Data transmission method based on smart city digital twin model

By authenticating the identity information of digital twin entities at different levels in the digital twin model, and using USIM operators to pre-install long-term keys and random numbers to generate identity authentication information, the problem of data transmission security in digital twin technology is solved, and higher data transmission security and credibility are achieved.

CN120343062AActive Publication Date: 2025-07-18SHENZHEN SMARTCITY TECH DEV GRP CO LTD +1
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510807861.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-07-18
Estimated Expiration
2045-06-17

AI Technical Summary

Technical Problem

The existing digital twin technology is insufficient in data transmission and faces the risk of data breaches and unauthorized access.

Method used

The receiving device authenticates the identity information of digital twin entities at different levels in the digital twin model, and uses USIM operators to pre-install long-term keys and random numbers to generate identity authentication information to ensure the security of data transmission.

Benefits of technology

Improves the security of data transmission, ensures that the data received by the receiving device is trustworthy, and reduces the risk of data breaches and unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120343062A_ABST
    Figure CN120343062A_ABST
Patent Text Reader

Abstract

The invention provides a data transmission method based on a smart city digital twinborn model, belongs to the technical field of digital twinborn, and is used for improving the security of data transmission through identity verification of digital twinborn entity granularity. The method comprises the following steps: receiving end equipment receives data of a digital twin model transmitted by sending end equipment, wherein the data of the digital twin model comprises data of digital twin entities of different levels; the receiving end device authenticates identity information of the digital twin entities of partial levels according to the data of the digital twin entities of partial levels in the digital twin model, and the digital twin entities of partial levels are digital twin entities associated with upper and lower levels in the digital twin model; and under the condition that the identity information of the digital twin entity is determined to be credible through authentication, the receiving end equipment sends the data of the digital twin model to back-end equipment in the BIM / CIM platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of digital twin technology, and in particular, to a data transmission method based on a digital twin object model for a smart city. Background Art

[0002] Digital twin technology is a technology that simulates and analyzes physical entities and their environments through digital models. It encompasses technologies in multiple fields such as the Internet of Things (IoT), big data analysis, and cloud computing. Digital twin models can reflect the state of physical entities in real time and be updated and optimized through data transmission. This technology has broad application prospects in fields such as manufacturing, urban planning, and healthcare.

[0003] A digital twin object model is an abstract form for digitally describing entities in the physical world (such as devices, sensors, etc.), and it has the following characteristics: Real-time data collection: The digital twin object model needs to collect data from physical entities in real time. This usually involves sensor technology, IoT devices, etc. The data collection frequency and accuracy directly affect the accuracy and real-time performance of the digital twin model. Data transmission network: The selection of the data transmission network is crucial for the performance of the digital twin object model. It needs to support high-speed, low-latency data transmission while ensuring data security and reliability. Technologies such as 5G networks and fiber optic networks are widely used in this field. Data processing and analysis: The collected data needs to be processed through data processing and analysis technologies. Data synchronization and update: The digital twin object model needs to be synchronized and updated according to real-time data.

[0004] However, among the above characteristics, a significant problem is the insufficient consideration of security. Although IoT devices usually have certain security measures (such as data encryption and authentication), they still face the risks of data leakage and unauthorized access when exchanging data with the platform. Summary of the Invention

[0005] Embodiments of this application provide a data transmission method based on a digital twin object model for a smart city to improve the security of data transmission through authentication at the digital twin entity granularity.

[0006] To achieve the above objective, this application adopts the following technical solutions: In a first aspect, a data transmission method based on a digital twin object model for a smart city is provided, which is applied to a receiving-end device. The receiving-end device is an interface gateway in a BIM / CIM platform. The method includes: the receiving-end device receives data of the digital twin object model transmitted by a sending-end device. The sending-end device is an object model, and the data of the digital twin object model includes data of digital twin entities at different levels; the receiving-end device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin object model. The some levels of digital twin entities are digital twin entities that associate upper and lower levels in the digital twin object model; when it is determined through authentication that the identity information of the digital twin entity is trustworthy, the receiving-end device sends the data of the digital twin object model to a backend device in the BIM / CIM platform.

[0007] Optionally, the digital twin entities at different levels include digital twin element entities at the first level, digital twin component entities at the second level, and digital twin system entities at the third level. Among them, the digital twin element entity represents a digital twin single object model, the digital twin component entity is constructed based on the digital twin element entity, the digital twin component entity represents a digital twin scenario object model, the digital twin system entity is constructed based on the digital twin component entity, and the digital twin system entity represents a digital twin city-level object model.

[0008] Optionally, the data of the digital twin element entity includes basic information, attributes, behaviors, and events. The data of the digital twin component entity includes the capabilities of the digital twin scenario object model, and the data of the digital twin system entity includes sensing system data, decision system data, and notification system data. Optionally, the data of the digital twin system entity further includes data of an orientation perception system.

[0009] Optionally, the receiving-end device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin object model, including: the receiving-end device authenticates the identity information of the digital twin component entity according to the data of the digital twin component entity and the secret key of the sending-end device.

[0010] Optionally, the digital twin component entity is M digital twin component entities, where M is an integer greater than 2. The receiving device authenticates the identity information of the digital twin component entity based on the data of the digital twin component entity and the secret key of the sending device, including: for the i-th digital twin component entity among the M digital twin component entities, where i traverses odd numbers from 1 to M: The receiving device obtains the preset identity token in the data of the i-th digital twin component entity; The receiving device generates identity authentication information based on the capability description field in the data of the i-th digital twin component entity and the secret key of the sending device; The receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the i-th digital twin component entity is trusted through authentication. Otherwise, the identity information of the i-th digital twin component entity is not trusted.

