A cloud computing-based big data information security protection and storage method and system

CN122528207APending Publication Date: 2026-08-07YIDU TECH (GUANGZHOU) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
YIDU TECH (GUANGZHOU) CO LTD
Filing Date
2026-05-15
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0004]本发明的目的是为了解决现有技术中存在的边缘节点原始时间戳易受授时跳变影响而发生顺序失真,进而导致云端数据安全封装、审计存证及分级存储可信性不足的缺点,而提出的一种基于云计算的大数据信息安全防护与存储方法及系统

Benefits of technology

[0055] This invention constructs an original event sequence by extracting the original timestamp, local monotonic count value, time base state, main influencing sector identifier, and current environmental phase quantity at the edge node side. It further establishes a causal edge set by combining the necessary sequential relationship between events, generates an initial reliable time using the particle swarm optimization algorithm, and reconstructs the final reliable logical time by applying monotonically increasing constraints, while simultaneously calculating the corresponding time reliability. By transforming the original time information affected by time synchronization jumps into a correctable, constrainable, and quantifiable reliable time result, this invention effectively weakens the interference caused by complex environmental disturbances on time sequence judgment, reduces cross-node event sequence distortion, audit relationship confusion, and unstable evidence storage time basis, and improves the accuracy, continuity, and interpretability of the event time reconstruction results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122528207A_ABST
    Figure CN122528207A_ABST
Patent Text Reader

Abstract

The application discloses a big data information security protection and storage method and system based on cloud computing, relates to the technical field of big data information security processing, and comprises the following steps: extracting original time stamps, local monotonic count values, time base states, main influence sector identifiers and current environment phase quantities of to-be-processed events generated by edge nodes to construct original event sequences; establishing a causal edge set according to the occurrence sequence between the to-be-processed events and generating an initial trusted time; applying a monotonic increasing constraint to the initial trusted time, reconstructing a final trusted logical time, and calculating corresponding time credibility; embedding the final trusted logical time and the time credibility into a hash link and a key derivation link, safely packaging data load, and generating a unified security object; and determining the storage level of the unified security object according to the time credibility and writing the unified security object into a corresponding hierarchical security storage area on the cloud platform side. The application can improve the sequential credibility, integrity and audit traceability of cloud data storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of big data information security processing technology, and in particular to a method and system for big data information security protection and storage based on cloud computing. Background Technology

[0002] In data processing scenarios where edge nodes and cloud platforms collaborate, edge nodes continuously collect device operation data, maintenance logs, access audit data, alarm records, and evidence objects, and upload this data to the cloud platform for centralized storage, security auditing, and compliance retention. In such scenarios, the timing link is susceptible to external environmental changes, signal anomalies, reflection interference, short-term persistence, and relock / pullback, causing partial reversals or incremental anomalies in the original timestamps generated by edge nodes. Since big data information security protection and storage processes highly depend on the order of events, log time consistency, and cloud evidence storage order, distortion of the original timestamps can easily lead to confusion in the sequence of events across nodes, inability to close the audit chain, inaccurate order of evidence objects, and decreased credibility of cloud-based security archiving results, thereby affecting subsequent data protection, accountability, and compliance auditing.

[0003] In existing cloud-based data security protection and storage processing technologies, the original timestamps reported by the edge side are typically assumed to be authentic and valid. Data encryption, integrity association, log archiving, evidence retention, and hierarchical storage operations are often directly performed based on these original timestamps. There is a lack of mechanisms for identifying and correcting time distortions caused by time synchronization anomalies. Erroneous time sequences affected by time synchronization anomalies are directly written into the hash chain, key derivation chain, and cloud archive chain. This not only makes it difficult to distinguish between the true order of events and the abnormal time sequence but may also permanently solidify local time discrepancies as legitimate storage results, making it impossible to restore the true sequence of events during subsequent queries, audits, evidence collection, and recovery. When the reliability of the time sequence is insufficient, there is often a lack of corresponding differentiated storage paths and access control policies. This results in low-reliability data and high-reliability data using the same protection and retention methods, making it difficult to simultaneously meet the integrity requirements, audit requirements, and the acceptability of storage results for cloud-based big data security protection. Summary of the Invention

[0004] The purpose of this invention is to address the shortcomings of existing technologies where the original timestamps of edge nodes are easily affected by time synchronization jumps, resulting in order distortion and insufficient reliability of cloud data security encapsulation, audit evidence storage, and hierarchical storage. Therefore, this invention proposes a big data information security protection and storage method and system based on cloud computing.

[0005] To address the problems existing in the prior art, the present invention adopts the following technical solution:

[0006] A cloud computing-based method for big data information security protection and storage, comprising:

[0007] S1. Extract the original timestamps, local monotonic counts, time base states, main affected sector identifiers, and current environmental phase quantities of the events to be processed generated by the edge nodes to construct the original event sequence;

[0008] S2. Establish a causal edge set based on the order of occurrence of the events to be processed, and input the original timestamp, local monotonic count value, time base state, main influence sector identifier and current environmental phase quantity into the particle swarm algorithm model to generate the initial reliable time of the events to be processed.

[0009] S3. Apply a monotonically increasing constraint to the initial trusted time, reconstruct the final trusted logical time of the event to be processed, and calculate the corresponding time trustworthiness based on the violation cases of the final trusted logical time in the causal edge set.

[0010] S4. Embed the final trusted logical time and time trustworthiness into the hash link and key derivation process, and perform secure encapsulation of the data payload corresponding to the event to be processed to generate a unified security object.

[0011] S5. Statistically analyze the time reliability of the same batch of unified security objects, determine the storage level of the unified security objects based on the statistically obtained distribution interval, and write the unified security objects into the hierarchical security storage area of ​​the corresponding storage level on the cloud platform side.

[0012] Preferably, the original timestamps, local monotonic counts, time base states, main influencing sector identifiers, and current environmental phase quantities of the events to be processed generated by the edge nodes are extracted to construct the original event sequence, including:

[0013] For each event to be processed, the original timestamp and local monotonic count value are extracted as the original time series features, the time base state is extracted as the time base attribute, and the main influence sector identifier and the current environmental phase quantity are extracted as the environmental association attribute.

[0014] Using the events to be processed in a steady-state synchronous time base state, calculate the baseline ratio between monotonic counts and time;

[0015] Calculate the environmental phase center quantity of the corresponding main affected sector based on the current environmental phase quantity belonging to the same main affected sector identifier;

[0016] Based on the angular difference between the current environmental phase quantity and the environmental phase center quantity, the environmental sector correlation quantity corresponding to each event to be processed is generated.

