An international airline layout diagram message and picture generation method based on AI image recognition
By using AI image recognition and encryption algorithms, cabin information in the layout diagram is automatically extracted and structured, solving the problems of low efficiency and data inconsistency in the process of generating layout diagrams for international airlines. This enables efficient and reliable generation of layout diagram messages and images, improving the system's security and operational stability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- FEIYOU TECH CO LTD
- Filing Date
- 2026-02-02
- Publication Date
- 2026-05-08
AI Technical Summary
International airline layout maps are susceptible to human error, inconsistent system interfaces, and the complexity of cross-system collaboration during the generation, modification, and distribution process, leading to inconsistent information, version confusion, or delayed updates. Furthermore, existing technologies lack systematic protection mechanisms, making it difficult to detect and isolate potential abnormal operations in a timely manner. Manual identification of cabin information is inefficient and prone to errors.
AI image recognition technology is used to automatically extract cabin identifiers and boundary coordinates from the source image of the layout map. Combined with data flow records and cabin information logs, encrypted data blocks are generated through encryption algorithms. Anomaly detection and access control are performed to isolate unauthorized modifications and ensure data integrity. Access logs are compared and encrypted on a multi-party collaboration platform to finally generate reliable layout map messages and images.
It enables the automatic extraction and structured representation of key elements in the layout diagram, improves the security and reliability of the generation process, reduces errors caused by human intervention, enhances the automation level and operational efficiency of international airline layout diagram generation, and ensures the security and consistency of data in a multi-party collaborative environment.
Smart Images

Figure CN121639858B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of aviation information technology and computer application technology, specifically to a method for generating international airline layout map messages and images based on AI image recognition. Background Technology
[0002] With the rapid development of the international air transport industry, airlines are increasingly reliant on information systems in areas such as aircraft configuration, cabin layout, and flight operation management. Layout diagrams, as crucial data carriers describing aircraft cabin structure, seat distribution, and related configuration information, typically circulate between multiple airline systems in the form of messages and images. Their accuracy and consistency directly impact key business operations such as flight planning, cabin sales management, and operational scheduling.
[0003] In existing technologies, the generation and management of international airline layout maps largely rely on manual maintenance or semi-automated processing. The data sources for these layout maps are complex, including both text-based cabin information records and image-based layout map files. Due to the frequent sharing and updating of layout map data between different systems and roles, the generation, modification, and distribution of layout maps are susceptible to human error, inconsistencies in system interfaces, and the complexity of cross-system collaboration, leading to inconsistencies, version chaos, or delayed updates. Furthermore, with the introduction of digital tools and multi-party collaboration platforms, the flow of layout map-related data between multiple system nodes has become commonplace. In this process, layout map data not only faces challenges in format conversion and content parsing but also the risk of abnormal interference or unauthorized modification during transmission and processing. Existing technologies typically focus on post-event verification or manual checks, lacking a systematic protection mechanism for the layout map generation process. This makes it difficult to promptly detect and isolate potential abnormal operations, thus affecting the reliability of the generated layout maps. Furthermore, key information such as cabin locations and area boundaries contained in the source images of layout maps often requires manual identification or analysis based on experience, which is not only inefficient but also prone to errors due to subjective judgment. In scenarios where layout maps need frequent updates, accurately extracting cabin-related elements from layout map images and effectively integrating them with structured data such as cabin information logs is a common challenge in existing technologies. Summary of the Invention
[0004] The purpose of this invention is to provide a method for generating international airline layout map messages and images based on AI image recognition, thereby solving the problems existing in the prior art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for generating international airline layout map messages and images based on AI image recognition, comprising:
[0006] S1. Through multi-party collaborative system interaction, obtain data flow records and cabin information logs from digital tools during the layout management process used to generate international airline layout map messages and layout map images, and obtain the layout map source images corresponding to the cabin information.
[0007] S2. Perform AI image recognition on the layout map source image to extract cabin identifiers, area boundaries and their coordinate positions to form structured layout map data. Perform encryption algorithm processing on data flow records, cabin information logs and structured layout map data to obtain encrypted data blocks, and determine the data integrity verification value in the abnormal interference detection stage.
[0008] S3. Determine whether there is abnormal interference in the data flow process based on the verification value calculated from the encrypted data block. If the verification value does not match the preset threshold, activate the access control module to isolate the illegal modification attempt and obtain the isolated secure data flow.
[0009] S4. Using a verification algorithm, cabin information and cabin allocation details are extracted from the isolated security data stream. Combined with cabin coordinates and area boundary layout elements obtained from AI image recognition, the cabin information is determined in the system interaction environment to determine whether it meets the requirements for generating the layout map. A layout map data set is generated to directly construct international airline layout map messages and layout map images.
[0010] Preferably, step S1 includes obtaining data flow records and cabin dynamic update records from digital tools during the layout map management process through multi-party collaborative interaction, thus obtaining data flow records and cabin dynamic update records; collecting cabin information logs based on data flow records and cabin dynamic update records, thus determining cabin information logs; matching layout map source images with cabin information logs and comparing them with dynamic update records to obtain layout map source images; if the layout map source image corresponds to the cabin information log, integrating the information log and verifying the image source and international standard message format to obtain integrated information log and verified image source; and using the integrated information log and verified image source to fuse and generate international airline layout map messages and layout map images to obtain layout map messages and layout map images.
[0011] Preferably, step S2 includes: extracting cabin identifiers and locating boundary coordinates from the layout image source using AI image recognition to obtain layout elements; forming structural data corresponding to the layout elements and integrating cabin occupancy status records to determine extended layout data; using the extended layout data to encrypt data flow records and integrate cabin information logs to construct an encrypted block; after obtaining the encrypted block, performing a judgment through interference detection; if abnormal interference exceeds a preset threshold, adjusting encryption parameters to obtain an adjusted encrypted block; performing a complete verification on the adjusted encrypted block to determine and generate a data integrity verification value; obtaining a dynamic layout adjustment verification and image verification integration record from the data integrity verification value; and preparing to generate an international airline layout map message and layout map image based on the fused message of the dynamic layout adjustment verification and image verification integration record.
[0012] Preferably, step S3 includes obtaining a verification value from the encrypted data block, performing interference anomaly judgment by comparing the verification value with a preset threshold, and determining the threshold matching verification result; if the threshold matching verification result does not match, the access control module is activated to attempt to isolate the illegal modification to obtain an isolated secure data stream; the isolated secure data stream is fused with cabin change tracking records, and a response strategy is executed to construct a process monitoring record; control intervention data is integrated based on the process monitoring record to obtain a secure data stream for use in layout diagram message and image generation.
[0013] Preferably, step S4 includes extracting cabin information and cabin allocation details from the isolated security data stream; using a verification algorithm and a hash function to calculate data integrity to obtain an extracted cabin data group; fusing the extracted cabin data group with image recognition results to obtain coordinate positions and area boundary divisions to generate fused layout elements; judging whether the fused layout elements meet the verification requirements in the interactive environment; if the judgment result meets the requirements, determining the verified layout element group; constructing message data based on the verified layout element group to obtain a message-constructed data stream; and integrating image generation elements through the message-constructed data stream to output a layout diagram data group.
[0014] Preferably, the process also includes S5: obtaining associated access control logs from the multi-party collaboration platform through the layout diagram data group, and comparing and analyzing the access control logs to determine whether there are potential traces of unauthorized modification, thereby obtaining a purified access log set. Specifically, this includes obtaining associated access control logs from the multi-party collaboration platform through the layout diagram data group, processing the access control logs using a comparison and analysis mechanism to obtain preliminary analysis results; integrating cabin layout fusion attributes based on the preliminary analysis results to determine whether there are traces of unauthorized modification, thereby identifying a potential risk set; performing security data verification based on the potential risk set and image coordinate boundaries to obtain purified processing elements and generate an intermediate log group; and using the intermediate log group to integrate interactive verification requirements and message data to construct and output the purified access log set.
[0015] Preferably, the method further includes S6: re-encapsulating the layout map data group using an encryption algorithm based on the purified permission log set, and determining whether the encapsulated data has the ability to resist abnormal interference during the digital tool update process, and outputting an enhanced data packet containing international airline layout map messages and layout map images. Specifically, this includes implementing the AES encryption algorithm on the layout data group using the purified log set to obtain the encapsulated preliminary data group; injecting a preset interference simulation signal sequence into the preliminary data group during the tool update process to determine the ability of the encapsulated data to resist abnormal interference, thereby obtaining a verification result set.
[0016] Preferably, step S6 further includes fusing a preset cabin permission mapping verification table with the verification result set to determine potential vulnerability points and generate a reinforcement strategy group; integrating the backup message paths of international airlines based on the reinforcement strategy group to obtain an intermediate packet containing image messages and layout image; constructing a preset boundary verification mechanism from the intermediate packet and outputting reinforcement data packets.
[0017] Preferably, the process also includes S7: verifying the enhanced data packets using a verification algorithm during data flow testing, distributing the verified data packets to system interaction nodes, summarizing and processing the node feedback to obtain a final integrity confirmation report, and obtaining cabin information update instructions from the flight scheduling system based on the final integrity confirmation report. The instruction execution verification algorithm is then used to determine whether passenger disruption is avoided, and the generation and publication of the international airline layout map message and layout map image are completed. Specifically, this includes using a preset sequence injection verification algorithm to obtain verified data packets during data flow testing; distributing the verified data packets to system interaction nodes to obtain a node feedback set; and merging and summarizing the node feedback set to determine the final integrity confirmation report.
[0018] Preferably, step S7 further includes extracting cabin information update instructions from the final integrity confirmation report, determining whether the instruction execution verification algorithm meets preset standards to obtain results, obtaining results to generate international airline layout map messages and layout map images, and constructing a release path.
[0019] As can be seen from the above technical solution, the present invention has the following beneficial effects:
[0020] This AI-based image recognition method for generating international airline layout map messages and images automatically extracts and structures key elements of the layout map by fusing the AI image recognition results of the layout map source image with cabin information logs and data flow records. This effectively reduces the impact of manual intervention on the accuracy and consistency of layout map generation. Furthermore, by introducing data encryption, integrity verification, anomaly detection, and access control mechanisms during the layout map generation process, potential unauthorized modifications and abnormal operations on layout map data during multi-party collaboration and cross-system flow are identified and isolated, improving the security and reliability of the layout map message and image generation process. In addition, by performing multi-node verification and integrity confirmation on the generated data, the final generated and published layout map messages and images better meet the practical application needs of flight scheduling and cabin management, thereby improving the automation level, stability, and overall operational efficiency of international airline layout map generation. Attached Figure Description
[0021] Figure 1 This is a flowchart of the method for generating international airline layout map messages and images according to the present invention. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] like Figure 1 As shown, this invention provides a technical solution: a method for generating international airline layout map messages and images based on AI image recognition, comprising:
[0024] S1. Through multi-party collaborative system interaction, obtain data flow records and cabin information logs from digital tools during the layout management process used to generate international airline layout map messages and layout map images, and obtain the layout map source images corresponding to the cabin information.
[0025] S2. Perform AI image recognition on the layout map source image to extract cabin identifiers, area boundaries and their coordinate positions to form structured layout map data. Perform encryption algorithm processing on data flow records, cabin information logs and structured layout map data to obtain encrypted data blocks, and determine the data integrity verification value in the abnormal interference detection stage.
[0026] S3. Determine whether there is abnormal interference in the data flow process based on the verification value calculated from the encrypted data block. If the verification value does not match the preset threshold, activate the access control module to isolate the illegal modification attempt and obtain the isolated secure data flow.
[0027] S4. Using a verification algorithm, extract cabin information and cabin allocation details from the isolated security data stream. Combined with cabin coordinates and area boundary layout elements obtained from AI image recognition, determine whether the cabin information meets the requirements for generating the layout map in the system interactive environment. Generate a layout map data set for directly constructing international airline layout map messages and layout map images.
[0028] S5. Obtain the associated access control logs in the multi-party collaboration platform through the layout diagram data group, and compare and analyze the access control logs to determine whether there are any potential traces of illegal modification, and obtain a cleaned access log set.
[0029] S6. Based on the purified permission log set, the layout diagram data group is repackaged using an encryption algorithm, and in the digital tool update process, it is determined whether the packaged data has the ability to resist abnormal interference, and an enhanced data packet containing international airline layout diagram messages and layout diagram images is output.
[0030] S7. The enhanced data packets are verified by the verification algorithm in the data flow test, and the verified data packets are distributed to the system interaction nodes. The node feedback is summarized and processed to obtain the final integrity confirmation report. The cabin information update instruction is obtained from the flight scheduling system through the final integrity confirmation report. The instruction execution verification algorithm is used to determine whether it avoids passenger impact. The international airline layout map message and layout map image are generated and published.
[0031] This implementation method is based on the technical background of frequent updates to the cabin layout of international airlines in a multi-system, multi-role collaborative environment with high security requirements. By integrating AI image recognition technology with data encryption, integrity verification and access control mechanisms, it enables the reliable generation and publication of layout map messages and layout map images.
