Method and device for transmitting differential data and storage medium

By introducing a WAPI encryption module into the RTK system to dynamically encrypt differential data, and combining it with WAPI secure link transmission, the problem of insufficient security in differential data transmission in the RTK system is solved, and the security and accuracy of data transmission are achieved.

CN121509997APending Publication Date: 2026-02-10国网四川省电力公司阿坝供电公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511660526.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-13
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing RTK systems lack security mechanisms for differential data transmission, making them vulnerable to interference signals, man-in-the-middle attacks, or replay attacks. This can lead to data being eavesdropped on or accessed by unauthorized devices, compromising the security of transmission.

Method used

The differential data is encrypted using a WAPI encryption module, and symmetric encryption is performed using dynamic encrypted data and session keys. Combined with WAPI secure link transmission, the security of the data during transmission is ensured.

Benefits of technology

It improves the security of differential data transmission, prevents data from being eavesdropped on or tampered with, and ensures that mobile terminals can accurately obtain location information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509997A_ABST
    Figure CN121509997A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of positioning, and discloses a method and device for transmitting differential data and a storage medium. The method is applied to base stations. The base station is provided with a WAPI encryption module; the method comprises the following steps: acquiring differential data to be transmitted; encrypting the differential data by using a WAPI encryption module to obtain encrypted differential data; and transmitting the encrypted differential data to a preset mobile terminal, triggering the mobile terminal to decrypt the encrypted differential data to obtain differential data, and obtaining positioning information corresponding to the mobile terminal based on the differential data. Therefore, before the differential data are sent, the differential data are encrypted, and the differential data cannot be cracked even if the differential data are monitored, so that the transmission security of the differential data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of positioning technology, and more specifically to a method, apparatus, and storage medium for transmitting differential data. Background Technology

[0002] RTK (Real-Time Kinematic) is a high-precision positioning technology based on the Global Navigation Satellite System (GNSS). Its core function is to improve GNSS positioning accuracy from meter-level to centimeter-level through real-time differential correction, providing high-precision and highly reliable absolute position information for various industries. Based on this function, RTK systems are also widely used in power systems. In power systems, a large number of RTK terminals are deployed on field towers or in mountainous substations and booster stations, requiring the reception of differential data from base stations to achieve centimeter-level positioning. The power grid is a key infrastructure, with strict requirements for network communication security. Especially in scenarios such as high-voltage transmission, control communication, and substation automation, network communication security is a dual requirement of policy and technology.

[0003] However, in traditional RTK systems, differential data is mostly transmitted via radio links, 4G (Fourth Generation) / 5G (Fifth Generation) networks, or dedicated communication links. It typically employs only basic verification methods such as CRC checksums. While this approach can detect some transmission errors, it cannot prevent malicious eavesdropping, tampering, or forgery. In open wireless environments, differential data is vulnerable to interference signals, man-in-the-middle attacks, or replay attacks during transmission. Therefore, existing RTK systems lack secure mechanisms for differential data transmission, making them susceptible to eavesdropping or spoofed access by unauthorized devices.

[0004] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this application, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0005] The technical problem to be solved by the present invention is how to improve the security of differential data transmission. The purpose is to provide a method, apparatus and storage medium for transmitting differential data, so as to improve the security of differential data transmission.

[0006] This invention is achieved through the following technical solution:

[0007] In a first aspect, a method for transmitting differential data is applied to a base station; the base station is equipped with a Wireless Local Area Network Authentication and Security Infrastructure (WAPI) encryption module; the method includes: acquiring differential data to be transmitted; encrypting the differential data using the WAPI encryption module to obtain encrypted differential data; transmitting the encrypted differential data to a preset mobile terminal, triggering the mobile terminal to decrypt the encrypted differential data to obtain the differential data, and obtaining the location information corresponding to the mobile terminal based on the differential data.

[0008] In some embodiments, encrypting the differential data using the WAPI encryption module to obtain encrypted differential data includes: acquiring dynamic encrypted data; and encrypting the differential data based on the dynamic encrypted data using the WAPI encryption module to obtain the encrypted differential data.

[0009] In some embodiments, the dynamically encrypted data includes one or more of the following: timestamp parameters, random number parameters, location parameters, and satellite status parameters.

[0010] In some embodiments, encrypting the differential data using the WAPI encryption module based on the dynamic encryption data to obtain the encrypted differential data includes: obtaining a first session key; obtaining a second session key using the WAPI encryption module according to the first session key and the dynamic encryption parameters; and symmetrically encrypting the differential data using the WAPI encryption module according to the second session key to obtain the encrypted differential data.

