A data processing method based on a spliced shared space command shelter

By generating a spliced ​​confidence state and security domain relationship diagram of the spliced ​​shared space command module, the problem of dynamic state management of seats and data flow in multi-module collaborative operations was solved, realizing secure and controllable data access and risk suppression, and avoiding information leakage and task chaos.

CN122372226APending Publication Date: 2026-07-10WUHAN LINGAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
WUHAN LINGAN TECH CO LTD
Filing Date
2026-06-09
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing modular shared command modules lack unified dynamic status management and security constraints for seats, terminals, and business data flows in multi-module collaborative operations. This leads to data sharing across modules and business domains relying on physical connectivity, resulting in information leaks and chaotic task execution.

Method used

By acquiring the shared space operation data set bound to the modular shelter assembly relationship, a splicing confidence status is generated, a seat security profile and data flow security label are established, permission verification is performed using the shared space security domain relationship graph, and a shared permission token is generated to achieve hierarchical sharing processing.

Benefits of technology

Under the conditions of changes in splicing structure and business collaboration, we must continuously maintain the effectiveness of security domain boundaries, avoid erroneous merging of security domains, and achieve full-process controllability and risk controllability of data access behavior.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372226A_ABST
    Figure CN122372226A_ABST
Patent Text Reader

Abstract

This invention provides a data processing method based on a modular shared command module, belonging to the technical field of data processing. The method includes: collecting operational data from the modular shared space and generating a modular confidence state; constructing a security domain relationship graph for the shared space; forming seat security profiles and data flow security tags; performing permission verification object matching based on the relationship graph during data subscription; generating a shared permission token in cross-module or cross-business domain scenarios; and finally performing hierarchical sharing processing on the target data flow based on the shared permission token, achieving dynamic security control of the data access and sharing process. This invention can improve the security of data processing in multi-module modular collaborative operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and specifically to a data processing method based on a modular shared space command cabin. Background Technology

[0002] Modular shared command modules are widely used to achieve collaborative operations and data sharing among multiple modules. Existing technologies typically achieve collaborative management of personnel and equipment through physically connecting modules, inter-module communication interfaces, and shared operating areas, and transmit data via standardized networks and communication protocols. However, existing solutions often lack the ability to uniformly manage and securely constrain the dynamic state of each seat, terminal, and business data stream after modularization. This leads to cross-module and cross-business domain data sharing relying heavily on physical connectivity, while lacking dynamic verification of permissions, identities, and business domain boundaries.

[0003] A significant technical flaw in existing technologies is that when multiple modular units are physically assembled, the access permissions, user identities, and business domain boundaries of seats and terminals fail to be updated in real time. This can lead to some seats potentially subscribing to data streams from other modular units without authorization. This is especially problematic in scenarios involving cross-unit sharing of situational data, video transmission, or mission instructions. Such mismerging of security domains can cause information leaks and mission execution chaos. Summary of the Invention

[0004] This invention provides a data processing method based on a modular shared space command module, which can improve the security of data processing in collaborative operations involving multiple modules.

[0005] In a first aspect of the present invention, a data processing method based on a modular shared space command module is provided, the method comprising: For multiple modular shared command cabins, obtain a set of shared space operation data bound to the modular cabin splicing relationship; Preprocessing is performed on the shared space operation data set to generate spliced ​​confidence states; Based on the shared space security domain relationship diagram, a seat security profile corresponding to each seat node is established, and a data flow security label corresponding to each data flow node is established. The shared space security domain relationship diagram is constructed based on the spliced ​​confidence state. The system parses any data subscription request initiated by any seat node and searches for the permission verification object corresponding to the parsing result in the shared space security domain relationship graph. When the data subscription request involves cross-cabin, cross-business domain or cross-cabin public display area, the data subscription request is verified. If the verification is successful, a shared permission token is generated based on the seat security profile and the data flow security tag. Based on the shared permission token, hierarchical sharing processing is performed on the target data stream.

[0006] In a second aspect of the invention, a data processing apparatus based on a modular shared space command module is provided. The apparatus is used to execute a data processing method based on a modular shared space command module as described above. The apparatus includes an acquisition module, a processing module, and an output module, wherein: The acquisition module is used to acquire a set of shared space operation data bound to the splicing relationship of multiple spliced ​​shared space command cabins. The processing module is used to perform preprocessing on the shared space operation data set to generate spliced ​​confidence states; The processing module is used to establish a seat security profile corresponding to each seat node based on the shared space security domain relationship graph, and to establish a data flow security label corresponding to each data flow node, wherein the shared space security domain relationship graph is constructed based on the splicing confidence state; The processing module is used to parse the data subscription request initiated by any seat node and search for the permission verification object corresponding to the parsing result in the shared space security domain relationship graph. The processing module is used to verify the data subscription request when the data subscription request involves cross-cabin, cross-business domain or cross-cabin public display area, and generate a shared permission token based on the seat security profile and the data flow security tag when the verification is successful. The output module is used to perform hierarchical sharing processing on the target data stream based on the shared permission token.

[0007] In a third aspect of the invention, an electronic device is provided, including a processor, a memory, a user interface, and a network interface, wherein the memory is used to store instructions, the user interface and the network interface are both used to communicate with other devices, and the processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method as described in any of the preceding embodiments.

[0008] In a fourth aspect of the invention, a non-transitory computer-readable storage medium is provided, the computer-readable storage medium storing instructions that, when executed, perform the method as described in any of the preceding claims.

[0009] In summary, one or more technical solutions provided in the embodiments of the present invention have at least the following technical effects or advantages: This invention transforms the modular cabin assembly state into a quantifiable assembly confidence state, and on this basis, constructs a shared space security domain relationship graph. This transforms the original sharing mechanism, which relied solely on physical connectivity, into a structured relationship model with dynamic semantic constraints. Simultaneously, it utilizes seat security profiles and data flow security tags to bidirectionally characterize access subjects and data objects. When a data subscription request occurs, path-level verification based on the relationship graph is implemented through permission verification objects. In cross-cabin or cross-business domain scenarios, a shared permission token is introduced as a fine-grained access control carrier. Furthermore, combined with hierarchical sharing processing, dynamic constraints are applied to data content and transmission methods. This ensures the continued effectiveness of security domain boundaries under conditions of changes in assembly structure, seat status, and business collaboration, avoiding security domain malfunctions caused by physical connectivity. Ultimately, this achieves full-process controllability and risk mitigation of data access behavior during multi-modal cabin collaborative operations. Attached Figure Description

[0010] Figure 1 This is a flowchart illustrating a data processing method based on a modular shared space command cabin disclosed in an embodiment of the present invention. Figure 2 This is a schematic diagram of the exterior of a modular shared space command cabin disclosed in an embodiment of the present invention; Figure 3 This is a schematic diagram of the layout of a modular shared space command cabin disclosed in an embodiment of the present invention; Figure 4 This is a schematic diagram of a data processing device based on a modular shared space command cabin disclosed in an embodiment of the present invention; Figure 5 This is a schematic diagram of the structure of an electronic device disclosed in an embodiment of the present invention.

[0011] Explanation of reference numerals in the attached drawings: 401, acquisition module; 402, processing module; 403, output module; 501, processor; 502, communication bus; 503, user interface; 504, network interface; 505, memory. Detailed Implementation

[0012] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.

[0013] In the description of the embodiments of the present invention, words such as "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "for example" or "for instance" in the embodiments of the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of words such as "for example" or "for instance" is intended to present the relevant concepts in a specific manner.

[0014] In the description of the embodiments of the present invention, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0015] While existing technologies achieve physical connectivity and shared operating areas in multi-cabin assembly and collaborative operations, they lack unified management and security constraints on the dynamic status of seats, terminals, and business data streams. This makes cross-cabin and cross-business domain data sharing dependent on physical connectivity and lacks real-time verification of permissions, identities, and business domain boundaries. This can easily lead to some seats accessing data streams from other cabins without authorization, resulting in information leaks and task execution chaos.

