SMS Encryption Transmission and Trusted Sending Methods and Systems
By constructing an event context set and generating a causal envelope to generate a sending key, the SMS message is encrypted and encapsulated, solving the problem of the inability to verify the legitimacy and authenticity of SMS messages in edge data transmission, and realizing the reliable sending of SMS messages and the suppression of false alarms.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN GUANZHUO INFORMATION TECH CO LTD
- Filing Date
- 2026-03-12
- Publication Date
- 2026-06-02
AI Technical Summary
In edge data transmission, existing technologies cannot effectively verify whether SMS messages were generated by legitimate devices under real-world conditions, leading to false alarms and mishandling.
By constructing an event context set and an event causal envelope, a sending key bound to this sending action is generated, the SMS service data is encrypted and encapsulated, and combined with the receiver's consistency verification, the reliable sending of SMS messages is ensured.
When SMS link capabilities are limited and the sender cannot be continuously online, the receiver can confirm that the SMS comes from a legitimate device and corresponds to the sending behavior of the current real event, reducing the risk of replaying old SMS and false linkage, and improving the interpretability and verifiability of SMS and the on-site status.
Smart Images

Figure CN122138158A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication transmission and information security technology, and more specifically, to a method and system for encrypted transmission and trusted sending of SMS messages. Background Technology
[0002] In edge data transmission services, SMS is usually used as a supplementary channel after the main link fails. Therefore, the existing technology first solves the problem of not leaking SMS content and not sending SMS messages by arbitrarily. Common practices include encrypting or verifying the integrity of SMS content, and then combining it with methods such as binding the sending number, verifying the device identity, identifying the gateway side, or verifying the signature on the platform side to confirm as much as possible that the SMS message comes from a registered device or a connected sending channel. In general scenarios, this approach can reduce the risk of SMS messages being tampered with or forged. However, in practical applications, such as when mountain pumping stations, power distribution terminals, or unattended monitoring equipment transmit alarm information via SMS, they often face limitations such as limited SMS length, long-term offline terminal, unstable on-site clock, inability of equipment to connect to the central authentication platform in real time, and the need for SMS messages to be stored and forwarded by operators and transmitted through multiple intermediate nodes. Under these restrictions, although the receiving end can determine that the text message appears to come from a legitimate device or legitimate channel, it is difficult to further determine whether the text message was actually generated by that device in response to the current real-world event at the current moment. As a result, a verifiable phenomenon will continue to occur in the field: old text messages will be resent even if the content and verification relationship still hold true; text messages sent by legitimate numbers or legitimate gateways will be inconsistent with the actual situation on the field; and text messages generated by the same type of alarm under different field causes will appear to have no essential difference on the receiving end. This will ultimately lead to false alarms, mishandling, or even incorrect linkage. The reason for this is that the existing technology mainly solves the problem of whether the text message itself is secure and whether the sender's identity is registered, but it does not further solve the one-to-one correspondence between the text message sending behavior and the real-world event on the field. Therefore, the technical problem to be solved by this application is: how to enable the receiving end to confirm that the received SMS message not only comes from a legitimate device, but also corresponds to the sending behavior of that device under the current real-world event, under edge data transmission conditions, where SMS link capacity is limited and the sending end cannot be continuously online. Summary of the Invention
[0003] To overcome the aforementioned deficiencies of the prior art, embodiments of the present invention provide a method and system for encrypted transmission and trusted sending of SMS messages. By constructing an event context set and an event causal envelope, a sending key bound to the current sending behavior is generated, SMS service data is encrypted and encapsulated, and combined with receiver consistency verification and validity confirmation, the receiver can determine whether the SMS message was generated by a legitimate device in response to a real event, thereby solving the problems mentioned in the background art.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a method for encrypted transmission and trusted delivery of SMS messages, comprising: S1, Input current on-site event data, current device status data, SMS template identifier and target recipient identifier, perform association and organization, and output event context set; S2 takes the event context set and the preceding state summary as input, performs causal correlation calculation, and outputs the event causal envelope; S3, input the event causal envelope and encryption key material, perform derivation calculations, and output the key for this transmission; S4: Input the SMS service data to be sent, the event causal envelope and the sending key, perform encryption processing and verification fragment extraction, and output the trusted SMS payload; S5, input the trusted SMS payload and the target recipient identifier, send the SMS, and output the sending completion status; S6, input trusted SMS payload, target recipient identifier and historical status information, perform consistency verification, and output the results of the sender authenticity determination, the send timing legitimacy determination and the event context consistency determination. S7 takes as input the results of the authenticity determination of the sending entity, the legitimacy determination of the sending timing, and the consistency determination of the event context, performs validity verification, and outputs a trusted sending confirmation result.
[0005] In a preferred embodiment, S1 includes: S1-1: Input current on-site event data, current device status data, SMS template identifier and target recipient identifier, perform field standardization mapping and missing item constraint screening, and output candidate context field set and field completeness flag; S1-2, Input candidate context field set, field completeness flag and preset business constraint set, construct field filtering target with event trigger validity, sending semantic limitation and receiving object legality as constraints, perform candidate field pruning and redundant field suppression calculation, and output initial context subset; S1-3: Input the initial context subset, current field event data, and current device status data; perform event perspective consistency verification and status perspective consistency verification; perform conflict location, priority judgment, and conflict resolution on conflict fields; and output the consistency correction context subset and conflict resolution flag.
[0006] In a preferred embodiment, S1 further includes: S1-4, Input the consistency correction context subset, the SMS template identifier and the target receiving object identifier, perform template semantic slot matching calculation and receiving object constraint projection calculation, and output the sending constraint context subset; S1-5, Input the sending constraint context subset and preset resource limit parameters, perform hierarchical compression coding calculation constrained by SMS payload length, perform recoverability error boundary determination on the compression reserved fields, and output resource-constrained context expression fragment and error control flag; S1-6, Input the resource-constrained context expression fragment, the consistency correction context subset and the conflict resolution flag, perform multiple rounds of confidence review and stopping condition determination calculation, and output the event context set when the field confidence meets the preset threshold and the context stability meets the convergence condition. In a preferred embodiment, S2 includes: S2-1 takes the event context set and the previous state summary as input, performs field destructuring, time sequence alignment and association domain mapping, and outputs the current event fragment set, the historical successor fragment set and the corresponding association index; S2-2, Input the current event fragment set, the historical inherited fragment set and the preset causal constraint set, construct a candidate causal path solution model with the goal of minimizing the cost of event triggering, minimizing the cost of state transition breakage and minimizing the cost of sending timing conflict, perform multi-path search and constraint filtering, and output the candidate causal path set and path cost sequence. S2-3, Input the candidate causal path set, the path cost sequence and the association index, perform multi-perspective consistency verification from the event perspective, state perspective and sending perspective, and perform conflict location, conflict attribution and conflict resolution on inconsistent paths, and output a consistent causal path set and conflict correction flag. S2-4, Input the consistent causal path set, the preceding state summary and the preset uncertainty model, perform path confidence estimation, abnormal transfer probability update and historical acceptance confidence correction, and output the confidence-enhanced causal path set and the corresponding path confidence sequence; S2-5, Input the confidence-enhanced causal path set, the path confidence sequence and the preset convergence criterion, perform iterative pruning and stability determination, and output the target causal path when the path confidence increment is lower than the preset threshold and the path ranking stability meets the stopping condition; S2-6, Input the target causal path, the conflict correction flag and the preceding state summary, perform trigger chain segment encoding, succession chain segment encoding and sending constraint chain segment encoding, and output the initial event causal envelope; S2-7, Input the initial event causal envelope and preset resource limit parameters, perform layered compression and recoverability verification under load length constraints, and output the event causal envelope when the envelope compression error meets the preset boundary.
[0007] In a preferred embodiment, S3 includes: S3-1: Input the event causal envelope and encryption key material, perform causal field deconstruction, key material domain mapping and constraint association calculation, construct a multi-domain derivation model with the goal of maximizing event binding strength, minimizing cross-event reuse risk and minimizing key exposure and diffusion cost, and output the candidate derivation factor set and corresponding constraint weights. S3-2, Input the candidate derived factor set, the constraint weights and the preset uncertainty evaluation rules, perform multiple rounds of factor screening, conflict factor suppression and derived stability confidence update, and output the target derived factor set when the confidence increment between two adjacent rounds is lower than the preset threshold and the remaining factor set satisfies the minimum distinguishable constraint; S3-3, Input the target derivation factor set and the encryption key material, perform hierarchical combination derivation, inter-domain isolation calculation and recoverability consistency verification, and output the current transmission key that is uniquely bound to the event causal envelope and satisfies the preset length constraint and anti-reuse constraint.
[0008] In a preferred embodiment, S4 includes: S4-1: Input the SMS service data to be sent, the event causal envelope, and the sending key. Perform business field deconstruction, causal field alignment, and key scope mapping. Construct a load organization model with the goals of minimizing the semantic fidelity cost of SMS service, minimizing the loss of causal binding strength, and minimizing the risk of exceeding the load length limit. Output a hierarchical set of business segments, a set of causal binding segments, and corresponding organization weights. S4-2, Input the hierarchical service segment set, the causal binding segment set, the organization weight and the key for this transmission, perform segmented encryption calculation, cross-segment association verification calculation and redundancy conflict suppression calculation, and perform reorganization error correction and confidence update on segments that do not meet the consistency constraints based on the segmented verification results, and output the ciphertext segment set and the candidate verification segment set; S4-3, Input the ciphertext fragment set, the candidate verification fragment set and the preset resource limit parameters, perform payload compression and encapsulation, recoverability error boundary verification and stop condition determination, and output a reliable SMS payload when the length of the compressed payload meets the SMS transmission constraint and the fragment recovery error meets the preset boundary.