[0011] Secondly, a method for transmitting differential data, applied to a mobile terminal; the method includes: receiving encrypted differential data sent by a base station; decrypting the encrypted differential data to obtain differential data; and obtaining location information corresponding to the mobile terminal based on the differential data.

[0012] In some embodiments, the base station is equipped with a WAPI decryption module; the decryption of the encrypted differential data to obtain the differential data includes: acquiring dynamic encrypted data and a first session key; and using the WAPI decryption module to decrypt the encrypted differential data based on the dynamic encrypted data and the first session key to obtain the differential data.

[0013] In some embodiments, obtaining the positioning information corresponding to the mobile terminal based on the differential data includes: obtaining satellite observation data corresponding to the mobile terminal; and performing position calculation using the differential data and the satellite observation data to obtain the positioning information.

[0014] Thirdly, an apparatus for transmitting differential data includes a processor and a memory storing program instructions, the processor being configured to execute the method for transmitting differential data as described above when the program instructions are executed.

[0015] Fourthly, a system for transmitting differential data includes: a base station configured to acquire differential data to be transmitted; encrypt the differential data using the WAPI encryption module to obtain encrypted differential data; transmit the encrypted differential data to a preset mobile terminal, trigger the mobile terminal to decrypt the encrypted differential data to obtain the differential data, and acquire location information corresponding to the mobile terminal based on the differential data; and a mobile terminal configured to receive encrypted differential data sent by the base station; decrypt the encrypted differential data to obtain the differential data; and acquire location information corresponding to the mobile terminal based on the differential data.

[0016] Fifthly, a storage medium storing program instructions that, when executed, perform the aforementioned method for transmitting differential data.

[0017] Compared with existing technologies, this invention acquires differential data to be transmitted, then encrypts the differential data using a WAPI encryption module to obtain encrypted differential data. This encrypted differential data is then transmitted to a preset mobile terminal, triggering the mobile terminal to decrypt the encrypted differential data and obtain the corresponding location information based on it. In this way, by encrypting the differential data before transmission, even if eavesdropped on, the differential data cannot be cracked, thus improving the security of differential data transmission. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the exemplary embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be considered as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort. In the drawings:

[0019] Figure 1 This is a schematic diagram of a system for transmitting differential data provided in an embodiment of this disclosure;

[0020] Figure 2 This is a flowchart of a method for transmitting differential data provided in an embodiment of this disclosure;

[0021] Figure 3 This is a flowchart of another method for transmitting differential data provided in an embodiment of this disclosure;

[0022] Figure 4This is a flowchart of yet another method for transmitting differential data provided in this disclosure embodiment;

[0023] Figure 5 This is a schematic diagram of an apparatus for transmitting differential data provided in an embodiment of this disclosure;

[0024] Figure 6 This is a schematic diagram of another apparatus for transmitting differential data provided in an embodiment of this disclosure;

[0025] Figure 7 This is a schematic diagram of another apparatus for transmitting differential data provided in an embodiment of this disclosure. Detailed Implementation

[0026] To make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the embodiments and accompanying drawings. The illustrative embodiments and descriptions of the present invention are only used to explain the present invention and are not intended to limit the present invention.

[0027] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0028] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0029] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily have to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.

[0030] In this application, "multiple" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.

[0031] Combination Figure 1This disclosure provides a system 100 for transmitting differential data, including: a base station 101, a mobile terminal 102, and a satellite 103.

[0032] Satellite 103 is a satellite device used by base station 101 and mobile terminal 102 for simultaneous observation and communication; there can be one or more of these devices. By observing the satellite, the mobile terminal can directly decode its own location. However, due to errors caused by ionospheric and tropospheric delays in satellite signals, the location is not accurate.

[0033] At this point, by introducing a base station with a known location, differential data can be obtained. This differential data represents the error between the location of the base station and the location decoded by the satellite, i.e., the error of the satellite signal.

[0034] Then the mobile terminal can obtain its own accurate location information through differential data.

[0035] Specifically, base station 101 is an RTK (Real-Time Kinematic) base station, which serves as the reference station side of system 100 for transmitting differential data.

[0036] Base station 101 is configured to acquire differential data to be transmitted; encrypt the differential data using the WAPI encryption module to obtain encrypted differential data; transmit the encrypted differential data to a preset mobile terminal, trigger the mobile terminal to decrypt the encrypted differential data, obtain the differential data, and obtain the corresponding location information of the mobile terminal based on the differential data.

[0037] Mobile terminal 102 is a mobile station for an RTK system. It can be used in power systems such as substations, intelligent inspection equipment, remote sensing equipment, or as a terminal device for outdoor workers.

