Sports exhibition audience cloud information processing method
By utilizing geodetic principles and median time difference key offset, combined with a trusted execution environment, high-precision segmentation and anonymization of sports and exhibition spectator trajectories were achieved. This solved the challenges of trajectory analysis and privacy protection in existing technologies, and improved the system's security and availability.
Patent Information
- Application Number
- CN202511046013.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-29
- Publication Date
- 2025-10-31
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing technologies struggle to achieve high-precision audience trajectory analysis and privacy protection in sports exhibitions, and cloud storage solutions suffer from issues such as chaotic key management and vulnerability to attacks.
By using path segmentation based on geodetic principles, key offset based on median time difference, and cyclic permutation mapping, combined with a trusted execution environment, the anonymity protection and encryption of audience trajectories are achieved.
It improves the segmentation accuracy and privacy protection of trajectory data, reduces the risk of key leakage, enhances the security and availability of the system, and supports flexible data analysis and recovery.
Smart Images

Figure CN120880650A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of information security and cloud computing technology, specifically a method for processing cloud information of sports exhibition attendees. Background Technology
[0002] With the increasing scale of sports and exhibition events, the demand for personnel flow management and audience services at exhibition venues is constantly rising. Traditional methods of audience management rely on manual inspections, camera monitoring, and post-event log analysis, which are insufficient for timely acquisition and processing of massive amounts of audience movement trajectory information, and also cannot conduct high-precision on-site behavior analysis while protecting privacy. In recent years, with the widespread application of technologies such as GPS, Wi-Fi / Bluetooth beacon (BLE), and ultra-wideband (UWB) positioning on smartphones, the indoor and outdoor positioning accuracy of audiences has improved to the meter level or even the decimeter level, and the amount of real-time collected latitude and longitude trajectory data is growing exponentially.
[0003] Most existing solutions, in mixed indoor and outdoor scenarios, simply project latitude and longitude data onto a planar coordinate system (such as East-North-Top coordinates or Mercator projection), and then use Euclidean distance for trajectory segmentation and crowd clustering. Due to the curvature of the Earth and projection distortion, such methods can produce meter-level or even ten-meter-level errors when large-scale or high-precision requirements are needed, thus affecting the accuracy of the segmentation algorithm and the reliability of subsequent trajectory analysis results. Existing audience privacy protection methods mainly rely on differential privacy, k-anonymity, or region blurring techniques to shuffle location data or add noise before statistical analysis. However, these methods often cannot guarantee the recovery of original data when trajectory tracing is needed, creating a contradiction between "difficult to restore" and "insufficient usability." In addition, global encryption or desensitization lacks fine-grained control over the trajectory, failing to achieve a closed-loop process that protects personal privacy while ensuring efficient cloud storage and authorized decryption. Many encryption processes directly use fixed or pseudo-random keys without feature binding for different audiences or different trajectories, leading to chaotic key management and vulnerability to "replay attacks" or "trajectory re-matching" attacks. There is a lack of innovative solutions that combine physical characteristics of the trajectory (such as distance from the Earth's surface) with time-series statistical characteristics (such as median time difference) to synchronously generate dynamic keys. Existing cloud storage often only performs basic access control or transmission encryption, without strictly isolating the original trajectory data from the keys. For example, some solutions store both the encryption key and the original data in a secure cloud area, relying on the cloud service provider's trust chain, but fail to retain a copy of the key in the viewer's terminal or Trusted Execution Environment (TEE), still failing to prevent unauthorized access to the real trajectory by internal personnel or external attacks.
[0004] Therefore, this case aims to propose a cloud information processing method for sports and exhibition attendees. By precisely segmenting the data using physical ground line distance, applying key offset based on median time difference, and employing cyclic permutation mapping, the attendee's trajectory is divided into several segments and their order shuffled, achieving anonymity protection for the complete path. Only the encrypted sequence is stored in the cloud; the original trajectory and key are retained at the attendee's end or in a trusted module, ensuring data privacy and security. Summary of the Invention
[0005] This invention provides a method for processing cloud information of sports exhibition attendees, which helps to solve the problems mentioned in the background art above.
[0006] This invention provides the following technical solution: a method for processing cloud information of sports exhibition attendees, comprising:
[0007] Collect raw latitude and longitude path data of spectators during sports exhibitions and events, and verify the legality and validity of the collected data to form an initial trajectory data set;
[0008] For special scenarios with fewer than two trajectory points, exception handling is performed, including path result setting and direct cloud storage processes;
[0009] Based on the principles of geodesy, the spherical distance between adjacent trajectory points in the trajectory data is calculated and accumulated segment by segment to obtain the total length information of the complete path.
[0010] Based on the preset equidistant segment length parameter, the path data is divided into multiple equidistant path segments, and the boundary index of each path segment is extracted to construct a path segment set.
[0011] Calculate the set of time differences between adjacent trajectory points in each path segment, sort them to obtain the median time difference, and construct the path encryption key index for each viewer based on the sum of the median and the timestamp.
[0012] Construct a segment-level permutation mapping function and its corresponding inverse mapping function based on the key index;
[0013] Based on the key index and permutation function, each segment of path data is encrypted at the segment level, and the encrypted path data is uploaded to the cloud storage system. Only the irreversible encryption result is stored, and the key and the original path data are stored in a trusted execution environment.
[0014] The authorizing party completes segment-level decryption by using preset keys and mapping relationships to recover the complete original path data.