[0009] In a preferred embodiment, S5 includes: S5-1: Input the trusted SMS payload and the target recipient identifier, perform recipient constraint matching, sending path candidate generation and link cost evaluation, construct a sending decision model with the objectives of maximizing target delivery credibility, minimizing sending delay cost and minimizing link exposure risk, and output the target sending path and the corresponding path confidence. S5-2, Input the target sending path, the trusted SMS payload and the path confidence, perform segmented sending scheduling, receipt observation consistency verification and abnormal sending behavior conflict resolution, and perform iterative correction of the sending path confidence based on the observation results. When the path confidence increment between two adjacent rounds is lower than the preset threshold and the sending result meets the preset stability condition, output the target sending record. S5-3, Input the target sending record, the trusted SMS payload and the preset completion judgment rule, perform delivery evidence aggregation, payload integrity verification and completion status convergence judgment, and output the sending completion status.
[0010] In a preferred embodiment, S6 includes: S6-1: Input the trusted SMS payload, the target receiving object identifier and historical state information, deconstruct the payload field, map the receiving object constraint and align the historical state, construct a consistency discrimination model with the goal of minimizing the sending subject matching deviation, minimizing the sending timing conflict cost and minimizing the event context break cost, and output the candidate authenticity evidence set, candidate timing evidence set and candidate context evidence set. S6-2, Input the candidate authenticity evidence set, the candidate timing evidence set, the candidate context evidence set and the preset multi-perspective verification rules, perform cross-consistency verification of the sending subject perspective, time evolution perspective and event acceptance perspective, and perform conflict location, confidence backoff and alternative evidence compensation for conflict evidence, and output the authenticity verification evidence chain, timing verification evidence chain and context verification evidence chain. S6-3, Input the authenticity verification evidence chain, the timing verification evidence chain, the context verification evidence chain and the preset uncertainty update rule, perform multi-round confidence fusion, abnormal hypothesis elimination and convergence stop determination, and output the authenticity determination result of the sending subject, the legitimacy determination result of the sending timing and the event context consistency determination result when the confidence increment of two adjacent rounds of determination is lower than the preset threshold and the stability of the evidence chain meets the preset conditions.
[0011] In a preferred embodiment, S7 includes: S7-1: Input the results of the authenticity judgment of the sending entity, the legitimacy judgment of the sending timing, and the consistency judgment of the event context. Perform normalization mapping of the judgment results, assembly of related constraints, and conflict dependency analysis. Construct an effective confirmation model with the goal of minimizing the risk of false confirmation, minimizing the risk of missed confirmation, and minimizing the cost of the decision chain break. Output a set of candidate confirmation states and corresponding confirmation weights. S7-2, Input the candidate confirmation state set, the confirmation weight and the preset multi-condition linkage rule, perform cross-verification, consistency alignment and conflict resolution of the authenticity judgment result, the timing legitimacy judgment result and the context consistency judgment result, and perform abnormal hypothesis elimination and confirmation weight iterative correction based on the conflict resolution result, and output the confirmation evidence chain and the corresponding state confidence. S7-3, Input the confirmation evidence chain, the state confidence level and the preset convergence stopping condition, perform multi-round confidence fusion, boundary condition verification and final validity determination, and output a reliable transmission confirmation result when the state confidence increment of two adjacent rounds is lower than the preset threshold and the stability of the confirmation evidence chain meets the preset condition.
[0012] In a preferred embodiment, the SMS encrypted transmission and trusted delivery system includes an association modeling module, a causal encapsulation module, a key derivation module, an encryption encapsulation module, a path transmission module, a consistency verification module, and a valid confirmation module. The association modeling module is used to input current on-site event data, current equipment status data, SMS template identifiers, and target recipient identifiers, perform association and organization, and output an event context set. The causal encapsulation module is used to take the event context set and the preceding state summary as input, perform causal correlation calculations, and output the event causal envelope; The key derivation module is used to take the event causal envelope and encryption key material as input, perform derivation calculations, and output the key for this transmission. The encryption payload module is used to input the SMS service data to be sent, the event causal envelope, and the sending key, perform encryption processing and verification fragment extraction, and output a trusted SMS payload. The path sending module is used to input a trusted SMS payload and the target recipient identifier, send the SMS, and output the sending completion status. The consistency verification module is used to input trusted SMS payload, target recipient identifier and historical status information, perform consistency verification, and output the results of determining the authenticity of the sending entity, the legitimacy of the sending time and the consistency of the event context. The valid confirmation module is used to input the results of the authenticity judgment of the sending entity, the legitimacy judgment of the sending timing, and the consistency judgment of the event context, to perform validity confirmation, and output a reliable sending confirmation result.
[0013] The technical effects and advantages of this invention are as follows: By constructing a series of event context sets, event causal envelopes, and three types of consistency judgment results, a correspondence is established between SMS sending behavior and current real-world events. This allows the receiving end to confirm, in addition to verifying the legitimacy of the source, whether the SMS was indeed generated by the device at the current moment for this event, even when the sending end is offline for a long time and the link is restricted. This relatively suppresses the risks of replaying old SMS messages, legitimate link proxying, and false linkage. By associating and organizing current on-site event data, device status data, SMS template identifiers, and target recipient identifiers, and combining them with prior status summaries to generate event causal envelopes, the SMS content simultaneously carries event triggering relationships, status succession relationships, and sending constraints. This relatively improves the problem of difficulty in distinguishing similar alarms under different on-site causes, and enhances the interpretability and verifiability between SMS messages and on-site status. By generating a key for this transmission bound to this transmission behavior based on the event causal envelope and encryption key material, the scope of key use is further narrowed from device-level static identity constraints to the current event and the current transmission round, thereby relatively reducing the risk of cross-event reuse and mitigating the spread of local key leakage to other event transmission behaviors to a certain extent. By performing layered organization, segmented encryption, cross-segment correlation verification, and payload compression and encapsulation on the data to be sent for SMS services, the trusted SMS payload can still retain the core business semantics and causal binding relationship under the condition of limited SMS length. This relatively improves the reception verification capability in the case of SMS segmentation, out-of-order delivery, replacement, or fragment loss, and improves the feasibility of implementation in scenarios with limited links. By combining target recipient constraints, candidate sending paths, and link cost evaluation to select the sending path, and iteratively correcting the path confidence based on the acknowledgment observation results, the SMS sending process is changed from a single submission to a closed-loop scheduling with feedback, thereby relatively reducing the problems of path misselection, false completion judgment, and unstable sending results caused by link state fluctuations. By forming authenticity verification evidence chains, timing verification evidence chains, and context verification evidence chains based on historical state information at the receiving end, and performing cross-verification, abnormal hypothesis elimination, and boundary condition review in the final validity confirmation stage, the credible transmission confirmation result is supported by multi-dimensional evidence, thereby relatively improving the ability to identify abnormal situations such as replay transmission, delayed arrival, forged transmission, and historical transmission interruption. Attached Figure Description
[0014] Figure 1This is a flowchart of the present invention.