[0017] The timing residual is constructed using the original timestamp and the local monotonic count value, and the steady-state residual scale is calculated based on the timing residual under steady-state synchronous time base state.

[0018] The original event sequence is constructed by associating and encapsulating the original timestamp, local monotonic count value, time base state, main influential sector identifier, current environmental phase quantity, baseline ratio, environmental sector correlation quantity, and steady-state residual scale according to the event correspondence.

[0019] Preferably, the initial reliable time for generating the event to be processed includes:

[0020] Based on the necessary sequential relationship of the events to be processed in the data processing flow, establish a set of causal edges pointing from preceding events to subsequent events;

[0021] The phase correction values ​​of multiple main influence sectors and the correction amplitude coefficients corresponding to different time base states are used as search variables for the particle swarm algorithm model.

[0022] Calculate the time correction amount corresponding to each event to be processed based on the correction amplitude coefficient, environmental sector correlation, steady-state residual scale, and phase correction amount;

[0023] The original timestamp is corrected based on the time correction amount to obtain the initial reliable time under the corresponding search variable;

[0024] Particle swarm optimization is performed with the objective function minimized as the guide. The initial credible time corresponding to the optimal search result is selected as the initial credible time of the event to be processed. The objective function comprehensively evaluates the degree of residual deviation between the initial credible time of adjacent events to be processed and the baseline ratio, as well as the degree of order violation of the initial credible time under the causal edge set constraint.

[0025] Preferably, reconstructing the final reliable logical time of the event to be processed includes:

[0026] The initial trusted time of the first event to be processed in the original event sequence is taken as the final trusted logical time of that event.

[0027] For each subsequent event to be processed in the original event sequence, obtain the initial reliable time of the event itself, and the final reliable logical time of the previous event to be processed plus the time increment determined by the baseline ratio and the monotonic count difference of adjacent events to be processed.

[0028] The larger of the initial trusted time and the final trusted logical time of the previous pending event, plus the time increment, is taken as the final trusted logical time of the current pending event.

[0029] Preferably, the temporal credibility is calculated based on the violation cases of the final credible logical time in the causal edge set, including:

[0030] For the current pending event, iterate through all causal edges in the causal edge set that start or end with the current pending event;

[0031] The cumulative difference between the final credible logical time of the current pending event and the final credible logical time of the associated pending events, which are reversed under the causal edge constraint, is used to obtain the causal violation quantity.

[0032] By combining the final reliable logical time difference, baseline ratio, steady-state residual scale, and causal violation quantity of the current pending event, the time reliability of the current pending event is calculated through a preset exponential decay relationship. The larger the causal violation quantity, the lower the output time reliability.

[0033] Preferably, the data payload corresponding to the event to be processed is securely encapsulated to generate a unified security object, including:

[0034] Get the data summary corresponding to the current pending event;

[0035] The integrity link value of the previous pending event, the data digest of the current pending event, the final trusted logical time, and the time trustworthiness are combined and hashed to generate the integrity link value of the current pending event.

[0036] Using the preset root key, the integrity link value of the previous event to be processed, and the final trusted logical time, the object key of the current event to be processed is generated through the key derivation function;

[0037] The object key is used to perform encryption operations on the data payload, integrity link value, final trusted logical time and time trustworthiness to generate an encrypted payload;

[0038] The encrypted payload, integrity link value, final trusted logical time, and time trustworthiness are combined to generate a unified security object.

[0039] Preferably, a set of causal edges is established, including:

[0040] Determine whether the first event necessarily precedes the second event in the data processing flow;

[0041] If the judgment result is yes, add a causal edge from the first event to the second event in the causal edge set;

[0042] Among them, the necessary sequential relationship in the data processing flow includes at least one of the following: local data writing precedes cloud upload confirmation, local alarm generation precedes cloud reception, and local audit record generation precedes cloud solidification.

[0043] Preferably, the unified security object is written to the hierarchical security storage area corresponding to the storage level on the cloud platform side, including:

[0044] Calculate the first and third quartiles of the time confidence level for all uniform security objects in the same batch;

[0045] When the time credibility of the current unified security object is lower than the first quartile, the current unified security object is determined as the lowest storage level and written into the security area to be verified, so that the security area to be verified can only perform append, verification and causal repair operations.

[0046] When the time credibility of the current unified security object is greater than or equal to the first quartile and lower than the third quartile, the current unified security object is determined to be of medium storage level and written to the controlled archive area so that the controlled archive area allows audit queries and controlled access operations to be performed.

[0047] When the time credibility of the current unified security object is greater than or equal to the third quartile, the current unified security object is determined as the highest storage level and written into the immutable archive area as the final evidence object.

[0048] To address the aforementioned problems, this invention also provides a cloud computing-based big data information security protection and storage system, comprising:

[0049] The original sequence construction module is used to extract the original timestamps, local monotonic counts, time base states, main influence sector identifiers, and current environmental phase quantities of the events to be processed generated by edge nodes, and construct the original event sequence.

[0050] The initial time generation module is used to establish a causal edge set based on the order of occurrence of events to be processed, and input the original timestamp, local monotonic count value, time base state, main influence sector identifier and current environmental phase quantity into the particle swarm algorithm model to generate the initial reliable time of the events to be processed.

[0051] The logical time reconstruction module is used to apply a monotonically increasing constraint to the initial trusted time, reconstruct the final trusted logical time of the event to be processed, and calculate the corresponding time trustworthiness based on the violation cases of the final trusted logical time in the causal edge set.

[0052] The data security encapsulation module is used to embed the final trusted logical time and time trustworthiness into the hash link and key derivation process, to securely encapsulate the data payload corresponding to the event to be processed, and to generate a unified security object.

[0053] The hierarchical security storage module is used to statistically analyze the time reliability of the same batch of unified security objects, determine the storage level of the unified security objects based on the statistically obtained distribution interval, and write the unified security objects into the hierarchical security storage area of ​​the corresponding storage level on the cloud platform side.

[0054] Compared with the prior art, the beneficial effects of the present invention are:

[0055] This invention constructs an original event sequence by extracting the original timestamp, local monotonic count value, time base state, main influencing sector identifier, and current environmental phase quantity at the edge node side. It further establishes a causal edge set by combining the necessary sequential relationship between events, generates an initial reliable time using the particle swarm optimization algorithm, and reconstructs the final reliable logical time by applying monotonically increasing constraints, while simultaneously calculating the corresponding time reliability. By transforming the original time information affected by time synchronization jumps into a correctable, constrainable, and quantifiable reliable time result, this invention effectively weakens the interference caused by complex environmental disturbances on time sequence judgment, reduces cross-node event sequence distortion, audit relationship confusion, and unstable evidence storage time basis, and improves the accuracy, continuity, and interpretability of the event time reconstruction results.

