A provincial level space reference online conversion method

By acquiring and analyzing surveying benchmark information from different coordinate systems, and combining it with a collaborative encryption architecture built using encryption units, the problems of low efficiency and difficulty in guaranteeing accuracy in online conversion of provincial spatial benchmarks have been solved. This has enabled high-precision conversion and data security across the entire province, meeting users' online conversion needs.

CN122220796BActive Publication Date: 2026-07-31GANSU INST OF SURVEYING & MAPPING ENG
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GANSU INST OF SURVEYING & MAPPING ENG
Filing Date
2026-05-18
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing technologies for online conversion of provincial spatial references suffer from low efficiency, difficulty in guaranteeing accuracy, lack of targeted encryption strategies, fragmented encryption systems, non-standard key management, and weak ability to prevent leakage of results data, making it impossible to achieve full-coverage, high-precision conversion and collaborative sharing.

Method used

By acquiring mapping benchmark information in different coordinate systems, analyzing GNSS static measurement and network adjustment results, selecting clean data, calculating transformation parameters using the comprehensive method and a four-parameter plane model, and performing gridding processing, a collaborative encryption architecture is constructed in conjunction with encryption units, including a server-side encryption module, a transmission link encryption channel, a lightweight encryption component for the user end, and key-token-generation factor management, to achieve adaptation to three levels of encryption and permission division.

Benefits of technology

It has achieved high-precision spatial benchmark conversion across the entire province, ensuring data consistency and the inheritance of results. It provides a user coordinate system service system to meet the online conversion needs of different users, and ensures data security through encryption measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122220796B_ABST
    Figure CN122220796B_ABST
Patent Text Reader

Abstract

This invention discloses an online conversion method for provincial spatial benchmarks, relating to the field of geodesy. The method includes acquiring mapping benchmark information from different coordinate systems and analyzing existing data; performing GNSS static measurements on the existing data to obtain network adjustment data; conducting point self-consistency analysis on the existing and network adjustment data and filtering out gross errors to obtain clean data; selecting a parameter calculation model; calculating and verifying initial conversion parameters based on the model to obtain standard conversion parameters; gridding the standard conversion parameters and integrating a gravity-based geoid to determine the geoid, and then evaluating and refining its accuracy. The online conversion method for provincial spatial benchmarks is equipped with a software platform. This application demonstrates significant importance in enhancing mapping benchmark support services and promoting the development of the provincial surveying and mapping geographic information industry, and has excellent market application prospects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of geodesy, and more particularly to a method for online conversion of provincial spatial benchmarks. Background Technology

[0002] In modern geographic information applications, land spatial planning, engineering construction, and navigation and positioning, the unification and high-precision conversion of spatial benchmarks are key technological foundations for ensuring data consistency and realizing the fusion and sharing of multi-source information. Traditional spatial benchmark conversion methods mainly rely on offline, stand-alone conversion software or preset parameter models, which suffer from problems such as low efficiency, inconvenience in parameter acquisition and management, difficulty in guaranteeing and verifying accuracy, inability to support collaboration and sharing, and limited service capabilities.

[0003] In recent years, although network-based spatial data services have emerged, they mostly focus on map browsing and simple queries, or only provide limited and general coordinate transformation functions, often lacking the ability to perform refined, high-precision, and comprehensive spatial benchmark transformations tailored to the characteristics of provincial administrative regions.

[0004] In addition, existing encryption technologies for online conversion of provincial spatial benchmarks suffer from problems such as a lack of targeted encryption strategies, fragmented encryption systems, non-standard key management, and weak ability to prevent leakage of results data.

[0005] Therefore, there is an urgent need for an online conversion method for provincial spatial references with good encryption. Summary of the Invention

[0006] To address the aforementioned issues, this application proposes an online conversion method for provincial spatial benchmarks. Addressing the current inconsistency in surveying and mapping geographic information results from different historical periods, this method comprehensively applies various methods to determine the conversion parameters with the highest accuracy for each region. Through parameter gridding, a unified conversion parameter with the highest accuracy across the entire province is formed. Online coordinate conversion service is then achieved through network security configuration. The method specifically includes the following steps: S1. Obtain mapping benchmark information in different coordinate systems and analyze existing results data, and perform GNSS static measurement on existing results data to obtain network adjustment results data; S2. Perform point consistency analysis on existing data and network adjustment data, and screen out gross errors to obtain clean data. S3. Select a parameter calculation model, calculate the initial conversion parameters based on the parameter calculation model, and verify them to obtain the standard conversion parameters; S4. The standard transformation parameters are gridded and integrated with the gravity-based geoid to determine the geoid, and the accuracy is evaluated and refined. The provincial-level spatial reference online conversion method is equipped with a software platform, and the software platform is equipped with an encryption unit; The encryption unit establishes a collaborative encryption architecture, deploying a server-side encryption module, a transmission link encryption channel, a user-side lightweight encryption component, a data storage encryption module, and a key-token-generation factor management server. It clarifies the adaptation standards, permission division, encryption strategies, generation rules, interaction processes, and update mechanisms for the three-level encryption levels and tokens.

[0007] Preferably, the point self-consistency analysis in S2 includes the coordinate method and the baseline vector method; The coordinate method refers to evaluating the absolute positional consistency of the points by comparing the X and Y coordinates of the existing data and the network adjustment data. The baseline vector method involves evaluating the relative changes between the point vectors of existing data and network adjustment data. There are pre-set limit tables for coordinate method and vector method; Filter out the points exceeding the limit in the coordinate method and the vectors exceeding the limit in the baseline vector method, and mark them; Based on the cases of exceeding the limits, each point was analyzed and judged to identify gross errors. By combining the network adjustment results with the gross error information, the network adjustment results are updated to obtain clean data.

[0008] Preferably, the parameter calculation model in S3 includes a comprehensive method transformation model and a planar four-parameter transformation model; The specific details of selecting parameters and calculating the model include: The distribution range of existing data points within the region was studied, and some points were selected as parameter calculation points and others as accuracy check points. Based on the characteristics of the model, the parameters are obtained. Based on the features of the comprehensive method model, the transformation parameters are obtained throughout the province to form a set of transformation parameters for the whole province. The transformation parameters of the four-parameter planar model are obtained by dividing the point distribution into blocks, with the overlap of the block areas ≥ 30%. The accuracy of the conversion parameters is verified using two evaluation indicators: internal compliance accuracy and external compliance accuracy, to determine the final conversion model and parameter accuracy.

