Safe and sensitive five-dimensional four-view city information model construction method
Through the five-dimensional and four-perspective framework, the urban information model construction method is solved, and the problems of insufficient information integration and data security risks are achieved, the comprehensive integration and management of urban information is achieved, the smart city's ability to deal with complex situations is improved, data security and system stability are ensured, and urban planning and emergency response are supported.
Patent Information
- Application Number
- CN202510474601.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-16
- Publication Date
- 2025-07-18
AI Technical Summary
The existing urban information model (CIM) construction methods have problems such as insufficient information integration, data security risks and insufficient response complexity, resulting in serious information silos and poor data sharing and collaboration capabilities, making it difficult to meet the complex management and emergency response needs of smart cities.
Adopting a five-dimensional and four-perspective framework, combining the four dimensions of physics, function, information, organization and society, as well as the three perspectives of technology, business, data and security, through data interaction and collaborative work, the comprehensive integration and management of urban information is achieved, including security measures such as data encryption, access control, intrusion detection and public participation, and an efficient and secure urban information model system is built.
It has improved the integration, data security and ability to deal with complex situations, provided strong technical support for smart city construction, ensured the confidentiality, integrity and availability of data, and supported urban planning, infrastructure management and emergency response fields.
Smart Images

Figure CN120338625A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of smart cities, and specifically to a method for constructing a secure and sensitive five-dimensional four-perspective urban information model. Background Art
[0002] With the acceleration of the global urbanization process, the scale and population of cities are constantly increasing, and the complexity and challenges of urban management are also rising. The construction of smart cities realizes the optimal allocation of urban resources through the integration of information technology, improves urban management efficiency and the quality of residents' lives. As one of the core technologies of smart cities, urban information models comprehensively apply technologies such as Building Information Modeling (BIM for short), Geographic Information System (GIS for short), and Internet of Things (IOT for short) to comprehensively digitally represent the physical form, functional operation, and information interaction of cities, providing scientific decision-making support tools for urban managers;
[0003] Although the urban information model, i.e., City Information Modeling (CIM for short) technology has been applied in many cities, there are still some significant problems in the existing CIM construction methods:
[0004] For example, there are insufficient information integration, data security risks, and insufficient response to complexity. Among them, insufficient information integration mainly means that traditional CIM methods usually focus on a specific area of the city. For example, BIM mainly targets the design and maintenance of buildings, while GIS focuses on the management of spatial data, lacking a comprehensive integration perspective that can cover all dimensions of the city, such as physical, functional, and information, resulting in serious information island phenomena, poor data sharing and collaboration capabilities between different systems, and restricting the comprehensive application potential of CIM;
[0005] Among them, data security risks refer to that with the deepening of smart city construction, the types and sensitivity of data managed in CIM systems are increasing day by day, including traffic flow monitoring, energy consumption records, public security monitoring, etc. The existing CIM construction methods lack measures in data security and privacy protection, lacking effective encryption, access control, and security monitoring means, which are prone to data leakage and unauthorized access, thus threatening urban security and residents' privacy;
[0006] Among them, the insufficient response to complexity means that urban information has the characteristics of multi-source heterogeneity, dynamic change, and multi-dimensional interweaving. The existing CIM methods show deficiencies in dealing with data from different sources, quickly responding to emergencies, and dynamically adjusting urban operation strategies, and it is difficult to meet the complex needs of actual urban management and emergency response. This current situation of lacking flexibility and dynamic adaptability limits the further development and application of CIM in smart cities.
[0007] To solve the above problems, the present invention proposes a method for constructing a security-sensitive, multi-dimensional and multi-perspective urban information model. By introducing a framework of five dimensions and four perspectives, the present invention can not only achieve the comprehensive integration and management of urban information, but also effectively ensure the security of data, and has stronger capabilities to handle complex situations, thereby providing strong technical support for the construction of smart cities. Summary of the Invention
[0008] The object of the present invention is to provide a security-sensitive method for constructing a five-dimensional and four-perspective urban information model. By combining five dimensions of physical, functional, information, organizational, and social, and four perspectives of technology, business, data, and security, it systematically models, integrates, and manages various types of urban information. This method focuses on the integrated management and security protection of urban information, aiming to improve the performance of urban information systems in aspects such as information integration, data security, and system response capabilities. It is widely applicable to fields such as smart city planning, infrastructure management, emergency response, urban operation, and decision-making support to solve problems such as insufficient information integration, potential data security risks, and insufficient response to complexity in the prior art. The comprehensive integration and management of urban information are achieved through data interaction and collaborative work among the five dimensions and four perspectives, where: the physical dimension and the functional dimension interact through the modeling of infrastructure data and functional systems; the functional dimension and the information dimension interact through sensor networks and Internet of Things devices for data collection and analysis; the information dimension and the organizational dimension achieve data permission allocation and sharing through a metadata management system; the organizational dimension and the social dimension achieve public participation and feedback collection through a user interaction platform; the technology perspective and the business perspective support the implementation of functional modules through a technical architecture; the business perspective and the data perspective support the data requirements of functional modules through data standards and specifications; the data perspective and the security perspective ensure the security of data through data encryption and access control; the security perspective and the technology perspective ensure the security of the technical architecture through security policies.
