtaining the initial safety level of each group of hydrological monitoring data, the rationality of the grouping and the uniformity of the safety level within the group are further evaluated. The specific method is to calculate the deviation between the safety impact level of each type of hydrological monitoring data in the group and the initial safety level of the group. If the level deviation of all data in a group is controlled within the preset deviation threshold, then the grouping is considered reasonable and the subsequent step B4 can be executed; on the contrary, if there is data in the group whose level deviation exceeds the threshold, it indicates that the grouping is not fine enough and the group of data needs to be further split into multiple groups, and steps B2 and B3 are re-executed for the split groups. Through iterative optimization, the rationality of the grouping and the uniformity of the safety level within the group are ensured. When splitting, the data group can be sorted according to the safety impact level and then divided into two groups according to the number of categories of the hydrological monitoring data in the group. If the number of categories is an even number, it is divided into two groups. If the number of categories is an odd number, one group after division has one more category than the other group.

[0123] Step B4 involves determining the initial security level for each data group after the deviation verification and iterative optimization in step B3, and using this initial security level as the final security level for that data group. This means that each data group receives a security level score that comprehensively reflects the data security status within the group, providing a quantitative basis for the formulation of subsequent data security management strategies.

[0124] Furthermore, in step B1, the safety impact level of each type of hydrological monitoring data is compared with the preset safety impact level threshold, achieving a preliminary data division based on the safety impact level, laying the foundation for the subsequent refined safety level calculation. In step B2, the solution does not simply average the safety levels of each type of data. Instead, it introduces a weighted average algorithm and takes into account the data volume. The larger the data volume, the greater the weight, which is more in line with actual application scenarios. Because data types with large data volumes often have a greater impact on overall safety, this weighted average method can more accurately reflect the overall security situation of the data group. In step B3, a level deviation verification mechanism is introduced. By calculating the deviation between the safety impact level of each type of data in the group and the initial safety level and setting a deviation threshold, if the deviation is too large, it indicates that the grouping may not be reasonable and the data group needs to be further split and the weighted average calculation and deviation verification need to be re-performed. This iterative optimization process can effectively improve the accuracy of the grouping and the uniformity of the safety level within the group. In step B4, the verified initial security level is used as the final data group security level, which ensures the accuracy and reliability of the security level determination, provides strong support for the subsequent data security management strategy based on the security level, and makes data security management more refined and effective. The above steps B1 to B4 are in a progressive relationship. Step B1 is the preliminary grouping, step B2 calculates the initial security level based on the preliminary grouping, step B3 performs deviation verification and grouping optimization on the initial security level, and step B4 obtains the final security level. Through the above steps, the accurate calculation and reasonable grouping of the security level of hydrological monitoring data are achieved, providing a more reliable basis for the subsequent differentiated data security management strategy.

[0125] Through the above technical solution, the present application can more accurately determine the security level of each group of hydrological monitoring data, fully consider the differences in data volume and security impact level of different types of data, avoid the security level deviation problem that may be caused by simple average calculation, ensure the rationality of grouping and the uniformity of security levels within the group, and provide a more reliable and refined security level basis for the formulation of subsequent data security strategies, so that more targeted security management measures can be taken for data groups with different security levels.

[0126] In some embodiments, step A3 comprises:

[0127] A301. Obtain the transmission delay of the underwater wireless communication link;

[0128] A302. Calculate the congestion level of the underwater wireless communication link based on the transmission delay;

[0129] A303. Calculate the bandwidth occupancy weight based on the congestion level.

[0130] In step A301, the transmission delay can be obtained by recording the sending timestamp of a data packet sent from the underwater sensor node to the shore-based monitoring center. When the shore-based monitoring center receives the data packet, it records the receiving timestamp and returns it to the underwater sensor node. The transmission delay of the data packet is calculated by taking the difference between the receiving and sending timestamps. Furthermore, to improve the accuracy of delay measurement, multiple measurements can be averaged, or a filtering algorithm such as a Kalman filter can be used to smooth the delay measurement to reduce noise interference.