[0038] The mobile terminal 102 is configured to receive encrypted differential data sent by the base station; decrypt the encrypted differential data to obtain differential data; and obtain the location information corresponding to the mobile terminal based on the differential data.

[0039] It should be noted that both the base station and the mobile terminal need to be powered on when transmitting differential data through this system. Therefore, both the base station and the mobile terminal need to be powered on before transmitting differential data.

[0040] Please see Figure 2 , Figure 2 This is a flowchart illustrating a method for transmitting differential data, as shown in an exemplary embodiment of this application.

[0041] Combination Figure 2 As shown in the embodiments of this disclosure, a method for transmitting differential data is provided, which is applied to a base station.

[0042] Specifically, the method for transmitting differential data includes:

[0043] Step S101: Obtain the differential data to be transmitted.

[0044] Step S102: Use the WAPI encryption module to encrypt the differential data to obtain encrypted differential data.

[0045] Step S103: The encrypted differential data is transmitted to a preset mobile terminal, triggering the mobile terminal to decrypt the encrypted differential data, obtain the differential data, and obtain the location information corresponding to the mobile terminal based on the differential data.

[0046] The method for transmitting differential data provided in this disclosure involves acquiring the differential data to be transmitted, encrypting it using a WAPI encryption module to obtain encrypted differential data, and then transmitting the encrypted differential data to a preset mobile terminal. This triggers the mobile terminal to decrypt the encrypted differential data, obtain the differential data, and retrieve the corresponding location information of the mobile terminal based on the differential data. In this way, by encrypting the differential data before transmission, even if eavesdropped on, the differential data cannot be cracked, thus improving the security of differential data transmission.

[0047] Furthermore, in step S101, acquiring the differential data to be transmitted includes: continuously acquiring satellite observation data corresponding to the base station; and acquiring differential data based on the satellite observation data corresponding to the base station and preset base station positioning data.

[0048] It should be noted that the preset base station positioning data is the actual location coordinates of the base station.

[0049] In some embodiments, the satellite observation data corresponding to the base station is GNSS data, which includes pseudorange measurements between the base station and the satellite, carrier phase between the base station and the satellite, Doppler shift between the base station and the satellite, and other data.

[0050] Among them, the pseudorange measurement is in meters, which includes the distance from the satellite to the receiver and is the basic observation value for single-point positioning; the carrier phase is in cycles, which has high accuracy but contains integer ambiguity, and can be used for high-precision positioning; the Doppler frequency shift is in Hz, which reflects the relative radial velocity between the satellite and the receiver and is used for velocity estimation and dynamic positioning.

[0051] Satellite observation data can be used to calculate the location of a base station, thus obtaining its measured position. The satellite observation data corresponding to the base station characterizes its measured position.

[0052] Therefore, differential data can be obtained by using the satellite observation data corresponding to the base station and the preset base station positioning data. This differential data characterizes the error between the satellite observation data and the base station positioning data. It should be noted that the method for obtaining differential data based on the satellite observation data corresponding to the base station and the preset base station positioning data is existing technology and will not be elaborated upon here.

[0053] Furthermore, in step S102, the differential data is encrypted using the WAPI encryption module to obtain encrypted differential data, including: acquiring dynamically encrypted data; and using the WAPI encryption module to encrypt the differential data based on the dynamically encrypted data to obtain encrypted differential data. In this way, by acquiring dynamically encrypted data and then using the WAPI encryption module to encrypt the differential data based on the dynamically encrypted data to obtain encrypted differential data, dynamic encryption of the differential data is achieved, raising the decryption threshold and further enhancing transmission security.

[0054] The dynamically encrypted data includes one or more of the following: timestamp parameters, random number parameters, location parameters, and satellite status parameters. By using one or more of these parameters as the dynamic encryption data, the uncertainty of the encrypted data is increased, thereby increasing the difficulty of decoding and improving transmission security.

[0055] Specifically, the timestamp parameter can be GNSS system time, satellite time, or network synchronization time.

[0056] The random number parameter can be a random number generated by the first pseudo-random number generator. It should be noted that the first pseudo-random number generator can generate random numbers based on a preset initial value using a preset deterministic algorithm.

[0057] Optionally, the base station can send random number parameters to the mobile terminal.

[0058] Specifically, along with the pseudo-random number R, a valid timestamp corresponding to that pseudo-random number is also sent. The mobile terminal can use this valid timestamp to determine whether the pseudo-random number is newly generated, which helps maintain consistency between the random number parameters of the base station and the mobile terminal.

[0059] Location parameters can be the real-time coordinates of a base station or mobile terminal.