[0009] Specifically, in the comprehensive integration and management of urban information, five dimensions (physical, functional, information, organizational, social) and four perspectives (technology, business, data, security) achieve deep integration through data interaction and collaborative work. The physical dimension and the functional dimension interact through the modeling of infrastructure data and functional systems (such as digital twin technology) to monitor and optimize the operation status of urban infrastructure in real time. The functional dimension and the information dimension collect data through sensor networks and Internet of Things devices, and generate insights with the help of big data analysis and artificial intelligence technologies to support decision-making. The information dimension and the organizational dimension achieve data permission allocation and sharing through a metadata management system to ensure data traceability and consistency. The organizational dimension and the social dimension collect public feedback through user interaction platforms (such as urban management APPs and social media), and use natural language processing and sentiment analysis technologies to support public participation. The technology perspective and the business perspective support the implementation of functional modules through a technology architecture (such as cloud computing, microservices) to ensure the efficient operation and scalability of the business. The business perspective and the data perspective meet the data requirements of functional modules through data standards and specifications, and centrally manage data using data warehouses and data lakes. The data perspective and the security perspective ensure the confidentiality, integrity, and availability of data through data encryption and access control, and monitor data security in real time with the help of a Security Information and Event Management (SIEM) system. The security perspective and the technology perspective guarantee the security of the technology architecture through security policies (such as network security, DevSecOps), and embed security into the entire process of design and operation. In addition, cross-dimensional and cross-perspective collaboration is achieved through the integration of data streams and workflows, a unified collaboration platform, and intelligent decision support. At the same time, a feedback mechanism and an iterative upgrade process are established to continuously optimize the operation efficiency and intelligence level of the urban information system.
[0010] To achieve the above-mentioned invention objectives, the present invention adopts the following technical solutions:
[0011] A method for constructing a security-sensitive five-dimensional four-perspective urban information model provided by the present invention comprehensively covers different levels and management requirements of urban information by introducing five dimensions and four perspectives, thereby constructing an efficient, secure, and scalable urban information model system. The following are the specific innovation points and implementation methods of the present invention:
[0012] Five-dimensional framework:
[0013] Preferably, the physical dimension focuses on the digital expression of the urban physical space, including the construction of three-dimensional models of urban buildings, roads, bridges, underground pipelines and other infrastructure. By using drone aerial photography, lidar scanning, BIM technology, and GIS, the physical structure information of the city can be obtained with high precision. This information provides important basic data support for urban planning, infrastructure maintenance, and emergency response.
[0014] Preferably, the functional dimension focuses on the modeling of urban functional systems, which specifically include transportation systems, energy supply systems and water resource management systems. By deploying a multi-agent simulation system, namely Multi-Agent System, referred to as MAS, and using traffic simulation tools, the functional operation of the city is simulated and optimized. The modeling of this dimension helps to improve the utilization efficiency of urban resources, optimize urban operation strategies, and reduce operating costs.
[0015] Preferably, the information dimension focuses on the management and optimization of information flow in the city. By deploying sensor networks and Internet of Things devices in the city, real-time data on traffic flow, environmental monitoring, public safety, etc. are collected. Big data processing technologies such as Hadoop and Spark are used to process and analyze data in real time to ensure the timeliness and accuracy of information flow, and provide real-time information support for urban management decisions.
[0016] Preferably, the organizational dimension aims to model the interactive relationships and management processes of urban management agencies, enterprises and public organizations. By introducing metadata management systems such as Apache Atlas, the hierarchical relationships, functional divisions, information permissions, etc. of the organization are managed and maintained. This dimension helps standardize urban management processes, improve organizational coordination capabilities, and ensure the orderly operation of the urban management system.
[0017] Preferably, the social dimension focuses on modeling public participation and social interaction, collects public opinions and feedback through user interaction platforms such as mobile applications and web portals, and enhances citizens' enthusiasm for participating in urban management. This dimension also includes social behavior analysis, such as population mobility patterns and public sentiment analysis, to provide city managers with more comprehensive social dynamic information.
[0018] Four-view frame:
[0019] Preferably, the technical perspective starts from the perspective of technical implementation and considers the technical architecture design of the CIM system, which includes technical elements such as data collection, data transmission, data storage and processing, adopts a distributed system architecture, and utilizes edge computing, cloud computing and big data technologies to ensure the efficiency and scalability of the system. The design from the technical perspective aims to build a high-performance technology platform to support real-time collection and processing of urban information.
[0020] Preferably, the business perspective starts from the business needs of urban management and operation, defines the functional modules and business processes of the CIM system, which include business functional modules such as urban planning management, public safety monitoring, traffic optimization management, and energy management. By combing the business processes, it is ensured that the CIM system can fully support various management needs of the city and improve the refinement and intelligence level of urban management.
[0021] Preferably, from the perspective of data management, the data perspective formulates data standards and specifications, manages the data life cycle, which includes processes such as data collection, cleaning, storage, analysis, and display. By introducing data lake technology, a unified data management platform is constructed to achieve the integration of multi-source heterogeneous data. The design of the data perspective aims to improve data quality, ensure data accuracy and consistency, and provide a reliable data foundation for the decision-making support of the CIM system.
[0022] Preferably, from the perspective of information security and privacy protection, the security perspective designs the security policies and mechanisms of the CIM system, which includes measures such as data encryption, access control, intrusion detection, and security monitoring. The AES-256 encryption algorithm is used to protect sensitive data, role-based access control is used to restrict user permissions, and an intrusion detection system is deployed to monitor the system security status in real time to ensure the confidentiality, integrity, and availability of data.
[0023] Preferably, for data encryption and protection, specifically at the intersection of the information dimension and the security perspective, the Advanced Encryption Standard AES-256 is used to encrypt all sensitive data. The Secure Sockets Layer SSL / TLS protocol is used during data transmission to prevent data from being intercepted or tampered with during network transmission. All encryption keys in the system are managed and stored through a secure key management service, namely Key Management Service, KMS, to ensure the security of the keys.
[0024] Preferably, for access control and user authentication: Implement Role-Based Access Control, abbreviated as RBAC, to ensure that only authorized users can access and operate sensitive data in the CIM system. The system uses the OAuth2.0 standard for user authentication, combined with multi-factor authentication, namely Multi-Factor Authentication, abbreviated as MFA, such as double verification of password plus SMS verification code, to further enhance the security of the system.