[0056] This invention further embeds the final trusted logical time and time trustworthiness into the hash linking, key derivation, and data security encapsulation processes to generate a unified security object. Based on the distribution of time trustworthiness, the unified security object is written into the hierarchical security storage area of ​​the cloud platform at different storage levels. By introducing trusted time basis in the security encapsulation stage and introducing a hierarchical management mechanism corresponding to the degree of trustworthiness in the storage stage, it can prevent data with insufficient time trustworthiness from directly entering the high-trustworthiness archiving path, and prevent incorrect time sequence from being solidified into the cloud integrity chain and evidence storage chain. This improves the integrity assurance capability, audit traceability capability, and storage result acceptability in the cloud big data security protection process. Attached Figure Description

[0057] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0058] Figure 1 A flowchart illustrating a cloud computing-based big data information security protection and storage method according to an embodiment of the present invention;

[0059] Figure 2 This is a functional block diagram of a cloud computing-based big data information security protection and storage system provided in one embodiment of the present invention. Detailed Implementation

[0060] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments.

[0061] Example: This example provides a cloud computing-based method for big data information security protection and storage. See [link to example]. Figure 1Specifically, it includes the following steps:

[0062] S1. Extract the original timestamps, local monotonic counts, time base states, main affected sector identifiers, and current environmental phase quantities of the events to be processed generated by the edge nodes to construct the original event sequence;

[0063] S2. Establish a causal edge set based on the order of occurrence of the events to be processed, and input the original timestamp, local monotonic count value, time base state, main influence sector identifier and current environmental phase quantity into the particle swarm algorithm model to generate the initial reliable time of the events to be processed.

[0064] S3. Apply a monotonically increasing constraint to the initial trusted time, reconstruct the final trusted logical time of the event to be processed, and calculate the corresponding time trustworthiness based on the violation cases of the final trusted logical time in the causal edge set.

[0065] S4. Embed the final trusted logical time and time trustworthiness into the hash link and key derivation process, and perform secure encapsulation of the data payload corresponding to the event to be processed to generate a unified security object.

[0066] S5. Statistically analyze the time reliability of the same batch of unified security objects, determine the storage level of the unified security objects based on the statistically obtained distribution interval, and write the unified security objects into the hierarchical security storage area of ​​the corresponding storage level on the cloud platform side.

[0067] In one embodiment of the present invention, the original timestamp, local monotonic count value, time base state, main influential sector identifier, and current environmental phase quantity of the events to be processed generated by the edge nodes are extracted to construct the original event sequence, including:

[0068] This embodiment is applied to a scenario of collaboration between general industrial facilities and edge cloud. It deploys multiple edge nodes to collect equipment operation data, maintenance logs, access audit data, alarm records, and evidence storage objects. All data is uploaded to the enterprise cloud platform at fixed intervals for centralized storage, security auditing, and compliant evidence storage. For each pending event generated by the edge nodes, the original timing features, time base attributes, and environmental correlation attributes are extracted sequentially according to the order of local hardware interrupts triggered by the event. The original timing features include the original timestamp and local monotonic count value synchronously collected at the time of event triggering. The original timestamp is output in real time by the edge node's time synchronization module, and the local monotonic count value is continuously incremented by a hardware timer independent of the time synchronization module within the edge node's MCU. This timer uses an internal high-precision RC oscillator. The oscillator serves as the clock source, with a counting frequency set to 1MHz. When the timer overflows, it automatically triggers an overflow interrupt and increments the high-order bits of the count value, ensuring that the count value remains strictly monotonically increasing throughout the entire cycle without any zero-return transitions. The time base attribute is the time base state output by the timing module at the moment the event is triggered. The time base state is divided into three categories: steady-state synchronization, short-term hold-up, and relock pullback. When the timing module locks on 4 or more valid satellites and the position accuracy factor is less than or equal to 2, it is determined to be steady-state synchronization, and the corresponding time base state is assigned a value of 0. When the timing module loses lock for less than or equal to 30 seconds and enters the internal hold-up mode, it is determined to be short-term hold-up, and the corresponding time base state is assigned a value of 1. When the timing module ends the hold-up mode, relocks the satellites, and completes the time synchronization pullback, it is determined to be relock pullback, and the corresponding time base state is assigned a value of 2.

[0069] The environmental association attributes include the main influence sector identifier of the satellite signal recorded by the timing module at the event trigger time and the current environmental phase quantity synchronously output by the environmental phase monitoring system. The main influence sector identifier is divided into 16 equally spaced sectors according to the horizontal azimuth of the timing antenna, with each sector corresponding to a 22.5-degree azimuth angle. The main influence sector identifier for each event is determined by the sector containing the azimuth angle of the satellite with the lowest carrier-to-noise ratio among all satellites locked by the timing module at the event trigger time. The current environmental phase quantity ranges from 0 to 2π, corresponding to the phase of a complete environmental cycle, where 0 corresponds to the peak value of the environmental cycle and π corresponds to the valley value. The sampling frequency of the environmental phase monitoring system is set to 1Hz. When the event trigger time and the environmental phase sampling time do not match, a linear interpolation method is used to obtain the accurate environmental phase quantity at the event trigger time. The synchronization error between the environmental phase quantity and the event trigger time is controlled within 100 milliseconds. It should be noted that in this embodiment, the sector containing the azimuth angle of the satellite with the lowest carrier-to-noise ratio is used as the main influence sector identifier, not... Instead of representing the overall satellite distribution of the event, this is used to extract the directional proxy quantity most sensitive to reflection interference. This is because, in general industrial facility scenarios, multipath reflection paths and reflection paths from adjacent structures preferentially reduce the effective carrier-to-noise ratio (CNR) of affected satellite signals, making these satellites more representative of the dominant source of reflection interference experienced by the timing antenna at any given time. Since this invention does not directly utilize this main affected sector identifier for positioning calculations, but instead combines it with the current environmental phase quantity to construct environmental sector correlation quantities, using the sector corresponding to the satellite with the lowest CNR can stably represent the main disturbed direction of the timing jump. This reduces the computational complexity of multi-satellite joint modeling without compromising the ability of subsequent time correction processes to identify scene interference. When multiple satellites with the same lowest CNR exist at the same time, the sector corresponding to the azimuth angle of the satellite with the lower elevation angle is preferentially selected as the main affected sector identifier. If the elevation angles are also the same, the sector corresponding to the satellite that first entered the lock list in time is selected as the main affected sector identifier.