[0032] During system operation, the multi-party collaborative system and digital tools first interact to synchronously acquire data flow records and cabin information logs during the layout map management process, and associate them with the corresponding layout map source images. Subsequently, AI image recognition algorithms are used to analyze the layout map source images, automatically identifying cabin identifiers, the areas to which cabins belong, and the coordinate positions of each cabin in the layout map, thereby forming structured layout map data that can be computed and processed.
[0033] Based on this, data flow records, cabin information logs, and structured layout data are uniformly processed using encryption algorithms to generate encrypted data blocks, and a data integrity verification value is calculated through an anomaly interference detection mechanism. By comparing the calculated verification value with a preset threshold, it is determined whether the data has been subjected to unauthorized interference during the flow process. When an anomaly is detected, the access control module is triggered to isolate data at risk of unauthorized modification, forming an isolated secure data flow.
[0034] Subsequently, the system uses a verification algorithm to extract valid cabin information and cabin allocation details from the isolated security data stream. Combined with cabin coordinates and area boundary layout elements obtained in the AI image recognition stage, the system verifies the completeness, consistency, and layout rationality of the cabin information in the system interaction environment, thereby generating a layout map data set that can be directly used to construct international airline layout map messages and layout map images.
[0035] After the layout diagram data set is generated, the system further calls upon the access control logs in the multi-party collaboration platform to compare and analyze the relevant logs to identify potential traces of unauthorized modification, and based on this, forms a purified access log set. Based on this access log set, the layout diagram data set is re-encapsulated using an encryption algorithm, and its resistance to abnormal interference is evaluated during the digitization tool update process, ultimately outputting a reinforced data package.
[0036] The enhanced data packets are verified using a validation algorithm during data flow testing. Once verified, they are distributed to each system interaction node, and the node feedback is summarized and analyzed to generate a final integrity confirmation report. The flight scheduling system uses this final integrity confirmation report to obtain cabin information update instructions. Before executing the instructions, it uses a validation algorithm to determine whether the instructions will affect passengers, thus ensuring the secure generation and publication of international airline layout map messages and images.
[0037] Compared with existing technologies, this implementation method introduces AI image recognition technology to achieve automated identification and structured processing of cabin information and spatial layout elements in international airline layout source images, reducing the efficiency loss and error risk caused by manual annotation and manual verification.
[0038] Meanwhile, by introducing encryption algorithms, integrity verification, and abnormal interference detection mechanisms throughout the entire data flow process, the security and reliability of layout diagram data in a multi-party collaborative environment are effectively improved. This enables the timely detection and isolation of unauthorized modifications, preventing the layout diagram information from being tampered with.
[0039] Furthermore, by performing secondary comparison and purification of access control logs, the final generated layout diagram data group has higher data purity and traceability, enhancing the system's ability to defend against potential security risks.
[0040] Introducing a final integrity confirmation report and instruction execution verification mechanism into the flight scheduling system enables an assessment of passenger impact before layout map updates, thereby reducing operational risks caused by layout map changes and improving the reliability and stability of international airlines' cabin management and scheduling.
[0041] S1 includes obtaining data flow records and cabin space dynamic update records during the layout map management process from digital tools through multi-party collaborative interaction, thus obtaining data flow records and cabin space dynamic update records; collecting cabin space information logs based on data flow records and cabin space dynamic update records, thus determining cabin space information logs; matching layout map source images with cabin space information logs and comparing them with dynamic update records to obtain layout map source images; if the layout map source image corresponds to the cabin space information log, integrating the information logs and verifying the image source and international standard message format to obtain integrated information logs and verified image sources; and using the integrated information logs and verified image sources to generate international airline layout map messages and layout map images to obtain layout map messages and layout map images.
[0042] In this implementation, a data acquisition channel for digital tools is first established through multi-party collaborative interaction. The multi-party collaborative interaction process is as follows: after the parties involved complete identity authentication and permission verification on the multi-party collaboration platform, the system triggers a data retrieval session based on the flight identifier. During the session, data flow records and cabin class dynamic update records in the layout management process are requested sequentially according to a pre-agreed data directory. Field-level parsing is then performed at the receiving end to form a unified record set. The field parsing process includes extracting timestamps, flight identifiers, cabin class numbers, operation types, operator identifiers, and data source node identifiers item by item, rejecting missing fields, and isolating and marking fields with abnormal formats. Timestamp processing uses the same time zone and precision rules. The receiving end sorts all records by timestamp from earliest to latest, and performs deduplication on duplicate records with the same timestamp and completely identical content. Deduplication is based on the complete consistency of the four combinations: flight identifier, cabin class number, operation type, and operator identifier.
[0043] After obtaining data flow records and cabin class dynamic update records, the system collects cabin class information logs based on these two types of records. This collection process is not a simple aggregation, but rather a "merging and attribution" of cabin class events. First, the system groups all records for the same flight using the flight identifier as the primary key; then, it merges records for the same cabin class into a single cabin class change chain using the cabin class number as the secondary key; finally, it maps the operation types within the cabin class change chain to cabin class status and cabin class attribute fields according to business semantics, forming a standard set of fields for the cabin class information log. The calculation process is reflected in the determination of the "latest state": for each cabin class change chain, the record with the latest timestamp that has not been isolated is taken as the currently valid record, while retaining the preceding records for that cabin class as a traceability link. If multiple records with different content exist for the same cabin class at the same timestamp, the system makes a decision based on the node priority reflected in the data flow record. The node priority parameter comes from the configuration list of the multi-party collaboration platform, which is provided by the business party and confirmed through the permission approval process when the system is put into production. When the node priorities are the same, the system then makes a decision based on the operator's permission level, which is determined by the role level table within the permission system. The above decision-making process outputs a unique current valid cabin class status.
[0044] After completing the cabin information log, the system matches the layout image source with the cabin information log and compares it with cabin dynamic update records to obtain the layout image source. The matching process first performs candidate set filtering: the system filters the candidate image set from the layout image resource pool according to flight identifier, aircraft type identifier, and cabin segment configuration identifier; the aircraft type identifier and cabin segment configuration identifier are derived from the cabin partition and seat arrangement features in the cabin information log. The derivation process involves parsing the cabin numbering rules and partition identifiers to obtain the partition boundary descriptions of first class, business class, and economy class, and then mapping them to a pre-set aircraft type configuration dictionary. After the candidate set is formed, the system performs consistency score calculation to determine the unique layout image source. The scoring calculation consists of several sub-items: The first sub-item is cabin quantity consistency. The system counts the number of currently valid cabin entries in the cabin information log and reads the cabin capacity declared in the metadata of the candidate image. The difference between the two is the cabin quantity deviation. The second sub-item is cabin number coverage. The system compares the set of cabin numbers in the cabin information log with the set of cabin number indices of the candidate image and calculates the number of uncovered cabins. The third sub-item is version freshness. The system reads the version timestamp of the candidate image and calculates the time difference with the latest timestamp of the cabin dynamic update record. The fourth sub-item is structural matching degree. The system reads the number of cabin segments, the number of aisles, and the emergency exit row position identifier declared in the candidate image and performs a consistency judgment on each item with the structural features derived from the cabin information log.
[0045] The above sub-items are aggregated according to preset weights to form a total score, and the candidate image with the highest total score that meets the threshold condition is selected as the source image for the layout. The weight parameters are determined based on the priority of business risks: the direct risk of generation errors corresponding to cabin number consistency and cabin number coverage is given the highest weight; version freshness corresponds to timeliness risk and is given the second highest weight; structural matching corresponds to layout display risk and is given the third highest weight. The threshold is determined using a dual constraint of historical stable period sample statistics and online acceptance rules: during the stable period, the system collects a period of continuously running, anomaly-free samples, and calculates the maximum value of cabin number deviation, the maximum value of uncovered cabin number, and the maximum value of version time difference, and uses this as a baseline; at the same time, the business acceptance provides the maximum acceptable deviation boundary. The final threshold is the stricter of the two to ensure that the matching results meet the business tolerance after going online. If none of the candidate images meet the threshold conditions, the system marks the flight as pending manual review and stops the subsequent generation process to avoid inconsistent output results.
[0046] Once the layout image source is determined, the system performs a "correspondence determination between the layout image source and the cabin information log." This correspondence determination process includes static consistency determination and dynamic consistency determination. Static consistency determination addresses the current cabin status: for each currently valid cabin entry in the cabin information log, the system verifies whether its cabin number appears in the cabin number index set of the layout image source and counts the number of missing entries; it also verifies whether the cabin partition identifier matches the cabin segment configuration identifier declared in the image. Dynamic consistency determination addresses recent cabin changes: the system extracts change events from the cabin dynamic update record within a time window that traces back from the latest timestamp. The time window parameter is determined by the business update frequency, and the process involves calculating the average interval of cabin update events within a recent operating cycle and setting the time window to a multiple of the average interval to cover common delays. Within this time window, it verifies whether each change event has been reflected after the version timestamp corresponding to the layout image source. If any unreflected events exist, a mismatch is determined. The corresponding determination threshold is also determined from two sources: on the one hand, based on the proportion of historical stable samples with zero missing items, and on the other hand, based on the business rules requiring zero missing items. Finally, zero missing items are used as the determination condition to ensure that each cabin information has a landing point in the layout map source image.
[0047] When the layout image source corresponds to the cabin information log, the system enters the information integration and verification process, outputting the integrated information log and the verified image source. The information integration process is manifested as "merging, trimming, sequencing, and labeling". Merging refers to merging records generated by the same cabin from different source nodes into a single currently valid entry according to decision rules; trimming refers to removing historical fields that have no impact on the current layout display, retaining only fields that affect the layout display and message generation, such as cabin number, cabin status, cabin partition, applicable population restriction identifier, and availability identifier; sequencing refers to arranging cabin entries in the order required for the layout display, with the arrangement rules determined by the natural order of cabin numbers and the partition order; labeling refers to attaching a traceability identifier to each entry. The traceability identifier is generated by compressing the node links in the data flow record. The generation process involves splicing node identifiers in chronological order and generating a fixed-length fingerprint for subsequent verification of source consistency.
[0048] The image source verification process includes file consistency verification, content integrity verification, and version consistency verification. File consistency verification calculates the image file's digest value and compares it with the digest values registered in the resource pool. The digest algorithm parameters are fixed in the system configuration, based on the system's existing security baseline. Content integrity verification reads the image's size, color channel, and encoding format information to verify whether it falls within a preset legal range. The legal range parameters are given by the output specifications of the digitization tool and agreed upon in the interface documentation. Version consistency verification compares the time difference between the image version timestamp and the latest timestamp in the cabin dynamic update record. The time difference must not exceed the aforementioned time window upper limit. The time window upper limit is jointly determined by the maximum synchronization delay in historical sample statistics and the business acceptance delay upper limit, with the stricter one being adopted.
[0049] The implementation process of international standard message format verification revolves around "field completeness, field order, field values, and structural hierarchy." Field completeness verification checks whether each item in the mandatory field list of the message has a source field in the integrated information log and can be mapped. The parameters of the mandatory field list are derived from the message specification list of the interface system and confirmed through joint debugging by both parties. Field order verification aligns the field sequence of the generated message with the sequence in the specification list item by item; any inconsistency results in failure. Field value verification performs code table mapping and range verification on each field. The code table parameters are derived from the airline's business code table library, and the range parameters are derived from the message field definition. Structural hierarchy verification counts and verifies the number of hierarchical nodes, parent-child relationships, and the number of repeated paragraphs in the message; the upper limit of the count is given by the specification list. After all the above verifications pass, a verified image source and an integrated information log that can be used for fusion are formed.
[0050] After integration and verification, the system uses the integrated information logs and verified image sources to generate international airline layout map messages and images, and outputs the layout map messages and images. The fusion process first establishes a mapping index from cabin class entries to image areas. The establishment of the mapping index depends on the cabin class number index table built into the layout map source images; when the image index table is missing, the fusion process will not enter the output stage and will trigger exception handling. After the mapping index is established, the system iterates through the integrated information logs one by one, mapping the status field, partition field, and restriction field of each cabin class entry to the display attribute set of the corresponding image area. The definition of the display attribute set is given by the rendering specifications of the digitization tool, and the rendering specifications are stored in the system configuration in an enumeration manner.
[0051] The subsequent process of generating the layout image involves updating the color, text, icon, and boundary styles of the display layer for each image region according to the set of display attributes. The update order strictly follows the hierarchical order in the rendering specification to avoid occlusion and overlay errors. The process of generating the layout image message involves splitting the integrated information log into flight-level, cabin-level, and class-level segments according to the message structure hierarchy, and outputting field values in order. Before output, the field values undergo code table mapping and validity verification. If the verification fails, the output is blocked and the reason for the failure is marked. Finally, the system performs a consistency verification between the layout image message and the layout image. The consistency verification checks whether the number of entries in the class-level segment in the message matches the number of mapped areas in the layout image, and also verifies whether the set of cabin numbering matches. The consistency verification threshold is set to complete consistency. This threshold is determined because layout image generation is a structured output scenario; any omission will lead to downstream parsing or display deviations, and the business acceptance rules require zero deviation.