[0015] Figure 2 This is a schematic diagram of the system modules of the present invention. Detailed Implementation
[0016] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0017] Refer to the instruction manual appendix Figure 1-2 The SMS encrypted transmission and trusted sending method of the present invention includes: S1, Input current on-site event data, current device status data, SMS template identifier and target recipient identifier, perform association and organization, and output event context set; In this implementation, S1 is used to organize the current on-site event data, current device status data, SMS template identifier, and target recipient identifier into an event context set that can directly participate in subsequent causal correlation calculations. Since the original input in edge data transmission scenarios typically comes from different data sources, the field names, units, time granularity, and completeness are inconsistent, and there may also be issues such as missing fields, template mismatches, and inaccurate recipient mappings. Therefore, it is necessary to first complete field unification, missing data screening, business constraint trimming, and consistency correction to ensure that the data used in subsequent steps can accurately represent the current on-site event and meet the field completeness and semantic determinism required for reliable SMS transmission. This implementation process includes the following steps: For S1-1, after receiving the current on-site event data, current device status data, SMS template identifier, and target recipient identifier, the input fields are first standardized and mapped. Specifically, according to the preset field mapping table, synonymous fields in different device protocols, different acquisition units, or different reporting codes are uniformly converted into standard field names. The units of numerical fields are standardized, the time granularity of time fields is standardized, and the encoding of enumeration fields is standardized. For example, alarm codes reported by different sensors are uniformly mapped to event type fields, and millisecond-level and second-level times are uniformly converted to the same time base. After standardization, missing item constraint screening is performed according to the preset integrity rules. The fields are divided into required fields, enhanced fields, and optional fields. Among them, event type, event trigger time, SMS template identifier, and target recipient identifier are required fields, device online status, module status, and recent control status are enhanced fields, and the remaining descriptive fields are optional fields. Missing required fields are marked as not being able to directly enter the subsequent trusted sending process. Missing enhanced fields retain the missing mark and are allowed to enter the next step. Missing optional fields only record the null value status. Finally, the candidate context field set and field completeness mark are output. For S1-2, after obtaining the candidate context field set and field completeness marker, field filtering is performed in conjunction with a preset business constraint set. The preset business constraint set includes at least three types of constraints: event trigger validity, sending semantic limitation, and receiving object validity. Among them, event trigger validity is used to determine whether the candidate field can support the actual validity of this event. For example, the event type, threshold field, and current measurement value should meet the preset trigger relationship. Sending semantic limitation is used to ensure that the SMS template only expresses the current type of business semantics and avoids the mixing of alarm templates and maintenance status fields. Receiving object validity is used to determine whether the target receiving object matches the current event level, template category, and the business domain to which the device belongs. Based on the above constraints, the candidate context field set is pruned and redundant fields are suppressed. Fields that simultaneously support event validity, template expression, and receiving object validity are retained first, while fields that only repeatedly express the same business meaning or are obviously irrelevant to the current sending are deleted. For example, when there are both coded event descriptions and text-based event descriptions for the same event, the coded field used for template filling can be retained and redundant text fields can be suppressed. Finally, the initial context subset is output. For S1-3, after obtaining the initial context subset, it is checked for consistency with the current on-site event data and the current device status data to eliminate conflicts caused by edge-side acquisition delay, asynchronous status refresh, or template mismatch. The event perspective consistency check is used to check whether the event fields match, such as whether the event type and trigger value direction are consistent, whether the event time is within the allowed time window, and whether the SMS template identifier corresponds to the event category. The status perspective consistency check is used to check whether the event fields are compatible with the device status. For example, when the event indicates that the device has exceeded the limit and stopped, the device status should show a corresponding stop status, control status change, or module sendable status. For conflicting fields found in the check, conflict localization is first performed to determine whether the conflict occurs in the event domain, status domain, template domain, or receiving object domain. Then, it is judged according to the preset priority rules, prioritizing the retention of fields with more direct sources, closer time to the event trigger time, and higher completeness. Conflict resolution flags are generated for fields that are replaced, deleted, or corrected. Finally, the consistency correction context subset and conflict resolution flags are output. Through the above processing, S1 can output a set of event contexts with stable structure, clear semantics, and direct callability for subsequent causal association calculations, even under conditions of inconsistent original input sources, inconsistent field expressions, and complex on-site conditions. This reduces the impact of irrelevant, redundant, and conflicting fields on the construction of subsequent event causal envelopes, improving the accuracy and executability of the trusted SMS sending link. In practical applications, for example, in a scenario of level exceeding the limit alarm at a mountain pumping station, the system first obtains the level value, threshold number, and trigger time reported by the level sensor as the current on-site event data, then obtains the online status of the pumping station controller, the SMS module status, and the most recent start / stop status as the current equipment status data, and retrieves the relevant data. The alarm template identifier and the current monitored object identifier are then used. Subsequently, the alarm codes and time formats from different sources are uniformly mapped to standard fields. The necessary fields such as event type, trigger time, template identifier, and receiving object are screened out. Then, extended fields that are irrelevant to this transmission are deleted according to the over-limit alarm constraints, template semantic constraints, and receiving object authorization rules. If it is found that the event field shows high liquid level over-limit, but the equipment status field still retains the normal status from an earlier time, the latest status is retained according to the field time freshness and source priority, and a conflict resolution flag is generated. Finally, a consistency correction context subset that can accurately represent the liquid level alarm event, the current status of the equipment, and the range of receiving objects is formed for subsequent steps to continue to use.
[0018] S2 takes the event context set and the preceding state summary as input, performs causal correlation calculation, and outputs the event causal envelope; In this implementation, S2 is used to generate an event causal envelope based on the event context set and the preceding state summary, so that subsequent key derivation and trusted SMS sending no longer depend solely on the content of a single message, but simultaneously bind the current event, historical continuity, and sending constraints. Since SMS sending in edge data transmission scenarios often occurs under conditions of main link anomaly, long-term device offline status, or incomplete state update synchronization, it is necessary to first extract event-related fragments from the current data, then extract continuity fragments from the historical data, form candidate causal paths after unifying the time base and field domains, and filter out the target causal path that can reasonably explain the current sending behavior through multi-perspective verification, anomaly correction, confidence update, and convergence pruning. Finally, the path is encoded and compressed to form the event causal envelope. This implementation process includes the following steps: For S2-1, after obtaining the event context set and the preceding state summary, field destructuring is first performed. The event context set is split into event trigger field, device status field, template constraint field, and receiving object field. The preceding state summary is split into preceding event identifier field, preceding state result field, preceding transmission result field, and preceding time field. Then, timing alignment is performed. Using the current event trigger time as a unified benchmark, the time fields in the preceding state summary are converted to the same time granularity. Based on a preset time window, it is determined whether the field is within the current event's acceptable range. Historical fields outside the time window are only retained as weak association references. On this basis, association domain mapping is performed. Each field is divided into the event domain, status domain, and transmission domain. An association index is established based on the field name, field source, and time sequence. The association index is used to indicate the correspondence, time relationship, and domain relationship between the current field and the historical field. Finally, the current event fragment set, the historical accepted fragment set, and the corresponding association index are output. For S2-2, after obtaining the current event fragment set, the historical succession fragment set, and the preset causal constraint set, a candidate causal path solving model is constructed. The preset causal constraint set includes at least event triggering constraint, state continuity constraint, and reasonable sending timing constraint. The event triggering constraint is used to determine whether a complete triggering relationship is formed within the current event fragment. The state continuity constraint is used to determine whether there is a reasonable state connection between the historical succession fragment and the current event fragment. The reasonable sending timing constraint is used to determine whether the current SMS should be triggered and sent at the current time. Based on the above constraints, the current event fragment and the historical succession fragment are combined according to the association index to form multiple candidate causal paths, and the path cost is calculated for each. The event triggering cost represents the degree of non-satisfaction of the triggering relationship within the current event. The state transition break cost represents the degree of inability to reasonably connect the historical state and the current state. The sending timing conflict cost represents the degree of mismatch between the current sending time and the business sending conditions. The three types of costs are summed according to preset weights to obtain the total path cost. Finally, paths with a total path cost lower than a preset threshold are retained, and the candidate causal path set and path cost sequence are output. For S2-3, after obtaining the candidate causal path set, path cost sequence, and association index, consistency checks are performed on each candidate causal path from the event perspective, state perspective, and sending perspective. The event perspective checks whether the event type, triggering condition, and template category are consistent; the state perspective checks whether the preceding state, current state, and transition direction are consistent; and the sending perspective checks whether the template constraints, target receiving object, and sending timing are consistent. For inconsistent paths under any perspective, conflict localization is first performed to determine whether the conflict occurs in the event domain, state domain, or sending domain. Then, conflict attribution is performed to determine whether the conflict is caused by outdated historical states, field mapping deviations, improper template selection, or mismatched receiving object constraints. After attribution, conflict resolution is performed according to preset processing rules. Conflict correction markers are generated for the corrected paths. Conflict correction markers are used to record the conflict type, conflict cause, and correction action. Finally, a consistent causal path set and conflict correction markers are output. For S2-4, after obtaining the consistent causal path set, the preceding state summary, and the preset uncertainty model, the path confidence of each consistent causal path is estimated. Specifically, the initial path confidence is calculated based on the total path cost, the number of conflict corrections, the time freshness of historical segments, and the completeness of the preceding state summary. The lower the total path cost, the fewer the number of conflict corrections, the closer the historical segments are to the current event, and the more complete the preceding state summary, the higher the path confidence. Subsequently, the abnormal transition probability is updated according to the preset uncertainty model. The abnormal transition probability is used to characterize the possibility of abnormal situations such as replay, delay, state jump, or template mismatch. The probability is corrected according to the degree of deviation between the current path and the preceding state summary. On this basis, the historical continuity confidence is further corrected according to the continuity between the current event and the historical continuity. Finally, the confidence-enhanced causal path set and the corresponding path confidence sequence are output. For S2-5, after obtaining the set of confidence-enhanced causal paths and the path confidence sequence, iterative pruning and stability determination are performed. Specifically, the paths are first sorted by confidence, and the head paths are retained as the current set of valid paths. Then, the sorting results of the current round and the confidence increment of the head paths are compared. If the sorting changes significantly or the confidence increment of the head paths is still higher than the preset threshold, the confidence of each path is recalculated based on the updated abnormal transition probability and historical acceptance confidence, and the tail low-confidence paths are pruned. When the confidence increment of the head paths in two adjacent rounds is lower than the preset threshold and the path sorting stability meets the stopping condition, the iteration is stopped and the optimally sorted path is determined as the target causal path. Finally, the target causal path is output. For S2-6, after obtaining the target causal path, conflict correction flag, and preceding state summary, the target causal path is segmented and encoded, specifically including trigger chain segment encoding, succession chain segment encoding, and sending constraint chain segment encoding. The trigger chain segment records the key fields required for the current event to be triggered and their relationships. The succession chain segment records the succession relationship between the preceding state summary and the current event. The sending constraint chain segment records the correspondence between the SMS template identifier, the target recipient identifier, and the current sending behavior and business constraints. During encoding, each chain segment is serialized according to the preset field order and length rules, and the correction information involved in the conflict correction flag is appended as a correction description bit so that the existence and location of correction can be identified during subsequent verification. Finally, the initial event causal envelope is output. For S2-7, after obtaining the initial event causal envelope and preset resource limit parameters, layered compression and recoverability verification are performed on the initial event causal envelope. The preset resource limit parameters include at least the upper limit of the available payload length of the SMS, the chain compression priority, and the field retention level. During compression, key trigger fields in the trigger chain and core receiving fields in the receiving chain are retained in full first. Non-key fields in the sending constraint chain are compressed using index replacement, short code mapping, or differential encoding, and the compression mapping relationship is recorded. After compression, recoverability verification is performed based on the retained fields and the compression mapping relationship to check whether the basic relationship between the trigger chain, receiving chain, and sending constraint chain can still be recovered. If the recovery error exceeds the preset boundary, the compression strategy is adjusted and re-verified until the envelope compression error does not exceed the preset boundary while satisfying the payload length limit. Finally, the event causal envelope is output. Through the above processing, S2 can establish a continuous, verifiable, and compressible causal link between the current event and the historical state. This allows subsequent steps to complete reliable transmission based on the validity of event triggering, the continuity of state succession, and the rationality of the transmission timing, rather than relying solely on static identity or message ontology. This improves its resistance to replay, mismatch, and forgery. Simultaneously, through path cost calculation, multi-perspective consistency verification, anomaly probability correction, and convergence pruning, even when the historical state is incomplete or there are disturbances in the edge inputs, it can still output a structurally stable and semantically clear event causal envelope. In practical applications, for example, in a mountainous pump station level exceeding limit alarm scenario, the system first splits the event context set into level exceeding limit event fragments, pump current state fragments, alarm template fragments, and receiving object fragments. Then, it extracts the previous round of level state and pump start-up status from the preceding state summary. The system records the stop status and SMS sending results, aligning them with a unified time base. Multiple candidate causal paths are then generated, representing different interpretations such as a stable over-limit triggering alarm sending after a continuous rise in liquid level, or short-term fluctuations in liquid level before reaching the sending condition. The system calculates the event establishment cost, state breakage cost, and sending timing conflict cost for each path. For the selected paths, consistency checks are performed on the event perspective, state perspective, and sending perspective to correct conflicts caused by outdated historical states or mismatched template constraints. After confidence updates and multiple rounds of pruning, the optimal path is determined. The liquid level over-limit triggering relationship, pump state continuity relationship, and alarm sending constraints are then encoded and compressed within the SMS payload length limit. Finally, an event causal envelope representing the current liquid level over-limit event and its historical continuity is obtained, which can be used for subsequent key derivation and trusted SMS payload generation.