[0009] Preferably, the encryption unit includes the following tasks: a) initialization of generation factors and tokens; b) encryption of identity authentication during token interaction; c) encryption of data transmission during token interaction; d) encryption of conversion parameters bound to generation factors; e) encryption of data storage; f) encryption of result data bound to the fusion terminal; g) closed-loop management of key-generation factor-token. The key-token-generation factor management server is the core carrier of the entire key and token management process, corresponding to tasks a and g, and is responsible for generating, distributing, updating, and deregistering root keys, derived keys, generation factors, and tokens. The server-side encryption module runs throughout the task group and is responsible for identity authentication and verification, certificate authentication and data encryption in data transmission, conversion parameter decryption and signature verification, result encryption authorization, and security core encryption operations and verification. The encrypted transmission link channel supports encrypted transmission and token interaction using encryption algorithms. Task c is the secure carrier for all data transmission between the user and the server, enabling confidentiality and integrity verification during data transmission. The lightweight encryption component on the user side is responsible for lightweight encryption operations such as local encrypted storage on the user side, token generation and interaction, and result decryption, corresponding to tasks a, b, c, and f. The data storage encryption module corresponds to tasks e and f, and is responsible for the encrypted storage of classified or non-classified data, log data, generation factors, and tokens in the server-side partitioned storage, as well as the encrypted storage of local data on the user end, to prevent data leakage in the storage process.

[0010] Preferably, the specific content of task a includes: After a user registers or logs in for the first time, the server randomly generates base data based on the user's terminal device identifier, user permissions, and default encryption level, and then generates the first generation factor, simultaneously generating the initial verification token and pushing it to the user's terminal storage. The user terminal stores the generation factor and the initial verification token, and establishes a binding relationship between the terminal device identifier and the generation factor and token; Task b includes the following: When a user logs in, the password is encrypted and stored using SHA-256 hash + salt value, and the password transmission uses double encryption; Meanwhile, the user terminal generates a verification token based on the stored generation factor and terminal device identifier, and sends it to the server. The server parses the verification token, verifies the legality of the generation factor and terminal device identifier, and completes identity authentication by combining it with password verification. Level 2 encryption scenarios employ a two-factor authentication method that combines account password with SMS or email verification code for one-time token verification; Level 3 encryption scenarios employ a two-factor authentication method that combines account and password with hardware encryption devices for secondary token verification. After logging in, an encrypted session token is generated to encrypt the session and destroy it after a timeout, while also updating the generation factor.

[0011] Preferably, the specific content of task c includes: When a user initiates a conversion request, the number of conversion requests N (N≥1) is recorded. If N>1, a second generation factor is generated based on the first generation factor, and the verification token is updated. All data between the user and the server is transmitted through an encrypted channel. The user sends a verification token and the server sends a response token. Data transmission can only proceed after both parties have completed the token comparison and verification. All transmitted data is accompanied by a message authentication code generated by SM4, which, combined with the token verification result, enables the verification of the confidentiality, integrity, and legality of data transmission.

[0012] Preferably, the specific content of task d includes: The conversion parameters are stored with dual encryption using SM4 or SM4+ hardware encryption modules, and the key, generation factor, user permissions, and terminal device identifier are bound together. When calling parameters, the client sends a verification token and a parameter call request. After the server verifies the validity of the token and the generation factor, it uses SM2 to temporarily decrypt the parameters. The decrypted parameters are only temporarily stored in memory and destroyed immediately after the conversion is completed. Simultaneously, all parameters are digitally signed using SM2, and the signature is verified in conjunction with the generation factor to prevent tampering. The generation factor is updated synchronously with the number of parameter calls, ensuring that the parameter calls are bound to the terminal and the number of requests.

[0013] Preferably, the specific content of task e includes: The server adopts a partitioned storage mode, with classified and non-classified data physically isolated. Source data, result data, log data, generation factors, and tokens are stored using corresponding levels of encryption algorithms. Log data, token interaction logs, and generation factor update logs are encrypted and retained for no less than one year. The user terminal uses the corresponding encryption method to store the generation factor, token, and local data according to the terminal type to prevent leakage caused by terminal theft.

[0014] Preferably, the specific content of task f includes: Standard results are encrypted using SM4, and the key, generation factor, user account, and terminal device identifier are bound together. Classified results are encrypted with SM4 double encryption and watermark embedding, and are subject to "one person, one authorization", supporting authorized sharing and setting an expiration period; After downloading, users must enter their account password and verification token using a dedicated tool to decrypt the file. The specialized tool is a component tool for a lightweight encryption component on the user side; Specialized tools limit the number of times results can be opened on the bound terminal device, and use a data overwrite mode when deleting to prevent data recovery; At the same time, the download and usage records of the results can be traced through the generation of factors and tokens.

[0015] Preferably, the specific content of task g includes: The root key and various derived keys are generated through a key management server and distributed using encrypted channels or hardware devices. The root key is protected by HSM hardware. The generation factor is updated synchronously with the number of conversion requests and the encryption level adjustment, and the token is refreshed synchronously with the generation factor update, realizing the linkage update of key, generation factor and token; The key and generation factor are automatically updated according to a preset cycle. For scenarios such as account cancellation, device loss, and token abnormality, the key, generation factor, and token can be cancelled and residual cleaned up in a compliant manner.

[0016] In summary, the provincial spatial benchmark online conversion method of this invention, compared with traditional technologies, is based on existing theoretical achievements and combined with usage requirements. Through reinvention, it solves the problem of converting different surveying and mapping geographic information results within a province to CGCS2000. By adopting parametric gridding, it ensures the highest conversion accuracy across the entire province, and has the following advantages: 1. The study proposes to achieve mutual conversion between CGCS2000, the 1980 Xi'an coordinate system, and the 1954 Beijing coordinate system based on a unified conversion model. This method not only ensures the consistency of results across the province but also realizes the inheritance of the original control results. 2. A method combining coordinate centroidization and the four-parameter method was proposed to obtain the conversion parameters between the urban coordinate system and CGCS2000 results, which is in a leading position in the domestic industry. 3. A user coordinate system service system was provided, which enabled online coordinate transformation and conversion of geodetic height to normal height, meeting the urgent needs of different users.