[0016] This invention discloses a data processing method based on a modular shared space command module, which is applied to a server. The server includes, but is not limited to, electronic devices such as mobile phones, tablets, wearable devices, and PCs (Personal Computers), and can also be a backend server running the data processing method based on the modular shared space command module. The server can be implemented using a standalone server or a server cluster composed of multiple servers.

[0017] This embodiment discloses a data processing method based on a modular shared space command cabin, referring to... Figure 1 It includes the following steps: S110 is designed for multiple modular shared command cabins, acquiring a set of shared space operation data bound to the modular cabin splicing relationship.

[0018] S120 performs preprocessing on the shared space operation data set to generate spliced ​​confidence states.

[0019] S130: Based on the shared space security domain relationship diagram, establish a seat security profile corresponding to each seat node, and establish a data flow security label corresponding to each data flow node.

[0020] S140: Parse the data subscription request initiated by any seat node and search for the permission verification object corresponding to the parsing result in the shared space security domain relationship graph.

[0021] S150: When a data subscription request involves cross-cabin, cross-business domain, or cross-cabin public display area, the data subscription request is verified. If the verification is successful, a shared permission token is generated based on the seat security profile and data flow security label.

[0022] S160, performs hierarchical sharing processing on the target data stream based on the shared permission token.

[0023] Mobile command modules are core mobile operation platforms in fields such as emergency command and communication support. Existing command module designs mainly take two forms: 1. Single-compartment extended independent modular unit or short-side spliced ​​external equipment compartment: This type expands the working space by extending the length of a single modular unit, or separates the equipment layout and personnel operating area by attaching an independent equipment compartment to a standard unit. Due to road width restrictions, the interior is often long and narrow. When arranging operating tables inside, space is limited, resulting in small worktables. The design of the display screen is also limited by the width of the short side of the unit, restricting it to approximately 55-inch LCD screens. If the screen is placed on the long side, personnel will be too close to the screen, resulting in a poor viewing experience. 2. Laterally electrically extended modular unit or electrically extended unit with independent external equipment compartment: This type expands the space by electrically unfolding the long side wall of the unit. If a large number of back-end cabinet devices need to be arranged, the unit needs to be extended and partitioned to create an equipment layout area, or an independent external equipment compartment needs to be attached.

[0024] Reference Figure 2 as well as Figure 3A modular shared space command cabin includes: an equipment cabin and a personnel operation cabin, both with widths meeting road transport width restrictions, and capable of being horizontally spliced ​​together after the long side panels are removed; the equipment cabin is equipped with a partition structure, dividing it into an equipment installation area and a shared space, which is connected to the personnel operation cabin to form an expanded personnel operation area, and the partition structure can effectively isolate the operating noise generated by the back-end cabinet equipment; a high-definition LED splicing screen is installed on the partition structure of the equipment cabin, with the screen size adapted to the expanded operation area, for data visualization and command and dispatch display; four 5-screen operation consoles are arranged in fixed positions in the personnel cabin, and two 5-screen operation consoles are fixed in the shared space of the equipment cabin during transportation. After the cabin is spliced ​​and deployed, they are deployed at the junction of the two cabins, forming an enclosed layout with three 5-screen operation consoles on each side and an electrically rotating electronic sand table in the middle, together with the original operation consoles in the personnel cabin. Together with the high-definition LED splicing screen, it forms a compact and fully functional small command center. The equipment compartment and the personnel operation compartment are connected by a quick-assembly mechanism and a sealing structure, enabling rapid disassembly and assembly as well as airtight protection. The side panels of both compartments are made of lightweight materials and feature a modular structure for easy disassembly and temporary storage. Power supply and communication boxes are located at the connection points between the two compartments. After assembly, quick circuit and communication connections can be established via prefabricated jumpers and quick-release connectors. The equipment compartment can accommodate at least eight server racks and allows for front and rear maintenance. After assembly, it can support the deployment of at least six 5-screen control consoles and one 55-inch electronic sand table, providing the capability for large-scale equipment deployment and multi-station collaborative command and support.

[0025] In one possible implementation, after the two modular units are transported to the work site, the side panels are removed. The personnel unit is equipped with a bottom pulley moving device. Because the deployed equipment is relatively light, it can be moved towards the equipment unit by manpower or a towing vehicle for docking. At the same time, the equipment unit is equipped with leveling outriggers, which can be adjusted in height for quick docking with the personnel unit. The two-module splicing mechanism includes locking components and positioning pins, which can quickly complete the splicing and positioning of two modules. It is equipped with a fixed and detachable dual waterproof structure. The fixed waterproof device is automatically formed when the two modules are locked together, while the detachable waterproof structure is installed by the operator inside the module after the splicing is completed. The waterproof structure is installed into the splicing gap by means of locking, which not only ensures the overall aesthetics of the module but also ensures the waterproof performance of the splicing joint after the two modules are spliced. A total of 6 sets of 5-screen operating consoles are arranged in the two compartments. The two sets of operating consoles in the equipment compartment are locked in the equipment compartment during transportation. After the two compartments are spliced, the locking bolts are released, and the two sets of operating consoles are moved to the splicing position of the two compartments using the pulleys at the bottom of the operating consoles. They are then arranged in the same direction as the 4 sets of operating consoles originally arranged in the personnel compartment, and the splicing process of the container is completed.

[0026] In practical implementation, when acquiring the shared space operation data set bound to the modular unit assembly relationship, each participating command modular unit must first be uniquely identified, including its modular unit number, its assigned task number, and its modular unit type information. The modular unit number is used to identify each modular unit node after assembly, ensuring accurate mapping of physical units to their corresponding data and seats when constructing the shared space security domain relationship diagram. The assigned task number is used to bind the current assembly task cycle, ensuring that subsequent data management only applies to the current task scope. The modular unit type information is used to distinguish between equipment units, personnel operation units, or hybrid units, so as to allocate data streams and seat permissions according to the unit's function. During implementation, modular unit information can be read through the digital identification code stored inside the unit or through an embedded control module, and uploaded to the shared space management system via a secure communication interface to form a preliminary modular unit information table.

[0027] When collecting the inter-module connection status, it is necessary to obtain the physical assembly status, communication interface connectivity status, and power supply connectivity status of each module and its neighboring modules. The physical assembly status confirms whether the modules have completed actual locking and docking and the positioning pins are fixed. The communication interface connectivity status determines whether the inter-module data link is established and can transmit normally. The power supply connectivity status ensures the shared power supply and stable operation of equipment between modules. During implementation, various status information is collected in real time using sensors, status detection modules, and status signal acquisition circuits integrated into the quick-release interfaces installed in the modules. This information is then encoded and bound to the module's identity information to form an inter-module connection status table.

[0028] The seat deployment status data collection includes the spatial location, deployment direction, display area, and control area of ​​fixed control consoles, mobile control consoles, electronic sand table seats, LED splicing screen control seats, and temporary portable terminal seats. The seat deployment status is used to map the physical location and operating permissions of each seat after assembly, and provides a basis for permission verification and data flow routing. During implementation, positioning markers or RFID tags installed inside the cabin, combined with the cabin layout diagram, are used to read the current location and deployment status of each seat, and the information is bound to the cabin number and splicing position relationship to generate a seat status set.

[0029] Terminal authentication status collection includes the identity information, authentication status, and task binding status of all access seats and modular units' computing devices, display devices, and communication terminals. Terminal authentication status ensures that each terminal can access the corresponding data streams and service domains in the spliced ​​shared space according to security policies, while distinguishing between terminals remaining from historical tasks and terminals currently performing tasks. During implementation, authentication can be performed using the digital certificate, hardware fingerprint, or security token used when the terminal starts up, and the authentication result is associated with the seat node, modular unit node, and task number to form a terminal status table.

