A land bridge along the port data security sharing method and system

By assessing the credibility of credentials and the integrity of data transmission, and combining multi-source event analysis, the data sharing at ports along the land bridge was graded, marked, and operational adjustments were made. This resolved the issues of unauthorized access and data distortion during the data sharing process at ports along the land bridge, thereby improving the security and credibility of data sharing.

CN120934818BActive Publication Date: 2026-03-20HORGOS ELECTRONIC PORT TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

During the data security sharing process at ports along the land bridge, there are issues such as unauthorized access due to leftover high-level credentials, data stream errors caused by vibrations in optical cables during data transmission, and delayed response to security incidents, which make it impossible to guarantee the integrity and reliability of data sharing.

Method used

By assessing the lifecycle, source context, and data request scope of credentials, monitoring the physical environment vibration data of the data transmission fiber optic cable, performing integrity checks in conjunction with conventional check codes, and correlating multi-source event streams, the alarm priority of security events is improved. Finally, the data stream is graded and marked and business operations are adjusted based on the overall trust score.

Benefits of technology

It effectively solves the problems of data distortion, unauthorized access, and delayed response to security incidents, improves the security, integrity, and reliability of data sharing at ports along the land bridge, and avoids business judgment errors caused by data distortion or security vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934818B_ABST
    Figure CN120934818B_ABST
Patent Text Reader

Abstract

The application discloses a land bridge along the line port data security sharing method and system, relates to the land bridge along the line port data security sharing field, and is used for improving the integrity and reliability of the land bridge along the line port data sharing, and comprises the following steps: receiving a data stream for carrying out a data access request, evaluating the life cycle, source context and data request range of a credential, and generating an access reliability score; in the transmission process of the data stream, monitoring physical environment vibration data of a data transmission optical cable, and combining the physical environment vibration data and a conventional check code to check the integrity of the data stream; combining the access reliability score and the data content integrity check result, calculating a comprehensive reliability total score of the data stream, and marking the data stream according to the comprehensive reliability total score; meanwhile, associating event streams from different sources, identifying security events, and improving the alarm priority of the security events; and according to the marking of the data stream, adjusting or limiting the business operation corresponding to the data stream.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of data security sharing of land bridge along the port, and particularly relates to a data security sharing method and system of land bridge along the port. BACKGROUND

[0002] In the process of data security sharing of land bridge along the port, when the port information technology maintenance personnel leaves a high-privilege remote diagnosis account credential due to operational negligence, and the terminal computer is sent to an external repair point for detection, the external technician accidentally discovers and attempts to use the credential to make unauthorized access to the port network, while the port network security isolation device fails to effectively prevent the internal credential login attempt in the non-standard connection mode due to the firmware logic vulnerability, resulting in that the audit log recording system fails to timely alarm due to the low priority setting, and thus the external personnel discovers and uses an internal data synchronization interface exposed due to the permission inheritance error.

[0003] The random query operation of the external personnel still touches and transmits a small amount of personnel entry and exit record metadata containing sensitive information, and in the transmission process, the port network transmission optical cable causes data stream bit error due to the instantaneous jitter of optical signals caused by external physical vibration, and finally the receiving system fails to completely interrupt the transmission due to the ambiguity of the processing logic of the "partially damaged data but still can be parsed" condition in the data sharing protocol, but instead performs incomplete data parsing, thereby causing the port management personnel to make an error judgment in the business process based on the incomplete and unauthorized access data.

[0004] Therefore, how to ensure the integrity, credibility and smooth execution of the business process of the data sharing of land bridge along the port in the above complex and multiple unexpected superimposed scenarios is a technical problem to be solved. SUMMARY

[0005] The present application provides a data security sharing method of land bridge along the port, which is used for improving the integrity and credibility of the data sharing of land bridge along the port.

[0006] In a first aspect, to solve the above technical problems, the present application provides a land bridge along the port data security sharing method, comprising: receiving data stream for data access request, data stream includes the credentials for requesting data; evaluate the life cycle of the credentials, the source context and the data request range, generate access credibility score; in the transmission process of data stream, monitor the physical environment vibration data of data transmission cable, and combine the physical environment vibration data and the conventional check code, carry out integrity check to data stream, obtain data content integrity check result; if the data content integrity check result indicates that the data stream integrity check fails or there is a potential distortion risk in the physical layer, mark the data stream as integrity damaged; combine the access credibility score and the data content integrity check result, calculate the comprehensive credibility total score of the data stream, and mark the data stream according to the comprehensive credibility total score; at the same time, associate the event stream from different sources, identify security events, and improve the alarm priority of security events; according to the hierarchical marking of data stream, adjust or limit the business operation corresponding to data stream.

[0007] Optionally, the physical environment vibration data of the data transmission cable is monitored, and the data stream is checked for integrity in combination with the physical environment vibration data and the conventional check code to obtain the data content integrity check result, comprising: collecting the optical signal physical characteristics of the data stream at the receiving end of the data transmission cable; according to the optical signal physical characteristics, a dynamic reference of the optical signal is established; the dynamic reference reflects the fluctuation range of the optical signal physical characteristics under normal operating conditions; the optical signal physical characteristics are compared with the dynamic reference to identify whether the optical signal has an abnormal mode, and an abnormal identification result is obtained; the abnormal mode includes instantaneous polarization state abnormality, spectral distribution abnormality and dispersion coefficient abnormality; according to the abnormal identification result, an optical signal quality score is generated, and the optical signal quality score is taken as the content integrity check result.

[0008] Optionally, according to the optical signal physical characteristics, a dynamic reference of the optical signal is established, comprising: dividing the optical signal physical characteristics into continuous data segments; obtaining contemporaneous port environment auxiliary data, the port environment auxiliary data including port heavy machinery equipment operating state and local microseismic vibration sensor output; in combination with the port environment auxiliary data, the degree of influence of the optical signal physical characteristics in each data segment by external disturbance is evaluated; according to the degree of influence of the optical signal physical characteristics in each data segment by external disturbance, data segments with a degree of influence by external disturbance lower than a preset threshold are selected as reference valid data; based on the reference valid data, the dynamic reference of the optical signal is periodically updated.

[0009] Optionally, the method further comprises: determining that the abnormal mode of the optical signal is a transient polarization state abnormality if, compared with the dynamic baseline of the optical signal, the transient polarization state of the optical signal has a non-periodic change exceeding a preset threshold within a preset time length; determining that the abnormal mode of the optical signal is a spectral distribution abnormality if, compared with the dynamic baseline of the optical signal, the spectral distribution of the optical signal has a transient broadening or shift; determining that the abnormal mode of the optical signal is a dispersion coefficient abnormality if, compared with the dynamic baseline of the optical signal, the dispersion coefficient of the optical signal has a nonlinear fluctuation within a preset time length during transmission; and marking that there is a risk of optical signal physical layer implicit distortion in the data stream in the case of identifying the abnormal mode of the optical signal.

