Traffic overload data security protection system based on quantum encryption technology
By employing quantum encryption technology and modular design based on iris information verification, the problems of high load, high cost, and leakage risk in traffic overload control data transmission have been solved, achieving a secure closed loop throughout the entire process and ensuring improved data security and processing efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZHEJIANG DODINDZ ELECTRONICS CO LTD
- Filing Date
- 2025-07-07
- Publication Date
- 2026-07-28
AI Technical Summary
Quantum encryption technology has a large application load and high cost in traffic control data transmission. Furthermore, there is a risk of leakage during pre-processing and post-processing, and it cannot respond in a timely manner to data leaks caused by the theft of non-key accounts or system attacks.
The traffic overload control data security protection system based on quantum encryption technology includes a modular design: a creation module receives data and creates static web pages, a monitoring module monitors network security, a verification module verifies data packet security through iris information, an instant access module intercepts and clears static web page data, an extraction module extracts, classifies and stores data, and combines offline database management of iris information and data limit alignment strategies to form a full-process security closed loop.
By using quantum encryption for transmission and iris verification, we ensure the security of data transmission and reception, reduce the risk of data retention, improve system operating efficiency, achieve synergistic optimization of data security and processing performance, and prevent data leakage and unauthorized access.
Smart Images

Figure CN120825313B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data communication technology, specifically to a traffic overload control data security protection system based on quantum encryption technology. Background Technology
[0002] Sub-encryption technology is based on the principles of quantum mechanics and transmits keys through quantum states. Its core advantage is that the key distribution process can detect eavesdropping; once intercepted, the quantum state is altered, ensuring absolute security of encrypted communication, making it suitable for scenarios with high confidentiality requirements.
[0003] The invention patent application with application number 202311609768.4 discloses a data security protection system. The system aims to solve the problem that "the system marks users as key monitoring users or ordinary monitoring users. The system can focus on monitoring the network information data of key monitoring users based on the marking results. However, because it only focuses on some users, it cannot react in time when non-key accounts are stolen or the entire system is attacked, resulting in data leakage."
[0004] However, when quantum encryption technology is applied to the transmission of traffic control data, the sheer volume of this data makes the application of quantum encryption technology burdensome and costly, and there is still a risk of leakage during the preprocessing of traffic control data before transmission and the postprocessing after reception.
[0005] To address this, a traffic overload control data security protection system based on quantum encryption technology was proposed. Summary of the Invention
[0006] In view of the above-mentioned shortcomings of the existing technology, the present invention provides a traffic overload control data security protection system based on quantum encryption technology, which can effectively solve the problems of the existing technology.
[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions;
[0008] This invention discloses a traffic overload control data security protection system based on quantum encryption technology, comprising:
[0009] The system comprises the following modules: a creation module for receiving traffic overload control data, creating static web pages and hyperlinks, and using these static web pages to record the data; a monitoring module for monitoring the network security of the data transmission, and controlling the transmission of data packets based on quantum encryption when the monitoring result is secure; a verification module for collecting iris information of all online system users in the receiving end's backend after receiving and decrypting data packets, comparing the collected iris information with the iris information in each data packet, and verifying the security of the data packet reception scenario based on the comparison result; an instant access module for accessing the static web page hyperlinks in each received data packet, capturing the traffic overload control data presented on the static web page after each hyperlink's corresponding static web page has finished loading, removing the static web page from the server and clearing the associated cached data; and an extraction module for traversing the traffic overload control data images captured in the static web pages and extracting the traffic overload control data from these images.
[0010] Furthermore, the traffic overload control data includes: vehicle weighing data and vehicle image data. Each traffic overload control data is marked with the license plate number of the vehicle from which it originates. The amount of traffic overload control data recorded in each of the static web pages is approximately equal.
[0011] The creation module has an offline database at its lower level. The offline database is used to store the iris information of system users. Each iris information is marked with the corresponding system user name. After each static webpage and its hyperlink are created, the hyperlink and a randomly selected marked iris information are used as the quantum encryption transmission target to perform the transmission operation from the sending end to the receiving end.
[0012] The offline database is integrated into a pre-set computer device. The user's iris information stored in the offline database is only available when the computer device is offline. Authorized users of the computer device have the right to modify, upload, and delete the user's iris information. The computer device is only connected to the network when selecting iris information.
[0013] Furthermore, the traffic overload control data recorded in each of the static web pages is aligned based on a limit alignment strategy to make the amount of traffic overload control data recorded in each of the static web pages approximately equal.