[0030] User login status collection includes the identity information, role, assigned task, accessible business domain, and temporary authorization period of each currently logged-in user. User login status is used to verify user access permissions during data subscription requests, ensuring that different users adhere to the principle of least privilege in cross-cabin and cross-business domain environments. During implementation, the login management system reads the user's identity and session state, maps them to the corresponding seat and terminal node, forming a user status set.

[0031] The business domain verification status collection includes the business domain identifier, security level, and cross-cabin sharing rules for each data stream. The business domain verification status is used to determine whether a data stream is allowed for cross-cabin transmission or cross-business domain access within the spliced ​​shared space. During implementation, the binding relationship between data streams and business domains is queried through the business management system, and these relationships are associated with the cabin number, seat number, terminal number, and task number to form a business domain status table.

[0032] Data flow attribute collection includes the source container, source terminal, task number, data type, propagation method, and control sensitivity of each data flow. Data flow attributes are used to establish data flow nodes in the shared space security domain relationship graph and assist in generating data flow security labels and permission mapping tables. During implementation, data flow attributes are read through network monitoring interfaces, data subscription records, and business application logs, and then bound to the container, seat, and terminal information in the spliced ​​confidence state to form a complete data flow state set.

[0033] Data subscription status collection includes data subscription request information initiated by each seat node or terminal, such as the requesting seat, requesting terminal, requesting user, target data stream, target business domain, request operation type, and request display location. Data subscription status is used to mark cross-domain candidate edges or permission mapping relationships when constructing the shared space security domain relationship graph. During implementation, the subscription management system captures subscription events from each seat or terminal and associates these events with the shelter, seat, terminal, user, and data stream node to form a data subscription status set, thereby completing the shared space operation data set bound to the shelter's splicing relationship.

[0034] In one possible implementation, preprocessing is performed on the shared space operational data set to generate a spliced ​​confidence state. Specifically, this includes: performing unified structured processing on the shared space operational data set to generate operational feature vectors; performing anomaly suppression processing based on the operational feature vectors to generate stable operational feature vectors; performing multi-source fusion processing based on the stable operational feature vectors to generate a splicing consistency index; performing confidence mapping processing based on the splicing consistency index to generate a spliced ​​confidence state; performing time-series smoothing processing based on the spliced ​​confidence state to generate a smoothed spliced ​​confidence state; and binding the smoothed spliced ​​confidence state with the shared space operational data set to generate a spliced ​​confidence state.

[0035] Specifically, regarding the unified structured processing of the shared space operation data set, time synchronization correction and semantic standardization are performed on the connection topology data, link status data, and spatial pose data from each modular unit. This ensures that different data sources form a consistent expression in terms of timestamps, data formats, and field meanings. Time synchronization correction compensates for the offset of timestamps from each data source, mapping them to a unified reference time axis. Semantic standardization unifies heterogeneous fields from different modular unit systems into a standard field set through predefined field mapping rules. Based on this, various types of data are vectorized and encoded. Discrete features are converted into numerical representations through one-hot encoding or embedding encoding, and continuous features are mapped to a unified numerical range through normalization, thereby forming an operation feature vector. The operation feature vector is used to uniformly describe the operation attributes of the modular unit in its current assembly state.

[0036] After obtaining the operational feature vector, anomaly suppression processing is performed on the feature vector to reduce the impact of outlier data on the overall evaluation. Outlier data includes instantaneous link fluctuations, sudden changes in device status, and spatial pose measurement errors. A multidimensional feature deviation function is constructed to quantify the degree to which each feature deviates from the statistical center, and a nonlinear compression mechanism is used to reduce the weight of outliers, making the processed feature vector more stable. The expression for the multidimensional feature deviation function is:

[0037] in, Let represent the stable operation feature vector corresponding to the i-th mobile cabin, and its value range is a non-negative real number vector; K represents the original running feature vector; K represents the number of feature dimensions. This represents the feature value of the i-th container in the k-th dimension, and its value is determined based on the corresponding operating parameters. The statistical mean of the k-th feature is obtained by statistically analyzing historical data or the current dataset. This represents the bias weighting coefficient, which ranges from 0 to 1 and is used to control the contribution of each dimension's feature bias to the overall suppression level. This represents the exponential adjustment parameter, which takes the value of a real number greater than or equal to 1. It is used to enhance the compression effect of large deviation values. The deviation is amplified by a power function and then the denominator is suppressed, thereby achieving nonlinear weakening of abnormal features.

[0038] After obtaining stable operating feature vectors, multi-source fusion processing is used to jointly model connection topology features, link quality features, and spatial matching features, thereby forming a unified splicing consistency index. Connection topology features describe the connection structure between modular units, link quality features describe the network communication status, and spatial matching features describe the geometric alignment degree after modular unit splicing. A fusion function is constructed to weight and integrate these features, making the contribution of different features in the overall evaluation adjustable. The expression for the splicing consistency index is:

[0039] in, represents the splicing consistency index of the i-th modular container, and its value range is a non-negative real number; M represents the number of fusion features; This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. This represents the topological characteristic value of the connection, and its value range is a non-negative real number; This represents the link quality characteristic value, and its value range is a non-negative real number; This represents the spatial matching feature value, and its value range is a non-negative real number; This represents the adjustment coefficient, which takes the value of a positive real number and is used to control the sensitivity of spatial matching features to the results. This represents the threshold parameter, which takes the value of a non-negative real number. It is used to limit the effective range of spatial matching features and achieves a smooth amplification of the degree of spatial matching through an exponential function.

[0040] After obtaining the splicing consistency index, it is converted into a standardized splicing confidence state through confidence mapping, enabling comparison of the splicing states of different modular units on a unified scale. A sigmoid function is used to achieve a non-linear mapping from the consistency index to the confidence level, suppressing low consistency states and reinforcing high consistency states. The expression for the confidence mapping function is:

[0041] in, This indicates the splicing confidence state, and its value ranges from 0 to 1; This indicates the consistency index of the splicing process; This represents the mapping slope coefficient, which takes the value of a positive real number and is used to control the steepness of the mapping function; This represents the offset parameter, which takes the value of a non-negative real number. It is used to adjust the center position of the function so that the system can adapt to the consistent distribution characteristics under different splicing scenarios.

[0042] After obtaining the splicing confidence state, it is dynamically stabilized through time-series smoothing to avoid frequent changes in the splicing state due to instantaneous data fluctuations. A time-weighted mechanism is introduced to fuse the current confidence state with historical confidence states, enabling the system to maintain both response speed and continuity. The expression for time-series smoothing is:

[0043] in, This indicates the current confidence state of the splicing process; This indicates the splicing confidence state at the previous moment; This indicates the currently calculated splicing confidence state; This represents the time weighting coefficient, which ranges from 0 to 1 and is used to control the degree of influence of historical states on the current state. A larger value indicates a greater reliance on historical states. Smaller values ​​indicate a greater dependence on the current state, and a smooth transition is achieved through linear weighting.

[0044] After obtaining the smooth splicing confidence state, it is bound to the shared space operation data set. By establishing a one-to-one correspondence between the cabin identifier and the splicing confidence state, the operation data of each cabin within a specific time window is associated with and stored with the corresponding splicing confidence state. A fast retrieval is achieved through an index structure, thereby forming the splicing confidence state. The splicing confidence state is used for the subsequent construction of the shared space security domain relationship graph and as a state reference in the access control process.