[0017] The technical method of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0018] Figure 1 This is a schematic diagram illustrating the steps of an online conversion method for provincial spatial references. Figure 2 A schematic diagram for selecting the parameter calculation model; Figure 3 Diagram showing parameter filling methods; Figure 4 A flowchart illustrating the evolution of a geoid model; Figure 5 This is a diagram of the coordinate online conversion service system architecture in Example 3; Figure 6 This is a schematic diagram of the Bursa seven-parameter conversion; Figure 7 This is a schematic diagram of a four-parameter transformation in a plane. Figure 8 To standardize the flowchart in coordinate format; Figure 9 Methods for converting between CGCS2000 and independent coordinate systems; Figure 10 A diagram illustrating the effect of filling in the conversion parameters; Figure 11 This is the main interface for coordinate transformation. Detailed Implementation

[0019] The technical method of the present invention will be further described below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps described in these embodiments do not limit the scope of this application.

[0020] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the scope of this application and its application or use.

[0021] Techniques, systems, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, they should be considered part of the instruction manual.

[0022] In all the examples shown and discussed herein, any specific values ​​should be interpreted as merely exemplary and not as limitations. Therefore, other examples of exemplary embodiments may have different values.

[0023] Unless otherwise defined, the technical or scientific terms used in this invention shall have the ordinary meaning as understood by one of ordinary skill in the art to which this invention pertains.

[0024] Example 1 A method for online conversion of provincial spatial benchmarks, such as Figure 1 As shown, this method aims to address the problems existing in the conversion of surveying and mapping geographic information results from different historical periods. It comprehensively applies various methods to determine the most accurate conversion parameters for each region, and through parameter gridding, forms a unified conversion parameter set with the highest accuracy for the entire province. Through network security configuration, it enables online coordinate conversion services. The specific steps include: S1. Obtain mapping benchmark information in different coordinate systems and analyze the existing results data, and perform GNSS static measurement on the existing results data to obtain network adjustment results data.

[0025] The collection and organization of surveying and mapping results in different coordinate systems within the province requires the collection of coordinate system data from various periods within the province, including the type of results, the year of construction, and the construction method, in order to lay the foundation for subsequent data analysis and implementation.

[0026] The collected data included the establishment methods, construction time, control point distribution range, and existing results of different coordinate systems, and the existing data were organized. Analysis revealed that the existing results mainly used three types of coordinate systems: the 1980 Xi'an coordinate system, the 1954 Beijing coordinate system, and local independent coordinate systems. The coordinate forms were geodetic coordinates (B, L) and Gaussian projection coordinates (X, Y), respectively, with the 1985 National Elevation Standard. The first two types of coordinate systems are characterized by uneven point distribution and poor accuracy; local independent coordinate systems are characterized by a large construction time span, diverse construction methods, and inconsistent control range.

[0027] The above work provides guidance for the implementation of subsequent work.

[0028] Based on the data analysis results of S1, GNSS static measurements were carried out on various coordinate system control points within the province according to the requirements of Class B GNSS observation. After the measurement was completed, the data was processed, and the CGCS2000 results of the observation points and other coordinate system results were obtained through network adjustment.

[0029] S2. Perform point self-consistency analysis on existing results data and network adjustment results data, and screen out gross errors to obtain clean data. The coordinate method and baseline vector method used in the self-consistency analysis of coordinate results not only accurately remove gross errors in the results, but also effectively supplement the points using GNSS network adjustment results, which greatly improves the accuracy of transformation parameters and the utilization rate of points.

[0030] Furthermore, the point self-consistency analysis in S2 includes the coordinate method and the baseline vector method.

[0031] The coordinate method refers to evaluating the absolute positional consistency of points by subtracting the X and Y coordinates of existing data and network adjustment data.

[0032] The baseline vector method involves evaluating the relative changes between point vectors in existing data and network adjustment data.

[0033] There are pre-set limit tables for coordinate method and vector method.

[0034] Considering the actual production uses and construction methods of each coordinate system, the tolerance limits are set according to Table 1.

[0035] Table 1. Limits of Error for Coordinate Method

[0036] The baseline vector method has limits set according to Table 2.

[0037] Table 2 Limit Table for Vector Method

[0038] By combining the two methods, gross errors in the existing results are filtered out to provide "clean" data for subsequent parameter conversion.

[0039] The points exceeding the limit in the coordinate method and the vectors exceeding the limit in the baseline vector method are selected and marked.

[0040] Based on the cases of exceeding the limits, each point is analyzed and judged to identify gross errors.

[0041] By combining the network adjustment results with the gross error information, the network adjustment results are updated to obtain clean data.

[0042] S3. Select a parameter calculation model, calculate the initial conversion parameters based on the parameter calculation model, and verify them to obtain the standard conversion parameters.

[0043] Furthermore, the parameter calculation models described in S3 include the comprehensive method transformation model and the planar four-parameter transformation model.

[0044] Specifically, the current data situation poses a significant obstacle to the selection of transformation parameter calculation models. This patent prioritizes transformation accuracy and, when determining transformation relationships, primarily employs a comprehensive method (Bursa's seven-parameter model) and a planar four-parameter model. Two methods are used to calculate the transformation parameters from different coordinate systems within the province to CGCS2000.

[0045] The comprehensive transformation model analysis, based on similarity transformation (Burza seven-parameter transformation), absorbs systematic errors by performing polynomial fitting on the coordinate residuals, thereby improving the accuracy of the transformation parameters. The coordinate system of the Burza seven-parameter transformation is as follows: Figure 6 As shown, Figure 6 The spatial position of a point can be represented by a corresponding rectangular coordinate system, as shown in the figure. Indicates A spatial rectangular coordinate system is established for the coordinate axes, named B, and the line segment... , These are the three directions of coordinate B, and they are spatially perpendicular to each other. Similarly... Let A be a spatial rectangular coordinate system. The translation parameter symbol in the Bursa seven-parameter model is equivalent to that in equation (1). , , , Let be the translation parameters along the X, Y, and Z axes from the spatial rectangular coordinate system A to the spatial rectangular coordinate system B.