[0060] It should be noted that when the location parameter in the dynamically encrypted data is the coordinates of the base station, the mobile terminal obtains the real-time coordinates of the base station in the following way: it receives coordinate transmission information sent by the base station; this coordinate transmission information includes the coordinates sent by the base station and a session identifier. The mobile terminal can use this session identifier to determine whether the coordinates sent by the base station are the most recently sent coordinates, i.e., the real-time coordinates of the base station.

[0061] It should be noted that the real-time coordinates of the mobile terminal can be the location information from the previous location. After each location is determined, the mobile terminal can send its location information back to the base station, achieving real-time location feedback.

[0062] Satellite status parameters include the number of visible satellites and the signal-to-noise ratio, which characterize the status parameters of satellites jointly observed by the base station and the mobile terminal.

[0063] In some embodiments, data is dynamically encrypted. Where P represents dynamically encrypted data, including: For timestamp parameters, For random number parameters, For position parameters; The latitude representing the real-time coordinates; Longitude representing real-time coordinates; The elevation representing the real-time coordinates; These are satellite status parameters.

[0064] Furthermore, the differential data is encrypted using the WAPI encryption module based on dynamically encrypted data to obtain encrypted differential data. This includes: obtaining a first session key; obtaining a second session key using the WAPI encryption module based on the first session key and dynamic encryption parameters; and performing symmetric encryption on the differential data using the second session key to obtain encrypted differential data. In this way, by obtaining the first session key, then using the WAPI encryption module to obtain the second session key based on the first session key and dynamic encryption parameters, and then using the WAPI encryption module to perform symmetric encryption on the differential data using the second session key to obtain encrypted differential data, the derivation of the second session key from the first session key is achieved. The encryption of differential data using the derived second session key by the WAPI encryption module increases the decoding difficulty and improves transmission security.

[0065] Furthermore, obtaining the first session key includes: performing two-way authentication with the mobile terminal via the WAPI protocol. If the two-way authentication is successful, the first session key is obtained.

[0066] In some embodiments, both the base station and the mobile terminal are configured with device identity codes. Two-way authentication means that both the base station and the mobile terminal authenticate each other's device identity codes. If the other party's device identity code is valid, one-way authentication succeeds. If both parties' device identity codes are valid, two-way authentication succeeds.

[0067] It should be noted that a search operation can be performed in the preset dual-code database. If the other party's device identification code is found, then the other party's device identification code is confirmed to be valid.

[0068] The first session key is a secure session key generated by the base station or terminal device after successful two-way authentication; it is also the session key for the WAPI link layer. It's important to note that the first session key is not a preset static key, but rather dynamically negotiated and generated by the base station and mobile terminal during the WAPI protocol authentication handshake phase. Its uniqueness and timeliness ensure the confidentiality and replay resistance of the communication link.

[0069] After generating the first session key, it will be sent to the other party to achieve the sharing of the first session key, so as to facilitate successful encryption and decryption.

[0070] It should be noted that after successful two-way authentication, an encrypted communication link is also established with the mobile terminal. This provides a secure foundation for subsequent parameter derivation and encrypted transmission.

[0071] The encrypted communication link can be a WAPI secure link. This allows the base station to communicate with the mobile terminal via the WAPI secure link. It should be noted that this application can maintain compatibility with existing WLAN security standards without altering the WAPI protocol format. This effectively prevents differential correction data from being maliciously eavesdropped, intercepted, or tampered with during transmission, thereby ensuring the confidentiality and integrity of the differential data.

[0072] Furthermore, the second session key is obtained using the WAPI encryption module based on the first session key and dynamic encryption parameters, including: calculating using the WAPI encryption module. Obtain the second session key. This is the second session key; The preset key derivation algorithm is used, such as HKDF (HMAC-based Key Derivation Function) or HMAC-SHA256 (Hash-based Message Authentication Code with SHA-256). This is the first session key; To dynamically encrypt data; The parameter concatenation operation represents the parameter concatenation operation. It represents the concatenation of the first session key and dynamically encrypted data.

[0073] Furthermore, the differential data is symmetrically encrypted using the WAPI encryption module based on the second session key to obtain encrypted differential data, including: obtaining encryption parameters using the WAPI encryption module; and calculating using the WAPI encryption module. This yields encrypted differential data. To encrypt differential data; The data is differential; For encryption parameters; It is an abstract representation function that refers to the use of a second session key. and For difference data Perform symmetric encryption.

[0074] It should be noted that the encryption parameters are random or semi-random parameters generated from dynamically generated encryption parameters. The encryption parameters are typically a fixed-length binary string, along with the second session key. Differential data By having everyone participate in encryption, the uniqueness and unpredictability of each encryption result are enhanced, thus improving security.