[0010] Optionally, the different sources include at least one of the following: a network security device, an audit log, a credential management module, and a physical environment perception module; and the correlation of the event streams from different sources, the identification of the security event, and the promotion of the alarm priority of the security event comprise: extracting entity identifiers involved in the event streams, the entity identifiers including user identifiers, device identifiers, IP addresses, and data interface identifiers; constructing an activity track chain of each entity in the port network based on the entity identifiers, and recording a low-priority event sequence triggered by each entity at different time points in different systems; defining a preset threat mode; the threat mode is a combination of low-priority events triggered by a specific entity in the activity track chain across time intervals or system boundaries; and comparing the activity track chain with the preset threat mode to correlate the event streams from different sources, identify the security event, and promote the alarm priority of the security event.

[0011] Optionally, the comparison of the activity track chain with the preset threat mode to correlate the event streams from different sources, identify the security event, and promote the alarm priority of the security event comprises: if the activity track chain is found to match any of the preset threat modes, accumulating risks for the entity or the related activity track chain; and promoting the alarm priority of the activity track chain to the highest level when the risk accumulation reaches a preset risk threshold.

[0012] Optionally, the definition of the preset threat mode comprises: determining a plurality of entity sets involved in the threat mode, the entity sets specifying at least two different types of entities participating in the threat mode; determining interaction rules expected between the entities in the threat mode; determining, for each entity, a specific low-priority event sequence that the entity will trigger in the threat mode; the specific low-priority event sequence includes a plurality of specific low-priority events sorted in a time sequence; determining that the specific low-priority events and the interactions occur within a specific time window and that the time window and system boundary conditions can span different system boundaries; and combining the plurality of entity sets, the interaction rules, the low-priority event sequences, and the time window and system boundary conditions to form the preset threat mode.

[0013] Optionally, the life cycle, source context and data request range of the credential are evaluated, an access trust score is generated, including: configuring a set of evaluation parameters of the life cycle, source context and data request range of the credential; the set of evaluation parameters includes a credential validity period, a source network area, an access time window, a data sensitivity classification and an access rule; the credential validity period and the access time window are adjusted according to a port business operation state signal; the set of evaluation parameters is adjusted according to a received threat intelligence instruction to obtain an adjusted set of evaluation parameters; the threat intelligence instruction is used to indicate adjustment of at least one of the following: a trust level of the source network area, the data sensitivity classification and the access rule, an internal security policy update instruction, a credential automatic clearing trigger condition and a data access restriction; based on the adjusted set of evaluation parameters, the life cycle, source context and data request range of the credential used by the data flow are evaluated; and according to the evaluation result, the access trust score is generated.

[0014] Optionally, the comprehensive trust score of the data flow is calculated, and the data flow is marked according to the comprehensive trust score, including: the access trust score and the data content integrity check result are weighted and summed to obtain the comprehensive trust score of the data flow; the data flow is marked according to the comprehensive trust score and a level mapping relationship; the level mapping relationship includes a mapping relationship between different trust scores and different trust levels.

[0015] In a second aspect, the present application provides a land bridge along the port data security sharing system, which is used for land bridge along the port data security sharing, and the system includes:

[0016] A data flow receiving module is configured to receive a data flow for a data access request, and the data flow includes a credential for requesting data;

[0017] An access trust evaluation module is configured to evaluate the life cycle, source context and data request range of the credential, and generate an access trust score;

[0018] A data integrity checking module is configured to monitor physical environment vibration data of a data transmission optical cable during transmission of the data flow, and combine the physical environment vibration data and a regular check code to check the integrity of the data flow, and obtain a data content integrity check result; if the data content integrity check result indicates that the data flow integrity check fails or there is a potential distortion risk at the physical layer, the data flow is marked as integrity damaged;

[0019] A data flow trust calculation and event association module is configured to combine the access trust score and the data content integrity check result to calculate a comprehensive trust score of the data flow, and mark the data flow according to the comprehensive trust score; at the same time, event streams from different sources are associated to identify security events and improve the alarm priority of the security events;

[0020] The business operation adjustment and decision support module is used to adjust or restrict the business operations corresponding to the data flow based on the hierarchical labeling of the data flow.

[0021] Compared with the prior art, the present invention has the following beneficial effects:

[0022] This application provides a method and system for secure data sharing at ports along the land bridge. By comprehensively evaluating the credibility of data access credentials, monitoring the physical integrity of data transmission in real time, and combining multi-source event correlation analysis, it hierarchically labels data streams and adjusts business operations. This effectively solves problems such as data distortion, unauthorized access, and delayed response to security incidents in existing technologies. It has the advantage of effectively improving the security, integrity, and credibility of data sharing at ports along the land bridge, and avoiding business judgment errors caused by data distortion or security vulnerabilities. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of a method for securely sharing data at ports along a land bridge, provided by an embodiment of the present invention.

[0024] Figure 2 This is a schematic diagram of another method for secure data sharing at ports along the land bridge provided in this embodiment of the invention;

[0025] Figure 3 This is a schematic diagram of a data security sharing system for ports along the land bridge provided in an embodiment of the present invention. Detailed Implementation

[0026] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of this application, and not all embodiments. The components of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0027] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0028] The following specific embodiments will provide a detailed introduction and explanation of a data security sharing method for ports along the land bridge provided in this application.

[0029] Reference Figure 1 This invention provides a method for secure data sharing at ports along a land bridge, comprising the following steps:

[0030] S1 receives the data stream used to make a data access request.

[0031] The data stream includes credentials used to request data.

[0032] As one possible implementation, when a user wants to access data of ports along the land bridge, they can log in to the Land Bridge Port Data Security Sharing System (hereinafter referred to as the System) through a terminal device to send a data stream for data access request to the System; correspondingly, the System receives the data stream for data access request.

[0033] S2. Evaluate the lifecycle of the credentials, the source context, and the scope of the data request to generate an access credibility score.

[0034] The access credibility score refers to the quantitative assessment of the legality, reliability, and potential risk of a data access request. It can be implemented using rule-based scoring models, machine learning algorithms, or expert systems. For example, it can be calculated by analyzing dimensions such as the validity period of credentials, the trust level of the source network, the access time window, and the sensitivity of the requested data.

[0035] As one possible implementation, the system can generate an access trust score based on the following steps:

[0036] S21. Configure the set of evaluation parameters for credential lifecycle, source context, and data request scope.

[0037] The evaluation parameter set includes the validity period of the credential, the source network region, the access time window, data sensitivity classification, and access rules.

[0038] As one possible implementation, the system can configure an initial set of evaluation parameters based on user input.

[0039] For example, the validity period of credentials can be set to the default 90 days, and the source network area can be divided into "Internal Trust Zone," "External Cooperation Zone," and "Internet Zone," each assigned a different initial trust level (e.g., high, medium, low). The access time window can be set to 8:00 to 18:00 on weekdays. Data sensitivity categories can include "Public," "Internal," "Sensitive," and "Top Secret," with corresponding access rules preset for each category.

