Method and system for safely sharing data of ports along land bridge

By assessing the credibility of credentials and verifying the integrity of data transmission, and combining multi-source event analysis, the data sharing at ports along the land bridge was graded, marked, and adjusted in terms of business operations. This resolved data security issues caused by operational negligence and data transmission errors, improved the security and credibility of data sharing, and ensured smooth business processes.

CN120934818AActive Publication Date: 2025-11-11HORGOS ELECTRONIC PORT TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511093833.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-11-11
Estimated Expiration
2045-08-06

AI Technical Summary

Technical Problem

During the data security sharing process at ports along the land bridge, there are issues such as abuse of high-level privilege credentials due to operational negligence, unauthorized access, data stream errors caused by instantaneous jitter of optical signals during data transmission, and ambiguities in the data sharing protocol processing logic. These issues lead to a decline in data integrity and reliability, affecting business process judgment.

Method used

An access trust score is generated by assessing the credential lifecycle, source context, and data request scope. Data content integrity is verified by combining physical environment vibration data of the data transmission fiber optic cable and conventional check codes. Security events are identified and alarm priorities are increased. Data streams are graded and labeled according to the overall trust score, and business operations are adjusted or restricted.

Benefits of technology

This effectively enhances the security, integrity, and reliability of data sharing at ports along the land bridge, avoids business judgment errors caused by data distortion or security vulnerabilities, and ensures the smooth execution of data sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934818A_ABST
    Figure CN120934818A_ABST
Patent Text Reader

Abstract

The invention discloses a land bridge port data security sharing method and system, relates to the field of land bridge port data security sharing, is used for improving the integrity and credibility of land bridge port data sharing, and comprises the following steps: receiving a data stream for carrying out a data access request, evaluating the life cycle, the source context and the data request range of the voucher, and generating an access credibility score; in the transmission process of the data stream, monitoring physical environment vibration data of the data transmission optical cable, and performing integrity check on the data stream in combination with the physical environment vibration data and the conventional check code; calculating a comprehensive credibility total score of the data stream by combining the access credibility score and a data content integrity verification result, and performing grading marking on the data stream according to the comprehensive credibility total score; meanwhile, event flows from different sources are associated, the security event is identified, and the alarm priority of the security event is improved; and adjusting or limiting the service operation corresponding to the data stream according to the grading mark of the data stream.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of secure data sharing at ports along land bridges, and more particularly to a method and system for secure data sharing at ports along land bridges. Background Technology

[0002] During the data security sharing process at ports along the land bridge, when port IT maintenance personnel neglected to leave behind high-privilege remote diagnostic account credentials, and the terminal computer was sent to an external repair shop for testing, external technicians accidentally discovered and attempted to use these credentials to make unauthorized access to the port network. At the same time, the port network security isolation equipment failed to effectively prevent this internal credential login attempt under non-standard connection mode due to a firmware logic vulnerability. As a result, the audit log recording system failed to issue an alarm in a timely manner due to low priority settings, which led to external personnel discovering and using an internal data synchronization interface exposed due to an error in permission inheritance.

[0003] Random queries by external personnel may still access and transmit a small amount of metadata containing sensitive information about entry and exit records. During transmission, the optical fiber cable of the port network may experience momentary jitter due to external physical vibrations, causing data stream errors. Ultimately, the receiving system fails to completely interrupt the transmission due to ambiguity in the data sharing protocol's handling logic for "partially damaged but still parseable" situations, and instead performs incomplete data parsing. This leads to port management personnel making incorrect judgments in their business processes based on this incomplete and unauthorized access to data.

[0004] Therefore, ensuring the integrity and reliability of data sharing at ports along the land bridge and the smooth execution of its business processes under the aforementioned complex and multifaceted unexpected scenarios is a pressing technical problem that needs to be solved. Summary of the Invention

[0005] This invention provides a method for secure data sharing at ports along the land bridge, which improves the integrity and reliability of data sharing at ports along the land bridge.

[0006] Firstly, to address the aforementioned technical problems, this invention provides a method for secure data sharing at ports along a land bridge, comprising: receiving a data stream for making a data access request, the data stream including credentials for requesting data; assessing the lifecycle of the credentials, the source context, and the scope of the data request to generate an access credibility score; during the transmission of the data stream, monitoring the physical environment vibration data of the data transmission optical cable, and combining the physical environment vibration data with a conventional checksum to perform an integrity check on the data stream, obtaining a data content integrity check result; if the data content integrity check result indicates that the data stream integrity check failed or there is a potential risk of physical layer distortion, then marking the data stream as integrity compromised; combining the access credibility score and the data content integrity check result to calculate the overall credibility score of the data stream, and classifying and marking the data stream according to the overall credibility score; simultaneously, associating event streams from different sources, identifying security events, and increasing the alarm priority of security events; and adjusting or restricting the business operations corresponding to the data stream according to the classification and marking of the data stream.

[0007] Optionally, the physical environment vibration data of the data transmission optical cable is monitored, and the data stream is checked for integrity in conjunction with the physical environment vibration data and conventional check codes to obtain the data content integrity verification result. This includes: collecting the physical characteristics of the optical signal of the data stream at the receiving end of the data transmission optical cable; establishing a dynamic benchmark for the optical signal based on the physical characteristics of the optical signal; the dynamic benchmark reflects the fluctuation range of the physical characteristics of the optical signal under normal operating conditions; comparing the physical characteristics of the optical signal with the dynamic benchmark to identify whether there are abnormal patterns in the optical signal and obtaining anomaly identification results; abnormal patterns include instantaneous polarization state anomalies, spectral distribution anomalies, and dispersion coefficient anomalies; generating an optical signal quality score based on the anomaly identification results, and using the optical signal quality score as the content integrity verification result.

[0008] Optionally, a dynamic benchmark for the optical signal is established based on its physical characteristics, including: dividing the physical characteristics of the optical signal into continuous data segments; acquiring concurrent port environmental auxiliary data, including the operating status of port heavy machinery and the output of local micro-vibration sensors; combining the port environmental auxiliary data to assess the degree to which the physical characteristics of the optical signal in each data segment are affected by external disturbances; selecting data segments whose degree of external disturbance is lower than a preset threshold as valid benchmark data based on the degree to which the physical characteristics of the optical signal in each data segment are affected by external disturbances; and periodically updating the dynamic benchmark of the optical signal based on the valid benchmark data.