[0025] Preferably, for intrusion detection and security monitoring, specifically deploy an Intrusion Detection System, abbreviated as IDS, in the CIM system to monitor network traffic and system activities in real time, detect and respond to potential security threats, and use the ELK, namely Elasticsearch Logstash Kibana stack, to build a security monitoring dashboard to display the running status and security events of the system in real time, providing an intuitive security monitoring tool for system administrators.
[0026] Preferably, for the multi-channel user interaction, it mainly provides convenient user access and operation methods by developing various user interfaces, such as mobile applications, Web portals, and APIs. Users can access urban information, submit suggestions and feedback, receive emergency notifications, etc. through these interfaces. The interface design focuses on the user experience to ensure the convenience of operation and the visual display of information.
[0027] Preferably, for the public participation in social feedback, it mainly introduces a public participation mechanism in the CIM system, collects opinions and suggestions from citizens through an online platform, improves the public's participation and support for urban management. Through data analysis and mining technologies, it analyzes public feedback, discovers problems and improvement spaces in urban management, and provides decision-making references for urban managers.
[0028] Preferably, for the user training and safety education, it mainly provides training courses for the users of the CIM system regularly. The content includes system operation guides, data protection measures, privacy policies, and network security knowledge. Through training, it improves the users' safety awareness and operation skills to ensure that users can use the system correctly and protect personal privacy and data security.
[0029] Compared with the prior art, the above one or more technical solutions have the following beneficial effects:
[0030] By introducing the five-dimensional four-perspective framework, this method comprehensively constructs an urban information model from multiple dimensions and perspectives, pays attention to information integration and security protection, effectively improves the integration degree, data security, and the ability to handle complex situations of the CIM system, and provides strong technical support for the construction of smart cities. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] The specification drawings forming a part of the present invention are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.
[0032] Figure 1 It is the overall architecture diagram of the urban information model system of the present invention, which shows the overall architecture of the urban information model system based on the five-dimensional four-perspective framework;
[0033] Figure 2 It is the schematic diagram of the five-dimensional framework of the present invention;
[0034] Figure 3 It is the schematic diagram of the four-perspective framework of the present invention;
[0035] Figure 4 It is the schematic diagram of data encryption and access control of the present invention;
[0036] Figure 5 It is the schematic diagram of the intrusion detection and security monitoring architecture of the present invention;
[0037] Figure 6 It is a schematic diagram of the user interaction and public participation interface of the present invention;
[0038] Figure 7 It is a schematic diagram of data flow and information integration of the present invention;
[0039] Figure 8 It is a schematic diagram of the public participation social feedback mechanism of the present invention. Detailed implementation manners
[0040] In order to enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0041] Embodiment 1
[0042] Please refer to Figure 1 - Figure 8 , a method for constructing a secure and sensitive five-dimensional four-perspective urban information model, wherein the overall architecture design steps of the CIM system are as follows:
[0043] Step 1, construction of the data acquisition layer, including sensor deployment and data acquisition technology. Sensor deployment refers to deploying sensors and Internet of Things devices at key positions in the city, such as transportation hubs, energy sites, buildings, and public places. Sensor types include environmental sensors: such as temperature and humidity sensors, air quality sensors, flow sensors, and energy consumption sensors;
[0044] The sensor network adopts low-power wide-area network (LPWAN) technology, such as LoRaWAN or NB-IoT, to ensure long-distance transmission and low-power operation of sensor data. Sensor data is published to the edge computing node through the MQTT protocol. The edge node uses a Raspberry Pi or a dedicated embedded device for data preprocessing, including data denoising, format conversion, and preliminary analysis, to reduce the burden of cloud data processing.
[0045] Among them, data acquisition technology refers to using wireless sensor network technology to realize the interconnection of data acquisition devices, using low-power wireless communication protocols such as LoRa and ZigBee to ensure the stability and coverage of the sensor network. UAV aerial photography and LiDAR technology of lidar are used to collect three-dimensional data of the urban physical structure.
[0046] Step 2: Implementation of the data transmission layer, including edge computing nodes and a data transmission network. Specifically, edge computing nodes are deployed near data collection points to achieve preliminary data processing and screening. The edge computing nodes use single-board computers such as Raspberry Pi or dedicated embedded devices for data denoising, preprocessing, and temporary storage.
[0047] Among them, the data transmission network specifically transmits edge node data to the cloud data center through a high-speed fiber optic network or a 5G network, and uses the MQTT protocol for data publishing and subscribing to achieve real-time data transmission and distribution.
[0048] Step 3: Design of the data processing layer, including a big data processing platform and a data lake architecture. Specifically, a big data processing platform based on Apache Hadoop and Apache Spark is built. The data processing layer is mainly responsible for data cleaning, integration, analysis, and storage. The Hadoop Distributed FileSystem (HDFS) is used to store large-scale data, and Spark is used for real-time data processing and analysis.
[0049] Among them, the data lake architecture specifically constructs a data lake to integrate data from different sources, including structured data database records, semi-structured data such as XML or JSON files, and unstructured data such as text, images, and videos, and uses Apache Hive and Presto for data query and analysis.
[0050] Step 4: Implementation of the application layer, including urban planning management and an emergency response system. Specifically, for urban planning management, an urban planning management application is developed to support functions such as the display of 3D urban models, building space analysis, and traffic flow simulation, and uses 3D visualization tools such as Unity3D or CesiumJS to display the urban model.
[0051] Among them, for the emergency response system, an urban planning management application is developed to support functions such as the display of 3D urban models, building space analysis, and traffic flow simulation. 3D visualization tools such as Unity3D or CesiumJS are used to display the urban model.