[0040] S22, adjusting the validity period and access time window of the credential according to the port business operation state signal.

[0041] The port business operation state signal refers to real-time or quasi-real-time information reflecting the current business operation of the port. For example, it can include business peak period, normal business, and business peak period, which can include cargo throughput, customs clearance efficiency, and personnel flow. The purpose is to dynamically adapt the validity of the credential and the access time to the actual needs of the port business.

[0042] As a possible implementation, the system can reduce the validity period of the credential and increase the access time window when the port business operation state signal indicates that the current business operation of the port is "business peak period".

[0043] For example, when the port business enters the holiday peak period, such as the Spring Festival or the National Day period, the system can receive a "business peak period" state signal from the port business management system. At this time, the system can automatically shorten the validity period of all newly issued or renewed credentials from 90 days to 30 days and adjust the access time window to 24 hours a day to meet the continuity requirements of the peak period business, while reducing the risk by shortening the validity period.

[0044] S23, adjusting the evaluation parameter set according to the received threat intelligence instruction to obtain an adjusted evaluation parameter set.

[0045] The threat intelligence instruction is used to indicate the adjustment of at least one of the following: trust level of source network area, data sensitivity classification and access rule, internal security policy update instruction, credential automatic removal trigger condition and data access restriction.

[0046] The internal security policy update instruction is an instruction issued by the port internal security management department or system to adjust the security policy configuration, which can include modifications to user permissions, data classification, and access control rules.

[0047] The credential automatic removal trigger condition refers to the rule that the system automatically revokes or deletes the credential when a specific pre-set condition is met, which can include credential expiration, user resignation, and abnormal behavior.

[0048] The data access restriction refers to the restriction condition imposed on the data access behavior, which can include access permissions, access frequency, and data desensitization requirements.

[0049] The threat intelligence instruction can include information about potential security threats, such as lists of malicious IP addresses, known attack patterns, and vulnerability warnings, with the aim of adjusting security evaluation parameters in a timely manner to respond to changes in external security threats.

[0050] For example, when the system receives a threat intelligence instruction from an external threat intelligence platform push that "a certain overseas IP segment has a large number of malicious scanning behaviors", the system can immediately adjust the trust level of the "Internet area" to which the IP segment belongs from "low" to "extremely low", and trigger more stringent review of all data access requests from the area. At the same time, if the internal security policy update instruction indicates that "all data access involving personnel entry and exit records must enable two-factor authentication and be limited to specific security terminals", the system can immediately update the data sensitivity classification and access rules to raise the data sensitivity of "personnel entry and exit records" to "top secret" and require that two-factor authentication and specific terminal access conditions be met when accessing such data.

[0051] In addition, if the internal security policy update instruction also indicates that "for credentials that have failed to log in for three consecutive times, the automatic clearing trigger condition should take effect immediately", the system can adjust the credential automatic clearing trigger condition accordingly to ensure that abnormal credentials are invalidated in a timely manner.

[0052] S24, based on the adjusted evaluation parameter set, evaluating the life cycle, source context and data request range of the data flow used credential.

[0053] As a possible implementation, the system can compare the credential validity period in the evaluation parameter set with the life cycle of the data flow used credential to obtain a life cycle score;

[0054] Compare the source network area in the evaluation parameter set with the source context of the data flow used credential to obtain a source context score;

[0055] Compare the data sensitivity classification and access rules in the evaluation parameter set with the data request range of the data flow used credential to obtain a data request range score.

[0056] In one example, when the life cycle of the data flow used credential is within the credential validity period, the life cycle score is 1, otherwise it is 0. When the source context of the data flow used credential does not include malicious source network area related content, the source context score is 1, otherwise it is 0. When the data request range of the credential meets the data sensitivity classification and access rules, the data request range score is 1, otherwise it is 0.

[0057] S25, generating an access credibility score according to the evaluation result.

[0058] As a possible implementation, the system can perform weighted summation processing on the life cycle score, source context score and data request range score to obtain the access credibility score.

[0059] S3, in the process of data stream transmission, monitoring the physical environment vibration data of the data transmission optical cable, and combining the physical environment vibration data and the conventional check code, checking the integrity of the data stream to obtain the data content integrity check result.

[0060] If the data content integrity check result indicates that the data stream integrity check fails or there is a potential distortion risk at the physical layer, the data stream is marked as integrity damaged.

[0061] The data transmission optical cable physical environment vibration data refers to the vibration information of the physical environment of the optical cable collected by the sensor during data transmission. It can be realized by optical fiber sensing technology, piezoelectric sensor or micro-electro-mechanical system (MEMS) sensor, such as distributed optical fiber sensing system or vibration sensor attached to the optical cable. The main purpose is to realize real-time monitoring of the physical integrity of the data transmission link and timely discover potential physical interference or attack.

[0062] As a possible implementation manner, the system can collect the optical cable micro-vibration data when the data stream is transmitted through the data transmission optical cable, and check the integrity of the data stream in combination with the data packet CRC code to obtain the data content integrity check result.

[0063] As another possible implementation manner, the system can check the integrity of the data stream based on the following steps:

[0064] S31, at the receiving end of the data transmission optical cable, collecting the optical signal physical characteristics of the data stream.

[0065] The optical signal physical characteristics refer to various physical parameters exhibited by the optical signal during transmission in the optical fiber, which can include the power, wavelength, polarization state, spectral distribution, dispersion coefficient, signal-to-noise ratio, etc. of the optical signal.

[0066] As a possible implementation manner, at the receiving end of the data transmission optical cable, a set of optical signal monitoring equipment can be deployed, and the optical signal physical characteristics of the data stream can be collected based on the optical signal monitoring equipment.

[0067] For example, the optical signal monitoring equipment can be an integrated photodetector array and high-speed digital signal processor, which is used to collect the optical signal physical characteristics of the data stream in real time.

[0068] S32, establishing a dynamic reference of the optical signal according to the optical signal physical characteristics.

[0069] The dynamic reference reflects the fluctuation range of the optical signal physical characteristics under normal operating conditions.

[0070] As a possible implementation manner, the system can continuously collect the physical characteristic data of the optical signals in the initial stage or stable operation stage of normal operation of the optical cable, and utilize a statistical analysis method, for example, calculate the average value and standard deviation of each physical characteristic parameter in a sliding time window, so as to construct a normal fluctuation range varying with time.

[0071] S33, compare the physical characteristics of the optical signals with the dynamic reference, identify whether the optical signals have abnormal patterns, and obtain an abnormal identification result.

[0072] The abnormal patterns include instantaneous polarization state abnormality, spectrum distribution abnormality, and dispersion coefficient abnormality.