[0009] Optionally, the method further includes: if the instantaneous polarization state of the optical signal undergoes a non-periodic change exceeding a preset threshold within a preset time period compared to the dynamic reference of the optical signal, then the abnormal mode of the optical signal is determined to be an instantaneous polarization state abnormality; if the spectral distribution of the optical signal exhibits instantaneous broadening or shift compared to the dynamic reference of the optical signal, then the abnormal mode of the optical signal is determined to be a spectral distribution abnormality; if the dispersion coefficient of the optical signal exhibits nonlinear fluctuations within a preset time period during transmission compared to the dynamic reference of the optical signal, then the abnormal mode of the optical signal is determined to be a dispersion coefficient abnormality; and in the case of identifying the abnormal mode of the optical signal, marking the data stream as having a risk of implicit physical layer distortion of the optical signal.

[0010] Optionally, the different sources include at least one of the following: network security devices, audit logs, credential management modules, and physical environment awareness modules; associating event streams from different sources, identifying security events, and increasing the alarm priority of security events includes: extracting entity identifiers involved in the event streams, where entity identifiers include user identifiers, device identifiers, IP addresses, and data interface identifiers; based on the entity identifiers, constructing an activity trajectory chain for each entity in the port network, and recording the low-priority event sequences triggered by each entity in different systems and at different times; defining preset threat patterns; a threat pattern is a combination of low-priority events continuously triggered by a specific entity across time intervals or system boundaries in the activity trajectory chain; comparing the activity trajectory chain with the preset threat patterns to associate event streams from different sources, identify security events, and increase the alarm priority of security events.

[0011] Optionally, the activity trajectory chain can be compared with preset threat patterns to associate event streams from different sources, identify security events, and increase the alarm priority of security events. This includes: if an activity trajectory chain is found to match any preset threat pattern, risk accumulation is performed on the entity or related activity trajectory chain; when the risk accumulation reaches a preset risk threshold, the alarm priority of the activity trajectory chain is increased to the highest level.

[0012] Optionally, a preset threat pattern is defined, including: identifying multiple sets of entities involved in the threat pattern, wherein the entity set specifies at least two entities of different types participating in the threat pattern; identifying the expected interaction rules between entities in the threat pattern; for each entity, identifying a specific low-priority event sequence that the entity will trigger in the threat pattern; the specific low-priority event sequence includes multiple specific low-priority events ordered in time sequence; identifying time windows and system boundary conditions in which the specific low-priority events and interactions occur within specific time windows and can span different system boundaries; and combining multiple sets of entities, interaction rules, low-priority event sequences, time windows, and system boundary conditions to form the preset threat pattern.

[0013] Optionally, the lifecycle, source context, and data request scope of the assessment credentials are evaluated to generate an access trust score. This includes: configuring a set of assessment parameters for the credential lifecycle, source context, and data request scope; the assessment parameter set includes the credential validity period, source network region, access time window, data sensitivity classification, and access rules; adjusting the credential validity period and access time window based on port business operation status signals; adjusting the assessment parameter set based on received threat intelligence instructions to obtain an adjusted assessment parameter set; the threat intelligence instructions are used to instruct adjustments to at least one of the following: trust level of the source network region, data sensitivity classification and access rules, update instructions based on internal security policies, automatic credential clearing trigger conditions, and data access restrictions; based on the adjusted assessment parameter set, evaluating the lifecycle, source context, and data request scope of the credentials used in the data flow; and generating an access trust score based on the assessment results.

[0014] Optionally, the overall credibility score of the data stream is calculated, and the data stream is classified and labeled according to the overall credibility score, including: weighted summation of access credibility score and data content integrity verification results to obtain the overall credibility score of the data stream; and classified and labeled according to the overall credibility score and the level mapping relationship; the level mapping relationship includes the mapping relationship between different credibility scores and different credibility levels.

[0015] Secondly, this invention provides a data security sharing system for ports along a land bridge, used for secure data sharing at ports along a land bridge. The system includes: The data stream receiving module is used to receive a data stream used to make a data access request. The data stream includes credentials for requesting data. The access credibility assessment module is used to assess the lifecycle of credentials, source context, and scope of data requests, and generate an access credibility score. The data integrity verification module is used to monitor the physical environment vibration data of the data transmission optical cable during the data stream transmission process. It combines the physical environment vibration data with conventional check codes to perform integrity verification on the data stream and obtain the data content integrity verification result. If the data content integrity verification result indicates that the data stream integrity verification has failed or there is a potential risk of physical layer distortion, the data stream is marked as integrity compromised. The data stream credibility calculation and event association module is used to combine access credibility score and data content integrity verification results to calculate the overall credibility score of the data stream, and classify and label the data stream according to the overall credibility score; at the same time, it associates event streams from different sources, identifies security events, and improves the alarm priority of security events. The business operation adjustment and decision support module is used to adjust or restrict the business operations corresponding to the data flow based on the hierarchical labeling of the data flow.

[0016] Compared with the prior art, the present invention has the following beneficial effects: This application provides a method and system for secure data sharing at ports along the land bridge. By comprehensively evaluating the credibility of data access credentials, monitoring the physical integrity of data transmission in real time, and combining multi-source event correlation analysis, it hierarchically labels data streams and adjusts business operations. This effectively solves problems such as data distortion, unauthorized access, and delayed response to security incidents in existing technologies. It has the advantage of effectively improving the security, integrity, and credibility of data sharing at ports along the land bridge, and avoiding business judgment errors caused by data distortion or security vulnerabilities. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of a method for securely sharing data at ports along a land bridge, provided by an embodiment of the present invention. Figure 2 This is a schematic diagram of another method for secure data sharing at ports along the land bridge provided in this embodiment of the invention; Figure 3 This is a schematic diagram of a data security sharing system for ports along the land bridge provided in an embodiment of the present invention. Detailed Implementation

[0018] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. The components of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0019] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0020] The following specific embodiments will provide a detailed introduction and explanation of a data security sharing method for ports along the land bridge provided in this application.

[0021] Reference Figure 1 This invention provides a method for secure data sharing at ports along a land bridge, comprising the following steps: S1 receives the data stream used to make a data access request.

[0022] The data stream includes credentials used to request data.

[0023] As one possible implementation, when a user wants to access data of ports along the land bridge, they can log in to the Land Bridge Port Data Security Sharing System (hereinafter referred to as the System) through a terminal device to send a data stream for data access request to the System; correspondingly, the System receives the data stream for data access request.

[0024] S2. Evaluate the lifecycle of the credentials, the source context, and the scope of the data request to generate an access credibility score.

[0025] The access credibility score refers to the quantitative assessment of the legality, reliability, and potential risk of a data access request. It can be implemented using rule-based scoring models, machine learning algorithms, or expert systems. For example, it can be calculated by analyzing dimensions such as the validity period of credentials, the trust level of the source network, the access time window, and the sensitivity of the requested data.

[0026] As one possible implementation, the system can generate an access trust score based on the following steps: S21. Configure the set of evaluation parameters for credential lifecycle, source context, and data request scope.