[0011] Optionally, the following relationship is satisfied among the capability description field in the data of the i-th digital twin component entity, the secret key of the sending device, and the preset identity token: AUTN = [(capability description ⊕ f5(K)) || RAND || f1(K, capability description, RAND) = MAC1] Wherein, the preset identity token is AUTN, the capability description field is capability description, ⊕ represents exclusive OR, K is a temporary key derived based on the secret key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; The secret key of the sending device is the long-term key in the USIM of the sending device, and the receiving device has the long-term key preset by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, capability description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 is consistent with MAC2. Message Authentication Code (MAC), MAC1 refers to Message Authentication Code 1; MAC2 refers to Message Authentication Code 2.

[0012] Optionally, the receiving device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin model, including: The receiving device authenticates the identity information of the digital twin element entity according to the data of the digital twin element entity and the secret key of the sending device; and, The receiving device authenticates the identity information of the digital twin system entity according to the data of the digital twin system entity and the secret key of the sending device.

[0013] Optionally, the digital twin element entity is N digital twin element entities, where N is an integer greater than 2. The receiving device authenticates the identity information of the digital twin element entity based on the data of the digital twin element entity and the key of the sending device, including: for the j-th digital twin element entity among the N digital twin element entities, where j traverses odd numbers from 1 to N: the receiving device obtains the preset identity token in the data of the j-th digital twin element entity; the receiving device generates identity authentication information based on the event in the data of the j-th digital twin element entity and the key of the sending device; the receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the j-th digital twin element entity is trusted through authentication. Otherwise, the identity information of the j-th digital twin element entity is not trusted.

[0014] Optionally, the following relationship is satisfied among the event in the data of the j-th digital twin element entity, the key of the sending device, and the preset identity token: AUTN = [Events ⊕ f5(K))||RAND||f1(K, Events, RAND) = MAC1] where the preset identity token is AUTN, the event is Events, ⊕ represents exclusive OR, K is a temporary key derived based on the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the receiving device has the long-term key preset by the operator of the USIM; the identity authentication information is MAC2, and MAC2 = f1(K, Events, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0015] Optionally, the receiving device authenticates the identity information of the digital twin system entity based on the data of the digital twin system entity and the key of the sending device. The receiving device obtains the description field of the decision-making system in the data of the digital twin system entity; the receiving device generates identity authentication information based on the description field of the decision-making system and the key of the sending device; the receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the digital twin system entity is trusted through authentication. Otherwise, the identity information of the digital twin system entity is not trusted.

[0016] Optionally, the following relationship is satisfied among the description field of the decision-making system in the data, the key of the sending device, and the preset identity token: AUTN = [Decision description ⊕ f5(K)) || RAND || f1(K, Decision description, RAND) = MAC1] Wherein, the preset identity token is AUTN, the description field of the decision system is Decision description, ⊕ represents exclusive OR, K is a temporary key derived from the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the receiving device is preset with a long-term key by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, Decision description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0017] In a second aspect, a receiving device is provided. The receiving device is an interface gateway in a BIM / CIM platform. The receiving device is configured to: receive the data of the digital twin object model transmitted by the sending device. The sending device is an object model, and the data of the digital twin object model includes the data of digital twin entities at different levels; the receiving device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin object model. The some levels of digital twin entities are digital twin entities that are associated with the upper and lower levels in the digital twin object model; when it is determined through authentication that the identity information of the digital twin entity is trustworthy, the receiving device sends the data of the digital twin object model to the backend device in the BIM / CIM platform.

[0018] Optionally, the digital twin entities at different levels include digital twin element entities at the first level, digital twin component entities at the second level, and digital twin system entities at the third level. Among them, the digital twin element entity represents the digital twin single object model, the digital twin component entity is constructed based on the digital twin element entity, the digital twin component entity represents the digital twin scenario object model, the digital twin system entity is constructed based on the digital twin component entity, and the digital twin system entity represents the digital twin city-level object model.

[0019] Optionally, the data of the digital twin element entity includes basic information, attributes, behaviors, and events, the data of the digital twin component entity includes the capabilities of the digital twin scenario object model, and the data of the digital twin system entity includes sensing system data, decision system data, and notification system data.

[0020] Optionally, the receiving device authenticates the identity information of the digital twin entities at some levels according to the data of the digital twin entities at some levels in the digital twin model, including: the receiving device authenticates the identity information of the digital twin component entity according to the data of the digital twin component entity and the secret key of the sending device.

[0021] Optionally, the digital twin component entity is M digital twin component entities, where M is an integer greater than 2. The receiving device authenticates the identity information of the digital twin component entities according to the data of the digital twin component entities and the secret key of the sending device, including: for the i-th digital twin component entity among the M digital twin component entities, where i traverses the odd numbers from 1 to M: the receiving device obtains the preset identity token in the data of the i-th digital twin component entity; the receiving device generates identity authentication information according to the capability description field in the data of the i-th digital twin component entity and the secret key of the sending device; the receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the i-th digital twin component entity is trusted through authentication. Otherwise, the identity information of the i-th digital twin component entity is not trusted.

[0022] Optionally, the following relationship is satisfied among the capability description field, the secret key of the sending device, and the preset identity token in the data of the i-th digital twin component entity: AUTN = [(capability description ⊕ f5(K)) || RAND || f1(K, capability description, RAND) = MAC1] Wherein, the preset identity token is AUTN, the capability description field is capability description, ⊕ represents exclusive OR, K is a temporary key derived based on the secret key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, f1 represents algorithm f1; the secret key of the sending device is the long-term key in the USIM of the sending device, and the receiving device is preset with the long-term key by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, capability description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 is consistent with MAC2.

[0023] Optionally, the receiving device authenticates the identity information of some levels of digital twin entities according to the data of the digital twin entities at some levels in the digital twin model, including: the receiving device authenticates the identity information of the digital twin element entity according to the data of the digital twin element entity and the key of the sending device; and the receiving device authenticates the identity information of the digital twin system entity according to the data of the digital twin system entity and the key of the sending device.