[0070] It should be noted that a pending event refers to a single data processing unit generated by an edge node during operation and entering the processing flow of this invention. This can be a device status acquisition record, operation and maintenance log, access audit record, alarm record, or a data object to be stored. A pending event is the smallest processing object for time correction, secure encapsulation, and hierarchical storage. The main impact sector identifier refers to the sector number obtained according to the circumferential azimuth of the timing antenna, used to characterize the main disturbance direction corresponding to the current pending event. This identifier is used to delineate the directional segment most relevant to timing jumps, thereby supporting subsequent joint analysis of environmental phase and sectors. The current environmental phase quantity refers to the environmental periodic phase quantity corresponding to the time of the pending event, used to characterize which stage of the complete environmental cycle the event is in. This quantity is used to introduce the natural factor of environmental periodic change into the timing anomaly analysis process. Time synchronization jumps refer to the phenomenon where, during the continuous output of time information by a time synchronization system, the output time changes non-smoothly within a short period of time due to reasons such as abnormal external time synchronization signals, temporary loss of synchronization link lock, enhanced reflection interference, relock pullback, or local hold-and-hold switching. This change usually manifests as a sudden shift of the time value forward or backward, or an abnormal local increment, thereby disrupting the time evolution relationship that should be continuous, stable, and coordinated with local monotonic counting. For business scenarios that rely on the order of events, consistency of audit time, and the credibility of cloud-based evidence storage, time synchronization jumps will directly lead to inconsistencies between the original timestamp and the actual order of occurrence, thereby affecting the trustworthy foundation for subsequent secure encapsulation, integrity association, and hierarchical storage.

[0071] Using all events to be processed that are in a steady-state synchronous time base state, calculate the baseline ratio between the monotonic count and time. The formula for calculating the baseline ratio is:

[0072]

[0073] in This represents the basic ratio of monotonic counting to time. This indicates the median operation, where i represents the sequence number of the event to be processed. This represents the time base state of the i-th pending event. The corresponding time base state is steady-state synchronization. This represents the original timestamp of the i-th pending event. This represents the original timestamp of the (i-1)th pending event. This represents the local monotonic count value of the i-th pending event. The median represents the local monotonic count value of the (i-1)th event to be processed. The ratio of the time difference to the count difference is included in the median calculation only when the time base states of two adjacent events are both in steady-state synchronization. The core reason for using the median to calculate the benchmark ratio is that the median can effectively eliminate accidental jitter anomalies within the steady-state synchronization interval, avoiding interference from extreme values ​​in the arithmetic mean. The resulting benchmark ratio can accurately reflect the linear correspondence between the hardware timer count increment and the standard time increment, unaffected by time jumps in non-steady-state intervals.

[0074] Based on the current environmental phase quantities of all pending events belonging to the same primary sector identifier, calculate the environmental phase center quantity of the corresponding primary sector. The formula for calculating the environmental phase center quantity is as follows:

[0075]

[0076] in This indicates the environmental phase center quantity corresponding to the main influencing sector identifier m. This represents the operation of taking the complex value of the argument. This indicates the main sector identifier of the i-th pending event. Indicates the identifier of the specified primary affected sector. The main affected sector is identified as The current environmental phase of the i-th pending event, where j is the imaginary unit. It is a natural constant; if the number of pending events corresponding to a certain main affected sector is 0, then the environmental phase center value of that sector is assigned a value of 0. If the number of pending events corresponding to a certain main affected sector is 1, then the environmental phase center value of that sector is directly assigned the current environmental phase value of that event. The core reason for using complex exponential summation and taking the argument angle to calculate the environmental phase center value is that the environmental phase value is a periodic cyclic angle value. Directly using the arithmetic mean to calculate will result in mean distortion when 0 and 2π are adjacent. This calculation method can accurately calculate the central trend of periodic angle data, and the obtained environmental phase center value can reflect the environmental phase position where the corresponding sector's time synchronization jump is concentrated.

[0077] Based on the angular difference between the current environmental phase quantity and the environmental phase center quantity of the corresponding main influencing sector, the environmental sector correlation quantity corresponding to each event to be processed is generated. The calculation formula for the environmental sector correlation quantity is as follows:

[0078]

[0079] in This represents the environmental sector association quantity of the i-th pending event. This represents the current environmental phase of the i-th event to be processed. Indicates the main impact sector identifier of the i-th pending event. The corresponding environmental phase center quantity, This represents cosine operation; the environmental sector correlation quantity obtained by this calculation method has a value range of -1 to 1. When the current environmental phase quantity of the event to be processed coincides with the environmental phase center quantity of the corresponding sector, the environmental sector correlation quantity takes the maximum value of 1, which means that the event to be processed is in the core influence environmental phase interval of the timing jump of the sector. The smaller the absolute value of the environmental sector correlation quantity, the lower the degree of influence of the timing jump of the event to be processed by the environmental phase lock. This calculation can quantify the degree of joint influence of the event to be processed by the environmental phase and the sector into a continuously calculable value, providing a quantitative basis for the subsequent time correction process.

[0080] Timing residuals are constructed using the original timestamps and local monotonic counts, and the steady-state residual scale is calculated based on the timing residuals under steady-state synchronized time base conditions. The formula for calculating the timing residuals is as follows:

[0081]

[0082] in This represents the timing residual of the i-th pending event. This represents the original timestamp of the i-th pending event. This represents the original timestamp of the (i-1)th pending event. This represents the basic ratio of monotonic counting to time. This represents the local monotonic count value of the i-th pending event. This represents the local monotonic count value of the (i-1)th event to be processed. The first event to be processed in the original event sequence does not participate in the timing residual calculation. The corresponding timing residuals are calculated sequentially starting from the second event to be processed. The timing residual directly reflects the deviation between the actual change of the original timestamp and the standard time change corresponding to the hardware monotonic count. The larger the absolute value of the deviation, the higher the degree to which the original timestamp of the event to be processed is affected by the time synchronization jump. The formula for calculating the steady-state residual scale is:

[0083]