[0027] The evaluation parameter set includes the validity period of the credential, the source network region, the access time window, data sensitivity classification, and access rules.

[0028] As one possible implementation, the system can configure an initial set of evaluation parameters based on user input.

[0029] For example, the validity period of credentials can be set to the default 90 days, and the source network area can be divided into "Internal Trust Zone," "External Cooperation Zone," and "Internet Zone," each assigned a different initial trust level (e.g., high, medium, low). The access time window can be set to 8:00 to 18:00 on weekdays. Data sensitivity categories can include "Public," "Internal," "Sensitive," and "Top Secret," with corresponding access rules preset for each category.

[0030] S22. Adjust the validity period of the voucher and the access time window based on the port business operation status signal.

[0031] Among them, the port operation status signal refers to real-time or near-real-time information reflecting the current operation of the port. For example, it may include peak business period, normal business, and indicators such as cargo throughput, customs clearance efficiency, and passenger flow during peak business period. Its purpose is to enable the validity of vouchers and access time to dynamically adapt to the actual needs of port operations.

[0032] As one possible implementation, the system can reduce the validity period of credentials and increase the access time window when the port's business operation status signal indicates that the current business operation status of the port is "peak period".

[0033] For example, when port operations enter peak holiday periods, such as during the Spring Festival or National Day, the system can receive a "peak period" status signal from the port operations management system. Based on this signal, the system can automatically shorten the validity period of all newly issued or renewed certificates from 90 days to 30 days and adjust the access window to 24 hours a day to meet the continuity requirements of peak operations, while also reducing risk by shortening the validity period.

[0034] S23. Adjust the set of assessment parameters according to the received threat intelligence instructions to obtain the adjusted set of assessment parameters.

[0035] Among them, threat intelligence instructions are used to instruct adjustments to at least one of the following: trust level of source network area, data sensitivity classification and access rules, update instructions based on internal security policy, automatic credential clearing trigger conditions and data access restrictions.

[0036] Among them, the internal security policy update instruction refers to the instruction issued by the port's internal security management department or system to adjust the security policy configuration, which may include modifications to user permissions, data classification, access control rules, etc.

[0037] Among them, the automatic credential clearing trigger condition refers to the rule that the system automatically revokes or deletes credentials when certain preset conditions are met. These conditions may include credential expiration, user resignation, abnormal behavior, etc.

[0038] Data access restrictions refer to the constraints imposed on data access behavior, which may include access permissions, access frequency, data anonymization requirements, etc.

[0039] Threat intelligence commands can include information on potential security threats, such as lists of malicious IP addresses, known attack patterns, and vulnerability alerts. Their purpose is to adjust security assessment parameters in a timely manner to respond to changes in external security threats.

[0040] For example, when the system receives a threat intelligence instruction from an external threat intelligence platform that "a certain overseas IP segment is exhibiting a large amount of malicious scanning behavior," the system can immediately adjust the trust level of the "Internet zone" to which that IP segment belongs from "low" to "very low," and trigger stricter review of all data access requests from that zone. Simultaneously, if an internal security policy update instruction states that "all data access involving personnel entry and exit records must enable two-factor authentication and be restricted to specific secure terminals," the system can immediately update the data sensitivity classification and access rules, raising the data sensitivity of "personnel entry and exit records" to "top secret," and mandating that access to this type of data must meet the conditions of two-factor authentication and access via a specific terminal.

[0041] In addition, if the internal security policy update instruction also indicates that "the automatic deletion trigger condition for credentials that have failed to log in three times in a row should take effect immediately", the system can adjust the automatic deletion trigger condition accordingly to ensure that abnormal credentials are invalidated in a timely manner.

[0042] S24. Based on the adjusted set of evaluation parameters, evaluate the lifecycle of the credentials used in the data flow, the source context, and the scope of the data request.

[0043] As one possible implementation, the system can compare the validity period of the credentials in the evaluation parameter set with the lifecycle of the credentials used in the data flow to obtain a lifecycle score; By comparing the source network region in the evaluation parameter set with the source context of the credentials used in the data stream, a source context score is obtained; By comparing the data sensitivity classification and access rules in the evaluation parameter set with the data request range of the credentials used by the data flow, a data request range score is obtained.

[0044] In one example, the lifecycle score is 1 if the credential used by the data flow is within its validity period, and 0 otherwise. The source context score is 1 if the source context of the credential used by the data flow does not include content related to malicious source network areas, and 0 otherwise. The data request scope score is 1 if the data request scope of the credential conforms to the data sensitivity classification and access rules, and 0 otherwise.

[0045] S25. Based on the evaluation results, generate an access credibility score.

[0046] As one possible implementation, the system can perform a weighted summation of the lifecycle score, the source context score, and the request scope score to obtain the access trustworthiness score.

[0047] S3. During the transmission of the data stream, monitor the physical environment vibration data of the data transmission optical cable, and combine the physical environment vibration data with the conventional check code to perform integrity verification on the data stream and obtain the data content integrity verification result.

[0048] If the data content integrity verification result indicates that the data flow integrity check failed or there is a potential risk of physical layer distortion, then the data flow is marked as having compromised integrity.

[0049] Among them, the physical environment vibration data of the data transmission optical cable refers to the vibration information of the physical environment of the optical cable collected by sensors during the data transmission process. It can be realized by using fiber optic sensing technology, piezoelectric sensors or microelectromechanical systems (MEMS) sensors, such as distributed fiber optic sensing systems or vibration sensors attached to the optical cable. Its main purpose is to realize real-time monitoring of the physical integrity of the data transmission link and timely detection of potential physical interference or attacks.

[0050] As one possible implementation, the system can collect micro-vibration data of the optical fiber cable when the data stream is transmitted through the data transmission optical fiber cable, and combine it with the CRC code of the data packet to check the integrity of the data stream and obtain the data content integrity verification result.

[0051] As another possible implementation, the system can perform integrity checks on the data stream based on the following steps: S31. At the receiving end of the data transmission optical cable, collect the physical characteristics of the optical signal of the data stream.

[0052] Among them, the physical characteristics of optical signals refer to the various physical parameters exhibited by optical signals when they are transmitted in optical fibers, which may include the power, wavelength, polarization state, spectral distribution, dispersion coefficient, signal-to-noise ratio, etc.

[0053] As one possible approach, an optical signal monitoring device can be deployed at the receiving end of the data transmission optical cable, and the physical characteristics of the optical signal of the data stream can be collected based on the optical signal monitoring device.

[0054] For example, optical signal monitoring equipment can be an integrated photodetector array and a high-speed digital signal processor for real-time acquisition of the physical characteristics of optical signals in data streams.

[0055] S32. Based on the physical characteristics of optical signals, establish a dynamic reference for optical signals.