[0015] Optionally, the process of collecting raw latitude and longitude path data of spectators during sports and exhibition activities, and verifying the legality and validity of the collected data to form an initial trajectory data set, specifically includes:
[0016] The audience members were numbered as follows The sampling point number is k∈{1,2,...,K} i};in, K represents the total number of viewers. i The total number of sampling points for the i-th audience member;
[0017] Obtain the original trajectory points of the i-th audience member and form the original path set P. i :
[0018] in, Let λ be the latitude of the k-th sampling point of the i-th audience member; i,k Let t be the longitude of the k-th sampling point of the i-th audience member; i,k The timestamp of the kth sampling point of the i-th viewer;
[0019] Using the WGS-84 ellipsoid, the Earth's average radius R = 6,371,000 meters;
[0020] For each point like or Then delete that point. make K i ←K i -1, and repeat the check until all points are valid or K. i =0;
[0021] If K at this time i <2, execute exception handling;
[0022] If K at this time i ≥2, for all k = 1, 2, ..., K i -1: Check if t i,k+1 ≤t i,k Then delete that point. Update P i With K i Repeat the test until all time increments.
[0023] Optionally, for special scenarios where the number of trajectory points is less than two, exception handling is performed, specifically including:
[0024] When K i <2 o'clock:
[0025] If K i =1, let the encryption result E i =P i Among them, E i Encrypted data for the path of the i-th viewer;
[0026] If Ki =0, let the encryption result be 0.
[0027] (ID) i E i The method ends when the data is stored in the cloud; among which, ID... i This is a unique identifier for the i-th viewer.
[0028] Optionally, the step of calculating the spherical distance between adjacent trajectory points in the trajectory data based on geodetic principles and performing segment-by-segment cumulative processing to obtain the total length information of the complete path specifically includes:
[0029] When K i When ≥2:
[0030] For k = 1, 2, ..., K i -1, calculate the distance d between two adjacent points of the i-th spectator in the k-th segment. i,k :
[0031]
[0032] in, For latitude difference; Δλ i,k =Δλ i,k+1 -Δλ i,k Difference in longitude;
[0033] Set the initial value C of the cumulative distance of the i-th viewer. i,0 =0;
[0034] Calculate the total distance of the i-th audience member before the k-th segment.
[0035] Calculate the total path length of the i-th viewer.
[0036] Optionally, the step of dividing the path data into multiple equidistant path segments according to a preset equidistant segment length parameter, extracting the boundary index of each path segment, and constructing a path segment set specifically includes:
[0037] When K i When ≥2:
[0038] Set the constant for the equidistant segment length to L. e ;
[0039] Calculate the number of path segments for the i-th viewer.
[0040] Obtain the sampling index κ of the end point of the s-th segment for the i-th audience member. i,s =min{k|C i,k ≥sL e}, and let κ i,0 =0, Where s = 1,...,N i -1 is the segment number;
[0041] Construct the set of points of segment s for the i-th audience member.
[0042]
[0043] Optionally, the step of calculating the set of time differences between adjacent trajectory points in each path segment, sorting them to obtain the median time difference, and constructing a path encryption key index for an individual viewer based on the sum of the median and the timestamp, specifically includes:
[0044] When K i When ≥2:
[0045] Calculate the time difference δ of the i-th audience member at the k-th time. i,k =t i,k+1 -t i,k ;
[0046] Construct the set ΔT of all adjacent time differences for the i-th audience member. i ={δ i,k |k=1,...,K i -1};
[0047] Let n = K i -1, and ΔT i Sort in ascending order to get: δ i,(1) ≤δ i,(2) ≤…≤δ i,(n) Where n is the number of differences, used only for median operations; m is the median index;
[0048] Obtain the median time difference of the i-th audience member.
[0049] Calculate the sum of the timestamps of all sampling points for the i-th audience member.
[0050] Construct the encryption key index for the i-th spectator Here, mod represents the modulo operation.
[0051] Optionally, the construction of the segment-level permutation mapping function and its corresponding inverse mapping function based on the key index specifically includes:
[0052] When K i When ≥2:
[0053] Construct the permutation function π for the i-th audience segment i (s)=[(s-1+M i )modN i]+1, s=1,...,N i ;
[0054] Construct the inverse function of the permutation of the i-th audience segment.
[0055]
[0056] Optionally, based on the key index and permutation function, each segment of path data is encrypted at the segment level, and the encrypted path data is uploaded to the cloud storage system, storing only the irreversible encryption result. The key used and the original path data are stored in a trusted execution environment, specifically including:
[0057] When K i When ≥2:
[0058] Construct the encrypted segment sequence of the i-th viewer
[0059] The cloud only stores entries (IDs) i E i );
[0060] Original path P i With key M i The key M is stored in a trusted security module and is not stored in the cloud. i ;
[0061] Unauthorized parties have no right to obtain M i .
[0062] Optionally, the authorized party, through a preset key and mapping relationship, completes segment-level decryption to recover the complete original path data, specifically including:
[0063] When K i When ≥2:
[0064] The licensor obtains (E) i M i );
[0065] Get the set of original path points of the i-th audience member in the s-th segment.
[0066] By connecting all segments of the original path obtained from the i-th viewer, we can obtain the complete original path of the i-th viewer. Where || represents the concatenation of segment sequences.