[0075] Furthermore, the encryption parameters are obtained using the WAPI encryption module, including: obtaining alternative encryption parameters based on dynamic encryption parameters using the WAPI encryption module; and calculating using the WAPI encryption module. , obtain the encrypted parameters. Among them, Characteristic hash algorithm; These are alternative encryption parameters.

[0076] It should be noted that the alternative encryption parameters can be obtained by concatenating one or more data from the dynamic encryption parameters.

[0077] For example: using the WAPI encryption module to obtain alternative encryption parameters based on dynamic encryption parameters, including: using the WAPI encryption module to calculate... , obtain alternative encryption parameters.

[0078] In some embodiments, the AES-GCM (Advanced Encryption Standard-Galois / Counter Mode) algorithm can be used to process differential data. Perform symmetric encryption.

[0079] Specifically, the AES-GCM algorithm can be used to encrypt the differential data with a Salt / nonce per packet and generate an authentication token. The nonce is the initialization vector for the AES-GCM algorithm.

[0080] It should be noted that the authentication token can be sent to the mobile terminal along with the encrypted differential data, so that the mobile terminal can decrypt and authenticate it.

[0081] Furthermore, in step 103, transmitting the encrypted differential data to a preset mobile terminal includes: transmitting the encrypted differential data to the preset mobile terminal via a WAPI secure link. This ensures that the differential data is simultaneously protected by WAPI frame encryption and the application layer's derived key, i.e., the second session key, providing dual encryption protection. Even if WAPI is bypassed, security is still maintained, achieving a combination of "end-to-end encryption + link encryption".

[0082] Please see Figure 3 , Figure 3 This is a flowchart illustrating a method for transmitting differential data, as shown in an exemplary embodiment of this application.

[0083] Combination Figure 3 As shown in the embodiments of this disclosure, a method for transmitting differential data is provided, which is applied to a mobile terminal.

[0084] Specifically, the method for transmitting differential data includes:

[0085] Step S301: Receive encrypted differential data sent by the base station.

[0086] Step S302: Decrypt the encrypted differential data to obtain the differential data.

[0087] Step S303: Obtain the location information corresponding to the mobile terminal based on the differential data.

[0088] The method for transmitting differential data provided in this disclosure involves receiving encrypted differential data sent by a base station, then decrypting the encrypted differential data to obtain the differential data, and finally obtaining the location information corresponding to the mobile terminal based on the differential data. Since the encrypted differential data is encrypted, it needs to be decrypted first to obtain the differential data and thus the location information. Even if eavesdropped on, the differential data cannot be cracked, improving the security of differential data transmission.

[0089] Furthermore, the mobile terminal is equipped with a WAPI decryption module; in step S302, the encrypted differential data is decrypted to obtain differential data, including: acquiring dynamic encrypted data and a first session key; and using the WAPI decryption module to decrypt the encrypted differential data based on the dynamic encrypted data to obtain the differential data. Thus, by acquiring the dynamic encrypted data and the first session key, and then using the WAPI decryption module to decrypt the encrypted differential data based on the dynamic encrypted data to restore the differential data, the corresponding location information of the mobile terminal can be obtained using this differential data, achieving precise positioning.

[0090] It should be noted that the dynamically encrypted data acquired by the mobile terminal is the same as the dynamically encrypted data acquired by the base station. Specifically, the random number parameter in the dynamically encrypted data acquired by the mobile terminal can be a random number generated by a second pseudo-random number generator. It should also be noted that the second pseudo-random number generator can generate random numbers based on a preset initial value using a preset deterministic algorithm.

[0091] In some embodiments, the second pseudo-random number generator can be the same as the first pseudo-random number generator, so that the base station and the mobile terminal can obtain the same random number parameters.

[0092] For example, a base station can periodically distribute a pseudo-random number R to a mobile terminal; the mobile terminal can then construct dynamically encrypted data consistent with that of the base station based on this pseudo-random number.

[0093] Specifically, along with the pseudo-random number R, a valid timestamp corresponding to that pseudo-random number is also sent. The mobile terminal can use this valid timestamp to determine whether the pseudo-random number is newly generated, which helps maintain consistency between the random number parameters of the base station and the mobile terminal.

[0094] It should be noted that when the location parameter in the dynamically encrypted data is the coordinates of the base station, the mobile terminal obtains the real-time coordinates of the base station in the following way: it receives coordinate transmission information sent by the base station; this coordinate transmission information includes the coordinates sent by the base station and a session identifier. The mobile terminal can use this session identifier to determine whether the coordinates sent by the base station are the most recently sent coordinates, i.e., the real-time coordinates of the base station.

