Method, system, device and storage medium for segmented dynamic encryption transmission of building data

By encrypting building data in segments and upgrading the encryption key under abnormal circumstances, and establishing data segment associations based on associated keys, the security problem of building data transmission is solved, and dynamic security defense and data transmission reliability are improved.

CN120474844BActive Publication Date: 2025-09-09SUZHOU ZHIZAIYUN DATA TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510970034.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-15
Publication Date
2025-09-09
Estimated Expiration
2045-07-15

AI Technical Summary

Technical Problem

Building data can be easily stolen or tampered with during transmission, and existing technologies cannot effectively guarantee transmission security.

Method used

A segmented dynamic encryption transmission method for building data is adopted. By receiving transmission instructions, the data is segmented and encryption keys are configured. The transmission process is monitored in real time. The encryption keys are upgraded in abnormal situations, and association keys are used to establish associations between data segments to achieve dynamic security defense.

Benefits of technology

It realizes the dynamic defense of "the more attacks, the safer" under abnormal circumstances, reduces the risk of data transmission leakage, and improves the security and reliability of building data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474844B_ABST
    Figure CN120474844B_ABST
Patent Text Reader

Abstract

The present application relates to a method, system, device, and storage medium for segmented dynamic encryption transmission of building data, which belongs to the field of data transmission technology. The method includes: receiving a transmission instruction, segmenting the global data to be transmitted to obtain a number of data segments, configuring an encryption key for each data segment, and using the encryption key to encrypt the corresponding data segment; transmitting the data segment, and monitoring the transmission process of the data segment in real time, and determining whether there is an abnormality, wherein the abnormality refers to a situation where the data segment transmission fails; if an abnormality exists, upgrading the encryption keys of the data segments other than the data segment corresponding to the abnormality, and re-encrypting the corresponding data segment using the upgraded encryption key. The present application has the effect of optimizing the transmission security of building data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data transmission, and in particular to a method, system, device and storage medium for segmented dynamic encryption transmission of building data. Background Art

[0002] With the acceleration of the digital transformation of the construction industry, building data is experiencing explosive growth. Current mainstream building data transmission technologies include TCP / IP-based wired transmission, low-power wide area network (WAN) wireless transmission like LoRa, and 5G mobile communication transmission. While these technologies are driving the intelligent development of the construction industry, they also face increasingly severe data security challenges. Specifically, building data is susceptible to theft or tampering during transmission, compromising its security. Therefore, a method for securely transmitting building data is urgently needed. Summary of the Invention

[0003] In order to optimize the transmission security of building data, the present application provides a method, system, device and storage medium for segmented dynamic encryption transmission of building data.

[0004] In a first aspect, the present application provides a method for segmented dynamic encryption transmission of building data, comprising:

[0005] receiving a transmission instruction, segmenting the global data to be transmitted into a plurality of data segments, configuring an encryption key for each data segment, and encrypting the corresponding data segment using the encryption key;

[0006] Transmitting the data segment, and monitoring the transmission process of the data segment in real time, and determining whether there is an abnormality, wherein the abnormality refers to a situation where the data segment fails to be transmitted;

[0007] If there is an abnormal situation, the encryption keys of the data segments other than the data segment corresponding to the abnormal situation are upgraded, and the corresponding data segments are re-encrypted using the upgraded encryption keys.

[0008] By adopting the above technical solution, abnormal situations are used as trigger conditions for key upgrades, and when abnormal situations occur, other data segments are upgraded and encrypted to achieve dynamic defense of "the more attacks, the safer it is". Single-point abnormalities trigger global security upgrades, realizing dynamic security enhancement of the data transmission process and reducing the risk of data transmission leakage.

[0009] Optionally, the method further includes:

[0010] Each of the data segments is also configured with an associated key, and an association between the data segments is established through the associated key;

[0011] The upgrading of the encryption keys of the data segments other than the data segment corresponding to the abnormal situation includes:

[0012] Determine the abnormal data segment where the abnormal situation occurs, and the associated data segment that has an associated relationship with the abnormal data segment, revoke the association between the associated data segment and the abnormal data segment, and upgrade the encryption key of the associated data segment based on the association key corresponding to the revoked association relationship.

[0013] By adopting the above technical solution, associations between data segments are established through associated keys, so that when an abnormal situation occurs, the data segment that needs to be encrypted and upgraded can be accurately locked through the associated keys, and the logical connection between the abnormal data segment and the associated data segment can be disconnected. The upgraded encryption key is derived from the invalid associated key, thereby ensuring that the new and old keys are associated but cannot be reversed, thereby realizing cascade encryption.