[0067] The present invention has the following beneficial effects:
[0068] 1. A strict legality and validity verification mechanism is introduced during the audience trajectory collection phase. Geographic coordinates and timestamps are standardized using a unified format, and missing, duplicate, or outdated trajectory points are removed in real time to ensure the quality of data input for subsequent processing. Unlike existing technologies that often directly store raw data or perform only simple cleaning, this solution adds a dual verification step of continuity and geographic coordinate legality. This avoids privacy risks caused by incorrect location and eliminates interference from dirty data in subsequent segmentation, encryption, and key generation, ensuring high reliability and traceability of the entire data processing flow from the source. Furthermore, this verification process can be completed without additional external service support, offering advantages such as flexible deployment and high real-time performance, thus improving the robustness and security of the entire process.
[0069] 2. For special scenarios involving single points or no trajectory points, this solution employs a lightweight abnormal path handling strategy: when there are fewer than two valid trajectory points, the complex encryption process is skipped. Instead, a predefined encrypted result or an empty set is directly output based on the unique identifier and uploaded to the cloud. This avoids the failure of conventional algorithms or ambiguity caused by excessively short trajectory lengths. Compared to existing methods that invariably revert to default behavior or report errors in such scenarios, this solution minimizes algorithmic overhead while ensuring business continuity. It eliminates the impact of invalid data on system performance and ensures the interpretability and consistency of cloud-stored results, thus guaranteeing the high availability of the overall platform.
[0070] 3. This solution employs an ellipsoidal Earth model suitable for engineering applications to accurately calculate the spherical distance between adjacent trajectory points on a local terminal or in a trusted execution environment. The total path length is then obtained through cumulative processing. Compared to traditional systems that commonly use two-dimensional Euclidean distance or approximate calculations ignoring Earth's curvature, this distance assessment method based on geodetic principles significantly reduces errors in long-distance or large-venue scenarios, ensuring the accuracy of segmentation and positioning. Furthermore, by accumulating segmented distances in real time and generating mileage curves, it not only provides a reliable data foundation for subsequent equidistant segmentation but also offers more refined support for platform operators to summarize and statistically analyze audience movement distances and conduct heatmap analysis, thus achieving a good balance between accuracy and performance.
[0071] 4. Based on precise path length, this solution divides the trajectory data into several equidistant path segments using a preset physical distance threshold, and extracts the boundary index of each segment to form a structured segment set. Compared with traditional solutions that divide by a fixed number of sampling points or time intervals, equidistant segmentation can maintain uniform granularity in space, achieving more controllable privacy protection and anonymization effects. Simultaneously, the segment length can be dynamically adjusted according to venue size, positioning accuracy, and real-time requirements, flexibly balancing encryption overhead and privacy strength. This innovation ensures that each path segment stored in the cloud has a consistent physical meaning, which is beneficial for permutation mapping and subsequent analysis and processing, and avoids the trade-offs between practicality and security caused by excessive refinement or coarsening while improving anonymity.
[0072] 5. This scheme calculates the set of time differences between adjacent sampling points within each path segment, and uses the median as a typical time feature. It then combines this median with the sum of all timestamps to generate a key index uniquely bound to the viewer and their trajectory. By using the median instead of the average or random selection for the time differences, it effectively eliminates the interference of occasional jumps or positioning delays on key generation, improving key stability and anti-attack capabilities. Unlike the static keys or simple pseudo-random keys commonly used in existing technologies, the index generation based on time-series features can automatically update the key when the user's actual trajectory changes, achieving tight coupling between the key and the trajectory. This innovation not only enhances the anti-replay and anti-forgery characteristics of the encryption scheme but also provides a verifiable consistency basis for segmented permutation mapping, meeting the requirements of high-security and high-availability application scenarios.
[0073] 6. This scheme performs cyclic permutations on path segment numbers using key indexes, defining a reversible, simple, and efficient segment-level mapping function and its inverse function, achieving anonymized rearrangement of segment order. Compared to traditional methods that use complex block ciphers or symmetric encryption to encrypt the entire path, this scheme's segment-level permutation significantly reduces computational complexity and storage overhead. It also allows for precise control over permutation granularity and mapping rules, and can dynamically adjust permutation offsets as needed to meet the adaptive requirements of different privacy strategies. Furthermore, this mapping structure only requires storing the mapping offset or key index to complete reverse recovery, ensuring the irreversibility of the encrypted path while allowing the authorizing party to accurately reconstruct the original trajectory based on the mapping inverse function, thus balancing security and controllability.
[0074] 7. After implementing the permutation mapping, this solution anonymizes and encrypts the sorted path segment sequence, uploading only the encryption result to the cloud. All keys and original trajectory data are stored in a local trusted execution environment or a dedicated security module. Compared to existing technologies that store keys and encryption results together in the same cloud or rely on third-party key management, this solution achieves physical isolation between the encryption result and the key, greatly reducing the risk of key leakage. The cloud only stores a list of path segments whose true order cannot be restored, providing anonymization support for data analysis and visualization. Simultaneously, it ensures that even if the cloud is compromised, unauthorized individuals cannot obtain any usable trajectory information, meeting high-level security and compliance requirements.