[0056] Among them, the dynamic reference reflects the fluctuation range of the physical characteristics of the optical signal under normal operating conditions.

[0057] As one possible approach, the system can continuously collect physical characteristic data of these optical signals during the initial or stable operation phase of the optical cable, and use statistical analysis methods, such as calculating the average value and standard deviation of each physical characteristic parameter within a sliding time window, to construct a normal fluctuation range that varies over time.

[0058] S33. Compare the physical characteristics of the optical signal with the dynamic benchmark to identify whether there is an abnormal pattern in the optical signal and obtain the anomaly identification result.

[0059] Among them, the abnormal modes include transient polarization state anomalies, spectral distribution anomalies, and dispersion coefficient anomalies.

[0060] As a possible implementation, compared to the dynamic reference of the optical signal, if the instantaneous polarization state of the optical signal undergoes a non-periodic change exceeding a preset threshold within a preset time period, then the abnormal mode of the optical signal is determined to be an instantaneous polarization state abnormality. Compared to the dynamic reference of the optical signal, if the spectral distribution of the optical signal shows transient broadening or shift, then the abnormal mode of the optical signal is determined to be spectral distribution abnormality. Compared to the dynamic reference of the optical signal, if the dispersion coefficient of the optical signal fluctuates nonlinearly within a preset time during transmission, the abnormal mode of the optical signal is determined to be an abnormal dispersion coefficient. When an abnormal pattern of optical signal is detected, the data stream is flagged for potential hidden distortion at the physical layer of the optical signal.

[0061] In some preferred embodiments, this application is implemented as follows. To identify instantaneous polarization state anomalies in optical signals, a high-speed polarization state analyzer can be deployed to collect instantaneous polarization state data of the optical signal in real time. This analyzer can collect data every 10 milliseconds and compare the collected polarization state data with a pre-established dynamic reference. If, within a preset 1-second duration, the trajectory point of the polarization state on the Poincaré sphere deviates from the dynamic reference range by more than a preset threshold of 5 degrees, and this deviation does not exhibit regular periodic fluctuations but rather random or sudden changes, the system can determine that the optical signal has an instantaneous polarization state anomaly. For the identification of spectral distribution anomalies, an integrated optical spectral analysis module can be used to continuously monitor the spectral shape of the optical signal. This module can scan the spectrum of the optical signal every 50 milliseconds. If it is detected that the 3dB bandwidth of the optical signal instantaneously broadens by more than a preset threshold of 10%, or its center wavelength instantaneously shifts by more than a preset threshold of 0.1 nanometers, the system can determine that the optical signal has a spectral distribution anomaly. For detecting anomalies in the dispersion coefficient, an online dispersion monitor can be used to periodically measure the dispersion coefficient of the optical signal. This monitor updates the dispersion coefficient data every minute. If the rate of change of the dispersion coefficient exceeds a preset threshold of 0.5 ps / nm / km within five consecutive minutes, and this change does not exhibit a linear trend typical of normal fiber aging or temperature changes, but rather shows non-linear, abrupt fluctuations, the system can determine that the optical signal has an anomaly in the dispersion coefficient. Once any of the above-mentioned anomaly patterns is identified, the system can immediately add a "physical layer implicit distortion risk" flag to the metadata of the data stream, or write this information to the security event log and trigger the corresponding alarm mechanism, so that subsequent data processing and security strategies can respond promptly.

[0062] S34. Based on the anomaly identification results, generate an optical signal quality score and use the optical signal quality score as the content integrity verification result.

[0063] As one possible implementation, the system can assign a preset risk value or weight to each identified abnormal pattern, and calculate the optical signal quality score by accumulating or weighting the values ​​according to the severity of the abnormality, and use the optical signal quality score as the result of content integrity verification.

[0064] S4. Combine the access credibility score and data content integrity verification results to calculate the overall credibility score of the data stream, and classify and label the data stream according to the overall credibility score; at the same time, associate event streams from different sources, identify security events, and increase the alarm priority of security events.

[0065] Among them, graded labeling refers to classifying data streams into different security levels or risk categories based on the overall trust score. This can be achieved by using preset threshold ranges, machine learning classifiers, or dynamic adjustment mechanisms based on policies. For example, data streams can be labeled as "high trust", "medium trust", or "low trust". The main purpose is to implement differentiated security policies and business operations for data streams with different risk levels.

[0066] Among them, associating event streams from different sources refers to the aggregation, analysis, and correlation of event data generated from multiple independent security information sources such as network security devices, audit logs, credential management modules, and physical environment perception modules. This can be achieved using Security Information and Event Management (SIEM) systems, big data analytics platforms, or graph database technologies. For example, by analyzing the correlation between different events in terms of time, entities, or behavioral patterns, the main purpose is to identify complex security threats or attack chains that are difficult to discover from a single event in a massive amount of events.

[0067] As one possible implementation, the system can perform a weighted summation of the access credibility score and the data content integrity verification results to obtain the overall credibility score of the data stream, and then classify and label the data stream according to the overall credibility score and the level mapping relationship.

[0068] It should be noted that the rating mapping relationship includes the mapping relationship between different total credibility scores and different credibility levels.

[0069] In some preferred embodiments, the weighted summation of the access credibility score and the data content integrity verification result can be implemented as follows: Assume the access credibility score ranges from 0 to 100, and the data content integrity verification result also ranges from 0 to 100. A weight coefficient w1 can be set for the access credibility score, and a weight coefficient w2 can be set for the data content integrity verification result, where w1 + w2 = 1. For example, if port operations place greater emphasis on data content integrity, w1 can be set to 0.4, and w2 to 0.6. Then, the overall credibility score of the data flow = (access credibility score * 0.4) + (data content integrity verification result * 0.6).

[0070] Furthermore, classifying and labeling data streams according to the overall credibility score and the level mapping relationship can be achieved by defining a leveling rule table. For example, the following level mapping relationship can be set: If the overall credibility score is between 90 and 100, it is marked as "high credibility".

[0071] If the overall credibility score is between 70 and 89, it is marked as "Medium Credibility".

[0072] If the overall credibility score is between 50 and 69, it is marked as "low credibility".

[0073] If the overall credibility score is below 50, it is marked as "unreliable".

[0074] Once the overall trustworthiness score of a data stream is calculated, the system queries the grading rule table and maps it to the corresponding trust level. For example, if a data stream has an overall trustworthiness score of 85, it will be marked as "Medium Trustworthiness". This specific weighted summation and grading method makes the security assessment of data streams more refined and operable, providing a clear basis for subsequent business operation adjustments.

[0075] S5. Adjust or restrict the business operations corresponding to the data flow based on the data flow's hierarchical label.