[0014] The limit alignment strategy for the traffic overload control data is as follows:
[0015] A maximum data volume is set for static webpages. Vehicle image data from the received traffic control data is preferentially placed into static webpages. Each time a vehicle image is placed, it checks if the cumulative number of vehicle image data placed on the static webpage exceeds the maximum data volume. If it does not exceed the maximum, the placement of vehicle image data continues. If it exceeds the preset value, the most recently placed vehicle image data is deleted from the static webpage. Then, vehicle weighing data from the traffic control data is used as the placement target. Each time a vehicle weighing data is placed, it checks if the cumulative number of data placed on the static webpage exceeds the maximum data volume. If it does not exceed the maximum, the placement of vehicle weighing data continues. If it exceeds the preset value, the process ends. The remaining traffic control data is recorded by creating new static webpages through the creation module.
[0016] Furthermore, the data packet consists of a static webpage hyperlink recording traffic overload control data and iris information. The data transmission network security monitoring logic in the monitoring module is represented as follows:
[0017]
[0018] In the formula: S represents the network security of data transmission; A′ represents the dynamic entropy index for attack resistance; T′ represents the comprehensive index for transmission stability; E′ represents the device link timeliness and reliability index; M′ represents the security management mechanism evolution index; and S0 represents the security judgment threshold.
[0019] When the network security S of the data transmission network obtained based on equation (1) is true in equation (2), the data transmission network is secure and the transmission operation is performed. Otherwise, the security monitoring of the data transmission network is performed again based on the specified period until the monitoring result is secure, and then the transmission operation is performed.
[0020] Furthermore, the verification module is equipped with a hand-raising unit at its lower level, which is used for system users to electronically raise their hands;
[0021] The collection of iris information and electronic hand-raising operation of all online system users in the receiving end backend are performed on the computer equipment and camera configured for each system user. After all online system users in the receiving end backend raise their hands through the hand-raising unit, the collection operation of system user iris information is triggered synchronously, and all system users execute iris information collection synchronously.
[0022] After the iris information of all system users has been collected, the receiving end decrypts the received data packets, obtains the iris information from each data packet, and simultaneously cleans the obtained iris information to remove duplicate iris information, thus obtaining iris information set A. The iris information collected by the system users is recorded as iris information set B. Iris information set A and iris information set B are then compared.
[0023] Specifically, the iris information obtained from each data packet is cleaned based on the system user name marked by each iris information during the cleaning operation.
[0024] Furthermore, the comparison operation between the iris information set A and the iris information set B involves picking up one iris information from each of the two sets and performing a similarity calculation, so that all combinations of iris information picked up by all picking methods undergo a similarity calculation once.
[0025] When every iris information in iris information set A has a similar item found in iris information set B, the verification module verifies the security of the data packet receiving scenario. When no one or more iris information in iris information set A has a similar item found in iris information set B, the module jumps to the hand-raising unit to reset the operation.
[0026] The verification module triggers the instantaneous access module to run when the verification result is safe.
[0027] Furthermore, the formula for calculating the similarity between two iris images is:
[0028] Iris information, or iris images, involves dividing two iris images into n equal parts. 2 Image blocks;
[0029]
[0030] In the formula: d ij Let be the Euclidean distance between the feature vectors of the corresponding image patches at positions (i, j) in the two iris images; α is the moderating coefficient for the influence of grayscale difference on similarity; D gray β is the average gray value difference between the two iris images; β is the theoretical maximum sum of distances between feature points of all image blocks; γ is the theoretical maximum value of the gray value difference.
[0031] in, In the formula: m is the dimension of the feature vector; Let α be the feature vector of the image patch corresponding to position (i, j) in the two iris images, where α∈(0,1] and β is calculated in advance from the preset iris image samples. The feature points of the image patch include the pixel with the largest difference in grayscale value with the neighboring pixels in the image patch. When SIMM is greater than the preset threshold, it is determined that the iris image from iris information set A is a similar item to the iris image from iris information set B in the two iris images that have performed similarity calculation.
[0032] Furthermore, during the operation of the instant access module, the computer device configured by the user of the system to which the iris information source camera belongs, which contains similar items in the iris information set B, is used for access.
[0033] The operation of capturing traffic overload control data presented on a static webpage is called a screenshot operation. The captured traffic overload control data is stored locally on the computer device that performs the capture operation.
[0034] The static webpage associated cache data includes: browser cache, CDN cache, server-side cache, and proxy server cache;
[0035] The creation module, after completing the creation of static web pages and their hyperlinks, deletes the traffic overload control data corresponding to the traffic overload control data recorded in the static web pages that it receives. When the monitoring module detects that the data transmission network is secure, the data packet is sent in the creation module.