[0046] The synthetic method, expressed mathematically using similarity transformation, is as follows: (1); In equation (1), These are translation parameters. These are rotation parameters. It is a scale parameter. The x-axis coordinates in coordinate system A. The Y-axis coordinate value in coordinate system A. The x-axis coordinates in coordinate system B. The Y-axis coordinate value in coordinate system B. The Z-axis coordinate value in coordinate system A. This represents the Z-axis coordinate value in the B coordinate system.

[0047] For example, suppose there exists a point P in coordinate B, denoted as P(X). B Y B Z B Now, transform point P to coordinate system A to obtain P(X). A Y A Z A ), which needs to be transformed using equation (1). The specific steps are: transform P(X) in coordinate system B. B Y B Z B The point is translated to the corresponding position P(X) in coordinate system A. A Y A Z A The translation parameters are obtained from equation (1). , , , At this point, point P in coordinate system B coincides with the corresponding point in coordinate system A. However, due to the spatial position of each coordinate axis, a spatial rotation is still required, i.e., in equation (1). Three rotation parameters, express and The angle of rotation required for overlap express and The angle of rotation required for overlap express and The angle of rotation is required for alignment; after the coordinate axes are aligned, a scale factor parameter is needed because the coordinate scales of coordinate systems B and A are inconsistent. Adjustments are made to ensure that P(X) in the B coordinate system is in the correct position. B Y B Z B The point is accurately transformed to P(X) in the A coordinate system. A Y A Z A )point.

[0048] A planar four-parameter transformation model is analyzed. This transformation model is mainly used for small-scale coordinate transformations. When calculating the transformation parameters, it is easy to obtain that the east-west and north-south distances of the transformation region are approximately equal. Its mathematical expression is as follows: (2); In formula (2) m is the translation parameter, and m is the scale parameter. For example, the rotation angle is... Figure 7 As shown, Figure 7 A point in the midplane can be represented by Cartesian coordinates, as shown in the figure. Indicates A Cartesian coordinate system is established with the origin at point A and the X and Y axes as the coordinate axes. The coordinate system is named A. , These are the two directions of the coordinate system, and their planar positions are perpendicular to each other. Similarly, ... Let A be a plane coordinate system. Let point P be a point in coordinate system A, denoted as P(X...). A Y A Now, transform point P to coordinate system B to obtain P(X). B Y B ), which needs to be transformed using equation (2). The specific steps are: transform P(X) in coordinate system A. A Y A The point is translated to the corresponding position P(X) in coordinate system B. B Y B The translation parameters are obtained from equation (2). , , , At this point, point P in coordinate system B coincides with the corresponding point in coordinate system A. However, due to the spatial position of each coordinate axis, a rotation is still required, with a rotation angle of . After rotating the coordinate axes, because the coordinate scales of coordinate system B and coordinate system A are inconsistent, a scale factor parameter is needed. Adjustments are made to ensure that P(X) in the B coordinate system is in the correct position. B Y B The point is accurately transformed to P(X) in the A coordinate system. A Y A )point.

[0049] The selected parameter calculation model includes the following details: The distribution range of existing data points within the region was studied, and some points were selected as parameter calculation points and others as accuracy check points.

[0050] Based on the characteristics of the model, the parameters are obtained. Based on the features of the comprehensive method model, the transformation parameters are obtained throughout the province to form a set of transformation parameters for the entire province.

[0051] The transformation parameters of the planar four-parameter model are obtained by dividing the points into blocks, with the overlap of the block areas being ≥30%.

[0052] The accuracy of the conversion parameters is verified using two evaluation indicators: internal compliance accuracy and external compliance accuracy, to determine the final conversion model and parameter accuracy.

[0053] Explanation of the parameter acquisition process of the comprehensive method: Taking the conversion from the 1980 Xi'an coordinate system to CGCS2000 as an example, this article introduces the parameter acquisition process of the comprehensive method.

[0054] Unified coordinate format: The coordinate forms of the 1980 Xi'an coordinate system results are mainly geodetic coordinates or Gaussian projection coordinates, while the coordinate form of the comprehensive method transformation model is spatial rectangular coordinates. Therefore, the coordinate forms should be unified when determining the transformation parameters. The specific transformation process is as follows: Figure 8 As shown: Let point P be the coordinate P(x,y) in the Gaussian plane. Given the Gaussian plane coordinates of point P, to obtain the geodetic coordinates P(B,L), an inverse Gaussian calculation is required, where L is the geodetic longitude of point P. The specific formula is as follows: (3); In equation (3), B is the geodetic latitude of point P; The latitude of the base point; y N The x-axis represents the natural coordinate. The radius of curvature of the meridian at the latitude of the base point; The radius of curvature of the zonal circle at the latitude of the base point; As an auxiliary quantity, the calculation formula is: , The second flattened heart rate, , t is the major semi-axis of the ellipsoid, b is the minor semi-axis of the ellipsoid, and t is the latitude tangent of the base point. The longitude difference is the difference between the point to be determined and the central meridian.

[0055] The formula for converting between geodetic coordinates and direct spatial coordinates is as follows: (4).

[0056] In equation (4), (B, L, H) are the geodetic coordinates on the ellipsoid, i.e., latitude, longitude, and geodetic height; (X, Y, Z) are the spatial rectangular coordinates; and N is the radius of curvature of the prime mover. The first eccentricity of the ellipsoid; Where N= , For the semi-major axis of the ellipsoid, , It is the minor semi-axis of the ellipsoid.

[0057] Parameter Calculation: The process of obtaining the parameters using the synthetic method is described below: ① Based on the control network type and site distribution, select overlapping points and checkpoints.

[0058] ② Using the coincident points, the transformation parameters are obtained according to the transformation model. By substituting the parameters back, the transformation coordinates and coordinate residuals of the coincident points are obtained.

[0059] ③ Use a polynomial to fit the coordinate residuals, remove points whose coordinate residuals do not meet the accuracy requirements, and then redetermine the coincident points.

[0060] ④ Repeat steps ② and ③ until the residual coordinates of the coincident points meet the accuracy requirements.

[0061] The process of obtaining parameters for the four-parameter transformation of a plane: The process of obtaining parameters for the four-parameter transformation of a plane is divided into two categories: one is the transformation from the 1980 Xi'an coordinate system and the 1954 Beijing coordinate system to CGCS2000, and the other is the transformation from an independent coordinate system to CGCS2000.