[0014] Optionally, the data segment includes a real data segment carrying the building data in the transmission instruction, and a virtual data segment not containing the building data in the transmission instruction;

[0015] The establishing of associations between data segments using association keys further includes:

[0016] By using an association key, the virtual data segment is associated with the real data segment, and an associated data segment set is established for the virtual data segment according to the association relationship; wherein the associated data segment set stores all the real data segments associated with the same virtual data;

[0017] The transmitting the data segment comprises:

[0018] According to the preset transmission scheme, the corresponding virtual data segments are transmitted first, and then the real data segments contained in the corresponding associated data segment set are transmitted;

[0019] monitoring, in real time during the transmission process, transmission results of the virtual data segment and each real data segment in the associated data segment set, wherein the transmission results at least include a determination result of an abnormality;

[0020] Based on the transmission result, a status assessment is performed on the corresponding channel, and a transmission plan is updated and executed according to the status assessment result; wherein the status assessment result at least includes a channel security level, and the transmission plan at least includes a transmission frequency for data segments within a corresponding associated data segment set.

[0021] By employing the above technical solution, virtual data segments are interspersed with real data segments, and the virtual data segments are used to detect channel security. The transmission scheme is then adjusted based on the detection results, and the transmission results of the virtual data segments are used to determine whether to trigger the encryption upgrade of the real data segments. Therefore, it can be seen that the use of virtual data segments for detection in this solution can further reduce the risk of real data leakage.

[0022] Optionally, associating the virtual data segment with the real data segment and establishing an associated data segment set for the virtual data segment based on the association relationship includes:

[0023] In real time, all real data segments in a preset sliding window are used to generate an associated data segment set, and the associated data segment set is associated with the virtual data segment; wherein, the real data segments in the sliding window are real data segments transmitted by a preset channel, and whenever any real data segment completes transmission, the sliding window slides forward to update the real data segments in the sliding window.

[0024] By adopting the above technical solution, a sliding window is configured for the virtual data segment, and the sliding window slides forward as the transmission of the real data segment is completed. The variable label is updated according to the sliding progress of the sliding window, so that the real data segment associated with the virtual data segment can be dynamically adjusted, that is, one virtual data segment can be associated with multiple real data segments, and the association relationship will automatically switch with the transmission of the real data segment, thereby realizing the multiplexing of virtual data segments and reducing the transmission of redundant virtual data segments.

[0025] Optionally, determining the abnormal data segment where the abnormal situation occurs, and the associated data segment associated with the abnormal data segment, revoking the association between the associated data segment and the abnormal data segment, and upgrading the encryption key of the associated data segment based on the association key corresponding to the revoked association, includes:

[0026] Determining an abnormal data segment where an abnormal situation occurs, and revoking the validity of a key associated with the abnormal data segment;

[0027] If the abnormal data segment is a real data segment, all real data segments in the same associated data segment set as the abnormal data segment are used as associated data segments, and the encryption keys of all the associated data segments are upgraded using the invalid associated key;

[0028] If the abnormal data segment is a virtual data segment, all real data segments in the associated data segments corresponding to the abnormal data segment are used as associated data segments, and the encryption keys of all the associated data segments are upgraded using the invalid associated keys.

[0029] By adopting the above technical solution and combining it with the above solution, it can be seen that whenever an abnormal situation occurs, the data segments related to it (real data segments and / or abnormal data segments) will be upgraded once. In other words, the number of upgrades of the encryption key is proportional to the number of times the abnormal situation occurs, and each upgrade is based on the invalid associated key.

[0030] Optionally, the real data segment is formed by combining several data slices;

[0031] The updating and executing of the transmission plan according to the status evaluation result also includes:

[0032] According to the channel congestion situation and the channel security level contained in the status assessment result, for the real data segments in the associated data segment set, the data shards of adjacent real data segments are migrated and reorganized to update the real data segments, and the updated real data segments contain common data shards with the real data segments before the update.

[0033] By adopting the above technical solution, the real data segments are reorganized according to the congestion situation to adjust the size of the real data segments. For example, when the channel status is poor, the data size of the real data segments is reduced to minimize the number of data fragment losses to better utilize limited bandwidth resources. When the channel status is good, the data segment size is appropriately increased to reduce segmentation overhead, thereby achieving an adaptive balance between transmission efficiency and security.

[0034] Optionally, the method further includes:

[0035] Regularly identify risk periods based on the occurrence of abnormal situations in historical periods;

[0036] Whenever the transmission instruction is received, the transmission time of each data segment is determined according to the importance of the data segment and the latest determined risk period, so that the transmission time of the data segment with higher importance has a greater time difference with the risk period.

[0037] By adopting the above technical solution, the transmission time of the data segments is adjusted according to the importance of the data segments, so as to reduce the probability of transmission abnormalities occurring in data segments with higher importance.

[0038] In a second aspect, the present application provides a segmented dynamic encryption transmission system for building data, comprising:

[0039] A data segmentation encryption module is used to receive a transmission instruction, segment the global data to be transmitted into a number of data segments, configure an encryption key for each data segment, and use the encryption key to encrypt the corresponding data segment;

[0040] a data anomaly monitoring module, configured to transmit the data segment, monitor the transmission process of the data segment in real time, and determine whether an anomaly occurs, wherein the anomaly refers to a failure in the transmission of the data segment;

[0041] The data encryption upgrade module is used to upgrade the encryption keys of data segments other than the data segment corresponding to the abnormal situation if there is an abnormal situation, and use the upgraded encryption key to re-encrypt the corresponding data segment.