[0095] It is evident that the base station and the mobile terminal can generate the same derived key without additional synchronization operations, thereby ensuring the consistency and timeliness of encryption and decryption at both ends.

[0096] In other embodiments, the second pseudo-random number generator may be different from the first pseudo-random number generator. The deterministic algorithm used by the second pseudo-random number generator is the same as that used by the first pseudo-random number generator. The initial value used by the second pseudo-random number generator is the same as that used by the first pseudo-random number generator. Therefore, the random number sequences generated by the second pseudo-random number generator and the first pseudo-random number generator are the same, so the base station and the mobile terminal can obtain the same random number parameters.

[0097] It should be noted that the first session key is the security key data obtained by performing two-way authentication with the base station via the WAPI protocol before receiving the encrypted differential data sent by the base station.

[0098] By using the same dynamically encrypted data and the first session key, the mobile terminal can generate the same second session key as the base station, thereby enabling the decryption of the encrypted differential data and obtaining the differential data.

[0099] Furthermore, the positioning information corresponding to the mobile terminal is obtained based on differential data, including: obtaining satellite observation data corresponding to the mobile terminal; and using differential data and satellite observation data to perform position calculation to obtain positioning information.

[0100] It should be noted that alternative positioning information for the mobile terminal can be calculated using satellite observation data corresponding to the mobile terminal. Differential data is used to correct errors in the alternative positioning information to obtain the final positioning information.

[0101] In this way, since the satellite observation data corresponding to the mobile terminal can be used to calculate the alternative positioning information for the mobile terminal, but this alternative positioning information contains errors, and since the base station and the mobile terminal observe the same satellites, meaning that the satellite observation data corresponding to the base station also has the same errors (represented by differential data), the error can be corrected on the alternative positioning information calculated from the satellite observation data corresponding to the mobile terminal using the differential data, thus obtaining accurate positioning information.

[0102] Please see Figure 4 , Figure 4 This is a timing diagram illustrating a specific embodiment of the present application for transmitting differential data.

[0103] Step S401: The base station acquires the differential data to be transmitted.

[0104] In step S402, the base station uses the WAPI encryption module to encrypt the differential data to obtain encrypted differential data.

[0105] In step S403, the base station transmits encrypted differential data to a preset mobile terminal, triggering the mobile terminal to decrypt the encrypted differential data, obtain the differential data, and acquire the corresponding location information of the mobile terminal based on the differential data.

[0106] In step S404, the mobile terminal receives encrypted differential data sent by the base station, and then decrypts the encrypted differential data to obtain the differential data.

[0107] Step S405: The mobile terminal obtains the location information corresponding to the mobile terminal based on the differential data.

[0108] The method for transmitting differential data provided in this disclosure involves acquiring the differential data to be transmitted through a base station, encrypting the differential data using a WAPI encryption module to obtain encrypted differential data, and then transmitting the encrypted differential data to a mobile terminal. The mobile terminal receives the encrypted differential data sent by the base station, decrypts it, and finally obtains the differential data. Based on the differential data, the mobile terminal obtains its corresponding location information. Thus, before transmitting the differential data, the base station encrypts it, ensuring that only the mobile terminal can decrypt the encrypted differential data and parse it to achieve accurate positioning. This prevents eavesdropping devices from cracking the differential data, improving the security of differential data transmission.

[0109] Combination Figure 5 As shown, this disclosure provides an apparatus 500 for transmitting differential data, the apparatus including: a differential data acquisition module 501, a WAPI encryption module 502, and a communication module 503.

[0110] Among them, the differential data acquisition module 501 is configured to acquire differential data to be transmitted.

[0111] WAPI encryption module 502 is configured to encrypt the differential data to obtain encrypted differential data.

[0112] The communication module 503 is configured to transmit the encrypted differential data to a preset mobile terminal, trigger the mobile terminal to decrypt the encrypted differential data, obtain the differential data, and obtain the location information corresponding to the mobile terminal based on the differential data.

[0113] The apparatus for transmitting differential data provided in this disclosure acquires the differential data to be transmitted, then encrypts the differential data using a WAPI encryption module to obtain encrypted differential data, and then transmits the encrypted differential data to a preset mobile terminal, triggering the mobile terminal to decrypt the encrypted differential data to obtain the differential data, and then obtains the location information corresponding to the mobile terminal based on the differential data.

[0114] Furthermore, the WAPI encryption module is configured to encrypt the differential data to obtain encrypted differential data by: acquiring dynamic encrypted data; and encrypting the differential data based on the dynamic encrypted data to obtain the encrypted differential data.