[0019] S3, input the event causal envelope and encryption key material, perform derivation calculations, and output the key for this transmission; In this implementation, S3 is used to generate the current sending key based on the event causal envelope and encryption key material, so that the key used for subsequent SMS encryption is bound to the current event, the current connection relationship, and the current sending constraint, instead of directly using a fixed key or a static key that is only related to the device identifier. Since the same device may trigger multiple similar events in the edge data transmission scenario, if the derivation rule only depends on the device identity or template category, it is easy to have problems such as cross-event reuse, the substitutability of historical keys, and the excessive impact of local leakage. Therefore, it is necessary to first extract the causal field that can distinguish the current sending behavior from the event causal envelope, and then construct a multi-domain derivation relationship by combining encryption key materials for different purposes. After screening and stability update, a target derivation factor set is formed, and then a current sending key that corresponds only to the current sending behavior is generated. This implementation process includes the following steps: For S3-1, after obtaining the event causal envelope and encryption key material, the event causal envelope is first deconstructed into causal fields, splitting it into trigger chain segment fields, succession chain segment fields, and sending constraint chain segment fields. The trigger chain segment field represents the triggering relationship of the current event, the succession chain segment field represents the succession relationship between the preceding state and the current event, and the sending constraint chain segment field represents the SMS template identifier, the target recipient identifier, and the business constraints corresponding to the current sending action. Simultaneously, the encryption key material is mapped into domains, dividing it into a device basic key domain, a business template key domain, and a sending round key domain. The device basic key domain provides device-level... Uniqueness is ensured by using a business template key field to distinguish different templates and business types, and a sending round key field to distinguish different sending rounds or different event instances. Subsequently, constraint association calculations are performed according to preset association rules to map various causal fields to their corresponding key fields, forming a multi-domain derivation model. Constraint weights are calculated for each candidate derivation factor, where event binding strength measures the factor's ability to distinguish the current event, cross-event reuse risk measures the likelihood that the factor will produce the same derivation result across different events, and key exposure and diffusion cost measures the impact range of the factor on other events or other rounds if it is leaked. Finally, a set of candidate derivation factors and their corresponding constraint weights are output. For S3-2, after obtaining the candidate derived factor set, constraint weights, and preset uncertainty assessment rules, the candidate derived factor set undergoes multiple rounds of screening. Specifically, firstly, the comprehensive score of each candidate derived factor is calculated based on the constraint weights. A higher comprehensive score indicates higher distinguishability of the current event, lower reuse risk, and smaller leakage and diffusion impact. Subsequently, conflicting factors are identified. Conflicting factors include factors that, while enhancing event binding, significantly increase reuse risk, as well as duplicate factors that express the same business meaning as already retained factors. Such conflicting factors are suppressed, i.e., their priority in participating in subsequent derivations is reduced. The factors are either selected at the first level or directly eliminated. After each round of screening, the derived stability is updated according to the preset uncertainty assessment rules. The derived stability can be determined by the change in the factor set, the change in the ranking of the head factors, and the increase in the comprehensive score. If the stability change between two adjacent rounds is still large, low-scoring factors and high-conflict factors are screened out until the confidence increment between two adjacent rounds is lower than the preset threshold and the remaining factor set satisfies the minimum distinguishable constraint. The minimum distinguishable constraint is used to ensure that the remaining factors can at least distinguish different event instances, different sending rounds, or different business templates. Finally, the target derived factor set is output. For S3-3, after obtaining the target derived factor set and encryption key material, a hierarchical combination derivation is performed. Specifically, the device basic key field is used as the first layer to generate basic derived values, the service template key field is used as the second layer to generate service derived values, and the sending round key field is used as the third layer to generate round derived values. The derived values of each layer are then synthesized in a preset order to obtain the candidate sending key for this time. During the combination process, inter-domain isolation calculations are performed to ensure that the intermediate derivation results of different key fields cannot be substituted for each other, and that the local information of any field cannot be used to deduce the complete sending key for this time. After obtaining the candidate sending key for this time, a recoverability consistency check is performed. Specifically, the derivation process is repeated based on the same event causal envelope and the same encryption key material to check whether the output results are consistent. The key is also verified according to the preset length constraint and anti-reuse constraint to see if it meets the subsequent SMS encryption requirements and whether different results are generated under different event causal envelopes. If not, the target derived factor set or hierarchical combination order is adjusted until the output is a sending key that is uniquely bound to the event causal envelope and meets the preset length constraint and anti-reuse constraint for this time. Through the above processing, S3 can incorporate the current event triggering relationship, historical inheritance relationship, and sending constraint relationship into the key generation process, ensuring that the sending key simultaneously possesses event uniqueness, round uniqueness, and business constraint characteristics. This avoids the cross-event reuse problem caused by fixed keys or single device keys. Simultaneously, through multi-domain derivation, conflict factor suppression, stability update, and inter-domain isolation control, the key's influence can be limited to the current sending behavior, reducing the cascading impact of local leakage on other events or other sending rounds, and improving the security and verifiability of subsequent SMS encryption processing. In practical applications: for example, in a mountainous pump station level over-limit alarm scenario, the system first extracts the level over-limit trigger field, pump start / stop inheritance field, alarm template, and target receiving object field from the event causal envelope, and then... The device master key, alarm template key, and sending round seed are mapped to the device basic key field, service template key field, and sending round key field, respectively. Then, based on the ability of each field to distinguish the current liquid level exceedance event and the risk of reuse for other events, a candidate derivation factor set is generated. Conflicting factors that repeatedly express the same alarm semantics or lead to cross-round reuse are eliminated. After multiple rounds of screening, the target derivation factor set that can jointly distinguish the current event, the current template, and the sending action of the current round is retained. Finally, the derivation is combined and derived in the order of device basic, template constraints, and round refinement. After inter-domain isolation and consistency verification, the sending key for this round is generated. This ensures that even if the same pump station experiences another liquid level exceedance event later, as long as the previous succession relationship or the sending round is different, a different sending key will be generated for continued use in the generation of subsequent trusted SMS payloads.