[0131] In step A302, the calculation of the degree of congestion can be implemented as follows: first, a benchmark transmission delay is set, which can be a measured value of the transmission delay when the underwater wireless communication link is in an idle state, or a preset empirical value. Then, the current transmission delay obtained in step A301 is compared with the benchmark transmission delay. If the current transmission delay is significantly higher than the benchmark transmission delay, it is determined that the underwater wireless communication link is in a congested state, and the degree of congestion is positively correlated with the degree to which the current transmission delay exceeds the benchmark transmission delay. Specifically, the degree of congestion can be quantified as a congestion factor, which can be obtained by normalizing the ratio or difference between the current transmission delay and the benchmark transmission delay.

[0132] In step A303, the bandwidth occupancy weight can be calculated by using a linear function, a nonlinear function, or a table lookup to determine the bandwidth occupancy weight based on the congestion level obtained in step A302. In a preferred embodiment, when the congestion level is high, the bandwidth occupancy weight is set to a higher value, indicating that bandwidth resources are more scarce and important than energy resources. When the congestion level is low, the bandwidth occupancy weight is set to a lower value, indicating that bandwidth resources can be given less consideration.

[0133] Specifically, this solution defines a specific calculation method for the bandwidth occupancy weight through the above steps. Through this method, the bandwidth occupancy weight can be dynamically adjusted according to the actual congestion status of the underwater wireless communication link, thereby affecting the selection of the encryption algorithm, so that the data security management method can better adapt to changes in the underwater wireless communication environment.

[0134] In some possible implementations, in step A301, transmission delays of multiple data packets on an underwater wireless communication link are obtained to form a delay sequence;

[0135] Step A302 includes:

[0136] The time delay sequence is smoothed by using a sliding window to obtain a smoothed time delay sequence;

[0137] Calculate the delay jitter and average transmission delay of the smoothed delay sequence;

[0138] The congestion level of underwater wireless communication links is calculated based on delay jitter and average transmission delay.

[0139] In step A301, the transmission delays of multiple data packets can be acquired by the underwater sensor node recording the transmission timestamp when sending a data packet and the reception timestamp when receiving confirmation information returned by the shore-based monitoring center. Thus, the transmission delay of each data packet can be calculated as the difference between the reception timestamp and the transmission timestamp. Furthermore, to form a delay sequence, the transmission delays of a predetermined number of data packets can be continuously acquired. For example, the sliding window size can be set to 10, meaning that a delay sequence is acquired every ten data packets.

[0140] In step A302, the sliding window smoothing process can specifically be to average the delay sequence data in the sliding window and use the average value as the smoothed delay value, thereby obtaining a smoothed delay sequence. The delay jitter can be calculated as the standard deviation of the delay values ​​in the smoothed delay sequence, reflecting the degree of delay fluctuation. The average transmission delay can be directly obtained by calculating the average value of all delay values ​​in the smoothed delay sequence, reflecting the average delay level of the link. The calculation of the congestion level can be implemented as a weighted sum of the delay jitter and the average transmission delay. The weight coefficient can be adjusted according to the actual application scenario and empirical data. For example, the weights of the delay jitter and the average transmission delay can be set equal, or according to the characteristics of the underwater environment, the delay jitter can be given a higher weight to more sensitively reflect the congestion changes of the link.

[0141] Specifically, the introduction of delay sequences overcomes the random errors inherent in single delay data, making congestion assessments more comprehensive. The use of sliding window smoothing effectively eliminates noise and mutations in delay sequences, extracting stable delay trends and ensuring the reliability of congestion assessments. The calculation of delay jitter and average transmission delay comprehensively characterizes the congestion state of underwater wireless communication links. Delay jitter reflects network instability, while average transmission delay reflects the average delay level. Their combined use makes congestion assessments more accurate. Ultimately, accurate congestion assessments provide a reliable basis for the subsequent calculation of bandwidth occupancy weights, thereby optimizing the overall performance of data security management methods, ensuring low power consumption and long lifespan for sensor nodes while ensuring data security.