[0045] In one possible implementation, before establishing a seat security profile corresponding to each seat node based on the shared space security domain relationship graph and establishing a data flow security label corresponding to each data flow node, the method further includes: mapping the spliced ​​confidence state to a spliced ​​association matrix; performing security domain partitioning based on the spliced ​​association matrix to form an initial security domain partitioning structure; combining the initial security domain partitioning structure and the initial seat security profile, performing seat node mapping to form a target mapping relationship between seat nodes and security domains; performing data flow node binding based on the target mapping relationship and the data flow security label to form a target association relationship between data flow nodes and security domains; and constructing a multi-layer heterogeneous graph structure and performing relationship graph normalization based on the target mapping relationship and the target association relationship to generate a shared space security domain relationship graph.

[0046] Specifically, regarding the mapping process from splicing confidence states to the splicing correlation matrix, a matrix structure reflecting the splicing correlation strength between any two modules is constructed by pairwise calculation of the splicing confidence states of each module in the splicing confidence state. The splicing correlation matrix is ​​used to describe the overall connection reliability between modules. The splicing correlation strength depends not only on the splicing confidence state of a single module but also on the physical connectivity and logical isolation constraints between modules. By introducing a nonlinear mapping function, the connection of low-confidence states is suppressed, enabling the matrix to avoid overall correlation distortion caused by local abnormal splicing. The expression of the splicing correlation matrix is ​​as follows:

[0047] in, This represents the splicing connection strength between the i-th and j-th modular container units, and its value ranges from 0 to 1. and These represent the splicing confidence states of the corresponding modular shelters, with values ​​ranging from 0 to 1; This represents the physical connectivity between the modular units. Its value is a non-negative real number, calculated by considering the number of connection links, bandwidth, and stability. This represents the adjustment coefficient, which takes the value of a positive real number and is used to control the sensitivity of the influence of changes in connectivity on the association strength. The threshold parameter, whose value range is a non-negative real number, is used to limit the suppression effect in the low connectivity interval. The connectivity is smoothly mapped by the S-shaped function, so that the spliced ​​correlation matrix has stability and anti-interference ability.

[0048] After obtaining the spliced ​​correlation matrix, a security domain partitioning process is performed on the spliced ​​correlation matrix to form an initial security domain partitioning structure. Security domain partitioning divides the modular shelter nodes into multiple subsets, ensuring that shelters within the same subset have high spliced ​​correlation strength, while the correlation strength between different subsets is lower, thus forming a logically isolated security domain structure. This process is achieved by constructing a security domain partitioning objective function, the expression of which is:

[0049] in, This represents the k-th security domain, whose value is a set of nodes; This indicates concatenating elements from the correlation matrix; This represents the cross-domain penalty coefficient, which is a positive real number. It is used to suppress highly correlated nodes from being assigned to different security domains. By maximizing the correlation strength within a domain and minimizing the correlation strength between domains, the security domain partitioning result can simultaneously meet the requirements of connectivity tightness and isolation.

[0050] After obtaining the initial security domain partitioning structure, seat node mapping is performed by combining the initial seat security profile. Each seat node is mapped to the corresponding security domain based on its affiliated shelter and its security attributes. The initial seat security profile describes the basic security attributes of the seat, including terminal trust level, business role, and access permission level. A mapping weight function is constructed to calculate the matching degree between the seat and the security domain, ensuring that the seat node is affected not only by its shelter affiliation but also by its security attributes during the mapping process. The expression of the mapping weight function is as follows:

[0051] in, This represents the mapping weight of the i-th seat node, and its value range is a non-negative real number; This indicates the splicing confidence status of the modular cabin where the seat is located; This represents the sensitivity level parameter in the seat security profile, and its value range is a non-negative real number. and This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. This represents the adjustment coefficient, which takes the value of a positive real number. It is used to control the inhibitory effect of the sensitivity level on the mapping weight. Through the exponential decay mechanism, it restricts the cross-domain mapping of highly sensitive seats, thereby forming the target mapping relationship between seat nodes and security domains.

[0052] After establishing the target mapping relationship between seat nodes and security domains, data flow node binding is performed by combining data flow security tags. Each data flow node is mapped to the corresponding security domain based on its source container, business domain identifier, and propagation constraints. The data flow security tag describes the security attributes of the data flow, including sensitivity level, access scope, and propagation path restrictions. A data flow association function is constructed to calculate the matching degree between data flow nodes and security domains, ensuring that the data flow node reflects its security attribute constraints during the binding process. The expression of the data flow association function is as follows:

[0053] in, The value of L represents the association strength of the m-th data stream node, and its value is a non-negative real number; L represents the number of label dimensions. This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. This represents the feature value of the data stream in the l-th dimension, and its range is determined according to the label definition. This represents the historical propagation frequency of the data stream along this dimension, and its value is a non-negative integer. This represents the adjustment coefficient, which is a positive real number. It is used to control the influence of propagation frequency on the association strength. The logarithmic function suppresses the influence expansion caused by high-frequency propagation, thereby forming the target association relationship between data flow nodes and security domains.

[0054] After obtaining the target mapping relationship between seat nodes and security domains, as well as the target association relationship between data flow nodes and security domains, a multi-layered heterogeneous graph structure is constructed to integrate the cabin nodes, seat nodes, and data flow nodes into the same graph model. Different types of nodes are connected by different types of edges, including splicing association edges, seat mapping edges, and data flow association edges, thus forming a multi-layered relationship network. Based on this, relationship graph normalization is performed. By uniformly normalizing the scale of various nodes and edge weights, and dynamically adjusting the cross-domain edge weights in combination with the splicing confidence state, the relationship graph maintains consistency and stability under different splicing states, thereby generating a shared space security domain relationship graph for subsequent permission verification and data sharing control.

[0055] In one possible implementation, a seat security profile corresponding to each seat node is established based on the shared space security domain relationship graph, and a data flow security label corresponding to each data flow node is established. Specifically, this includes: performing feature extraction on the seat nodes in the shared space security domain relationship graph and embedding them with domain constraints to generate seat feature vectors; performing multi-dimensional weight fusion based on the seat feature vectors to generate seat security vectors; combining the seat security vectors with the shared space security domain relationship graph and performing neighborhood propagation correction to generate corrected security vectors; performing feature extraction on the data flow nodes in the shared space security domain relationship graph and embedding them with path constraints to generate data flow feature vectors; performing label calculation based on the data flow feature vectors to generate data flow security label vectors; and performing node binding on the corrected security vectors and data flow security label vectors, and performing consistency verification based on the shared space security domain relationship graph to form seat security profiles and data flow security labels.

[0056] Specifically, the process of feature extraction and domain constraint embedding is performed around the seat nodes in the shared space security domain relationship graph. This is achieved by reading the cabin identifier, terminal identifier, business role identifier, and historical access behavior parameters associated with the seat nodes from the shared space security domain relationship graph, and uniformly encoding the above multi-source attributes to map discrete attributes into vector form and compress continuous attributes to a uniform range through a normalization function, thereby forming a seat feature vector. On this basis, a domain constraint embedding mechanism is introduced to superimpose the information of the security domain to which the seat node belongs into the seat feature vector in the form of an embedded vector. This ensures that the seat feature vector contains not only individual attributes but also security domain affiliation characteristics, thereby ensuring that the subsequent security assessment process can reflect spatial isolation constraints.

[0057] After obtaining the seat feature vector, a seat security vector is generated through multi-dimensional weighted fusion processing. A non-linear fusion function is constructed to weight and integrate features from different dimensions, dynamically adjusting the contribution of different features in the security assessment. The expression for the seat security vector is:

[0058] in, Let K represent the seat security vector of the i-th seat node, and its value range is a non-negative real number vector; K represents the number of feature dimensions. This represents the weight coefficient of the k-th dimension, which ranges from 0 to 1 and sums to 1. This represents the eigenvalue of the seat in the k-th dimension, and its range of values ​​is determined according to the eigenvalue definition. This represents the safety baseline value for this feature, and its value range is a non-negative real number. This represents the threshold parameter, which takes the value of a non-negative real number and is used to divide the safe interval. This represents the adjustment coefficient, which is a positive real number. It is used to control the sensitivity of a feature to the result. The S-shaped function is used to smoothly adjust the contribution of a feature, thereby avoiding an excessive influence of a single feature on the overall result.