[0062] The coordinate system was changed from the Xi'an coordinate system of 1980 and the Beijing coordinate system of 1954 to CGCS2000.

[0063] Based on the distribution of control point results within the province, the control point distribution is divided into regions according to the size of the region. After the division, the results of different coordinate systems are re-Gaussian projected according to the central meridian of the region to solve some coordinate cross-zone problems and ensure that the projection deformation is minimized.

[0064] The transformation parameters are obtained from the projected coordinates using a four-parameter model. The obtained parameters are numbered according to the partition, with the numbering method being Q1, Q2, Q3... (representing the transformation from the 1980 coordinate system to CGCS2000), B1, B2, B3... (representing the transformation from the 1954 Beijing coordinate system to CGCS2000).

[0065] Transformation from independent coordinate systems to CGCS2000: Independent coordinate systems vary greatly due to differences in their construction time and the units involved, the variety of technical methods, and the corresponding national standards. This makes it impossible to use a unified method to determine the transformation relationship between CGCS2000 and independent coordinate systems.

[0066] Based on the actual conditions of each independent coordinate system, the transformation methods used during the transformation process can be summarized into two main categories and seven methods, as detailed below. Figure 9 The optimal conversion method was selected through extensive trial calculations and comparisons.

[0067] Accuracy verification: Verification of the accuracy of the transformation parameters using the comprehensive method: Accuracy verification is divided into internal compliance accuracy and external compliance accuracy. Internal compliance accuracy has been completed during the parameter conversion process. Here, we only describe the external compliance accuracy verification process.

[0068] First, convert the results of various coordinate systems to CGCS2000 using the determined transformation parameters. Then, calculate the difference between the transformed CGCS2000 and the adjusted CGCS2000 to obtain the coordinate residuals of each coordinate component. Finally, calculate the external compliance accuracy of the transformation parameters according to the following formula.

[0069] (5); Equation (5) is the formula for calculating the external consistency accuracy of spatial coordinate point residuals. For coordinate component residuals, This represents the spatial coordinate point residual.

[0070] (6); Equation (6) is the formula for calculating the external consistency accuracy of the Gaussian projection coordinate point residuals. For coordinate component residuals, The residuals are the coordinates of the Gaussian projection points.

[0071] The accuracy of the conversion parameters using the comprehensive method is shown in Table 3.

[0072] Table 3 Accuracy of Conversion Parameters in the Comprehensive Method

[0073] Verification of the accuracy of planar four-parameter transformation: The overall accuracy of the four-parameter transformation of the plane from the 1980 Xi'an coordinate system and the 1954 Beijing coordinate system to CGCS2000 is better than ±0.05m in each region, which is higher than the accuracy of the comprehensive method transformation. The overall accuracy of the transformation of the independent coordinate system to CGCS2000 is better than ±0.1m.

[0074] S4. Grid the standard conversion parameters and integrate the gravity-based geoid to determine the geoid, and then evaluate and refine its accuracy.

[0075] The gridding of transformation parameters is the core of determining the entire transformation method. Based on extensive empirical calculations, this invention divides the grid into "15″×15″" grids, corresponding to actual distances of approximately "500m×500m," ensuring the accuracy of parameters as the transformation area expands. The coordinate system used for the grid is CGCS2000. Filling the parameter grid requires extensive programming to establish the correspondence between the transformation parameters and the area, as detailed below: Step 401: Grid the entire province according to the grid division requirements. Based on the accuracy verification results, the accuracy of the planar four-parameter transformation model is better than the comprehensive method. First, fill the grid with the planar four parameters of each partition according to the actual positions corresponding to the parameters. Considering that the boundary of a partition area cannot cover a complete grid, the filling of the transformation parameters is based on the size of the coverage area. If the boundary coverage area exceeds 50% of a grid, then fill a grid; otherwise, do not fill a grid. After filling, add a 1″ outline to the outer boundary of the filled area to solve the grid edge connection problem. For areas not filled with four parameters, fill them entirely with the parameters obtained by the comprehensive method. See the appendix for the specific filling method. Figure 3 See attached for the fill effect. Figure 10 .

[0076] Step 402: All grids are numbered according to uniform requirements. The numbering rule is "xxxxyyyy", where x represents the row number and y represents the column number. For example, grid "00210310" represents the grid in row 21 and column 310. The grid number includes the area where the grid is located, and all are automatically generated by the program. Step 403: Match the grid number with the parameter number. For example, the parameter number "C" is represented as "00210310C" with the corresponding grid number "00210310". This forms the grid code shown in the figure below. Figure 7 In the text, "C" indicates that the parameters for this region are converted to a single set of parameters for the entire province, and "Qi" indicates that the parameters for this region are converted to the four parameters for the i-th region.

[0077] Step 404: Parameter conversion search. Assuming P(B,L) is the result of the 1980 Xi'an coordinate system, the result of point P is converted to CGCS2000 based on the parameters of the Bursa model, and then the grid corresponding to point P is searched.

[0078] Step 405: If point P belongs to the 00050003 grid, then use the planar four-parameter model and parameter Q1 for coordinate transformation.

[0079] Specifically, assume that the coordinates of point P in the 1980 Xi'an coordinate system are (B p L p First, the coordinates of point P are converted to CGCS2000 using the synthetic method parameters. Then, the point position is mapped to a specific grid, and the corresponding grid number is read. If the number is "C", the synthetic method parameters will be called to convert P(B) to CGCS2000. p L p Convert to CGCS2000, if the number is "Q i Then, the four parameters of the i-th region will be called to P(B) p L pThe coordinates are converted to CGCS2000 and combined with the central meridian of the region. The CGCS2000 coordinates obtained by parameter conversion are converted to CGCS2000 coordinates under the standard zone by changing the zone.

[0080] The process of integrating gravity-based quasi-geoids to determine, assess, and refine the quasi-geoid mainly includes: processing and analyzing densified gravity data; processing elevation model data; analyzing and processing GNSS leveling points; gravity reduction and average gravity anomaly calculation; calculation of gravity-based quasi-geoid years; GNSS calculation of the measured quasi-geoid; correction of the gravity-based quasi-geoid using GNSS leveling data; and model progress verification.