[0084] in Represents the steady-state residual scale. This indicates the calculation of the absolute deviation of the median, where i represents the sequence number of the event to be processed. This represents the time base state of the i-th pending event. The corresponding time base state is steady-state synchronization. Let represent the timing residual of the i-th event to be processed. The timing residual is included in the median absolute deviation calculation only when the time base states of two adjacent events are both in steady-state synchronization. The minimum number of valid samples for calculation is no less than 5. If the number of valid samples is less than 5, then 1.4826 times the standard deviation of the timing residuals of all steady-state synchronization events in the entire sequence is taken as the steady-state residual scale. Furthermore, the purpose of setting the above boundary processing rules is to ensure that the steady-state residual scale remains computable and consistent even in small sample scenarios. When the number of valid samples within the steady-state synchronization interval is insufficient, directly using the median absolute deviation may easily lead to unstable scale estimation due to insufficient samples, thereby amplifying subsequent time correction and time... To address the random fluctuations in reliability calculations, this embodiment uses the standard deviation of the timing residuals from the entire sequence's steady-state synchronization events, converted to a consistent value, as a substitute scale. This provides a reference scale consistent with the steady-state residual dimensions for subsequent correction and normalization calculations, thus avoiding scale distortion when there is insufficient data at edge nodes or a short steady-state synchronization interval. This ensures the entire reliable time reconstruction process can be stably executed across different batches and nodes. The core reason for using the median absolute deviation to calculate the steady-state residual scale is that this statistic effectively resists outlier interference, accurately reflects the normal fluctuation range of timing residuals under steady-state synchronization, and can serve as a benchmark threshold for subsequent judgment of timing anomalies.

[0085] The original timestamp, local monotonic count value, time base state, main influential sector identifier, current environmental phase quantity, and the baseline ratio uniformly calculated for the entire batch, the environmental sector correlation quantity and steady-state residual scale corresponding to each event to be processed are associated and encapsulated one by one in the ascending order of the local monotonic count value. Each event corresponds to an independent data record, and all data records are arranged in ascending order of local monotonic count value to form a complete original event sequence, providing a complete and traceable basic dataset for subsequent initial trusted time generation and trusted logical time reconstruction.

[0086] In one embodiment of the present invention, a causal edge set is established according to the order of occurrence of the events to be processed, and the original timestamp, local monotonic count value, time base state, main influence sector identifier, and current environmental phase quantity are input into the particle swarm optimization algorithm model to generate the initial reliable time of the events to be processed, including:

[0087] Based on the necessary sequence of events in the data processing flow, a set of causal edges pointing from preceding events to subsequent events is established. For each set of events to be processed, a determination of the necessary sequence is performed to determine whether the first event necessarily occurs before the second event in the data processing flow. If the determination result is yes, a causal edge pointing from the first event to the second event is added to the causal edge set. The necessary sequence in the data processing flow includes local data writing before cloud upload confirmation, local alarm generation before cloud reception, and local audit record generation before cloud solidification. All events to be processed carry a unique device identifier and a global serial number. Local events and corresponding cloud events are matched one-to-one using the device identifier and global serial number. After matching, the sequence is determined according to the full-link time sequence logic of data processing. If a local event has no corresponding cloud event, it is not included in the construction scope of the causal edge set. If a cloud event has no corresponding preceding local event, it is also not included in the construction scope of the causal edge set, ensuring that each causal edge in the causal edge set corresponds to a real and necessary sequence logic, without the introduction of false causal relationships.

[0088] The phase correction values ​​of multiple main influence sectors and the correction amplitude coefficients corresponding to different time base states are used as search variables in the particle swarm optimization (PSO) model. There are 16 main influence sectors, corresponding to 16 equally spaced azimuth sectors; therefore, 16 independent phase correction values ​​are set. The time base states are divided into three categories: steady-state synchronization, short-term hold-up, and relock pullback; therefore, 3 independent correction amplitude coefficients are set. The search variable dimension for a single particle is 19 dimensions, and the expression for the search variable is:

[0089]

[0090] in This represents the combination of search variables corresponding to a single particle. This represents the phase correction amount corresponding to the 1st to 16th main affected sectors. This represents the correction amplitude coefficient corresponding to the steady-state synchronization time base state. This represents the correction amplitude coefficient corresponding to the short-term hold-at-time base state. The correction amplitude coefficient represents the time base state corresponding to the relocking pullback. Each search variable has a defined range of values, with the phase correction ranging from 0 to 2π and the correction amplitude coefficient ranging from 0 to 10, to ensure that no physically meaningless parameter values ​​appear during the particle search process.

[0091] Based on the combination of search variables corresponding to particles, and combined with the environmental sector correlation, steady-state residual scale, and phase correction generated in the previous steps, the time correction amount corresponding to each event to be processed is calculated. The formula for calculating the time correction amount is as follows:

[0092]

[0093] in Indicates the combination of search variables The corresponding time correction amount for the i-th pending event. Indicates the time base state of the i-th pending event. The corresponding correction amplitude coefficient, When it is 0, it corresponds to , When it is 1, it corresponds to , When it is 2, it corresponds to , This represents the environmental sector association quantity of the i-th pending event. This represents the current environmental phase of the i-th event to be processed. Indicates the main impact sector identifier of the i-th pending event. The corresponding phase correction amount, This represents the steady-state residual scale. The core design of this calculation formula lies in deeply binding the time correction amount with the scene-specific environmental phase, sector, and time base state. The corresponding correction amount will only be generated when the event to be processed is in the core influence range of the time synchronization transition, thus avoiding over-correction of the normal timestamp in the steady-state synchronization state. At the same time, the correction amount is normalized by the steady-state residual scale to ensure that the magnitude of the correction amount matches the normal fluctuation range of the time synchronization transition, thus avoiding the problems of over-correction or under-correction.

[0094] Based on the calculated time correction amount, the original timestamp is corrected to obtain the initial reliable time under the corresponding search variable. The formula for calculating the initial reliable time is as follows:

[0095]

[0096] in Indicates the combination of search variables The initial reliable time corresponding to the i-th pending event. This represents the original timestamp of the i-th pending event. Indicates the combination of search variables The time correction amount for the i-th event to be processed is obtained by directly taking the original timestamp of the first event to be processed in the original event sequence without performing a correction operation, thus ensuring the stability of the baseline starting point of the time series.