[0036] Furthermore, during the operation of the extraction module, vehicle image data is captured from traffic overload control data, and vehicle weighing data is obtained through text extraction. After the capture and extraction of vehicle image data and vehicle weighing data are completed, the vehicle image data and vehicle weighing data are recombined based on the marking information of the vehicle image data and vehicle weighing data, so that vehicle image data and vehicle weighing data with the same marking information are combined with each other. Based on the combination result, the data are then stored separately in the computer device.
[0037] The extraction module's operations are performed on the computer device, and the computer device disconnects from the network during the static webpage removal and cache data clearing phase of the instant access module.
[0038] Furthermore, the connection methods of the modules in the system include at least the following:
[0039] The creation module is connected to an offline database via a wireless network. The creation module is also connected to a monitoring module and a verification module via a wireless network. The verification module is connected to a hand-raising unit via a wireless network. The verification module is also connected to an instant access module and an extraction module via a wireless network.
[0040] Compared with the known prior art, the technical solution provided by this invention has the following beneficial effects:
[0041] This invention provides a traffic overload control data security protection system based on quantum encryption technology. During operation, the system ensures the security of data transmission and reception by combining quantum encryption transmission with dynamic verification of iris information. It reduces the risk of data retention by removing and clearing the cache after instant access to static web pages. Combined with offline database management of iris information, data limit alignment, and offline extraction, it forms a secure closed loop from transmission to processing. This system not only ensures the integrity and confidentiality of traffic overload control data through multi-dimensional protection mechanisms, but also improves system operating efficiency through dynamic data processing strategies. It achieves synergistic optimization of data security and processing efficiency, effectively preventing data leakage and unauthorized access. Attached Figure Description
[0042] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0043] Figure 1 This is a schematic diagram of a traffic overload control data security protection system based on quantum encryption technology.
[0044] Figure 2 This is a schematic diagram of the system logic architecture in this invention. Detailed Implementation
[0045] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0046] The present invention will be further described below with reference to embodiments.
[0047] Example:
[0048] This embodiment of the traffic overload control data security protection system based on quantum encryption technology, such as Figure 1 As shown, it includes:
[0049] Create a module to receive traffic overload control data, create static web pages and static web page hyperlinks, and use static web pages to record traffic overload control data;
[0050] Traffic overload control data includes: vehicle weighing data and vehicle image data. Each traffic overload control data is marked with the license plate number of the vehicle from which it originates. The amount of traffic overload control data recorded in each static webpage is approximately equal.
[0051] The creation module has an offline database at the lower level. The offline database is used to store the iris information of system users. Each iris information is marked with the corresponding system user name. After each static webpage and its hyperlink are created, the hyperlink and a randomly selected marked iris information are used as the quantum encryption transmission target to perform the transmission operation from the sending end to the receiving end.
[0052] The offline database is integrated into a pre-set computer device. The user's iris information stored in the offline database is only available when the computer device is offline. Authorized users of the computer device have the right to modify, upload, and delete the user's iris information. The computer device is only connected to the network when selecting iris information.
[0053] The traffic overload control data recorded in each static webpage is aligned based on a limit alignment strategy to make the amount of traffic overload control data recorded in each static webpage approximately equal.
[0054] The limit alignment strategy for traffic overload control data is as follows:
[0055] The maximum data volume for static webpages is set. Vehicle image data from the received traffic control data is preferentially placed into static webpages. Each time a vehicle image is placed into a static webpage, it is checked whether the cumulative number of vehicle image data placed in the static webpage exceeds the maximum data volume for static webpages. If it does not exceed the maximum value, the placement of vehicle image data continues. If it exceeds the preset value, the newly placed vehicle image data in the static webpage is deleted. Then, vehicle weighing data from the traffic control data is used as the placement target. Each time a vehicle weighing data is placed, it is checked whether the cumulative number of data placed in the static webpage exceeds the maximum data volume for static webpages. If it does not exceed the maximum value, the placement of vehicle weighing data continues. If it exceeds the preset value, the process ends. The remaining traffic control data is recorded by creating new static webpages through the creation module.
[0056] The monitoring module is used to monitor the network security of data transmission. When the monitoring result is secure, it controls the data packets to be transmitted based on quantum encryption.
[0057] The data packet consists of a static webpage hyperlink recording traffic overload control data and iris information. The network security monitoring logic for data transmission in the monitoring module is represented as follows:
[0058]
[0059] In the formula: S represents the network security of data transmission; A′ represents the dynamic entropy index for attack resistance; T′ represents the comprehensive index for transmission stability; E′ represents the device link timeliness and reliability index; M′ represents the security management mechanism evolution index; and S0 represents the security judgment threshold.