[0052] S2 includes extracting cabin identifiers and locating boundary coordinates from the layout map source image using AI image recognition to obtain layout elements, forming structural data corresponding to the layout elements, and integrating cabin occupancy status records to determine extended layout data; using the extended layout data to encrypt data flow records and integrate cabin information logs to construct an encrypted block; after obtaining the encrypted block, performing judgment through interference detection, if abnormal interference exceeds a preset threshold, adjusting encryption parameters to obtain an adjusted encrypted block; performing a complete verification on the adjusted encrypted block to determine the generation of a data integrity verification value, obtaining a dynamic layout adjustment verification and image verification integration record from the data integrity verification value; and preparing to generate an international airline layout map message and layout map image based on the fused message of the dynamic layout adjustment verification and image verification integration record.
[0053] In this implementation, firstly, artificial intelligence image recognition is performed on the layout map source image to extract cabin identifiers and boundary coordinate positioning information. Before the image enters the recognition process, the system performs basic consistency processing on the image, including resolution verification, orientation verification, color channel verification, and coordinate system establishment. Resolution verification is performed by reading the image width and height values and comparing them with the minimum resolution threshold. The minimum resolution threshold is given by the output specification of the digitization tool. If the specification is not given, the lower limit is obtained by statistically analyzing the smallest size sample that can be stably recognized in history. Orientation verification is performed by reading the orientation markers in the image metadata and rotating the image to a unified orientation. The orientation unification standard is determined by the layout map resource pool registration rules. Color channel verification is performed by reading the number of channels and converting them to a unified channel structure. The unified channel structure is determined by the input requirements for training the recognition model. Coordinate system establishment is performed by defining the upper left corner of the image as the origin and establishing the horizontal and vertical coordinate directions, so that the subsequent boundary coordinates have a unified reference.
[0054] After standardization, the system locates cabin class identifiers in the images. The location process begins with text region detection, outputting the rectangular range and detection confidence level of each suspected cabin class number region. The detection confidence threshold is determined by two constraints: one part comes from the lowest confidence quantile of true positive detections in historical normal samples, and the other part comes from the upper limit requirement for false positive rate in business acceptance. The final threshold adopts the stricter boundary to suppress false positives. For text regions that pass the threshold, the system performs character parsing to obtain the cabin class number text and performs rule validation on the parsing results. Rule validation includes character length validation and number format validation. The character length threshold is obtained from the cabin class number length distribution statistics in the aircraft configuration dictionary, and the number format threshold is given by the airline's cabin class number specifications. Both constrain the legality of the parsing results. If the parsed text does not meet the rule validation, the text region is marked as invalid and included in the anomaly record, and is not included in the layout element construction.
[0055] In parallel with cabin identification extraction, the system performs boundary coordinate localization on the layout image to obtain cabin area boundaries and area separation boundaries. Boundary localization begins with line and contour extraction. First, edge enhancement is performed on the image to extract continuous line segments. Then, the line segments are judged for closure to form candidate regions. The closure judgment process is based on "endpoint distance" and "gap length": the endpoint distance is calculated for the endpoint coordinates of each line segment, and the set of line segments with endpoint distance less than the closure distance threshold is judged as candidate members of the same closed contour. The closure distance threshold is determined by image resolution and line width statistics. The line width statistics are obtained by sampling the thickness of the line pixel band. The higher the resolution, the larger the threshold; the thicker the line width, the larger the threshold.
[0056] For candidate closed contours, the system calculates the area of its enclosed region and compares it with a minimum region area threshold. The area calculation is based on the bounded range of the boundary point set in the coordinate system. The minimum region area threshold is obtained from the statistics of the minimum display area per seat in the historical layout diagram, and is also constrained by the minimum seat size in the aircraft configuration dictionary. The final threshold adopts the stricter boundary to eliminate noisy contours. For closed contours that pass the area threshold, the system outputs the boundary point sequence in coordinate order as the cabin boundary coordinate set, and performs smoothing and point number compression processing on the boundary point sequence to reduce the number of redundant points while maintaining the shape of the coordinate set. The upper limit of the point count is determined by the constraints of subsequent rendering and message carrying costs, specifically based on the maximum load of the system transmission unit and the boundary point processing limit of the rendering engine, with the stricter boundary being taken as the upper limit of the point count.
[0057] After obtaining the cabin number and cabin boundary coordinates, the system constructs layout elements and forms corresponding structural data. The construction of structural data hinges on the "one-to-one binding of cabin numbers to boundary regions," a process completed using spatial correlation calculations. The system first calculates the center position of each boundary region by taking the median of the maximum and minimum x-coordinates and the median of the maximum and minimum y-coordinates of the boundary point sequence. Next, it calculates the center position of the text area for each cabin number. Then, it calculates the distance between the text center and the boundary center, using the absolute values of the coordinate differences to form sortable distance values. Within the same candidate range, the boundary region with the smallest distance value is selected as the binding region for that cabin number. To avoid incorrect binding, the system introduces a maximum binding distance threshold. This threshold is determined based on the average relative spacing between the number and seat frame in the layout diagram, combined with the influence of image scaling, using a stricter boundary as the maximum binding distance threshold. If the minimum distance value still exceeds this threshold, the cabin number is marked as an unbound entry and not included in the valid structural data.
[0058] After binding is complete, the structural data must include at least the cabin class number, the set of cabin boundary coordinates, the cabin's region identifier, and the cabin sorting index. The cabin's region identifier is determined by the spatial relationship between the region separation boundary and the cabin boundary. The system calculates the partition polygon into which the cabin boundary center falls and assigns the corresponding partition identifier. The cabin sorting index is obtained by grouping the longitudinal positions of the cabin boundary centers within the same partition and sorting their lateral positions. The grouping threshold is determined by the longitudinal spacing statistics of seats in the same row, and the sorting rules are constrained by both the cabin class number specification and the spatial position to ensure that the sorting results are consistent in image rendering and message segment organization.
[0059] After the structural data is generated, the system integrates cabin occupancy status records to determine the extended layout data. The cabin occupancy status records are sourced from the occupancy status acquisition module in the layout management link, and each record includes at least the flight identifier, cabin number, occupancy status, and status update timestamp. The integration process aligns the flight identifier and cabin number using a double-key method. After alignment, the occupancy status and status update timestamp are incorporated into the corresponding structural data entries. If any missing entries exist during alignment, the system performs a missing entry count and generates a missing entry ratio. The missing entry ratio is calculated by dividing the number of missing entries by the total number of valid structural data entries. The missing entry ratio threshold is determined by the minimum integrity requirements of the business, while also being constrained by the upper bound of the missing entry ratio during historical stable periods; the final threshold adopts the stricter boundary. When the missing entry ratio exceeds the threshold, this batch of extended layout data is marked as unqualified and does not enter the encrypted encapsulation link, blocking untrusted input at the source.
[0060] Subsequently, the extended layout data is used to encrypt the data flow records and merge them with the cabin information logs to construct an encrypted block. Before merging, the system first unifies the data flow records and cabin information logs according to field definitions, including unified timestamp precision, unified node identifier encoding, unified cabin number format, and unified operation type enumeration. The parameters for unified field definitions are derived from the docking specification list and the data dictionary of the multi-party collaboration platform. The data dictionary serves as a unified basis to avoid cross-system discrepancies. After unification, the system concatenates the extended layout data, data flow records, and cabin information logs into a data sequence in a fixed order and performs segmentation processing to form a data segment set.
[0061] The segment length parameter is determined by two types of constraints: the first is the optimal performance range of the encryption algorithm for the input block size, and the second is the interference localization granularity requirement, with smaller segments being shorter. The system determines the lower limit of performance based on the throughput stability range obtained from historical performance stress tests, and determines the upper limit of granularity based on the minimum acceptable range of abnormal localization. The final segment length is a value that balances both and satisfies the security policy. For each data segment, the system generates a segment identifier and a sequence identifier. The segment identifier is obtained by performing a digest calculation on the segment content. The digest length parameter is specified by the security baseline and constrained by collision risk requirements. The sequence identifier is generated by the segment number and bound to the flight identifier to avoid cross-flight reordering.
[0062] Subsequently, the data segment set is encrypted to form an encrypted block. The encryption key, rotation period, and derivation factor update frequency belong to the encryption parameter set. The key length is determined by the security level requirements, the rotation period is jointly determined by the maximum session duration of the multi-party collaborative link and the key exposure window requirements, and the derivation factor update frequency is determined by the abnormal interference risk level. The risk level is jointly given by the historical attack surface assessment and the frequency statistics of permission changes.
[0063] After the encrypted block is formed, it enters the interference detection stage. Interference detection quantifies abnormal interference and compares it with a preset threshold. The abnormal interference quantification is obtained by summarizing multiple indicators, which include at least the data segment count consistency indicator, segment identifier continuity indicator, cabin number set consistency indicator, and occupancy status time series consistency indicator. The data segment count consistency indicator is obtained by comparing the difference in the number of data segments before and after fusion, and the difference value is the absolute difference; the segment identifier continuity indicator is obtained by checking whether there are missing or duplicate numbers in the sequence identifier and calculating the number of anomalies; the cabin number set consistency indicator is obtained by calculating the difference between the cabin number set in the extended layout data and the cabin number set in the cabin information log; the occupancy status time series consistency indicator is obtained by counting the number of status flips of the same cabin within the same time window and comparing it with the maximum flip number threshold. The time window length is determined by the average interval of cabin status updates, and the maximum flip number threshold is determined by the upper bound of historical normal operation samples and is constrained by business rules.
[0064] The abnormal interference level is calculated by weighting and summarizing the various indicators. The weight parameters are determined based on the risk contribution: indicators involving missing or rearranged content have higher weights, while those involving time-series fluctuations have lower weights. The weights are determined from fault playback and audit conclusions, with indicators causing erroneous messages and images grouped into the high-weight set. The preset threshold is determined using a dual-source constraint: firstly, by collecting samples from the stable period to obtain the natural fluctuation upper bound of the abnormal interference level; secondly, by setting blocking boundaries based on business security policies, with the final threshold set to the more stringent boundary. If the abnormal interference level exceeds the preset threshold, encryption parameter adjustments are triggered. The adjustment process involves resetting the encryption strength level, segment length, segment identifier binding depth, and rotation cycle.
[0065] The encryption strength level is determined based on the graded range of abnormal interference values. This graded range is defined by the security policy table and linked to the permission level. The segment length is adjusted to be shorter than the original segment length to improve positioning accuracy. The segment identifier binding depth is achieved by incorporating more metadata into the segment identifier input range, making replay and splicing more difficult to pass verification. The rotation cycle is adjusted to be shorter to compress the key exposure window. After adjustments are complete, the adjusted encryption block is output.
[0066] A complete verification is performed on the adjusted encryption block to determine the generated data integrity verification value. The complete verification is divided into segment-level verification and overall verification. Segment-level verification checks the consistency between the segment identifier and the segment content digest segment by segment, and verifies the binding relationship between the sequence identifier and the flight identifier. If any segment is inconsistent, the failed segment number is recorded and the reason for the verification failure is marked. Overall verification concatenates all segment identifiers in sequence and then calculates the overall digest value, which is compared with the overall digest value registered during the encryption block generation stage. If they match, the overall verification passes. The data integrity verification value is composed of the segment-level verification result summary identifier and the overall verification result summary identifier, and is bound to the flight identifier, version timestamp, and key parameter digest. The key parameter digest contains digest information such as segment length, key length, rotation cycle, and derivation factor update frequency.
[0067] Based on data integrity verification values, the system generates integrated records for dynamic layout adjustment verification and image verification. The generation of the dynamic layout adjustment verification record uses cabin number as an index, verifying the consistency between the latest status of the cabin occupancy status record and the cabin allocation details in the cabin information log. This verification includes checking for status conflicts, reversed update timestamps, and concurrent conflict operations within the same cabin. The number of conflicts is obtained by iterating through each record and comparing it to a conflict threshold, which is set as an unacceptable boundary by business rules and is also constrained by the upper bound of stable period samples. The generation of the image verification integration record uses structured data as an index, recombining the cabin number set, cabin boundary coordinate set, and area separation boundary set to obtain a reconstructed layout, and then verifying its consistency with the layout elements output by the identification process.
[0068] The consistency check includes counting the consistency of cabin number sets, counting the overlap ratio of boundary coordinates, and counting the continuity of region boundaries. The overlap ratio of boundary coordinates is calculated by discretizing the two sets of boundary coordinates to the same pixel grid, counting the ratio of overlapping pixels to the total number of pixels, and comparing this ratio to an overlap ratio threshold. This threshold is determined by the upper bound of the reconstruction error in the stable period samples, and is further incorporating the rendering engine's tolerance requirements for boundary approximation, ultimately resulting in a more stringent boundary. The continuity of region boundaries is counted by counting the number of broken segments at the dividing boundary and comparing this count to a breakage threshold, which is determined by the upper bound of line extraction at normal noise levels. These check results are bound to the data integrity verification value to form two types of integrated records, ensuring that each cabin entry simultaneously possesses both business status verification and image space verification conclusions.