[0142] In some embodiments, step A4 comprises:

[0143] A401. For each set of hydrological monitoring data, based on the type identifiers of the various types of hydrological monitoring data within the set, select multiple encryption algorithms that are compatible with the set of hydrological monitoring data from a preset encryption algorithm parameter library. The encryption algorithm parameter library stores pre-assessed energy consumption, bandwidth overhead, and security strength parameters for different encryption algorithms.

[0144] A402. For each selected encryption algorithm, calculate the comprehensive performance index value of the corresponding encryption algorithm based on the corresponding energy consumption, bandwidth overhead and security strength parameters, as well as the energy consumption weight, the corresponding data security weight and bandwidth occupancy weight.

[0145] Among them, in step A401, the preset encryption algorithm parameter library is used to store parameters of multiple encryption algorithms, and the parameters include at least energy consumption, bandwidth overhead and security strength. For each set of hydrological monitoring data, the data type is first identified, and the type identifier is used to retrieve and filter out the adapted encryption algorithm from the encryption algorithm parameter library. For example, if the hydrological monitoring data contains types such as temperature and salinity, the filtered encryption algorithm needs to be able to effectively process these types of data. The data types that each encryption algorithm can effectively process can be recorded in the encryption algorithm parameter library in advance in the form of an encryption algorithm capability query table, so that the corresponding encryption algorithm can be filtered out by querying the query table. By filtering by type identifier, the selection range of the encryption algorithm can be narrowed down, and the efficiency and accuracy of subsequent performance evaluation can be improved.

[0146] Among them, in step A402, for each encryption algorithm screened out, the calculation of the comprehensive performance index value is performed. The calculation process comprehensively considers the energy consumption parameters, bandwidth overhead parameters and security strength parameters of the encryption algorithm, and combines the energy consumption weight, data security weight and bandwidth occupancy weight determined in the previous step. The role of the weight here is to adjust the relative importance of the three factors of energy consumption, data security and bandwidth occupancy in the comprehensive performance evaluation. For example, when the battery power is low, the energy consumption weight can be set higher, so that when selecting an encryption algorithm, algorithms with lower energy consumption are given priority. Through the calculation of the comprehensive performance index value, the comprehensive performance of each encryption algorithm can be quantified, providing a numerical basis for the subsequent selection of the optimal encryption algorithm.

[0147] Specifically, step A401 performs a preliminary screening of encryption algorithms to ensure that the encryption algorithms subsequently evaluated and selected match the current monitoring data type. This avoids invalid evaluations of inappropriate algorithms and improves the efficiency of algorithm selection. Based on the screening in step A401, step A402 calculates comprehensive performance index values ​​to achieve a quantitative performance evaluation of multiple adaptive encryption algorithms. The calculation of comprehensive performance index values ​​comprehensively considers energy consumption, bandwidth overhead, and security strength, and adjusts the influence of each factor through weights, so that the selection of algorithms can better adapt to the needs of the actual application environment. For example, in energy-limited or bandwidth-limited scenarios, the weights can be adjusted so that the algorithm selection focuses more on low power consumption or low bandwidth overhead. Therefore, through the screening in step A401 and the index value calculation in step A402, the encryption algorithm with the best comprehensive performance can be selected for each set of hydrological monitoring data, thereby taking into account the energy efficiency and bandwidth utilization of underwater sensor nodes while ensuring data security.

[0148] In some embodiments, step A6 includes:

[0149] A601. Prioritize each group of hydrological monitoring data units based on security level; data with higher security levels has higher priority.

[0150] A602. Transmit each set of hydrological monitoring data to the shore-based monitoring center via the underwater wireless communication link according to priority, and monitor the packet loss rate of the underwater wireless communication link during the transmission process;

[0151] A603. When it is detected that the packet loss rate exceeds the preset packet loss rate threshold, the transmission of data with a priority not higher than the preset priority threshold is suspended, and data with a priority higher than the preset priority threshold is retransmitted first until the packet loss rate returns to below the preset threshold, and the remaining data is transmitted.