[0060] When the data transmission network security S obtained based on equation (1) is true in equation (2), the data transmission network is secure and the transmission operation is executed. Otherwise, the data transmission network security monitoring is performed again based on the specified period until the monitoring result is secure, and then the transmission operation is executed.
[0061] This formula integrates attack resistance dynamic entropy, transmission stability, device link reliability, and security management evolution indicators, and compares them with security thresholds to judge network security. Its process covers multiple types of risks, ensuring that transmission only occurs when it is safe, and protecting the basic environment.
[0062] The formula for calculating the dynamic entropy index A′ for attack defense is:
[0063]
[0064] In the formula: H is the information entropy of the attack defense situation; n is the number of attack types; p i Let i be the probability of successfully defending against the i-th type of attack;
[0065] The above formula is based on the attack defense information entropy, the number of attack types, and the probability of successfully defending against each attack, reflecting the ability to defend against multiple attacks;
[0066] The formula for calculating the comprehensive transmission stability index T′ is:
[0067]
[0068] Where: σ f The standard deviation of the flow rate; σ is the average flow rate; d The standard deviation of the delay; The mean value is the delay; n is the total number of sample periods (historical periods); w i For weights; l i Let be the packet loss rate in the i-th period;
[0069] Among them, w i The higher the network load for the corresponding period, the larger the value.
[0070] This formula combines the standard deviation and mean of traffic and delay, packet loss rate, and load weight to effectively reflect transmission stability.
[0071] The formula for calculating the device link timeliness reliability index E′ is:
[0072]
[0073] In the formula: F n Number of equipment failures; F t The total operating time of the device or link; L b L represents the number of backup links. m The number of primary links; λ is the dynamic attenuation factor; t is the current running time of the device or link;
[0074] Wherein, the dynamic attenuation factor λ takes a value of 0-1 and can be set according to the aging rate of the equipment, environmental factors, etc., and f(·) is a constraint function. When the value of f is non-zero, f(·) takes the value of In itself, When the value of is zero, f(·) takes a preset minimum value;
[0075] The above formula calculates indicators based on the number of equipment failures, total operating time, the ratio of backup links to primary links, dynamic attenuation factor, and current operating time. It reflects the long-term reliable operation capability of equipment and links. Its calculation principle is that equipment reliability is inversely proportional to the failure frequency and directly proportional to the link redundancy (backup links), and it decays with operating time. The constraint function ensures that it can still be calculated when the backup link is zero. Its rationality is that equipment and links are the hardware foundation of data transmission. Failures, aging, and insufficient redundancy will directly affect the transmission reliability. This formula integrates these hardware characteristics, can accurately assess the reliability of the transmission carrier, and provide hardware-level security for data transmission.
[0076] The formula for calculating the safety management mechanism evolution index M′ is:
[0077]
[0078] In the formula: U s O s S s To verify the number of correctly authenticated users, the number of compliant access operations, and the number of audited security incidents (current status); U t O t S t This represents the total number of authenticated users, the total number of access operations, and the total number of security incidents to be audited (corresponding to a specified time period); k is the management mechanism optimization coefficient; and N is the number of times the management mechanism has been optimized.
[0079] Among them, the management mechanism optimization coefficient k can be determined based on historical optimization data or expert evaluation;
[0080] The above formula calculates the metrics by combining the ratio of the number of correctly authenticated users, the number of compliant access operations, and the number of audited security events to the corresponding total number under the current state, along with the optimization coefficient and the number of optimizations of the management mechanism. This reflects the effectiveness and evolutionary capability of the security management mechanism. The calculation principle is that the value of the management mechanism lies not only in its current operating effect (the proportion of correct operations) but also in its iterative capability (the number of optimizations) as risks change. Its rationality lies in the fact that traffic control data involves sensitive information, and the management mechanism (such as user authentication and access control) needs to dynamically adapt to new risks. The formula evaluates both the current effect and incorporates evolutionary capability, avoiding the one-sidedness of static evaluation and ensuring that the management mechanism continuously adapts to security needs.
[0081] The verification module is used to collect the iris information of all online system users in the background of the receiving end after receiving and decrypting the data packet. The collected iris information of online system users is compared with the iris information in each data packet, and the security of the data packet receiving scenario is verified based on the comparison results.
[0082] The verification module has a hand-raising unit at its lower level, which is used for system users to raise their hands electronically;
[0083] The collection of iris information and electronic hand-raising operation of all online system users in the receiving end backend are performed on the computer equipment and camera configured for each system user. After all online system users in the receiving end backend raise their hands through the hand-raising unit, the collection of iris information of system users is triggered synchronously, and all system users execute iris information collection synchronously.