[0024] Optionally, the digital twin element entity is N digital twin element entities, where N is an integer greater than 2. The receiving device authenticates the identity information of the digital twin element entity according to the data of the digital twin element entity and the key of the sending device, including: for the jth digital twin element entity among the N digital twin element entities, where j iterates through the odd numbers from 1 to N: the receiving device obtains the preset identity token in the data of the jth digital twin element entity; the receiving device generates identity authentication information according to the event in the data of the jth digital twin element entity and the key of the sending device; the receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the jth digital twin element entity is trusted through authentication. Otherwise, the identity information of the jth digital twin element entity is not trusted.

[0025] Optionally, the following relationship holds among the event in the data of the jth digital twin element entity, the key of the sending device, and the preset identity token: AUTN = [Events ⊕ f5(K))||RAND||f1(K, Events, RAND) = MAC1] Wherein, the preset identity token is AUTN, the event is Events, ⊕ represents exclusive OR, K is a temporary key derived based on the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the receiving device is preset with the long-term key by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, Events, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 is consistent with MAC2.

[0026] Optionally, the receiving device authenticates the identity information of the digital twin system entity based on the data of the digital twin system entity and the key of the sending device. The receiving device obtains the description field of the decision-making system in the data of the digital twin system entity; the receiving device generates identity authentication information according to the description field of the decision-making system and the key of the sending device; the receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it means that the authentication is passed and the identity information of the digital twin system entity is determined to be trustworthy. Otherwise, the identity information of the digital twin system entity is not trustworthy.

[0027] Optionally, the following relationship is satisfied among the description field of the decision-making system in the data, the key of the sending device, and the preset identity token: AUTN = [Decision description ⊕ f5(K))||RAND||f1(K, Decision description, RAND) = MAC1] Wherein, the preset identity token is AUTN, the description field of the decision-making system is Decision description, ⊕ represents exclusive OR, K is a temporary key derived from the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the receiving device is preset with the long-term key by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, Decision description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0028] In a third aspect, a computer-readable storage medium is provided, including: a computer program or instruction; when the computer program or instruction runs on a computer, the computer is caused to execute the data transmission method described in the first aspect.

[0029] In a fourth aspect, a computer program product is provided, including: a computer program or instruction, when the computer program or instruction runs on a computer, the computer is caused to execute the data transmission method described in the first aspect.

[0030] In summary, when the receiving device receives the data of the digital twin model transmitted by the sending device, the receiving device authenticates the identity information of the digital twin entities at some levels according to the data of the digital twin entities at some levels in the digital twin model. The digital twin entities at some levels are the digital twin entities that associate the upper and lower levels in the digital twin model, that is, more fine-grained security authentication is realized; when it is determined through authentication that the identity information of the digital twin entity is trustworthy, the receiving device sends the data of the digital twin model to the backend device in the BIM / CIM platform, which can ensure that the data received by the backend device is secure and trustworthy, thereby further improving the security of data transmission. Description of the Drawings

[0031] Figure 1 It is a schematic framework diagram of a data transmission system based on a digital twin model of a smart city provided by an embodiment of the present application; Figure 2 It is a schematic flowchart of a data transmission method based on a digital twin model of a smart city provided by an embodiment of the present application; Figure 3 It is a schematic diagram of the architecture of the model in the data transmission method based on the digital twin model of the smart city provided by the embodiment of the present application. Detailed Embodiments

[0032] First, the technical terms involved in the present application will be introduced below.

[0033] Thing Model: An abstract form for digitally describing entities in the physical world (such as devices, sensors, etc.). It includes various attributes of the entity (such as temperature value, switch state), behaviors (such as start, stop operations), and events (such as fault alarms). Through the thing model, functions such as status monitoring, control, and data analysis of physical entities can be realized.

[0034] Digital Twin: Using digital technology to create a virtual copy of a physical object. This copy can not only reflect the current state and behavior of the physical object, but also predict future behavior trends through simulation. In a smart city, digital twin technology is used to optimize urban planning, management, and service provision by establishing accurate digital models for various components of the city (such as buildings, transportation systems, etc.).

[0035] Building Information Modeling (BIM): A digital representation method used for the design, construction, and management of buildings or infrastructure projects. It not only contains geometric shape information but also includes a large amount of non-geometric attribute information, such as material properties, cost estimates, etc. BIM enables project teams to effectively share information throughout the entire life cycle, thereby improving efficiency, reducing costs, and minimizing errors.

[0036] City Information Modeling (CIM): CIM is an extension of the BIM concept at the urban scale, aiming to construct an integrated urban-level information model. CIM integrates data from different sources (including Geographic Information System (GIS) data, BIM data, etc.) to support a wider range of analysis and decision-making processes. Through CIM, urban managers can better understand urban development dynamics, optimize resource allocation, and promote sustainable development.

[0037] The technical solutions in this application will be described below in conjunction with the accompanying drawings.

[0038] In the embodiments of this application, "indicating" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. If the information indicated by a certain piece of information (such as the first indication information, the second indication information, or the third indication information below, etc.) is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to use the arrangement order of each piece of information pre-agreed (such as stipulated by a protocol) to achieve the indication of specific information, thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by separately indicating the same information.

[0039] In addition, the specific indication method can also be various existing indication methods, such as but not limited to, the above-mentioned indication methods and their various combinations, etc. The specific details of various indication methods can refer to the prior art and will not be elaborated herein. As can be seen from the above description, for example, when it is necessary to indicate multiple pieces of information of the same type, there may be a situation where the indication methods of different pieces of information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiments of the present application do not limit the selected indication method. In this way, the indication methods involved in the embodiments of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.