[0069] Finally, the system prepares and generates international airline layout map messages and images by merging the dynamic layout adjustment verification integration records and image verification integration records. The message preparation and merging process uses the cabin class number as the primary key, merging spatial attributes from the extended layout data, allocation attributes from the cabin class information log, dynamic layout adjustment verification conclusions, and image verification conclusions. During the merging process, the priority of fields is clearly defined: spatial attributes are based on the structural data, allocation attributes are based on the cabin class information log, and verification conclusions are based on the integrated records.
[0070] After merging, the message generation process organizes data segments according to the international standard field order and hierarchical structure, arranging flight-level information, cabin segment-level information, and cabin class-level information in sequence, and marking the verification status of each cabin class entry. The image generation process renders the cabin area based on the cabin class boundary coordinate set, renders visual identifiers based on the occupancy status, and applies blocking markers to abnormal entries based on the verification conclusion, preventing abnormal entries from entering the publication state. After the message and image are generated, a terminal consistency check is performed. The check is completed through three consistency judgments: cabin class entry count, cabin class number set count, and area partition count. The threshold for these three judgments is set to complete consistency, and this threshold is determined based on the zero deviation requirement of the publication class output.
[0071] S3 includes obtaining a checksum from the encrypted data block, performing interference and anomaly judgment by comparing the checksum with a preset threshold, and determining the threshold matching verification result; if the threshold matching verification result does not match, the access control module is activated to attempt to isolate the illegal modification and obtain the isolated secure data stream; the isolated secure data stream is integrated with the cabin change tracking record, and a response strategy is executed to construct the process monitoring record; the control intervention data is integrated based on the process monitoring record to obtain the secure data stream used for layout diagram message and image generation.
[0072] In this implementation, this step is geared towards a multi-party collaborative data flow environment, establishing a data security control link with "verification value comparison" as the entry point, "permission isolation and handling" as the core, and "integrated process monitoring and control intervention" as the closed loop. This link begins with extracting the verification value from the encrypted data block. The verification value characterizes the content and structural state of the encrypted data block at the time of its generation. The extraction process is completed using fixed parsing rules: the system first unpacks the outer encapsulation fields of the encrypted data block, locates the field containing the verification value, and performs a length consistency check on the field boundaries, based on the field length in the encapsulation specification. When the field length is inconsistent with the encapsulation specification, the system directly determines that the encrypted data block has a structural anomaly, includes it in the anomaly interference count, and enters the subsequent isolation path. After the verification value extraction is completed, the system obtains a preset threshold and comparison rules in parallel. The preset threshold is used to define the upper bound of the verification value deviation within the acceptable range, and the comparison rules are used to define what kind of deviation is judged as an anomaly interference.
[0073] The determination of preset thresholds follows the principle of "stricter of historical baseline constraints and security policy constraints," forming a hierarchical threshold system. Historical baseline constraints are derived from normal sample statistics within a stable operating cycle. The system categorizes samples of the same machine type, version, packaging method, and collaborative link, and statistically analyzes the deviation distribution boundaries of verification values during normal flow. Deviation statistics are based on the comparison differences after repeatedly extracting verification values from the same encrypted data block at different nodes; the difference count is the number of inconsistencies, and the difference location is the number of inconsistent field positions. Security policy constraints stem from the business side's requirement for zero deviation in layout diagram releases and its tolerance boundary for unauthorized modifications. The security policy defines "content-level deviation" and "structural-level deviation" as unacceptable boundaries.
[0074] The maximum natural fluctuation boundary of the historical baseline is merged with the unacceptable boundary of the security policy, and the final threshold adopts the more stringent boundary. The determination of the threshold grading parameters is tied to the risk level, which is jointly determined by the number of collaborating nodes, the frequency of permission changes, and the density of recent abnormal events: the number of collaborating nodes is obtained from data flow records, the frequency of permission changes is obtained from permission control logs, and the density of abnormal events is obtained from the summary of the abnormal judgment results of the previous period. The higher the risk level, the more stringent the corresponding threshold, which is reflected in the reduced upper limit of the number of allowed inconsistencies, the reduced upper limit of the number of allowed inconsistent field positions, and the reduced upper limit of the number of allowed structural anomalies.
[0075] During the threshold matching verification process, after obtaining the checksum from the encrypted data block, the system calculates the "threshold matching verification result" according to a unified rule. This calculation process consists of three parts: The first part is the checksum consistency review. The system reconstructs the verification context based on the segment identifier, sequence identifier, and key metadata digest in the encrypted data block, and repeatedly extracts the checksum from the same context. The number of repeated extractions is determined by the security level, which is mapped from the risk level. The higher the risk level, the more repeated extractions are performed. The system counts whether all the checksums after repeated extraction are consistent, and the number of inconsistencies is used as the consistency deviation count. The second part is the cross-node consistency check. The system locates the checksum digest generated by the upstream node for the encrypted data block from the data flow record and compares it with the checksum digest extracted by the current node. The digest generation rule is given by the encapsulation specification, the digest length parameter is specified by the security baseline, and the number of digest inconsistencies is used as the cross-node deviation count. The third section is a structural integrity check. It performs counting checks on the segment count, segment sequence continuity, and segment identifier uniqueness of the encrypted data blocks. The segment count deviation is the absolute value of the segment count difference; the sequence continuity deviation is the sum of the number of missing segments and the number of duplicate segments; and the segment identifier uniqueness deviation is the number of duplicate identifiers. The system summarizes the consistency deviation count, cross-node deviation count, and structural deviation count according to risk weights to obtain the degree of abnormal interference.
[0076] Risk weight parameters are determined by risk level. Higher risk levels assign higher weights to structural deviations, cross-node deviations, and consistency deviations. The degree of abnormal interference is compared with a preset threshold to obtain a threshold matching verification result, which is either a match or a mismatch. The judgment boundary is defined by the threshold.
[0077] When the threshold matching verification result does not match, the system activates the access control module and attempts to isolate the unauthorized modification, outputting a secure data stream after isolation. The access control module is activated via an event-triggered mechanism. Triggering events include flight identifiers, encrypted data block identifiers, abnormal interference levels, trigger node identifiers, and trigger timestamps. The completeness of the trigger event fields is constrained by the event template, which is determined by the access control system configuration file. Isolation processing employs a tiered isolation strategy, with tiered parameters including session isolation level, subject isolation level, and data segment isolation level. The session isolation level is determined based on the session identifier in the data flow record and the session range at the time of the anomaly. The system calculates the set of data segments generated within the same session within a time window tracing back from the time of the anomaly. The time window parameter is obtained from the maximum propagation delay of the collaborative link and is constrained by the upper limit of the business release timeliness, ultimately taking the strictest boundary. The system then separates this set from the main data stream and transfers it to the isolation zone.
[0078] The isolation level of a subject is determined based on the operator's identity and permission level. The permission level is derived from the role level table in the permission control log. The system verifies the most recent permission change record associated with the operator who triggered the anomaly. If the permission change occurred within the backtracking window, the subject is marked as a high-risk subject, and subsequent requests are blocked. The isolation level of a data segment is determined based on the anomaly location results. Based on the missing number position, duplicate number position, and duplicate identifier position of the aforementioned structural integrity check output, the affected segment sequence number range is located, and the data segments within this range are stripped from the main data stream. After isolation, the secure data stream is formed by sequentially reassembling the data segments that were not stripped. The reassembly process includes segment sequence verification and segment identifier verification. If the verification fails, the batch of secure data streams is marked as unusable and prevented from entering the subsequent generation link, thus preventing untrusted data from participating in the layout diagram output.
[0079] After obtaining the isolated security data stream, the system integrates the isolated security data stream with cabin class change tracking records, executes response strategy construction, and generates process monitoring records. The integration of cabin class change tracking records uses flight identifier and cabin class number as the primary key and timestamp as the sorting key. The system aligns each cabin class entry in the isolated security data stream with the cabin class change tracking records, outputting three types of count results during the alignment process: The first type is a cabin class change coverage count, which checks whether a corresponding change link exists in the tracking record for the cabin class number appearing in the security data stream; if not, it is counted as missing. The second type is a change timing consistency count, which checks whether the last change timestamp in the tracking record is later than the update timestamp of the corresponding entry in the security data stream; if it is later, it is counted as a timing conflict. The third type is a source link consistency count, which checks whether the source node marked in the tracking record appears in the set of legitimate nodes in the data flow record; if not, it is counted as a link anomaly. These counts are used to construct the response strategy.
[0080] The response strategy is constructed using the anomaly type classification results as the entry point. The anomaly type is determined jointly by the aforementioned anomaly location results and counting results: structural fractures are prioritized as rearrangement or insertion risks; cross-node summary inconsistencies are prioritized as tampering risks; temporal conflicts are prioritized as replay risks; and source link anomalies are prioritized as forged node risks. Strategy parameters include the blocking scope, recovery path, review level, and notification recipients. The blocking scope is determined based on the set of affected cabins, which is obtained by the union of counts triggered by missing, conflicting, and abnormal links. The recovery path is determined based on upstream trusted nodes in the data flow record, which is determined by the set of nodes in the access control log that have no anomaly records in the recent period. The review level is determined based on the risk level; the higher the risk level, the higher the review level. The notification recipients are determined based on the responsibility chain in the access control system, which is provided by the organization's management configuration. Process monitoring records are generated synchronously during strategy construction. Monitoring record fields include the anomaly trigger point, anomaly type, anomaly interference level, isolation action set, affected cabin set size, strategy identifier, strategy effective timestamp, and execution result identifier.
[0081] After the process monitoring records are generated, the system integrates control intervention data based on these records and outputs a secure data flow for layout diagram message and image generation. The control intervention data originates from actual action receipts from the access control module. Receipt fields include blocking actions, isolation actions, recovery actions, review actions, and release actions. The integration process uses policy identifiers in the monitoring records as indexes, aligning receipt actions with policy definitions item by item. If a policy-defined action is not executed, it is marked as an execution gap; if an undefined action is executed, it is marked as an unauthorized action. Both execution gaps and unauthorized actions trigger secondary blocking, preventing the corresponding data batch from entering the layout diagram generation chain. After successful alignment, the system binds and encapsulates the control intervention data with the isolated secure data stream. The binding includes a secure data stream version identifier, an intervention action summary, an anomaly type summary, and an affected cabin set summary, ensuring that subsequent layout diagram message and image generation processes simultaneously obtain intervention conclusions and traceability evidence when receiving data.
[0082] After binding and encapsulation, the system performs terminal verification on the secure data flow. The verification includes three items: segment count continuity, cabin number set integrity, and policy effectiveness consistency. The criteria for these three verifications are set to be fully satisfied: segment counts must be continuous without breaks, cabin number set must be consistent with the isolated secure data flow, and policy effectiveness consistency must be consistent with monitoring records. After successful terminal verification, the secure data flow enters the layout diagram message and image generation process, ensuring that the generation link operates based on data that has completed anomaly detection, isolation handling, and monitoring record and intervention integration.
[0083] S4 includes extracting cabin information and cabin allocation details from the isolated security data stream; using a verification algorithm and a hash function to calculate data integrity to obtain the extracted cabin data group; fusing the extracted cabin data group with image recognition results to obtain coordinate positions and area boundary divisions to generate fused layout elements; verifying the fused layout elements against interactive environment requirements; if the verification results are met, determining the verified layout element group; constructing message data based on the verified layout element group to obtain the message-constructed data stream; and integrating image elements through the message-constructed data stream to output the layout diagram data group.
[0084] In this implementation, firstly, cabin class information and cabin allocation details are extracted from the isolated security data stream. Then, a hash function is used to verify data integrity using a verification algorithm to obtain the extracted cabin class data group. The extraction process is constrained by a data structure template, which includes fields such as flight identifier, cabin segment identifier, cabin number, cabin status, allocation details, update timestamp, source node, and isolation disposal identifier. The system segments and parses the isolated security data stream, locating field boundaries and performing type parsing according to the template field order. Fields that fail to parse trigger field missing counts and field anomaly counts. The count results are compared with the field missing threshold and field anomaly threshold to determine whether the batch proceeds to the next process.
[0085] The thresholds for missing and abnormal fields are determined by the strictest of two constraints: first, the list of required fields generated in the message, where missing required fields directly triggers blocking; second, the upper bound of anomalies from historical stable sample statistics, used to identify abnormal fluctuations. After field parsing, the system merges multiple records with the same cabin number, using timestamps as the primary merging rule. The record with the latest timestamp and a reliable isolation / disposal identifier is selected as the current valid record, while retaining preceding records for the same cabin as a traceability chain. If concurrent records with the same timestamp exist for the same cabin number, the system determines a unique valid record based on the source node priority and operator permission level. The source node priority is given by the collaboration link configuration list, and the operator permission level is given by the role level table in the permission control log. After merging, a set of cabin entries is formed. The system sorts the set of cabin entries, prioritizing cabin segment identifiers and then cabin number, generating a standardized data sequence after sorting.