[0097] Particle swarm optimization is performed with the objective function minimized. The objective function comprehensively evaluates the residual deviation between the initial confidence times of adjacent events and the baseline ratio, as well as the order violation of the initial confidence times under the constraints of the causal edge set. The formula for calculating the objective function is as follows:

[0098]

[0099] in Indicates the combination of search variables The corresponding objective function value; the smaller the objective function value, the better the optimization effect of the combination of search variables. This represents the initial reliable time for the i-th pending event. This represents the initial reliable time for the (i-1)th pending event. This represents the basic ratio of monotonic counting to time. This represents the local monotonic count value of the i-th pending event. This represents the local monotonic count value of the (i-1)th pending event. Represents the steady-state residual scale. Represents the set of causal edges. This indicates that the set of causal edges consists of preceding events. Pointing to subsequent events The causal edge, Indicates the preceding event The initial reliable time, Indicates subsequent events The initial reliable time, Indicates subsequent events The original timestamp, Indicates the preceding event The original timestamp; the objective function consists of two core computational terms. The first term is the monotonic counting consistency term, which is used to constrain the change in the initial reliable time to be consistent with the standard time change corresponding to the hardware monotonic counting, ensuring that the monotonicity of the time series conforms to the actual operating rules of the hardware timer. Dividing by the steady-state residual scale is to normalize this term and eliminate the influence of dimensions. The second term is the causal constraint violation term, which is used to penalize the situation where the initial reliable time violates the necessary sequential relationship. When the initial reliable time of the preceding event is later than the initial reliable time of the following event, a corresponding violation penalty value will be generated to ensure that the optimized initial reliable time conforms to the true causal logic of the data processing flow. Dividing by the median absolute deviation of the original time difference of the causal edge is to normalize this term and avoid the imbalance of optimization weights caused by the difference in magnitude between the two computational terms. If the causal edge set is empty, the second term is 0, and only the first term is retained for optimization. If the median absolute deviation of the denominator is 0, the denominator is assigned a value of 1 to avoid division by zero error.

[0100] The particle swarm optimization (PSO) algorithm is executed with clearly defined and reproducible parameters. The population size is set to 30, the maximum number of iterations is set to 100, and the inertia weight uses a linear decreasing strategy, with an initial inertia weight of 0.9 and a final inertia weight of 0.4. Both the individual learning factor and the global learning factor are set to 2. The initial positions of particles are generated using a uniform random distribution within the range of the search variables, and the initial velocity is set to 0. During each iteration, the velocity and position of each particle are updated sequentially. If the updated particle position exceeds the range of the search variables, it is restricted to the corresponding value boundary. Simultaneously, the individual optimal position of each particle and the global optimal position of the population are recorded. The convergence condition for the iteration process is that the change in the global optimal objective function value of the population over 10 consecutive generations is less than 0.000001. Iteration stops when the maximum number of iterations is reached or the convergence condition is met. The combination of search variables corresponding to the global optimal position at the time of iteration stop is selected as the optimal search result. Based on the optimal search result, the initial reliable time corresponding to each event to be processed is calculated, serving as the basis data for subsequent reliable logical time reconstruction.

[0101] In one embodiment of the present invention, a monotonically increasing constraint is applied to the initial trusted time to reconstruct the final trusted logical time of the event to be processed, and the corresponding time trustworthiness is calculated based on the violation cases of the final trusted logical time in the causal edge set, including:

[0102] The original event sequence is ordered in a strictly increasing order based on the local monotonic count values, ensuring that the order of events in the sequence is unaffected by changes in the original timestamp timing and is determined solely by the output of a hardware timer unaffected by timing link interference. The initial reliable time of the first event to be processed in the original event sequence is taken as the final reliable logical time of that event, and the corresponding formula is:

[0103]

[0104] in This represents the final reliable logical time of the first event to be processed in the original event sequence. This represents the initial reliable time of the first event to be processed in the original event sequence. The first event to be processed is the starting point of the time base of the entire sequence. There are no preceding related events, and there is no possibility of time backtracking or causal violation. Directly using the initial reliable time can ensure the stability of the time base of the entire sequence and avoid the cumulative error caused by the base offset to the time reconstruction of all subsequent events.

[0105] For each subsequent event to be processed in the original event sequence with a sequence number greater than or equal to 2, the final reliable logical time is calculated sequentially in ascending order of the sequence. The initial reliable time of each event to be processed is obtained, along with the final reliable logical time of the preceding event to be processed, plus a time increment determined by the baseline ratio and the monotonic count difference between adjacent events to be processed. The formula for calculating the time increment is as follows:

[0106]

[0107] in This represents the time increment between the i-th pending event and the (i-1)-th pending event. This represents the basic ratio of monotonic counting to time. This represents the local monotonic count value of the i-th pending event. This represents the local monotonic count value of the (i-1)th event to be processed. The physical meaning of this time increment is the minimum reasonable time interval between two adjacent events calculated based on the hardware timer count difference that is not affected by time synchronization, combined with the benchmark ratio. This interval is determined by the operating rules of the hardware timer and is the minimum time difference between the later event and the previous event that the later event satisfies. It can be used as the core benchmark of monotonic constraints.

[0108] The larger of the initial reliable time of the event to be processed and the final reliable logical time of the previous event to be processed, plus the time increment, is taken as the final reliable logical time of the current event to be processed. The corresponding calculation formula is as follows:

[0109]

[0110] in This represents the final reliable logical time of the i-th pending event. This represents the initial reliable time for the i-th pending event. This represents the final reliable logical time of the (i-1)th pending event. This represents the time increment between the i-th event and the (i-1)-th event. By imposing a strict monotonically increasing constraint on the initial reliable time, the limitations of particle swarm optimization (PSO) are addressed. It can only guarantee the minimization of the overall objective function, but cannot ensure that the time series between each adjacent event is strictly monotonically increasing. This avoids the problem of local time series regression in the initial reliable time. When the initial reliable time of the event being processed is greater than or equal to the sum of the final reliable logical time and the time increment of the previous event, it indicates that the initial reliable time meets the strict monotonically increasing constraint. Directly using the initial reliable time can maximize the preservation of the time series obtained from PSO. The time correction results based on causal constraints and environmental phase correlation characteristics indicate that if the initial credible time of the event to be processed is less than the result of the final credible logical time plus the time increment of the previous event to be processed, it indicates that there is a time backtracking in the initial credible time. In this case, the result of the final credible logical time plus the time increment of the previous event to be processed is used as the final value, which can forcibly correct the time backtracking problem, ensure that the final generated full-sequence credible logical time conforms to the true order of events, maintains a strict monotonically increasing trend throughout, reduces the risk of time inversion, and avoids over-correction of the initial credible time, thus ensuring the accuracy and rationality of the time reconstruction results.

