Railway sensitive data security detection method and system

By acquiring sensor data from the railway Internet of Things (IoT) system and using blockchain technology to verify and compare the information, the security and reliability issues of sensitive data in the railway IoT system have been resolved, enabling real-time integrity verification and reliability assurance of the data.

CN121841817APending Publication Date: 2026-04-10CHINA RAILWAY SIYUAN SURVEY & DESIGN GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-28
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

The railway Internet of Things (IoT) system suffers from single-point failures that lead to unavailability of security services, and the security of sensitive railway data cannot be guaranteed when the integrated monitoring platform is controlled by an unauthorized third party.

Method used

By acquiring sensor data, analyzing and processing it to obtain raw sensitive data, and using a preset algorithm to calculate the first verification information, sending it to the blockchain and obtaining the on-chain address, the integrity and consistency of the data are ensured by combining the verification request and verification information of the regulatory module.

Benefits of technology

It enables real-time integrity verification of sensitive data in the railway Internet of Things system, improves the security and reliability of the system, prevents data tampering, and ensures that the reliability audit function of key data can continue to operate even in the event of node failure or attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841817A_ABST
    Figure CN121841817A_ABST
Patent Text Reader

Abstract

The invention discloses a railway sensitive data security detection method and system, and the method comprises the steps: obtaining sensing data, and carrying out the analysis processing of the sensing data, and obtaining original sensitive data; calculating the original sensitive data through a preset algorithm to obtain first verification information; sending the first verification information to the block chain, and waiting for receiving an on-chain address of the first verification information returned by the block chain; when a data detection command is received, a verification request is sent to the supervision module; meanwhile, calculating the current sensitive data through the same preset algorithm to obtain second verification information; the link address of the second verification information and the link address of the first verification information are sent to the supervision module, and a verification result returned by the supervision module is waited to be received; and according to the verification result, determining whether the original sensitive data is consistent with the current sensitive data. According to the technical scheme provided by the embodiment of the invention, the railway sensitive data can be subjected to integrity detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically to a method and system for detecting the security of sensitive railway data. Background Technology

[0002] In current railway IoT systems, data security is subject to varying degrees of centralization. This centralization creates a vulnerability to single points of failure, ultimately leading to the unavailability of security services. More seriously, if the integrated monitoring platform falls under the control of an unauthorized third party, it could fundamentally damage the entire railway IoT system, making it impossible to ensure the security of sensitive data within the railway system, especially core railway engineering data.

[0003] Therefore, it is necessary to design a scheme for integrity detection of sensitive railway data to ensure the security and reliability of data in the railway Internet of Things system. Summary of the Invention

[0004] This invention provides a method and system for detecting the security of sensitive railway data, so as to ensure the security and reliability of sensitive data in railway Internet of Things systems.

[0005] In a first aspect, the present invention provides a method for detecting the security of sensitive railway data, comprising:

[0006] Acquire sensor data collected during railway transportation, and obtain raw sensitive data by analyzing and processing the sensor data;

[0007] The original sensitive data is calculated using a preset algorithm to obtain first verification information; the first verification information is sent to the blockchain, and the blockchain address is awaited to receive the first verification information returned by the blockchain.

[0008] When a data detection command is received, a verification request is sent to the monitoring module; at the same time, the current sensitive data is calculated using the same preset algorithm to obtain the second verification information.

[0009] The on-chain address of the second verification information and the first verification information is sent to the monitoring module, and the monitoring module is waited to receive the verification result returned by the monitoring module. Based on the verification result, it is determined whether the original sensitive data is consistent with the current sensitive data.

[0010] Furthermore, the process of analyzing and processing the sensor data to obtain the raw sensitive data includes:

[0011] By performing feature extraction and importance analysis on the sensor data, the original sensitive data in the sensor data is screened out;

[0012] And / or, by processing the sensing data, operational data is generated, and by performing importance analysis on the operational data, original sensitive data in the operational data is filtered out.

[0013] Furthermore, the process by which the blockchain returns the on-chain address specifically includes:

[0014] After receiving the first verification information, the blockchain records the first verification information into the distributed ledger to form a new block;

[0015] After the first verification information is recorded, a unique on-chain address for the block is generated.