[0086] During the integrity verification phase, the verification algorithm uses a hash function to calculate a digest value for the standardized data sequence and compares it with the reference digest value carried in the isolated secure data stream. If the digests match, the extracted data is determined to be complete and consistent, forming the extracted cabin data group. The digest calculation process includes determining serialization rules, digest parameters, and comparison rules. Serialization rules ensure consistency in calculation results across different nodes for the same batch of data. These rules include fixed field order, fixed field separators, normalized numeric fields, fixed timestamp precision, and fixed null value handling rules. Fixed field order is defined by the data structure template; fixed field separators are defined by the system security encapsulation specification; normalized numeric fields use a unified base and unified decimal place rules, constrained by both message and rendering specifications; fixed timestamp precision is constrained by a unified end-to-end clock specification; and fixed null value handling rules require missing fields to use a consistent placeholder method and be included in the digest calculation to avoid missing fields being ignored and causing digest collisions. The summary parameters include summary length and number of calculation rounds. The summary length is determined by the security baseline and collision risk requirements, while the number of calculation rounds is determined by the risk level. The risk level is derived from the previous anomaly isolation results and node risk profiles; the higher the risk level, the more calculation rounds are required. The comparison rules include full comparison and segmented comparison. Full comparison is used to determine overall consistency, while segmented comparison is used to locate inconsistencies. The segment length parameter is consistent with the length of the previous encrypted segments to achieve consistency location across steps. When full comparison fails or segmented comparison finds inconsistencies, the batch of data enters the blocking path and generates an anomaly flag.
[0087] After obtaining the extracted cabin class data set, the image recognition results of the extracted cabin class data set are used to obtain coordinate positions and area boundary divisions to generate fused layout elements. The image recognition results include at least the cabin class number index, cabin coordinate position, cabin boundary coordinate set, area boundary division identifier, area boundary coordinate set, recognition confidence, and recognition version timestamp. The fusion process uses the cabin class number as the primary key for alignment, traversing each cabin class entry in the extracted cabin class data set, retrieving the cabin class number with the same name from the image recognition result index, and completing the binding. After successful alignment, the coordinate position, cabin boundary coordinate set, area boundary division identifier, and area boundary coordinate set are merged into the cabin class entry to form the fused layout element entry. When alignment fails, the missing entries are counted and the missing ratio is calculated. The missing ratio is obtained by dividing the number of missing entries by the total number of cabin class entries. The missing ratio threshold is jointly constrained by the business release zero deviation requirement and the upper bound of the historical stable period missing ratio. The threshold is set to the stricter boundary. If the threshold is exceeded, generation is blocked and the process enters the review path. After successful alignment, a spatial consistency calculation is performed to confirm the rationality of the coordinates and boundaries. This calculation includes at least boundary closure count, boundary area validity count, and coordinate point consistency count. Boundary closure count checks the connection relationship between the first and last points of the cabin boundary coordinate set and counts the number of closure failures. The closure failure threshold is set to 0, based on the fact that single cabin area boundaries are structural elements and cannot be missing. Boundary area validity count calculates the area enclosed by the boundary and compares it with the minimum seat display area threshold, which is determined by the mapping relationship between the minimum seat size statistics in the aircraft configuration dictionary and image resolution. Coordinate point consistency count determines whether the cabin coordinate position falls within the corresponding cabin boundary area. The threshold for inconsistent point counts is set to 0, based on the fact that point deviation will directly lead to rendering misalignment.
[0088] Subsequently, the integrated layout elements are verified to meet the requirements in the interactive environment. If the verification result is satisfactory, the verified layout element group is determined. The interactive environment consists of a rule verification component, a permission constraint component, and a version consistency component. These three components perform compliance checks on the same element item separately. The rule verification component generates a rule base based on the layout diagram for verification. The rule base includes cabin boundary rules, cabin numbering rules, occupancy status rules, allocation details rules, and conflict constraint rules. The cabin segment boundary rule is used to verify that the boundary delineation identifier of the area to which the cabin belongs is consistent with the cabin segment identifier. For each cabin entry, its cabin segment identifier is compared with the area boundary delineation identifier, and the number of inconsistencies is counted. The inconsistency threshold is set to 0. The cabin numbering rule is used to verify that the numbering format is consistent with the aircraft configuration dictionary. The number of non-compliant numbers is set to a threshold of 0. The occupancy status rule is used to verify the logical consistency between the occupancy status and the allocation details. The system performs a legality matching on the combination of occupancy status and allocation identifier. The threshold for the number of illegal combinations is defined by the business rules as an unacceptable boundary. The conflict constraint rule is used to verify that there is no mutually exclusive allocation of the same cabin within the same time window. The time window length parameter is obtained by statistically analyzing the average interval of cabin status updates and is constrained by business timeliness requirements. The conflict number threshold is determined by the stricter of the historical stable period upper bound and the business strategy.
[0089] The permission constraint component verifies permissions based on the permission control policy, which includes the operator's permission level, the authorized scope of the operation type, the cabin sensitivity level, and the change approval link identifier. The system associates each cabin entry with its source node and operator identity, verifying whether its operation type falls within the authorized scope. The authorized scope parameter comes from the permission policy table. Simultaneously, it verifies the matching relationship between the cabin sensitivity level and the operator's permission level, with matching rules derived from the mapping relationship between the role level table and the sensitivity level table. The version consistency component verifies according to version timestamp alignment rules. The system compares the image recognition version timestamp with the latest update timestamp of the extracted cabin data group. The time difference parameter is obtained from the maximum synchronization delay of the collaborative link and is constrained by the business release timeliness limit. If the time difference exceeds the limit, the entry is blocked. After completing the verification of the three components, the system summarizes all cabin entries that pass verification into a verified layout element group, and outputs the failed entries as a blocking list with a failure reason identifier. The verified layout element group serves as the sole input for message construction.
[0090] After determining the verified layout element group, the system constructs message data based on the verified layout element group to obtain the message-constructed data stream. Message construction follows a message structure template, which defines the flight layer field set, cabin segment layer field set, cabin class layer field set, and field order. The system first generates flight layer segments. Flight layer fields are obtained by summarizing the flight identifier, version identifier, and verification identifier from the verified layout element group. The verification identifier summarization process uses the number of verified entries and the total number of entries to form a consistency status identifier, and includes a blocking list summary for auditing. Then, cabin segment layer segments are generated. The system groups cabin class entries according to cabin segment identifiers. Group counting is achieved by taking a unique value for the cabin segment identifier. The number of cabin segments is compared with the number of cabin segments in the aircraft configuration dictionary, and the difference threshold is set to 0. Finally, cabin class layer segments are generated. Cabin class entries are output by sorting the cabin class index. The output fields include cabin class number, occupancy status, allocation details identifier, coordinate location summary, boundary identifier summary, and verification conclusion identifier.
[0091] Coordinate location summaries and boundary identifier summaries are used to maintain a traceable association between the message and image elements. The summary generation rules are consistent with the aforementioned integrity summary rules to ensure consistency across stages. After construction, a post-construction data stream is formed, and it undergoes verification by counting complete fields, counting fields in sequence, and counting code table mappings. The verification thresholds are all set to be fully satisfied, based on the premise that the message is a structured output and structural deviations are not allowed to enter the publishing chain.
[0092] Finally, the image generation elements are integrated through the data stream after message construction to output the layout map data set. The integration of image generation elements uses the data stream after message construction as the main index, extracting the associated coordinate positions, cabin boundary coordinate sets, area boundary coordinate sets, occupancy status, and allocation detail identifiers for each cabin layer segment. The occupancy status and allocation details are then mapped to a set of display attributes. The display attribute set includes color identifiers, texture identifiers, text identifiers, icon identifiers, and boundary style identifiers. The mapping rules are derived from the rendering specification table, which is jointly determined by the display specifications of the digital tool and the business-side state semantic mapping.
[0093] Color identifier parameters are determined by a set of status categories, which are provided by a business code table library; texture identifier parameters are used to distinguish similar color states and avoid visual confusion, and are constrained by terminal display specifications and accessibility requirements; text identifier parameters are obtained by combining cabin number and key status phrases, and the phrase set is provided by business specifications; icon identifier parameters are obtained by mapping allocation detail identifiers, and the mapping table is provided by a business rule library; boundary style identifier parameters are jointly determined by area boundary division identifiers and cabin sensitivity levels, and are used to distinguish areas and sensitive cabins on the image.
[0094] After integration, the layout map data group simultaneously contains the data stream after message construction and the set of elements for image generation, along with consistency verification results. The system performs terminal consistency counting on the layout map data group. The counting content includes at least three items: consistency of cabin entry quantity, consistency of cabin number set, and consistency of area boundary set. The thresholds for all three items are set to complete consistency, based on the requirement that the layout map message and layout map image must express the same business status using the same cabin set and the same spatial partition. After the terminal consistency count passes, the layout map data group serves as the direct input for the subsequent generation and publication of layout map messages and layout map images, thereby achieving end-to-end verifiable generation from isolated secure data streams to a unified output data group.
[0095] S5 includes obtaining associated access control logs from a multi-party collaboration platform through layout map data groups, processing the access control logs using a comparison and analysis mechanism to obtain preliminary analysis results; integrating cabin layout fusion attributes based on the preliminary analysis results to determine whether there are any traces of illegal modification, thereby identifying a potential risk set; performing security data verification based on the potential risk set and image coordinate boundaries to obtain purification processing elements and generate an intermediate log group; and using the intermediate log group to integrate interactive verification requirements and message data to construct and output a purified access control log set.
[0096] In this implementation, firstly, the associated access control logs are obtained from the multi-party collaboration platform through the layout diagram data group. The association retrieval uses flight identifiers, data batch identifiers, layout version identifiers, participating node identifier sets, and generation timestamp intervals within the layout diagram data group as search criteria. The system initiates a log retrieval request to the multi-party collaboration platform and returns a candidate log set. Flight identifiers and data batch identifiers are directly derived from the metadata fields of the layout diagram data group; the layout version identifier is obtained by merging the identification version identifier and message construction version identifier within the layout diagram data group to avoid cross-version mixing; the participating node identifier set is obtained by taking a unique value from the source node field of the layout diagram data group; the generation timestamp interval is determined by the start and finish timestamps of the layout diagram data group, and a preset backtracking window is used to cover the delay propagation in the collaboration link. The backtracking window parameters are determined by the strictest of two types of constraints: one is the upper bound of the maximum inter-node propagation delay statistically analyzed during historical stable periods, and the other is the minimum requirement for audit coverage from the business side. Ultimately, a longer coverage range is chosen for the backtracking window to reduce omissions.
[0097] A field integrity check is performed on the candidate log set. The check items include operator identity, role, operation type, authorization identifier, approval chain, node identifier, timestamp, and object identifier fields. Field integrity thresholds are determined according to mandatory field rules, which are derived from the access control log specification list. If a mandatory field is missing, the log entry is marked as unusable and added to the missing field count. If the missing field count exceeds the upper limit, the batch cleanup process is terminated, and an anomaly cause identifier is output. The upper limit for missing fields is jointly determined by compliance requirements and the upper limit of missing fields during the stable period. Compliance requirements restrict the audit chain from having critical breakpoints, the upper limit of the stable period is used to identify abnormal fluctuations, and the final upper limit for missing fields is determined by the more stringent boundary.
[0098] After obtaining a usable set of access control logs, the system uses a comparison and analysis mechanism to process the logs and obtain preliminary analysis results. The comparison and analysis mechanism operates on time series alignment and rule matching. The system first groups the logs by flight identifier and data batch identifier, then sorts them by timestamp from earliest to latest, and simultaneously performs deduplication on duplicate logs with the same timestamp and completely identical field content. Deduplication is determined based on the consistency of five combinations: operator identity, node identifier, operation type, object identifier, and authorization identifier. After sorting, the system performs permission consistency comparison, authorization scope comparison, approval chain continuity comparison, anomaly frequency comparison, and node legality comparison on the log chain. Permission consistency comparison uses the role field and operation type field as input. Based on the role permission mapping table, it determines whether the role has the corresponding operation type permission. The mapping table parameters are from the permission policy library, which is maintained and approved by the system deployment party. Inconsistencies are counted in the permission conflict count, with the permission conflict threshold set to 0, based on the assumption that permission conflicts directly point to unauthorized access risks. The authorization scope comparison takes the authorization identifier field and the object identifier field as input. The system verifies whether the authorization covers the object according to the authorization scope table. The parameters of the authorization scope table are defined by the business resource domain and associated with the role level table. The number of times the authorization is not covered is included in the authorization gap count, and the authorization gap threshold is set to 0.
[0099] The approval link continuity comparison uses the approval link field as input. The system checks whether the operation type requiring approval has a corresponding approval start point, approval node, and approval conclusion node, and counts the number of missing nodes. The missing node threshold is determined by the operation type approval rule table. The approval rule table sets full-link integrity requirements for high-sensitivity operations and partial link requirements for low-sensitivity operations. The rule table takes precedence. The anomaly frequency comparison uses the number of operations performed by the same operator within a time window as input. The system counts the number of operations and compares it with the frequency threshold. The time window parameter is jointly determined by the session cycle of the collaboration platform and the business change density, taking the window length that covers a complete change session. The frequency threshold is determined by the upper limit of the average number of operations performed by the same role during historical stable periods, and is stricter than the upper limit of the anti-fraud policy in the security strategy.