[0073] As a possible implementation manner, compared with the dynamic reference of the optical signals, if the instantaneous polarization state of the optical signals has a non-periodic change exceeding a preset threshold within a preset time length, it is determined that the abnormal pattern of the optical signals is instantaneous polarization state abnormality.

[0074] Compared with the dynamic reference of the optical signals, if the spectrum distribution of the optical signals has instantaneous broadening or deviation, it is determined that the abnormal pattern of the optical signals is spectrum distribution abnormality.

[0075] Compared with the dynamic reference of the optical signals, if the dispersion coefficient of the optical signals has a nonlinear fluctuation within a preset time length in the transmission process, it is determined that the abnormal pattern of the optical signals is dispersion coefficient abnormality.

[0076] In the case of identifying the abnormal pattern of the optical signals, it is marked that the data stream has a risk of optical signal physical layer implicit distortion.

[0077] In some preferred embodiments, the application is implemented as follows. In order to identify the instantaneous polarization state anomaly of the optical signal, a high-speed polarization state analyzer can be deployed to collect the instantaneous polarization state data of the optical signal in real time. The analyzer can collect data every 10 milliseconds and compare the collected polarization state data with the pre-established dynamic reference. If the trajectory point of the polarization state on the Poincare sphere deviates from the dynamic reference range by more than the pre-set 5-degree threshold within a pre-set 1-second time period, and such deviation does not present regular periodic fluctuations but random or sudden changes, the system can determine that the optical signal has an instantaneous polarization state anomaly. For the identification of spectral distribution anomaly, an integrated optical spectrum analysis module can be used to continuously monitor the spectral shape of the optical signal. The module can scan the spectrum of the optical signal every 50 milliseconds. If the 3dB bandwidth of the optical signal is temporarily widened by more than the pre-set 10% threshold, or the center wavelength is temporarily shifted by more than the pre-set 0.1 nanometer threshold, the system can determine that the optical signal has a spectral distribution anomaly. In terms of the detection of dispersion coefficient anomaly, an online dispersion monitor can be used to periodically measure the dispersion coefficient of the optical signal. The monitor can update the dispersion coefficient data every 1 minute. If the dispersion coefficient changes at a rate exceeding the pre-set 0.5 ps / nm / km threshold within 5 consecutive minutes, and such change does not conform to the linear trend of normal fiber aging or temperature change but presents nonlinear, sudden fluctuations, the system can determine that the optical signal has a dispersion coefficient anomaly. Once any of the above types of optical signal anomaly patterns is identified, the system can immediately add a "physical layer implicit distortion risk" label to the metadata of the data stream, or write this information to the security event log, and trigger the corresponding alarm mechanism, so that subsequent data processing and security policies can respond in a timely manner.

[0078] S34, generating an optical signal quality score according to the abnormality identification result, and taking the optical signal quality score as the content integrity verification result.

[0079] As a possible implementation, the system can assign a pre-set risk value or weight to each identified abnormality pattern, and perform cumulative or weighted average calculation according to the severity of the anomaly, to generate an optical signal quality score, and take the optical signal quality score as the content integrity verification result.

[0080] S4, calculating the comprehensive trustworthiness total score of the data stream in combination with the access trustworthiness score and the data content integrity verification result, and marking the data stream according to the comprehensive trustworthiness total score; at the same time, associating event streams from different sources, identifying security events, and raising the alarm priority of the security events.

[0081] The hierarchical marking refers to dividing the data flow into different security levels or risk categories according to the total score of the comprehensive credibility, which can be implemented by using a preset threshold range, a machine learning classifier or a dynamic adjustment mechanism based on a strategy, for example, marking the data flow as “highly credible”, “moderately credible” or “lowly credible”, which is mainly to implement differentiated security strategies and business operations for data flows of different risk levels.

[0082] The correlation of event streams from different sources refers to the aggregation, analysis and correlation of event data from multiple independent security information sources such as network security devices, audit logs, credential management modules and physical environment perception modules, which can be implemented by using a security information and event management (SIEM) system, a big data analysis platform or a graph database technology, for example, by analyzing the correlation between different events in terms of time, entity or behavior patterns, which is mainly to identify complex security threats or attack chains from massive events that cannot be found by a single event.

[0083] As a possible implementation manner, the system can perform weighted summation on the access credibility score and the data content integrity verification result to obtain the total score of the comprehensive credibility of the data flow, and perform hierarchical marking on the data flow according to the total score of the comprehensive credibility and the level mapping relationship.

[0084] It should be noted that the level mapping relationship includes the mapping relationship between different credibility total scores and different credibility levels.

[0085] In some preferred embodiments, the weighted summation on the access credibility score and the data content integrity verification result can be specifically implemented by the following manner: assuming that the range of the access credibility score is 0 to 100, and the range of the data content integrity verification result is also 0 to 100. A weight coefficient w1 can be set for the access credibility score, and a weight coefficient w2 can be set for the data content integrity verification result, and w1 + w2 = 1. For example, if the port business pays more attention to the integrity of the data content, w1 can be set as 0.4, and w2 can be set as 0.6. Then, the total score of the comprehensive credibility of the data flow = (access credibility score * 0.4) + (data content integrity verification result * 0.6).

[0086] Further, the hierarchical marking on the data flow according to the total score of the comprehensive credibility and the level mapping relationship can be specifically implemented by defining a hierarchical rule table. For example, the following level mapping relationship can be set:

[0087] If the total score of the comprehensive credibility is between 90 and 100, it is marked as a “highly credible” level.

[0088] If the total score of the comprehensive credibility is between 70 and 89, it is marked as a “moderately credible” level.

[0089] If the total score of the comprehensive trustworthiness is between 50 and 69, it is marked as a "low trust" level.

[0090] If the total score of the comprehensive trustworthiness is less than 50, it is marked as an "untrusted" level.

[0091] When the total score of the comprehensive trustworthiness of a data stream is calculated, the system queries the grading rule table to map it to the corresponding trust level. For example, if the total score of the comprehensive trustworthiness of a data stream is 85, it will be marked as a "medium trust" level. This specific weighted summation and grading marking method makes the security evaluation of the data stream more refined and operable, and provides a clear basis for subsequent business operation adjustment.

[0092] S5. Adjust or limit the business operation corresponding to the data stream according to the grading marking of the data stream.

[0093] Among them, adjusting or limiting the business operation corresponding to the data stream refers to dynamically modifying or restricting the business processing flow, access permission or data usage mode involved in the data stream according to the grading marking of the data stream, which can be realized by using an access control list ACL, a policy enforcement point PEP or a business process orchestration engine. For example, for a low trustworthiness data stream, its access to sensitive data can be limited, the processing priority can be reduced, or manual approval can be triggered. The main purpose is to effectively control the potential risk data stream and avoid the impact of security incidents on business.

[0094] As a possible implementation, for a data stream marked as "low trust", the system can automatically reject its access request; for a "medium trust" data stream, additional identity verification or limitation of access to sensitive data can be triggered; and for a "high trust" data stream, it is allowed to pass normally to ensure smooth execution of the business process.