[0040] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information and sent separately, and the sending periods and / or sending opportunities of these sub-information can be the same or different. The embodiments of the present application do not limit the specific sending method. Among them, the sending periods and / or sending opportunities of these sub-information can be predefined, such as predefined according to a protocol, or can be configured by the sending device by sending configuration information to the receiving device.

[0041] "Predefined" or "pre-configured" can be implemented by pre-saving corresponding codes, tables or other ways that can be used to indicate relevant information in the device. The embodiments of the present application do not limit its specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be separately provided, or can be integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially separately provided and partially integrated in a decoder, a processor, or a communication device. The type of the memory can be any form of storage medium, and the embodiments of the present application do not limit this.

[0042] The "protocol" involved in the embodiments of the present application can refer to a protocol family in the communication field, a standard protocol similar to the frame structure of a protocol family, or a related protocol applied to a future communication system. The embodiments of the present application do not make specific limitations on this.

[0043] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all refer to that the device will make corresponding processing under a certain objective situation, which does not limit the time, and does not require the device to have a judgment action when implementing, nor does it mean that there are other limitations.

[0044] In the description of the embodiments of the present application, unless otherwise specified, " / " means that the objects associated before and after are in an "or" relationship. For example, A / B may represent A or B. The "and / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. Among them, A and B may be singular or plural. Also, in the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or similar expressions refer to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that the terms such as "first" and "second" do not limit the quantity and execution order, and the terms such as "first" and "second" do not necessarily mean different. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way for easy understanding.

[0045] For ease of understanding the embodiments of the present application, first, take Figure 1 the data transmission system based on the digital twin model of a smart city shown in Figure 1 as an example to illustrate in detail the system applicable to the embodiments of the present application. Exemplarily,

[0046] As Figure 1 shown, the data transmission system includes: a sending-end device and a receiving-end device.

[0047] The sending-end device may be a terminal and has the function of collecting data of the digital twin model.

[0048] For example, a terminal can also be referred to as a user equipment (UE), access terminal, subscriber unit, user station, mobile station (MS), mobile device, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication device, user agent, or user equipment. The terminal in the embodiments of the present application can be a mobile phone, cellular phone, smart phone, tablet (Pad), wireless data card, personal digital assistant (PDA), wireless modem, handset, laptop computer, machine type communication (MTC) terminal, computer with wireless transceiver function, virtual reality (VR) terminal, augmented reality (AR) terminal, wireless terminal in industrial control. It should be noted that the transmitting device being a terminal is only an example. For example, the transmitting device can also be an Internet of Things platform, such as the object model in the Internet of Things platform.

[0049] The receiving device can be an interface gateway in the BIM / CIM platform. In other words, the receiving device is an interface exposed to the transmitting device. The transmitting device cannot further perceive other devices in the BIM / CIM platform, such as backend devices, nor can it directly access these devices to ensure data security.

[0050] Please refer to Figure 2 , the embodiments of the present application provide a data transmission method based on the digital twin object model of a smart city. This method can be executed by the receiving device. The process of this method includes: S201, receive the data of the digital twin object model transmitted by the transmitting device.

[0051] The data of the digital twin object model contains data of digital twin entities at different levels.

[0052] For example, as Figure 3 shown, it is a schematic diagram of the architecture of the model in the data transmission method based on the digital twin object model of a smart city. Combining Figure 3 , digital twin entities at different levels include digital twin element entities at the first level, digital twin component entities at the second level, and digital twin system entities at the third level.

[0053] Among them, the digital twin element entity corresponds to an Element, which is the basic functional unit of an Internet of Things device and includes properties, actions, and events. Properties describe the static or dynamic state of a device (such as the "temperature value" property of a temperature and humidity sensor), actions define the operations that a device can perform (such as the "start" and "stop" actions of an air conditioner), and events represent the state changes or anomalies actively reported by a device (such as the "excessive concentration" event of a smoke sensor). As the smallest granularity of the physical model, elements directly map the functions and states of physical devices. For example, the "temperature" property of a temperature and humidity sensor records real-time data, the "switch" action controls the start and stop of the device, and the "threshold alarm" event triggers an anomaly notification. The digital twin element entity represents the digital twin single physical model, or rather, the single physical model. The single physical model is the digital representation that corresponds one-to-one with the actual Internet of Things device. As the basic unit of the entire system, it consists of multiple groups of properties, actions, and events, comprehensively describing the functional characteristics and operating states of the device. Properties are used to depict the static or dynamic information of a device, such as the temperature value of a temperature and humidity sensor, the power consumption of an electric meter, the online status of a camera, etc.; actions represent the operation instructions that a device can execute, such as the switch control of an air conditioner, the opening and closing adjustment of curtains, the remote unlocking of a door lock, etc.; events are the state changes or anomalies actively reported by a device, such as smoke exceeding the standard alarm, power failure notice, device offline reminder, etc. Different types of properties, actions, and events constitute the data basis and functional source of subsequent higher-level models, and are the core basis for realizing device access, management, and linkage.

[0054] The digital twin component entity is built based on the digital twin element entity. The digital twin component entity corresponds to the element component. The element component is a functional module composed of multiple related elements, which describes the subsystem or business unit of the device. For example, the "lighting module" of the smart street lamp integrates elements such as "brightness attributes", "dimming behavior", and "fault events" to form a complete lighting control unit; the "motor module" of industrial equipment aggregates elements such as "speed attributes", "start-stop behavior", and "overload events" to achieve motor status monitoring and control. By encapsulating common logic, components support functional reuse (such as multiple street lamps sharing the same lighting module template) and simplify the modeling process of complex equipment. The digital twin component entity represents the digital twin scenario object model, or the scenario subclass object model, that is, on the basis of the monomer object model, a scenario object model is constructed, which is mainly for small-scale application scenarios such as rooms, homes, and buildings. By combining multiple monomer object models, functional collaboration and business linkage between devices can be achieved. For example, in the home energy-saving scenario, the models of temperature and humidity sensors, air conditioners, curtains and other equipment are integrated together to automatically adjust the operating status of the equipment according to environmental data to achieve energy saving; in the lighting scenario of the office area, the light sensor and human body sensing equipment are combined to realize the intelligent start and stop and brightness adjustment of the lights; in the enterprise fire protection scenario, smoke detectors, alarm devices, exhaust systems, etc. are integrated to form a unified emergency response mechanism. This level emphasizes the abstraction and encapsulation of specific scenario requirements, and organizes the data and capabilities from different monomer models into a complete scenario solution through rule engines or logical orchestration.