[0020] S4: Input the SMS service data to be sent, the event causal envelope and the sending key, perform encryption processing and verification fragment extraction, and output the trusted SMS payload; In this implementation, S4 is used to generate a trusted SMS payload based on the SMS service data to be sent, the event causal envelope, and the current sending key. This ensures that the content entering the SMS link can express the semantics of the current service, maintain its causal relationship with the current event, and meet the transmittability and verifiability requirements under the condition of limited SMS length. Since the SMS link length is limited in edge data transmission scenarios and there are risks of segmentation, out-of-order delivery, and fragment replacement, the original service data cannot be directly encrypted and sent as a whole. Instead, it is necessary to first complete the correspondence organization of service fields and causal fields, and then combine this sending key to perform segmented encryption, cross-segment verification, and compression encapsulation, thereby outputting a trusted SMS payload that can directly enter the SMS sending step. This implementation process includes the following steps: For S4-1, after obtaining the SMS service data to be sent, the event causal envelope, and the sending key, the service data to be sent is first deconstructed into core service fields, descriptive service fields, and auxiliary service fields. The core service fields directly express the main business semantics of the SMS, the descriptive service fields express supplementary information related to the current event, and the auxiliary service fields express optional extended information. Then, causal field alignment is performed on the event causal envelope, mapping the fields related to the SMS expression in the triggering chain, successor chain, and sending constraint chain to their corresponding service fields, ensuring that the core service fields correspond at least to the current event triggering relationship and sending constraint relationship. Based on this, key scope mapping is performed, i.e., according to... The hierarchical source relationship of the key sent in this study determines the encryption scope of each business field, binding strong encryption and verification constraints to core business fields, medium-strength constraints to business fields, and allowing downgrade processing for auxiliary business fields when their length is limited. Then, a payload organization model is constructed to calculate the organization weight of each field fragment. Among them, the semantic fidelity cost of SMS business is used to measure the impact of deleting or compressing the field on the semantic integrity of SMS, the causal binding strength loss is used to measure the degree of weakening of credibility after the field is removed from the event causal envelope, and the payload length exceeding the limit risk is used to measure the possibility of SMS exceeding the limit after retaining the field. The three factors are combined according to the preset weight to determine the field retention priority. Finally, the hierarchical business fragment set, the causal binding fragment set, and the corresponding organization weight are output. For S4-2, after obtaining the hierarchical business segment set, causal binding segment set, organizational weight, and the current transmission key, the segments are first sorted according to the organizational weight, and multiple segments to be encrypted are generated according to a preset length limit, ensuring that the business fields and causal fields within the same segment group correspond. Then, segmented encryption calculation is performed, specifically, each segment group is encrypted using the current transmission key or a segment subkey derived from the current transmission key, generating ciphertext segments corresponding to the segment group. After segmented encryption is completed, cross-segment association verification calculation is performed, that is, extracting the association digest between adjacent ciphertext segments, and combining the verification result of the previous segment and the current segment identifier. Together with the corresponding causal binding fragments, they form candidate verification fragments to prevent fragment rearrangement, fragment replacement, or fragment loss. For fragments with duplicate expressions, semantic conflicts, or verification conflicts, redundant conflict suppression calculations are performed. Fragments with high organizational weights and closer causal bindings are retained first, while fragments that only repeatedly express the same business meaning or will destroy cross-segment consistency are deleted. If a fragment fails to meet the consistency constraints after verification, the field allocation relationship between the fragment and adjacent fragments is readjusted or replaced with synonymous short code fields, and its fragment credibility is updated until each fragment meets the consistency requirements both within and between fragments. Finally, the ciphertext fragment set and the candidate verification fragment set are output. For S4-3, after obtaining the ciphertext fragment set, candidate check fragment set, and preset resource limit parameters, payload compression and encapsulation are performed. The preset resource limit parameters include at least the maximum usable length of a single SMS message, compression priority, and field retention level. During encapsulation, core ciphertext fragments and necessary check fragments are retained in their entirety first. Explanatory fragments and redundant check information are compressed using short code replacement, index mapping, or differential compression. The header, ciphertext, and check segments of the trusted SMS payload are formed in a preset order. After compression, recoverability error boundary verification is performed. This involves checking whether the receiver can still recover the basic order relationship, causal binding relationship, and necessary business semantics of each ciphertext fragment based on the length of each encapsulated fragment, the mapping relationship, and the check fragment. If the recovery error exceeds the preset boundary, the current compression strategy is rolled back, and some compressed fields are recovered or the compression ratio of the check fragment is reduced before re-encapsulation. When the length of the compressed payload meets the SMS transmission constraints and the fragment recovery error meets the preset boundary, the adjustment is stopped and the trusted SMS payload is output. Through the above processing, S4 can organize the SMS business data to be sent into a trusted SMS payload that takes into account business semantics, causal binding, and sending verification, even under the condition of limited SMS length. This allows the receiving end to not only verify the integrity of the SMS content but also verify whether the segments maintain the correct order and causal relationship, thereby improving its resistance to segment replacement, out-of-order splicing, and replay of historical segments. Simultaneously, through layered organization, segmented encryption, cross-segment verification, and recoverability control, it can stably preserve core business semantics and trusted constraints without significantly increasing the SMS payload burden. In practical applications, for example, in a scenario of level exceedance alarms at pumping stations in mountainous areas, the system first splits the SMS business data to be sent into fields such as level exceedance type, current level value, alarm level, trigger time, pumping station location, and handling prompts, and then... The liquid level exceedance triggering relationship, preceding state inheritance relationship, and alarm reception constraints in the event causal envelope are aligned to the corresponding business fields. Based on the sending key, the core alarm field is encrypted with high priority, and the location description field is encrypted with compressible encryption. Then, the fields are organized into multiple fragment groups according to the maximum SMS length. Each fragment group is encrypted and a cross-segment association verification fragment is generated. If it is found that retaining both the location description field and the handling prompt field will cause the length limit to be exceeded, the field with stronger binding to the event causality is retained first, and the prompt field is represented by a short code. Finally, the ciphertext fragment and the verification fragment are compressed and encapsulated to ensure that the receiving end can still recover the core semantics of this liquid level exceedance alarm, the fragment order, and the correspondence between it and the event causal envelope while meeting the SMS sending length requirement, forming a trusted SMS payload for subsequent sending.
[0021] S5, input the trusted SMS payload and the target recipient identifier, send the SMS, and output the sending completion status; In this implementation, S5 is used to send the trusted SMS payload to the target receiver according to the sending constraints corresponding to the target receiver identifier, and output the sending completion status for subsequent consistency verification. Since SMS sending in edge data transmission scenarios is affected by the SMS module status, SMS center availability, target object type, link stability, and receipt availability, the trusted SMS payload cannot be directly submitted for sending. Instead, an available sending path needs to be determined first, and then the target sending path is selected based on delivery capability, latency level, and link risk. During the sending process, the path reliability is continuously corrected based on the receipt results. Finally, the completion of the sending is determined based on delivery evidence and payload integrity. This implementation process includes the following steps: For S5-1, after obtaining the trusted SMS payload and the target recipient identifier, the recipient constraint matching is first performed, that is, the target recipient identifier is compared with the preset recipient rule table to determine the number type, priority, allowed sending time window and allowed sending method corresponding to the target recipient. Then, the sending path candidates are generated by combining the current device's SMS module status, SMS center configuration status, historical sending records and target recipient rules. The sending path candidates include at least the direct sending path, the sending path via the preset SMS center and the priority round-robin sending path. On this basis, the link cost evaluation is performed on each path. The target delivery reliability is calculated based on the historical delivery success rate, the current module availability status and the target recipient reception stability. The sending delay cost is calculated based on the historical sending duration, the current module queuing status and the link busy level. The link exposure risk is calculated based on the number of intermediate forwarding links, the path exposure degree and historical abnormal records. A sending decision model is formed according to the preset weights. Finally, the path with the best comprehensive score is selected as the target sending path, and the target sending path and the corresponding path confidence are output. For S5-2, after obtaining the target transmission path, trusted SMS payload, and path confidence, segmented transmission scheduling is performed on the trusted SMS payload according to the target transmission path. When the length of the trusted SMS payload does not exceed the upper limit of a single SMS length, it is sent in a single transmission mode. When the length of the trusted SMS payload exceeds the upper limit of a single SMS length, it is sent segment by segment according to a predetermined segment order, and a sequence identifier is added to each segment. During the transmission process, the module return results, SMS center response information, and receiver acknowledgment information are continuously collected, and acknowledgment observation consistency verification is performed to check whether the acknowledgment status, arrival order, and time interval of each transmission segment are consistent with the target transmission path. Path matching is performed. If duplicate transmissions, fragment loss, fragment out-of-order delivery, missing receipts, or abnormal path responses are detected, conflict resolution for abnormal transmission behavior is executed. First, it is determined whether the abnormality is due to link jitter, unreachable target receiver, or unstable intermediate path. Then, retransmission, path switching, or fragment reassembly is performed according to preset processing rules, and the path confidence is corrected based on the observation results of this round. When the path confidence increment between two adjacent rounds is lower than a preset threshold and the transmission result meets the preset stability condition, path correction is stopped and the target transmission record is output. The target transmission record includes at least the transmission time, transmission path, transmission fragment status, receipt result, and abnormality handling result. For S5-3, after obtaining the target sending record, trusted SMS payload, and preset completion judgment rules, the delivery evidence aggregation is first performed, that is, summarizing the module sending success flag, SMS center acceptance result, receiver acknowledgment result, and fragment arrival record in the target sending record to form the delivery evidence set for this sending; then, the payload integrity verification is performed, that is, checking whether the receiver has received the complete payload based on the number of fragments, fragment order identifier, and verification fragment in the trusted SMS payload. If there are missing fragments or incorrect order, the sending result is marked as incomplete delivery; after completing the delivery evidence aggregation and payload integrity verification, the completion status convergence judgment is performed according to the preset completion judgment rules. The preset completion judgment rules include at least four status judgment conditions: successful completion, partial completion, pending confirmation, and sending failure. When the delivery evidence is sufficient and the payload integrity is passed, it is judged as successful completion; when some fragments have arrived but the whole is not closed, it is judged as partial completion or pending confirmation; when the delivery evidence is insufficient and the retry condition is not met, it is judged as sending failure, and finally the sending completion status is output; Through the above processing, S5 can achieve controlled transmission and closed-loop confirmation of trusted SMS payloads under conditions of unstable SMS link status, constrained recipients, and asynchronous receipt information. This ensures that the transmission step not only completes SMS submission but also outputs a transmission result with path information, receipt information, and completion judgment, providing reliable input for subsequent consistency verification. Simultaneously, through path evaluation, transmission process correction, and completion status determination, the risks of incorrect transmission path selection, fragment out-of-ordering, and false completion judgments can be reduced, improving the stability and verifiability of the trusted SMS transmission link. In practical applications, for example, in a scenario of level exceedance alarms at a mountain pumping station, the system first identifies the target recipient based on the duty officer's number and the platform's receiving number, checking the SMS module status, SMS center configuration, and historical delivery records. Multiple candidate sending paths are generated in the record, and the path with high delivery reliability, low latency, and fewer intermediate forwarding links is selected as the target sending path. When the reliable SMS payload is long, the system splits it into multiple sending segments and sends them in sequence. At the same time, the system continuously collects module receipts and SMS center responses. If a segment receipt is found to be missing and the link response deteriorates, the segment is resent according to preset rules or a backup path is switched, and the path confidence is adjusted simultaneously. After all segments are sent, the system summarizes the module sending results, SMS center acceptance results, and target receiver receipts. Combining the segment order and verification segments, the system determines whether the alarm SMS has been completely delivered and finally outputs the corresponding sending completion status for subsequent steps to continue to verify the authenticity of the sending subject, the legitimacy of the sending timing, and the consistency of the event context.