[0059] After obtaining the seat security vector, a neighborhood propagation correction process is performed by combining it with the shared space security domain relationship graph. This incorporates the adjacency relationships of seat nodes in the graph structure into the calculation, allowing the security state to be propagated in a weighted manner within the local neighborhood. This corrects the security assessment bias of isolated nodes or boundary nodes. The expression for the neighborhood propagation correction is as follows:

[0060] in, This represents the modified seat security vector; Indicates the relationship with seat nodes The set of adjacent nodes; This represents the propagation weight between nodes, and its value ranges from 0 to 1; Represents the seat security vector of adjacent nodes; This represents the path distance between nodes in the shared space security domain relationship graph, and its value range is a non-negative real number; This represents the attenuation coefficient, which is a positive real number. It is used to control the degree of attenuation of propagation influence with distance. By using an exponential attenuation mechanism, the influence of distant nodes is limited, thereby ensuring local consistency.

[0061] After completing the seat node processing, feature extraction and path constraint embedding are performed on the data flow nodes in the shared space security domain relationship graph. By encoding the source cabin identifier, business domain identifier, data type identifier, and propagation path information associated with the data flow nodes, the node sequence and cross-domain number in the propagation path are converted into path features. The path constraint information is then fused into the data flow feature vector through the embedding function, so that the data flow feature vector can reflect its propagation behavior and cross-domain characteristics, thereby forming a data flow feature vector with path constraint capability.

[0062] After obtaining the data stream feature vector, a data stream security label vector is generated through label calculation. A label calculation function is constructed to comprehensively model the data stream's sensitivity level, propagation frequency, and access scope, enabling the labels to reflect the data stream's security attributes. The expression for the data stream security label vector is:

[0063] in, represents the data stream security label vector of the m-th data stream node, and its value range is a non-negative real number vector; L represents the number of label dimensions; This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. This represents the feature value of the data stream in the l-th dimension, and its range is determined based on the data attributes. This represents the historical propagation frequency of the data stream along this dimension, and its value is a non-negative integer. This represents the adjustment coefficient, which takes the value of a positive real number. It is used to control the impact of propagation frequency on tag strength. By using a logarithmic function to compress the impact of high-frequency propagation, the tag results are made more stable.

[0064] After obtaining the corrected security vector and the data flow security label vector, node binding is performed to associate them with the corresponding seat nodes and data flow nodes respectively. Consistency verification is then performed in conjunction with the shared space security domain relationship graph. By verifying the security domain relationship between the seat nodes and the data flow nodes, it is determined whether they meet the same domain or controlled cross-domain conditions. Node binding relationships that do not meet the conditions are constrained and corrected, thereby forming a seat security profile and data flow security label with consistent structure and satisfying security domain constraints, which are used in subsequent access control and data sharing decision-making processes.

[0065] In one possible implementation, the data subscription request initiated by any seat node is parsed, and the corresponding permission verification object is searched in the shared space security domain relationship graph. Specifically, this includes: performing structured parsing on the data subscription request and aligning the nodes to generate a subscription request feature vector; performing multi-dimensional constraint mapping based on the subscription request feature vector to generate a constraint feature vector; performing graph path location processing in the shared space security domain relationship graph using the constraint feature vector to generate a candidate path set; performing optimal path filtering processing based on the candidate path set to generate a target path; and extracting a set of key nodes based on the target path and performing binding processing to generate a permission verification object.

[0066] Specifically, regarding the structured parsing and node alignment process of data subscription requests, semantic decomposition of seat identifiers, target data stream identifiers, business domain identifiers, and access type identifiers in the data subscription request is performed. These are then uniformly encoded according to predefined field specifications. Discrete attributes are mapped to vectors through embedding encoding, and continuous attributes are mapped to a unified numerical range through a normalization function, thereby generating a subscription request feature vector. Based on this, node alignment processing is performed, matching the seat identifiers in the subscription request feature vector with seat nodes in the shared space security domain relationship graph, and matching the target data stream identifier with data stream nodes. This ensures a one-to-one correspondence between each dimension of the subscription request feature vector and the nodes in the relationship graph. Node alignment is used to ensure that subsequent path search and permission verification processes are performed within a unified graph structure.

[0067] After obtaining the subscription request feature vector, multi-dimensional constraint mapping is used to map the business domain constraints, access level constraints, and time context constraints in the subscription request to a unified constraint space. A request constraint function is constructed to non-linearly integrate the constraint features of each dimension, enabling the constraint information to be expressed at the same scale, thereby generating a constraint feature vector. This constraint feature vector describes the restrictions of the subscription request under different security dimensions, and its expression is as follows:

[0068] in, Let K represent the constraint feature vector of the i-th subscription request, whose value range is a non-negative real number vector; K represents the number of constraint dimensions. This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. This represents the original feature value of the i-th subscription request in the k-th dimension, and its range is determined according to the constraint type. This represents a context parameter, whose value is a non-negative real number, used to describe the current environment or state information; This represents the threshold parameter, which takes the value of a non-negative real number and is used to divide the constraint effective interval. This represents the adjustment coefficient, which takes the value of a positive real number. The constraint strength is smoothly adjusted through the S-shaped function, so that the constraint mapping result has continuity.

[0069] After obtaining the constraint feature vectors, path search is performed in the shared space security domain relation graph through graph path localization processing. The seat node is taken as the starting point, and the target data flow node as the ending point. The edge weights in the path are dynamically adjusted based on the constraint feature vectors to ensure the path search process reflects the constraints. Path weights are generated by accumulating the edge weights in the path, thereby selecting a set of candidate paths that meet the constraints. The expression for the path weights is:

[0070] in, The path weight is represented by a non-negative real number; P represents the set of node pairs contained in the path. This represents the original edge weight between nodes, and its value ranges from non-negative real numbers. This represents the path distance between nodes, and its value is a non-negative real number. This represents the distance attenuation coefficient, which takes the value of a positive real number and is used to control the impact of path length on weight. This represents the combined effect value of the constraint feature vectors. By accumulating the path weights, paths that meet the constraints and have lower path costs are included in the candidate path set.

[0071] After obtaining the candidate path set, each candidate path is comprehensively evaluated through optimal path screening. A path selection function is constructed to jointly model path weights, path lengths, and the number of security domain crossings, thereby determining the optimal path. The expression for the path selection function is:

[0072] in, Indicates the optimal path; Indicates path weight; This represents the path length, and its value is a positive integer. This represents the number of times a security domain is crossed in the path, and its value is a non-negative integer. and This represents the penalty coefficient, which is a positive real number. It is used to suppress paths that are too long or cross too many domains, thereby ensuring that the optimal path has low risk while satisfying the constraints.

[0073] After obtaining the optimal path, permission verification objects are generated through key node extraction and binding. By identifying key nodes in the optimal path, seat nodes, security domain nodes, and data flow nodes in the path are extracted into a set of key nodes, and binding processing is performed on the set to form a permission verification object that corresponds one-to-one with the subscription request. The permission verification object is used to describe the complete access path of the subscription request in the shared space security domain relationship graph and the key security entities involved, thereby providing an accurate object basis for subsequent permission verification.