[0016] Furthermore, it also includes:

[0017] An auditing system is built based on the aforementioned blockchain;

[0018] The auditing system and the integrated monitoring platform exchange information bidirectionally through an API interface.

[0019] The integrated monitoring platform stores the first verification information in the blockchain by calling the API interface, or receives the on-chain address of the first verification information from the blockchain.

[0020] Furthermore, it also includes:

[0021] After obtaining the original sensitive data, a unique label is assigned to the original sensitive data;

[0022] The original sensitive data and the current sensitive data correspond to the sensitive data in the tag at different times;

[0023] When a data detection command is received, the current sensitive data corresponding to the tag at the current moment is determined by searching the tag.

[0024] Furthermore, it also includes:

[0025] When the verification request is sent to the monitoring module, the current sensitive data is calculated using the same preset algorithm to obtain the second verification information.

[0026] Furthermore, the process by which the monitoring module returns the verification result specifically includes:

[0027] After receiving the second verification information and the on-chain address of the first verification information, the monitoring module obtains the first verification information from the blockchain through the on-chain address of the first verification information.

[0028] After obtaining the first verification information, the verification result is obtained by comparing the first verification information and the second verification information.

[0029] Secondly, the present invention provides a railway sensitive data security detection system, including: an integrated monitoring platform, a blockchain, and a regulatory module;

[0030] The integrated monitoring platform is used for security detection of sensitive railway data;

[0031] The blockchain is used to receive the first verification information sent by the integrated monitoring platform, and after receiving the first verification information, to return the on-chain address of the first verification information to the integrated monitoring platform; and to receive the on-chain address of the first verification information sent by the supervision module, and after receiving the on-chain address, to return the first verification information to the supervision module.

[0032] The monitoring module is used to receive the second verification information and the on-chain address of the first verification information sent by the integrated monitoring platform, and after receiving the second verification information and the on-chain address, to obtain the first verification information from the blockchain; and to obtain the verification result by comparing the first verification information and the second verification information.

[0033] Thirdly, embodiments of the present invention provide an electronic device, the electronic device comprising:

[0034] At least one processor; and a memory communicatively connected to the at least one processor;

[0035] The memory stores a computer program that can be executed by at least one processor, such that the at least one processor is able to perform the steps of the method according to any embodiment of the present invention.

[0036] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the steps of a method according to any embodiment of the present invention.

[0037] Compared with the prior art, the present invention has the following advantages:

[0038] The technical solution in this embodiment of the invention first acquires sensor data and analyzes and processes it to obtain raw sensitive data. Then, it calculates the raw sensitive data using a preset algorithm to obtain first verification information, which is sent to the blockchain, and the system waits to receive the on-chain address of the first verification information returned by the blockchain. Next, when a data detection command is received, a verification request is sent to the monitoring module. Simultaneously, the current sensitive data is calculated using the same preset algorithm to obtain second verification information. Finally, the second verification information and the on-chain address of the first verification information are sent to the monitoring module, and the system waits to receive the verification result returned by the monitoring module. Based on the verification result, it is determined whether the raw sensitive data and the current sensitive data are consistent. This technical solution enables integrity detection of railway sensitive data, ensuring the security and reliability of data in the railway Internet of Things system. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only preferred embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 A flowchart illustrating a railway sensitive data security detection method provided in an embodiment of the present invention;

[0041] Figure 2 A schematic diagram of a railway Internet of Things (IoT) architecture provided for an embodiment of the present invention;

[0042] Figure 3 A schematic diagram of the architecture of an auditing system provided in an embodiment of the present invention;

[0043] Figure 4 This is a data interaction diagram of an auditing system and an integrated monitoring platform provided in an embodiment of the present invention;

[0044] Figure 5 A flowchart illustrating a sensitive data verification method provided in an embodiment of the present invention;

[0045] Figure 6 This is a schematic diagram of the structure of a railway sensitive data security detection system provided in an embodiment of the present invention;

[0046] Figure 7 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0047] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0048] Figure 1 This is a flowchart illustrating a railway sensitive data security detection method provided in an embodiment of the present invention. This embodiment is particularly applicable to scenarios where sensitive data is detected under single-point fault conditions. The method can be executed by a railway sensitive data security detection system, which can be implemented in software and / or hardware and can be configured in electronic devices.