[0042] In a third aspect, the present application provides a device for segmented dynamic encryption transmission of building data, comprising a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and execute any method described in the first aspect.

[0043] In a fourth aspect, the present application provides a computer-readable storage medium storing a computer program that can be loaded by a processor and execute any of the methods described in the first aspect.

[0044] In summary, this application includes at least one of the following beneficial technical effects:

[0045] In this application, abnormal situations are used as trigger conditions for key upgrades. When abnormal situations occur, other data segments are upgraded and encrypted to achieve dynamic defense of "the more attacks, the more secure". Single-point abnormalities trigger global security upgrades, achieving dynamic security enhancement of the data transmission process and reducing the risk of data leakage.

[0046] Furthermore, association keys are used to establish associations between data segments, so that when an abnormal situation occurs, the data segment that needs to be encrypted and upgraded can be accurately locked through the association keys, and the logical connection between the abnormal data segment and the associated data segment can be disconnected. The upgraded encryption key is derived from the invalid association key, thereby ensuring that the new and old keys are associated but cannot be reversed, thereby realizing cascade encryption. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0048] Figure 1 It is a flow chart of the method for segmented dynamic encryption transmission of building data disclosed in an embodiment of the present application.

[0049] Figure 2 It is a structural block diagram of the building data segmented dynamic encryption transmission system disclosed in the embodiment of this application.

[0050] Description of the accompanying drawings: 201, data segmentation encryption module; 202, data anomaly monitoring module; 203, data encryption upgrade module. DETAILED DESCRIPTION

[0051] The following is combined with Figure 1-2 This application is described in further detail.

[0052] The present application discloses a method for segmented dynamic encryption transmission of building data (hereinafter referred to as the encryption transmission method), which aims to encrypt and transmit building data, improve the security of building data during transmission, and reduce the risk of data leakage. The execution subject of the encryption transmission method is a segmented dynamic encryption transmission system for building data (hereinafter referred to as the encryption transmission system). Figure 1 Specifically explain the specific execution steps of the encrypted transmission system for the encrypted transmission method.

[0053] S101, receiving a transmission instruction, segmenting the global data to be transmitted into a number of data segments, configuring an encryption key for each data segment, and encrypting the corresponding data segment using the encryption key.

[0054] Each data segment is also configured with an associated key, and the association between the data segments is established through the associated key.

[0055] And further, the data segments include real data segments that carry the building data in the transmission instruction, and virtual data segments that do not contain the building data in the transmission instruction;

[0056] The step of “establishing associations between data segments using association keys” further includes the following sub-steps:

[0057] By using an association key, all real data segments in a preset sliding window are converted into an associated data segment set in real time, and the associated data segment set is associated with a virtual data segment; wherein, the real data segment in the sliding window is a real data segment transmitted by a preset channel, and whenever any real data segment completes transmission, the sliding window slides forward to update the real data segment in the sliding window.

[0058] In implementation, a user can access the encrypted transmission system via a webpage and trigger a transmission instruction, which involves uploading the global data to be transmitted and recipient information; the global data specifically refers to building data. The encrypted transmission system is configured to segment the global data into a number of data segments X1, X2, ..., Xn based on its size (e.g., segmentation is achieved through semantic segmentation of BIM building IDs). Each data segment may be assigned an ID number, which identifies the corresponding data segment and describes the correspondence between the data segments. After the global data is transmitted to the recipient, the data segments can be recombined to form the global data based on the correspondence between the ID numbers. Prior to transmission, the present application further proposes encrypting each data segment.

[0059] Accordingly, each data segment corresponds to a hierarchical key structure, which specifically includes a master key, an encryption key, and an association key. The master key is the root key of the encrypted transmission system and can be generated based on the national secret SM2 key agreement protocol. The master key is used to derive the encryption key and association key. The encryption key is used to encrypt the content of the corresponding data segment to form ciphertext, while the association key is used to establish and define the association between data segments.

[0060] Specifically, the encrypted transmission system derives an encryption key for each data segment based on the master key and a preset key derivation function (such as HKDF-SHA256), and then uses the encryption key to encrypt the corresponding data segment. The encryption algorithm can be AES-256, National Encryption SM4 and other existing algorithms. The specific encryption method is an existing technology and will not be elaborated on.

[0061] The encrypted transmission system derives the association key based on the master key and the ID of the data segment to be associated (such as Ri, i=1, 2, 3...) through a preset key derivation function (such as HMAC-SHA256). In combination with the above, it can be seen that the data segments of this application are specifically divided into real data segments containing the building data in the transmission instruction and virtual data segments that do not contain the building data in the transmission instruction. The association key is mainly used to establish the association relationship between the virtual data segment and the real data segment. Therefore, the encrypted transmission system needs to first determine the real data segment to be associated with the virtual data segment (that is, the associated data segment set mentioned above, such as [R1, R2, R3], where R1, R2, and R3 all represent real data segments), and then generate the association key through HMAC operation based on the ID list of the real data segments included in the associated data segment set. For example, an association key LK_V1 is generated for the virtual data segment V1, and LK_V1=HMAC(Masterkey, "R1|| R2|| R3||"), and write linked_frags: ["R1", " R2", "R3"], and write the virtual data segment ID (such as V1) into the header of each real data segment in the associated data segment set, thereby establishing an association relationship between the virtual data segment V1 and the real data segments R1, R2, and R3. In addition to the association key LK, the virtual data segment header also needs to include a list of real data segment IDs corresponding to the associated data segment set and the LK digital signature (such as Ed25519 (LK||nonce), where nonce is a timestamp or encrypted random number, which can be generated based on a hardware entropy source).

