Subway network data security storage method and system

By fusing features from multi-source heterogeneous data, using global master key encryption, and employing distributed storage in the metro consortium blockchain network, the problems of centralized data storage and rigid access control in the metro system have been solved, thereby improving the security and reliability of metro network data.

CN121923792AInactive Publication Date: 2026-04-24CHENGDU SHUANGYANG RAIL TRANSIT EQUIPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHENGDU SHUANGYANG RAIL TRANSIT EQUIPMENT CO LTD
Filing Date
2026-01-27
Publication Date
2026-04-24
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing subway data storage technologies suffer from several drawbacks: centralized storage leads to a single point of failure, static encryption is ill-suited to the needs of multi-department collaboration, and rigid access control results in insufficient data security and reliability.

Method used

By employing multi-source heterogeneous subway network data feature fusion, global master key encryption, block encryption, homomorphic encryption, and smart storage contracts, combined with the subway consortium blockchain network for distributed storage and dynamic permission management, multi-layer dynamic encryption and dynamic permission control are achieved.

Benefits of technology

It improves the security and reliability of subway network data, prevents data leakage and tampering, meets the needs of multi-department collaboration, and reduces operational risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121923792A_ABST
    Figure CN121923792A_ABST
Patent Text Reader

Abstract

The invention discloses a metro network data security storage method and system, and belongs to the technical field of metro communication and data security. Metro network fusion feature data is formed through extraction and fusion of multi-source heterogeneous metro network feature data, and is subjected to block encryption by using a symmetric session key; according to the method, the symmetric session key is subjected to enhanced encryption, so that a multiple encryption protection mechanism of data multilayer dynamic encryption and ciphertext homomorphic encryption is achieved, the invisibility of original data is ensured while the data operation calculation requirement is ensured, and the security of subway network data is greatly improved; besides, the metro alliance chain network is established, the intelligent storage contract is used for performing dynamic authority management on the metro alliance chain network, dynamic authority monitoring of the metro network data is realized, and the security and reliability of metro network data storage are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of subway communication and data security technology, specifically relating to a method and system for secure storage of subway network data. Background Technology

[0002] As the arteries of urban public transportation, the safe and efficient operation of the subway network relies heavily on a vast and complex data ecosystem. This system generates and processes massive amounts of multi-source, heterogeneous data streams daily, encompassing real-time command signals for automatic train control, equipment status monitoring for power supply and environmental control, passenger transaction records from automatic fare collection systems, continuous streaming media from video surveillance, and emerging intelligent operation and maintenance sensor information. This data is not only highly valuable and requires real-time processing, but also heavily involves core operational safety and passenger privacy. Any leakage, alteration, loss, or unauthorized access during storage could lead to operational disruptions and service disputes, or even major public safety incidents with incalculable social and economic consequences.

[0003] However, existing subway data storage technologies generally adopt a hybrid storage model of centralized databases and peripheral security gateways. Specifically, subway data is centrally stored in the core server of the control center or in the storage area network, and protected by firewalls, intrusion detection systems, and traditional static encryption methods (such as transparent database encryption or file system encryption). However, due to the centralized storage and simple encryption, this architecture makes the centralized storage node a single point of failure and an obvious target for attacks. Once it is breached or a hardware failure occurs, it may lead to large-scale data paralysis. Furthermore, the static and coarse-grained access control policies are difficult to adapt to the complex data collaboration needs of multiple departments and roles (such as dispatching, maintenance, security, or external partners) in subway operations, which can easily lead to rampant privilege abuse or management rigidity.

[0004] As mentioned above, how to provide a secure storage method and system for subway network data that can improve the storage security and reliability of subway network data has become an urgent problem to be solved. Summary of the Invention

[0005] The purpose of this invention is to provide a method and system for secure storage of subway network data, in order to solve the above-mentioned problems existing in the prior art.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a method for secure data storage in a subway network, comprising: The process involves acquiring raw multi-source heterogeneous metro network data, performing data preprocessing and standardization on the raw multi-source heterogeneous metro network data to obtain standard multi-source heterogeneous metro network data, extracting multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data, and performing feature fusion processing on the multi-source heterogeneous metro network feature data to obtain metro network fused feature data. For the metro network fusion feature data, a pair of global master keys is generated. Using the global master keys, a symmetric session key is randomly generated. The symmetric session key is used to encrypt the metro network fusion feature data in blocks to obtain multiple metro network ciphertext data blocks. The global master key is then used to enhance the encryption of the symmetric session key to obtain session key ciphertext. The session key ciphertext and each of the metro network ciphertext data blocks are combined to form multiple multi-layer metro network encrypted data packets. Multiple subway network management agencies are used as consensus nodes. A subway consortium blockchain network is established based on these consensus nodes. Encrypted data packets of the multi-layered subway network are distributed and stored in the subway consortium blockchain network. A preset smart storage contract is used to dynamically manage the permissions of the subway consortium blockchain network. The smart storage contract includes an encrypted data registration contract, a network access control contract, and a key storage management contract. Obtain the data access request from the authorized party, and query and decrypt the accessed subway network data based on the smart storage contract.