[0049] like Figure 1 As shown, this method is applied to an integrated monitoring platform and specifically includes:

[0050] S1 acquires sensor data collected during railway transportation and obtains raw sensitive data through analysis and processing of the sensor data.

[0051] The sensing data is acquired by sensors deployed in railway transportation scenarios. This data can include infrastructure status data, environmental data, and equipment data. For example, infrastructure status data includes settlement, deformation, and stress; environmental data includes temperature, humidity, wind speed, rainfall, and gas concentration; and equipment data includes braking system status, axle temperature, vibration, and energy consumption. After collecting this data, the sensor nodes transmit it to the integrated monitoring platform via the railway Internet of Things (IoT).

[0052] Figure 2 This is a schematic diagram of the architecture of a railway Internet of Things (IoT) provided in an embodiment of the present invention, such as... Figure 2 As shown, the architecture of the entire railway Internet of Things (IoT) is divided into three layers: a monitoring layer, a transmission layer, and a central layer. The monitoring layer deploys various sensor terminals, such as distance sensors, stress sensors, displacement sensors, settlement sensors, and other intelligent terminal applications. After collecting the corresponding sensor data, these terminals transmit the data to the integrated monitoring platform and other monitoring and production management systems via the transmission layer. The transmission layer uses the railway wireless communication network to fully cover the communication needs of all sensor nodes. The integrated monitoring platform and other monitoring and production management systems in the central layer remotely perform relevant railway transportation analysis work using this sensor data.

[0053] Before analyzing and processing sensor data, it is necessary to clean the sensor data to ensure its integrity.

[0054] Furthermore, by analyzing and processing the sensor data, the raw sensitive data is obtained, including:

[0055] By performing feature extraction and importance analysis on the sensor data, the original sensitive data in the sensor data is screened out;

[0056] And / or, by manipulating the sensor data, operational data is generated, and by performing importance analysis on the operational data, the original sensitive data in the operational data is filtered out.

[0057] It should be noted that these raw sensitive data are usually core engineering data generated in railway transportation, or operational data generated by the integrated monitoring platform after analyzing sensor data and performing corresponding operational processing.

[0058] These raw sensitive data are centrally stored in the integrated monitoring platform, which can access this raw sensitive data.

[0059] S2, calculate the original sensitive data using a preset algorithm to obtain the first verification information; send the first verification information to the blockchain and wait for the on-chain address to receive the first verification information returned by the blockchain.

[0060] The preset algorithms may include: parity check algorithm, LRC check algorithm, CRC check algorithm, MD5 / SHA check algorithm, and BCC XOR check algorithm, etc. To ensure the integrity and authenticity of the original sensitive data in the integrated monitoring platform, the original sensitive data is checked and calculated, and a check value is generated and stored in the blockchain as the first check information.

[0061] It should be noted that the inherent immutability and traceability of blockchain provide a reliable evidence foundation for high-value and sensitive operational data, enabling any illegal modification of the original sensitive data to be detected instantly through on-chain verification values. This transforms data integrity auditing from complex post-event verification into efficient real-time verification and second-level response, with evidence storage latency ≤1 second.

[0062] In some embodiments, the process of the blockchain returning the on-chain address specifically includes:

[0063] After receiving the first verification information, the blockchain records the first verification information in the distributed ledger, forming a new block;

[0064] After the first verification information is recorded, a unique on-chain address for the block is generated.

[0065] Understandably, storing the primary verification information and railway sensitive data in different systems fundamentally solves the single point of failure and data tampering risks inherent in centralized architectures. Railway sensitive data is stored in an integrated monitoring platform responsible for driving core business operations; while verification information is recorded in different blocks of the blockchain. Leveraging its distributed ledger characteristics and multi-node consensus mechanism, this ensures that even if individual nodes or the central platform fail or are attacked, the integrity auditing function of critical data within the system continues to operate sustainably.