[0100] The node legitimacy comparison uses the node identifier field as input to verify whether the node identifier exists in the list of legitimate nodes. The list of legitimate nodes is generated by the access registration form of the multi-party collaboration platform and is subject to permission approval. The number of times a node does not exist is counted as an illegal node, and the threshold for illegal nodes is set to 0. The system summarizes the permission conflict count, authorization gap count, approval missing count, anomaly frequency count, and illegal node count to form a preliminary analysis result. The preliminary analysis result includes a set of anomaly types, a set of anomaly subjects, a set of anomaly nodes, a set of anomaly time windows, and a set of anomaly objects, and includes a location index for each type of count.
[0101] After generating preliminary analysis results, the system integrates cabin layout fusion attributes to determine if there are any traces of unauthorized modifications, thereby identifying potential risk sets. Cabin layout fusion attributes are derived from the layout map data set and include at least the following: cabin number set, cabin status set, cabin allocation details set, cabin coordinate location set, cabin boundary coordinate set, area boundary division identifier set, verification conclusion identifier set, and message construction audit field set. The fusion process first completes object mapping. The system matches abnormal object identifiers from the preliminary analysis results with cabin numbers or area boundary identifiers from the layout map data set. The matching rules are determined based on the object identifier coding standard, which is defined by the collaboration platform's resource domain. After successful object mapping, time mapping is completed. The system performs an intersection check between the abnormal time window and the cabin entry update timestamp. The intersection check uses time interval overlap counting, and the number of overlaps is used as the time association count.
[0102] Simultaneously, the system completes subject mapping, matching the abnormal subject with the source operator identity recorded in the layout diagram data group. The number of successful matches is used as the subject association count. The system then performs illegal modification trace determination, based on three types of consistency: authorization link consistency, data change consistency, and spatial change consistency. Authorization link consistency is checked by verifying whether the operation corresponding to the abnormal subject has authorization identifiers and approval links; if not, it is marked as a missing link. Data change consistency is checked by verifying whether the cabin status or allocation details of the layout diagram data group have changed within the abnormal time window; changes are counted by comparing before and after versions, and the number of changes is used as the change count. Spatial change consistency is checked by verifying whether the abnormal object corresponds to cabin boundary or area boundary elements; if so, it further verifies whether the boundary coordinates have changed; boundary changes are counted by comparing the boundary coordinate set summary.
[0103] The process combines missing link markers with change counts and boundary change counts to determine potential risks. Entries that satisfy both missing link and change conditions are added to the potential risk set. Each potential risk set entry must include at least the anomaly subject, anomaly node, anomaly object, a set of associated cabins, a set of associated area boundaries, an anomaly time window, anomaly type, and risk level. The risk level parameter is determined by the anomaly type weight and the scope of impact. The anomaly type weight is given by the safety policy table, and the scope of impact is obtained by counting the number of associated cabins and associated areas; the greater the number of associated areas, the higher the risk level.
[0104] After identifying the potential risk set, the system performs safety data verification based on the potential risk set and image coordinate boundaries, and generates an intermediate log set by obtaining purification processing elements. Safety data verification uses the image coordinate boundaries in the layout map data set as objective constraints to perform spatial consistency and state consistency verification on the cabins and areas involved in the potential risk set. Spatial consistency verification first maps the cabin numbers in the potential risk set to the cabin boundary coordinate set, verifying boundary closure and boundary area validity. The threshold for the number of closure failures is set to 0, and the area threshold is obtained by mapping the minimum seat display area of the aircraft model. Simultaneously, continuity verification is performed on the area boundaries, which is completed by counting broken segments. The broken segment threshold is determined by the stricter of the upper limit of noise broken segments in the historical stable period and the rendering specification requirements.
[0105] The status consistency verification takes cabin status and allocation details as input, comparing the operation type declared in the access control log with the data change type. The system maps the operation type to a set of allowed changes. The allowed change set parameter comes from a joint mapping table of the access control policy library and the business rule library. The number of times a change type is not in the allowed set is counted as an inconsistency count, and the inconsistency threshold is set to 0. After the verification is completed, the system generates purification elements. The purification elements include at least the following: the log entry index set to be removed, the log entry index set to be retained, the log entry index set to be downgraded, the log entry index set to trigger review, and the corresponding risk reason identifier.
[0106] The criteria for removal are the coexistence of missing links and failed verification; the criteria for retention are complete links and passed verification; the criteria for demotion are complete links but excessive anomaly frequency; and the criteria for review are spatial verification boundary values close to the threshold or insufficient temporal correlation counts. The aforementioned index set is used to reorganize the original access control logs into intermediate log groups. The intermediate log group generation process includes filtering by index, rearranging by time, merging by subject, and tagging by policy. Merging by subject uses the operator's identity as the primary key, merging consecutive operations of the same subject into operation fragments. The fragment boundaries are determined by a time interval threshold, which is determined by the upper bound of the maximum interval between consecutive operations of the same subject during a historical stable period and is subject to stricter constraints based on the session cycle. The policy tagging appends the conclusion identifiers for removal, demotion, review, and retention to the corresponding log entries.
[0107] After generating the intermediate log group, the system integrates the interactive verification requirements and message data construction using the intermediate log group, outputting a cleaned permission log set. The interactive verification requirements originate from the preceding layout element verification stage and include rule verification conclusions, permission verification conclusions, version consistency conclusions, and blocking list summaries. Using the cabin number and time window as indexes, the system aligns the operation fragments in the intermediate log group with the interactive verification conclusions, forming an "operation fragment—verification conclusion" binding relationship. The alignment process calculates coverage, which is the number of bound fragments divided by the total number of operation fragments. The coverage threshold is determined by the compliance audit integrity requirements and is stricter than the lower bound of the stable period coverage rate. Message data construction and integration uses the message construction audit field as the entry point. The system verifies the consistency of key version identifiers, key node identifiers, and key timestamps used during message construction with the corresponding nodes and times in the intermediate log group. Consistency verification is based on the number of inconsistencies, with the inconsistency threshold set to 0. After integration, the purified permission log set is output. The purified permission log set includes purified log entries, operation fragment summaries, subject risk level, node risk level, association index with layout diagram data group, binding index with interaction verification conclusion, and consistency conclusion with message construction audit field.
[0108] S6 includes implementing AES encryption on the layout data group using a cleaned log set to obtain a pre-encapsulated data group; injecting a preset interference simulation signal sequence into the tool update process using the pre-encapsulated data group to determine the ability of the encapsulated data to resist abnormal interference, thereby obtaining a verification result set; integrating a preset cabin permission mapping verification table into the verification result set to identify potential vulnerability points and generate a reinforcement strategy group; integrating the backup message paths of international airline layouts based on the reinforcement strategy group to obtain an intermediate packet containing image messages and layout image; constructing a preset boundary verification mechanism from the intermediate packet and outputting a reinforced data packet.
[0109] In this implementation, firstly, a symmetric encryption algorithm is applied to the layout data group using a cleaned log set to obtain a preliminary encapsulated data group. The implementation process unfolds along the main lines of "batch association, field standardization, serialization, segmentation, encryption, and summary binding." The system uses flight identifier, data batch identifier, and layout version identifier as association primary keys to associate and assemble the cleaned log set with the layout data group. The calculation process of association assembly involves performing a consistency comparison between the log batch identifier in the cleaned log set and the batch identifier in the layout data group, and cross-verifying the main risk identifier, node risk identifier, and approval link summary in the cleaned log set with the source node set and interaction verification conclusion summary in the layout data group. Only after the verification is passed will the data be encapsulated. The field standardization process unifies the field order, field type, timestamp precision, and null value handling method for the message element set and image element set of the layout data group according to the encapsulation template requirements. The encapsulation template is determined by the system's built-in versioning specification file, and the version number is bound to the layout version identifier to avoid cross-version field mismatches.
[0110] The serialization process concatenates standardized fields into a continuous byte sequence according to the encapsulation template. During concatenation, normalization is performed on numeric fields, precision pruning is performed on timestamp fields, and enumeration mapping is performed on boolean fields. The mapping table is derived from the business code table library and referenced in the encapsulation template. The segmentation process divides the continuous byte sequence into multiple data segments. The segment length parameter is jointly determined by the throughput stability range of encryption processing and the anomaly location granularity requirements: the system statistically analyzes the average processing latency and peak latency under different segment lengths during historical stable periods, and selects the minimum segment length that meets the latency upper limit as the performance lower limit; at the same time, a minimum locatable unit is set according to the anomaly location requirements. The minimum locatable unit is determined by audit requirements and fault playback experience, requiring that when a single segment is affected, it can be located at the cabin level. Finally, the segment length is a value that does not exceed the performance lower limit and meets the location granularity.
[0111] The encryption process uses a unified key and a unified block mode to encrypt each segment, and generates a segment number and a segment digest for each segment. The segment number is used for reassembly and rearrangement detection, and the segment digest is used for segment-level integrity verification. The segment digest length parameter is determined by collision risk control requirements, which are derived from a security baseline. The security baseline is determined based on the business sensitivity level and compliance constraints. Key-related parameters include at least the key length, key rotation cycle, random vector length, padding rules, and derivation factor update frequency. The key length parameter is determined based on the security level, which is calculated by combining the cabin sensitivity level, the number of cooperating nodes, and the density of recent abnormal events. The cabin sensitivity level is derived from the preset cabin permission mapping verification table, the number of cooperating nodes is obtained by counting the source node set, and the density of abnormal events is obtained by dividing the number of interference judgments in the previous period by the number of processing batches. The higher the security level, the longer the key length. The key rotation cycle is constrained by the key exposure window requirements and the business processing throughput. The processing time of a single batch and the maximum number of concurrent batches during the historical stable period are statistically analyzed to give the shortest rotation cycle without reducing throughput. At the same time, the upper limit of the rotation cycle is compressed to an acceptable range according to the security policy, and the shorter rotation cycle is finally selected.
[0112] The length of the random vector is determined by the security requirements of the block pattern and is linked to the key length; the padding rule is determined by the block length requirements and is fixed as part of the encapsulation template; the derivation factor update frequency is determined by the risk level, which is derived from the comprehensive score of the subject risk identifier and the node risk identifier in the cleaned log set. The score is calculated as a weighted sum of the number of high-risk subjects and the number of low-trust nodes, and the weights of high-risk subjects and low-trust nodes are given by the security policy table. After encryption, the encrypted payload, segment sequence number sequence, segment digest sequence, overall digest, encapsulation version number, and log digest binding information are combined to form a preliminary data set. The overall digest is calculated from the segment digests concatenated in segment sequence number order and is used for overall integrity verification.
[0113] Secondly, by introducing a pre-set interference simulation signal sequence into the tool update phase using the initial data set, the ability of the encapsulated data to resist abnormal interference is assessed, and a verification result set is obtained. The tool update phase refers to the operational stage where digital tools or multi-party collaboration platforms undergo version updates, interface rule changes, rendering specification adjustments, and permission policy adjustments. This stage is prone to structural drift and link jitter. The design of the pre-set interference simulation signal sequence is based on the principle of "covering common interference types, covering key field locations, and covering multiple intensity gradients." The sequence generation process manifests as performing controlled perturbations on the initial data set. The perturbation types include at least segment truncation perturbation, segment insertion perturbation, segment rearrangement perturbation, segment repetition perturbation, timestamp drift perturbation, permission digest forgery perturbation, version number mismatch perturbation, and field boundary perturbation. Each type of perturbation is configured with intensity parameters and effective range parameters: the intensity parameter is characterized by the perturbation ratio or the number of perturbations, and the effective range parameter is characterized by the affected segment sequence number range.
[0114] The perturbation ratio threshold and perturbation number threshold are determined by stringent consideration of two types of boundaries: one type of boundary is derived from the upper bound of natural noise fluctuations during historical stable periods, used to ensure that the simulated signal covers the risk range outside of natural fluctuations; the other type of boundary is derived from the worst-case requirements of the security policy's attack surface assumptions, used to ensure that the simulated signal covers the high-risk intensity range, and the final threshold is set to the larger coverage range. The system generates multiple perturbation samples for each type of perturbation according to the intensity gradient. The gradient number parameter is determined by the verification coverage requirement, which is specified by the testing strategy as achieving sufficient risk coverage within a limited time.
[0115] The verification channel performs structural verification, digest verification, log binding verification, permission mapping verification, and recovery capability verification on each perturbation sample. Structural verification calculates the continuity of segment sequence numbers, the consistency of the number of segments, and the consistency of the length of the encapsulation header fields. Continuity is obtained by counting the number of missing and duplicate numbers; the consistency of the number of segments is obtained by comparing the number of encrypted payload segments with the cardinality of the segment sequence number set; and the consistency of field length is obtained by counting the difference between the length of the encapsulation template and the actual length. Digest verification calculates the consistency between the segment digest comparison and the overall digest comparison; the number of inconsistencies is used as a digest failure count. Log binding verification calculates the consistency of the bound fields between the cleaned log digest and the preliminary data group log digest; the number of inconsistencies is used as a binding failure count. Permission mapping verification calculates whether sensitive operations meet the constraints of the existence of the approval link digest and the subject's risk level; the number of violations is used as a permission failure count. Recovery capability verification calculates whether the affected segment can be located and its output blocked after a perturbation is detected. The location success rate is obtained by dividing the number of successful locations by the number of perturbation samples, and the blocking accuracy rate is obtained by comparing the number of blocking attempts with the number of attempts that should have been blocked. The above verification results are summarized to form a verification result set, which includes the pass conclusion, failure segment number range, failure type identifier, location success rate, blocking accuracy rate, and risk level for each type of disturbance. The pass threshold is determined based on the principle of "direct blocking for zero-tolerance items and strict adherence to the baseline for statistical items": the field length consistency failure count threshold in structural verification is set to 0, the summary verification failure count threshold is set to 0, and the log binding failure count threshold is set to 0; the location success rate threshold and the blocking accuracy rate threshold are jointly determined by the historical stable period baseline and security policy requirements.