[0007] In one possible design, raw multi-source heterogeneous subway network data is acquired, preprocessed and standardized to obtain standard multi-source heterogeneous subway network data, and multi-source heterogeneous subway network feature data is extracted from the standard multi-source heterogeneous subway network data. Feature fusion processing is then performed on the multi-source heterogeneous subway network feature data to obtain fused subway network feature data, including: Using a data acquisition interface, raw subway network data from multiple key data systems of the subway network are collected in real time. These key data systems include the train control data system, the ticketing and ticket checking data system, and the video surveillance data system. Add timestamps and source identifiers to the original subway network data of each key data system, so that the original subway network data of each key data system with added timestamps and source identifiers can be used as the original multi-source heterogeneous subway network data. The source identifier is used to characterize the key data system that is the source of the original subway network data. The original multi-source heterogeneous subway network data is filled with missing values ​​and outliers are removed to obtain pre-multi-source heterogeneous subway network data. The privacy information of the pre-multi-source heterogeneous metro network data is obfuscated to obtain multi-source heterogeneous metro network data; Obtain a preset data structure format, use the data structure format to standardize the multi-source heterogeneous subway network data, and align the standardized multi-source heterogeneous subway network data according to the timestamp to obtain standard multi-source heterogeneous subway network data. Obtain preset data feature types, and extract various multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data according to the data feature types. The data feature types include operation efficiency features, metro passenger flow features, equipment status features, and video semantic features. Each of the multi-source heterogeneous subway network feature data is quantized into feature vectors, and each feature vector is concatenated into a high-dimensional feature concatenation vector. Then, the high-dimensional feature concatenation vector is mapped to a low dimension using principal component analysis to obtain a low-dimensional feature concatenation vector. The low-dimensional feature splicing vector is normalized to obtain the subway network fusion feature data.

[0008] In one possible design, a global master key is generated for the metro network fusion feature data. Using the global master key, a symmetric session key is randomly generated. This symmetric session key is then used to encrypt the metro network fusion feature data in blocks, resulting in multiple metro network ciphertext data blocks, including: Four distinct prime numbers are randomly selected. The composite security modulus is calculated by multiplying these four distinct prime numbers together. Based on the composite security modulus, the Euler's totient function value of the composite security modulus is then calculated. A positive integer coprime to the Euler's totient function of the composite security modulus is randomly selected between the smallest prime number 1 and the Euler's totient function value of the composite security modulus, and used as the public key exponent. Based on the composite security modulus, a prime number that is coprime to the composite security modulus is selected as the additional security modulus; Based on the public key exponent, the modular inverse of the Euler's totient function value with respect to the composite security modulus is calculated and used as the private key exponent; The composite security modulus, the public key exponent, and the additional security modulus are combined to form a global public key. The Euler's totient function value of the composite security modulus and the private key exponent are combined to form a global private key. Based on the global public key and the global private key, a pair of global master keys is generated. The fused feature data of the subway network is divided into blocks to obtain multiple subway network data blocks, wherein the number of subway network data blocks is less than the composite security modulus; A preset enhanced encryption algorithm is obtained. Based on the global public key in the global master key, a symmetric session key is randomly generated. Using the symmetric session key and the enhanced encryption algorithm, each of the subway network data blocks is encrypted to obtain multiple subway network ciphertext data blocks.

[0009] In one possible design, the symmetric session key is enhanced and encrypted using the global master key to obtain session key ciphertext. The session key ciphertext and each of the subway network ciphertext data blocks are then combined to form multiple multi-layered subway network encrypted data packets, including: Using the global public key from the global master key, the symmetric session key is encrypted using the enhanced encryption algorithm to obtain the session key ciphertext; The session key ciphertext is used as the outer layer data, and each of the subway network ciphertext data blocks is used as the inner layer data. The outer layer data and the inner layer data are combined into multiple multi-layer subway network encrypted data packets.

[0010] In one possible design, the enhanced encryption algorithm includes a basic encryption function and an enhanced encryption function; Accordingly, using the symmetric session key and the enhanced encryption algorithm, each of the subway network data blocks is encrypted to obtain multiple subway network ciphertext data blocks, including: Using the aforementioned basic encryption function, basic encryption calculations are performed on each of the metro network data blocks using the following formula (1): (1) in, This represents the index number of each of the aforementioned subway network data blocks. This represents the metro network fusion feature data in each of the aforementioned metro network data blocks. The public key index, For the composite safety modulus, This represents the modulo operation. This represents each of the aforementioned subway network data blocks after basic encryption processing; Using the enhanced encryption function, the various subway network data blocks after basic encryption processing are processed by the following formula (2). Perform enhanced encrypted computation: (2) in, For hash functions, For the additional security module, For each of the aforementioned subway network data blocks, the timestamp is... This indicates a concatenation operation. This represents the XOR operation. This refers to each of the subway network data blocks after enhanced encryption processing, and each of the subway network data blocks after enhanced encryption processing... As encrypted data blocks for various subway networks; Accordingly, using the global public key from the global master key, the symmetric session key is encrypted using the enhanced encryption algorithm to obtain the session key ciphertext, which includes: Using the enhanced encryption function, the various subway network data blocks after basic encryption processing are processed by the following formula (3). Perform enhanced encrypted computation: (3) in, This refers to the symmetric session key. For a random number, This represents the ciphertext of the session key obtained after encryption.

[0011] In one possible design, before establishing a subway consortium blockchain network based on multiple subway network management agencies as consensus nodes, the following steps are also included: Obtain a preset homomorphic encryption algorithm, and use the homomorphic encryption algorithm to generate a pair of homomorphic encryption master keys; The homomorphic encryption master key is used to homomorphically encrypt the fused feature data of the subway network to obtain a homomorphic computation key; The homomorphic computation key is used to encrypt each of the subway network data blocks to obtain multiple homomorphic subway network ciphertext data.