[0066] In some embodiments, an auditing system is built based on blockchain;

[0067] The auditing system and the integrated monitoring platform exchange information bidirectionally through an API interface.

[0068] The integrated monitoring platform stores the first verification information in the blockchain by calling the API interface, or receives the on-chain address of the first verification information from the blockchain.

[0069] Understandably, the auditing system is built on the Fabric architecture and interacts bidirectionally with the integrated detection platform through API interfaces. It adopts a modular design, and the integrated monitoring platform only needs to call the API interface to realize the complete storage of historical operation log verification information and to locate and trace any business behavior.

[0070] Figure 3 A schematic diagram of the architecture of an auditing system provided in an embodiment of the present invention, such as... Figure 3 As shown, the architecture of the entire audit system is divided into three layers: data layer, blockchain layer, and application layer. The audit system uses blockchain technology at its core, primarily encompassing the application layer, blockchain layer, and data layer. Through this layered design, it achieves an organic integration of user operation, blockchain processing, and data storage. Specifically, the application layer facilitates user interaction, the blockchain layer ensures data security and immutability, and the data layer provides efficient data storage and verification methods, collectively guaranteeing the stable operation of the system and data security.

[0071] Figure 4 This is a data interaction diagram of an auditing system and an integrated monitoring platform provided in an embodiment of the present invention, such as... Figure 4 As shown, the audit system receives the first verification information transmitted by the integrated monitoring platform via an API interface and stores it in the distributed ledger of the blockchain. Simultaneously, the audit system records the first verification information in the distributed ledger of the blockchain, forming a new block. After recording, a unique on-chain address is generated. Finally, the audit system returns the on-chain address to the integrated monitoring platform via the API interface.

[0072] S3, when a data detection command is received, a verification request is sent to the monitoring module; at the same time, the current sensitive data is calculated using the same preset algorithm to obtain the second verification information.

[0073] In some embodiments, after obtaining the original sensitive data, a unique label is assigned to the original sensitive data;

[0074] The original sensitive data and the current sensitive data correspond to the sensitive data in this tag at different times;

[0075] When a data detection command is received, the sensitive data corresponding to that tag at the current moment is determined by searching for the tag.

[0076] It should be noted that the original sensitive data and the current sensitive data essentially refer to the same data. However, in the actual operation of the integrated monitoring platform, the original sensitive data may be tampered with due to some special circumstances. Therefore, by tagging the original sensitive data and searching for the current sensitive data through the tag at any given time, and then analyzing the consistency between the original sensitive data and the current sensitive data, it can be determined whether the sensitive data has become abnormal.

[0077] In some embodiments, when a verification request is sent to the monitoring module, the current sensitive data is calculated using the same preset algorithm to obtain the second verification information.

[0078] Specifically, each time the integrated monitoring platform uses the current sensitive data, it can send a verification request to the regulatory module.

[0079] In addition, a data verification cycle can be set. Whenever a cycle is reached, the railway Internet of Things system sends a data detection command to the integrated monitoring platform. For example, a 24-hour cycle can be used. When the integrated monitoring platform receives the data detection command, it sends a verification request to the monitoring module.

[0080] S4. Send the second verification information and the on-chain address of the first verification information to the supervision module, and wait to receive the verification result returned by the supervision module; based on the verification result, determine whether the original sensitive data is consistent with the current sensitive data.

[0081] In some embodiments, the process by which the monitoring module returns the verification result specifically includes:

[0082] After receiving the second verification information and the on-chain address of the first verification information, the monitoring module obtains the first verification information from the blockchain through the on-chain address of the first verification information.

[0083] After obtaining the first verification information, the verification result is obtained by comparing the first verification information with the second verification information.

[0084] Furthermore, if the verification results show that the first verification information and the second verification information are consistent, then the original sensitive data is consistent with the current sensitive data;

[0085] If the verification results show that the first and second verification information are inconsistent, then the original sensitive data is inconsistent with the current sensitive data. In this case, it indicates that the sensitive data has changed, which may be due to a malfunction or attack on the integrated monitoring platform.