[0022] S6, input trusted SMS payload, target recipient identifier and historical status information, perform consistency verification, and output the results of the sender authenticity determination, the send timing legitimacy determination and the event context consistency determination. In this implementation, S6 is used to perform consistency verification on the current SMS sending behavior based on the trusted SMS payload, the target recipient identifier, and historical state information, and output the results of the sender authenticity determination, the sending timing legitimacy determination, and the event context consistency determination, respectively. Since SMS messages in edge data transmission scenarios may experience replay, proxy sending, delayed arrival, out-of-order splicing, or incomplete historical states, the receiving end cannot determine its trustworthiness solely based on the SMS content itself. Instead, it needs to jointly compare the sending information reflected in the SMS payload with the target recipient constraints and historical state information, establishing an evidence chain from three directions: sender, time evolution, and event continuation. Conflict handling and confidence fusion are used to eliminate abnormal interpretations, ultimately forming three verifiable judgment results. This implementation process includes the following steps: For S6-1, after obtaining the trusted SMS payload, target recipient identifier, and historical state information, the trusted SMS payload is first deconstructed into encrypted service fields, verification fields, sequence identifier fields, and causal binding fields. Key fields reflecting the sending source, sending time, and event semantics are then extracted. Next, recipient constraint mapping is performed, matching the target recipient identifier with a preset recipient rule table to obtain the allowed sending template, allowed event level, allowed time window, and allowed sending source range corresponding to the target recipient. Based on this, historical state alignment is performed, specifically extracting information from the historical state information related to the current SMS service type, target recipient, and... The historical event fields, historical sending fields, and historical confirmation fields related to the previous processing results are aligned to the time base corresponding to the current SMS message with a unified time granularity. After the above processing is completed, a consistency discrimination model is constructed. The sending subject matching deviation is used to measure the degree of mismatch between the sending source reflected in the current SMS message payload and the allowed sending source range. The sending timing conflict cost is used to measure the degree of mismatch between the sending time corresponding to the current SMS message and the allowed time window and historical evolution order. The event context break cost is used to measure the degree of break between the event semantics in the current SMS message payload and the historical state inheritance relationship. Finally, the candidate authenticity evidence set, candidate timing evidence set, and candidate context evidence set are output. For S6-2, after obtaining the candidate authenticity evidence set, candidate timing evidence set, candidate context evidence set, and preset multi-perspective verification rules, cross-consistency verification is performed from the perspectives of the sending subject, time evolution, and event continuation. The sending subject perspective is used to verify whether the source identifier, key association information, and target receiving object constraints in the current SMS payload match each other. The time evolution perspective is used to verify whether the time sequence corresponding to the current SMS is consistent with historical sending records, historical confirmation results, and allowed time windows. The event continuation perspective is used to verify whether the event state, causal binding relationship, and historical event processing results expressed in the current SMS can be connected end to end. If evidence conflict occurs under any perspective, conflict localization is performed first to determine whether the conflict occurs in the subject evidence, timing evidence, or context evidence. Then, confidence backoff is performed, that is, the weight of conflicting evidence in subsequent judgment is reduced. When the main evidence is insufficient to form a stable judgment, alternative evidence compensation is performed. Specifically, similar historical records, auxiliary verification fields, or adjacent time sequence evidence are called to supplement the corresponding evidence chain. Finally, the authenticity verification evidence chain, timing verification evidence chain, and context verification evidence chain are output. For S6-3, after obtaining the authenticity verification evidence chain, timing verification evidence chain, context verification evidence chain, and preset uncertainty update rules, multiple rounds of confidence fusion are performed on the three evidence chains. Specifically, the initial confidence of each evidence chain is calculated first, and then the comprehensive confidence is updated based on the consistency within the evidence chain, the mutual support between evidence, and the completeness of historical state information. Subsequently, abnormal hypothesis elimination is performed, that is, abnormal hypotheses such as replay transmission, forged transmission, delayed arrival, out-of-order splicing, and missing historical inheritance are examined one by one, and abnormal interpretations that are obviously incompatible with the current evidence chain are eliminated. After each round of fusion, the judgment confidence increment and evidence chain order change of the two adjacent rounds are compared. When the judgment confidence increment of the two adjacent rounds is lower than the preset threshold and the stability of the evidence chain meets the preset conditions, the iteration stops, and the judgment results of the authenticity of the sending subject, the judgment result of the legitimacy of the sending timing, and the judgment result of the event context consistency are output respectively. Each judgment result can be expressed in the form of pass, fail, or need to be supplemented. Through the above processing, S6 can combine the trusted SMS payload with the constraints of the target recipient and historical state information for verification. This allows the receiver to not only determine whether the SMS comes from a legitimate sender, but also to further determine whether the timing of its transmission is reasonable and whether the event semantics it expresses are continuous with the historical state. This improves the ability to identify anomalies such as replay, proxy transmission, out-of-order transmission, and forgery. Simultaneously, through multi-perspective evidence chain construction, conflict evidence processing, and multi-round confidence fusion, it can still output stable three-category judgment results even when historical information is incomplete or the link is disturbed, providing a reliable basis for the final trusted transmission confirmation. In practical applications, for example, in a mountainous pumping station level over-limit alarm scenario, after receiving the trusted SMS payload, the receiver first deconstructs the level over-limit alarm field, fragment verification field, sequence identifier, and causal binding field. Based on the target receiving rules corresponding to the duty number, it is determined that the number is allowed to receive high-level liquid level alarms and that they can originate from the corresponding pumping station equipment. Then, the previous round of liquid level status, the previous round of SMS sending records, and the previous round of alarm confirmation results are extracted from the historical status information. It is then checked whether the source information of the current alarm is consistent with the corresponding pumping station equipment, whether the current sending time falls within the allowed alarm time window, and whether the current liquid level exceeding the limit is connected with the previous round of liquid level rise. If it is found that the evidence of a certain subject or timing is insufficient, the corresponding evidence chain is supplemented by adjacent historical records or auxiliary verification fields. After multiple rounds of confidence fusion and abnormal hypothesis elimination, the final results of the determination of the authenticity of the sending subject, the determination of the legitimacy of the sending time, and the determination of the consistency of the event context are output for subsequent reliable sending confirmation.