[0012] In one possible design, multiple subway network management agencies are designated as consensus nodes. A subway consortium blockchain network is established based on these consensus nodes. Encrypted data packets from each of the multi-layered subway networks are distributed and stored within the consortium blockchain network. A pre-defined smart storage contract is used to dynamically manage permissions within the subway consortium blockchain network, including: Multiple metro network management agencies are used as consensus nodes, and multiple metro network application servers are used as data storage nodes. The metro network management agencies include metro operation management agencies, metro signal management agencies, and metro power supply management agencies. The metro network application servers include metro station servers, depot servers, and metro control center servers. Obtain preset consensus network parameters, and establish a consensus network based on each consensus node and each data storage node, as the metro consortium blockchain network; A globally unique identifier is added to each of the multi-layer subway network encrypted data packets, and the root hash value of each multi-layer subway network encrypted data packet is calculated based on the globally unique identifier of each multi-layer subway network encrypted data packet. Multiple data storage transactions are constructed in the metro consortium blockchain network. Each data storage transaction is signed using the private key of each storage node, and the signed data storage transactions are broadcast to the metro consortium blockchain network. Each data storage transaction is used to store a multi-layer metro network encrypted data packet. The signatures of each data storage transaction are verified through consensus by each of the data storage nodes, and the data storage transactions that have passed the consensus verification are input to the corresponding data storage nodes to complete distributed storage. Obtain a preset smart storage contract, and use the smart storage contract to distribute and verify permissions to each data requester, thereby realizing dynamic permission management of the metro consortium blockchain network.

[0013] Secondly, the present invention provides a subway network data security storage system, comprising: The metro data acquisition unit is used to acquire raw multi-source heterogeneous metro network data, perform data preprocessing and standardization on the raw multi-source heterogeneous metro network data to obtain standard multi-source heterogeneous metro network data, extract multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data, and perform feature fusion processing on the multi-source heterogeneous metro network feature data to obtain metro network fused feature data. The data enhancement encryption unit is used to generate a pair of global master keys for the metro network fusion feature data, randomly generate a symmetric session key using the global master key, and use the symmetric session key to perform block encryption on the metro network fusion feature data to obtain multiple metro network ciphertext data blocks. The global master key is then used to enhance the encryption of the symmetric session key to obtain session key ciphertext. The session key ciphertext and each of the metro network ciphertext data blocks are combined into multiple multi-layer metro network encrypted data packets. The data on-chain storage unit is used to establish a metro consortium blockchain network based on multiple metro network management agencies as consensus nodes, and to distribute and store the encrypted data packets of the multi-layer metro network in the metro consortium blockchain network. It also uses a preset smart storage contract to dynamically manage the permissions of the metro consortium blockchain network. The smart storage contract includes an encrypted data registration contract, a network access control contract, and a key storage management contract. The data retrieval management unit is used to obtain data retrieval requests from authorized parties and, based on the smart storage contract, to query and decrypt the retrieved subway network data.

[0014] Thirdly, the present invention provides an electronic device comprising a memory, a processor, and a transceiver connected in sequence and communication, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the subway network data security storage method as described in the first aspect or any possible design of the first aspect.

[0015] Fourthly, the present invention provides a computer-readable storage medium storing instructions that, when executed on a computer, perform the subway network data security storage method described in the first aspect or any possible design of the first aspect.

[0016] Fifthly, the present invention provides a computer program product containing instructions that, when executed on a computer, cause the computer to perform the subway network data security storage method as described in the first aspect or any possible design of the first aspect.

[0017] Beneficial Effects: This invention provides a method and system for secure storage of subway network data, comprising: First, acquiring raw multi-source heterogeneous subway network data; preprocessing and standardizing the raw multi-source heterogeneous subway network data to obtain standard multi-source heterogeneous subway network data; extracting multi-source heterogeneous subway network feature data from the standard multi-source heterogeneous subway network data; and performing feature fusion processing on the multi-source heterogeneous subway network feature data to obtain subway network fused feature data; Second, generating a pair of global master keys for the subway network fused feature data; using the global master keys to randomly generate a symmetric session key; using the symmetric session key to encrypt the subway network fused feature data in blocks to obtain multiple subway network ciphertext data blocks; and using the... The global master key is used to enhance the encryption of the symmetric session key to obtain the session key ciphertext. The session key ciphertext and each of the subway network ciphertext data blocks are combined to form multiple multi-layer subway network encrypted data packets. Then, multiple subway network management agencies are used as consensus nodes, and a subway consortium blockchain network is established based on the consensus nodes. The multi-layer subway network encrypted data packets are distributed and stored in the subway consortium blockchain network. A preset smart storage contract is used to dynamically manage the permissions of the subway consortium blockchain network. The smart storage contract includes an encrypted data registration contract, a network access control contract, and a key storage management contract. Finally, the data access request from the authorized party is obtained, and the accessed subway network data is queried and decrypted based on the smart storage contract. By extracting and fusing feature data from multiple heterogeneous subway networks, a subway network fusion feature data was formed. This data was then encrypted in blocks using symmetric session keys, and enhanced encryption was applied to the symmetric session keys. This achieved a multi-layered dynamic encryption and homomorphic encryption mechanism, ensuring the invisibility of the original data while meeting the data operation and computing needs, thus significantly improving the security of subway network data. Furthermore, a subway consortium blockchain network was established to dynamically manage permissions using smart storage contracts, enabling dynamic permission monitoring of subway network data and enhancing the security and reliability of subway network data storage. Attached Figure Description

[0018] Figure 1 A flowchart illustrating the subway network data security storage method provided in an embodiment of the present invention; Figure 2 A functional structure diagram of a subway network data security storage system provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the present invention will be briefly introduced below in conjunction with the accompanying drawings and descriptions of the embodiments or the prior art. Obviously, the following description of the structure of the accompanying drawings is only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. It should be noted that the description of these embodiments is for the purpose of helping to understand the present invention, but does not constitute a limitation of the present invention.

[0020] It should be understood that although the terms first, second, etc., may be used herein to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, a first unit may be referred to as a second unit, and similarly, a second unit may be referred to as a first unit, without departing from the scope of the exemplary embodiments of the invention.

[0021] It should be understood that the term "and / or" that may appear in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, B exists alone, and A and B exist simultaneously. The term " / and" that may appear in this document describes another relationship between related objects, indicating that two relationships can exist. For example, A / and B can mean: A exists alone, and A and B exist alone. In addition, the character " / " that may appear in this document generally indicates that the related objects before and after it are in an "or" relationship.