[0086] In this embodiment, the monitoring module can achieve rapid source tracing through smart contracts, and can locate and provide complete historical information of any business behavior within 5 seconds, which greatly improves the efficiency of security threat discovery and root cause location.

[0087] Figure 5 This is a flowchart illustrating a sensitive data verification method provided in an embodiment of the present invention, as shown below. Figure 5 As shown, in some specific implementation processes, this scheme includes: First, the integrated monitoring platform receives sensor data sent by sensor nodes, extracts raw sensitive data such as operation information, and calculates the verification value of the raw sensitive data (i.e., the first verification information). Then, the integrated monitoring platform stores the verification value in IPFS (InterPlanetary File System). IPFS sends the corresponding hash value and hash address to the blockchain, and then the integrated monitoring platform waits to receive the on-chain address returned by the blockchain. Next, when the integrated monitoring platform receives a query request for a specific operation information (i.e., sensitive data) from the monitoring module, it sends the corresponding on-chain address to the blockchain. Subsequently, the blockchain sends the request verification information to IPFS, and IPFS queries the corresponding current sensitive data in the request and sends the verification value of the current sensitive data (i.e., the second verification information) to the monitoring module. Finally, the monitoring module completes the integrity check of the sensitive data.

[0088] In this embodiment, a blockchain-based separation of business and technology design is adopted. This not only builds a more secure and reliable data transmission and storage foundation but also expands the application potential for integrating smart contracts to achieve automated operation and maintenance processes (such as condition-triggered alarms), helping to further optimize resource allocation and reduce operating costs. Compared with existing railway IoT systems, the advantage of this embodiment lies in fundamentally solving the single point of failure and data tampering risks caused by centralized architecture. By introducing blockchain technology to build a decentralized audit module, and utilizing its distributed ledger characteristics and multi-node consensus mechanism, it ensures that even if individual nodes or traditional central platforms fail or are attacked, the integrity audit function of key data in the system (such as operation log verification values) can continue to operate, significantly enhancing the robustness of the system.

[0089] The technical solution in this invention, by deploying blockchain in a railway IoT system, successfully achieves integrity auditing of sensitive data in an integrated monitoring platform for railway infrastructure, solving the problems of unreliability and insecurity of sensitive data in current railway IoT systems. Utilizing a design concept of separating business and technology, sensitive data is stored in the integrated monitoring platform, while verification data is stored in the blockchain, ensuring the immutability and transparency of the data. By comparing the verification information of sensitive data obtained from different nodes, the integrity of the data can be quickly and accurately determined, thereby significantly improving the security and reliability of the entire railway IoT system.

[0090] Based on the same inventive concept Figure 6 This is a schematic diagram of a railway sensitive data security detection system provided in an embodiment of the present invention, as shown below. Figure 6 As shown, the system specifically includes: an integrated monitoring platform, a blockchain, and a regulatory module.

[0091] The integrated monitoring platform is used to acquire sensor data collected during railway transportation and to obtain raw sensitive data by analyzing and processing the sensor data.

[0092] The integrated monitoring platform is also used to calculate the original sensitive data using a preset algorithm to obtain the first verification information; send the first verification information to the blockchain, and wait for the on-chain address to receive the first verification information returned by the blockchain;

[0093] The integrated monitoring platform is also used to send a verification request to the monitoring module when it receives a data detection command; at the same time, it calculates the current sensitive data using the same preset algorithm to obtain the second verification information.

[0094] The integrated monitoring platform is also used to send the on-chain addresses of the second verification information and the first verification information to the supervision module, and wait to receive the verification results returned by the supervision module; based on the verification results, it determines whether the original sensitive data is consistent with the current sensitive data.

[0095] The blockchain is used to receive the first verification information sent by the integrated monitoring platform, and after receiving the first verification information, to return the on-chain address of the first verification information to the integrated monitoring platform; and to receive the on-chain address of the first verification information sent by the regulatory module, and after receiving the on-chain address, to return the first verification information to the regulatory module.