[0023] S7: Input the results of the authenticity determination of the sending entity, the legitimacy determination of the sending timing, and the consistency determination of the event context, perform validity verification, and output the trusted sending confirmation result; In this implementation, S7 is used to perform a final validity confirmation of the SMS sending behavior based on the results of the authenticity determination of the sending entity, the legitimacy determination of the sending timing, and the consistency determination of the event context, and outputs a credible sending confirmation result. Since the three types of determination results correspond to the three dimensions of sending source, sending time, and event acceptance, the validity of any one dimension alone is insufficient to directly prove the credibility of the sending. Therefore, it is necessary to first perform a unified mapping of the three types of determination results, and then construct a validity confirmation model by combining their dependencies and conflict relationships. Subsequently, a confirmation evidence chain is formed through cross-verification, conflict resolution, and anomaly removal. Finally, after multiple rounds of fusion and boundary verification, a final confirmation result is given. This implementation process includes the following steps: For S7-1, after obtaining the results of the sender authenticity determination, the send timing legitimacy determination, and the event context consistency determination, the determination results are first normalized and mapped. This means that the three types of determination results are uniformly converted into comparable confirmation status expressions, which include pass, fail, and pending further verification, and can correspond to preset numerical ranges. Then, the association constraint assembly is performed, mapping the sender authenticity determination results to the allowed sender source constraint, the send timing legitimacy determination results to the allowed sender time window constraint, and the event context consistency determination results to the historical state inheritance constraint, forming the association constraint relationship between the three types of determination results. On this basis, conflict dependency analysis is performed to determine whether there are mutual support, mutual negation, or conditional dependency relationships between the three types of determination results, and a validity confirmation model is constructed. The false confirmation risk is used to measure the possibility that an abnormal SMS is wrongly confirmed as a trustworthy SMS, the missed confirmation risk is used to measure the possibility that a genuine SMS is wrongly rejected, and the determination chain break cost is used to measure the impact of a missing or mismatched key determination on the overall confirmation chain. Finally, the candidate confirmation status set and corresponding confirmation weights are output. For S7-2, after obtaining the candidate confirmation state set, confirmation weights, and preset multi-condition linkage rules, cross-verification of the authenticity judgment result, the timing legitimacy judgment result, and the context consistency judgment result is first performed to check whether the three types of judgment results can support each other to form a closed confirmation relationship. Then, consistency alignment is performed to map the three types of judgment results to the same confirmation state space according to the preset multi-condition linkage rules. The preset multi-condition linkage rules include at least a fully pass rule, a partial supplementary verification rule, and a direct rejection rule. The fully pass rule is used when all three types of judgment results meet the pass condition to enter the credible candidate state. The partial supplementary verification rule is used when one of the three types of judgment results is supplementary verification and the others are not. When two conditions form a stable support, the system enters the pending confirmation candidate state. The direct rejection rule is used when the authenticity of the sending entity or the consistency of the event context is clearly not met, and the system directly enters the rejection candidate state. When there is a conflict among the three types of judgment results, conflict resolution is performed. The confirmation weight of the conflicting item is reduced according to the source of the conflict, the intensity of the conflict, and the priority of the associated constraints, while the candidate confirmation state consistent with the other judgment results is retained. After the conflict is resolved, abnormal hypothesis elimination is performed. Abnormal interpretations such as replay transmission, spoofed transmission, delayed arrival, missing historical data, or local evidence distortion are eliminated one by one. The confirmation weight is iteratively adjusted according to the elimination results, and finally the confirmation evidence chain and the corresponding state confidence are output. For S7-3, after obtaining the confirmed evidence chain, state confidence, and preset convergence stopping conditions, multi-round confidence fusion is first performed. That is, the state confidence corresponding to each candidate confirmed state is updated in rounds, so that the confirmed state supported by more evidence chains and with higher boundary condition satisfaction obtains a higher comprehensive confidence. Then, boundary condition review is performed to check whether there are boundary conditions such as insufficient historical state information, some evidence chains only supported by alternative evidence, unstable transmission completion state, or changes in target receiving object constraints. If the above conditions exist, the corresponding candidate confirmed state is downweighted or the state to be supplemented is retained. After each round of fusion, the state confidence increment and confirmed evidence chain ranking change of the two adjacent rounds are compared. When the state confidence increment of the two adjacent rounds is lower than the preset threshold and the stability of the confirmed evidence chain meets the preset condition, the iteration stops, and the confirmed state with the highest comprehensive confidence and satisfying the boundary conditions is output as the credible transmission confirmation result. The credible transmission confirmation result includes credible transmission, confirmation to be supplemented, and untrusted transmission. Through the above processing, S7 can further complete the final confirmation loop after the three types of judgment results are formed. This allows the system to not only determine whether the sending source, sending timing, and event acceptance are valid, but also whether the three together constitute an acceptable and credible sending result, thereby reducing the risk of false confirmation and missed confirmation. Simultaneously, through multi-condition linkage, conflict resolution, anomaly removal, and boundary verification, even if some evidence is insufficient or local judgments are disturbed, it can still output a stable and interpretable final confirmation result. In practical applications, for example, in a mountainous pumping station level exceeding limit alarm scenario, after obtaining the judgment results on the authenticity of the sending entity, the legitimacy of the sending timing, and the consistency of the event context, the system first maps these three to the results obtained through... The system first identifies three states: failure or pending verification. Then, it constructs candidate confirmation states based on constraints related to the pump station equipment source, alarm time window, and historical liquid level. If all three criteria are met, the system directly enters the trusted sending candidate state. If the legitimacy of the sending timing is delayed due to local acknowledgment and requires further verification, but the other two criteria are met, the system enters the pending confirmation candidate state. If the authenticity of the sending entity fails or the event context consistency fails, the system directly enters the rejection candidate state. Subsequently, the system eliminates abnormal assumptions such as replaying or forging alarms based on historical anomaly records and adjusts the weights of each candidate confirmation state. After multiple rounds of fusion and boundary verification, it outputs the trusted sending confirmation result corresponding to this liquid level exceeding limit alarm for subsequent alarm handling or linkage control.
[0024] Furthermore, it also includes: a text message encrypted transmission and trusted sending system, comprising a correlation modeling module, a causal encapsulation module, a key derivation module, an encryption loading module, a path sending module, a consistency verification module, and a valid confirmation module, characterized in that: The association modeling module is used to input current on-site event data, current equipment status data, SMS template identifiers, and target recipient identifiers, perform association and organization, and output an event context set. The causal encapsulation module is used to take the event context set and the preceding state summary as input, perform causal correlation calculations, and output the event causal envelope; The key derivation module is used to take the event causal envelope and encryption key material as input, perform derivation calculations, and output the key for this transmission. The encryption payload module is used to input the SMS service data to be sent, the event causal envelope, and the sending key, perform encryption processing and verification fragment extraction, and output a trusted SMS payload. The path sending module is used to input a trusted SMS payload and the target recipient identifier, send the SMS, and output the sending completion status. The consistency verification module is used to input trusted SMS payload, target recipient identifier and historical status information, perform consistency verification, and output the results of determining the authenticity of the sending entity, the legitimacy of the sending time and the consistency of the event context. The valid confirmation module is used to input the results of the authenticity judgment of the sending entity, the legitimacy judgment of the sending timing, and the consistency judgment of the event context, to perform validity confirmation, and output a reliable sending confirmation result.
[0025] Working Principle: This solution establishes the SMS sending process as a verifiable closed-loop link. The system first organizes the event context based on the current on-site event, device status, SMS template, and recipient. Then, it generates an event causal envelope based on the previous state, explaining why the SMS is sent by the current device at the current moment. Subsequently, it generates the sending key based on this causal envelope and key materials, and uses this key to encrypt and encapsulate the SMS content, forming a trusted SMS payload. During sending, it selects the sending path based on recipient constraints and link status, and records the sending result. Upon receiving the SMS, the receiving end not only verifies the SMS content but also considers historical status to determine the authenticity of the sender, the rationality of the sending timing, and the continuity of the event context. Finally, it outputs a trusted sending confirmation result by combining these three results. In other words, the output of the previous step becomes the input and constraint of the next step, ensuring that the entire SMS link maintains a causal relationship from event generation to reception confirmation. For example, in a scenario where a pump station in a mountainous area experiences a level exceeding the limit alarm, after the edge device detects that the level has exceeded the upper limit, it first organizes the level value, trigger time, pump status, alarm template, and duty number into an event context. Then, it combines the previous level status and the previous sending result to generate an event causal envelope, indicating that this alarm was indeed triggered by the current level change. The system then generates a sending key based on this causal envelope, encrypts and encapsulates the alarm content, and selects an appropriate path to send it according to the current SMS link status. After receiving the SMS, the receiving end verifies it by combining the pump station's historical level changes, historical sending records, and receiving rules to confirm whether the SMS actually originated from the pump station, whether it was sent at the appropriate time, and whether it is consistent with historical states. In this way, even if the device is offline for a long time or the link is unstable, the receiving end can still determine that the SMS can not only be interpreted but also that its source is reliable, its timing is reasonable, and its context is continuous.
[0026] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A method for encrypted transmission and trusted delivery of SMS messages, characterized in that, include: S1, Input current on-site event data, current device status data, SMS template identifier and target recipient identifier, perform association and organization, and output event context set; S2 takes the event context set and the preceding state summary as input, performs causal correlation calculation, and outputs the event causal envelope; S3, input the event causal envelope and encryption key material, perform derivation calculations, and output the key for this transmission; S4: Input the SMS service data to be sent, the event causal envelope and the sending key, perform encryption processing and verification fragment extraction, and output the trusted SMS payload; S5, input the trusted SMS payload and the target recipient identifier, send the SMS, and output the sending completion status; S6, input trusted SMS payload, target recipient identifier and historical status information, perform consistency verification, and output the results of the sender authenticity determination, the send timing legitimacy determination and the event context consistency determination. S7 takes as input the results of the authenticity determination of the sending entity, the legitimacy determination of the sending timing, and the consistency determination of the event context, performs validity verification, and outputs a trusted sending confirmation result.
2. The SMS encrypted transmission and trusted sending method according to claim 1, characterized in that: S1 includes: S1-1, Input current on-site event data, current device status data, SMS template identifier and target recipient identifier, perform field standardization mapping and missing item constraint screening, and output candidate context field set and field completeness mark; S1-2, Input the candidate context field set, field completeness flag and preset business constraint set, construct the field filtering target with the event trigger validity, sending semantic limitation and receiving object legality as constraints, perform candidate field pruning and redundant field suppression calculation, and output the initial context subset; S1-3: Input the initial context subset, current field event data, and current device status data; perform event perspective consistency verification and status perspective consistency verification; perform conflict location, priority judgment, and conflict resolution on conflict fields; and output the consistency correction context subset and conflict resolution flag.