[0076] Adjusting or restricting the business operations corresponding to a data flow refers to dynamically modifying or constraining the business processing flow, access permissions, or data usage methods involved in the data flow based on the data flow classification label. This can be achieved using Access Control Lists (ACLs), Policy Enforcement Points (PEPs), or business process orchestration engines. For example, for low-trust data flows, access to sensitive data can be restricted, processing priority can be reduced, or manual approval can be triggered. The main purpose is to effectively manage potentially risky data flows and avoid security incidents from affecting business operations.

[0077] As one possible implementation, the system can automatically reject access requests for data streams marked as "low trust"; for "medium trust" data streams, additional authentication may be triggered or access to sensitive data may be restricted; and for "high trust" data streams, they may be allowed to pass normally to ensure the smooth execution of business processes.

[0078] Through the above technical solutions, this application effectively addresses multiple challenges faced in data security sharing at ports along the land bridge. First, by assessing the credential lifecycle, source context, and data request scope, it can promptly identify and prevent the abuse of high-privilege credentials or unauthorized access due to operational negligence, improving the refinement and effectiveness of access control. Second, by introducing vibration data monitoring of the physical environment of the data transmission fiber optic cable and combining it with conventional checksums for integrity verification, the system can perceive and detect potential distortion or tampering risks during data transmission at the physical level, compensating for the shortcomings of traditional verification mechanisms and ensuring the authenticity and integrity of data content. Furthermore, by comprehensively evaluating access credibility scores and data content integrity verification results, and classifying and labeling data streams, the system can comprehensively and objectively quantify the overall risk of data streams, avoiding misjudgments or omissions due to errors in single-dimensional judgments. Simultaneously, by correlating event streams from different sources, it can identify difficult-to-detect security events from the information and increase their alarm priority, thereby addressing threats caused by system vulnerabilities or incorrect permission inheritance, achieving timely threat detection and response. Ultimately, by adjusting or restricting business operations based on data flow classification and labeling, the system can adopt differentiated response strategies according to risk levels. This prevents incomplete or unauthorized data from being improperly processed, thereby ensuring the smooth execution of port business processes and enhancing the reliability of the entire port data system. This solution, through multi-layered and interconnected security protection, constructs a robust data security sharing environment, addressing the various unexpected scenarios mentioned in the background technology, and ensuring the integrity and reliability of data sharing at ports along the land bridge and the smooth execution of their business processes.

[0079] In some of the solutions mentioned above in this application, a dynamic benchmark for optical signals is proposed based on the physical characteristics of optical signals. However, in the actual port environment along the land bridge, optical cables are easily disturbed by external environmental factors such as the operation of heavy machinery and equipment and local micro-vibrations. These disturbances will affect the stability of the physical characteristics of optical signals, resulting in the inaccuracy of the established dynamic benchmark, which in turn affects the accuracy of the subsequent optical signal quality score and makes it impossible to accurately identify anomalies in the data stream.

[0080] In one possible design, such as Figure 2 As shown, the system can establish a dynamic reference for the optical signal based on the following steps: S101. Divide the physical characteristics of the optical signal into continuous data segments.

[0081] Dividing the physical characteristics of optical signals into continuous data segments refers to dividing continuously acquired physical characteristic data of optical signals, such as optical power, polarization state, spectral distribution, or dispersion coefficient, into a series of independent, temporally continuous data blocks according to a predetermined time interval or data volume. Specifically, this can be done by setting a fixed duration or a fixed number of data points. The purpose is to perform refined analysis of the local characteristics of optical signals so as to facilitate subsequent correlation and evaluation of external disturbances within a specific time window.

[0082] As one possible implementation, the system can continuously collect the physical characteristics of optical signals, such as optical power, polarization state, spectral distribution, and dispersion coefficient, at the receiving end of the data transmission optical cable. These continuously collected optical signal physical characteristic data can be divided into continuous data segments, for example, every 10 seconds as a data segment, or every 1000 accumulated sampling points as a data segment.

[0083] S102. Obtain auxiliary data on the port environment during the same period.

[0084] The port environmental auxiliary data includes the operating status of heavy machinery and equipment at the port, and the output of local micro-vibration sensors. Simultaneous port environmental auxiliary data refers to port environmental auxiliary data collected within the same time period as the acquisition of the physical characteristics of optical signals.

[0085] For example, the operating status of heavy machinery and equipment at ports can refer to the start-up, stop, and operational intensity of equipment such as cranes and forklifts.

[0086] As one possible implementation, the system can obtain the operating status of heavy machinery equipment at the port from the operation logs, vibration sensors, or acoustic sensors; and obtain local micro-vibration sensors from high-sensitivity accelerometers or fiber optic sensor arrays.

[0087] S103. Combine port environment auxiliary data to assess the degree to which the physical characteristics of optical signals in each data segment are affected by external disturbances.

[0088] Among them, assessing the degree to which the physical characteristics of optical signals within each data segment are affected by external disturbances refers to using the acquired port environment auxiliary data to analyze the physical characteristics data of optical signals within each continuous data segment, and to determine the correlation and intensity between their fluctuations or changes and the external disturbances occurring at the same time.

[0089] As one possible implementation, the system can correlate the fluctuation amplitude of the physical properties of the optical signal with the output intensity of the local micro-vibration sensor at the same time. When the micro-vibration intensity exceeds a certain preset value, or when the physical properties of the optical signal and the micro-vibration intensity show a high correlation, it can be considered that the optical signal in the data segment has been affected by external disturbance.

[0090] S104. Based on the degree to which the physical characteristics of the optical signal in each data segment are affected by external disturbances, select data segments whose degree of external disturbance is lower than a preset threshold as the benchmark valid data.

[0091] Among them, selecting data segments whose external disturbances are less than a preset threshold as benchmark valid data means selecting data segments whose physical characteristics of optical signals are less affected by external disturbances than a specific standard based on the evaluation results. These data segments are considered to be a relatively stable, reliable data set that can truly reflect the normal transmission status of optical cables.

[0092] As one possible implementation, the system can filter out data segments whose external disturbances are less than a preset threshold and use them as valid baseline data.

[0093] For example, a preset threshold of 0.05 can be set for the disturbance impact index. Any data segment whose disturbance impact index is lower than this threshold is considered as valid baseline data.

[0094] This allows us to exclude data that is highly susceptible to external environmental interference, ensuring that the data used to establish dynamic benchmarks is highly pure and representative.

[0095] S105. Based on the valid reference data, periodically update the dynamic reference of the optical signal.

[0096] The periodic updating of the dynamic reference of the optical signal refers to recalculating or adjusting the dynamic reference of the optical signal using newly selected valid reference data at predetermined time intervals or after accumulating a sufficient number of valid reference data. As one possible implementation, the system can use algorithms such as sliding window averaging, exponential smoothing, or adaptive filtering to incorporate new reference data into the calculation of the existing reference in order to update the dynamic reference of the optical signal.