[0062] It should be noted here that the present application can preset multiple channels to transmit data segments, and each channel can be preset with a virtual data segment and a sliding window. The sliding window is used to slide forward with the transmission of the data segments transmitted in the corresponding channel. For example, every time the transmission of a data segment is completed, the sliding window slides forward once, and the data segments in the sliding window are the data segment set to be transmitted in the corresponding channel. Therefore, the present application proposes to use the sliding window to determine the associated data segment set, that is, all data segments in the sliding window constitute an associated data segment set, and each time the sliding window slides forward and the data segments in the corresponding associated data segment set are updated, the associated key before the sliding window slides forward is used as the HMAC input to generate a new associated key, thereby updating the associated key, and the original associated key will be invalidated, and then the association relationship between the corresponding virtual data segment and the real data segment in the associated data segment set is re-established based on the updated associated key, thereby realizing the dynamic association between the virtual data segment and the real data segment.

[0063] S102 , transmitting the data segment, and monitoring the transmission process of the data segment in real time, and determining whether there is an abnormality, wherein the abnormality refers to a situation where the data segment transmission fails.

[0064] The step of "transmitting data segments" further includes the following sub-steps:

[0065] S1021, according to a preset transmission scheme, the corresponding virtual data segment is transmitted first, and then the real data segment included in the corresponding associated data segment set is transmitted;

[0066] S1022, monitoring in real time during the transmission process the transmission result of the virtual data segment and each real data segment in the associated data segment set, wherein the transmission result at least includes a determination result of an abnormality;

[0067] S1023, perform status evaluation on the corresponding channel based on the transmission result, and update and execute the transmission plan according to the status evaluation result; wherein the status evaluation result at least includes the channel security level, and the transmission plan at least includes the transmission frequency of the data segments in the corresponding associated data segment set.

[0068] In practice, after implementing data segmentation and establishing a binding relationship between real data segments and virtual data segments using the aforementioned scheme, the real data segments are then transmitted according to a preset transmission scheme. Specifically, the preset transmission scheme includes: based on the correspondence between preset channels, virtual data segments, sliding windows, and associated data segment sets, all real data segments to be transmitted are grouped according to a preset number of channels, with the number of groupings corresponding to the preset number of channels. The transmission order of the virtual data segments and real data segments is then selected in real time based on the channel state assessment results of the preset channels. For example, if the associated data segment set is [R1, R2, R3], then R1, R2, and R3 will sequentially enter the corresponding channels for transmission according to the sliding progress of the sliding window. However, during this process, the corresponding virtual data segment V1 will be interspersed. For example, if the transmission order is defined as: V1, R1, V1, R2, V1, R3, it can be understood that V1 is transmitted once before each of R1, R2, and R3; or, alternatively, the transmission order is defined as: V1, R1, R2, V1, R3. The frequency of interleaving virtual data segments in the transmission process of real data segments (such as interleaving every i real data segments, i ≥ 1, the smaller i is, the higher the corresponding interleaving frequency) will depend on the channel state.

[0069] Specifically, the encrypted transmission system is used to monitor the transmission process in real time during each transmission of virtual data segments and real data segments, such as deploying probes at the transport layer (such as TCP retransmission counter) and the application layer (such as custom heartbeat packets) at the same time to monitor the transmission duration or whether there are any abnormal conditions. Abnormal conditions refer to situations where data segment transmission fails, which can specifically include the following types of abnormal conditions: packet loss (such as the receiver fails to receive the data segment), verification failure (such as CRC or hash value mismatch), and active security alarms (such as IDS detecting a man-in-the-middle attack); the corresponding transmission results at least include whether there are any abnormal conditions and the transmission time.

[0070] Accordingly, the encrypted transmission system pre-sets several transmission time ranges and the corresponding channel congestion level for each transmission time range. Therefore, by determining the corresponding transmission time range based on the transmission time in the transmission result, the channel congestion level for the current preset channel can be derived. Furthermore, the encrypted transmission system pre-stores the data segment transmission frequency f1 corresponding to each channel congestion level. The data segment transmission frequency represents the time interval between the completion of transmission of the previous data segment and the start of transmission of the next data segment on the preset channel. Here, the data segment is either a real data segment or a virtual data segment.