[0075] 8. When the original trajectory needs to be restored, this solution allows the authorized party to controllably decrypt the encrypted path segments in the cloud using pre-saved key indexes and mapping inverse functions in a local or secure environment, and seamlessly connect the segments in the correct order to generate the complete original trajectory. Unlike traditional decryption operations that often require transmitting the key to the cloud or calling remote services, this solution achieves strict control over the key and mapping rules through localized decryption and inverse mapping, avoiding the security risks caused by cross-domain key transmission. Simultaneously, the segment-level recovery mechanism supports selective restoration of portions of the trajectory within a specific time or spatial range, improving data utilization flexibility and audit traceability, and providing a solid foundation for personalized analysis and de-identified sharing. Attached Figure Description
[0076] Figure 1 This is a schematic diagram of the process of the present invention. Detailed Implementation
[0077] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0078] Example, refer to Figure 1 A method for processing cloud information of sports exhibition attendees, comprising:
[0079] Collect raw latitude and longitude path data of spectators during sports exhibitions and events, and verify the legality and validity of the collected data to form an initial trajectory data set;
[0080] For special scenarios with fewer than two trajectory points, exception handling is performed, including path result setting and direct cloud storage processes;
[0081] Based on the principles of geodesy, the spherical distance between adjacent trajectory points in the trajectory data is calculated and accumulated segment by segment to obtain the total length information of the complete path.
[0082] Based on the preset equidistant segment length parameter, the path data is divided into multiple equidistant path segments, and the boundary index of each path segment is extracted to construct a path segment set.
[0083] Calculate the set of time differences between adjacent trajectory points in each path segment, sort them to obtain the median time difference, and construct the path encryption key index for each viewer based on the sum of the median and the timestamp.
[0084] Construct a segment-level permutation mapping function and its corresponding inverse mapping function based on the key index;
[0085] Based on the key index and permutation function, each segment of path data is encrypted at the segment level, and the encrypted path data is uploaded to the cloud storage system. Only the irreversible encryption result is stored, and the key and the original path data are stored in a trusted execution environment.
[0086] The authorizing party completes segment-level decryption by using preset keys and mapping relationships to recover the complete original path data.
[0087] The first step verifies the legality and validity of the collected audience path data, eliminating missing or incorrect location points to ensure the quality of data input for subsequent processing. The second step handles special cases with very few trajectory points to prevent algorithm failure or ambiguity in minimal data scenarios. The third step accurately calculates and accumulates the geodetic distances between adjacent trajectory points to obtain the complete path length, providing a reliable physical basis for subsequent uniform segmentation. The fourth step divides the trajectory into several equidistant path segments according to preset physical distances, extracts the boundary indices of each segment, and constructs a structured segment set, maintaining both spatial uniformity and algorithm controllability. The fifth step sorts the adjacent time differences within each segment and extracts the median value, combining it with the sum of timestamps to generate a key index, giving the key both temporal stability and distinctiveness. The sixth step defines a reversible segment-level permutation mapping function and its inverse function based on the key index, providing flexible and controllable mapping rules for encrypted rearrangement. The seventh step rearranges and encrypts each path segment according to the mapping function, and uploads the anonymized segment sequence containing only the permutation results to the cloud, ensuring that the cloud does not store any reversible original information. The eighth step allows the authorized party to recover the correct segment order and reconstruct the complete original trajectory locally using the pre-stored key and the inverse mapping function, achieving controllable path backtracking.
[0088] By organically combining the above steps, the security risks commonly encountered in traditional trajectory encryption, such as leakage of original data, the presence of keys and data at the same end, and the vulnerability of single encryption strategies to replay attacks, are solved. At the same time, data privacy protection and subsequent trajectory analysis needs are taken into account. The separation of responsibilities is achieved between the cloud and the trusted execution environment, which not only ensures the irreversibility of encrypted data, but also enables the rapid recovery of the original trajectory during authorization.
[0089] The process involves collecting raw latitude and longitude path data of spectators during sports and exhibition activities, and verifying the legality and validity of the collected data to form an initial trajectory data set, specifically including:
[0090] The audience members were numbered as follows The sampling point number is k∈{1,2,...,K} i};in, K represents the total number of viewers. i The total number of sampling points for the i-th audience member;
[0091] Obtain the original trajectory points of the i-th audience member and form the original path set P. i :
[0092] in, Let λ be the latitude of the k-th sampling point of the i-th audience member; i,k Let t be the longitude of the k-th sampling point of the i-th audience member; i,k The timestamp of the kth sampling point of the i-th audience member; a unified definition of the audience trajectory data format to provide standardized input for subsequent distance, segmentation, encryption and other algorithms;
[0093] The WGS-84 ellipsoid is adopted, with the Earth's average radius R = 6,371,000 meters; the Earth model on which the geodetic distance calculation is based is defined, providing physical constants for the distance calculation;
[0094] For each point like or Then delete that point. make K i ←K i -1, and repeat the check until all points are valid or K. i =0; Filters out abnormal or erroneously located data to ensure that the data processed by subsequent algorithms is valid and reliable;
[0095] If K at this time i <2, execute exception handling;
[0096] If K at this time i ≥2, for all k = 1, 2, ..., K i -1: Check if ti,k+1 ≤t i,k Then delete that point. Update P i With K i Repeat the test until all time increments are achieved; ensure the integrity and consistency of the trajectory time series, and avoid errors in subsequent time difference and median calculations.
[0097] Focusing on the collection and validity verification of raw latitude and longitude path data, a unified format for audience trajectory data is defined to ensure consistent parsing standards for geographic coordinates and timestamp information across different modules. By judging the latitude and longitude range and timestamp order point by point, abnormal sampling points are automatically deleted and iteratively verified to avoid invalid or misaligned positioning affecting subsequent distance calculations and segmentation operations. Pre-setting Earth model parameters provides accurate physical constant support for geodetic distance calculations. By verifying the incrementality of timestamps, time reversal or duplicate recordings caused by network latency or sensor jitter are eliminated, ensuring that all trajectory points have strict temporal relationships.