[0097] This allows the dynamic reference to adapt to slow changes or seasonal drift that may occur during the long-term operation of the optical cable, maintaining its accuracy and timeliness.

[0098] For example, the dynamic reference can be set to be updated every 24 hours, or when a sufficient number (e.g., 100) of valid reference data segments have been accumulated. The update method can be a moving average method, which incorporates the latest valid reference data segments into the calculation of the dynamic reference while removing the oldest data segments, thereby ensuring that the dynamic reference can reflect the latest fluctuation range of the optical signal under normal operating conditions in real time and adapt to long-term environmental changes.

[0099] Understandably, through the aforementioned mechanism, this solution effectively addresses the issue of inaccurate dynamic benchmarks caused by external disturbances affecting optical cables in the complex environments of ports along the land bridge. Compared to establishing a benchmark solely based on the physical characteristics of the optical signal, this solution introduces calibration using external environmental data, enabling the established dynamic benchmark to eliminate the influence of external interference and thus more accurately reflect the inherent characteristics of the optical signal. Consequently, when the physical characteristics of the optical signal are compared with this more accurate dynamic benchmark, the accuracy of identifying abnormal patterns in the optical signal is significantly improved, allowing the generated optical signal quality score to more reliably indicate the integrity or potential distortion risk of the data stream. This improvement in benchmark accuracy directly enhances the reliability of the entire data stream integrity verification, ensuring the physical layer security of data transmission in complex port environments.

[0100] In some embodiments, the different sources include at least one of the following: network security devices, audit logs, credential management modules, and physical environment awareness modules; in order to correlate event streams from different sources, identify security events, and increase the alarm priority of security events, this application further includes the following steps: S201. Extract the entity identifiers involved in the event stream.

[0101] In this context, an entity identifier refers to a unique identifier possessed by an object with an independent identity or traceability within the port network. Entity identifiers include user identifiers, device identifiers, IP addresses, and data interface identifiers.

[0102] S202. Based on entity identifiers, construct the activity trajectory chain of each entity in the port network, and record the low-priority event sequence triggered by each entity in different systems and at different times.

[0103] Among them, the activity trajectory chain refers to a set of events that record the temporal sequence and system context of a series of behavioral events of an entity in the port network based on entity identifiers, with the aim of comprehensively reflecting the entity's behavioral patterns.

[0104] Low-priority event sequences refer to a series of events that may not pose a serious threat on their own, but may indicate potential security risks when they occur in a specific order or combination. These events may include multiple failed login attempts, unauthorized access attempts, and abnormal file operations. The purpose is to capture cumulative and hidden signs of threats.

[0105] As one possible implementation, the system can deploy multiple data collection agents, which are connected to the port's network security devices (such as firewalls and intrusion detection systems), audit log servers, credential management systems, and physical environment awareness modules (such as access control systems and environmental sensors). These agents are responsible for collecting event streams from their respective sources in real time. The system can search for event streams identifying entities from different sources and construct a chain of activity trajectories for each entity within the port network.

[0106] At the same time, the engine will identify and record the priority of each event, and add those events that are preset to low priority (such as single login failure, non-sensitive file access, non-critical port scanning) to the activity trajectory chain of the corresponding entity to form a low-priority event sequence.

[0107] For example, when user A logs into system S1 at time T1 and then accesses data interface D1 at time T2, these events will be recorded as nodes and edges in user A's activity trajectory chain.

[0108] S203, Define the preset threat mode.

[0109] Among them, threat patterns are combinations of low-priority events that are continuously triggered by a specific entity across time intervals or system boundaries in its activity trajectory chain.

[0110] It should be noted that these threat patterns can be defined in advance by the operator.

[0111] For example, “multiple attempts to log in to different systems within a short period of time but all failures, followed by an attempt to access an internal data interface” can be defined as a threat pattern. This pattern specifies the types of entities involved (e.g., users, IP addresses), the expected sequence of low-priority events (e.g., login failure events, interface access events), the time window in which these events occur (e.g., within 5 minutes), and whether they can cross system boundaries.

[0112] S204. Compare the activity trajectory chain with the preset threat pattern to associate event streams from different sources, identify security events, and increase the alarm priority of security events.

[0113] As one possible implementation, when the threat pattern recognition module finds that the activity trajectory chain of an entity matches any preset threat pattern, the system will identify it as a security event and raise its alarm priority.

[0114] For example, if an external IP address fails to log in to multiple internal systems within a short period of time and then attempts to access an internal data interface, the system will immediately identify this as a security event. The alert will then be escalated from a standard "information" or "warning" level to a "high-risk" or "urgent" level, triggering corresponding alert notifications, such as sending an SMS or email to the security administrator, or highlighting the alert on the Security Operations Center (SOC) dashboard.

[0115] As another possible implementation, if an activity trajectory chain is found to match any preset threat pattern, the system can accumulate risks for the entity or related activity trajectory chains; when the accumulated risks reach a preset risk threshold, the alarm priority of the activity trajectory chain is raised to the highest level.

[0116] In some preferred embodiments, this application is implemented as follows: Assume that in a port network, an external technician attempts to log in using a legacy high-privilege remote diagnostic account and subsequently attempts to access an internal data interface. The system constructs the activity trajectory chain of this external technician by associating event streams from different sources such as network security devices and audit logs. Preset threat patterns may include "external IP using internal high-privilege credentials to log in" and "high-privilege account attempting to access sensitive data interfaces," etc. When the system first detects that the external technician's activity trajectory chain matches the threat pattern of "external IP using internal high-privilege credentials to log in," the system does not immediately issue the highest-level alert, but instead accumulates risk for the external technician's entity (e.g., its IP address or associated device identifier) ​​and its activity trajectory chain. For example, the system can assign an initial risk score to this match, such as 20 points. Subsequently, if the external technician's activity trajectory chain further matches the threat pattern of "high-privilege account attempting to access sensitive data interfaces," the system will again accumulate risk for the entity and trajectory chain, for example, adding another 30 points. At this point, the accumulated risk score for the entity and trajectory chain reaches 50 points. The system's preset risk threshold can be set to 50 points. When the accumulated risk score reaches 50 points, the system determines that the behavior constitutes a high threat. At this point, the system will raise the alert priority of the external technician's activity trajectory chain to the highest level. For example, by sending a P0-level emergency alert notification to the security operations center, automated response measures can be triggered, such as temporarily isolating the IP address or disabling the remote diagnostic account.

[0117] In some embodiments, relying solely on a single type of entity or a simple sequence of events may not be sufficient to capture complex and covert threat behaviors. Furthermore, the way different types of entities interact, the timing of events, and system boundaries can also significantly impact threat identification.