[0071] In addition, the encrypted transmission system also stores the deduction points corresponding to each type of abnormal situation. On the basis of the preset score (such as 100), if an abnormal situation occurs, the security score is calculated based on the corresponding abnormal situation type and the corresponding deduction points. The security score = preset score - the deduction point corresponding to the abnormal situation type corresponding to the abnormal situation that occurs; the corresponding encrypted transmission system also stores several security score ranges, and the interspersed frequency f2 of the virtual data segment corresponding to each security score range corresponding to different channel congestion levels during the transmission of the real data segment; the encrypted transmission system can determine a transmission scheme with transmission frequency f1 and interspersed frequency f2 based on the transmission results of the real-time transmitted data segment. The encrypted transmission system updates the preset transmission scheme in real time according to the determined transmission scheme, thereby realizing the update of the transmission scheme, so that the transmission of real data segments and virtual data segments can be performed based on the updated transmission scheme.

[0072] It should be noted here that, in this application, each real data segment in the default associated data segment set will be entered into the corresponding preset channel for transmission in sequence according to the ID number, and only when the transmission of a real data segment or a virtual data segment is completed will the next real data segment or virtual data segment be transmitted. That is, at the same time, there is only one data segment in the preset channel, and the data segment can be a real data segment or a virtual data segment.

[0073] S103: If an abnormality exists, the encryption keys of the data segments other than the data segment corresponding to the abnormality are upgraded, and the corresponding data segments are re-encrypted using the upgraded encryption keys.

[0074] The “upgrading the encryption keys of the data segments other than the data segment corresponding to the abnormal situation” in S103 further includes the following sub-steps:

[0075] Determine the abnormal data segment where the abnormal situation occurs, and revoke the validity of the key associated with the abnormal data segment;

[0076] If the abnormal data segment is a real data segment, all real data segments in the same associated data segment set as the abnormal data segment are used as associated data segments, and the encryption keys of all associated data segments are upgraded using the invalid associated key;

[0077] If the abnormal data segment is a virtual data segment, all real data segments in the associated data segments corresponding to the abnormal data segment are used as associated data segments, and the encryption keys of all associated data segments are upgraded using the invalid associated key.

[0078] In implementation, when the encrypted transmission system is used to detect an abnormal situation, the data segment with the abnormal situation will be regarded as an abnormal data segment. The situation where the data segment has an abnormal situation can be specifically divided into two situations: virtual data segment abnormality and real data segment abnormality.

[0079] When a virtual data segment is abnormal, the encryption transmission system will immediately revoke the validity of the associated key of the virtual data segment, that is, mark the corresponding associated key as invalid. At this time, the encryption transmission system will generate a new virtual data segment to re-inherit the associated data segment set associated with the abnormal data segment, and generate a new hierarchical key structure for it (that is, including the master key, encryption key and associated key); and use all real data segments in the associated data segment set associated with the abnormal data segment as associated data segments, and use the invalid associated key to upgrade the encryption keys of all associated data segments.

[0080] When a real data segment is abnormal, the encryption transmission system will make all other real data segments except the current abnormal data segment and the corresponding virtual data segments contained in the associated data segment set where the abnormal data segment is located as associated data segments, and at the same time mark the associated key of the abnormal data segment as invalid, and use the invalid associated key to upgrade the encryption keys of all associated data segments.

[0081] Exemplarily, the method for implementing encryption key upgrade using associated keys is as follows:

[0082] When the associated key LK becomes invalid, it will be XORed with the hash value of the abnormal data segment ID as the input seed for deriving the new encryption key IEK_new. The old IEK hash value (such as old_iek_hash) and the upgrade proof (proof) will be embedded in the corresponding data segment header for verification by the receiver. The proof is the HMAC signature of the new encryption key IEK_new and the old IEK hash value using the master key. The receiver locally derives IEK_new using the same HKDF parameters and verifies the legitimacy of the proof field.

[0083] Exemplarily, when the abnormal data segment is the virtual data segment V3, the encryption keys IEK of R5, R6, and R7 in the corresponding associated data segment set are required.

[0084] At this time, the sender's operations are:

[0085] IEK_R5_new=HKDF(LK_V3⊕sha256("V3_Tampered"),

[0086] Write old_iek_hash and proof into the header of the real data segment R5;

[0087] Use IEK_R5_new to encrypt the building data in the real data segment R5. Similarly, update the encryption keys for R6 and R7.

[0088] The receiver's operations are:

[0089] Synchronously derive IEK_R5_new, verify the proof, and use IEK_R5_new to decrypt subsequent data. Similarly, derive, verify, and decrypt the encryption keys for R6 and R7.

[0090] In other embodiments, in addition to the invalidation of the associated key of the abnormal data segment due to an abnormal situation, the associated key will also be updated as the sliding window advances, thereby causing the associated key before the update to become invalid. At this time, the invalid associated key can also be used to upgrade the encryption keys of all real data segments in the corresponding associated data segment set, so as to achieve multiple encryption upgrades of the real data segment before the real data segment is transmitted, thereby further improving its transmission security.

[0091] Optionally, the real data segment is formed by combining several data slices.

[0092] Before "updating and executing the transmission plan based on the status assessment results" in S1023, the following also applies:

[0093] According to the channel congestion situation and the channel security level included in the status assessment result, for the real data segments in the associated data segment set, the data shards of adjacent real data segments are migrated and reorganized to update the real data segments, and the updated real data segments contain common data shards with the real data segments before the update. The data shards are arranged in a preset order. For example, data segment R1 is divided into three data shards R1_1, R1_2, and R1_3, which can be expressed as (R1_1, R1_2, R1_3).