[0152] Among them, in step A601, priority allocation operation is performed for hydrological monitoring data of different security levels. Data with a high security level is assigned a higher transmission priority, and data with a low security level is assigned a lower transmission priority, thereby ensuring that important data enjoys priority during the transmission process.

[0153] In step A602, the data is transmitted to the shore-based monitoring center through the underwater wireless communication link according to the priority order determined in step A601. During the data transmission process, the packet loss rate of the underwater wireless communication link is continuously monitored for real-time evaluation of the channel quality.

[0154] Among them, in step A603, when the monitored packet loss rate exceeds the preset packet loss rate threshold, the system determines that the quality of the current underwater wireless communication link has deteriorated. At this time, the data transmission operation is adjusted, and the transmission of data with a priority not higher than the preset priority threshold is suspended. Instead, data with a priority higher than the preset priority threshold is prioritized and retransmitted, thereby ensuring the reliability of high-security level data transmission. Until the monitored packet loss rate returns to below the preset threshold, indicating that the channel quality has improved, the system resumes transmission of the low-priority data that was previously suspended.

[0155] Specifically, hydrological monitoring data of different security levels is prioritized. During the data transmission phase, the system transmits high-priority data first, followed by low-priority data. During data transmission, the packet loss rate monitoring module monitors packet loss in the underwater wireless communication link in real time. For example, the packet loss rate is calculated by counting the difference between the total number of transmitted packets and the total number of received acknowledgment packets. A preset packet loss rate threshold, such as 10%, is pre-set, as is a preset priority threshold, such as medium priority. When the monitored packet loss rate exceeds 10%, the system determines that channel quality has degraded and immediately suspends transmission of low-priority data, prioritizing retransmission of high- and medium-priority data to ensure that high-security data reaches the shore-based monitoring center first. When the packet loss rate returns to below 10%, the system resumes transmission of the previously suspended low-priority data. This priority scheduling and packet loss rate monitoring mechanism effectively ensures the transmission reliability of high-security data despite fluctuations in underwater wireless communication link quality.

[0156] refer to Figure 2 The present application provides a data security management device for securely managing hydrological monitoring data collected by underwater sensor nodes when performing underwater pipeline safety monitoring. The device includes:

[0157] The power monitoring module 1 is used to monitor the remaining battery power of the underwater sensor node and determine the energy consumption weight based on the comparison result of the remaining battery power and the preset power threshold (the specific process refers to step A1 above);

[0158] Security level determination module 2 is used to group the hydrological monitoring data collected by the underwater sensor nodes and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data (refer to step A2 above for the specific process);

[0159] Bandwidth evaluation module 3, used to determine the bandwidth occupancy weight according to the congestion level of the underwater wireless communication environment (for the specific process, refer to step A3 above);

[0160] Performance calculation module 4 is used to calculate the comprehensive performance index values ​​of different encryption algorithms for each set of hydrological monitoring data based on the determined energy consumption weight, the corresponding data security weight, the bandwidth occupancy weight, and the pre-assessed energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms (for the specific process, refer to step A4 above);

[0161] Data encryption module 5 is used to select the encryption algorithm with the best comprehensive performance index value for each set of hydrological monitoring data and encrypt the hydrological monitoring data (for the specific process, refer to step A5 above);

[0162] The data transmission module 6 is used to transmit the encrypted hydrological monitoring data to the shore-based monitoring center via an underwater wireless communication link (for the specific process, please refer to step A6 above).

[0163] In the embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interface, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0164] In addition, the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, and may be located in one place or distributed across multiple network units. Some or all of these units may be selected based on actual needs to achieve the purpose of the solution of this embodiment.

[0165] Furthermore, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0166] In this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any actual relationship or order between these entities or operations.