[0098] By employing the aforementioned multiple verification methods, this technology addresses common issues in existing technologies, such as unstable raw data quality, errors in distance or key calculations due to the inclusion of dirty data, segment breakage, or misalignment of segment boundaries. This ensures that subsequent equidistant segmentation based on physical distance and encryption key generation based on temporal characteristics are performed on high-quality data, thereby improving the robustness and accuracy of the entire encryption process. Furthermore, this verification mechanism is executed entirely in a local or trusted environment, without relying on external third-party verification services, offering advantages such as flexible deployment and high real-time performance.
[0099] For the special scenario where the number of trajectory points is less than two, exception handling is performed, specifically including:
[0100] When K i <2 o'clock:
[0101] If K i =1, let the encryption result E i =P i Among them, E i The encrypted data is for the path of the i-th viewer; in the case of a single point, no encryption is required, and the data is saved as is.
[0102] If K i =0, let the encryption result be 0. When there are no sampling points, output an empty set to avoid misprocessing in subsequent steps;
[0103] (ID) i E i The method ends when the data is stored in the cloud; among which, ID... i Use it as a unique identifier for the i-th viewer; store the processed results in the cloud to complete the encryption process.
[0104] Special anomaly handling design was implemented for special scenarios with fewer than two trajectory points. When there is only a single sampling point, the point is directly uploaded as the encrypted result to avoid meaningless segmentation and replacement operations; when no trajectory points are collected at all, an empty set is output as the encrypted result and the subsequent process is terminated to avoid any erroneous calls or infinite iterations to zero-point data; after processing, the result and the audience's unique identifier are stored in the cloud to achieve a one-time closed loop.
[0105] By addressing this specific scenario, the risks of common encryption algorithms failing, entering infinite loops, or inferring unreasonable keys due to lack of data availability when sampling fails or instantaneous location coverage is insufficient are resolved. By directly adopting the simplest result and associating it with a unique identifier, the logical traceability of each record stored in the cloud is ensured, so that the overall stability of the system is not affected even if the audience does not generate a valid trajectory. At the same time, the computational and storage overhead of the system under extreme conditions is reduced, and the system's fault tolerance and high availability for various abnormal data are improved.
[0106] Based on geodetic principles, the method calculates the spherical distance between adjacent trajectory points in the trajectory data and performs segment-by-segment cumulative processing to obtain the total length information of the complete path. Specifically, this includes:
[0107] When K i When ≥2:
[0108] For k = 1, 2, ..., K i -1, calculate the distance d between two adjacent points of the i-th spectator in the k-th segment. i,k :
[0109]
[0110] in, For latitude difference; Δλ i,k =Δλ i,k+1 -Δλ i,k For longitude difference; calculate the actual Earth surface distance between each pair of adjacent sampling points to provide basic data for segmentation and accumulation;
[0111] Set the initial value C of the cumulative distance of the i-th viewer. i,0 =0;
[0112] Calculate the total distance of the i-th audience member before the k-th segment.
[0113] Accumulate distances segment by segment to generate a cumulative mileage curve, supporting equidistant segmented positioning;
[0114] Calculate the total path length of the i-th viewer. Obtain the total distance the audience walks to calculate the number of segments.
[0115] After trajectory point verification, the true distance between adjacent sampling points on the Earth's surface is accurately obtained through spherical distance calculation based on geodetic principles, and the distances are accumulated segment by segment to generate a full-length mileage curve. Unlike common two-dimensional Euclidean distance approximations or simple coordinate difference processing, this scheme uses an Earth ellipsoid model that meets engineering requirements and calculates the shortest path on the sphere through a weighted algorithm of longitude and latitude differences, effectively eliminating errors caused by ignoring the curvature of the Earth.
[0116] This distance calculation and accumulation step solves the problem of large cumulative error and inaccurate segment boundary positioning caused by planar approximation algorithms when the audience trajectory spans hundreds or even thousands of meters in large-scale exhibition scenarios. The generated accurate mileage curve not only provides a reliable physical basis for subsequent equidistant segmentation, but can also be directly reused for applications that need to count the audience's walking distance, estimate the flow density and heat distribution. Moreover, the calculation is completed in a local or trusted environment without relying on the network or external map services, which has the advantages of both accuracy and autonomous controllability.