[0094] In implementation, the real data segment is further divided into several data fragments based on the above-mentioned segmentation method. Accordingly, whenever the channel status of the preset channel is obtained based on the transmission result evaluation, the encrypted transmission system is also used to readjust the data fragmentation structure of each real data segment based on the arrangement order of the real data segment in the associated data segment set and the arrangement order of the data segments contained in each real data segment, and then realize transmission according to the updated transmission plan based on the adjusted data segment.

[0095] Exemplarily, when there is the following associated data segment set: [(R1_1, R1_2, R1_3), (R2_1, R2_2, R2_3, R2_4), (R3_1, R3_2, R3_3)], the corresponding encrypted transmission system pre-stores a data segment size threshold corresponding to each channel congestion level. Based on the above correspondence, the encrypted transmission system determines the corresponding data size threshold according to the currently determined channel congestion level. The data size threshold refers to the data size value of the largest data segment that can be transmitted within a preset transmission time range based on the current preset channel congestion level. The encrypted transmission system is configured to, based on the determined data size threshold and in the order in which the data segments in the associated data segment set are transmitted, sequentially determine whether each real data segment is larger than the data size threshold. If larger than the data size threshold, the data fragment of the corresponding data segment (hereinafter referred to as the target data segment) is migrated to an adjacent, subsequent data segment until the data size of the target data segment is no larger than the data size threshold. The migration operation is performed sequentially in the order of migrating the corresponding data fragments from back to front. If R1 is the target data segment, R1_3 will be migrated to R2 first. If the data size of R1 (R1_1, R1_2) after migration is not greater than the data size threshold, then determine whether the data size of R2 after migration is greater than the data size threshold. Similarly, if the last real data segment in the associated data segment set needs to be migrated out of the data shard to make its data size no greater than the data size threshold, then the data shard at the migration location will be migrated out of the associated data segment set and migrated to other data segments that have not yet entered the associated data segment set.

[0096] In addition, when the encrypted transmission system determines whether each real data segment is larger than the data size threshold in sequence according to the order in which the data segments in the associated data segment set are transmitted, if the size of the real data segment Ri is smaller than the data size threshold, then for all data fragments contained in the real data segment Ri+1, the sizes of the data fragments in the real data segment Ri+1 are sequentially compared with the difference between Ri and the data size threshold in the order from front to back according to the preset order (i.e., Ri+1_1, Ri+1_2, Ri+1_3). For example, if the size of the real data segment Ri is much smaller than the data size threshold, , Ri+1_1 is smaller than the difference between the size of the real data segment Ri and the data size threshold, then Ri+1_1 is migrated to Ri, and the difference between the size of Ri and the data size threshold of the migrated Ri is recalculated each time after the previous one, and then the recalculated difference is compared with the first data fragment (i.e., Ri+1_2) of the previous Ri+1. When the difference is smaller than the size of the first data fragment, the reorganization of the current real data segment Ri is completed. In summary, through the above two migration methods, the sizes of all real data segments in the associated data segment set can be as close to the data size threshold as possible.

[0097] Optionally, the encrypted transmission method further includes the following steps:

[0098] Regularly identify risk periods based on the occurrence of abnormal situations in historical periods;

[0099] Whenever a transmission instruction is received, the transmission time of each data segment is determined according to the importance of the data segment and the latest determined risk period, so that the transmission time difference between the transmission time and the risk period of the data segment with higher importance is greater.

[0100] In practice, the encrypted transmission system is used to determine abnormal situations and their corresponding occurrence times within a specified time interval (i.e., the historical period described above). Each occurrence time is then used to determine the corresponding risk period. For example, if the occurrence time is T, the risk period is determined to be [Tt, T+t]. Furthermore, the encrypted transmission system is pre-configured to include different building data types and the importance level of each building data type.

[0101] The encrypted transmission system is used to determine the transmission time of each data segment in real time based on the current time and all the latest determined risk time periods each time a transmission instruction is received and the global data is segmented, and the following conditions are met: the transmission time is not within any risk time period, and the time difference between the corresponding data segment and the nearest risk time period is determined according to the importance of the data segment. The higher the importance, the greater the time difference. The corresponding encrypted transmission system pre-stores the time difference value corresponding to the importance of each data type.

[0102] The embodiment of the present application also discloses a building data segmented dynamic encryption transmission system. Figure 2 ,include:

[0103] The data segment encryption module 201 is used to receive a transmission instruction, segment the global data to be transmitted into a number of data segments, configure an encryption key for each data segment, and encrypt the corresponding data segment using the encryption key;

[0104] The data anomaly monitoring module 202 is used to transmit data segments, monitor the transmission process of the data segments in real time, and determine whether there are any anomalies, wherein an anomaly refers to a situation where the data segment transmission fails;

[0105] The data encryption upgrade module 203 is used to upgrade the encryption keys other than the data segment corresponding to the abnormal situation if an abnormal situation exists, and re-encrypt the corresponding data segment using the upgraded encryption key.