[0084] After the iris information of all system users has been collected, the receiving end decrypts the received data packets, obtains the iris information from each data packet, and simultaneously cleans the obtained iris information to remove duplicate iris information, thus obtaining iris information set A. The iris information collected by the system users is recorded as iris information set B. Iris information set A and iris information set B are then compared.
[0085] Among them, the iris information obtained from each data packet is cleaned based on the system user name marked by each iris information during the cleaning operation;
[0086] The comparison operation between iris information set A and iris information set B involves picking one iris information from each of the two sets and calculating the similarity, so that all combinations of iris information picked by all picking methods are subjected to a similarity calculation.
[0087] When every iris information in iris information set A has a similar item found in iris information set B, the verification module verifies the security of the data packet receiving scenario. When no one or more iris information in iris information set A has a similar item found in iris information set B, the module jumps to the hand-raising unit to reset the operation.
[0088] The verification module triggers the instantaneous access module to run when the verification result is safe.
[0089] The formula for calculating the similarity between two iris images is:
[0090] Iris information, or iris images, involves dividing two iris images into n equal parts. 2 Image blocks;
[0091]
[0092] In the formula: d ij Let be the Euclidean distance between the feature vectors of the corresponding image patches at positions (i, j) in the two iris images; α is the moderating coefficient for the influence of grayscale difference on similarity; D gray β is the average gray value difference between the two iris images; β is the theoretical maximum sum of distances between feature points of all image blocks; γ is the theoretical maximum value of the gray value difference.
[0093] in, In the formula: m is the dimension of the feature vector; Let α be the feature vector of the image block corresponding to position (i, j) in the two iris images, where α ∈ (0, 1] and β is calculated in advance from the preset iris image samples. The feature points of the image block include the pixel with the largest difference in grayscale value with the adjacent pixels in the image block. When SIMM is greater than the preset threshold, it is determined that the iris image from iris information set A is a similar item to the iris image from iris information set B in the two iris images that have performed similarity calculation.
[0094] By calculating using the above logical formula and combining local features with grayscale distribution to determine similarity, the accuracy of iris matching is effectively improved, ensuring reliable identity verification at the receiving end.
[0095] The instant access module is used to access the static webpage hyperlinks in each received data packet. After the static webpage corresponding to each hyperlink has finished loading, it intercepts the traffic control data presented on the static webpage. After the interception operation is completed, it removes the static webpage from the server and clears the associated cache data of the static webpage.
[0096] During the instant access module's operation phase, access is performed using the computer device configured by the user of the system to which the iris information source camera, which contains similar items in the iris information set B, belongs;
[0097] The operation of capturing traffic overload control data presented on a static webpage is called a screenshot operation. The captured traffic overload control data is stored locally on the computer device that performs the capture operation.
[0098] Static webpage associated cache data includes: browser cache, CDN cache, server-side cache, and proxy server cache;
[0099] The creation module deletes the traffic overload control data corresponding to the traffic overload control data recorded in the static webpage after completing the creation of the static webpage and the creation module deletes the traffic overload control data it receives. When the monitoring module detects that the data transmission network is secure, the data packet is sent in the creation module.
[0100] The extraction module is used to traverse the traffic control data images captured from static web pages and extract traffic control data from the traffic control data images.
[0101] During the extraction module's operation phase, vehicle image data is captured from traffic overload control data, and vehicle weighing data is obtained through text extraction. After the capture and extraction of vehicle image data and vehicle weighing data are completed, the vehicle image data and vehicle weighing data are recombined based on the marking information of the vehicle image data and vehicle weighing data, so that vehicle image data and vehicle weighing data with the same marking information are combined with each other. Based on the combination result, the data are then stored separately in the computer device.
[0102] The operation of the extraction module is performed on the computer device, and the computer device disconnects from the network during the static webpage removal and cache data clearing phase of the instant access module.
[0103] The connection methods for each module in the system should at least include:
[0104] The creation module has an offline database that is interactively connected to via a wireless network. The creation module also has a monitoring module and a verification module that are interactively connected to via a wireless network. The verification module has a hand-raising unit that is interactively connected to via a wireless network. The verification module also has an instant access module and an extraction module that are interactively connected to via a wireless network.