[0095] Through the technical solution, the multiple problems in the process of port data security sharing along the land bridge can be effectively solved. First, by evaluating the credential life cycle, source context and data request range, high-privilege credential misuse or unauthorized access caused by operational negligence can be identified and prevented in a timely manner, improving access control refinement and effectiveness. Second, by introducing data transmission cable physical environment vibration data monitoring and combining with conventional check codes for integrity verification, the system can perceive and detect potential distortion or tampering risks in the data transmission process from the physical layer, making up for the shortcomings of traditional verification mechanisms and ensuring the authenticity and integrity of the data content. Further, the access credibility score and data content integrity verification result are comprehensively evaluated, and the data stream is marked with a classification, so that the system can make a comprehensive and objective quantitative judgment on the overall risk of the data stream, avoiding misjudgment or missed judgment due to single-dimensional judgment errors. At the same time, by correlating event streams from different sources, difficult-to-detect security events can be identified from the information, and the alarm priority can be improved, so as to deal with threats caused by system vulnerabilities or permission inheritance errors, and realize the timeliness of threat discovery and response. Finally, according to the classification marking of the data stream, the business operation is adjusted or limited, so that the system can adopt differentiated response strategies according to the risk level, avoiding the improper handling of incomplete or unauthorized data, thereby ensuring the smooth execution of port business processes and enhancing the reliability of the entire port data system. The present scheme builds a robust data security sharing environment through multi-level and linked security protection, and deals with various unexpected scenarios mentioned in the background technology, ensuring the integrity, credibility and smooth execution of the port data sharing along the land bridge.

[0096] In some of the above schemes of the present application, a dynamic reference of the optical signal is established according to the physical characteristics of the optical signal. However, in the actual port environment along the land bridge, the optical cable is easily disturbed by external environmental factors such as the operation of heavy machinery and local micro-vibration, which affects the stability of the physical characteristics of the optical signal, resulting in inaccurate dynamic reference, and further affecting the accuracy of subsequent optical signal quality scoring, and unable to accurately identify the abnormalities in the data stream.

[0097] In one possible design, as shown in Figure 2 , the system can establish a dynamic reference of the optical signal based on the following steps:

[0098] S101, divide the physical characteristics of the optical signal into continuous data segments.

[0099] The division of the optical signal physical characteristics into continuous data segments refers to dividing the continuously collected optical signal physical characteristic data, such as optical power, polarization state, spectral distribution, or dispersion coefficient, into a series of independent, time-continuous data blocks according to a predetermined time interval or data size. Specifically, the division can be achieved by setting a fixed time length or a fixed number of data points. The purpose is to perform fine analysis on the local characteristics of the optical signal, so as to facilitate subsequent correlation and evaluation of external disturbances in a specific time window.

[0100] As a possible implementation manner, the system can continuously collect the physical characteristics of the optical signal, such as optical power, polarization state, spectral distribution, and dispersion coefficient, at the receiving end of the data transmission optical cable. These continuously collected optical signal physical characteristic data can be divided into continuous data segments, for example, every 10 seconds as a data segment, or every 1000 accumulated sampling points as a data segment.

[0101] S102, acquire synchronous port environment auxiliary data.

[0102] The port environment auxiliary data includes the running state of the port heavy machinery equipment and the output of the local micro-vibration sensor. The synchronous port environment auxiliary data refers to the port environment auxiliary data in the same time period as the collection of the optical signal physical characteristics.

[0103] For example, the running state of the port heavy machinery equipment can refer to the start, stop, and work intensity of the equipment such as cranes and forklifts.

[0104] As a possible implementation manner, the system can acquire the running state of the port heavy machinery equipment from the running log of the port heavy machinery equipment, vibration sensor, or acoustic sensor, and acquire the local micro-vibration sensor from the high-sensitivity accelerometer or fiber sensor array.

[0105] S103, evaluate the degree of influence of external disturbances on the optical signal physical characteristics in each data segment in combination with the port environment auxiliary data.

[0106] The evaluation of the degree of influence of external disturbances on the optical signal physical characteristics in each data segment refers to analyzing the optical signal physical characteristic data in each continuous data segment using the acquired port environment auxiliary data to determine the correlation and strength between the fluctuations or changes and the synchronous external disturbances.

[0107] As a possible implementation manner, the system can correlate the fluctuation amplitude of the optical signal physical characteristics with the output intensity of the synchronous local micro-vibration sensor. When the micro-vibration intensity exceeds a certain preset value, or the optical signal physical characteristics and the micro-vibration intensity show a high degree of correlation, it can be considered that the optical signal in the data segment is influenced by external disturbances.

[0108] S104, screening data segments with an influence degree of external disturbance lower than a preset threshold as reference valid data according to the degree of influence of the physical characteristics of the optical signals in each data segment.

[0109] The screening of the data segments with an influence degree of external disturbance lower than a preset threshold as reference valid data means that according to the evaluation result, data segments with an influence degree of external disturbance lower than a certain standard are selected, and these data segments are considered to be relatively stable, reliable and can truly reflect the data set of the normal transmission state of the optical cable.

[0110] As a possible implementation manner, the system can screen the data segments with an influence degree of external disturbance lower than a preset threshold as reference valid data.

[0111] For example, a preset threshold of the disturbance influence index can be set as 0.05, and any data segment with a disturbance influence index lower than the threshold is identified as reference valid data.

[0112] In this way, data with greater external environmental interference can be excluded, and data used to establish the dynamic reference has high purity and representativeness.

[0113] S105, periodically updating the dynamic reference of the optical signals based on the reference valid data.

[0114] The periodic updating of the dynamic reference of the optical signals means that new reference valid data is used to recalculate or adjust the dynamic reference of the optical signals according to a predetermined time interval or after a sufficient number of reference valid data is accumulated.

[0115] As a possible implementation manner, the system can update the dynamic reference of the optical signals by using algorithms such as sliding window averaging, exponential smoothing or adaptive filtering to integrate the new reference valid data into the calculation of the existing reference.

[0116] In this way, the dynamic reference can adapt to possible slow changes or seasonal drifts during the long-term operation of the optical cable, and the accuracy and timeliness of the dynamic reference can be maintained.

[0117] For example, the dynamic reference can be updated once every 24 hours, or when a sufficient number (for example, 100) of reference valid data segments are accumulated. The updating method can use a sliding average method to include the latest reference valid data segment into the calculation of the dynamic reference, and remove the oldest data segment, so that the dynamic reference can reflect the latest fluctuation range of the optical signals under normal operating conditions in real time, and adapt to long-term changes in the environment.