[0106] Optionally, each data segment is also configured with an associated key;

[0107] Also included is a data association module for establishing associations between data segments using an association key;

[0108] The data encryption upgrade module 203 is also used to determine the abnormal data segment where the abnormal situation occurs, and the associated data segment that has an associated relationship with the abnormal data segment, revoke the association between the associated data segment and the abnormal data segment, and upgrade the encryption key of the associated data segment based on the associated key corresponding to the revoked association relationship.

[0109] Optionally, the data association module is further configured to associate the virtual data segment with the real data segment using an association key, and to establish an associated data segment set for the virtual data segment based on the association relationship; wherein the associated data segment set stores all real data segments associated with the same virtual data;

[0110] The data anomaly monitoring module 202 is also used to preferentially transmit the corresponding virtual data segment according to a preset transmission plan, and then transmit the real data segment contained in the corresponding associated data segment set; during the transmission process, the transmission results of the virtual data segment and each real data segment in the associated data segment set are monitored in real time, wherein the transmission results at least include the determination results of the abnormal situation; and is also used to perform status evaluation on the corresponding channel based on the transmission results, and update and execute the transmission plan according to the status evaluation results; wherein the status evaluation results at least include the channel security level, and the transmission plan at least includes the transmission frequency of the data segments in the corresponding associated data segment set.

[0111] Optionally, the data association module is also used to generate an associated data segment set from all real data segments in a preset sliding window in real time, and associate the associated data segment set with the virtual data segment; wherein, the real data segment in the sliding window is the real data segment transmitted by the preset channel, and whenever any real data segment completes transmission, the sliding window slides forward to update the real data segment in the sliding window.

[0112] Optionally, the data encryption upgrade module 203 is also used to determine the abnormal data segment where the abnormal situation occurs and revoke the validity of the associated key of the abnormal data segment; if the abnormal data segment is a real data segment, all real data segments in the same associated data segment set as the abnormal data segment are used as associated data segments, and the encryption keys of all associated data segments are upgraded using the invalid associated key; if the abnormal data segment is a virtual data segment, all real data segments in the associated data segment corresponding to the abnormal data segment are used as associated data segments, and the encryption keys of all associated data segments are upgraded using the invalid associated key.

[0113] Optionally, the data anomaly monitoring module 202 is also used to migrate and reorganize data shards of adjacent real data segments in the associated data segment set based on the channel congestion situation and channel security level contained in the status assessment result, so as to update the real data segment, and make the real data segment after the update contain common data shards with the real data segment before the update.

[0114] Optionally, a risk avoidance module is also included, which is used to regularly determine risk periods based on the occurrence time of abnormal situations that occurred in historical periods; whenever a transmission instruction is received, the transmission time of each data segment is determined according to the importance of the data segment and the current latest determined risk period, so that the more important the data segment, the greater the time difference between the transmission time and the risk period.

[0115] An embodiment of the present application also discloses a device for transmitting segmented dynamic encryption of building data. The device includes a memory and a processor. The memory stores a computer program that can be loaded by the processor and execute the above-mentioned method for transmitting segmented dynamic encryption of building data.

[0116] An embodiment of the present application also discloses a computer-readable storage medium, which stores a computer program that can be loaded by a processor and execute the above-mentioned segmented dynamic encryption transmission method for building data. The computer-readable storage medium includes, for example: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.

[0117] It should be noted that, in this document, relational terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.

[0118] The above embodiments are intended only to illustrate the technical solutions of this application and are not intended to limit the scope of protection of this application. Obviously, the embodiments described are only some of the embodiments of this application, not all of them. Based on these embodiments, all other embodiments obtained by persons of ordinary skill in the art without inventive effort are also within the scope of protection to be protected by this application.

Claims

1. A method for segmented dynamic encryption transmission of building data, characterized in that: include: receiving a transmission instruction, segmenting the global data to be transmitted into a plurality of data segments, configuring an encryption key for each data segment, and encrypting the corresponding data segment using the encryption key; Transmitting the data segment, and monitoring the transmission process of the data segment in real time, and determining whether there is an abnormality, wherein the abnormality refers to a situation where the data segment fails to be transmitted; If there is an abnormal situation, the encryption keys of the data segments other than the data segment corresponding to the abnormal situation are upgraded, and the corresponding data segments are re-encrypted using the upgraded encryption keys; Each of the data segments is also configured with an associated key, and an association between the data segments is established through the associated key; The upgrading of the encryption keys of the data segments other than the data segments corresponding to the abnormal situation includes: Determining the abnormal data segment where the abnormal situation occurs and the associated data segment associated with the abnormal data segment, revoking the association between the associated data segment and the abnormal data segment, and upgrading the encryption key of the associated data segment based on the association key corresponding to the revoked association; The data segments include real data segments carrying the building data in the transmission instruction, and virtual data segments not containing the building data in the transmission instruction; The establishing of associations between data segments using association keys further includes: By using an association key, the virtual data segment is associated with the real data segment, and an associated data segment set is established for the virtual data segment according to the association relationship; wherein the associated data segment set stores all the real data segments associated with the same virtual data; The transmitting the data segment comprises: According to the preset transmission scheme, the corresponding virtual data segments are transmitted first, and then the real data segments contained in the corresponding associated data segment set are transmitted; monitoring, in real time during the transmission process, transmission results of the virtual data segment and each real data segment in the associated data segment set, wherein the transmission results at least include a determination result of an abnormality; Based on the transmission result, a status assessment is performed on the corresponding channel, and a transmission plan is updated and executed according to the status assessment result; wherein the status assessment result at least includes a channel security level, and the transmission plan at least includes a transmission frequency for data segments within a corresponding associated data segment set.