[0105] In this embodiment, the creation module receives traffic overload control data, creates static web pages and static web page hyperlinks, and uses the static web pages to record traffic overload control data. The monitoring module monitors the network security of the data transmission network. When the monitoring result is secure, the data packets are controlled to be transmitted based on quantum encryption. The verification module further receives and decrypts the data packets at the receiving end, collects the iris information of all online system users in the receiving end's background, and compares the collected online system user iris information with the iris information in each data packet. Based on the comparison result, the security of the data packet receiving scenario is verified. Then, the instant access module accesses the static web page hyperlinks in each received data packet. After the static web page corresponding to each hyperlink is loaded, the traffic overload control data presented on the static web page is captured. After the capture operation is completed, the static web page is removed from the server and the associated cached data of the static web page is cleared. Finally, the extraction module traverses the traffic overload control data images captured in the static web page and extracts the traffic overload control data from the traffic overload control data images.
[0106] The system described in the above embodiments ensures the security of traffic control data through multiple layers of protection, including quantum encryption transmission and iris verification. Static web pages are deleted immediately after access, reducing the risk of data leakage. Offline database management of iris information enhances user information security. Accurate data extraction and categorized storage ensure both secure data transmission and reception, as well as data integrity and availability, effectively safeguarding the security of traffic control data throughout the entire process.
[0107] See Figure 2 As shown in the figure, this diagram further illustrates the operational logic architecture of the system in this embodiment.
[0108] The following are application examples of the system described in the above embodiments:
[0109] To strengthen the secure cross-regional transmission and management of overload control data on the XX Expressway, a "Traffic Overload Control Data Security Protection System Based on Quantum Encryption Technology" was deployed. This system enables encrypted transmission, secure verification, and closed-loop management of overload control data between 13 municipal overload control stations and the provincial traffic data center. The system covers the entire process of security protection for vehicle weighing data and vehicle image data, effectively preventing risks such as data transmission leakage and unauthorized access.
[0110] Application process:
[0111] 1. Overload control data collection and static webpage creation (creation module work)
[0112] Weighing equipment at local city and county weight control stations collects real-time weighing data of passing vehicles (e.g., "Ji A·12345 truck, total weight 52 tons"), while high-definition cameras simultaneously capture vehicle image data (including license plate number and full vehicle appearance). All data is marked with the source vehicle's license plate number.
[0113] After receiving the above data, the system creation module allocates data based on the "limit alignment strategy": the maximum data size of a single static webpage is set to 10MB, and vehicle image data (approximately 2MB per image) is placed first. When the data size reaches the 10MB limit after placing 5 images, the remaining data is automatically allocated to a new static webpage; if the image data is insufficient, vehicle weighing data (approximately 0.1MB per image) is added to ensure that the data size of each static webpage is approximately equal.
[0114] After a static webpage is created, the system randomly selects one iris information entry with a username tag (such as the iris information of "Zhang San, provincial data center administrator") from the offline database, binds the static webpage hyperlink to the iris information, and uses it as the target identifier for quantum encrypted transmission.
[0115] The offline database is deployed on a dedicated computer. Administrators can only update iris information when the computer is offline. The computer is temporarily connected to the network when selecting iris information and automatically disconnects after completion, ensuring the security of iris information.
[0116] 2. Network security monitoring and quantum-encrypted transmission (monitoring module in operation)
[0117] The monitoring module of the overload control station monitors the transmission network between itself and the provincial data center in real time. By calculating parameters such as "dynamic entropy of attack resistance" and "comprehensive index of transmission stability" (refer to the system's built-in security judgment formula), it confirms that there are no abnormal attacks on the network and that the link is stable.
[0118] Once the monitoring result is "safe", the system triggers a quantum encryption mechanism to encrypt the data packet containing static webpage hyperlinks and bound iris information, and transmits it to the provincial data center through quantum key distribution technology.
[0119] 3. Security verification at the receiving end (verification module + hand-raising unit operation)
[0120] After the provincial data center receives the data packet, the three online administrators (Zhang San, Li Si, and Wang Wu) initiate an electronic hand-raising operation through the terminal "hand-raising unit," triggering their respective terminal cameras to synchronously collect iris information, forming an iris information set B (including the iris data of Zhang San, Li Si, and Wang Wu).
[0121] The system decrypts the data packet, extracts the iris information set A (i.e., the iris information of "Zhang San" bound when the vehicle overload control station sends the data), and cleans set A by username (removing duplicates and keeping only the iris information of "Zhang San").
[0122] The system compares the iris information in set A with that in set B: each iris image is divided into 256 image blocks, the Euclidean distance and grayscale difference of the feature vectors of the corresponding blocks are calculated, and the similarity formula is used to determine that the iris of "Zhang San" has a high similarity item in set B (similarity > preset threshold 90%), thus verifying the security of the receiving scene.
[0123] 4. Instantaneous access and data capture (operation of the instantaneous access module)
[0124] After successful verification, the system triggers the instant access module to access the static webpage hyperlink in the data packet through Zhang San's terminal.