[0022] Example: like Figure 1 As shown, the first aspect of this embodiment provides a method for securely storing subway network data, which may include, but is not limited to, the following steps: S1. Obtain raw multi-source heterogeneous metro network data, perform data preprocessing and standardization on the raw multi-source heterogeneous metro network data to obtain standard multi-source heterogeneous metro network data, extract multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data, perform feature fusion processing on the multi-source heterogeneous metro network feature data to obtain metro network fused feature data. In one possible implementation, step S1 involves acquiring raw multi-source heterogeneous subway network data, performing data preprocessing and standardization on the raw multi-source heterogeneous subway network data to obtain standard multi-source heterogeneous subway network data, extracting multi-source heterogeneous subway network feature data from the standard multi-source heterogeneous subway network data, and performing feature fusion processing on the multi-source heterogeneous subway network feature data to obtain subway network fused feature data. This can be decomposed into, but is not limited to, the following steps S11-S18, specifically including: S11. Using a data acquisition interface, raw subway network data from multiple key data systems of the subway network are collected in real time, including train control data system, ticketing and ticket checking data system and video surveillance data system. S12. Add timestamps and source identifiers to the original subway network data of each key data system, so as to use the original subway network data of each key data system with added timestamps and source identifiers as the original multi-source heterogeneous subway network data, wherein the source identifier is used to characterize the key data system that is the source of the original subway network data collected. S13. Perform missing value filling and outlier removal on the original multi-source heterogeneous subway network data to obtain pre-multi-source heterogeneous subway network data; S14. Obfuscate the privacy information of the pre-multi-source heterogeneous subway network data to obtain multi-source heterogeneous subway network data; S15. Obtain a preset data structure format, use the data structure format to standardize the multi-source heterogeneous subway network data, and align the standardized multi-source heterogeneous subway network data according to the timestamp to obtain standard multi-source heterogeneous subway network data. S16. Obtain a preset data feature type, and extract various multi-source heterogeneous subway network feature data from the standard multi-source heterogeneous subway network data according to the data feature type, wherein the data feature type includes operation efficiency features, subway passenger flow features, equipment status features and video semantic features; S17. Quantize each of the multi-source heterogeneous subway network feature data into feature vectors, and concatenate each feature vector into a high-dimensional feature concatenation vector. Then, use principal component analysis to perform low-dimensional mapping on the high-dimensional feature concatenation vector to obtain a low-dimensional feature concatenation vector. S18. Normalize the low-dimensional feature splicing vector to obtain the subway network fusion feature data.

[0023] It should be noted that in the secure storage method provided in this embodiment, the original multi-source heterogeneous subway network data may include, but is not limited to, subway operation data, subway passenger information, subway equipment status data, and subway video surveillance data. This data undergoes preprocessing, standardization, and feature extraction to transform the massive, heterogeneous original network data in the subway system into a set of core feature vectors that can comprehensively and efficiently characterize the system's safety and operational status. Furthermore, feature dimensionality reduction and feature concatenation are used to reduce the complexity of data processing, highlight the key points of data storage, and provide an important prerequisite for achieving efficient and secure storage in the future.

[0024] S2. For the metro network fusion feature data, generate a pair of global master keys, use the global master keys to randomly generate a symmetric session key, use the symmetric session key to encrypt the metro network fusion feature data in blocks to obtain multiple metro network ciphertext data blocks, and use the global master keys to enhance the encryption of the symmetric session key to obtain session key ciphertext, and combine the session key ciphertext and each metro network ciphertext data block into multiple multi-layer metro network encrypted data packets. In one possible implementation, step S2 involves generating a global master key pair for the metro network fusion feature data, and using the global master key to randomly generate a symmetric session key. This symmetric session key is then used to encrypt the metro network fusion feature data in blocks, resulting in multiple metro network ciphertext data blocks. This can be, but is not limited to, decomposed into steps S21-S27, specifically including: S21. Randomly select four distinct prime numbers, multiply these four distinct prime numbers to calculate the composite security modulus, and calculate the Euler's totient function value of the composite security modulus based on the composite security modulus: S22. Randomly select a positive integer that is coprime to the Euler's totient function of the composite security modulus between the smallest prime number 1 and the Euler's totient function value of the composite security modulus, and use it as the public key exponent; S23. Based on the composite security modulus, select a prime number that is coprime to the composite security modulus as the additional security modulus; S24. Based on the public key exponent, calculate the modular inverse of the Euler's totient function value with respect to the composite security modulus, and use it as the private key exponent; S25. Combine the composite security modulus, the public key exponent, and the additional security modulus to form a global public key; combine the Euler's totient function value of the composite security modulus and the private key exponent to form a global private key; and generate a pair of global master keys based on the global public key and the global private key. S26. The metro network fusion feature data is divided into blocks to obtain multiple metro network data blocks, wherein the number of metro network data blocks is less than the composite security modulus; S27. Obtain a preset enhanced encryption algorithm, randomly generate a symmetric session key based on the global public key in the global master key, and use the symmetric session key and the enhanced encryption algorithm to encrypt each of the subway network data blocks to obtain multiple subway network ciphertext data blocks.

[0025] In one possible implementation, step S2 involves enhancing the encryption of the symmetric session key using the global master key to obtain session key ciphertext. The session key ciphertext and each of the subway network ciphertext data blocks are then combined to form multiple multi-layered subway network encrypted data packets. This can be, but is not limited to, decomposed into the following steps S28-S29, specifically including: S28. Using the global public key in the global master key, the symmetric session key is encrypted using the enhanced encryption algorithm to obtain the session key ciphertext; S29. Use the session key ciphertext as outer layer data, use each of the subway network ciphertext data blocks as inner layer data, and combine the outer layer data and the inner layer data into multiple multi-layer subway network encrypted data packets.