[0074] In one possible implementation, a shared license token is generated based on the seat security profile and the data flow security label. Specifically, this includes: performing feature alignment processing on the seat security profile and the data flow security label to generate an aligned feature vector; performing matching degree calculation processing based on the aligned feature vector to generate a matching degree parameter; combining the matching degree parameter, cross-domain relationship strength, and historical access behavior parameters to perform risk adjustment processing to generate a risk adjustment parameter; performing fusion calculation processing based on the matching degree parameter and the risk adjustment parameter to generate a shared license strength parameter; and performing encoding processing based on the shared license strength parameter, combined with the seat security profile identifier, the data flow security label identifier, and the time validity parameter, and performing consistency verification to generate a shared license token.

[0075] Specifically, regarding the feature alignment processing of seat security profiles and data flow security labels, a unified mapping is performed on the features of seat security profile vectors and data flow security label vectors in the security domain dimension, sensitivity level dimension, and business semantic dimension. This enables the two types of vectors to form comparable expressions within the same feature space. Feature alignment is achieved by constructing a dimension mapping function to convert the originally semantically different feature dimensions into corresponding dimensions in a unified semantic space. Furthermore, the cross-domain dimensions are weighted and corrected by combining the security domain boundary constraints in the shared space security domain relationship graph. This ensures that the aligned feature vectors retain the original attribute information while also possessing security domain constraint capabilities, thereby generating aligned feature vectors.

[0076] After obtaining the aligned feature vectors, the similarity and differences between the seat security profile and the data flow security label are jointly modeled through matching degree calculation. A security matching function is constructed to weight and accumulate the similarity of each feature dimension, and a difference penalty mechanism is used to reduce the impact of mismatched features, thereby generating a matching degree parameter. The matching degree parameter is used to measure the degree of seat security adaptation to the data flow, and its expression is:

[0077] Where M represents the matching degree parameter, which ranges from 0 to 1; K represents the number of feature dimensions; This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. This represents the feature value of the seat security profile in the k-th dimension, and its range is determined according to the feature definition. This represents the feature value of the data flow security label in the k-th dimension, and its value range is determined according to the label definition. and This represents the normalization coefficient, used to eliminate scale differences between different dimensions; This represents the difference penalty coefficient, which takes the range of positive real numbers. It reduces the matching contribution when the feature differences are large through an exponential decay function.

[0078] After obtaining the matching degree parameters, risk adjustment processing is performed by combining the matching degree parameters, cross-domain relationship strength, and historical access behavior parameters. The cross-domain relationship strength describes whether a cross-security domain access path exists between the seat node and the data flow node. The historical access behavior parameters describe the frequency of abnormal behavior of the seat during historical access. A risk assessment function is constructed to fuse these parameters, enabling the system to comprehensively consider the current matching status and historical risk factors, thereby generating risk adjustment parameters, the expression of which is:

[0079] Where R represents the risk adjustment parameter, which takes the value of a non-negative real number; M represents the matching degree parameter; and D represents the cross-domain relationship strength, which takes the value of 0 to 1. This represents the number of historical access anomalies, and its value is a non-negative integer. This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. By weighting and integrating the reverse matching term, cross-domain factors, and historical behavior, a dynamic assessment of the risk level can be achieved.

[0080] After obtaining the risk adjustment parameters, the matching degree parameters and risk adjustment parameters are jointly modeled through fusion calculation. By constructing a shared license generation function, a balance is achieved between the degree of security adaptation and the degree of risk. This ensures that requests with high matching degree and low risk receive higher license strength, while requests with low matching degree or high risk are suppressed, thereby generating the shared license strength parameter, the expression of which is:

[0081] Where L represents the shared permit strength parameter, which ranges from 0 to 1; M represents the matching degree parameter; and R represents the risk adjustment parameter. The risk parameter is used as a suppression term in the calculation through a fractional structure, thereby achieving dynamic adjustment of the permit strength.

[0082] After obtaining the shared license strength parameter, a shared license token is generated through encoding and consistency verification. The shared license strength parameter is combined with the seat security profile identifier, data flow security label identifier, and time validity parameter to construct structured token data. The verification mechanism verifies whether each field in the token meets the security constraints in the shared space security domain relationship graph, including security domain consistency verification and cross-domain access legality verification, thereby generating a shared license token. The shared license token is used as the basis for access control in the subsequent data flow sharing process to achieve fine-grained control over data access behavior.

[0083] In one possible implementation, hierarchical sharing processing is performed on the target data stream based on the shared permission token, specifically including: performing token parsing processing and node alignment processing on the shared permission token to generate a permission feature vector; performing hierarchical determination processing based on the permission feature vector to generate sharing level parameters; performing policy mapping processing based on the sharing level parameters to generate sharing policy parameters; performing hierarchical processing control on the target data stream based on the sharing policy parameters; and performing dynamic adjustment processing based on the sharing policy parameters and in conjunction with the shared space security domain relationship graph.

[0084] Specifically, regarding the token parsing and node alignment processing of the shared license token, the structured fields are converted into numerical expressions by decoding the shared license strength parameter, seat security profile identifier, data flow security label identifier, and time validity parameter in the shared license token, thereby generating a license feature vector. The token parsing process is used to restore the original semantic information of each field in the token, and the node alignment process is used to match the seat security profile identifier with the seat node in the shared space security domain relationship graph and the data flow security label identifier with the data flow node, so that each dimension of the license feature vector establishes a one-to-one correspondence with the node in the graph structure, thereby ensuring that the subsequent processing can be carried out under a unified graph structure.

[0085] After obtaining the permission feature vector, a hierarchical decision-making process is used to jointly model the shared permission strength parameter and the sensitivity level parameter in the data flow security label. A hierarchical decision-making function is constructed to achieve a non-linear fusion of permission strength and data sensitivity, thereby generating a shared level parameter. This shared level parameter characterizes the shareability of the target data flow under the current access conditions, and its expression is:

[0086] Where G represents the sharing level parameter, with a value ranging from 0 to 1; L represents the sharing license strength parameter, with a value ranging from 0 to 1; and S represents the sensitivity level parameter in the data flow security label, with a value ranging from a non-negative real number. and This represents the weighting coefficient, which ranges from 0 to 1 and sums to 1. This represents the sensitivity adjustment coefficient, which takes the value of a positive real number and is used to control the inhibitory effect of the sensitivity level on the sharing level. This represents the mapping slope coefficient, which takes the value of a positive real number. The threshold parameter ranges from 0 to 1. It uses a sigmoid function to achieve a segmented response to the shared permit strength, making the grading results smoother.

[0087] After obtaining the sharing level parameters, the parameters are converted into specific data sharing policies through policy mapping. By constructing a hierarchical policy function, the sharing level is divided into multiple intervals, each corresponding to different data processing rules, including data pruning intensity, anonymization degree, and transmission restrictions, thereby generating the sharing policy parameters, the expression of which is:

[0088] Where P represents the shared policy parameter, and its value range is a non-negative real number; K represents the number of policy levels; This represents the weight coefficient of the k-th level strategy, and its value ranges from 0 to 1; This indicates the indicator function, which states that when the shared level parameter G falls within the k-th level interval... The value is 1 if the condition is met, and 0 otherwise. This represents the adjustment coefficient, which takes the value of a positive real number and is used to control the sensitivity of the strategy response. This represents a threshold parameter, with a value ranging from 0 to 1. It is used to divide different policy intervals and to achieve the mapping from shared levels to policies through a segmentation function.

[0089] After obtaining the sharing strategy parameters, hierarchical processing control is performed on the target data stream. The data stream is processed in multiple dimensions according to the sharing strategy parameters, including cropping the data content to limit the information granularity, desensitizing sensitive fields to reduce the risk of data leakage, limiting the transmission rate to control the data propagation range, and adjusting the resolution or frame rate of video data. This enables the target data stream to be shared in a controllable manner while meeting security constraints. The hierarchical processing control is driven by the strategy parameters, giving the data processing process dynamic adaptability.