[0096] The monitoring module is used to receive the second verification information and the on-chain address of the first verification information sent by the integrated monitoring platform, and after receiving the second verification information and the on-chain address, to obtain the first verification information from the blockchain; and to obtain the verification result by comparing the first verification information and the second verification information.

[0097] Based on the same inventive concept Figure 7 This is a schematic diagram of the structure of an electronic device that implements the railway sensitive data security detection method according to embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0098] like Figure 7 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0099] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0100] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as railway sensitive data security detection methods.

[0101] In some embodiments, the railway sensitive data security detection method can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the railway sensitive data security detection method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the railway sensitive data security detection method by any other suitable means (e.g., by means of firmware).

[0102] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0103] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0104] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0105] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0106] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0107] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0108] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0109] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A railway sensitive data security detection method applied to an integrated monitoring platform, characterized in that, The system comprises: acquiring sensing data collected during railway transportation, and obtaining original sensitive data by analyzing and processing the sensing data; calculating the original sensitive data by a preset algorithm to obtain first verification information; sending the first verification information to a blockchain, and waiting to receive an on-chain address of the first verification information returned by the blockchain; when receiving a data detection command, sending a verification request to a supervision module; at the same time, calculating the current sensitive data by the same preset algorithm to obtain second verification information; sending the second verification information and the on-chain address of the first verification information to the supervision module, and waiting to receive a verification result returned by the supervision module; determining whether the original sensitive data and the current sensitive data are consistent according to the verification result.

2. The method of claim 1, wherein, The original sensitive data is obtained by analyzing and processing the sensing data, comprising: filtering out the original sensitive data in the sensing data by feature extraction and importance analysis on the sensing data; and / or, generating operation data by operation processing on the sensing data, and filtering out the original sensitive data in the operation data by importance analysis on the operation data.

3. The method of claim 1, wherein, The process of the blockchain returning the on-chain address specifically comprises: after receiving the first verification information, the blockchain records the first verification information into a distributed ledger to form a new block; and after the recording of the first verification information is completed, a unique on-chain address of the block is generated.

4. The method of claim 1, wherein, Further comprising: building an audit system based on the blockchain; the audit system and the integrated monitoring platform perform bidirectional information interaction through an API interface; the integrated monitoring platform stores the first verification information in the blockchain or receives the on-chain address of the first verification information from the blockchain by calling the API interface.

5. The method of claim 1, wherein, Further comprising: after obtaining the original sensitive data, a unique label is added to the original sensitive data; the original sensitive data and the current sensitive data respectively correspond to sensitive data in the label at different time points; when receiving a data detection command, the current sensitive data corresponding to the label at the current time point is determined by searching the label.

6. The method of claim 1, wherein, Further comprising: when sending the verification request to the supervision module, the current sensitive data is calculated by the same preset algorithm to obtain the second verification information.

7. The method of claim 1, wherein, The process of the supervision module returning the verification result specifically comprises: after receiving the second verification information and the on-chain address of the first verification information, the supervision module acquires the first verification information from the blockchain through the on-chain address of the first verification information; and after acquiring the first verification information, the verification result is obtained by comparing the first verification information and the second verification information.

8. A railway sensitive data security detection system characterized by, The system is configured to implement the method of any one of claims 1-7, and the system comprises an integrated monitoring platform, a blockchain, and a supervision module; The integrated monitoring platform is used for safety detection of railway sensitive data according to the method in any one of claims 1-7. The blockchain is used for receiving the first verification information sent by the integrated monitoring platform, and returning the on-chain address of the first verification information to the integrated monitoring platform after receiving the first verification information; and receiving the on-chain address of the first verification information sent by the supervision module, and returning the first verification information to the supervision module after receiving the on-chain address. The supervision module is used for receiving the second verification information and the on-chain address of the first verification information sent by the integrated monitoring platform, and obtaining the first verification information from the blockchain after receiving the second verification information and the on-chain address; and obtaining the verification result by comparing the first verification information and the second verification information.

9. An electronic device, comprising: The electronic device comprises: at least one processor; and a memory connected with the at least one processor in communication; The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the steps of the method in any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for enabling the processor to execute the steps of the method in any one of claims 1-7 when executed.