[0118] It can be understood that through the above mechanism, the scheme effectively solves the problem that the optical cable is easily affected by external disturbances, leading to inaccurate dynamic reference under the complex environment of the port along the land bridge. Compared with establishing a reference only according to the physical characteristics of the optical signal, the scheme introduces the calibration of external environment data, so that the established dynamic reference can exclude the influence of external interference, thereby more accurately reflecting the inherent characteristics of the optical signal. Therefore, when comparing the physical characteristics of the optical signal with this more accurate dynamic reference, the accuracy of identifying whether the optical signal has an abnormal pattern is significantly improved, and thus the generated optical signal quality score can more reliably indicate the integrity or potential distortion risk of the data stream. This improvement in the accuracy of the reference directly enhances the reliability of the entire data stream integrity verification, ensuring the physical layer security of data transmission in complex port environments.

[0119] In some embodiments, the different sources include at least one of the following: a network security device, an audit log, a credential management module, a physical environment perception module; in order to associate event streams from different sources, identify security events, and improve the alarm priority of security events, the application further includes the following steps:

[0120] S201, extracting entity identifiers involved in the event stream.

[0121] Among them, the entity identifier refers to a unique identifier possessed by an object with an independent identity or traceable in the port network. The entity identifier includes user identification, device identification, IP address, data interface identification.

[0122] S202, based on the entity identifier, constructing an activity track chain of each entity in the port network, and recording a low-priority event sequence triggered by each entity at different time points in different systems.

[0123] Among them, the activity track chain refers to a collection of time sequence and system context of a series of behavior events of an entity in the port network based on the entity identifier, and its purpose is to fully reflect the behavior pattern of the entity.

[0124] Among them, the low-priority event sequence refers to a series of events that may not constitute a serious threat on its own, but when they occur in a specific order or combination, they may indicate potential security risks. Specifically, it can be multiple login failures, unauthorized access attempts, abnormal file operations, etc., and its purpose is to capture cumulative and hidden signs of threats.

[0125] As a possible implementation, the system can deploy multiple data collection agents, respectively connecting to the network security devices (e.g. firewalls, intrusion detection systems) of the port, audit log servers, credential management systems, and physical environment sensing modules (e.g. access control systems, environmental sensors). These agents are responsible for collecting the event streams from the respective sources in real time, and the system can search the event streams of entity identifications from different sources to build the activity track chain of each entity in the port network.

[0126] Meanwhile, the engine will identify and record the priority of each event, and add those events preset as low priority (e.g. single login failure, non-sensitive file access, non-critical port scanning) to the activity track chain of the corresponding entity, forming a low-priority event sequence.

[0127] For example, when user A logs in system S1 at time T1, and then accesses data interface D1 at time T2, these events will be recorded as nodes and edges in the activity track chain of user A.

[0128] S203, define preset threat patterns.

[0129] Among them, the threat pattern is a combination of low-priority events triggered by a specific entity in the activity track chain, across time intervals or system boundaries.

[0130] It should be noted that these threat patterns can be defined by the operator in advance.

[0131] For example, "multiple attempts to log in to different systems within a short period of time but all fail, and then attempt to access internal data interfaces" can be defined as a threat pattern. This pattern will specify the entity type involved (e.g. user, IP address), the expected low-priority event sequence (e.g. login failure event, interface access event), and the time window in which these events occur (e.g. within 5 minutes) and whether it can cross system boundaries.

[0132] S204, compare the activity track chain with the preset threat patterns to associate event streams from different sources, identify security events, and raise the alarm priority of security events.

[0133] As a possible implementation, when the threat pattern recognition module finds that the activity track chain of an entity matches any of the preset threat patterns, the system will identify it as a security event and raise its alarm priority.

[0134] For example, if an external IP address is found to have continuously failed to log in to multiple internal systems in a short period of time, and then attempts to access an internal data interface, the system can immediately identify this as a security incident. The alert can then be escalated from a regular “information” or “warning” level to a “high risk” or “emergency” level, and trigger corresponding alert notifications, such as sending a text message or email to a security administrator, or highlighting on a dashboard in a security operations center (SOC).

[0135] As yet another possible implementation, if an activity trail chain is found to match any pre-defined threat pattern, the system can accumulate risk for the entity or the related activity trail chain; when the accumulated risk reaches a pre-defined risk threshold, the alert priority of the activity trail chain is escalated to the highest level.

[0136] In some preferred embodiments, the application is implemented as follows: assume that in a port network, an external technician uses a left-behind high-privilege remote diagnosis account to attempt to log in, and then attempts to access an internal data interface. The system constructs an activity trail chain of the external technician by correlating event streams from different sources such as network security devices and audit logs. Pre-defined threat patterns can include “external IP logs in using internal high-privilege credentials” and “high-privilege account attempts to access sensitive data interfaces”, etc. When the system first finds that the activity trail chain of the external technician matches the threat pattern of “external IP logs in using internal high-privilege credentials”, the system does not immediately issue an alert at the highest level, but accumulates risk for the entity (e.g. its IP address or associated device identifier) and the activity trail chain of the external technician. For example, the system can assign an initial risk score of 20 points for this match. Subsequently, if the activity trail chain of the external technician further matches the threat pattern of “high-privilege account attempts to access sensitive data interfaces”, the system will again accumulate risk for the entity and the trail chain, for example, by adding another 30 points. At this time, the accumulated risk score of the entity and the trail chain reaches 50 points. The system's pre-defined risk threshold can be set to 50 points. When the accumulated risk score reaches 50 points, the system determines that the behavior constitutes a higher threat, at which point the system will escalate the alert priority of the activity trail chain of the external technician to the highest level. For example, by sending a P0-level emergency alert notification to the security operations center, and can trigger automated response measures, such as temporarily isolating the IP address or disabling the remote diagnosis account.

[0137] In some embodiments, relying solely on a single type of entity or a simple sequence of events may not be sufficient to fully capture complex and covert threat behaviors. In addition, the way different types of entities interact with each other, as well as the timing and system boundaries of event occurrences, can also have an important impact on threat identification.

[0138] To this end, in order to define the preset threat mode, the present application further comprises the following steps:

[0139] S301, determine a plurality of entity sets involved in the threat mode.

[0140] Among them, the entity set specifies at least two different types of entities participating in the threat mode. For example, it can include "external technical personnel" entities (type external user), "port management terminal" entities (type device), "internal data interface" entities (type application interface), "audit log system" entities (type system), etc.

[0141] S302, determine the interaction rules expected between entities in the threat mode.

[0142] Among them, the interaction rule refers to the behavior association or dependency relationship that may occur between different entities under a specific threat scenario, which can include access, transmission, modification, deletion, login, connection, etc.

[0143] For example, the "external technical personnel" entity attempts to log in to the port network through the "port management terminal" entity; the "external technical personnel" entity accesses the "internal data interface" entity through the "port management terminal" entity; the "internal data interface" entity sends a data query request to the "audit log system" entity.

[0144] S303, for each entity, determine the specific low-priority event sequence that the entity will trigger in the threat mode.