[0090] After completing the hierarchical processing of data streams, the sharing strategy parameters are dynamically adjusted in real time. By combining the node load status, link status, and cross-domain path changes in the shared space security domain relationship diagram, the sharing strategy parameters are adaptively updated, enabling the hierarchical sharing of data streams to be dynamically adjusted according to changes in the system's operating status, thereby ensuring the stability and security of the data sharing process in complex splicing environments.

[0091] In one possible implementation, after performing hierarchical sharing processing on the target data stream based on the shared license token, the method further includes: performing unified collection and encoding processing on seat switching, terminal insertion / removal, inter-cabin connection changes, service session changes, user login changes, and display resource usage changes during the data sharing operation to generate a running event stream; performing event mapping processing based on the running event stream to update the shared space security domain relationship graph; performing state detection processing based on the updated shared space security domain relationship graph to identify key state changes; performing controlled shared connection edge revocation processing based on the key state changes; performing shared license token clearing processing based on the controlled shared connection edge revocation processing; and performing data stream state recovery processing based on the controlled shared connection edge revocation processing and the shared license token clearing processing.

[0092] Specifically, focusing on the generation of operational event streams during the data sharing process, continuous monitoring is conducted on seat switching, terminal plugging / unplugging, inter-cabin connection changes, business session changes, user login changes, and display resource usage changes. All these changes are uniformly abstracted into operational events, and these events are uniformly encoded. Seat switching represents a user's migration status change between different seat nodes; terminal plugging / unplugging represents the access or removal of terminal devices; inter-cabin connection changes represent changes in the physical or network connection status between cabins; business session changes represent changes in task context or business processes; user login changes represent changes in authentication status; and display resource usage changes represent the usage status of public display resources. By aligning the timestamps and standardizing the fields of these events, an operational event stream is generated, enabling events from different sources to be expressed under a unified structure.

[0093] After obtaining the running event stream, the running event stream is synchronously mapped to the shared space security domain relationship graph through event mapping processing. By constructing an event mapping function, the node identifiers in the running event stream are matched with the cabin nodes, seat nodes, terminal nodes, and data stream nodes in the relationship graph, and the node attributes or connection edge states are updated according to the event type, thereby realizing the dynamic adjustment of the relationship graph. The expression of the event mapping function is as follows:

[0094] in, A diagram showing the shared space security domain relationships at the current moment; This represents the relationship diagram from the previous time step; E represents the number of running events; The weight coefficient for the e-th event ranges from 0 to 1 and is used to characterize the degree of influence of different events on the update of the relationship graph. This represents an event mapping function whose output is the adjustment amount for node attributes or edge weights. By weighting and superimposing multiple events, the relationship graph can be updated in real time.

[0095] After updating the relationship graph, key state changes are identified through state detection. By jointly analyzing changes in node attributes and edge connection states in the relationship graph, it detects situations such as modular cabin splitting, inter-cabin link disconnection, terminal removal from current seat, user account cancellation, task number switching, or shared license token expiration. A state judgment function is constructed to quantify these changes; its expression is:

[0096] Where S represents the state change determination value, and its value range is a non-negative real number; This represents the state change of the i-th type of node, and its value range is a non-negative real number; This represents the change in the connection state of the j-th type of edge, and its value range is a non-negative real number; and This represents the weighting coefficient, which ranges from 0 to 1. It is used to adjust the impact of different types of changes on the judgment result. By weighting and fusing node changes and edge changes, the identification of key state changes is achieved.

[0097] After detecting a critical state change, the shared space security domain relationship graph is adjusted through controlled shared connection edge revocation. Controlled shared connection edges related to the critical state change are deleted or their weights are reset to zero. Controlled shared connection edges represent cross-domain data transmission paths established under the constraints of shared permission tokens. By revoking such connection edges, the cross-domain data transmission path is cut off, thereby blocking the flow of data that no longer meets the security conditions.

[0098] After the controlled shared connection edge is revoked, the relevant tokens are invalidated through the shared permission token clearing process. By deleting or marking the invalidated shared permission tokens, they are no longer involved in subsequent access control decisions, thereby ensuring that the access control is consistent with the current system state.

[0099] After the token is cleared, the corresponding data flow is restored from the cross-domain shared state to the intra-domain isolated state through data flow state recovery processing. By reconstructing the transmission path of the data flow in the security domain relationship graph of the shared space, it is made to propagate only within its own security domain, and the original access control policy is restored. This enables the secure rollback of the data flow when the system state changes, ensuring the security and consistency of the overall data sharing process.

[0100] This embodiment also discloses a data processing device based on a modular shared space command cabin, referring to... Figure 4 The device includes an acquisition module 401, a processing module 402, and an output module 403. It is used to execute any of the data processing methods described above for a modular shared space command module, wherein: The acquisition module 401 is used to acquire a set of shared space operation data bound to the splicing relationship of multiple spliced ​​shared space command cabins. Processing module 402 is used to perform preprocessing on the shared space running data set to generate spliced ​​confidence states; The processing module 402 is used to establish a seat security profile corresponding to each seat node based on the shared space security domain relationship diagram, and to establish a data flow security label corresponding to each data flow node. The shared space security domain relationship diagram is constructed based on spliced ​​confidence states. Processing module 402 is used to parse the data subscription request initiated by any seat node and search for the permission verification object corresponding to the parsing result in the shared space security domain relationship graph; Processing module 402 is used to verify the data subscription request when the data subscription request involves cross-cabin, cross-business domain or cross-cabin public display area, and generate a shared permission token based on seat security profile and data flow security label when the verification is passed; Output module 403 is used to perform hierarchical sharing processing on the target data stream based on the shared permission token.

[0101] It should be noted that the above embodiments of the apparatus are only illustrated by the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process can be found in the method embodiments, which will not be repeated here.

[0102] This embodiment also discloses an electronic device, as shown in the reference. Figure 5 The electronic device may include: at least one processor 501, at least one communication bus 502, user interface 503, network interface 504, and at least one memory 505.

[0103] The communication bus 502 is used to enable communication between these components.

[0104] The user interface 503 may include a display screen and a camera. Optionally, the user interface 503 may also include a standard wired interface and a wireless interface.

[0105] The network interface 504 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).

[0106] The processor 501 may include one or more processing cores. The processor 501 connects to various parts of the server using various interfaces and lines, and performs various server functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 505, and by calling data stored in memory 505. Optionally, the processor 501 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The processor 501 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content to be displayed on the screen; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the processor 501 and may be implemented as a separate chip.

[0107] The memory 505 may include random access memory (RAM) or read-only memory. Optionally, the memory may include a non-transitory computer-readable storage medium. The memory 505 may be used to store instructions, programs, code, code sets, or instruction sets. The memory 505 may include a program storage area and a data storage area. The program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch functionality, sound playback functionality, image playback functionality, etc.), instructions for implementing the various method embodiments described above, etc.; the data storage area may store data involved in the various method embodiments described above, etc. Optionally, the memory 505 may also be at least one storage device located remotely from the aforementioned processor 501. As a computer storage medium, the memory 505 may include an operating system, a network communication module, a user interface 503 module, and an application program for a data processing method based on a modular shared space command cabin.

[0108] exist Figure 5In the electronic device shown, the user interface 503 is mainly used to provide an input interface for the user and to obtain the user input data; while the processor 501 can be used to call an application program stored in the memory 505 that is a data processing method based on a spliced ​​shared space command cabin. When executed by one or more processors 501, the electronic device performs one or more methods as described in the above embodiments.

[0109] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, as some steps can be performed in other orders or simultaneously according to the present invention. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0110] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.

[0111] In the several embodiments provided by this invention, it should be understood that the disclosed apparatus can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some service interface; the indirect coupling or communication connection between apparatuses or units may be electrical or other forms.