[0026] It should be noted that the secure storage method provided in this embodiment uses an enhanced encryption algorithm to perform block encryption on the metro network fusion feature data, avoiding the impact of simple encryption algorithms on the data storage security of the metro network. Through multi-layer encryption, the encryption of the metro network fusion feature data and the symmetric session key are achieved, which greatly increases the complexity of the encryption algorithm and eliminates the possibility of reverse reasoning. Furthermore, the symmetric session key is generated using a symmetric encryption algorithm (such as AES-256-GCM, i.e., Advanced Encryption Standard with a 256-bit keyin Galois / Counter Mode), providing confidentiality and integrity authentication for the symmetric session key.

[0027] Furthermore, the secure storage in this embodiment is a distributed storage system based on blockchain, which enables subway data to be distributed and stored across numerous nodes in the network. This provides resistance to single points of failure and DDoS (Distributed Denial of Service) attacks, ensuring that the data remains available and intact even if some storage nodes fail.

[0028] In one possible implementation, in step S2, the enhanced encryption algorithm includes a basic encryption function and an enhanced encryption function; Accordingly, in step S27, the symmetric session key and the enhanced encryption algorithm are used to encrypt each of the subway network data blocks to obtain multiple subway network ciphertext data blocks, including: S271. Using the aforementioned basic encryption function, perform basic encryption calculations on each of the metro network data blocks using the following formula (1): (1) in, This represents the index number of each of the aforementioned subway network data blocks. This represents the metro network fusion feature data in each of the aforementioned metro network data blocks. The public key index, For the composite safety modulus, This represents the modulo operation. This represents each of the aforementioned subway network data blocks after basic encryption processing; S272. Using the enhanced encryption function, each of the metro network data blocks after basic encryption processing is processed by the following formula (2). Perform enhanced encrypted computation: (2) in, For hash functions, For the additional security module, For each of the aforementioned subway network data blocks, the timestamp is... This indicates a concatenation operation. This represents the XOR operation. This refers to each of the subway network data blocks after enhanced encryption processing, and each of the subway network data blocks after enhanced encryption processing... As encrypted data blocks for various subway networks; Accordingly, in step S28, using the global public key from the global master key, the symmetric session key is encrypted using the enhanced encryption algorithm to obtain the session key ciphertext, which includes: Using the enhanced encryption function, the various subway network data blocks after basic encryption processing are processed by the following formula (3). Perform enhanced encrypted computation: (3) in, This refers to the symmetric session key. For a random number, This represents the ciphertext of the session key obtained after encryption.

[0029] Specifically, in this embodiment, the hash function can be the SHA-256 (Secure Hash Algorithm 256-bit) secure hash algorithm.

[0030] S3. Multiple subway network management agencies are used as consensus nodes. A subway consortium blockchain network is established based on the consensus nodes. The encrypted data packets of the multi-layer subway network are distributed and stored in the subway consortium blockchain network. The subway consortium blockchain network is dynamically managed by a preset smart storage contract. The smart storage contract includes an encrypted data registration contract, a network access control contract, and a key storage management contract. In one possible implementation, before establishing a subway consortium blockchain network by using multiple subway network management agencies as consensus nodes in step S3, the following steps S301-S303 may also be included, but are not limited to: S301. Obtain a preset homomorphic encryption algorithm, and use the homomorphic encryption algorithm to generate a pair of homomorphic encryption master keys; S302. Use the homomorphic encryption master key to perform homomorphic encryption on the metro network fusion feature data to obtain a homomorphic computation key; S303. Encrypt each of the subway network data blocks using the homomorphic computation key to obtain multiple homomorphic subway network ciphertext data.

[0031] It should be noted that this embodiment achieves proactive and adaptive all-round protection by integrating distributed blockchain storage, multi-layer dynamic encryption, and homomorphic encryption computation. Blockchain technology ensures the immutability of the root hash value and permission policies, eliminating the possibility of data forgery or deletion at the source. The introduction of homomorphic encryption technology allows for direct computation of encrypted subway network data, meeting operational analysis needs while ensuring the leakage of original data, thus forming a secure storage architecture that provides reliable evidence, dynamic protection, and privacy-preserving computation.

[0032] In one possible implementation, step S3 involves using multiple subway network management agencies as consensus nodes, establishing a subway consortium blockchain network based on these nodes, distributing and storing the encrypted data packets of each multi-layered subway network within the consortium blockchain network, and dynamically managing permissions of the subway consortium blockchain network using a preset smart storage contract. This can be broken down into, but is not limited to, the following steps S31-S36, specifically including: S31. Multiple metro network management agencies are used as consensus nodes, and multiple metro network application servers are used as data storage nodes. The metro network management agencies include metro operation management agencies, metro signal management agencies, and metro power supply management agencies. The metro network application servers include metro station servers, depot servers, and metro control center servers. S32. Obtain preset consensus network parameters, and establish a consensus network based on each consensus node and each data storage node, as the subway consortium blockchain network; S33. Add a globally unique identifier to each of the multi-layer subway network encrypted data packets, and calculate the root hash value of each of the multi-layer subway network encrypted data packets based on the globally unique identifier of each of the multi-layer subway network encrypted data packets; S34. Multiple data storage transactions are constructed in the metro consortium blockchain network. Each data storage transaction is signed using the private key of each storage node, and the signed data storage transactions are broadcast to the metro consortium blockchain network. Each data storage transaction is used to store a multi-layer metro network encrypted data packet. S35. Consensus verification is performed on the signatures of each data storage transaction through each of the data storage nodes, and the data storage transactions that have passed consensus verification are input to the corresponding data storage nodes to complete distributed storage; S36. Obtain a preset smart storage contract, and use the smart storage contract to distribute and verify permissions to each data requester, thereby realizing dynamic permission management of the metro consortium blockchain network.