[0145] Among them, the specific low-priority event sequence includes a plurality of specific low-priority events sorted in time sequence. It can include multiple login failures, small traffic data transmission, non-working time access, specific file reading, etc., the purpose of which is to filter valuable threat clues from a large number of events and avoid missing hidden attacks;

[0146] For example, for the "external technical personnel" entity, the low-priority event sequence it may trigger includes: multiple non-working time login attempt failures -> successful login but abnormal source IP -> attempt to access multiple non-related system directories. For the "internal data interface" entity, the low-priority event sequence it may trigger includes: receiving a query request from an unauthorized source -> querying non-sensitive data but touching sensitive metadata. For the "audit log system" entity, the low-priority event sequence it may trigger includes: recording low-level abnormal login events -> recording access events to non-core business data interfaces.

[0147] S304, determine the time window in which the specific low-priority event and the interaction occur, and the time window and system boundary conditions that can span different system boundaries.

[0148] The time window and system boundary condition refer to a time range for limiting occurrence of a specific low-priority event and interaction and a system or network area limit that can be crossed, which can include a time interval, duration, and whether the event occurs between different subnets, different security domains, or different physical areas, and aims to accurately define a context of a threat pattern, reduce false positives, and adapt to a complex and variable port network environment.

[0149] For example, the above login attempt, access, and query event occur within 30 minutes (time window); the login attempt comes from a port external network area, and the data interface access occurs in a port internal network area (crosses a system boundary).

[0150] S305, combine the plurality of entity sets, interaction rules, low-priority event sequences, and time window and system boundary conditions to form a preset threat pattern.

[0151] In this way, when an actual activity track chain matches the pattern, the system can accurately identify the composite security event and improve the alarm priority thereof.

[0152] As shown in FIG. 1, the embodiment of the present application also provides a land bridge along a port data security sharing system. The system comprises: Figure 3 A data flow receiving module is configured to receive a data flow for making a data access request, wherein the data flow comprises a credential for requesting data;

[0153] An access credibility evaluation module is configured to evaluate a life cycle, source context, and data request range of the credential, and generate an access credibility score;

[0154] A data integrity checking module is configured to monitor physical environment vibration data of a data transmission cable during transmission of the data flow, and combine the physical environment vibration data and a conventional check code to perform integrity checking on the data flow, to obtain a data content integrity check result; if the data content integrity check result indicates that the data flow integrity checking fails or there is a potential distortion risk at a physical layer, the data flow is marked as integrity damaged;

[0155] A data flow credibility calculation and event association module is configured to combine the access credibility score and the data content integrity check result to calculate a comprehensive credibility total score of the data flow, and grade mark the data flow according to the comprehensive credibility total score; at the same time, associate event flows from different sources to identify a security event, and improve an alarm priority of the security event;

[0156]

[0157] ​The business operation adjustment and decision assistance module is configured to adjust or limit a business operation corresponding to the data flow according to the hierarchical label of the data flow.

[0158] The embodiment of the present application further provides a terminal device. The terminal device comprises a processor, a memory and a computer program stored in the memory and executable on the processor, such as a land-bridge-port-data-security-sharing program. The processor implements the steps in the above various land-bridge-port-data-security-sharing methods when executing the computer program. Alternatively, the processor implements the functions of the modules / units in the above various system embodiments when executing the computer program.

[0159] The computer program can be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the terminal device.

[0160] The terminal device can be a desktop computer, a notebook computer, a palm computer, a smart tablet and the like. The terminal device can comprise, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above components are only examples of the terminal device and do not constitute a limitation on the terminal device, and the terminal device can comprise more or fewer components than the above, or combine certain components or different components, for example, the terminal device can further comprise an input / output device, a network access device, a bus and the like.

[0161] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The processor is a control center of the terminal device, which connects all parts of the terminal device through various interfaces and lines.

[0162] The memory can be used to store computer programs and / or modules, and the processor realizes various functions of the terminal device by running or executing the computer programs and / or modules stored in the memory, and calling data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), etc.; and the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory can include a high-speed random access memory, and can also include a non-volatile memory, for example, a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory devices.

[0163] The modules / units integrated in the terminal device can be stored in a computer readable storage medium if they are realized in the form of software function units and sold or used as independent products. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program can realize the steps of the above-mentioned various method embodiments when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer readable medium can include any entity or system capable of carrying computer program code, a recording medium, a U disk, a mobile hard disk, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc. It should be noted that the content included in the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.

[0164] It should be noted that the system embodiments described above are only illustrative, and units described as separate components can or can not be physically separated, and components shown as units can or can not be physical units, i.e. can be located in one place or can be distributed to multiple network units. Part or all of the modules can be selected to achieve the purpose of the embodiment according to actual needs. In addition, the connection relationship between the modules in the system embodiment provided by the present application indicates that there is a communication connection between them, which can be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement it without creative labor.

[0165] The above specific embodiments further illustrate the purpose, technical solutions and beneficial effects of the present application. It should be understood that the above is only a specific embodiment of the present application and is not intended to limit the protection scope of the present application. It is particularly pointed out that any modification, equivalent replacement, improvement, etc. made by those skilled in the art within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A method for secure data sharing at ports along a land bridge, characterized in that, include: Receive a data stream for making a data access request, the data stream including credentials for requesting data; Assess the lifecycle, source context, and data request scope of the credentials to generate an access trust score; During the transmission of the data stream, the physical environment vibration data of the data transmission optical cable is monitored, and the data stream is checked for integrity by combining the physical environment vibration data with a conventional check code to obtain the data content integrity check result; if the data content integrity check result indicates that the data stream integrity check has failed or there is a potential risk of physical layer distortion, the data stream is marked as having compromised integrity. By combining the access credibility score and the data content integrity verification result, the overall credibility score of the data stream is calculated, and the data stream is classified and labeled according to the overall credibility score; at the same time, event streams from different sources are correlated to identify security events and the alarm priority of the security events is increased. Based on the hierarchical labeling of the data stream, adjust or restrict the business operations corresponding to the data stream; The physical environment vibration data of the monitored data transmission optical cable is used, and combined with the physical environment vibration data and a conventional checksum, the data stream is subjected to integrity verification to obtain the data content integrity verification result, including: At the receiving end of the data transmission optical cable, the physical characteristics of the optical signal of the data stream are collected; Based on the physical characteristics of the optical signal, a dynamic reference for the optical signal is established; the dynamic reference reflects the fluctuation range of the physical characteristics of the optical signal under normal operating conditions. The physical properties of the optical signal are compared with the dynamic reference to identify whether there is an abnormal mode in the optical signal, and an anomaly identification result is obtained; the abnormal mode includes instantaneous polarization state anomaly, spectral distribution anomaly, and dispersion coefficient anomaly. Based on the anomaly identification results, an optical signal quality score is generated, and the optical signal quality score is used as the content integrity verification result.