[0125] After the static webpage loads (displaying "weighing data and images of 5 trucks including Hebei A·12345"), the terminal automatically takes a screenshot and saves the data images.
[0126] After the screenshot is taken, the system immediately deletes the static webpage from the server and clears the browser cache, CDN cache, and server-side cache to ensure that no data remains.
[0127] 5. Data extraction and secure storage (extraction module in operation)
[0128] Zhang San's terminal disconnects from the network. The extraction module extracts vehicle image data from the screenshot image and extracts weighing data (such as "Ji A·12345, 52 tons") through optical character recognition technology.
[0129] The system recombines the vehicle image and the weighing data according to the license plate number (such as binding "the image of Ji A·12345 + 52 tons of data"), and classifies and stores them on the local hard disk of the terminal according to the license plate number, completing the secure landing of overloading control data.
[0130] In summary, during the operation of the system in the above embodiments, through quantum encryption transmission combined with iris information dynamic verification, the security of data transmission and reception scenarios is ensured. The method of removing and clearing the cache immediately after instant access to the static web page is adopted to reduce the risk of data retention. It cooperates with the offline database to manage iris information, data limit alignment, and extraction during network disconnection, etc., forming a full-process security closed-loop from transmission to processing. It not only ensures the integrity and confidentiality of traffic overloading control data through a multi-dimensional protection mechanism, but also improves the system operation efficiency with a dynamic data processing strategy, achieving the collaborative optimization of data security and processing efficiency, and effectively preventing data leakage and illegal access.
[0131] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than limiting it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements will not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A traffic overload control data security protection system based on quantum encryption technology, characterized in that, include: Create a module to receive traffic overload control data, create static web pages and static web page hyperlinks, and use static web pages to record traffic overload control data; The monitoring module is used to monitor the network security of data transmission. When the monitoring result is secure, it controls the data packets to be transmitted based on quantum encryption. The verification module is used to collect the iris information of all online system users in the background of the receiving end after receiving and decrypting the data packet. The collected iris information of online system users is compared with the iris information in each data packet, and the security of the data packet receiving scenario is verified based on the comparison results. The instant access module is used to access the static webpage hyperlinks in each received data packet. After the static webpage corresponding to each hyperlink has finished loading, it intercepts the traffic control data presented on the static webpage. After the interception operation is completed, it removes the static webpage from the server and clears the associated cache data of the static webpage. The extraction module is used to traverse the traffic control data images captured from static web pages and extract traffic control data from the traffic control data images. The traffic overload control data includes: vehicle weighing data and vehicle image data. Each traffic overload control data is marked with the license plate number of the vehicle from which it originates. The amount of traffic overload control data recorded in each of the static web pages is approximately equal. The creation module has an offline database at its lower level. The offline database is used to store the iris information of system users. Each iris information is marked with the corresponding system user name. After each static webpage and its hyperlink are created, the hyperlink and a randomly selected marked iris information are used as the quantum encryption transmission target to perform the transmission operation from the sending end to the receiving end. The offline database is integrated into a pre-set computer device. The user's iris information stored in the offline database is only available when the computer device is offline. Authorized users of the computer device have the right to modify, upload, and delete the user's iris information. The computer device is only connected to the network when selecting iris information.
2. The traffic overload control data security protection system based on quantum encryption technology according to claim 1, characterized in that, The traffic overload control data recorded in each of the static web pages is aligned based on a limit alignment strategy to make the amount of traffic overload control data recorded in each of the static web pages approximately equal. The limit alignment strategy for the traffic overload control data is as follows: A maximum data volume is set for static webpages. Vehicle image data from the received traffic control data is preferentially placed into static webpages. Each time a vehicle image is placed, it checks if the cumulative number of vehicle image data placed on the static webpage exceeds the maximum data volume. If it does not exceed the maximum, the placement of vehicle image data continues. If it exceeds the preset value, the most recently placed vehicle image data is deleted from the static webpage. Then, vehicle weighing data from the traffic control data is used as the placement target. Each time a vehicle weighing data is placed, it checks if the cumulative number of data placed on the static webpage exceeds the maximum data volume. If it does not exceed the maximum, the placement of vehicle weighing data continues. If it exceeds the preset value, the process ends. The remaining traffic control data is recorded by creating new static webpages through the creation module.