[0117] The step of dividing the path data into multiple equidistant path segments according to a preset equidistant segment length parameter, extracting the boundary index of each path segment, and constructing a path segment set specifically includes:
[0118] When K i When ≥2:
[0119] Set the constant for the equidistant segment length to L. e Determine the theoretical length of each segment to achieve uniform segmentation; L e This is used to evenly divide the entire trajectory of the audience into several segments according to the "physical distance"; mathematically, the number of segments is... Simultaneously segment boundary index κ i,s By C i,k ≥sL e Determined; by setting a fixed physical length L e This ensures that each segment has a "controllable length" and consistent segmentation rules, facilitating subsequent segment-level encryption and replacement. The number of segments affects: when L... e Smaller, N i As L increases, the trajectory is segmented into finer pieces, resulting in longer anonymized segment sequences and stronger privacy protection, but also increasing computational and storage overhead; when L... e Larger, N i Reducing segmentation and coarser data size improves processing efficiency, but the increased granularity of the trajectory may lead to a decrease in anonymization effectiveness. Privacy versus usability trade-offs: Little L e →More detailed geographic information reduces the risk of leakage, but if it is too detailed, the "fine-tuning" location may still be inferred even after encryption and rearrangement due to the segment being too short; Large L e→Highly controllable and with low system overhead, but may result in insufficient privacy after trajectory reconstruction. Value selection criteria: Venue size and layout: For small indoor exhibitions (such as exhibition halls), 2–5 meters can be used to match the walking accuracy of the audience; for large sports venues, 5–10 meters can be used to balance performance and privacy. Positioning system accuracy: If high-precision UWB / RTLS (<1 meter error) is used, a smaller L value can be selected. e If relying solely on Wi-Fi / BLE (error range ~3–10 meters), L is recommended. e ≥ Error Upper Limit. Business Performance Requirements: When high real-time requirements are needed, L can be appropriately increased. e Reduce the number of segments; when privacy is a priority, L can be appropriately reduced. e Increase the granularity of segmentation. Recommended range. Where D represents the maximum straight-line distance (in meters) between venue zones. Typical example: Indoor precise positioning, L e = 3-5 meters; large outdoor area, L e =10-20 meters; if performance needs to be considered, L can be set first. e =5 meters, to be adjusted according to actual encryption and decryption speed and storage pressure.
[0120] Calculate the number of path segments for the i-th viewer. Calculate the actual number of segments needed, ensuring that each segment does not exceed L. e And at least one paragraph;
[0121] Obtain the sampling index κ of the end point of the s-th segment for the i-th audience member. i,s =min{k|C i,k ≥sL e}, and let κ i,0 =0, Where s = 1,...,N i -1 represents the segment number; it locates the sampling point index corresponding to the end of the s-th segment, providing a specific location for segment point division.
[0122] Construct the set of points of segment s for the i-th audience member.
[0123] Extract the sampling point set of each segment according to the index to form a segment unit that can be independently encrypted.
[0124] Based on pre-set physical distances, the complete trajectory data of the audience is divided into multiple path segments of equal length, and the start and end indices of each segment are clearly defined, forming a structured set of segments. Unlike traditional segmentation based on a fixed number of sampling points or time intervals, equidistant segmentation truly uses physical distance as the basis to ensure that the length of each segment is basically consistent, eliminating the segment imbalance problem caused by changes in positioning frequency.
[0125] By using the steps of equidistant segmentation and segment boundary indexing, the problem that segment boundaries cannot accurately reflect the actual movement distance under high-frequency or low-frequency sampling conditions is solved; spatial granularity is controllable, which can dynamically adjust the segment length according to the venue size and positioning accuracy, and ensure the balance between the amount of data per segment and the anonymization effect when subsequent segment-level encryption is performed; the structured segment index provides a clear operation unit for segment-level permutation mapping, and also facilitates subsequent support for on-demand recovery of trajectories for specific time periods, improving the system's flexibility and data utilization efficiency.
[0126] The calculation of the time difference set of adjacent trajectory points in each path segment, sorting them to obtain the median time difference, and constructing the path encryption key index for each viewer based on the sum of this median and the timestamp, specifically includes:
[0127] When K i When ≥2:
[0128] Calculate the time difference δ of the i-th audience member at the k-th time. i,k =t i,k+1 -t i,k ; Calculate adjacent time intervals to provide temporal characteristics for median calculation and key generation;
[0129] Construct the set ΔT of all adjacent time differences for the i-th audience member. i ={δ i,k |k=1,...,K i -1};
[0130] Let n = K i -1, and ΔT i Sort in ascending order to get: δ i,(1) ≤δ i,(2) ≤…≤δ i,(n) Where n is the number of differences, used only for median operations; m is the median index;
[0131] Obtain the median time difference of the i-th audience member.
[0132] The median was used to eliminate the effects of extreme jumps and to extract typical time intervals.
[0133] Calculate the sum of the timestamps of all sampling points for the i-th audience member. Accumulated time features, combined with the median, generate a key uniquely bound to the path;
[0134] Construct the encryption key index for the i-th spectator Here, mod is the modulo operation; it generates segment permutation offsets to ensure that the same path corresponds to the same key, and different paths have obvious differences.
[0135] Within each path segment, the time difference set of adjacent sampling points is sorted and the median is extracted. This median is then combined with the sum of all timestamps to generate an encrypted key index for each viewer. Compared to directly using the average time interval or a simple pseudo-random seed, this scheme avoids interference from timing anomalies caused by occasional jumps and location intervals in key generation by using the median. It combines typical time characteristics with accumulated time characteristics throughout the process, ensuring that the key not only reflects the unique movement characteristics of the viewer but also has the ability to resist interference from minute time-series perturbations.
[0136] By using this time difference median calculation and key index generation steps, the risk of replay attacks caused by insufficient static or random keys and the problem of encryption / decryption inconsistency caused by timing anomalies in existing technologies are solved. The generated key index corresponds one-to-one with the number of path segments and can be used directly as a permutation offset for segment-level mapping, simplifying the complexity of key management. At the same time, this method does not require a high-intensity random number source and can complete key generation based solely on sampling time characteristics, which helps to efficiently deploy it in resource-constrained mobile terminals or sensor nodes.
[0137] The construction of the segment-level permutation mapping function and its corresponding inverse mapping function based on the key index specifically includes:
[0138] When K i When ≥2:
[0139] Construct the permutation function π for the i-th audience segment i (s)=[(s-1+M i )mod N i ]+1, s=1,...,N i The original segments are encrypted and rearranged by cyclically shifting the segment sequence number to the right using the key.