[0033] It should be noted that the smart storage contract provided in this embodiment encodes complex access control, key distribution, and lifecycle management policies into automatically executed programs, eliminating errors and delays that may be caused by manual intervention and ensuring absolute consistency and transparency in policy execution. All operations are recorded, simplifying compliance reviews and security incident tracing, and significantly reducing the operation and maintenance costs of subway data storage.

[0034] S4. Obtain the data access request from the authorized party, and query and decrypt the accessed subway network data based on the smart storage contract.

[0035] In one possible implementation, step S4, obtaining the data access request from the authorized party, and querying and decrypting the accessed subway network data based on the smart storage contract, can be broken down into steps S41-S48, specifically including: S41. Obtain the data call request issued by the authorized user and submit it to the Metro Alliance Chain Network, wherein the data call request includes at least the requested data ID, operation type (read / restore), request time, and authorized digital signature; S42. Verify the authorization party's digital signature in the data access request through the network access control contract in the smart storage contract to determine whether the user is the authorization party, and evaluate whether the user has the right to access the data content corresponding to the data ID at the time of the request through the smart storage contract. S43. After verification is completed, the key storage management contract in the smart storage contract is started, the corresponding session key ciphertext is distributed to the user, and the session key ciphertext is encrypted using the user's public key to generate a one-time key package; S44. The key package is returned to the user, who submits a parallel decryption job to the Metro Consortium Blockchain Network to form a decryption driver program. The input parameters of the decryption driver program include the key package and a list of off-chain data addresses to be decrypted, and the list of off-chain data addresses to be decrypted is obtained through the Metro Consortium Blockchain Network. S45. The decryption driver obtains the private key in the global master key, and uses the private key to decrypt the key packet to obtain the session key ciphertext. The decryption driver distributes multiple decryption tasks and pulls subway network ciphertext data blocks from each of the data storage nodes in parallel according to the list of off-chain data addresses to be decrypted. S46. Use the session key ciphertext and the corresponding decryption algorithm (e.g., AES-256-GCM) to decrypt each of the subway network ciphertext data blocks to obtain multiple subway network data blocks; S47. Extract data from each of the subway network data blocks and perform integrity verification (calculate the hash value of each of the subway network data blocks and compare it with the original hash queried from the subway consortium blockchain network) to reassemble the data that has passed the integrity verification to form decrypted data; S48. Send the decrypted data to the user to complete the data retrieval.

[0036] like Figure 2 As shown, the second aspect of this embodiment provides a hardware system for implementing the subway network data secure storage method described in the first aspect of the embodiment, including: The metro data acquisition unit is used to acquire raw multi-source heterogeneous metro network data, perform data preprocessing and standardization on the raw multi-source heterogeneous metro network data to obtain standard multi-source heterogeneous metro network data, extract multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data, and perform feature fusion processing on the multi-source heterogeneous metro network feature data to obtain metro network fused feature data. The data enhancement encryption unit is used to generate a pair of global master keys for the metro network fusion feature data, randomly generate a symmetric session key using the global master key, and use the symmetric session key to perform block encryption on the metro network fusion feature data to obtain multiple metro network ciphertext data blocks. The global master key is then used to enhance the encryption of the symmetric session key to obtain session key ciphertext. The session key ciphertext and each of the metro network ciphertext data blocks are combined into multiple multi-layer metro network encrypted data packets. The data on-chain storage unit is used to establish a metro consortium blockchain network based on multiple metro network management agencies as consensus nodes, and to distribute and store the encrypted data packets of the multi-layer metro network in the metro consortium blockchain network. It also uses a preset smart storage contract to dynamically manage the permissions of the metro consortium blockchain network. The smart storage contract includes an encrypted data registration contract, a network access control contract, and a key storage management contract. The data retrieval management unit is used to obtain data retrieval requests from authorized parties and, based on the smart storage contract, to query and decrypt the retrieved subway network data.

[0037] The working process, working details and technical effects of the system provided in this embodiment can be found in the first aspect of the embodiment, and will not be repeated here.

[0038] like Figure 3 As shown, the third aspect of this embodiment provides an electronic device, including: a memory, a processor, and a transceiver that are sequentially and communicatively connected, wherein the memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the subway network data security storage method as described in the first aspect of the embodiment.

[0039] For specific examples, the memory may include, but is not limited to, random access memory (RAM), read-only memory (ROM), flash memory, first-in-first-out (FIFO) memory, and / or first-in-last-out (FILO) memory, etc.; specifically, the processor may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor may be implemented using at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), PLA (Programmable Logic Array). The processor may also include a main processor and a coprocessor. The main processor, also known as the CPU (Central Processing Unit), is used to process data in the wake-up state; the coprocessor is a low-power processor used to process data in the standby state.

[0040] In some embodiments, the processor may integrate a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the screen. For example, the processor may not be limited to microprocessors of the STM32F105 series, reduced instruction set computer (RISC) microprocessors, x86 architecture processors, or processors with integrated neural network processing units (NPUs). The transceiver may be, but is not limited to, a Wi-Fi transceiver, a Bluetooth transceiver, a General Packet Radio Service (GPRS) transceiver, a ZigBee transceiver (a low-power LAN protocol based on the IEEE 802.15.4 standard), a 3G transceiver, a 4G transceiver, and / or a 5G transceiver. Furthermore, the device may also include, but is not limited to, a power module, a display screen, and other necessary components.

[0041] The working process, working details and technical effects of the electronic device provided in this embodiment can be found in the first aspect of the embodiment, and will not be repeated here.