[0052] Step 5: Implementation of the security control layer, including data encryption, access control, and intrusion detection and security monitoring. Specifically, for data encryption, during the data collection and transmission process, the AES-256 encryption algorithm is used to protect sensitive data, and all data is encrypted before entering the data processing layer, and the SSL / TLS protocol is used to ensure data security during transmission.
[0053] Among them, access control specifically uses role-based access control policies to define the permissions of different user roles, such as system administrators, city managers, and public users, and combines the OAuth2.0 standard to implement user authentication and authorization;
[0054] Among them, intrusion detection and security monitoring specifically deploy the Snort intrusion detection system to monitor network traffic and system activity logs, and use the ELK stack to build a security monitoring dashboard to display security events and system status in real time.
[0055] Embodiment 2
[0056] Please refer to Figure 1 - Figure 8 , a method for constructing a security-sensitive five-dimensional four-perspective urban information model, where the application steps of the five-dimensional framework are as follows:
[0057] Step 1, the implementation of the physical dimension, including 3D modeling and infrastructure management. Among them, 3D modeling specifically uses drone aerial images and LiDAR point cloud data to generate a 3D model of the city, and processes and optimizes the physical model through software tools such as AutoCAD or ArcGIS to ensure the accuracy and usability of the model;
[0058] Among them, infrastructure management specifically applies the 3D model to infrastructure management, such as pipeline inspection, road maintenance, bridge detection, etc., and visualizes underground pipelines and other hidden facilities during on-site inspections through AR technology.
[0059] Step 2, the implementation of the functional dimension, including traffic simulation and optimization and energy management. Among them, traffic simulation and optimization specifically deploy SUMO, that is, the Simulation of Urban Mobility traffic simulation tool, to simulate urban traffic flow, optimize traffic signal control, reduce congestion, and combine real-time traffic data and historical data to use machine learning algorithms (such as LSTM neural networks) to predict traffic flow changes;
[0060] The traffic simulation tool is seamlessly integrated with the 3D model data of the physical dimension to obtain the status information of roads, bridges, and traffic lights in real time, and conducts data interaction with the traffic optimization module of the business perspective through the API interface to achieve dynamic traffic signal control and congestion warning.
[0061] Among them, energy management specifically develops an energy management application to monitor urban energy consumption, optimize energy distribution, and uses blockchain technology to record energy transactions to ensure data transparency and security.
[0062] Step 3: Implementation of the information dimension, including sensor network and data integration and real-time monitoring and alarm. Specifically, sensor network and data integration involves establishing an Internet of Things platform, managing data collection, transmission and storage of sensor nodes, using the Kafka message queue system to achieve real-time data distribution and processing, and integrating multi-source data.
[0063] Among them, real-time monitoring and alarm specifically uses the data stream processing engine to realize real-time analysis of environmental monitoring, traffic flow and other data, set threshold alarms, and automatically trigger alarms and notify relevant departments when the monitoring data exceeds the set threshold.
[0064] Step 4: Implementation of the organizational dimension, including information rights, data sharing and collaborative work platform. Information rights and data sharing specifically involve using metadata management systems to manage organizational hierarchies and information rights, define data access rights and sharing strategies, and ensure data sharing and collaboration between different departments.
[0065] Among them, the collaborative work platform is specifically developed to support information sharing and task allocation between city managers and relevant departments. The platform includes functions such as task management, document sharing, and online meetings.
[0066] Step five, the realization of the social dimension, includes public interaction and feedback and social behavior analysis. Public interaction and feedback specifically involves the development of a public participation platform that allows citizens to submit suggestions, report issues and participate in urban management through mobile applications or web interfaces. The platform supports the review and release of user-generated content to ensure the authenticity and validity of the information. Social behavior analysis specifically involves the use of natural language processing, or NLP, to analyze public opinions on social media, understand public sentiment and public opinion trends, and combine urban data to analyze and predict social behavior patterns to provide a reference for urban management.
[0067] The above five dimensions achieve collaborative work through data interaction, among which: the physical dimension and the functional dimension achieve interaction through the modeling of infrastructure data and functional systems; the functional dimension and the information dimension achieve interaction in data collection and analysis through sensor networks and Internet of Things devices; the information dimension and the organizational dimension achieve data permission allocation and sharing through the metadata management system; the organizational dimension and the social dimension achieve public participation and feedback collection through the user interaction platform.
[0068] Embodiment 3
[0069] See also Figure 1 - Figure 8 , a security-sensitive five-dimensional four-view urban information model construction method, in which the application steps of the four-view framework are:
[0070] Step 1, implementation from a technical perspective, including technical architecture design and data processing technologies. Specifically, for technical architecture design, a microservices architecture is used to design the CIM system, with each functional module developed and deployed independently to ensure the scalability and maintainability of the system. The system components are deployed through Docker containerization technology, and Kubernetes is used for container orchestration and management;
[0071] Among them, for data processing technologies, Hadoop and Spark are specifically used for batch processing and stream processing to ensure the efficiency of data processing. HBase is used as a large-scale data storage to support high-concurrency read and write operations.
[0072] Step 2, implementation from a business perspective, including business process definition and functional module development. Specifically, for business process definition, in combination with urban management requirements, business processes are designed, such as emergency response processes, traffic management processes, energy scheduling processes, etc. Through a business process management system, namely the Building Plan Management System, abbreviated as BPM, the automation and visualization of business processes are realized;
[0073] Among them, for functional module development, each functional module required for urban management is developed, such as traffic optimization modules, emergency response modules, public participation modules, etc. Each module communicates with each other through API interfaces to achieve data sharing and function integration.