2. The method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The step of establishing a dynamic reference for the optical signal based on the physical characteristics of the optical signal includes: The physical characteristics of the optical signal are divided into continuous data segments; Acquire concurrent port environmental auxiliary data, including the operating status of port heavy machinery and equipment and the output of local micro-vibration sensors; Based on the aforementioned port environment auxiliary data, assess the degree to which the physical characteristics of the optical signal within each data segment are affected by external disturbances; Based on the degree to which the physical characteristics of the optical signal within each data segment are affected by external disturbances, data segments whose degree of external disturbance is lower than a preset threshold are selected as the benchmark valid data. Based on the aforementioned valid reference data, the dynamic reference of the optical signal is periodically updated.

3. The method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The method further includes: Compared to the dynamic reference of the optical signal, if the instantaneous polarization state of the optical signal undergoes a non-periodic change exceeding a preset threshold within a preset time period, then the abnormal mode of the optical signal is determined to be an instantaneous polarization state abnormality. Compared to the dynamic reference of the optical signal, if the spectral distribution of the optical signal shows transient broadening or shift, then the abnormal mode of the optical signal is determined to be spectral distribution abnormality. Compared to the dynamic reference of the optical signal, if the dispersion coefficient of the optical signal fluctuates nonlinearly within a preset time during transmission, the abnormal mode of the optical signal is determined to be an abnormal dispersion coefficient. If an abnormal pattern is detected in the optical signal, the data stream is flagged as having a risk of implicit physical layer distortion of the optical signal.

4. A method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The different sources include at least one of the following: network security devices, audit logs, credential management modules, and physical environment awareness modules; The association of event streams from different sources, identification of security events, and elevation of the alarm priority of the security events include: Extract the entity identifiers involved in the event stream, including user identifier, device identifier, IP address, and data interface identifier; Based on the entity identifier, construct the activity trajectory chain of each entity in the port network, and record the low-priority event sequence triggered by each entity in different systems and at different time points; Define a preset threat pattern; the threat pattern is a combination of low-priority events that are continuously triggered by a specific entity across time intervals or system boundaries in the activity trajectory chain. The activity trajectory chain is compared with the preset threat pattern to associate event streams from different sources, identify security events, and increase the alarm priority of the security events.

5. A method for secure data sharing at ports along a land bridge according to claim 4, characterized in that, The step of comparing the activity trajectory chain with the preset threat pattern to correlate event streams from different sources, identify security events, and increase the alarm priority of the security events includes: If the activity trajectory chain is found to match any preset threat pattern, then risk accumulation is performed on the entity or the related activity trajectory chain; When the accumulated risk reaches a preset risk threshold, the alarm priority of the activity trajectory chain will be raised to the highest level.

6. A method for secure data sharing at ports along a land bridge according to claim 4, characterized in that, The defined preset threat patterns include: Identify a set of multiple entities involved in the threat pattern, wherein the set of entities specifies at least two entities of different types participating in the threat pattern; Determine the expected interaction rules between entities in the threat pattern; For each entity, a specific low-priority event sequence that the entity will trigger in the threat pattern is determined; the specific low-priority event sequence includes multiple specific low-priority events ordered in time series. The specific low-priority events and interactions are determined to occur within a specific time window, and span different system boundaries and system boundary conditions. The preset threat pattern is formed by combining the multiple entity sets, the interaction rules, the low-priority event sequence, the time window, and the system boundary conditions.

7. A method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The assessment of the credential's lifecycle, source context, and data request scope to generate an access trust score includes: Configure a set of evaluation parameters for credential lifecycle, source context, and data request scope; the set of evaluation parameters includes credential validity period, source network region, access time window, data sensitivity classification, and access rules; Adjust the validity period of the voucher and the access time window based on the port business operation status signal; The set of assessment parameters is adjusted according to the received threat intelligence instructions to obtain the adjusted set of assessment parameters; the threat intelligence instructions are used to instruct the adjustment of at least one of the following: the trust level of the source network area, the data sensitivity classification and access rules, the update instructions based on the internal security policy, the automatic credential clearing trigger conditions and data access restrictions; Based on the adjusted set of evaluation parameters, the lifecycle, source context, and data request scope of the credentials used in the data stream are evaluated. Based on the evaluation results, an access credibility score is generated.

8. A method for secure data sharing at ports along a land bridge according to claim 1, characterized in that, The calculation of the overall credibility score of the data stream, and the classification and labeling of the data stream based on the overall credibility score, includes: The access credibility score and the data content integrity verification result are weighted and summed to obtain the overall credibility score of the data stream; The data stream is classified and labeled according to the overall credibility score and the level mapping relationship; the level mapping relationship includes the mapping relationship between different credibility scores and different credibility levels.

9. A data security sharing system for ports along a land bridge, used to ensure the integrity, reliability, and smooth execution of business processes of data sharing at ports along a land bridge, characterized in that... The system includes: A data stream receiving module is configured to receive a data stream for making a data access request, the data stream including credentials for requesting data; The access credibility assessment module is used to assess the lifecycle, source context, and data request scope of the credentials, and generate an access credibility score. The data integrity verification module is used to monitor the physical environment vibration data of the data transmission optical cable during the transmission of the data stream, and combine the physical environment vibration data with a conventional check code to perform integrity verification on the data stream and obtain the data content integrity verification result; if the data content integrity verification result indicates that the data stream integrity verification has failed or there is a potential risk of physical layer distortion, the data stream is marked as having compromised integrity. The data stream credibility calculation and event association module is used to combine the access credibility score and the data content integrity verification result to calculate the overall credibility score of the data stream, and to classify and label the data stream according to the overall credibility score; at the same time, it associates event streams from different sources, identifies security events, and increases the alarm priority of the security events. The business operation adjustment and decision support module is used to adjust or restrict the business operations corresponding to the data stream based on the hierarchical label of the data stream; The physical environment vibration data of the monitored data transmission optical cable is used, and combined with the physical environment vibration data and a conventional checksum, the data stream is subjected to integrity verification to obtain the data content integrity verification result, including: At the receiving end of the data transmission optical cable, the physical characteristics of the optical signal of the data stream are collected; Based on the physical characteristics of the optical signal, a dynamic reference for the optical signal is established; the dynamic reference reflects the fluctuation range of the physical characteristics of the optical signal under normal operating conditions. The physical properties of the optical signal are compared with the dynamic reference to identify whether there is an abnormal mode in the optical signal, and an anomaly identification result is obtained; the abnormal mode includes instantaneous polarization state anomaly, spectral distribution anomaly, and dispersion coefficient anomaly. Based on the anomaly identification results, an optical signal quality score is generated, and the optical signal quality score is used as the content integrity verification result.

Citation Information

Patent Citations

  • Zero-trust access control method based on cloud side-end cooperation

    CN119316235A

  • Data asset credible circulation method and system based on intelligent contract dynamic evaluation

    CN120415902A