[0055] The digital twin system entity is constructed based on the digital twin component entity. The digital twin system entity corresponds to a System, which is an overall model of a group of one or more devices and realizes cross-device collaboration by invoking component capabilities. For example, the "energy management system" in a smart park integrates "lighting components", "air conditioning components", "electric meter components", etc., and coordinates the linkage of multiple devices to optimize energy consumption; the "automation system" on an industrial production line collaborates through "robot arm components", "sensor components", "control components", etc. to complete the closed-loop control of the production process. The system constructs complex business logics through the association relationships between components. For example, it automatically adjusts the air conditioning power according to the temperature and humidity sensor data, or dynamically allocates device loads based on the electric meter readings. The digital twin system entity represents the digital twin city-level physical model, or rather, the city-level system physical model. The digital twin city-level physical model is the highest-level city-level physical model, which is integrated and extended on the basis of single-entity and scenario models, faces broader cross-space complex applications, and serves the overall operation and management of a smart city. At this level, the device and scenario sub-physical models in different buildings, communities, and traffic nodes can be uniformly accessed to form a larger-scale digital twin system. For example, the urban traffic physical model can integrate traffic lights, cameras, traffic flow monitoring devices, etc. across intersections and road sections to realize the dynamic optimization of traffic signals and congestion prediction; the urban fire protection physical model improves the overall emergency response ability by connecting resources such as fire alarm systems, drone patrols, and emergency command centers in various regions; the urban energy physical model can be used to coordinate various power, gas, and renewable energy facilities and optimize energy scheduling and allocation. This level not only has powerful data aggregation and analysis capabilities but also supports cross-regional and cross-system intelligent decision-making and collaborative control.

[0056] It can be seen that elements, components, and systems form a hierarchical structure: elements are the basic units responsible for raw data collection; components are aggregations of elements that achieve functional modularization; and systems are integrations of components that support cross-device collaboration. Data flow and control flow are passed step by step between levels - elements provide underlying data, components process logic, and systems coordinate globally. Through standardized interfaces (such as the TSL language) and dynamic binding mechanisms (such as loading components on demand), the physical model supports the unified access, flexible expansion, and efficient operation of heterogeneous devices, ultimately achieving seamless modeling and management from single devices to complex systems. Correspondingly, the three levels of the digital twin single physical model, the digital twin scenario physical model, and the digital twin city-level physical model form a complete system from micro to macro and from local to whole. The single physical model provides basic data support, the scenario model realizes local functional closed-loop, and the city-level model is responsible for global coordination and optimization. Data interaction and instruction transmission are carried out between the three through standardized interfaces, forming a unified operation mechanism from device perception to scenario linkage and then to urban governance. This hierarchical and progressive, gradually abstracted structure not only improves the scalability and flexibility of the digital twin system but also provides a solid technical foundation for the evolution of IoT applications from single-point intelligence to system intelligence.

[0057] On this basis, the data of digital twin element entities includes basic information (such as the static information of physical devices (such as device ID, model), dynamic states (such as temperature values, power consumption), and geometric and spatial information of physical devices (such as coordinates, orientations), etc.), attributes, behaviors, and events. The data of digital twin component entities includes the capabilities of the digital twin scenario physical model, that is, describing what functions the scenario physical model has, such as the function of adjusting the operating state of a device, the function of alarming, etc. Specifically, it can include a capability description field (that is, describing what kind or type of capability this is) and the content of the capability (that is, the specific description of the capability). And the data of digital twin system entities includes sensing system data (specifically, it can include a description field of the sensing system, that is, indicating that it is a sensing system, and the content description of the sensing system, that is, the specific functions implemented by the sensing system), decision system data (specifically, it can include a description field of the decision system, that is, indicating that it is a decision system, and the content description of the decision system, that is, the specific functions implemented by the decision system), and notification system data (specifically, it can include a description field of the notification system, that is, indicating that it is a notification system, and the content description of the notification system, that is, the specific functions implemented by the notification system).

[0058] S202, the receiving device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin physical model.

[0059] These some levels of digital twin entities are the digital twin entities that associate the upper and lower levels in the digital twin physical model.

[0060] For example, the receiving-end device authenticates the identity information of the digital twin component entity based on the data of the digital twin component entity and the key of the sending-end device. The following is a specific introduction.

[0061] In a possible way, the digital twin component entity is M digital twin component entities, where M is an integer greater than 2.

[0062] On this basis, for the i-th digital twin component entity among the M digital twin component entities, i traverses the odd numbers from 1 to M: The receiving-end device obtains the preset identity token in the data of the i-th digital twin component entity. It should be understood that the data of the digital twin model is encrypted during transmission. For example, the TLS 1.3 protocol is used for end-to-end encryption during the data transmission process. However, the identity authentication information for identity information authentication is not encrypted during transmission, but the identity authentication information itself is information protected by integrity, such as including the following Message Authentication Code (MAC) 1 to prevent being tampered with.

[0063] Thus, the receiving-end device generates identity authentication information based on the capability description field in the data of the i-th digital twin component entity (specifically, it can be the preset identity token) and the key of the sending-end device. The receiving-end device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it means that the identity information of the i-th digital twin component entity is trusted through authentication. Otherwise, the identity information of the i-th digital twin component entity is not trusted. For example, the following relationship is satisfied among the capability description field, the key of the sending-end device, and the preset identity token in the data of the i-th digital twin component entity.