[0081] Based on national standards and application requirements, the provincial geoid model is configured with a grid resolution of [resolution value missing]. The model accuracy for plains and low hills was designed to be ±3~5cm, while the accuracy for mountains and plateaus was ±5~8cm. The quasi-geoid calculation integrated provincial 5-meter grid DEM data, gravity data, GPS results, high-precision leveling results, and regional gravity field models. Finally, the quasi-geoid accuracy was verified by topographic region. The model accuracy for plains and low hills was ±2.4cm, and the model accuracy for mountains and plateaus was ±5.2cm; both meeting the accuracy design requirements. The evolution process of the quasi-geoid model is shown in the appendix. Figure 4 .

[0082] Example 2 The provincial-level spatial reference online conversion method is equipped with a software platform, and the software platform is equipped with an encryption unit.

[0083] The encryption unit establishes a collaborative encryption architecture, deploying a server-side encryption module, a transmission link encryption channel, a user-side lightweight encryption component, a data storage encryption module, and a key-token-generation factor management server. It clarifies the adaptation standards, permission division, encryption strategies, generation rules, interaction processes, and update mechanisms for the three-level encryption levels and tokens.

[0084] Furthermore, the encryption unit includes the following tasks: a) initialization of generation factors and tokens; b) encryption of identity authentication during token interaction; c) encryption of data transmission during token interaction; d) encryption of conversion parameters bound to generation factors; e) encryption of data storage; f) encryption of result data bound to the fusion terminal; g) closed-loop management of key-generation factor-token.

[0085] The key-token-generation factor management server is the core carrier of the entire key and token management process, corresponding to tasks a and g, and is responsible for generating, distributing, updating, and deregistering root keys, derived keys, generation factors, and tokens.

[0086] The server-side encryption module runs throughout the task group and is responsible for identity authentication and verification, certificate authentication and data encryption during data transmission, conversion parameter decryption and signature verification, result encryption authorization, and security core encryption operations and verification.

[0087] The encrypted transmission link channel supports encrypted transmission and token interaction using encryption algorithms. Task c is the secure carrier for all data transmission between the user and the server, enabling confidentiality and integrity verification during data transmission.

[0088] The lightweight encryption component on the user side is responsible for lightweight encryption operations such as local encrypted storage on the user side, token generation and interaction, and result decryption, corresponding to tasks a, b, c, and f.

[0089] The data storage encryption module corresponds to tasks e and f, and is responsible for the encrypted storage of classified or non-classified data, log data, generation factors, and tokens in the server-side partitioned storage, as well as the encrypted storage of local data on the user end, to prevent data leakage in the storage process.

[0090] Furthermore, the specific content of task a includes: After a user registers or logs in for the first time, the server randomly generates base data based on the user's terminal device identifier, user permissions, and default encryption level, and then generates the first generation factor. Simultaneously, an initial verification token is generated and pushed to the user's terminal storage.

[0091] The user terminal stores the generation factor and the initial verification token, and establishes a binding relationship between the terminal device identifier and the generation factor and token.

[0092] Task b includes the following: When a user logs in, the password is encrypted and stored using SHA-256 hash + salt value, and the password transmission uses double encryption.

[0093] Meanwhile, the user terminal generates a verification token based on the stored generation factor and terminal device identifier, and sends it to the server.

[0094] The server parses the verification token, verifies the validity of the generation factor and terminal device identifier, and completes identity authentication by combining it with password verification.

[0095] The secondary encryption scenario uses a two-factor authentication method that combines account password with SMS or email verification code for one-time token verification.

[0096] Level 3 encryption scenarios employ a two-factor authentication method that combines account and password with hardware encryption devices for secondary token verification. After logging in, an encrypted session token is generated to encrypt the session and destroy it after a timeout, while also updating the generation factor.

[0097] Furthermore, the specific content of task c includes: When a user initiates a conversion request, the number of conversion requests N (N≥1) is recorded. If N>1, a second generation factor is generated based on the first generation factor, and the verification token is updated.

[0098] All data between the user and the server is transmitted through an encrypted channel. The user sends a verification token and the server sends a response token. Data transmission can only proceed after both parties have completed the token comparison and verification.

[0099] All transmitted data is accompanied by a message authentication code generated by SM4, which, combined with the token verification result, enables the verification of the confidentiality, integrity, and legality of data transmission.

[0100] Furthermore, the specific content of task d includes: The conversion parameters are stored with dual encryption using SM4 or SM4+ hardware encryption modules, and the key, generation factor, user permissions, and terminal device identifier are bound together.

[0101] When calling parameters, the client sends a verification token and a parameter call request. After the server verifies the validity of the token and the generation factor, it temporarily decrypts the parameters using SM2. The decrypted parameters are only temporarily stored in memory and destroyed immediately after the conversion is completed.

[0102] Simultaneously, all parameters are digitally signed using SM2, and the signature is verified in conjunction with the generation factor to prevent tampering.

[0103] The generation factor is updated synchronously with the number of parameter calls, ensuring that the parameter calls are bound to the terminal and the number of requests.

[0104] Furthermore, the specific content of task e includes: The server adopts a partitioned storage mode, with classified and non-classified data physically isolated. Source data, result data, log data, generation factors, and tokens are stored using corresponding levels of encryption algorithms. Log data, token interaction logs, and generation factor update logs are encrypted and retained for no less than one year. The user terminal uses the corresponding encryption method to store the generation factor, token, and local data according to the terminal type to prevent leakage caused by terminal theft.

[0105] Furthermore, the specific content of task f includes: The standard results are encrypted using SM4, and the key, generation factor, user account, and terminal device identifier are bound together.

[0106] Classified results are encrypted using SM4 double encryption with embedded watermarks, and are subject to "one person, one authorization," supporting authorized sharing and setting an expiration date.

[0107] After downloading, users can decrypt the app by entering their account password and verification token using a dedicated tool.

[0108] The specialized tool is a component tool for a lightweight encryption component on the user side.

[0109] The dedicated tool restricts the results to being opened only a specified number of times on the bound terminal device, and uses a data overwrite mode when deleting to prevent data recovery.

[0110] At the same time, the download and usage records of the results can be traced through the generation of factors and tokens.

[0111] Furthermore, the specific content of task g includes: The root key and various derived keys are generated through a key management server and distributed using encrypted channels or hardware devices. The root key is protected by HSM hardware.