[0167] The above description is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, various modifications and variations of the present application are possible. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A data security management method for securely managing hydrological monitoring data collected by underwater sensor nodes when performing underwater pipeline safety monitoring, characterized in that: The steps of the method include: A1. Monitor the remaining battery power of the underwater sensor node and determine the energy consumption weight based on the comparison result between the remaining battery power and the preset power threshold; A2. Group the hydrological monitoring data collected by the underwater sensor nodes and determine the data security weight of each group of hydrological monitoring data based on its security level; A3. Determine bandwidth occupancy weights based on the congestion level of the underwater wireless communication environment; A4. For each set of hydrological monitoring data, calculate the comprehensive performance index values ​​of different encryption algorithms based on the determined energy consumption weight, the corresponding data security weight, the bandwidth usage weight, and the pre-assessed energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms; A5. For each set of hydrological monitoring data, select the encryption algorithm with the best comprehensive performance index value and encrypt the hydrological monitoring data; A6. Transmit the encrypted hydrological monitoring data to a shore-based monitoring center via an underwater wireless communication link; Step A2 includes: A201 extracts metadata of hydrological monitoring data collected by underwater sensor nodes, the metadata including a data type identifier; A202. Based on the data type identifier, query and obtain the safety impact level of various types of hydrological monitoring data; A203. Group various types of hydrological monitoring data according to the safety impact level, and calculate the safety level of each group of hydrological monitoring data based on the safety impact level of each type of hydrological monitoring data within the group; A204. Determine the data security weight for each group of hydrological monitoring data based on the correspondence between the preset security level and the data security weight; Step A203 includes: B1. Compare the safety impact levels of various types of hydrological monitoring data with the preset safety impact level thresholds and preliminarily group the hydrological monitoring data; B2. Calculate the initial safety level of each group of hydrological monitoring data using a weighted average algorithm based on the data volume and safety impact level of each type of hydrological monitoring data within the group. The greater the data volume, the greater the weight of the corresponding hydrological monitoring data. B3. Calculate the level deviation between the safety impact level of each type of hydrological monitoring data within each group of hydrological monitoring data and the corresponding initial safety level. If all level deviations within the group do not exceed the preset deviation threshold, execute step B4 for the corresponding data group. Otherwise, split the corresponding data group into multiple groups of data and execute steps B2 and B3 again for the resulting split data groups. B4. Using the initial security level of each set of hydrological monitoring data as the security level of the corresponding data set.

2. A data security management method according to claim 1, characterized in that: Step A1 includes: A101. Collect the battery voltage value of the underwater sensor node in real time and convert the battery voltage value into a percentage of the remaining battery power; A102. Compare the remaining battery power percentage with a preset high power threshold and a low power threshold; wherein the high power threshold is greater than the low power threshold; A103. If the remaining battery power percentage is greater than the high power threshold, the energy consumption weight is set to a first preset value; A104. If the remaining battery power percentage is less than the low power threshold, the energy consumption weight is set to a second preset value; A105. If the remaining battery power percentage is between a high power threshold and a low power threshold, calculate the energy consumption weight according to a linear function so that the energy consumption weight is between a first preset value and a second preset value.

3. A data security management method according to claim 2, characterized in that: Step A101 includes: The sliding average filtering algorithm is used to smooth the battery voltage value of the underwater sensor node collected in real time to obtain the filtered battery voltage value; Calculate the voltage change rate based on the filtered battery voltage value; Evaluate the battery health status based on the filtered battery voltage value and the voltage change rate curve to obtain a health status evaluation value; The filtered battery voltage value at the current moment is corrected according to the health status evaluation value, and the corrected battery voltage value is converted into a percentage of the remaining battery power.

4. A data security management method according to claim 1, characterized in that: Step A3 includes: A301. Obtain the transmission delay of the underwater wireless communication link; A302. Calculate the degree of congestion of the underwater wireless communication link based on the transmission delay; A303. Calculate the bandwidth occupancy weight according to the congestion level.

5. A data security management method according to claim 4, characterized in that: In step A301, the transmission delays of multiple data packets on the underwater wireless communication link are obtained to form a delay sequence; Step A302 includes: The time delay sequence is smoothed by using a sliding window to obtain a smoothed time delay sequence; Calculate the delay jitter and average transmission delay of the smoothed delay sequence; The congestion level of the underwater wireless communication link is calculated according to the delay jitter and the average transmission delay.