[0064] AUTN = [(capability description ⊕ f5(K)) || RAND || f1(K, capability description, RAND) = MAC1] Among them, the preset identity token is AUTN, the capability description field is capability description, ⊕ represents exclusive OR, K is a temporary key derived based on the key of the sending-end device and RAND, f5 represents the algorithm f5 (i.e., one of the key algorithms), RAND is a random number, an 8-bit random number randomly generated by the sending-end device, f1 represents the algorithm f1 (i.e., one of the key algorithms); the key of the sending-end device is the long-term key in the USIM of the sending-end device, and the receiving-end device has the long-term key preset by the operator of the USIM.

[0065] It should be understood that capability description⊕f5(K) indicates that it is a hidden capability description, avoiding directly passing the plaintext capability description in the pre-set identity token. For the receiving device, the receiving device can perform an exclusive OR operation on the hidden capability description and f5(K) to obtain the plaintext capability description. In this way, the receiving device can generate identity authentication information, such as the identity authentication information being MAC2, and MAC2 = f1(K, capability description, RAND).

[0066] In this way, determining whether the identity authentication information is consistent with the pre-set identity token means determining whether MAC1 and MAC2 are consistent.

[0067] It should also be understood that the above K is derived from the long-term key without leaving the USIM, which can avoid the risk of long-term key exposure. In addition, using the long-term key to derive K is to reuse the current security mechanism on the terminal side, which can simplify the security design logic while improving security and avoid introducing new security mechanisms that are not conducive to the implementation on the terminal side.

[0068] It should also be understood that since the digital twin component entity is in the second layer and is associated with the first and third layers, if security risks occur, such as information being tampered with or forged, then the overall model cannot be realized. Therefore, the second layer can be the key layer and is also the data most likely to be attacked. At this time, authenticating the identity information of the second layer can avoid this security risk.

[0069] In another possible way, the receiving device authenticates the identity information of the digital twin element entity based on the data of the digital twin element entity and the key of the sending device; and the receiving device authenticates the identity information of the digital twin system entity based on the data of the digital twin system entity and the key of the sending device.

[0070] For example, the digital twin element entity is N digital twin element entities, where N is an integer greater than 2. For the j-th digital twin element entity among the N digital twin element entities, j traverses the odd numbers from 1 to N: The receiving device obtains the pre-set identity token in the data of the j-th digital twin element entity; The receiving device generates identity authentication information based on the event in the data of the j-th digital twin element entity and the key of the sending device; The receiving device determines whether the authentication information is consistent with the preset identity token. If the authentication information is consistent with the preset identity token, it indicates that the identity information of the j-th digital twin element entity is trusted through authentication; otherwise, the identity information of the j-th digital twin element entity is not trusted. Among them, the following relationship is satisfied among the events in the data of the j-th digital twin element entity, the key of the sending device, and the preset identity token: AUTN = [Events ⊕ f5(K))||RAND||f1(K, Events, RAND) = MAC1] Among them, the preset identity token is AUTN, the event is Events, ⊕ represents exclusive OR, K is a temporary key derived from the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the receiving device has a long-term key preset by the operator of the USIM; The authentication information is MAC2, and MAC2 = f1(K, Events, RAND); In this way, determining whether the authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0071] In addition, the receiving device obtains the description field of the decision-making system (it should be understood that it is taken as an example of the decision-making system, but it is not a limitation. For example, it can also be a sensing system or a notification system) in the data of the digital twin system entity.

[0072] The receiving device generates authentication information based on the description field of the decision-making system and the key of the sending device. The receiving device determines whether the authentication information is consistent with the preset identity token. If the authentication information is consistent with the preset identity token, it indicates that the identity information of the digital twin system entity is trusted through authentication; otherwise, the identity information of the digital twin system entity is not trusted. Among them, the following relationship is satisfied among the description field of the decision-making system in the data, the key of the sending device, and the preset identity token: AUTN = [Decision description ⊕ f5(K))||RAND||f1(K, Decision description, RAND) = MAC1] Among them, the preset identity token is AUTN, the description field of the decision-making system is Decision description, ⊕ represents exclusive OR, K is a temporary key derived from the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the receiving device has a long-term key preset by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, Decision description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0073] It should be understood that the specific principle in another possible way can also refer to the relevant introduction in the above-mentioned one possible way, and will not be elaborated here.

[0074] It should also be understood that since the digital twin element entity and the digital twin system entity are respectively in the first layer and the third layer, if only the data in the first layer is tampered with or forged, it may not affect the overall function of the model. However, if the data in the third layer is tampered with or forged, it will affect the overall function of the model. Considering security, therefore, the identity information authentication can be performed on the whole of the first layer and the third layer.

[0075] It should also be understood that the above-mentioned generation of identity authentication information and the preset identity token usually use description fields. The specific reason is that the information content of the description field itself is private enough, but does not involve specific content and has little information, so it can be used for authentication. Of course, for events where the information content is private and not much, it can also be used for authentication.

[0076] S203. When it is determined through authentication that the identity information of the digital twin entity is trustworthy, the receiving end device sends the data of the digital twin model to the backend device in the BIM / CIM platform.

[0077] The backend device can import the data of the digital twin model into BIM / CIM for modeling to implement the functions of the digital twin model.

[0078] In summary, when the receiving end device receives the data of the digital twin model transmitted by the sending end device, the receiving end device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin model. These levels of digital twin entities are the digital twin entities that associate the upper and lower levels in the digital twin model, that is, more fine-grained security authentication is achieved; when it is determined through authentication that the identity information of the digital twin entity is trustworthy, the receiving end device sends the data of the digital twin model to the backend device in the BIM / CIM platform, which can ensure that the data received by the backend device is safe and trustworthy, thereby further improving the security of data transmission.