3. The SMS encrypted transmission and trusted sending method according to claim 2, characterized in that: S1 also includes: S1-4, Input the consistency correction context subset, the SMS template identifier and the target receiving object identifier, perform template semantic slot matching calculation and receiving object constraint projection calculation, and output the sending constraint context subset; S1-5, Input the sending constraint context subset and preset resource limit parameters, perform hierarchical compression coding calculation constrained by SMS payload length, perform recoverability error boundary determination on the compression reserved fields, and output resource-constrained context expression fragment and error control flag; S1-6, Input the resource-constrained context expression fragment, the consistency correction context subset, and the conflict resolution flag, perform multiple rounds of confidence review and stopping condition determination calculation, and output the event context set when the field confidence meets the preset threshold and the context stability meets the convergence condition.
4. The SMS encrypted transmission and trusted sending method according to claim 3, characterized in that: S2 includes: S2-1 takes the event context set and the previous state summary as input, performs field destructuring, time sequence alignment and association domain mapping, and outputs the current event fragment set, the historical successor fragment set and the corresponding association index; S2-2, Input the current event fragment set, the historical inherited fragment set and the preset causal constraint set, construct a candidate causal path solution model with the goal of minimizing the cost of event triggering, minimizing the cost of state transition breakage and minimizing the cost of sending timing conflict, perform multi-path search and constraint filtering, and output the candidate causal path set and path cost sequence. S2-3, Input the candidate causal path set, the path cost sequence and the association index, perform multi-perspective consistency verification from the event perspective, state perspective and sending perspective, and perform conflict location, conflict attribution and conflict resolution on inconsistent paths, and output a consistent causal path set and conflict correction flag. S2-4, Input the consistent causal path set, the preceding state summary and the preset uncertainty model, perform path confidence estimation, abnormal transfer probability update and historical acceptance confidence correction, and output the confidence-enhanced causal path set and the corresponding path confidence sequence; S2-5, Input the confidence-enhanced causal path set, the path confidence sequence and the preset convergence criterion, perform iterative pruning and stability determination, and output the target causal path when the path confidence increment is lower than the preset threshold and the path ranking stability meets the stopping condition; S2-6, Input the target causal path, the conflict correction flag and the preceding state summary, perform trigger chain segment encoding, succession chain segment encoding and sending constraint chain segment encoding, and output the initial event causal envelope; S2-7, Input the initial event causal envelope and preset resource limit parameters, perform layered compression and recoverability verification under load length constraints, and output the event causal envelope when the envelope compression error meets the preset boundary.
5. The SMS encrypted transmission and trusted sending method according to claim 4, characterized in that: S3 includes: S3-1: Input the event causal envelope and encryption key material, perform causal field deconstruction, key material domain mapping and constraint association calculation, construct a multi-domain derivation model with the goal of maximizing event binding strength, minimizing cross-event reuse risk and minimizing key exposure and diffusion cost, and output the candidate derivation factor set and corresponding constraint weights. S3-2, Input the candidate derived factor set, the constraint weights and the preset uncertainty evaluation rules, perform multiple rounds of factor screening, conflict factor suppression and derived stability confidence update, and output the target derived factor set when the confidence increment between two adjacent rounds is lower than the preset threshold and the remaining factor set satisfies the minimum distinguishable constraint; S3-3, Input the target derivation factor set and the encryption key material, perform hierarchical combination derivation, inter-domain isolation calculation and recoverability consistency verification, and output the current transmission key that is uniquely bound to the event causal envelope and satisfies the preset length constraint and anti-reuse constraint.
6. The SMS encrypted transmission and trusted sending method according to claim 5, characterized in that: S4 includes: S4-1: Input the SMS service data to be sent, the event causal envelope, and the sending key. Perform business field deconstruction, causal field alignment, and key scope mapping. Construct a load organization model with the goals of minimizing the semantic fidelity cost of SMS service, minimizing the loss of causal binding strength, and minimizing the risk of exceeding the load length limit. Output a hierarchical set of business segments, a set of causal binding segments, and corresponding organization weights. S4-2, Input the hierarchical service segment set, the causal binding segment set, the organization weight and the key for this transmission, perform segmented encryption calculation, cross-segment association verification calculation and redundancy conflict suppression calculation, and perform reorganization error correction and confidence update on segments that do not meet the consistency constraints based on the segmented verification results, and output the ciphertext segment set and the candidate verification segment set; S4-3, Input the ciphertext fragment set, the candidate verification fragment set and the preset resource limit parameters, perform payload compression and encapsulation, recoverability error boundary verification and stop condition determination, and output a reliable SMS payload when the length of the compressed payload meets the SMS transmission constraint and the fragment recovery error meets the preset boundary.
7. The SMS encrypted transmission and trusted sending method according to claim 6, characterized in that: S5 includes: S5-1: Input the trusted SMS payload and the target recipient identifier, perform recipient constraint matching, sending path candidate generation and link cost evaluation, construct a sending decision model with the objectives of maximizing target delivery credibility, minimizing sending delay cost and minimizing link exposure risk, and output the target sending path and the corresponding path confidence. S5-2, Input the target sending path, the trusted SMS payload and the path confidence, perform segmented sending scheduling, receipt observation consistency verification and abnormal sending behavior conflict resolution, and perform iterative correction of the sending path confidence based on the observation results. When the path confidence increment between two adjacent rounds is lower than the preset threshold and the sending result meets the preset stability condition, output the target sending record. S5-3, Input the target sending record, the trusted SMS payload and the preset completion judgment rule, perform delivery evidence aggregation, payload integrity verification and completion status convergence judgment, and output the sending completion status.
8. The SMS encrypted transmission and trusted sending method according to claim 7, characterized in that: S6 includes: S6-1: Input the trusted SMS payload, the target receiving object identifier and historical state information, deconstruct the payload field, map the receiving object constraint and align the historical state, construct a consistency discrimination model with the goal of minimizing the sending subject matching deviation, minimizing the sending timing conflict cost and minimizing the event context break cost, and output the candidate authenticity evidence set, candidate timing evidence set and candidate context evidence set. S6-2, Input the candidate authenticity evidence set, the candidate timing evidence set, the candidate context evidence set and the preset multi-perspective verification rules, perform cross-consistency verification of the sending subject perspective, time evolution perspective and event acceptance perspective, and perform conflict location, confidence backoff and alternative evidence compensation for conflict evidence, and output the authenticity verification evidence chain, timing verification evidence chain and context verification evidence chain. S6-3, Input the authenticity verification evidence chain, the timing verification evidence chain, the context verification evidence chain and the preset uncertainty update rule, perform multi-round confidence fusion, abnormal hypothesis elimination and convergence stop determination, and output the authenticity determination result of the sending subject, the legitimacy determination result of the sending timing and the event context consistency determination result when the confidence increment of two adjacent rounds of determination is lower than the preset threshold and the stability of the evidence chain meets the preset conditions.
9. The SMS encrypted transmission and trusted sending method according to claim 8, characterized in that: S7 includes: S7-1: Input the results of the authenticity judgment of the sending entity, the legitimacy judgment of the sending timing, and the consistency judgment of the event context. Perform normalization mapping of the judgment results, assembly of related constraints, and conflict dependency analysis. Construct an effective confirmation model with the goal of minimizing the risk of false confirmation, minimizing the risk of missed confirmation, and minimizing the cost of the decision chain break. Output a set of candidate confirmation states and corresponding confirmation weights. S7-2, Input the candidate confirmation state set, the confirmation weight and the preset multi-condition linkage rule, perform cross-verification, consistency alignment and conflict resolution of the authenticity judgment result, the timing legitimacy judgment result and the context consistency judgment result, and perform abnormal hypothesis elimination and confirmation weight iterative correction based on the conflict resolution result, and output the confirmation evidence chain and the corresponding state confidence. S7-3, Input the confirmation evidence chain, the state confidence level and the preset convergence stopping condition, perform multi-round confidence fusion, boundary condition verification and final validity determination, and output a reliable transmission confirmation result when the state confidence increment of two adjacent rounds is lower than the preset threshold and the stability of the confirmation evidence chain meets the preset condition.
10. A text message encrypted transmission and trusted sending system, comprising an association modeling module, a causal encapsulation module, a key derivation module, an encryption encapsulation module, a path sending module, a consistency verification module, and a valid confirmation module, characterized in that: The association modeling module is used to input current on-site event data, current equipment status data, SMS template identifiers, and target recipient identifiers, perform association and organization, and output an event context set. The causal encapsulation module is used to take the event context set and the preceding state summary as input, perform causal correlation calculations, and output the event causal envelope; The key derivation module is used to take the event causal envelope and encryption key material as input, perform derivation calculations, and output the key for this transmission. The encryption payload module is used to input the SMS service data to be sent, the event causal envelope, and the sending key, perform encryption processing and verification fragment extraction, and output a trusted SMS payload. The path sending module is used to input a trusted SMS payload and the target recipient identifier, send the SMS, and output the sending completion status. The consistency verification module is used to input trusted SMS payload, target recipient identifier and historical status information, perform consistency verification, and output the results of determining the authenticity of the sending entity, the legitimacy of the sending time and the consistency of the event context. The valid confirmation module is used to input the results of the authenticity judgment of the sending entity, the legitimacy judgment of the sending timing, and the consistency judgment of the event context, to perform validity confirmation, and output a reliable sending confirmation result.