[0042] The fourth aspect of this embodiment provides a storage medium that stores instructions containing the subway network data security storage method described in the first aspect of the embodiment. That is, the storage medium stores instructions that, when executed on a computer, perform the subway network data security storage method as described in the first aspect of the embodiment.

[0043] The storage medium refers to a carrier for storing data, which may include, but is not limited to, floppy disks, optical disks, hard disks, flash memory, USB flash drives, and / or Memory Sticks. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices.

[0044] The working process, working details and technical effects of the storage medium provided in this embodiment can be found in the first aspect of the embodiment, and will not be repeated here.

[0045] The fifth aspect of this embodiment provides a computer program product containing instructions that, when executed on a computer, cause the computer to perform the subway network data security storage method as described in the first aspect of this embodiment, wherein the computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0046] Finally, it should be noted that the above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for securely storing data in a subway network, characterized in that, include: The process involves acquiring raw multi-source heterogeneous metro network data, performing data preprocessing and standardization on the raw multi-source heterogeneous metro network data to obtain standard multi-source heterogeneous metro network data, extracting multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data, and performing feature fusion processing on the multi-source heterogeneous metro network feature data to obtain metro network fused feature data. For the metro network fusion feature data, a pair of global master keys is generated. Using the global master keys, a symmetric session key is randomly generated. The symmetric session key is used to encrypt the metro network fusion feature data in blocks to obtain multiple metro network ciphertext data blocks. The global master key is then used to enhance the encryption of the symmetric session key to obtain session key ciphertext. The session key ciphertext and each of the metro network ciphertext data blocks are combined to form multiple multi-layer metro network encrypted data packets. Multiple subway network management agencies are used as consensus nodes. A subway consortium blockchain network is established based on these consensus nodes. Encrypted data packets of the multi-layered subway network are distributed and stored in the subway consortium blockchain network. A preset smart storage contract is used to dynamically manage the permissions of the subway consortium blockchain network. The smart storage contract includes an encrypted data registration contract, a network access control contract, and a key storage management contract. Obtain the data access request from the authorized party, and query and decrypt the accessed subway network data based on the smart storage contract.

2. The subway network data secure storage method according to claim 1, characterized in that, The process involves acquiring raw multi-source heterogeneous metro network data, performing data preprocessing and standardization on the raw multi-source heterogeneous metro network data to obtain standard multi-source heterogeneous metro network data, extracting multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data, and performing feature fusion processing on the multi-source heterogeneous metro network feature data to obtain metro network fused feature data, including: Using a data acquisition interface, raw subway network data from multiple key data systems of the subway network are collected in real time. These key data systems include the train control data system, the ticketing and ticket checking data system, and the video surveillance data system. Add timestamps and source identifiers to the original subway network data of each key data system, so that the original subway network data of each key data system with added timestamps and source identifiers can be used as the original multi-source heterogeneous subway network data. The source identifier is used to characterize the key data system that is the source of the original subway network data. The original multi-source heterogeneous subway network data is filled with missing values ​​and outliers are removed to obtain pre-multi-source heterogeneous subway network data. The privacy information of the pre-multi-source heterogeneous metro network data is obfuscated to obtain multi-source heterogeneous metro network data; Obtain a preset data structure format, use the data structure format to standardize the multi-source heterogeneous subway network data, and align the standardized multi-source heterogeneous subway network data according to the timestamp to obtain standard multi-source heterogeneous subway network data. Obtain preset data feature types, and extract various multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data according to the data feature types. The data feature types include operation efficiency features, metro passenger flow features, equipment status features, and video semantic features. Each of the multi-source heterogeneous subway network feature data is quantized into feature vectors, and each feature vector is concatenated into a high-dimensional feature concatenation vector. Then, the high-dimensional feature concatenation vector is mapped to a low dimension using principal component analysis to obtain a low-dimensional feature concatenation vector. The low-dimensional feature splicing vector is normalized to obtain the subway network fusion feature data.

3. The method for secure storage of subway network data according to claim 1, characterized in that, For the metro network fusion feature data, a global master key is generated. Using the global master key, a symmetric session key is randomly generated. The symmetric session key is then used to encrypt the metro network fusion feature data in blocks, resulting in multiple metro network ciphertext data blocks, including: Four distinct prime numbers are randomly selected. The composite security modulus is calculated by multiplying these four distinct prime numbers together. Based on the composite security modulus, the Euler's totient function value of the composite security modulus is then calculated. A positive integer coprime to the Euler's totient function of the composite security modulus is randomly selected between the smallest prime number 1 and the Euler's totient function value of the composite security modulus, and used as the public key exponent. Based on the composite security modulus, a prime number that is coprime to the composite security modulus is selected as the additional security modulus; Based on the public key exponent, the modular inverse of the Euler's totient function value with respect to the composite security modulus is calculated and used as the private key exponent; The composite security modulus, the public key exponent, and the additional security modulus are combined to form a global public key. The Euler's totient function value of the composite security modulus and the private key exponent are combined to form a global private key. Based on the global public key and the global private key, a pair of global master keys is generated. The fused feature data of the subway network is divided into blocks to obtain multiple subway network data blocks, wherein the number of subway network data blocks is less than the composite security modulus; A preset enhanced encryption algorithm is obtained. Based on the global public key in the global master key, a symmetric session key is randomly generated. Using the symmetric session key and the enhanced encryption algorithm, each of the subway network data blocks is encrypted to obtain multiple subway network ciphertext data blocks.

4. The subway network data secure storage method according to claim 3, characterized in that, The symmetric session key is enhanced and encrypted using the global master key to obtain session key ciphertext. The session key ciphertext and each of the subway network ciphertext data blocks are then combined to form multiple multi-layered subway network encrypted data packets, including: Using the global public key from the global master key, the symmetric session key is encrypted using the enhanced encryption algorithm to obtain the session key ciphertext; The session key ciphertext is used as the outer layer data, and each of the subway network ciphertext data blocks is used as the inner layer data. The outer layer data and the inner layer data are combined into multiple multi-layer subway network encrypted data packets.