[0115] Furthermore, the dynamically encrypted data includes one or more of the following: timestamp parameters, random number parameters, location parameters, and satellite status parameters.

[0116] Furthermore, the WAPI encryption module is configured to encrypt the differential data based on the dynamic encryption data to obtain the encrypted differential data in the following manner: obtaining a first session key; using the WAPI encryption module to obtain a second session key based on the first session key and the dynamic encryption parameters; and using the WAPI encryption module to perform symmetric encryption on the differential data based on the second session key to obtain the encrypted differential data.

[0117] Combination Figure 6 As shown, this disclosure provides another device 600 for transmitting differential data, which includes a receiving module 601, a WAPI decryption module 602, and a positioning module 603.

[0118] The receiving module 601 is configured to receive encrypted differential data sent by the base station.

[0119] WAPI decryption module 602 is configured to decrypt the encrypted differential data to obtain differential data.

[0120] The positioning module 603 is configured to obtain the positioning information corresponding to the mobile terminal based on the differential data.

[0121] The apparatus for transmitting differential data provided in this disclosure receives encrypted differential data sent by a base station, then decrypts the encrypted differential data to obtain the differential data, and then obtains the location information corresponding to the mobile terminal based on the differential data. Since the encrypted differential data is encrypted, it needs to be decrypted first to obtain the differential data, and then the location information can be obtained. Even if eavesdropped on, the differential data cannot be cracked, thus improving the security of differential data transmission.

[0122] Furthermore, the WAPI decryption module 602 is configured to decrypt the encrypted differential data to obtain the differential data by: acquiring dynamic encrypted data and a first session key; and decrypting the encrypted differential data based on the dynamic encrypted data and the first session key to obtain the differential data.

[0123] The positioning module 603 is configured to obtain the positioning information corresponding to the mobile terminal based on the differential data in the following manner: obtaining satellite observation data corresponding to the mobile terminal; and performing position calculation using the differential data and the satellite observation data to obtain the positioning information.

[0124] This application integrates the WAPI encryption mechanism into the positioning device in the RTK base station. The WAPI module is integrated inside the RTK base station equipment to control the differential data output. At the same time, additional dynamic encryption parameters are introduced on the basis of WAPI to realize the secure transmission of differential data and terminal authentication, improve the overall anti-attack capability and reliability of the system, and meet the application requirements of secure data transmission of mobile terminals.

[0125] Combination Figure 7 As shown, this disclosure provides another apparatus for transmitting differential data, including a processor 701 and a memory 702. Optionally, the apparatus may further include a communication interface 703 and a bus 704. The processor 701, communication interface 703, and memory 702 can communicate with each other via the bus 704. The communication interface 703 can be used for information transmission. The processor 701 can call logical instructions in the memory 702 to execute the method for transmitting differential data described in the above embodiments.

[0126] Furthermore, the logic instructions in the aforementioned memory 702 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium.

[0127] The memory 702, as a storage medium, can be used to store software programs and computer-executable programs, such as program instructions / modules corresponding to the methods in the embodiments of this disclosure. The processor 701 executes functional applications and data processing by running the program instructions / modules stored in the memory 702, that is, it implements the method for transmitting differential data in the above embodiments.

[0128] The memory 702 may include a program storage area and a data storage area. The program storage area may store the operating system and application programs required for at least one function; the data storage area may store data created based on the use of the terminal device. Furthermore, the memory 702 may include high-speed random access memory and may also include non-volatile memory.

[0129] In some embodiments, the device for transmitting differential data is applied to a base station. It acquires the differential data to be transmitted, then encrypts the differential data using a WAPI encryption module to obtain encrypted differential data, and then transmits the encrypted differential data to a preset mobile terminal. The mobile terminal is then triggered to decrypt the encrypted differential data to obtain the differential data, and the location information corresponding to the mobile terminal is obtained based on the differential data.

[0130] In other embodiments, the device for transmitting differential data is applied to a mobile terminal. It receives encrypted differential data sent by a base station, decrypts the encrypted differential data to obtain the differential data, and then uses the differential data to obtain the location information corresponding to the mobile terminal. Thus, since the encrypted differential data is encrypted, it needs to be decrypted first to obtain the differential data, and then the location information. Even if eavesdropped on, the differential data cannot be cracked, improving the security of differential data transmission.

[0131] This disclosure provides a storage medium storing computer-executable instructions configured to perform the method described above for transmitting differential data.

[0132] The aforementioned storage media can be either transient computer-readable storage media or non-transitory computer-readable storage media. Non-transitory storage media include various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks, and can also be transient storage media.