[0140] Construct the inverse function of the permutation of the i-th audience segment.
[0141] Provides the opposite operation to the forward mapping, used to decrypt and recover the original segment number.
[0142] This paper proposes a reversible permutation mapping of path segment numbers based on the aforementioned key index, and defines a corresponding inverse mapping function for segment-level encrypted rearrangement and decryption recovery. This mapping achieves anonymization of the path segment order by cyclically shifting each segment number by an offset. Unlike encrypting the entire path as a whole or relying on symmetric cryptography, this scheme's segment-level permutation rearranges large-scale trajectory data with extremely low computational overhead. Furthermore, the mapping and inverse mapping structures are simple and clear, facilitating rapid execution and verification in resource-constrained environments.
[0143] By defining the mapping function and inverse mapping function, the problem of difficulty in partial recovery or low efficiency after traditional whole data encryption is solved. The segment-level reversible mapping not only ensures the security of not being able to easily restore the true order after anonymization, but also enables accurate and fast recovery of the original sequence segment by segment during authorization. At the same time, the mapping rules only rely on the pre-generated key index, without the need to store complex mapping tables, which reduces storage and management costs and improves the scalability and ease of operation and maintenance of the algorithm.
[0144] Based on the key index and permutation function, each segment of path data is encrypted at the segment level, and the encrypted path data is uploaded to the cloud storage system, storing only the irreversible encryption result. The key used and the original path data are stored in a trusted execution environment, specifically including:
[0145] When K i When ≥2:
[0146] Construct the encrypted segment sequence of the i-th viewer The segmented sequence is rearranged according to the permutation function to form an anonymized list of segments;
[0147] The cloud only stores entries (IDs) i E i );
[0148] Original path P i With key M i The key M is stored in a trusted security module and is not stored in the cloud. i ;
[0149] The encrypted results are securely stored in the cloud without revealing the actual trajectory and key.
[0150] Unauthorized parties have no right to obtain M i .
[0151] Segment-level encryption is achieved by applying a predefined permutation mapping function to each path segment, and only the rearranged anonymized segment list is uploaded to the cloud. The original trajectory data and keys are stored in a local trusted execution environment or security module, achieving physical isolation between data and keys. Unlike common methods that store keys in the cloud or rely on third-party key management, this solution eliminates the risk of reverse engineering and recovery of original data due to key leakage in the cloud.
[0152] By employing this segment-level encryption and cloud storage process, the risk of single-point leakage caused by the coexistence of keys and encryption results in a cloud environment is resolved. Although the encrypted list retains the complete data volume and segment index, the original data cannot be directly reconstructed due to the scrambled order, thus balancing the needs of data anonymization and big data analysis. The secure storage of local keys and original data ensures that the system can resist unauthorized access when subjected to external intrusion, thereby improving the overall security level and compliance of the solution.
[0153] The authorized party, through a preset key and mapping relationship, completes segment-level decryption to recover the complete original path data, specifically including:
[0154] When K i When ≥2:
[0155] The licensor obtains (E) i M i Ensure that only the legitimate party possesses the decrypted information;
[0156] Get the set of original path points of the i-th audience member in the s-th segment. Restore the correct order of each segment using the inverse mapping function;
[0157] By connecting all segments of the original path obtained from the i-th viewer, we can obtain the complete original path of the i-th viewer. Where || represents segment sequence concatenation; the recovered segments are concatenated in sequence to reconstruct the complete original trajectory for subsequent analysis.
[0158] The authorized party is required to use a pre-reserved key index and permutation inverse mapping function within a local or trusted environment to decrypt and rearrange the cloud-anonymized segment list, and then reassemble the segments in the correct order to restore the complete original trajectory data. Unlike traditional processes that require transmitting keys to the cloud or relying on remote decryption services, this solution performs the decryption operation entirely locally, avoiding the security risks associated with cross-domain key transmission.
[0159] By implementing this authorization decryption and original path recovery steps, the common problems of high latency and high risk encountered by the authorizing party when rapidly tracing the trajectory of a specific audience member in restricted scenarios are resolved. The segment-level selective recovery mechanism not only supports the restoration of the full data on demand, but also allows for partial recovery of specific time periods or geographical areas, improving the flexibility of subsequent data analysis. The performance of localized decryption and reverse mapping operations can be optimized according to hardware conditions, and can also be combined with access control policies to achieve hierarchical authorization and fine-grained auditing of sensitive trajectory data.
[0160] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0161] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the technical principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for processing cloud information of sports exhibition attendees, characterized in that, include: Collect raw latitude and longitude path data of spectators during sports exhibitions and events, and verify the legality and validity of the collected data to form an initial trajectory data set; For special scenarios with fewer than two trajectory points, exception handling is performed, including path result setting and direct cloud storage processes; Based on the principles of geodesy, the spherical distance between adjacent trajectory points in the trajectory data is calculated and accumulated segment by segment to obtain the total length information of the complete path. Based on the preset equidistant segment length parameter, the path data is divided into multiple equidistant path segments, and the boundary index of each path segment is extracted to construct a path segment set. Calculate the set of time differences between adjacent trajectory points in each path segment, sort them to obtain the median time difference, and construct the path encryption key index for each viewer based on the sum of the median and the timestamp. Construct a segment-level permutation mapping function and its corresponding inverse mapping function based on the key index; Based on the key index and permutation function, each segment of path data is encrypted at the segment level, and the encrypted path data is uploaded to the cloud storage system. Only the irreversible encryption result is stored, and the key and the original path data are stored in a trusted execution environment. The authorizing party completes segment-level decryption by using preset keys and mapping relationships to recover the complete original path data.