[0079] In this embodiment, a receiving device is further provided. The receiving device is an interface gateway in the BIM / CIM platform, and the receiving device is configured to: receive the data of the digital twin object model transmitted by the sending device, where the data of the digital twin object model includes the data of digital twin entities at different levels; the receiving device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin object model, and the some levels of digital twin entities are digital twin entities that are associated with upper and lower levels in the digital twin object model; when it is determined through authentication that the identity information of the digital twin entity is credible, the receiving device sends the data of the digital twin object model to the backend device in the BIM / CIM platform.

[0080] Optionally, the digital twin entities at different levels include digital twin element entities at the first level, digital twin component entities at the second level, and digital twin system entities at the third level. Among them, the digital twin element entity represents the digital twin single object model, the digital twin component entity is constructed based on the digital twin element entity, the digital twin component entity represents the digital twin scenario object model, the digital twin system entity is constructed based on the digital twin component entity, and the digital twin system entity represents the digital twin city-level object model.

[0081] Optionally, the data of the digital twin element entity includes basic information, attributes, behaviors, and events, the data of the digital twin component entity includes the capabilities of the digital twin scenario object model, and the data of the digital twin system entity includes sensing system data, decision system data, and notification system data.

[0082] Optionally, the receiving device authenticates the identity information of some levels of digital twin entities according to the data of some levels of digital twin entities in the digital twin object model, including: the receiving device authenticates the identity information of the digital twin component entity according to the data of the digital twin component entity and the secret key of the sending device.

[0083] Optionally, the digital twin component entity is M digital twin component entities, where M is an integer greater than 2. The receiving device authenticates the identity information of the digital twin component entities based on the data of the digital twin component entities and the secret key of the sending device, including: for the i-th digital twin component entity among the M digital twin component entities, where i traverses odd numbers from 1 to M: The receiving device obtains the preset identity token in the data of the i-th digital twin component entity; The receiving device generates identity authentication information based on the capability description field in the data of the i-th digital twin component entity and the secret key of the sending device; The receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the i-th digital twin component entity is trusted through authentication. Otherwise, the identity information of the i-th digital twin component entity is not trusted.

[0084] Optionally, the following relationship holds among the capability description field in the data of the i-th digital twin component entity, the secret key of the sending device, and the preset identity token: AUTN = [(capability description ⊕ f5(K))||RAND||f1(K, capability description, RAND) = MAC1] Where, the preset identity token is AUTN, the capability description field is capability description, ⊕ represents exclusive OR, K is a temporary key derived based on the secret key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the secret key of the sending device is the long-term key in the USIM of the sending device, and the receiving device has the long-term key preset by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, capability description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0085] Optionally, the receiving device authenticates the identity information of some levels of digital twin entities based on the data of some levels of digital twin entities in the digital twin model, including: The receiving device authenticates the identity information of the digital twin element entity based on the data of the digital twin element entity and the secret key of the sending device; and, The receiving device authenticates the identity information of the digital twin system entity based on the data of the digital twin system entity and the secret key of the sending device.

[0086] Optionally, the digital twin element entity is N digital twin element entities, where N is an integer greater than 2. The receiving device authenticates the identity information of the digital twin element entity based on the data of the digital twin element entity and the key of the sending device, including: for the j-th digital twin element entity among the N digital twin element entities, where j iterates over odd numbers from 1 to N: The receiving device obtains the preset identity token in the data of the j-th digital twin element entity; The receiving device generates identity authentication information based on the event in the data of the j-th digital twin element entity and the key of the sending device; The receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the j-th digital twin element entity is trusted through authentication. Otherwise, the identity information of the j-th digital twin element entity is not trusted.

[0087] Optionally, the following relationship is satisfied among the event in the data of the j-th digital twin element entity, the key of the sending device, and the preset identity token: AUTN = [Events ⊕ f5(K)) || RAND || f1(K, Events, RAND) = MAC1] Wherein, the preset identity token is AUTN, the event is Events, ⊕ represents exclusive OR, K is a temporary key derived based on the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; The key of the sending device is the long-term key in the USIM of the sending device, and the receiving device has the long-term key preset by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, Events, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0088] Optionally, the receiving device authenticates the identity information of the digital twin system entity based on the data of the digital twin system entity and the key of the sending device. The receiving device obtains the description field of the decision-making system in the data of the digital twin system entity; The receiving device generates identity authentication information based on the description field of the decision-making system and the key of the sending device; The receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it indicates that the identity information of the digital twin system entity is trusted through authentication. Otherwise, the identity information of the digital twin system entity is not trusted.

[0089] Optionally, the following relationship is satisfied among the description field of the decision-making system in the data, the key of the sending device, and the preset identity token: AUTN = [Decision description ⊕ f5(K)) || RAND || f1(K, Decision description, RAND) = MAC1] Among them, the preset identity token is AUTN, the description field of the decision system is Decision description, ⊕ represents exclusive OR, K is a temporary key derived from the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the receiving device is preset with the long-term key by the operator of the USIM; The identity authentication information is MAC2, and MAC2 = f1(K, Decision description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

[0090] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer program or instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0091] It should be understood that in various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0092] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0093] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.

[0094] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be electrical, mechanical, or other forms.

[0095] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0096] In addition, the functional units in each embodiment of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.

[0097] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0098] As described above, the above are only specific implementation manners of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims.

Claims

1. A data transmission method based on a digital twin biological model of a smart city, characterized in that, Applied to a receiving device, the receiving device being an interface gateway in a BIM / CIM platform, the method includes: The receiving device receives data of a digital twin object model transmitted by a sending device, the sending device being an object model, and the data of the digital twin object model includes data of digital twin entities at different levels; The receiving device authenticates the identity information of the digital twin entities at some levels according to the data of the digital twin entities at some levels in the digital twin object model, and the digital twin entities at some levels are digital twin entities associated with upper and lower levels in the digital twin object model; When it is determined through authentication that the identity information of the digital twin entity is trustworthy, the receiving device sends the data of the digital twin object model to a backend device in the BIM / CIM platform.