[0116] Subsequently, the verification results were integrated with a pre-defined cabin permission mapping verification table to identify potential vulnerabilities and generate reinforcement strategy groups. The pre-defined cabin permission mapping verification table serves as a verification benchmark that establishes constraints on cabin sensitivity levels, operation types, role levels, approval chain requirements, node trust levels, and data item impact scope. The parameters of this verification table are determined from a summary of permission policy libraries, business rule libraries, and compliance requirements: cabin sensitivity levels are given by the business's risk classification of cabin categories and associated with aircraft type cabin segments; the set of operation types is given by the operation enumeration supported by the collaboration platform and confirmed by the business; role levels are given by the role level table of the permission system; approval chain requirements are given by the compliance process configuration; and node trust levels are obtained from node access audits and historical anomaly density statistics. Anomaly density is calculated by dividing the number of times a node triggers anomalies by the number of batches the node participates in; higher anomaly density results in a lower trust level.
[0117] The fusion judgment process uses the failure type and disturbance type identifiers in the verification result set as entry points, mapping them to constraint items in the verification table to calculate the "constraint violation degree". The constraint violation degree is calculated by counting the number of highly sensitive constraints and the number of missing link constraints triggered for each failed sample, and combining this with the impact range count to form a risk score. The impact range count is obtained by counting the number of affected cabins and the number of affected area boundaries. Samples with risk scores reaching the high-risk threshold are clustered as potential vulnerability points. The determination of the high-risk threshold also adopts a stricter double-boundary approach: on the one hand, the highest risk score during historical stable periods under conditions without real attacks is used as a natural upper bound; on the other hand, according to the security policy, triggering highly sensitive constraints is considered a high-risk boundary, and the final threshold adopts the stricter boundary. The system generates reinforcement strategy groups according to vulnerability point type. Each reinforcement strategy group at least covers encryption encapsulation enhancement strategies, digest binding enhancement strategies, segmentation and reassembly constraint enhancement strategies, permission link binding enhancement strategies, node trust constraint enhancement strategies, backup path switching strategies, and boundary verification enhancement strategies.
[0118] The determination logic of each strategy parameter corresponds one-to-one with the vulnerability type: If the vulnerability is concentrated in segment rearrangement and segment insertion, the segment length is adjusted to be shorter and the segment sequence number verification strength is increased. The segment sequence number verification strength is achieved by introducing stricter continuity and repetition judgments. If the vulnerability is concentrated in digest collision or digest mismatch, the digest length is increased and multiple layers of digest binding are added. The increased binding layers are jointly constrained by the encapsulation template version number and the log digest binding field. If the vulnerability is concentrated in permission link forgery, the binding depth between the approval link digest and the subject risk identifier is increased. The binding depth is achieved by including more approval node digests in the binding scope, while shrinking the set of executable operations for low-trust nodes. The shrinkage rule is given by the node trust level constraint item in the verification table. If the vulnerability is concentrated in version mismatch caused by tool updates, the version consistency verification threshold is tightened, and the backup path switching condition is bound to the version mismatch trigger condition. The version mismatch trigger condition is jointly determined by the timestamp difference count and the version number inconsistency count.
[0119] After the reinforcement strategy group is determined, an intermediate packet containing image messages and layout diagrams is obtained based on the backup message paths integrated by the reinforcement strategy group for international airlines. The backup message paths are constructed with "consistent field structure, consistent parsing rules, and consistent semantic expression" as constraints, and form mutually substitutable output channels with the main path. Path template parameters include path identifier, field set, field order, list of required fields, list of validation fields, image element referencing method, and risk identifier carrying method.
[0120] The system determines whether to enable the backup path based on the path switching strategy in the reinforcement strategy group. The input for the switching strategy is derived from the verification result set and the vulnerability point set. The decision process calculates the "switching trigger flag," which is jointly determined by the existence of high-risk vulnerability points, the existence of version mismatch, and the existence of a decrease in node trust level. If any one of these conditions is met, the switch is triggered. After enabling the backup path, the system performs path reorganization on the layout data group: message elements are rearranged according to the backup template field order, image elements are organized into rendering input fragments according to the reference method of the backup template, and the risk identifier summary, policy identifier summary, and cleanup log summary binding information are included in the packet header.
[0121] The intermediate package structure includes at least the main path encrypted payload segment, the backup path encrypted payload segment, the path selection identifier segment, the boundary verification configuration segment, and the audit digest segment. The parameters of the path selection identifier segment are determined by the node capabilities, which are determined by the node resolution capability table registered on the collaboration platform. If the target node does not support backup path resolution, the path selection identifier is fixed as the main path; otherwise, the backup path is selected first according to the risk level.
[0122] Finally, a pre-defined boundary verification mechanism is constructed from the intermediate packet body, and an enhanced data packet is output. This pre-defined boundary verification mechanism establishes inviolable judgment rules for the structure, semantics, and permissions of the enhanced data packet, enabling it to autonomously detect drift and trigger blocking during cross-node flow. The structure boundary verification checks the number of segments, segment order, segment digest consistency, and the length of the encapsulation header field. The verification calculations are: segment number difference count, number of missing numbers count, number of duplicate numbers count, number of inconsistent segment digest count, and field length difference count. All difference count thresholds are set to 0.
[0123] Semantic boundary verification verifies the set of cabin number, cabin segment partition identifier, cabin status, and region boundary index. Verification calculation is achieved by counting the number of differences between these sets, with a threshold of 0. Simultaneously, timestamp differences are counted for verification, with the upper limit determined by the strictest combination of the maximum synchronization delay statistics of the collaborative link and the upper limit of business release timeliness. Permission boundary verification verifies the consistency of cleanup log summary binding, the consistency of subject risk identifiers, the completeness of approval link summaries, and the satisfaction of node trust level constraints. Verification calculations include counting the number of binding inconsistencies, the number of risk identifier inconsistencies, the number of missing approval nodes, and the number of constraint violations, all with a threshold of 0.
[0124] The boundary verification mechanism's configuration parameters are bound to the encapsulation template version number. Changes in the version number trigger a synchronous update of the boundary configuration, and a configuration digest is carried in the boundary verification configuration section of the intermediate packet, enabling receiving nodes to verify the consistency of their own verification rules using the configuration digest. A full boundary verification is performed locally on the intermediate packet. After successful verification, the intermediate packet and the boundary verification result digest are bound and encapsulated to form a reinforced data packet. The reinforced data packet carries a path selection identifier, audit digest, policy digest, and boundary verification digest, enabling subsequent nodes to perform rapid consistency checks before decapsulation. Furthermore, if any boundary violation is detected, the entry into the layout diagram message and layout diagram image generation and release chain is directly blocked.
[0125] S7 includes using enhanced data packets to obtain qualified data packets through a preset sequence injection verification algorithm during data flow testing; distributing qualified data packets to system interaction nodes to obtain node feedback sets; merging and summarizing the node feedback sets to determine the final integrity confirmation report; extracting cabin information update instructions from the final integrity confirmation report, determining whether the instruction execution verification algorithm meets preset standards to obtain results; obtaining the results to generate international airline layout map messages and layout map images, and constructing the release path.
[0126] In this implementation, firstly, the system uses a pre-defined sequence injection verification algorithm to obtain qualified data packets during data flow testing, employing enhanced data packets. After the enhanced data packets enter the test channel, the system selects the corresponding pre-defined sequence according to the test strategy. The pre-defined sequence describes the processing order, state switching order, and anomaly triggering order of the enhanced data packets in the actual transmission link. The determination of the pre-defined sequence is based on node topology, link length, and risk level as inputs: the node topology is provided by the system's interactive node registry; the link length is obtained from the node hop count statistics in the routing table; the risk level is calculated jointly by the anomaly event density of the previous period, the node trust level distribution, and the permission change frequency; the anomaly event density is the number of anomaly triggers divided by the number of processing batches; the node trust level distribution is obtained from the proportion of low-trust nodes; and the permission change frequency is the number of permission change records divided by the time window length.
[0127] The above inputs are mapped to corresponding sequence templates in a preset sequence library. Each sequence template includes parameters for sequence length, number of injection points, set of injection types, and intensity gradient. The sequence length parameter increases with link length and the number of nodes; the number of injection points increases with risk level; the set of injection types covers structural disturbances, semantic drift, permission binding offsets, and path switching mismatches; and the intensity gradient parameter covers multiple intensity ranges from natural fluctuation boundaries to the worst-case boundary of security policies.
[0128] The implementation process of the preset sequence injection verification algorithm proceeds in layers, from rapid judgment to deep verification. First, the encapsulation header consistency is verified on the enhanced data packet. Verification items include the field length and format of the data packet identifier, version identifier, path selection identifier, boundary check digest, audit digest, and policy digest. These field length and format parameters are determined by the encapsulation template. If any field fails to meet the template requirements, a structural anomaly is determined, and subsequent steps are halted. After the structural verification passes, the system performs boundary check mechanism verification, which proceeds in the order of structural boundary, semantic boundary, and permission boundary. Structural boundary verification is completed through segment count, segment sequence number continuity count, duplicate segment count, and segment digest consistency count. The segment count is the cardinality of the segment sequence number set; the continuity count is the sum of the number of missing and duplicate numbers; the duplicate segment count is the number of times the segment digest is repeated; and the segment digest consistency count is the number of times the segment digest is inconsistent.
[0129] The threshold parameters for the above counting are set to the "zero deviation" boundary. The threshold is determined based on the fact that the enhanced data packet is a critical payload before release, and structural deviations will lead to downstream unpacking failures or mismatch risks, thus not falling within the fault tolerance range. Semantic boundary verification performs set consistency comparison on the set of cabin number, cabin segment partition, cabin status, and region boundary index. Set consistency comparison is completed by counting the number of difference sets, with a threshold of 0 for the number of difference sets, based on the fact that semantic deviations directly lead to inconsistencies between message and image representations. Permission boundary verification verifies the consistency of cleanup log summary binding, subject risk identifier consistency, approval link summary integrity, and node trust level constraint satisfaction. Verification is completed by counting the number of inconsistencies and missing data, with thresholds for both the number of inconsistencies and missing data being set to 0, based on the fact that permission boundaries are critical constraints of the security closed loop, and authorization link breaks are not allowed.
[0130] After boundary verification, the injection steps are executed according to a preset sequence. At each injection point, a controlled perturbation is applied to the enhanced data packet, and the above verification is re-executed to verify the self-verification and blocking capabilities of the enhanced data packet under perturbation scenarios. The type and intensity of the injected perturbation are given by the sequence template. The upper bound of the perturbation intensity is determined by the worst-case boundary of the security policy, and the lower bound of the perturbation intensity is determined by the upper bound of natural fluctuations during the historical stable period. The system verifies multiple intensity levels within this range. For each intensity level, the system records the verification results and failed location, and calculates the location success rate and blocking accuracy rate. The location success rate is the number of times the affected segment was successfully located divided by the number of injected samples. The blocking accuracy rate is the number of times the sample that should be blocked was actually blocked divided by the number of times it should be blocked. The location success rate threshold and the blocking accuracy rate threshold are determined by the stricter of two types of constraints: one type of constraint comes from the coverage requirements of the security policy on the publishing link, and the other type of constraint comes from the baseline capability lower limit during the historical stable period. The final threshold is the more stringent boundary. Enhanced data packets that meet all zero-bias thresholds and whose location success rate and blocking accuracy rate reach the threshold boundaries are marked as valid data packets.
[0131] After a valid data packet is generated, it is distributed to system interaction nodes, and a node feedback set is obtained. The node set is determined based on the node routing table and capability registration table. The node routing table provides a list of nodes that must be covered, and the capability registration table provides the node's parsing capabilities for the primary and backup paths. The system sorts the node set according to the following priority order: critical path nodes, external interface nodes, and low-trust nodes. Prioritizing critical path nodes ensures that core links are verified first; prioritizing external interface nodes exposes external compatibility issues as early as possible; and prioritizing low-trust nodes exposes parsing deviations in high-risk environments in advance. The distribution process generates a distribution task for each node. The task includes a data packet identifier, version identifier, path selection identifier, boundary check summary, expected feedback field list, and feedback timeout boundary. The feedback timeout boundary parameter is determined by the node's historical response latency statistics and the upper limit of business release timeliness. The upper limit of the node's response latency distribution during the stable period is calculated, and a stricter boundary is taken between this and the business upper limit. After receiving the data packet, the node performs a local pre-check, which includes boundary check summary consistency verification and version identifier consistency verification. After passing the pre-check, the node enters the unpacking and parsing process.