[0111] For each current pending event in the original event sequence, all causal edges in the causal edge set are traversed sequentially according to the event number. All related causal edges that start from or end with the current pending event are selected. Causal edges that start from the current pending event correspond to a preceding event that must have occurred before the current pending event, and causal edges that end with the current pending event correspond to a following event that must have occurred after the current pending event. All causal edges are precisely matched using the unique device identifier and global serial number carried by the pending event to ensure that there are no mismatched or missing related causal edges. If the current pending event has no corresponding related causal edge, the causal violation count of the event is directly determined to be 0.

[0112] After filtering the causal edges, the cumulative difference between the final reliable logical time of the current event to be processed and the final reliable logical time of the related events to be processed, which are reversed under the causal edge constraints, is calculated to obtain the causal violation quantity. The formula for calculating the causal violation quantity is as follows:

[0113]

[0114] in This represents the causal violation quantity of the i-th currently pending event. Represents the set of causal edges. This represents a causal edge that ends with the current pending event i and starts with the preceding event u. This represents the final reliable logical time of the preceding event u. This indicates the final reliable logical time of the event i currently pending. This represents a causal edge that starts with the current pending event i and ends with the subsequent event v. This represents the final credible logical time of the subsequent event v. The calculation formula consists of two independent accumulation terms. The first accumulation term is used to calculate the time inversion difference caused by the final credible logical time of the preceding event being later than the current event when the current event is the subsequent event. The second accumulation term is used to calculate the time inversion difference caused by the final credible logical time of the current event being later than the subsequent event when the current event is the preceding event. A non-zero accumulation value is only generated when the time inversion occurs. The core reason for using the cumulative difference rather than the number of violations to calculate the causal violation quantity is that the magnitude of the time difference of the time inversion directly reflects the degree of distortion of the causal relationship of the event. The larger the time difference, the more serious the destruction of the causal relationship. Compared with simply counting the number of violations, the cumulative difference can more accurately quantify the severity of causal violations, providing a quantitative basis that conforms to the actual distortion situation for the subsequent calculation of time credibility.

[0115] Combining the final reliable logical time difference, baseline ratio, steady-state residual scale, and causal violation amount of the current pending event, the time reliability of the current pending event is calculated through a preset exponential decay relationship. First, the timing deviation term of the current pending event is calculated. The formula for calculating the timing deviation term is as follows:

[0116]

[0117] in This represents the timing deviation term for the i-th currently pending event. This represents the final reliable logical time of the i-th currently pending event. This represents the final reliable logical time of the (i-1)th pending event. This represents the ratio of the monotonic counts calculated in the preceding steps to the baseline of time. This represents the local monotonic count value of the i-th currently pending event. This represents the local monotonic count value of the (i-1)th pending event. The steady-state residual scale is used to represent the first event to be processed in the original event sequence. Since there are no preceding adjacent events, its timing deviation term is directly determined to be 0. This timing deviation term is used to quantify the degree of deviation between the adjacent difference of the final reliable logic time and the standard time increment corresponding to the hardware monotonic count. The purpose of dividing by the steady-state residual scale is to normalize the deviation value, eliminate the influence of the dimension, and make the timing deviation term and the causal violation term be on the same order of magnitude to avoid weight imbalance.

[0118] The formula for calculating the causal violation normalization term is as follows:

[0119]

[0120] in This represents the causal violation normalization term for the i-th currently pending event. This represents the causal violation quantity of the i-th currently pending event. Represents the set of causal edges. This represents a causal edge in the set of causal edges that points from a preceding event u to a subsequent event v. This represents the original timestamp of the subsequent event v. This represents the original timestamp of the preceding event u. If the causal edge set is empty, or the median absolute deviation of the denominator is calculated to be 0, the denominator of the causal violation normalization term is directly assigned to 1 to avoid division by zero error. This normalization term is used to convert the causal violation quantity into a dimensionless standardized value to ensure that its weight matches that of the timing deviation term.

[0121] The time reliability of the current event to be processed is calculated using the exponential decay relationship. The formula for calculating time reliability is:

[0122]

[0123] in This represents the time reliability of the i-th currently pending event. This indicates exponential operations with the natural constant e as the base. This represents the timing deviation term for the i-th currently pending event. This represents the causal violation normalization term for the i-th current event to be processed. The core reason for using an exponential decay relationship to calculate time reliability is that this calculation method naturally constrains the range of time reliability values ​​between 0 and 1, eliminating the need for additional normalization processing. At the same time, it can achieve the effect of small deviations having a gradual impact on reliability, while large deviations and serious causal violations causing a rapid decrease in reliability. This aligns with the data reliability judgment logic in industrial scenarios. The larger the number of causal violations, the larger the corresponding causal violation normalization term value, and the smaller the result of the exponential operation, resulting in a lower final output time reliability. This matches the reliability judgment rules. The calculated time reliability of each event to be processed will serve as the core quantitative basis for subsequent secure encapsulation and hierarchical storage. In this embodiment, the input to the exponential decay relationship consists of only two parts: a timing deviation term and a causal violation normalization term. The timing deviation term characterizes the degree of local deviation of the final reliable logical time of the current event to be processed relative to the hardware monotonic counting benchmark, while the causal violation normalization term characterizes the degree of global order distortion of the current event to be processed under the constraints of the causal edge set. The reason for using the sum of the two terms before exponential mapping is that this method can compress local timing anomalies and global causal anomalies into the same reliability output space without introducing additional multi-level judgment thresholds, ensuring that the time reliability remains continuously changing and monotonically decreasing. When both the timing deviation term and the causal violation normalization term are small, the output time reliability is close to 1, indicating that the event to be processed conforms to the hardware monotonic counting law and does not disrupt the necessary sequential relationship in the data processing flow. When either term increases, the output time reliability decreases, indicating that the risk of the event to be processed in terms of time reliability increases. This allows for a one-to-one quantitative connection between time reliability and subsequent hierarchical storage levels.