2. The method for segmented dynamic encryption transmission of building data according to claim 1, characterized in that: The step of associating the virtual data segment with the real data segment and establishing an associated data segment set for the virtual data segment based on the association relationship includes: In real time, all real data segments in a preset sliding window are used to generate an associated data segment set, and the associated data segment set is associated with the virtual data segment; wherein, the real data segments in the sliding window are real data segments transmitted by a preset channel, and whenever any real data segment completes transmission, the sliding window slides forward to update the real data segments in the sliding window.

3. The method for segmented dynamic encryption transmission of building data according to claim 1, characterized in that: The determining of the abnormal data segment where the abnormal situation occurs and the associated data segment associated with the abnormal data segment, revoking the association between the associated data segment and the abnormal data segment, and upgrading the encryption key of the associated data segment based on the association key corresponding to the revoked association, includes: Determining an abnormal data segment where an abnormal situation occurs, and revoking the validity of a key associated with the abnormal data segment; If the abnormal data segment is a real data segment, all real data segments in the same associated data segment set as the abnormal data segment are used as associated data segments, and the encryption keys of all the associated data segments are upgraded using the invalid associated key; If the abnormal data segment is a virtual data segment, all real data segments in the associated data segment set corresponding to the abnormal data segment are used as associated data segments, and the encryption keys of all the associated data segments are upgraded using the invalid associated key.

4. The method for segmented dynamic encryption transmission of building data according to claim 1, characterized in that: The real data segment is formed by combining several data slices; The updating and executing of the transmission plan according to the status evaluation result also includes: According to the channel congestion situation and the channel security level contained in the status assessment result, for the real data segments in the associated data segment set, the data shards of adjacent real data segments are migrated and reorganized to update the real data segments, and the updated real data segments contain common data shards with the real data segments before the update.

5. The method for segmented dynamic encryption transmission of building data according to claim 1, characterized in that: The method further comprises: Regularly identify risk periods based on the occurrence of abnormal situations in historical periods; Whenever the transmission instruction is received, the transmission time of each data segment is determined according to the importance of the data segment and the latest determined risk period, so that the transmission time of the data segment with higher importance has a greater time difference with the risk period.

6. A building data segmented dynamic encryption transmission system, characterized in that: include, A data segment encryption module (201) is used to receive a transmission instruction, segment the global data to be transmitted to obtain a plurality of data segments, configure an encryption key for each data segment, and encrypt the corresponding data segment using the encryption key; A data anomaly monitoring module (202) is used to transmit the data segment, monitor the transmission process of the data segment in real time, and determine whether an anomaly exists, wherein the anomaly refers to a situation where the data segment transmission fails; A data encryption upgrade module (203) is used to upgrade the encryption keys of other data segments except the data segment corresponding to the abnormal situation if an abnormal situation exists, and re-encrypt the corresponding data segment using the upgraded encryption key; Each data segment is also configured with an associated key; the data segment includes a real data segment carrying the building data in the transmission instruction, and a virtual data segment that does not contain the building data in the transmission instruction; Also included is a data association module for establishing associations between data segments using an association key; The data encryption upgrade module (203) is further used to determine the abnormal data segment where the abnormal situation occurs, and the associated data segment associated with the abnormal data segment, cancel the association between the associated data segment and the abnormal data segment, and upgrade the encryption key of the associated data segment based on the association key corresponding to the canceled association relationship; The data association module is further configured to associate the virtual data segment with the real data segment using an association key, and to establish an associated data segment set for the virtual data segment based on the association relationship; wherein the associated data segment set stores all real data segments associated with the same virtual data; The data anomaly monitoring module (202) is also used to preferentially transmit the corresponding virtual data segment according to a preset transmission scheme, and then transmit the real data segment contained in the corresponding associated data segment set; during the transmission process, the transmission results of the virtual data segment and each real data segment in the associated data segment set are monitored in real time, wherein the transmission results at least include the determination results of the abnormal situation; and is also used to perform a status evaluation on the corresponding channel based on the transmission results, and update and execute the transmission scheme according to the status evaluation results; wherein the status evaluation results at least include the channel security level, and the transmission scheme at least includes the transmission frequency of the data segments in the corresponding associated data segment set.

7. A device for segmented dynamic encryption transmission of building data, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that A computer program is stored which can be loaded by a processor and execute the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Device and method for processing data

    CN104077349A

  • Training method, system and equipment of neural network model for detecting network intrusion

    CN114462588A