[0074] Step 3, implementation from a data perspective, including data standardization and data life cycle management. Specifically, for data standardization, data standards are formulated to unify data formats and naming specifications to ensure the consistency of data from different sources. Data conversion tools such as Talend are used to achieve data format conversion and standardization processing;
[0075] Among them, for data life cycle management, the life cycle of data is defined, including data collection, storage, use, archiving, and deletion. Data management tools such as Apache Ranger are used to achieve classified management and permission control of data.
[0076] Step 4, implementation from a security perspective, including data encryption technology and security monitoring and auditing. Specifically, for data encryption technology, the AES-256 algorithm is used to encrypt sensitive data to protect the confidentiality of data. The SSL / TLS protocol is used to encrypt network communication to prevent data from being intercepted during transmission;
[0077] Among them, security monitoring and auditing specifically involve real-time monitoring of the system security status through intrusion detection systems and Security Information and Event Management (SIEM) systems, and regular security audits to check the system's security policies and configurations, discover and fix security vulnerabilities.
[0078] The above four perspectives work together through data interaction, where: between the technical perspective and the business perspective, the implementation of functional modules is supported by the technical architecture; between the business perspective and the data perspective, the data requirements of functional modules are supported by data standards and specifications; between the data perspective and the security perspective, data encryption and access control ensure data security; between the security perspective and the technical perspective, security policies guarantee the security of the technical architecture.
[0079] Embodiment 4
[0080] Please refer to Figure 1 - Figure 8 , a method for constructing a security-sensitive five-dimensional four-perspective urban information model, where the application steps of security-sensitive design and implementation are as follows:
[0081] Step 1, data encryption and protection, including encrypted transmission, data storage encryption, and fine-grained encryption. Among them, encrypted transmission specifically means that all data involving sensitive information is encrypted using the Transport Layer Security (TLS) protocol during transmission, and each data collection point and edge computing node is configured with a TLS certificate to ensure the confidentiality of data during transmission and prevent man-in-the-middle attacks;
[0082] In practical applications, for example, in a smart transportation system, traffic flow data and vehicle location information are encrypted and transmitted to the cloud data center through TLS to ensure that the data is not stolen or tampered with during transmission. At the same time, the edge computing node performs preliminary encryption processing on the data to further reduce the risk of data leakage.
[0083] Among them, data storage encryption specifically means that in terms of data storage, AES-256 is used to encrypt static data, and big data processing platforms such as HDFS are configured with transparent data encryption functions to keep the data stored on the disk always encrypted, and the key management service is used to manage the generation, distribution, and storage of encryption keys;
[0084] Among them, fine-grained encryption specifically means adopting different encryption strategies for different types of data. For example, for very sensitive personal identity information, a higher-strength encryption algorithm is used, and zero-knowledge encryption technology is implemented to ensure that the data is only decrypted when authorized access occurs.
[0085] Step 2, Data access control, including role-based access control, multi-factor authentication, and the principle of least privilege. Among them, role-based access control specifically means implementing RBAC in the CIM system, defining different user roles such as city administrators, data analysts, and public users and their corresponding access rights. Only authorized roles can access specific types of data and system functions. Configure the RBAC policy through the identity and access management service;
[0086] Among them, multi-factor authentication specifically means that when a user accesses the CIM system, multi-factor authentication is required. In addition to the traditional username and password, the user also needs to confirm their identity through a second verification method such as a text message verification code, email verification, or a hardware token to improve the security of the system;
[0087] Among them, the principle of least privilege specifically means assigning the least privilege to each user role, that is, only granting the minimum permissions required to complete their tasks. In this way, even if a user account is compromised, the potential damage can be minimized.
[0088] Step 3, Security monitoring and intrusion detection, including intrusion detection systems, security information and event management, and network security monitoring. Among them, the intrusion detection system specifically means deploying an intrusion detection system such as Snort at the network layer of the CIM system to monitor and analyze network traffic in real time. The IDS can identify abnormal traffic patterns and potential attack behaviors, such as denial-of-service attacks, SQL injection, and cross-site scripting attacks, and issue alerts;
[0089] Among them, security information and event management specifically means using a SIEM system, such as Splunk or IBM QRadar, to collect and analyze security logs and event data from various system components. The SIEM system integrates security information, detects threats in real time, automates response processes, and generates detailed security reports;
[0090] Among them, network security monitoring specifically means configuring network traffic analysis tools, such as Wireshark or NetFlow, to monitor network traffic, identify abnormal behaviors and potential threats, and block malicious traffic and attacks by configuring firewalls and intrusion prevention systems.
[0091] Step 4, Data privacy protection, including data de-identification, differential privacy, and privacy risk assessment. Among them, data de-identification specifically means de-identifying personal sensitive information before storing and analyzing data. For example, replacing personal identity information with a hash value or other irreversible identifiers to prevent the abuse of information after data leakage;
[0092] Among them, differential privacy specifically refers to the application of differential privacy technology when releasing statistical data and analysis results. By adding noise to the query results, it prevents attackers from inferring sensitive data from the query results and protects personal privacy.
[0093] Among them, privacy risk assessment specifically refers to regularly conducting privacy impact assessments on the CIM system, identifying and evaluating privacy risks, and formulating and implementing corresponding privacy protection measures based on the assessment results to ensure that the system complies with the requirements of relevant laws and regulations.
[0094] Step Five, security auditing and compliance, including security auditing, compliance management, and security training. Among them, security auditing specifically refers to regularly performing security audits, checking system configurations, access logs, and operation behaviors to ensure compliance with security policies and standards. The auditing process includes monitoring and recording user behaviors, data access, and system configurations.