[0112] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0113] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0114] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory 505 and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned memory 505 includes various media capable of storing program code, such as a USB flash drive, external hard drive, magnetic disk, or optical disk.

[0115] The present invention also discloses a non-transitory computer-readable storage medium storing instructions. When executed by one or more processors 501, these instructions cause an electronic device to perform one or more methods as described in the above embodiments.

[0116] The above are merely exemplary embodiments of this disclosure and should not be construed as limiting the scope of this disclosure. Any equivalent changes and modifications made in accordance with the teachings of this disclosure shall still fall within the scope of this disclosure. Those skilled in the art will readily conceive of other embodiments of this disclosure upon considering the specification and the disclosure of practical truths. This invention is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not described in this disclosure. The specification and embodiments are to be considered exemplary only, and the scope and spirit of this disclosure are defined by the claims.

Claims

1. A data processing method based on a modular shared space command cabin, characterized in that, The method includes: For multiple modular shared command cabins, obtain a set of shared space operation data bound to the modular cabin splicing relationship; Preprocessing is performed on the shared space operation data set to generate spliced ​​confidence states; Based on the shared space security domain relationship diagram, a seat security profile corresponding to each seat node is established, and a data flow security label corresponding to each data flow node is established. The shared space security domain relationship diagram is constructed based on the spliced ​​confidence state. The system parses any data subscription request initiated by any seat node and searches for the permission verification object corresponding to the parsing result in the shared space security domain relationship graph. When the data subscription request involves cross-cabin, cross-business domain or cross-cabin public display area, the data subscription request is verified. If the verification is successful, a shared permission token is generated based on the seat security profile and the data flow security tag. Based on the shared permission token, hierarchical sharing processing is performed on the target data stream.

2. The data processing method based on a modular shared space command cabin according to claim 1, characterized in that, The preprocessing of the shared space operational data set to generate a spliced ​​confidence state specifically includes: Perform unified structured processing on the shared space runtime data set to generate runtime feature vectors; Anomaly suppression processing is performed based on the aforementioned operational feature vector to generate a stable operational feature vector; Multi-source fusion processing is performed based on the stable operating feature vector to generate a splicing consistency index; Confidence mapping is performed based on the splicing consistency index to generate splicing confidence states; Based on the splicing confidence state, perform time-series smoothing processing to generate a smooth splicing confidence state; The smooth splicing confidence state is bound to the shared space operation data set to generate a splicing confidence state.

3. The data processing method based on a modular shared space command cabin according to claim 1, characterized in that, Before establishing a seat security profile corresponding to each seat node based on the shared space security domain relationship diagram, and establishing a data flow security label corresponding to each data flow node, the method further includes: Map the spliced ​​confidence states to a spliced ​​correlation matrix; Based on the spliced ​​correlation matrix, security domain partitioning is performed to form an initial security domain partitioning structure; Combining the initial security domain partitioning structure and the initial seat security profile, seat node mapping is performed to form a target mapping relationship between seat nodes and security domains; For the target mapping relationship, data flow node binding is performed in conjunction with the data flow security label to form a target association relationship between the data flow node and the security domain; Based on the target mapping relationship and the target association relationship, a multi-layer heterogeneous graph structure is constructed and the relationship graph normalization is performed to generate a shared space security domain relationship graph.

4. The data processing method based on a modular shared space command cabin according to claim 1, characterized in that, The step of establishing a seat security profile corresponding to each seat node based on the shared space security domain relationship diagram, and establishing a data flow security label corresponding to each data flow node, specifically includes: Feature extraction is performed on the seat nodes in the shared space security domain relationship graph, and domain constraint embedding is performed to generate seat feature vectors; Multi-dimensional weight fusion is performed based on the seat feature vector to generate a seat security vector; By combining the seat security vector with the shared space security domain relationship graph, a neighborhood propagation correction is performed to generate a corrected security vector; Feature extraction is performed on the data flow nodes in the shared space security domain relationship graph, and path constraint embedding is performed to generate data flow feature vectors; Based on the data stream feature vector, perform label calculation to generate a data stream security label vector; The modified security vector and the data flow security label vector are bound to an execution node, and a consistency check is performed in conjunction with the shared space security domain relationship graph to form the seat security profile and the data flow security label.

5. The data processing method based on a modular shared space command module according to claim 1, characterized in that, The step of parsing the data subscription request received from any seat node and searching for the corresponding permission verification object in the shared space security domain relationship graph specifically includes: The data subscription request is subjected to structured parsing and node alignment to generate a subscription request feature vector; Perform multidimensional constraint mapping based on the subscription request feature vector to generate constraint feature vector; The constraint feature vectors are used to perform graph path localization processing in the shared space security domain relation graph to generate a candidate path set. Optimal path filtering is performed based on the candidate path set to generate the target path; Based on the target path, extract the set of key nodes and perform binding processing to generate the permission verification object.

6. The data processing method based on a modular shared space command module according to claim 1, characterized in that, The process of generating a shared permission token based on the seat security profile and the data stream security label specifically includes: Perform feature alignment processing on the seat security profile and the data stream security label to generate an aligned feature vector; Perform matching degree calculation processing based on the alignment feature vector to generate matching degree parameters; By combining the matching degree parameter, cross-domain relationship strength, and historical access behavior parameter, risk adjustment processing is performed to generate risk adjustment parameters; A fusion calculation process is performed based on the matching degree parameter and the risk adjustment parameter to generate a shared license strength parameter; Encoding is performed based on the shared license strength parameter, combined with the seat security profile identifier, the data stream security label identifier, and the time validity parameter, and consistency verification is performed to generate the shared license token.

7. The data processing method based on a modular shared space command module according to claim 1, characterized in that, The hierarchical sharing process performed on the target data stream based on the shared permission token specifically includes: The shared license token is parsed and node alignment is performed to generate a license feature vector; Based on the permission feature vector, perform hierarchical determination processing to generate shared level parameters; Based on the shared level parameters, perform policy mapping processing to generate shared policy parameters; Based on the shared strategy parameters, hierarchical processing control is performed on the target data stream; Dynamic adjustment processing is performed based on the shared policy parameters and the shared space security domain relationship graph.

8. A data processing device based on a modular shared space command cabin, characterized in that, The device is used to execute a data processing method based on a modular shared space command module as described in any one of claims 1-7. The device includes an acquisition module, a processing module, and an output module, wherein: The acquisition module is used to acquire a set of shared space operation data bound to the splicing relationship of multiple spliced ​​shared space command cabins. The processing module is used to perform preprocessing on the shared space operation data set to generate spliced ​​confidence states; The processing module is used to establish a seat security profile corresponding to each seat node based on the shared space security domain relationship graph, and to establish a data flow security label corresponding to each data flow node, wherein the shared space security domain relationship graph is constructed based on the splicing confidence state; The processing module is used to parse the data subscription request initiated by any seat node and search for the permission verification object corresponding to the parsing result in the shared space security domain relationship graph. The processing module is used to verify the data subscription request when the data subscription request involves cross-cabin, cross-business domain or cross-cabin public display area, and generate a shared permission token based on the seat security profile and the data flow security tag when the verification is successful. The output module is used to perform hierarchical sharing processing on the target data stream based on the shared permission token.

9. An electronic device, characterized in that, The device includes a processor, a communication bus, a user interface, a network interface, and a memory. The memory is used to store instructions. The user interface and the network interface are both used to communicate with other devices. The communication bus is used to enable communication between the components within the electronic device. The processor is used to execute the instructions stored in the memory to cause the electronic device to perform the method as described in any one of claims 1-7.

10. A non-transitory computer-readable storage medium, characterized in that, The computer-readable storage medium stores instructions that, when executed, perform the method as described in any one of claims 1-7.