2. The method for processing cloud information of sports exhibition attendees according to claim 1, characterized in that, The process involves collecting raw latitude and longitude path data of spectators during sports and exhibition activities, and verifying the legality and validity of the collected data to form an initial trajectory data set, specifically including: The audience members were numbered as follows The sampling point number is k∈{1,2,...,K} i };in, K represents the total number of viewers. i The total number of sampling points for the i-th audience member; Obtain the original trajectory points of the i-th audience member and form the original path set P. i : in, Let λ be the latitude of the k-th sampling point of the i-th audience member; i,k Let t be the longitude of the k-th sampling point of the i-th audience member; i,k The timestamp of the kth sampling point of the i-th viewer; Using the WGS-84 ellipsoid, the Earth's average radius R = 6,371,000 meters; For each point like or Then delete that point. make K i ←K i -1, and repeat the check until all points are valid or K. i =0; If K at this time i <2, execute exception handling; If K at this time i ≥2, for all k = 1, 2, ..., K i -1: Check if t i,k+1 ≤t i,k Then delete that point. Update P i With K i Repeat the test until all time increments.
3. The method for processing cloud information of sports exhibition attendees according to claim 2, characterized in that, For the special scenario where the number of trajectory points is less than two, exception handling is performed, specifically including: When K i <2 hours: If K i =1, let the encryption result E i =P i Among them, E i Encrypted data for the path of the i-th viewer; If K i =0, let the encryption result be 0. (ID) i E i The method ends when the data is stored in the cloud; among which, ID... i This is a unique identifier for the i-th viewer.
4. The method for processing cloud information of sports exhibition attendees according to claim 3, characterized in that, Based on geodetic principles, the method calculates the spherical distance between adjacent trajectory points in the trajectory data and performs segment-by-segment cumulative processing to obtain the total length information of the complete path. Specifically, this includes: When K i When ≥2: For k = 1, 2, ..., K i -1, calculate the distance d between two adjacent points of the i-th spectator in the k-th segment. i,k : in, For latitude difference; Δλ i,k =Δλ i,k+1 -Δλ i,k Difference in longitude; Set the initial value C of the cumulative distance of the i-th viewer. i,0 =0; Calculate the total distance of the i-th audience member before the k-th segment. Calculate the total path length of the i-th viewer.
5. The method for processing cloud information of sports exhibition attendees according to claim 4, characterized in that, The step of dividing the path data into multiple equidistant path segments according to a preset equidistant segment length parameter, extracting the boundary index of each path segment, and constructing a path segment set specifically includes: When K i When ≥2: Set the constant for the equidistant segment length to L. e ; Calculate the number of path segments for the i-th viewer. Obtain the sampling index κ of the end point of the s-th segment for the i-th audience member. i,s =min{k|C i,k ≥sL e }, and let κ i,0 =0, Where s = 1,...,N i -1 is the segment number; Construct the set of points of segment s for the i-th audience member.
6. The method for processing cloud information of sports exhibition attendees according to claim 5, characterized in that, The calculation of the time difference set of adjacent trajectory points in each path segment, sorting them to obtain the median time difference, and constructing the path encryption key index for each viewer based on the sum of this median and the timestamp, specifically includes: When K i When ≥2: Calculate the time difference δ of the i-th audience member at the k-th time. i,k =t i,k+1 -t i,k ; Construct the set ΔT of all adjacent time differences for the i-th audience member. i ={δ i,k |k=1,...,K i -1}; Let n = K i -1, and ΔT i Sort in ascending order to get: δ i,(1) ≤δ i,(2) ≤…≤δ i,(n) Where n is the number of differences, used only for median operations; m is the median index; Obtain the median time difference of the i-th audience member. Calculate the sum of the timestamps of all sampling points for the i-th audience member. Construct the encryption key index for the i-th spectator Here, mod represents the modulo operation.
7. The method for processing cloud information of sports exhibition attendees according to claim 6, characterized in that, The construction of the segment-level permutation mapping function and its corresponding inverse mapping function based on the key index specifically includes: When K i When ≥2: Construct the permutation function π for the i-th audience segment i (s)=[(s-1+M i )mod N i ]+1, s=1,...,N i ; Construct the inverse function of the permutation of the i-th audience segment.
8. The method for processing cloud information of sports exhibition attendees according to claim 7, characterized in that, Based on the key index and permutation function, each segment of path data is encrypted at the segment level, and the encrypted path data is uploaded to the cloud storage system, storing only the irreversible encryption result. The key used and the original path data are stored in a trusted execution environment, specifically including: When K i When ≥2: Construct the encrypted segment sequence of the i-th viewer The cloud only stores entries (IDs) i E i ); Original path P i With key M i The key M is stored in a trusted security module and is not stored in the cloud. i ; Unauthorized parties have no right to obtain M i .
9. The method for processing cloud information of sports exhibition attendees according to claim 8, characterized in that, The authorized party, through a preset key and mapping relationship, completes segment-level decryption to recover the complete original path data, specifically including: When K i When ≥2: The licensor obtains (E) i M i ); Get the set of original path points of the i-th audience member in the s-th segment. By connecting all segments of the original path obtained from the i-th viewer, we can obtain the complete original path of the i-th viewer. Where || represents the concatenation of segment sequences.