6. A data security management method according to claim 1, characterized in that: Step A4 includes: A401. For each set of hydrological monitoring data, based on the type identifiers of the various types of hydrological monitoring data within the set, select multiple encryption algorithms that are compatible with the set of hydrological monitoring data from a preset encryption algorithm parameter library. The encryption algorithm parameter library stores pre-assessed energy consumption, bandwidth overhead, and security strength parameters for different encryption algorithms. A402. For each selected encryption algorithm, calculate the comprehensive performance index value of the corresponding encryption algorithm based on the corresponding energy consumption, bandwidth overhead and security strength parameters, as well as the energy consumption weight, the corresponding data security weight and the bandwidth occupancy weight.

7. A data security management method according to claim 1, characterized in that: Step A6 includes: A601. Prioritize each group of hydrological monitoring data based on security level; data with higher security levels have higher priority. A602. Transmit each set of hydrological monitoring data to the shore-based monitoring center via the underwater wireless communication link according to priority, and monitor the packet loss rate of the underwater wireless communication link during the transmission process; A603. When it is detected that the packet loss rate exceeds the preset packet loss rate threshold, the transmission of data with a priority not higher than the preset priority threshold is suspended, and data with a priority higher than the preset priority threshold is retransmitted first until the packet loss rate returns to below the preset threshold, and the remaining data is transmitted.

8. A data security management device for securely managing hydrological monitoring data collected by underwater sensor nodes when performing underwater pipeline safety monitoring, characterized in that: The device includes: The power monitoring module is used to monitor the remaining battery power of the underwater sensor node and determine the energy consumption weight based on the comparison result between the remaining battery power and the preset power threshold; A security level determination module is used to group the hydrological monitoring data collected by the underwater sensor nodes and determine the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data; A bandwidth evaluation module is used to determine the bandwidth occupancy weight according to the congestion level of the underwater wireless communication environment; A performance calculation module is used to calculate the comprehensive performance index values ​​of different encryption algorithms for each set of hydrological monitoring data based on the determined energy consumption weight, the corresponding data security weight, the bandwidth occupancy weight, and the pre-assessed energy consumption, bandwidth overhead, and security strength parameters of different encryption algorithms; The data encryption module is used to select the encryption algorithm with the best comprehensive performance index value for each set of hydrological monitoring data and encrypt the hydrological monitoring data of this set; A data transmission module, used to transmit the encrypted hydrological monitoring data to the shore-based monitoring center via an underwater wireless communication link; The security level determination module groups the hydrological monitoring data collected by the underwater sensor nodes and determines the data security weight of each group of hydrological monitoring data according to the security level of each group of hydrological monitoring data. A201 extracts metadata of hydrological monitoring data collected by underwater sensor nodes, the metadata including a data type identifier; A202. Based on the data type identifier, query and obtain the safety impact level of various types of hydrological monitoring data; A203. Group various types of hydrological monitoring data according to the safety impact level, and calculate the safety level of each group of hydrological monitoring data based on the safety impact level of each type of hydrological monitoring data within the group; A204. Determine the data security weight for each group of hydrological monitoring data based on the correspondence between the preset security level and the data security weight; Step A203 includes: B1. Compare the safety impact levels of various types of hydrological monitoring data with the preset safety impact level thresholds and preliminarily group the hydrological monitoring data; B2. Calculate the initial safety level of each group of hydrological monitoring data using a weighted average algorithm based on the data volume and safety impact level of each type of hydrological monitoring data within the group. The greater the data volume, the greater the weight of the corresponding hydrological monitoring data. B3. Calculate the level deviation between the safety impact level of each type of hydrological monitoring data within each group of hydrological monitoring data and the corresponding initial safety level. If all level deviations within the group do not exceed the preset deviation threshold, execute step B4 for the corresponding data group. Otherwise, split the corresponding data group into multiple groups of data and execute steps B2 and B3 again for the resulting split data groups. B4. Using the initial security level of each set of hydrological monitoring data as the security level of the corresponding data set.