[0095] Among them, compliance management specifically refers to establishing a compliance management framework to ensure that the CIM system follows international and national data protection laws and regulations and regularly conducting compliance checks to ensure that the system complies with all legal requirements when processing sensitive data.
[0096] Among them, security training specifically refers to regularly providing security awareness training to system users and administrators. The training content includes security operation specifications, data protection methods, emergency response procedures, etc. to enhance the security awareness and capabilities of all employees.
[0097] Step Six, emergency response and recovery, including an emergency response plan, disaster recovery, and a security incident reporting mechanism. Among them, the emergency response plan specifically refers to formulating and implementing an emergency response plan, including response steps for events such as cyberattacks and data breaches, and regularly rehearsing the emergency response plan to ensure rapid response and handling in the event of a security incident.
[0098] Among them, disaster recovery specifically refers to implementing a disaster recovery strategy in the system to ensure that in the event of a major security incident or disaster, the critical functions of the system can be quickly restored. The disaster recovery strategy includes data backup and recovery, off-site disaster tolerance, business continuity plans, etc.
[0099] Among them, the security incident reporting mechanism specifically refers to establishing a security incident reporting mechanism. When users or administrators discover security vulnerabilities or abnormal situations, they can report them quickly. The system automatically records and tracks security incidents to ensure timely response and repair.
[0100] Example Five
[0101] Please refer to Figure 1 - Figure 8 , a method for constructing a security-sensitive five-dimensional four-perspective urban information model, where the design and application steps of the urban energy management system are as follows:
[0102] Step 1: Acquisition and management of energy data, including smart meters and sensors, the Internet of Things (IoT) platform, and storage of energy data. Specifically, deploy smart meters and sensors to monitor the energy consumption in various regions of the city in real time. The smart meters are installed at key locations such as buildings, industrial facilities, and transportation facilities to collect energy data such as electricity, gas, and water.
[0103] Specifically, build an IoT platform to manage and control smart meters and sensors distributed across the city. Use lightweight protocols such as MQTT to achieve remote control and data transmission of devices, and integrate the Kafka message queue system to support real-time processing and transmission of large-scale energy data.
[0104] Specifically, use HDFS to store large-scale energy data to ensure data persistence and high availability. Use HBase as real-time data storage to support high-concurrency read and write operations. The database adopts partitioning and indexing strategies to improve query efficiency.
[0105] Step 2: Analysis and optimization of energy data, including data cleaning and processing, energy consumption prediction model, and energy efficiency analysis. Specifically, use ETL tools to clean, transform, and load energy data to ensure data consistency and accuracy, and use Spark for batch processing and real-time data analysis.
[0106] Specifically, build an energy consumption prediction model, use machine learning algorithms such as regression analysis and time series analysis to predict future energy demand, and optimize energy scheduling and allocation strategies by analyzing historical data and real-time data.
[0107] Specifically, through the analysis of energy data, evaluate the energy use efficiency of different buildings, facilities, and regions, identify high-energy-consuming areas or equipment, and provide suggestions for energy efficiency improvement, such as replacing high-energy-consuming equipment, adjusting lighting systems, and optimizing air-conditioning settings.
[0108] Step 3: Local blockchain-based energy trading platform, including the construction of the blockchain network, the development of smart contracts, and the transparency and security of transactions. Specifically, use Hyperledger Fabric or Ethereum to build a blockchain network to achieve decentralized energy trading. Each energy producer and consumer acts as a blockchain node to participate in the recording and verification of transactions.
[0109] In practical applications, such as in smart energy management, solar power plants and household users conduct energy transactions through a blockchain network. Smart contracts automatically execute transaction rules to ensure the transparency and security of transactions. Each transaction is recorded on the blockchain for all participants to view in real time, avoiding middlemen and potential fraud in traditional energy transactions.
[0110] Among them, the development of smart contracts specifically involves developing smart contracts to define energy transaction rules and protocols. Smart contracts automatically execute energy transactions, record transaction information such as transaction time, transaction amount, energy type, and both parties to the transaction, write smart contracts using the Solidity language, and deploy them in the blockchain network;
[0111] Among them, the transparency and security of transactions specifically mean that the distributed ledger technology of the blockchain ensures the transparency and immutability of energy transaction data. Each transaction is verified by multiple nodes to prevent double-spending and fraud. The execution results of smart contracts are automatically recorded on the blockchain, and both parties to the transaction can view the transaction status in real time.
[0112] Example Six
[0113] Please refer to Figure 1 - Figure 8 , a method for constructing a security-sensitive five-dimensional four-perspective urban information model, where the integration and collaboration steps of the CIM platform are as follows:
[0114] Step 1, platform integration strategy, including unified data interfaces, microservice architecture, and service orchestration and integration. Among them, the unified data interface specifically means designing a unified data interface to achieve data interoperability between different systems and applications, using RESTful API and GraphQL interfaces to support operations such as data query, insertion, update, and deletion;
[0115] The microservice architecture adopts Docker containerization technology, with each functional module independently deployed and managed, and container orchestration is carried out through Kubernetes to ensure the high availability and scalability of the system. Service orchestration and integration are achieved through a message queue system (such as Kafka) to ensure decoupling and asynchronous communication between modules, and improve the overall performance and stability of the system.
[0116] Among them, the microservice architecture specifically means that the CIM platform adopts a microservice architecture, with functional modules independently deployed and managed, and the API gateway manages the access and routing of microservices to ensure the stability and scalability of the services;
[0117] Among them, service orchestration and integration specifically refer to using service orchestration tools, such as using Kubernetes to manage and deploy each service of the CIM platform, and through a message queue system, such as using RabbitMQ and Kafka to achieve decoupling and asynchronous communication between services.