3. The traffic overload control data security protection system based on quantum encryption technology according to claim 2, characterized in that, The data packet consists of a static webpage hyperlink recording traffic overload control data and iris information. The data transmission network security monitoring logic in the monitoring module is represented as follows: ; In the formula: For network security of data transmission; Dynamic entropy index for defense against attacks; A comprehensive indicator of transmission stability; For device link timeliness and reliability indicators; As an indicator of the evolution of safety management mechanisms; The threshold for determining safety; Among them, the data transmission network security is obtained based on equation (1). When Equation (2) is true, the data transmission network is secure and the transmission operation is performed. Otherwise, the data transmission network security monitoring is performed again based on the specified period until the monitoring result is secure, and then the transmission operation is performed.
4. The traffic overload control data security protection system based on quantum encryption technology according to claim 3, characterized in that, The verification module is equipped with a hand-raising unit, which is used for system users to raise their hands electronically. The collection of iris information and electronic hand-raising operation of all online system users in the receiving end backend are performed on the computer equipment and camera configured for each system user. After all online system users in the receiving end backend raise their hands through the hand-raising unit, the collection operation of system user iris information is triggered synchronously, and all system users execute iris information collection synchronously. After the iris information of all system users has been collected, the receiving end decrypts the received data packets, obtains the iris information from each data packet, and simultaneously cleans the obtained iris information to remove duplicate iris information, thus obtaining iris information set A. The iris information collected by the system users is recorded as iris information set B. Iris information set A and iris information set B are then compared. Specifically, the iris information obtained from each data packet is cleaned based on the system user name marked by each iris information during the cleaning operation.
5. The traffic overload control data security protection system based on quantum encryption technology according to claim 4, characterized in that, The comparison operation between the iris information set A and the iris information set B involves picking up one iris information from each of the two sets and calculating the similarity, so that all combinations of iris information picked up by all picking methods undergo a similarity calculation. When every iris information in iris information set A has a similar item found in iris information set B, the verification module verifies the security of the data packet receiving scenario. When no one or more iris information in iris information set A has a similar item found in iris information set B, the module jumps to the hand-raising unit to reset the operation. The verification module triggers the instantaneous access module to run when the verification result is safe.
6. The traffic overload control data security protection system based on quantum encryption technology according to claim 5, characterized in that, The formula for calculating the similarity between two iris images is: Iris information, or iris images, involves dividing two iris images evenly into two parts. Image blocks; ; In the formula: Let Euclidean distance be the feature vector representation of the corresponding image patch at position (i, j) in the two iris images; This is the moderating coefficient for the impact of grayscale difference on similarity; The difference in average grayscale values between two iris images; This represents the theoretical maximum sum of distances between feature points in all image patches; This represents the theoretical maximum value of the grayscale difference. in, In the formula: The dimension of the feature vector; Let be the feature vectors of the image patches at positions (i, j) in the two iris images. ∈ (0, 1], The image block feature points are obtained by pre-calculating from preset iris image samples. These feature points include the pixels in the image block with the largest difference in grayscale average value from their neighboring pixels. When the similarity exceeds a preset threshold, it is determined that among the two iris images for which similarity calculation is performed, the iris image from iris information set A is a similar item to the iris image from iris information set B.
7. The traffic overload control data security protection system based on quantum encryption technology according to claim 1, characterized in that, During the operation of the instant access module, access is performed using the computer device configured by the user of the system to which the iris information source camera with similar items in the iris information set B belongs; The operation of capturing traffic overload control data presented on a static webpage is called a screenshot operation. The captured traffic overload control data is stored locally on the computer device that performs the capture operation. The static webpage associated cache data includes: browser cache, CDN cache, server-side cache, and proxy server cache; The creation module, after completing the creation of static web pages and their hyperlinks, deletes the traffic overload control data corresponding to the traffic overload control data recorded in the static web pages that it receives. When the monitoring module detects that the data transmission network is secure, the data packet is sent in the creation module.
8. The traffic overload control data security protection system based on quantum encryption technology according to claim 1, characterized in that, During the operation of the extraction module, vehicle image data is captured from traffic overload control data, and vehicle weighing data is obtained through text extraction. After the vehicle image data and vehicle weighing data are captured and extracted, the vehicle image data and vehicle weighing data are recombined based on the marking information of the vehicle image data and vehicle weighing data, so that vehicle image data and vehicle weighing data with the same marking information are combined with each other. Then, based on the combination result, they are stored separately in the computer device. The extraction module's operations are performed on the computer device, and the computer device disconnects from the network during the static webpage removal and cache data clearing phase of the instant access module.
9. The traffic overload control data security protection system based on quantum encryption technology according to claim 1, characterized in that, The connection methods of each module in the system include at least the following: The creation module is connected to an offline database via a wireless network. The creation module is also connected to a monitoring module and a verification module via a wireless network. The verification module is connected to a hand-raising unit via a wireless network. The verification module is also connected to an instant access module and an extraction module via a wireless network.