[0118] To this end, in order to define a preset threat pattern, this application also includes the following steps: S301. Identify the set of multiple entities involved in the threat pattern.

[0119] The entity set specifies at least two entities of different types participating in the threat pattern. For example, this could include an "External Technician" entity (type: External User), a "Port Management Terminal" entity (type: Device), an "Internal Data Interface" entity (type: Application Interface), an "Audit Log System" entity (type: System), etc.

[0120] S302. Determine the expected interaction rules between entities in the threat model.

[0121] Interaction rules refer to the behavioral associations or dependencies that may occur between different entities under specific threat scenarios, and may include operations such as access, transmission, modification, deletion, login, and connection.

[0122] For example, the "External Technical Personnel" entity attempts to log in to the port network through the "Port Management Terminal" entity; the "External Technical Personnel" entity accesses the "Internal Data Interface" entity through the "Port Management Terminal" entity; the "Internal Data Interface" entity sends a data query request to the "Audit Log System" entity.

[0123] S303. For each entity, determine the specific low-priority event sequence that the entity will trigger in the threat mode.

[0124] The specific low-priority event sequence includes multiple specific low-priority events sorted by time sequence. These may include multiple login failures, small-volume data transmissions, access outside of working hours, and reading specific files. The purpose is to filter out valuable threat clues from massive events and avoid missing covert attacks. For example, for the "External Technical Personnel" entity, a possible low-priority event sequence includes: multiple failed login attempts outside of working hours -> successful login but with an abnormal source IP -> attempts to access multiple unrelated system directories. For the "Internal Data Interface" entity, a possible low-priority event sequence includes: receiving a query request from an unauthorized source -> querying non-sensitive data but touching sensitive metadata. For the "Audit Log System" entity, a possible low-priority event sequence includes: logging low-level abnormal login events -> logging access events to non-core business data interfaces.

[0125] S304. Determine specific low-priority events and interactions that occur within a specific time window, and allow time windows and system boundary conditions to span different system boundaries.

[0126] Among them, time windows and system boundary conditions refer to the time range in which specific low-priority events and interactions occur, as well as the system or network areas they can cross. These can include the time interval between events, the duration of events, and whether events occur in different subnets, different security domains, or different physical areas. The purpose is to accurately define the context of threat patterns, reduce false alarms, and adapt to the complex and ever-changing port network environment.

[0127] For example, the login attempts, access, and query events mentioned above occur within a consecutive 30-minute period (time window); the login attempts originate from the external network area of ​​the port, while the data interface access occurs within the internal network area of ​​the port (crossing system boundaries).

[0128] S305. Combine multiple entity sets, interaction rules, low-priority event sequences, time windows, and system boundary conditions to form a preset threat pattern.

[0129] In this way, when the actual activity trajectory chain matches this pattern, the system can accurately identify this type of complex security event and increase its alarm priority.

[0130] like Figure 3 As shown in the figure, this invention also provides a data security sharing system for ports along the land bridge. The system includes: A data stream receiving module is used to receive a data stream for making a data access request, the data stream including credentials for requesting data; The access credibility assessment module is used to assess the lifecycle, source context, and data request scope of the credentials, and generate an access credibility score. The data integrity verification module is used to monitor the physical environment vibration data of the data transmission optical cable during the transmission of the data stream, and combine the physical environment vibration data with a conventional check code to perform integrity verification on the data stream and obtain the data content integrity verification result; if the data content integrity verification result indicates that the data stream integrity verification has failed or there is a potential risk of physical layer distortion, the data stream is marked as having compromised integrity. The data stream credibility calculation and event association module is used to combine the access credibility score and the data content integrity verification result to calculate the overall credibility score of the data stream, and to classify and label the data stream according to the overall credibility score; at the same time, it associates event streams from different sources, identifies security events, and increases the alarm priority of the security events. The business operation adjustment and decision support module is used to adjust or restrict the business operations corresponding to the data stream based on the hierarchical label of the data stream.

[0131] This invention also provides a terminal device. The terminal device includes a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a data security sharing program for ports along the land bridge. When the processor executes the computer program, it implements the steps in the above-described embodiments of the data security sharing method for ports along the land bridge. Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in the above-described system embodiments.

[0132] For example, a computer program can be divided into one or more modules / units, one or more of which are stored in memory and executed by a processor to complete the present invention. One or more modules / units can be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in a terminal device.

[0133] Terminal devices can be computing devices such as desktop computers, laptops, PDAs, and smart tablets. Terminal devices may include, but are not limited to, processors and memory. Those skilled in the art will understand that the above-described components are merely examples of terminal devices and do not constitute a limitation on the terminal device. The device may include more or fewer components than described above, or a combination of certain components, or different components. For example, a terminal device may also include input / output devices, network access devices, buses, etc.

[0134] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device through various interfaces and lines.

[0135] Memory can be used to store computer programs and / or modules. The processor implements various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory, and by accessing data stored in the memory. Memory can mainly include a program storage area and a data storage area. The program storage area can store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area can store data created based on the use of the mobile phone (such as audio data, phonebook, etc.). In addition, memory can include high-speed random access memory, and can also include non-volatile memory, such as hard disk, RAM, plug-in hard disk, SmartMedia Card (SMC), Secure Digital (SD) card, Flash Card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0136] If the modules / units integrated into the terminal device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or system capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0137] It should be noted that the system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the system embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0138] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention in detail. It should be understood that the above are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.

Claims

1. A method for secure data sharing at ports along a land bridge, characterized in that, include: Receive a data stream for making a data access request, the data stream including credentials for requesting data; Assess the lifecycle, source context, and data request scope of the credentials to generate an access trust score; During the transmission of the data stream, the physical environment vibration data of the data transmission optical cable is monitored, and the data stream is checked for integrity by combining the physical environment vibration data with a conventional check code to obtain the data content integrity check result; if the data content integrity check result indicates that the data stream integrity check has failed or there is a potential risk of physical layer distortion, the data stream is marked as having compromised integrity. By combining the access credibility score and the data content integrity verification result, the overall credibility score of the data stream is calculated, and the data stream is classified and labeled according to the overall credibility score; at the same time, event streams from different sources are correlated to identify security events and the alarm priority of the security events is increased. Based on the hierarchical labeling of the data stream, adjust or restrict the business operations corresponding to the data stream.

2. The method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The physical environment vibration data of the monitored data transmission optical cable is used, and combined with the physical environment vibration data and a conventional checksum, the data stream is subjected to integrity verification to obtain the data content integrity verification result, including: At the receiving end of the data transmission optical cable, the physical characteristics of the optical signal of the data stream are collected; Based on the physical characteristics of the optical signal, a dynamic reference for the optical signal is established; the dynamic reference reflects the fluctuation range of the physical characteristics of the optical signal under normal operating conditions. The physical properties of the optical signal are compared with the dynamic reference to identify whether there is an abnormal mode in the optical signal, and an anomaly identification result is obtained; the abnormal mode includes instantaneous polarization state anomaly, spectral distribution anomaly, and dispersion coefficient anomaly. Based on the anomaly identification results, an optical signal quality score is generated, and the optical signal quality score is used as the content integrity verification result.