2. The data transmission method according to claim 1, wherein The digital twin entities at different levels include digital twin element entities at the first level, digital twin component entities at the second level, and digital twin system entities at the third level. Among them, the digital twin element entity represents a digital twin single object model, the digital twin component entity is built based on the digital twin element entity, the digital twin component entity represents a digital twin scenario object model, the digital twin system entity is built based on the digital twin component entity, and the digital twin system entity represents a digital twin city-level object model.

3. The data transmission method according to claim 2, wherein The data of the digital twin element entity includes basic information, attributes, behaviors, and events. The data of the digital twin component entity includes the capabilities of the digital twin scenario object model, and the data of the digital twin system entity includes sensing system data, decision system data, and notification system data.

4. The data transmission method according to claim 2 or 3, characterized in that, The receiving device authenticates the identity information of the digital twin entities at some levels according to the data of the digital twin entities at some levels in the digital twin object model, including: The receiving device authenticates the identity information of the digital twin component entity according to the data of the digital twin component entity and the secret key of the sending device.

5. The data transmission method according to claim 4, characterized in that, The digital twin component entity is M digital twin component entities, M being an integer greater than 2. The receiving device authenticates the identity information of the digital twin component entity according to the data of the digital twin component entity and the secret key of the sending device, including: For the i-th digital twin component entity among the M digital twin component entities, i traverses odd numbers from 1 to M: The receiving device obtains a preset identity token in the data of the i-th digital twin component entity; The receiving device generates identity authentication information according to the capability description field in the data of the i-th digital twin component entity and the secret key of the sending device; The receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it means that it is determined through authentication that the identity information of the i-th digital twin component entity is trustworthy. Otherwise, the identity information of the i-th digital twin component entity is not trustworthy.

6. The data transmission method according to claim 5, wherein The following relationship is satisfied among the capability description field in the data of the i-th digital twin component entity, the key of the sending device, and the preset identity token: AUTN = [(capability description ⊕ f5(K))||RAND||f1(K, capability description, RAND) = MAC1] Wherein, the preset identity token is AUTN, the capability description field is capability description, ⊕ represents exclusive OR, K is a temporary key derived based on the key of the sending device and RAND, f5 represents algorithm f5, RAND is a random number, and f1 represents algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the long-term key is preset by the operator of the USIM for the receiving device; The identity authentication information is MAC2, and MAC2 = f1(K, capability description, RAND); Determining whether the identity authentication information is consistent with the preset identity token means determining whether MAC1 and MAC2 are consistent.

7. The data transmission method according to claim 2 or 3, characterized in that The receiving device authenticates the identity information of the digital twin entities at some levels according to the data of the digital twin entities at some levels in the digital twin model, including: The receiving device authenticates the identity information of the digital twin element entity according to the data of the digital twin element entity and the key of the sending device; And, the receiving device authenticates the identity information of the digital twin system entity according to the data of the digital twin system entity and the key of the sending device.

8. The data transmission method according to claim 7, wherein The digital twin element entity is N digital twin element entities, N is an integer greater than 2, and the receiving device authenticates the identity information of the digital twin element entity according to the data of the digital twin element entity and the key of the sending device, including: For the j-th digital twin element entity among the N digital twin element entities, j traverses the odd numbers from 1 to N: The receiving device obtains the preset identity token in the data of the j-th digital twin element entity; The receiving device generates identity authentication information according to the event in the data of the j-th digital twin element entity and the key of the sending device; The receiving device determines whether the identity authentication information is consistent with the preset identity token. If the identity authentication information is consistent with the preset identity token, it means that the identity information of the j-th digital twin element entity is trusted through authentication. Otherwise, the identity information of the j-th digital twin element entity is not trusted.

9. The data transmission method according to claim 8, characterized in that The following relationship is satisfied among the event in the data of the j-th digital twin element entity, the key of the sending device, and the preset identity token: AUTN = [(Events ⊕ f5(K))||RAND||f1(K, Events, RAND) = MAC1] Among them, the pre-set identity token is AUTN, the event is Events, ⊕ represents exclusive OR, K is a temporary key derived from the key of the sending device and RAND, f5 represents the algorithm f5, RAND is a random number, and f1 represents the algorithm f1; the key of the sending device is the long-term key in the USIM of the sending device, and the long-term key is pre-set by the operator of the USIM for the receiving device; The identity authentication information is MAC2, and MAC2 = f1(K, Events, RAND); Determining whether the identity authentication information is consistent with the pre-set identity token means determining whether MAC1 and MAC2 are consistent.

10. The data transmission method according to claim 7, characterized in that The receiving device authenticates the identity information of the digital twin system entity according to the data of the digital twin system entity and the key of the sending device, including: The receiving device obtains the description field of the decision-making system in the data of the digital twin system entity; The receiving device generates identity authentication information according to the description field of the decision-making system and the key of the sending device; The receiving device determines whether the identity authentication information is consistent with the pre-set identity token. If the identity authentication information is consistent with the pre-set identity token, it means that the identity information of the digital twin system entity is trusted through authentication. Otherwise, the identity information of the digital twin system entity is not trusted.

Citation Information

Patent Citations

  • User recognizing module, authentication center, authentication method and system

    CN101378582A

  • Digital twin processing method and device and machine readable medium

    CN113689574A

  • Authority management method suitable for twinborn application

    CN115549964A

  • Smart city management system and method based on digital twinborn technology

    CN117113428A

  • Key management method, system and equipment for digital twinning service and medium

    CN118827086A