[0118] Step 2, the platform collaboration mechanism, including a collaborative working environment, data sharing and access control, and multi-party data collaboration. Among them, the collaborative working environment specifically refers to developing a collaborative working environment to support the collaborative work of different roles such as urban managers, engineers, and data analysts. The collaborative working environment integrates functions such as project management tools, document sharing platforms, and online meeting systems, and supports efficient communication and cooperation between teams.
[0119] Among them, data sharing and access control specifically refer to defining data sharing policies to ensure the flow of data between different departments and applications, and using an attribute-based access control mechanism to dynamically control data access permissions according to user attributes and environmental context.
[0120] Among them, multi-party data collaboration specifically refers to supporting data collaboration between multiple cities, institutions, and enterprises. By establishing a data alliance to share non-sensitive data, cross-regional and cross-departmental data cooperation is achieved. A data exchange platform such as ODI is used for data exchange and integration.
[0121] Step 3, the platform extension plan, including modular design, support for heterogeneous data, and open APIs. Among them, modular design specifically means that the CIM platform adopts a modular design, and each functional module can be independently developed, deployed, and extended. The addition of new functions will not affect the operation of existing functions, and the system can be flexibly extended according to requirements.
[0122] Among them, supporting heterogeneous data specifically means that the CIM platform supports the integration of multiple data formats and data sources, such as relational databases, NoSQL databases, file systems, cloud storage, etc., and realizes the unified management and access of data through data adapters.
[0123] Among them, open APIs specifically mean that the CIM platform provides open API interfaces. Third-party developers can develop customized applications and services based on the platform. Through the API developer portal, API documentation, sample code, and technical support are provided to promote the development of the ecosystem.
[0124] Embodiment 7
[0125] Please refer to Figure 1 - Figure 8 , a method for constructing a secure and sensitive five-dimensional four-perspective urban information model, where the steps of the urban emergency response and disaster management system are as follows:
[0126] Step 1: Collection and processing of emergency data, including sensor networks, video surveillance and image recognition, and data integration and analysis. Specifically, for the sensor network, deploy sensor networks in important urban areas such as transportation hubs, buildings, bridges, and subway stations to monitor environmental parameters such as temperature, humidity, vibration, and gas concentration in real time. Use the Internet of Things platform to uniformly manage and control the sensors, collect data, and transmit it to the cloud.
[0127] Among them, video surveillance and image recognition specifically refer to deploying high-definition cameras for video surveillance, using computer vision technologies such as face recognition, vehicle recognition, and behavior analysis to identify the video stream, and combining deep learning models to automatically detect abnormal behaviors such as violent incidents, fires, and traffic accidents.
[0128] Among them, data integration and analysis specifically refer to integrating data from sensors, cameras, social media, and public reports, storing and managing it through a data lake architecture, and using a real-time data stream processing engine for data analysis to identify potential emergency events.
[0129] Step 2: Impact response and command system, including a command and dispatch platform, emergency plan management, and multi-department collaborative response. Specifically, for the command and dispatch platform, develop a command and dispatch platform to achieve the scheduling and management of emergency resources. The platform integrates functions such as map display, resource allocation, and task management, supporting the rapid response and decision-making of the emergency command center for various emergency events.
[0130] The command and dispatch platform is seamlessly integrated with the sensor network and data lake architecture in the information dimension to obtain environmental monitoring data, traffic flow data, and public feedback information in real time. Through the emergency response module from the business perspective, the platform automatically matches the emergency plan, generates an emergency response strategy, and notifies relevant departments (such as fire, medical, and public security) through the collaborative work platform in the organizational dimension for collaborative response.
[0131] Among them, emergency plan management specifically refers to formulating and maintaining an emergency plan library covering different types of emergency events such as fires, earthquakes, floods, and terrorist attacks. When the platform detects an emergency event, it automatically matches the corresponding plan and generates an emergency response strategy.
[0132] Among them, multi-department collaborative response specifically refers to establishing a multi-department collaborative response mechanism. When an emergency event occurs, it automatically notifies relevant departments such as fire, medical, public security, and transportation, and through the collaborative work platform, realizes information sharing and real-time communication among multiple departments.
[0133] Step 3: Disaster prediction and early warning system, including meteorological and geological data integration, disaster simulation and analysis, and public early warning system. Among them, meteorological and geological data integration specifically integrates meteorological data such as rainfall, wind speed, temperature, and geological data such as seismic activity or land subsidence for disaster prediction, and uses machine learning models to analyze historical data and real-time data to predict potential natural disasters;
[0134] Among them, disaster simulation and analysis specifically uses disaster simulation software to conduct disaster simulation and analysis, simulate the impact range and damage degree of different disaster scenarios, and evaluate the disaster resistance ability of the city and the effectiveness of the emergency plan;
[0135] Among them, the public early warning system specifically develops a public early warning system, issues early warning information to the public through channels such as text messages, radio, and social media, combines GIS technology, provides location-based early warning services, and pushes early warning notifications for specific areas in real time.
[0136] As mentioned above, only the specific preferred embodiments of the present invention are described, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.