[0112] The generation factor is updated synchronously with the number of conversion requests and the encryption level adjustment, and the token is refreshed synchronously with the generation factor update, realizing the linkage update of key, generation factor and token.

[0113] The key and generation factor are automatically updated according to a preset cycle. For scenarios such as account cancellation, device loss, and token abnormality, the key, generation factor, and token can be cancelled and residual cleaned up in a compliant manner.

[0114] Example 3 The software design and development employed VC++ and a client / server architecture, primarily consisting of a server-side and a client-side component. The server-side primarily addressed two main issues: firstly, how to protect confidential data such as coordinate transformation parameters and the geoid; and secondly, server-side access issues. In practice, the server-side, coordinate transformation parameters, and geoid data were encapsulated and managed using dynamic authorization passwords; access to the server-side software was impossible without the password. The client-side was deployed on PCs, with the software uniquely bound to the PC via a machine serial number and equipped with an independent encryption / decryption module. Users logged in to the client using a dedicated account and password to achieve online coordinate transformation. The architecture of the online coordinate transformation service system is attached. Figure 5 This can be achieved through the following steps: Step 101: System architecture design.

[0115] Step 102: Programming language selection.

[0116] Step 103: Server-side and client-side development.

[0117] Step 104: Server-side deployment and model plug-in functionality added.

[0118] Step 105: Deploy the client and independent encryption / decryption modules.

[0119] Example 4 The network information configuration and online conversion system includes server-side and client-side software. Both software are developed based on a client / server architecture. The client and server are linked via communication methods such as the Internet, GPRS, CDMA, and Wi-Fi, and this is achieved through the following steps: Step 201: Implement multi-level management of users and administrators on the server side to enhance management security.

[0120] Step 202: Users can obtain conversion services on their own within the authorized scope, preventing malicious use.

[0121] Step 203: The conversion model, classified parameters, and geoid refinement model are encapsulated in server-side software and deployed on the server. Non-authorized personnel and ordinary people cannot access the classified data.

[0122] Step 204: Client software deployment is carried out through authorized deployment. The client and computer are physically bound together. Under network connectivity, data exchange with the server is achieved through the client software.

[0123] Step 205: Convert data for encrypted transmission to ensure data security. There are two encryption modes: active encryption mode and passive encryption mode. In passive encryption mode, the source file participating in the operation is not encrypted, but it is automatically encrypted during transmission. Active encryption means that the source file is encrypted first through a separate encryption module before participating in the operation. The result file of the operation needs to be decrypted before it can be opened.

[0124] Step 206: Online conversion by users. Users, based on authorization, log in remotely with their dedicated accounts and perform coordinate conversion services as needed. Coordinate conversion can be single-point or batch conversion. For enterprises and institutions, this not only improves production efficiency and saves production costs to a certain extent, but also yields significant socio-economic benefits and is highly valuable for promotion.

[0125] The online coordinate conversion system serves as an important supplement to the services provided by provincial surveying and mapping benchmarks. It aims to maximize the satisfaction of users' conversion needs between different coordinate systems and facilitate user operation. To ensure user-friendly interaction with the computer, and while prioritizing security, the system includes the following functions.

[0126] (1) User can change login password: In order to ensure the user’s use and management of their own account, the user can change the login password on the client after authorization.

[0127] (2) Coordinate transformation: After successful login, users can perform corresponding coordinate transformations within the authorized range. Coordinate transformation can be a single point transformation or a batch transformation. The user-side coordinate transformation interface is as follows: Figure 11 As shown.

[0128] (3) File Encryption: Considering that user coordinates need to be transmitted to the server for processing during coordinate transformation, an encryption module is designed to prevent data leakage during data transmission. Users can use the encryption module GsEnDeData.exe to encrypt ordinary source files. When selecting the active encryption method (corresponding to the encrypted source file ".MMM"), the ordinary source file must first be encrypted using the encryption module GsEnDeData.exe. Double-click GsEnDeData.exe to start running the encryption module.

[0129] This invention solves the problem of converting coordinate data between CGCS2000 and the 1980 Xi'an coordinate system, the 1954 Beijing coordinate system, and city-specific coordinate systems within a province. It lays a solid foundation for unifying various coordinate data across the province and facilitates seamless integration of different coordinate systems. The software framework is rationally constructed, easy to operate, and allows users to convert coordinates online independently, making it highly practical and widely applicable.

[0130] Finally, it should be noted that the above embodiments are only used to illustrate the technical methods of the present invention and not to limit them. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the technical methods of the present invention, and these modifications or equivalent substitutions cannot cause the modified technical methods to deviate from the spirit and scope of the technical methods of the present invention.

Claims

1. A method for online conversion of provincial spatial references, characterized in that, Includes the following steps: S1. Obtain mapping benchmark information in different coordinate systems and analyze existing results data, and perform GNSS static measurement on existing results data to obtain network adjustment results data; S2. Perform point consistency analysis on existing data and network adjustment data, and screen out gross errors to obtain clean data. S3. Select a parameter calculation model, calculate the initial conversion parameters based on the parameter calculation model, and verify them to obtain the standard conversion parameters; S4. The standard transformation parameters are gridded and integrated with the gravity-based geoid to determine the geoid, and the accuracy is evaluated and refined. The provincial-level spatial reference online conversion method is equipped with a software platform, and the software platform is equipped with an encryption unit; The encryption unit establishes a collaborative encryption architecture, deploying a server-side encryption module, a transmission link encryption channel, a user-side lightweight encryption component, a data storage encryption module, and a key-token-generation factor management server. It clarifies the adaptation standards, permission division, encryption strategies, generation rules, interaction processes, and update mechanisms for the three-level encryption levels and tokens. The point self-consistency analysis in S2 includes the coordinate method and the baseline vector method; The coordinate method refers to evaluating the absolute positional consistency of the points by comparing the X and Y coordinates of the existing data and the network adjustment data. The baseline vector method involves evaluating the relative changes between the point vectors of existing data and network adjustment data. There are pre-set limit tables for coordinate method and vector method; Filter out the points exceeding the limit in the coordinate method and the vectors exceeding the limit in the baseline vector method, and mark them; Based on the cases of exceeding the limits, each point was analyzed and judged to identify gross errors. By combining the network adjustment results with the gross error information, the network adjustment results are updated to obtain clean data.