3. A method for secure data sharing at ports along a land bridge according to claim 2, characterized in that, The step of establishing a dynamic reference for the optical signal based on the physical characteristics of the optical signal includes: The physical characteristics of the optical signal are divided into continuous data segments; Acquire concurrent port environmental auxiliary data, including the operating status of port heavy machinery and equipment and the output of local micro-vibration sensors; Based on the aforementioned port environment auxiliary data, assess the degree to which the physical characteristics of the optical signal within each data segment are affected by external disturbances; Based on the degree to which the physical characteristics of the optical signal within each data segment are affected by external disturbances, data segments whose degree of external disturbance is lower than a preset threshold are selected as the benchmark valid data. Based on the aforementioned valid reference data, the dynamic reference of the optical signal is periodically updated.

4. A method for secure data sharing at ports along a land bridge according to claim 2, characterized in that, The method further includes: Compared to the dynamic reference of the optical signal, if the instantaneous polarization state of the optical signal undergoes a non-periodic change exceeding a preset threshold within a preset time period, then the abnormal mode of the optical signal is determined to be an instantaneous polarization state abnormality. Compared to the dynamic reference of the optical signal, if the spectral distribution of the optical signal shows transient broadening or shift, then the abnormal mode of the optical signal is determined to be spectral distribution abnormality. Compared to the dynamic reference of the optical signal, if the dispersion coefficient of the optical signal fluctuates nonlinearly within a preset time during transmission, the abnormal mode of the optical signal is determined to be an abnormal dispersion coefficient. If an abnormal pattern is detected in the optical signal, the data stream is flagged as having a risk of implicit physical layer distortion of the optical signal.

5. A method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The different sources include at least one of the following: network security devices, audit logs, credential management modules, and physical environment awareness modules; The association of event streams from different sources, identification of security events, and elevation of the alarm priority of the security events include: Extract the entity identifiers involved in the event stream, including user identifier, device identifier, IP address, and data interface identifier; Based on the entity identifier, construct the activity trajectory chain of each entity in the port network, and record the low-priority event sequence triggered by each entity in different systems and at different time points; Define a preset threat pattern; the threat pattern is a combination of low-priority events that are continuously triggered by a specific entity across time intervals or system boundaries in the activity trajectory chain. The activity trajectory chain is compared with the preset threat pattern to associate event streams from different sources, identify security events, and increase the alarm priority of the security events.

6. A method for secure data sharing at ports along a land bridge according to claim 5, characterized in that, The step of comparing the activity trajectory chain with the preset threat pattern to correlate event streams from different sources, identify security events, and increase the alarm priority of the security events includes: If the activity trajectory chain is found to match any preset threat pattern, then risk accumulation is performed on the entity or the related activity trajectory chain; When the accumulated risk reaches a preset risk threshold, the alarm priority of the activity trajectory chain will be raised to the highest level.

7. A method for secure data sharing at ports along a land bridge according to claim 5, characterized in that, The defined preset threat patterns include: Identify a set of multiple entities involved in the threat pattern, wherein the set of entities specifies at least two entities of different types participating in the threat pattern; Determine the expected interaction rules between entities in the threat pattern; For each entity, a specific low-priority event sequence that the entity will trigger in the threat pattern is determined; the specific low-priority event sequence includes multiple specific low-priority events ordered in time series. The specific low-priority events and interactions are determined to occur within a specific time window, and can span different system boundary time windows and system boundary conditions. The preset threat pattern is formed by combining the multiple entity sets, the interaction rules, the low-priority event sequence, the time window, and the system boundary conditions.

8. A method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The assessment of the credential's lifecycle, source context, and data request scope to generate an access trust score includes: Configure a set of evaluation parameters for credential lifecycle, source context, and data request scope; the set of evaluation parameters includes credential validity period, source network region, access time window, data sensitivity classification, and access rules; Adjust the validity period of the voucher and the access time window based on the port business operation status signal; The set of assessment parameters is adjusted according to the received threat intelligence instructions to obtain the adjusted set of assessment parameters; the threat intelligence instructions are used to instruct the adjustment of at least one of the following: the trust level of the source network area, the data sensitivity classification and access rules, the update instructions based on the internal security policy, the automatic credential clearing trigger conditions and data access restrictions; Based on the adjusted set of evaluation parameters, the lifecycle, source context, and data request scope of the credentials used in the data stream are evaluated. Based on the evaluation results, an access credibility score is generated.

9. A method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The calculation of the overall credibility score of the data stream, and the classification and labeling of the data stream based on the overall credibility score, includes: The access credibility score and the data content integrity verification result are weighted and summed to obtain the overall credibility score of the data stream; The data stream is classified and labeled according to the overall credibility score and the level mapping relationship; the level mapping relationship includes the mapping relationship between different credibility scores and different credibility levels.

10. A data security sharing system for ports along a land bridge, used to ensure the integrity, reliability, and smooth execution of business processes of data sharing at ports along a land bridge, characterized in that... The system includes: A data stream receiving module is used to receive a data stream for making a data access request, the data stream including credentials for requesting data; The access credibility assessment module is used to assess the lifecycle, source context, and data request scope of the credentials, and generate an access credibility score. The data integrity verification module is used to monitor the physical environment vibration data of the data transmission optical cable during the transmission of the data stream, and combine the physical environment vibration data with a conventional check code to perform integrity verification on the data stream and obtain the data content integrity verification result; if the data content integrity verification result indicates that the data stream integrity verification has failed or there is a potential risk of physical layer distortion, the data stream is marked as having compromised integrity. The data stream credibility calculation and event association module is used to combine the access credibility score and the data content integrity verification result to calculate the overall credibility score of the data stream, and to classify and label the data stream according to the overall credibility score; at the same time, it associates event streams from different sources, identifies security events, and increases the alarm priority of the security events. The business operation adjustment and decision support module is used to adjust or restrict the business operations corresponding to the data stream based on the hierarchical label of the data stream.

Citation Information

Patent Citations

  • Identity management system and method including architecture for the same

    CA2801659A1

  • Zero-trust access control method based on cloud side-end cooperation

    CN119316235A

  • Government affair data sharing system based on data security law risk control mode

    CN119989417A

  • Autonomous response trusted data hierarchical fusing control method and system

    CN120320929A

  • Data asset credible circulation method and system based on intelligent contract dynamic evaluation

    CN120415902A