Claims
1. A method for constructing a security-sensitive five-dimensional four-perspective urban information model, including five dimensions and four perspectives, characterized in that, The present method constructs a city information model with five dimensions and four perspectives as the framework: The five dimensions include the physical dimension, the functional dimension, the information dimension, the organizational dimension, and the social dimension. Among them, the physical dimension is the infrastructure of the digital city, specifically including buildings, roads, bridges, and underground pipelines, and uses drone aerial photography, lidar scanning, BIM technology, and GIS to obtain physical structure information; among them, the functional dimension is to model the city's functional systems, and modeling the city's functional systems specifically includes the transportation system, the energy supply system, and the water resource management system, and uses multi-agent simulation systems and traffic simulation tools; among them, the information dimension is to manage and optimize the flow of urban information, specifically referring to collecting data through sensor networks and Internet of Things devices, and using big data processing technology to process and analyze the data in real time; among them, the organizational dimension is to model the interaction relationships and management processes of urban management agencies, enterprises, and public organizations, specifically referring to using a metadata management system to manage organizational hierarchical relationships and functional divisions; among them, the social dimension is to model public participation and social interaction, specifically referring to using a user interaction platform to collect public opinions and feedback, and conduct social behavior analysis; The four perspectives include the technical perspective, the business perspective, the data perspective, and the security perspective. Among them, the technical perspective is to design the technical architecture of the CIM system, specifically including designing the technical architecture of the CIM system, including data collection, transmission, storage, and processing, and using a distributed system architecture and big data technology; among them, the business perspective is to define the functional modules and business processes of the CIM system, specifically including urban planning management, public safety monitoring, traffic optimization management, and energy management; among them, the data perspective is to formulate data standards and specifications, specifically referring to managing the data life cycle and using data lake technology to achieve unified management of data; among them, the security perspective is to design security policies and mechanisms, specifically including data encryption, access control, intrusion detection, and security monitoring, and using the AES-256 encryption algorithm, role-based access control, and multi-factor identity authentication. The comprehensive integration and management of urban information are achieved through data interaction and collaborative work among the five dimensions and four perspectives. Among them: The physical dimension and the functional dimension interact through the modeling of infrastructure data and functional systems; the functional dimension and the information dimension interact through data collection and analysis via sensor networks and Internet of Things devices; the information dimension and the organizational dimension achieve data permission allocation and sharing through the metadata management system; the organizational dimension and the social dimension achieve public participation and feedback collection through the user interaction platform; the technical perspective and the business perspective support the implementation of functional modules through the technical architecture; the business perspective and the data perspective support the data requirements of functional modules through data standards and specifications; the data perspective and the security perspective ensure the security of data through data encryption and access control; the security perspective and the technical perspective guarantee the security of the technical architecture through security policies. Specifically, the physical dimension and the functional dimension interact through the modeling of infrastructure data and functional systems (such as digital twin technology) to monitor and optimize the operating status of urban infrastructure in real time. The functional dimension and the information dimension collect data through sensor networks and Internet of Things devices, and generate insights with the help of big data analysis and artificial intelligence technologies to support decision-making. The information dimension and the organizational dimension achieve data permission allocation and sharing through the metadata management system to ensure data traceability and consistency. The organizational dimension and the social dimension collect public feedback through user interaction platforms (such as urban management APPs and social media), and use natural language processing and sentiment analysis technologies to support public participation. The technical perspective and the business perspective support the implementation of functional modules through technical architectures (such as cloud computing and microservices) to ensure the efficient operation and scalability of the business. The business perspective and the data perspective meet the data requirements of functional modules through data standards and specifications, and use data warehouses and data lakes for centralized data management. The data perspective and the security perspective ensure the confidentiality, integrity, and availability of data through data encryption and access control, and use a Security Information and Event Management (SIEM) system to monitor data security in real time. The security perspective and the technical perspective guarantee the security of the technical architecture through security policies (such as network security and DevSecOps), and embed security into the entire process of design and operation and maintenance. In addition, cross-dimensional and cross-perspective collaboration is achieved through the integration of data streams and workflows, a unified collaboration platform, and intelligent decision support. At the same time, a feedback mechanism and an iterative upgrade process are established to continuously optimize the operating efficiency and intelligent level of the urban information system.
2. A method for constructing a security-sensitive five-dimensional four-perspective urban information model according to claim 1, characterized in that: The construction of the security perspective includes the following steps: S1. Encryption and protection of data: Specifically, use the AES-256 encryption algorithm to encrypt sensitive data, use the SSL / TLS protocol during data transmission, and use a key management service for the secure management of keys; S2. Access control and user authentication: Implement role-based access control and the OAuth2.0 standard for user authentication, combined with multi-factor authentication; S3. Intrusion detection and security monitoring: Deploy an intrusion detection system, use the ELK stack for security monitoring, and display the system status and security events in real time; S4. Security auditing and emergency response: Conduct regular security audits, develop an emergency response plan, and generate security reports to guide policy improvement.
3. A method for constructing a security-sensitive five-dimensional four-perspective urban information model according to claim 1, characterized in that: The construction of the social dimension includes the following steps: S1. Multi-channel user interaction: Develop mobile applications, web portals, and API interfaces to support urban information query, feedback submission, and receipt of emergency notifications; S2. Public participation and social feedback: Collect public opinions and suggestions through online platforms, conduct public sentiment analysis, and provide decision-making references for urban managers; S3. User training and safety education: Regularly provide training courses on system operation guides, data protection measures, privacy policies, and network security knowledge.
4. A method for constructing a security-sensitive five-dimensional four-perspective urban information model according to claim 2, characterized in that: The construction of the data perspective includes the following steps: S1. Data collection path: The data flow path from the data collection layer to the data processing layer; S2. Dataset dusting process: The process of data cleaning, format conversion, and fusion, using data lake technology for data integration; S3. Information display: Visual display of the processed information at the application layer, including the urban management dashboard and the emergency response interface.
5. A method for constructing a security-sensitive five-dimensional four-perspective urban information model according to claim 1, characterized in that: The construction of the social dimension includes the following steps: S1. Opinion collection: Collect public opinions and suggestions through mobile applications, Web platforms, and telephone channels; S2. Opinion processing: Classification, statistics, analysis, and release of feedback results of opinions; S3. Public sentiment analysis: Collection of social media data, text analysis, and sentiment classification.
Citation Information
Cited By
Digital twinborn irrigation area full-life-cycle intelligent management system for grain safety
CN121615914A