[0133] The foregoing description and accompanying drawings fully illustrate embodiments of this disclosure to enable those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, procedural, and other changes. The embodiments represent only possible variations. Individual components and functions are optional unless explicitly required, and the order of operation may vary. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. Moreover, the terminology used in this application is for describing embodiments only and is not intended to limit the claims. As used in the description of embodiments and claims, the singular forms “a,” “an,” and “the” are intended to equally include the plural forms unless the context clearly indicates otherwise. Similarly, the term “and / or” as used in this application means including one or more of the associated listed items and all possible combinations thereof. Additionally, when used in this application, the term "comprise" and its variations "comprises" and / or "comprising" refer to the presence of stated features, integrals, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components, and / or groups thereof. Without further limitations, an element defined by the phrase "comprises a..." does not exclude the presence of other identical elements in the process, method, or apparatus that includes said element. In this document, each embodiment may focus on the differences from other embodiments, and similar or identical parts between embodiments can be referred to mutually. For methods, products, etc., disclosed in the embodiments, if they correspond to the method section disclosed in the embodiments, the relevant parts can be referred to the description of the method section.

[0134] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of this disclosure. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0135] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than that shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. In the descriptions corresponding to the flowcharts and block diagrams in the accompanying drawings, the operations or steps corresponding to different blocks may also occur in a different order than disclosed in the description, and sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. Each block in a block diagram and / or flowchart, and combinations of blocks in a block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

Claims

1. A method for transmitting differential data, characterized in that, The method is applied to a base station; the base station is equipped with a WAPI encryption module for wireless LAN authentication and security infrastructure; the method includes: Obtain the differential data to be transmitted; The differential data is encrypted using the WAPI encryption module to obtain encrypted differential data; The encrypted differential data is transmitted to a preset mobile terminal, which triggers the mobile terminal to decrypt the encrypted differential data, obtain the differential data, and obtain the location information corresponding to the mobile terminal based on the differential data.

2. The method according to claim 1, characterized in that, The step of encrypting the differential data using the WAPI encryption module to obtain encrypted differential data includes: Obtain dynamically encrypted data; The WAPI encryption module is used to encrypt the differential data based on the dynamic encryption data to obtain the encrypted differential data.

3. The method according to claim 2, characterized in that, The dynamically encrypted data includes one or more of the following: timestamp parameters, random number parameters, location parameters, and satellite status parameters.

4. The method according to claim 2, characterized in that, The step of encrypting the differential data using the WAPI encryption module based on the dynamic encryption data to obtain the encrypted differential data includes: Obtain the first session key; The WAPI encryption module is used to obtain the second session key based on the first session key and the dynamic encryption parameters; The WAPI encryption module is used to symmetrically encrypt the differential data according to the second session key to obtain the encrypted differential data.

5. A method for transmitting differential data, characterized in that, Applied to mobile terminals; the method includes: Receive encrypted differential data sent by the base station; Decrypt the encrypted differential data to obtain the differential data; The location information corresponding to the mobile terminal is obtained based on the differential data.

6. The method according to claim 5, characterized in that, The base station is equipped with a WAPI decryption module; Decrypting the encrypted differential data to obtain the differential data includes: Obtain dynamically encrypted data and the first session key; The WAPI decryption module is used to decrypt the encrypted differential data based on the dynamic encrypted data and the first session key to obtain the differential data.

7. The method according to claim 5, characterized in that, The step of obtaining the location information corresponding to the mobile terminal based on the differential data includes: Obtain satellite observation data corresponding to the mobile terminal; The location information is obtained by using the differential data and the satellite observation data to calculate the location.

8. An apparatus for transmitting differential data, comprising a processor and a memory storing program instructions, characterized in that, The processor is configured to, when executing the program instructions, perform the method for transmitting differential data as described in any one of claims 1 to 8.

9. A system for transmitting differential data, characterized in that, include: The base station is configured to acquire differential data to be transmitted; The differential data is encrypted using the WAPI encryption module to obtain encrypted differential data; The encrypted differential data is transmitted to a preset mobile terminal, triggering the mobile terminal to decrypt the encrypted differential data, obtain the differential data, and obtain the location information corresponding to the mobile terminal based on the differential data; The mobile terminal is configured to receive encrypted differential data sent by the base station; Decrypt the encrypted differential data to obtain the differential data; The location information corresponding to the mobile terminal is obtained based on the differential data.

10. A storage medium storing program instructions, characterized in that, When the program instructions are executed, they perform the method for transmitting differential data as described in any one of claims 1 to 7.