5. The subway network data secure storage method according to claim 4, characterized in that, The enhanced encryption algorithm includes a basic encryption function and an enhanced encryption function; Accordingly, using the symmetric session key and the enhanced encryption algorithm, each of the subway network data blocks is encrypted to obtain multiple subway network ciphertext data blocks, including: Using the aforementioned basic encryption function, basic encryption calculations are performed on each of the metro network data blocks using the following formula (1): (1) in, This represents the index number of each of the aforementioned subway network data blocks. This represents the metro network fusion feature data in each of the aforementioned metro network data blocks. The public key index, For the composite safety modulus, This represents the modulo operation. This represents each of the aforementioned subway network data blocks after basic encryption processing; Using the enhanced encryption function, the various subway network data blocks after basic encryption processing are processed by the following formula (2). Perform enhanced encrypted computation: (2) in, For hash functions, For the additional security module, For each of the aforementioned subway network data blocks, the timestamp is... This indicates a concatenation operation. This represents the XOR operation. This refers to each of the subway network data blocks after enhanced encryption processing, and each of the subway network data blocks after enhanced encryption processing... As encrypted data blocks for various subway networks; Accordingly, using the global public key from the global master key, the symmetric session key is encrypted using the enhanced encryption algorithm to obtain the session key ciphertext, which includes: Using the enhanced encryption function, the various subway network data blocks after basic encryption processing are processed by the following formula (3). Perform enhanced encrypted computation: (3) in, This refers to the symmetric session key. For a random number, This represents the ciphertext of the session key obtained after encryption.

6. The subway network data secure storage method according to claim 3, characterized in that, Before establishing a subway consortium blockchain network by using multiple subway network management agencies as consensus nodes, the following steps are also included: Obtain a preset homomorphic encryption algorithm, and use the homomorphic encryption algorithm to generate a pair of homomorphic encryption master keys; The homomorphic encryption master key is used to homomorphically encrypt the fused feature data of the subway network to obtain a homomorphic computation key; The homomorphic computation key is used to encrypt each of the subway network data blocks to obtain multiple homomorphic subway network ciphertext data.

7. The method for securely storing subway network data according to claim 1, characterized in that, Multiple subway network management agencies serve as consensus nodes, and a subway consortium blockchain network is established based on these nodes. Encrypted data packets from each of the multi-layered subway networks are distributed and stored within this consortium blockchain network. A pre-set smart storage contract is used to dynamically manage permissions within the consortium blockchain network, including: Multiple metro network management agencies are used as consensus nodes, and multiple metro network application servers are used as data storage nodes. The metro network management agencies include metro operation management agencies, metro signal management agencies, and metro power supply management agencies. The metro network application servers include metro station servers, depot servers, and metro control center servers. Obtain preset consensus network parameters, and establish a consensus network based on each consensus node and each data storage node, as the metro consortium blockchain network; A globally unique identifier is added to each of the multi-layer subway network encrypted data packets, and the root hash value of each multi-layer subway network encrypted data packet is calculated based on the globally unique identifier of each multi-layer subway network encrypted data packet. Multiple data storage transactions are constructed in the metro consortium blockchain network. Each data storage transaction is signed using the private key of each storage node, and the signed data storage transactions are broadcast to the metro consortium blockchain network. Each data storage transaction is used to store a multi-layer metro network encrypted data packet. The signatures of each data storage transaction are verified through consensus by each of the data storage nodes, and the data storage transactions that have passed the consensus verification are input to the corresponding data storage nodes to complete distributed storage. Obtain a preset smart storage contract, and use the smart storage contract to distribute and verify permissions to each data requester, thereby realizing dynamic permission management of the metro consortium blockchain network.

8. A secure data storage system for a subway network, characterized in that, The method for securely storing subway network data as described in any one of claims 1 to 7 includes: The metro data acquisition unit is used to acquire raw multi-source heterogeneous metro network data, perform data preprocessing and standardization on the raw multi-source heterogeneous metro network data to obtain standard multi-source heterogeneous metro network data, extract multi-source heterogeneous metro network feature data from the standard multi-source heterogeneous metro network data, and perform feature fusion processing on the multi-source heterogeneous metro network feature data to obtain metro network fused feature data. The data enhancement encryption unit is used to generate a pair of global master keys for the metro network fusion feature data, randomly generate a symmetric session key using the global master key, and use the symmetric session key to perform block encryption on the metro network fusion feature data to obtain multiple metro network ciphertext data blocks. The global master key is then used to enhance the encryption of the symmetric session key to obtain session key ciphertext. The session key ciphertext and each of the metro network ciphertext data blocks are combined into multiple multi-layer metro network encrypted data packets. The data on-chain storage unit is used to establish a metro consortium blockchain network based on multiple metro network management agencies as consensus nodes, and to distribute and store the encrypted data packets of the multi-layer metro network in the metro consortium blockchain network. It also uses a preset smart storage contract to dynamically manage the permissions of the metro consortium blockchain network. The smart storage contract includes an encrypted data registration contract, a network access control contract, and a key storage management contract. The data retrieval management unit is used to obtain data retrieval requests from authorized parties and, based on the smart storage contract, to query and decrypt the retrieved subway network data.

9. An electronic device, characterized in that, The device includes a memory, a processor, and a transceiver that are sequentially and communicatively connected. The memory is used to store a computer program, the transceiver is used to send and receive messages, and the processor is used to read the computer program and execute the subway network data security storage method as described in any one of claims 1 to 7.

10. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or the instructions are executed by the computer, they implement the subway network data security storage method as described in any one of claims 1 to 7.