[0132] The node parsing process performs structural analysis and field validation on the message payload, constructs rendering inputs and verifies boundaries on the image element payload, and returns the validation conclusions, parsing conclusions, rendering conclusions, and interface interaction conclusions according to the feedback field list. The system summarizes the feedback from each node to form a node feedback set, and counts the missing feedback nodes. The missing count threshold is determined by the critical node coverage requirements. Missing critical nodes are directly judged as failing, while missing non-critical nodes trigger a fallback path evaluation.
[0133] Subsequently, the node feedback sets are merged and aggregated to determine the final integrity confirmation report. The merging and aggregation process uses the packet identifier as the primary key to merge feedback and performs consistency comparisons on multi-node conclusions for the same verification item, generating a list of passed conclusions and conflict lists. Consistency comparison is completed through counting; the system counts the number of passed nodes, the number of failed nodes, and the number of timeout nodes, and calculates the pass rate, which is the number of passed nodes divided by the number of nodes that should have provided feedback. The pass rate threshold is jointly determined by node type weighting requirements and business release strategies: key nodes have high weight, external interface nodes have high weight, and low-trust nodes have high weight. The pass rate calculation incurs a greater penalty for high-weight nodes failing; the business release strategy uses the full pass of key nodes as a mandatory boundary. The system also clusters the failure reasons based on failure type identifiers and failure location indexes, categorizing failures into structural failures, semantic failures, permission failures, path failures, and performance timeout failures. The number of each type of failure is counted, and the failure percentage is calculated. The failure percentage is used for risk level calculation.
[0134] Risk level calculation is based on the failure rate and failure type weights, with weights derived from the security policy table. Permission failures and structural failures have high weights, followed by semantic failures, and then path failures and timeout failures. The final integrity verification report includes an overall data packet conclusion, a list of nodes that passed, a list of nodes that failed, a list of nodes that timed out, a conflict list, a failure type distribution, a risk level, a recommended path selection conclusion, a fallback path conclusion, an audit summary, and an evidence index. The evidence index is compiled from the location indexes reported by each node.
[0135] After the final integrity confirmation report is generated, the system extracts the cabin information update instruction from the report and determines whether the instruction execution verification algorithm meets the preset standards to obtain the result. Instruction extraction is predicated on the conclusions passed and the recommended path selection conclusions in the report. The system only generates instructions when the overall conclusions are passed and the key nodes meet the requirements through the checklist. The field set of the cabin information update instruction includes flight identifier, cabin set, update type, update effective time, version identifier, path identifier, rollback identifier, approval summary, and risk level summary. The cabin set is determined by the cabin number set corresponding to the verified layout element group. The update type is jointly determined by the status change identifier and allocation detail change identifier in the layout data group. The effective time is determined by the business scheduling window and is constrained by the flight operation schedule, which is provided by the flight scheduling system's planning data.
[0136] The preset standards for the instruction execution verification algorithm consist of field integrity standards, permission compliance standards, timeliness consistency standards, conflict avoidance standards, and passenger impact avoidance standards. The field integrity standard is based on a list of required fields, with a threshold of 0 for the number of missing required fields. The permission compliance standard is based on the approval chain summary and role level constraints in the cleaned permission log set, with a threshold of 0 for the number of unauthorized accesses. The timeliness consistency standard uses the difference between the effective time and the current system time as input. The lower and upper bounds of the time difference are determined by the business release strategy. The lower bound is used to avoid synchronization failures due to overly close effectiveness, and the upper bound is used to avoid state drift due to overly distant effectiveness. The boundary is taken from the value given by the business strategy and the upper bound of the historical synchronization delay is strict. The conflict avoidance standard verifies whether there are mutually exclusive instructions for the same flight and cabin class within the effective window, with a mutual exclusion threshold of 0. The set of mutually exclusive instructions is obtained from the instruction queue of the scheduling system. The passenger impact avoidance standard verifies the overlap between the estimated number of affected passengers and the set of affected seats. The estimated number of affected passengers is obtained from the reservation mapping table of the scheduling system, and the overlap is obtained by counting the intersection of the instruction cabin class set and the allocated passenger seat set.
[0137] The thresholds for the number of affected passengers and the overlap threshold are jointly determined by the business service commitment and the upper limit of remedial costs. The thresholds for critical cabin segments are more stringent, while those for ordinary cabin segments are relatively lenient. The specific thresholds are given by the cabin class sensitivity level mapping table. The system verifies each of the above standards and outputs the verification results, which include a pass conclusion, a list of failures, failure reason identifiers, and suggested handling strategy identifiers.
[0138] Finally, based on the verification results, the system generates international airline layout map messages and images, and constructs the release path. The inputs for the generation stage are verified data packets, a final integrity confirmation report, and command verification results. The system enters the release state for generation when the command verification result is passed. During the generation process, the system determines the primary or backup path as the output channel based on the suggested path selection conclusion, and extracts the message payload from the data packets according to the message template. It then performs field order verification, code table mapping verification, and verification summary verification, with all verification thresholds set to zero deviation boundaries. For image generation, the system extracts the image element payload from the data packets, constructs rendering input based on coordinate boundaries and display attributes, and performs boundary closure verification, landing point consistency verification, and regional continuity verification, with all verification thresholds set to zero deviation boundaries.
[0139] After the message and image are generated, a consistency check is performed. The consistency check counts the consistency of the number of cabin entries, the set of cabin numbers, and the set of cabin segment partitions, with a difference threshold of 0. The release path is constructed based on the target system list, release order, rollback path, and audit identifier. The target system list is determined by the nodes through the list and the business release matrix. The release order is determined according to the principle of placing external systems last and internal systems first to reduce the risk of external impact. The rollback path is determined by the rollback path conclusion in the report and bound to the version identifier. The audit identifier is generated by combining the data packet identifier, report identifier, and instruction identifier. After the release path is generated, the layout diagram message and layout diagram image enter the release queue and carry audit and rollback information, so that in the event of subsequent anomalies, the audit identifier can be used to trace back and the rollback path can be used to complete the recovery.
[0140] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for generating international airline layout map messages and images based on AI image recognition, characterized in that, include: S1. Through multi-party collaborative system interaction, obtain data flow records and cabin information logs from digital tools during the layout management process used to generate international airline layout map messages and layout map images, and obtain the layout map source images corresponding to the cabin information. S2. Perform AI image recognition on the layout map source image to extract cabin identifiers, area boundaries and their coordinate positions to form structured layout map data. Perform encryption algorithm processing on data flow records, cabin information logs and structured layout map data to obtain encrypted data blocks, and determine the data integrity verification value in the abnormal interference detection stage. S3. Determine whether there is abnormal interference in the data flow process based on the verification value calculated from the encrypted data block. If the verification value does not match the preset threshold, activate the access control module to isolate the illegal modification attempt and obtain the isolated secure data flow. S4. Using a verification algorithm, extract cabin information and cabin allocation details from the isolated security data stream. Combined with cabin coordinates and area boundary layout elements obtained from AI image recognition, determine whether the cabin information meets the requirements for generating the layout map in the system interactive environment. Generate a layout map data set for directly constructing international airline layout map messages and layout map images. S5. Obtain the associated access control logs in the multi-party collaboration platform through the layout diagram data group, and compare and analyze the access control logs to determine whether there are any potential traces of illegal modification, and obtain a cleaned access log set. S6. Based on the purified permission log set, the layout diagram data group is repackaged using an encryption algorithm, and in the digital tool update process, it is determined whether the packaged data has the ability to resist abnormal interference, and an enhanced data packet containing international airline layout diagram messages and layout diagram images is output. S7. The enhanced data packets are verified by the verification algorithm in the data flow test, and the verified data packets are distributed to the system interaction nodes. The node feedback is summarized and processed to obtain the final integrity confirmation report. The cabin information update instruction is obtained from the flight scheduling system through the final integrity confirmation report. The instruction execution verification algorithm is used to determine whether it avoids passenger impact. The international airline layout map message and layout map image are generated and published.
2. The method for generating international airline layout map messages and images based on AI image recognition according to claim 1, characterized in that: S1 includes: By engaging multiple parties in collaborative interaction, data flow records and cabin dynamic update records are obtained from digital tools during the layout management process. Collect cabin information logs based on data flow records and cabin dynamic update records, and determine cabin information logs; The layout source image is obtained by matching the cabin information log with the layout image source image and comparing it with the dynamic update record. If the layout map source image corresponds to the cabin information log, the information log is integrated and the image source and international standard message format are verified to obtain the integrated information log and the verified image source. The integrated information logs and verified image sources are used to generate international airline layout map messages and layout map images.
3. The method for generating international airline layout map messages and images based on AI image recognition according to claim 1, characterized in that: S2 includes: AI image recognition is used to extract cabin identifiers and boundary coordinates from the source image of the layout map to obtain layout elements, form structural data corresponding to the layout elements, and integrate cabin occupancy status records to determine extended layout data. An encrypted block is constructed by encrypting data flow records using extended layout data and fusing cabin information logs. After obtaining the encrypted block, an interference detection is performed to determine if abnormal interference exceeds a preset threshold. If the interference exceeds the preset threshold, the encryption parameters are adjusted to obtain an adjusted encrypted block. To determine the generated data integrity verification value, a complete verification of the adjusted encryption block is performed. The integrated record of dynamic layout adjustment verification and image verification is obtained from the data integrity verification value. Based on the dynamic layout adjustment verification and image verification integration records, prepare to generate international airline layout map messages and layout map images.
4. The method for generating international airline layout map messages and images based on AI image recognition according to claim 1, characterized in that: S3 includes: Obtain the verification value from the encrypted data block, and perform interference and anomaly judgment by comparing the verification value with a preset threshold to determine the threshold matching verification result; If the threshold matching verification result does not match, the access control module is activated to attempt to isolate the illegal modification and obtain a secure data stream after isolation. The system employs isolated safety data streams to integrate cabin change tracking records and executes response strategies while monitoring the process. By integrating control intervention data based on process monitoring records, safety data flow is obtained for the generation of layout diagram messages and images.
5. The method for generating international airline layout map messages and images based on AI image recognition according to claim 1, characterized in that: S4 includes: Cabin information and cabin allocation details are extracted from the isolated security data stream. Data integrity is calculated using a hash function through a verification algorithm to obtain the extracted cabin data group. The extracted cabin data sets are fused with image recognition results to obtain coordinate positions and region boundary divisions, generating fused layout elements. The system checks whether the merged layout elements meet the verification requirements in the interactive environment. If the verification result is satisfactory, the group of verified layout elements is determined. Based on the verified layout element group, construct message data to obtain the message construction data stream; After constructing the data stream through messages, the image generation elements are integrated, and the layout map data set is output.
6. The method for generating international airline layout map messages and images based on AI image recognition according to claim 1, characterized in that, S5 includes: By obtaining the associated access control logs from the multi-party collaboration platform through the layout diagram data group, and processing the access control logs using a comparison and analysis mechanism, preliminary analysis results are obtained. Based on the preliminary analysis results and the integration of cabin layout attributes, it is determined whether there are traces of illegal modification, thereby identifying potential risk sets. Security data verification is performed based on the potential risk set combined with image coordinate boundaries, and purification processing elements are obtained to generate intermediate log groups. An intermediate log group is used to integrate interactive verification requirements and message data to construct a cleaned permission log set.
7. The method for generating international airline layout map messages and images based on AI image recognition according to claim 1, characterized in that, S6 includes: AES encryption algorithm is applied to the layout data group using a cleaned log set to obtain the encapsulated preliminary data group; By injecting a preset interference simulation signal sequence into the tool update stage of the initial data set, the ability of the encapsulated data to resist abnormal interference is judged, thereby obtaining a verification result set.
8. The method for generating international airline layout map messages and images based on AI image recognition according to claim 7, characterized in that: S6 further includes: By integrating the verification result set with the preset cabin permission mapping verification table, potential vulnerability points are identified and reinforcement strategy groups are generated. Based on the backup message paths of international airlines integrated by the enhanced strategy group, obtain the intermediate packet body containing the map message and the layout map image; A pre-defined boundary verification mechanism is constructed from the intermediate packet body, and an enhanced data packet is output.
9. The method for generating international airline layout map messages and images based on AI image recognition according to claim 1, characterized in that, S7 includes: In data flow testing, enhanced data packets are used to obtain verified data packets through a preset sequence injection verification algorithm. Validated data packets are distributed to system interaction nodes, and node feedback sets are obtained. The node feedback sets are merged and aggregated to determine the final integrity confirmation report.
10. The method for generating international airline layout map messages and images based on AI image recognition according to claim 9, characterized in that: The S7 also includes: Extract cabin information update instructions from the final integrity confirmation report, and determine whether the instruction execution verification algorithm meets the preset standards to obtain the results; The results are used to generate international airline layout map messages and layout map images, and to construct the publishing path.
Citation Information
Patent Citations
Acquisition method, query system and query method of flight detailed seat layout map
CN118820499A
Industrial data security control method and system based on block chain
CN120433957A