2. The method according to claim 1, wherein, The parameter calculation models described in S3 include the comprehensive method transformation model and the planar four-parameter transformation model; The specific details of selecting parameters and calculating the model include: The distribution range of existing data points within the region was studied, and some points were selected as parameter calculation points and others as accuracy check points. Based on the characteristics of the model, the parameters are obtained. Based on the features of the comprehensive method model, the transformation parameters are obtained throughout the province to form a set of transformation parameters for the whole province. The transformation parameters of the four-parameter planar model are obtained by dividing the point distribution into blocks, with the overlap of the block areas ≥ 30%. The accuracy of the conversion parameters is verified using two evaluation indicators: internal compliance accuracy and external compliance accuracy, to determine the final conversion model and parameter accuracy.

3. The method according to claim 2, wherein, The encryption unit includes the following tasks: a) generating factor and token initialization; b) encrypting identity authentication through token interaction; c. Encrypted data transmission during token interaction; d. Encrypted conversion parameters bound to fusion generation factors; e. Encrypted data storage; f. Encrypted result data bound to fusion terminals; g. Closed-loop management of key-generation factor-token. The key-token-generation factor management server is the core carrier of the entire key and token management process, corresponding to tasks a and g, and is responsible for generating, distributing, updating, and deregistering root keys, derived keys, generation factors, and tokens. The server-side encryption module runs throughout the task group and is responsible for identity authentication and verification, certificate authentication and data encryption in data transmission, conversion parameter decryption and signature verification, result encryption authorization, and security core encryption operations and verification. The encrypted transmission link channel supports encrypted transmission and token interaction using encryption algorithms. Task c is the secure carrier for all data transmission between the user and the server, enabling confidentiality and integrity verification during data transmission. The lightweight encryption component on the user side is responsible for lightweight encryption operations such as local encrypted storage, token generation and interaction, and result decryption on the user side, corresponding to tasks a, b, c, and f. The data storage encryption module corresponds to tasks e and f, and is responsible for the encrypted storage of classified or non-classified data, log data, generation factors, and tokens in the server-side partitioned storage, as well as the encrypted storage of local data on the user end, to prevent data leakage in the storage process.

4. The provincial spatial reference online conversion method of claim 3, wherein, The specific content of Task A includes: After a user registers or logs in for the first time, the server randomly generates base data based on the user's terminal device identifier, user permissions, and default encryption level, and then generates the first generation factor, simultaneously generating the initial verification token and pushing it to the user's terminal storage. The user terminal stores the generation factor and the initial verification token, and establishes a binding relationship between the terminal device identifier and the generation factor and token; Task b includes the following: When a user logs in, the password is encrypted and stored using SHA-256 hash + salt value, and the password transmission uses double encryption; Meanwhile, the user terminal generates a verification token based on the stored generation factor and terminal device identifier, and sends it to the server. The server parses the verification token, verifies the legality of the generation factor and terminal device identifier, and completes identity authentication by combining it with password verification. Level 2 encryption scenarios employ a two-factor authentication method that combines account password with SMS or email verification code for one-time token verification; Level 3 encryption scenarios employ a two-factor authentication method that combines account and password with hardware encryption devices for secondary token verification. After logging in, an encrypted session token is generated to encrypt the session and destroy it after a timeout, while also updating the generation factor.

5. The provincial spatial reference online conversion method according to claim 4, wherein, Task C includes the following: When a user initiates a conversion request, the number of conversion requests N (N≥1) is recorded. If N>1, a second generation factor is generated based on the first generation factor, and the verification token is updated. All data between the user and the server is transmitted through an encrypted channel. The user sends a verification token and the server sends a response token. Data transmission can only proceed after both parties have completed the token comparison and verification. All transmitted data is accompanied by a message authentication code generated by SM4, which, combined with the token verification result, enables the verification of the confidentiality, integrity, and legality of data transmission.

6. The provincial spatial reference online conversion method according to claim 5, wherein, The specific content of task d includes: The conversion parameters are stored with dual encryption using SM4 or SM4+ hardware encryption modules, and the key, generation factor, user permissions, and terminal device identifier are bound together. When calling parameters, the client sends a verification token and a parameter call request. After the server verifies the validity of the token and the generation factor, it uses SM2 to temporarily decrypt the parameters. The decrypted parameters are only temporarily stored in memory and destroyed immediately after the conversion is completed. Simultaneously, all parameters are digitally signed using SM2, and the signature is verified in conjunction with the generation factor to prevent tampering. The generation factor is updated synchronously with the number of parameter calls, ensuring that the parameter calls are bound to the terminal and the number of requests.

7. The method according to claim 6, wherein, Task e includes the following: The server adopts a partitioned storage mode, with classified and non-classified data physically isolated. Source data, result data, log data, generation factors, and tokens are stored using corresponding levels of encryption algorithms. Log data, token interaction logs, and generation factor update logs are encrypted and retained for no less than one year. The user terminal uses the corresponding encryption method to store the generation factor, token, and local data according to the terminal type to prevent leakage caused by terminal theft.

8. The method according to claim 7, wherein, The specific content of task f includes: Standard results are encrypted using SM4, and the key and generation factor are bound to the user account and terminal device identifier. Classified results are encrypted using SM4 double encryption with embedded watermarks, and support authorized sharing with a validity period. After downloading, users must enter their account password and verification token using a dedicated tool to decrypt the file. The specialized tool is a component tool for a lightweight encryption component on the user side; Specialized tools limit the number of times results can be opened on the bound terminal device, and use a data overwrite mode when deleting to prevent data recovery; At the same time, the download and usage records of the results can be traced through the generation of factors and tokens.

9. The method according to claim 8, wherein, The specific content of task g includes: The root key and various derived keys are generated through a key management server and distributed using encrypted channels or hardware devices. The root key is protected by HSM hardware. The generation factor is updated synchronously with the number of conversion requests and the encryption level adjustment, and the token is refreshed synchronously with the generation factor update, realizing the linkage update of key, generation factor and token; The key and generation factor are automatically updated according to a preset cycle. For scenarios such as account cancellation, device loss, and token abnormality, the key, generation factor, and token can be cancelled and residual cleaned up in a compliant manner.