[0124] In one embodiment of the present invention, the final trusted logical time and time trustworthiness are embedded in the hash linking and key derivation stages to securely encapsulate the data payload corresponding to the event to be processed, generating a unified security object, including:

[0125] For each currently pending event in the original event sequence, arranged in monotonically increasing order of count value, obtain its corresponding data digest. The data digest is generated by performing a national cryptographic SM3 hash operation on the original data payload of the current pending event. The original data payload includes complete original data of device status data, operation logs, access records, alarm records, or evidence objects. The hash operation outputs a data digest of fixed length 256 bits. The integrity link value of the previous pending event, the data digest of the current pending event, the final trusted logical time, and the time trustworthiness are concatenated byte-wise and then hashed to generate the integrity link value of the current pending event. The formula for calculating the integrity link value is:

[0126]

[0127] in This represents the integrity link value of the i-th currently pending event. This indicates the SM3 hash operation. This represents the integrity link value of the (i-1)th pending event. This indicates a byte order concatenation operation. This represents the data summary of the i-th currently pending event. This represents the final reliable logical time of the i-th currently pending event. This represents the time credibility of the i-th current pending event. For the first pending event in the original event sequence, the integrity link value of its predecessor pending event adopts a preset system root integrity initial value. The system root integrity initial value is a fixed 256-bit random number generated by the cloud platform cryptographic machine and stored offline in the hardware security module throughout the process. The core design of this calculation formula is to construct a chain-like integrity verification structure based on trusted logical time, incorporating the integrity link value of the predecessor event into the hash operation of the current event, forming a hash chain with strong correlation between preceding and following events. This ensures that any tampering with any event will cause the integrity link values ​​of all subsequent events to become invalid. At the same time, the final trusted logical time and time credibility are directly embedded into the core input of the hash operation, rather than using the original timestamp that is contaminated by the time authorization. This makes the construction of the entire hash chain based on the reconstructed trusted time order, avoiding the contaminated erroneous time order from being solidified into the tamper-proof integrity verification chain, and ensuring the order credibility and integrity of the data stored in the cloud are tamper-proof.

[0128] Using a preset root key, the integrity link value of the previous event to be processed, and the final trusted logical time, the object key for the current event to be processed is generated through a key derivation function. Furthermore, in this embodiment, the key derivation function employs a fixed-output-length key derivation process. The derivation input is a combination of byte sequences representing the system root key, the integrity link value of the previous event to be processed, and the final trusted logical time of the current event to be processed. The output length is fixed at 128 bits to maintain consistency with the key length required by the subsequent SM4 national cryptographic algorithm. The key derivation process is completed internally within the cloud platform's hardware security module; external business programs only receive the object key derivation result. This approach avoids accessing the system root key and derived intermediate states, thus ensuring the root key remains within module boundaries. For different pending events, as long as the integrity link value of the previous pending event or the final trusted logical time of the current pending event differs, the derived object key will be different. This achieves a one-time pad key isolation effect for each event. With this implementation, even if an attacker obtains the object key corresponding to a certain unified security object, they cannot deduce the system root key or directly deduce the object keys corresponding to other unified security objects. This ensures the cryptographic isolation and chain security between unified security objects. The formula for calculating the object key is:

[0129]

[0130] in This represents the object key for the i-th currently pending event. This represents the SM4-KDF key derivation function that conforms to national cryptographic management standards. This refers to the preset system root key. The system root key is generated by the cloud platform's hardware cryptographic machine and stored entirely in the hardware security module. It is only accessed during key derivation and is not exposed externally. This represents the integrity link value of the (i-1)th pending event. This indicates a byte order concatenation operation. This represents the final trusted logical time of the i-th current pending event. For the first pending event in the original event sequence, the system root integrity initial value is used to replace the integrity link value of the previous pending event in key derivation. The core design of this calculation formula is to implement a one-time pad encryption mechanism for each event. The object key of each pending event is derived independently and is not related to each other. Even if the object key of a single event is leaked, it will not affect the data security of other events. At the same time, the derivation of the object key is deeply bound to the integrity link value of the previous event and the final trusted logical time of the current event. Only when the hash chain is complete and the time order is correct can the correct object key be derived, further strengthening the strong correlation between trusted logical time and data encryption security, preventing data from being decrypted and accessed even after it has been tampered with or the time order has been adjusted.

[0131] The generated object key is used to perform symmetric encryption operations on the data payload, integrity link value, final trusted logical time, and time trustworthiness to generate an encrypted payload. The encryption operation adopts the national standard SM4-GCM certified encryption mode. The calculation formula for the encryption operation is as follows:

[0132]

[0133] in This represents the encrypted payload of the i-th currently pending event. This indicates that the encryption operation is certified by the national cryptographic standard SM4-GCM. This represents the object key for the i-th currently pending event. This represents the raw data payload of the i-th currently pending event. This represents the integrity link value of the i-th currently pending event. This represents the final reliable logical time of the i-th currently pending event. The time credibility of the i-th current pending event is represented. During the encryption operation, a 128-bit authentication tag is generated simultaneously. The authentication tag is stored along with the encryption payload and is used to verify the integrity and authenticity of the encrypted data during decryption. The core reason for adopting the national cryptographic standard SM4-GCM authentication encryption mode is that this algorithm can simultaneously achieve data confidentiality encryption and integrity authentication. It generates an unforgeable authentication tag while encrypting the data. Any tampering with the encryption payload will cause the authentication tag verification to fail and decryption to be impossible. At the same time, the algorithm complies with the national cryptographic management standards and is compatible with the compliance requirements of industrial scenarios and cloud platforms. In this embodiment, the national cryptographic standard SM4-GCM authentication encryption mode processes the input plaintext byte by byte, without additional grouping and padding steps. The original data payload, integrity link value, final trusted logical time, and time credibility are directly used as authentication encryption inputs after being concatenated in a fixed byte order. The generated authentication tag and encryption payload are written together into a unified security object to ensure the consistency between the encryption result and the authentication result.

[0134] It should be noted that the data payload refers to the original business data content carried by the event to be processed. It is the core data ontology for subsequent digest calculation, encryption encapsulation, and cloud storage. It does not include subsequent derived integrity link values, time trustworthiness, or other additional security fields. The data digest refers to the fixed-length result obtained after performing a hash operation on the data payload of the event to be processed. It is used to characterize the content features of the original data payload. The data digest itself does not directly carry business content but is used for subsequent integrity verification and secure encapsulation.

[0135] The generated encrypted payload, integrity link value, final trusted logical time, and time trustworthiness are combined and encapsulated in a fixed byte order to generate a standardized unified security object. The unified security object is encapsulated in a fixed-structure TLV format, with each field carrying a corresponding type identifier and length identifier to ensure that the content of each field can be accurately parsed during cloud platform storage and retrieval without any parsing ambiguity. During the encapsulation process, the device identifier, global serial number, and main affected sector identifier corresponding to the event are simultaneously included as auxiliary fields in the unified security object to ensure that each unified security object can independently trace the corresponding original event and the entire chain processing process. The generated unified security object will serve as the sole processing object for subsequent hierarchical storage.

[0136] In one embodiment of the present invention, the time reliability of the same batch of unified security objects is statistically analyzed, the storage level of the unified security objects is determined based on the statistically obtained distribution interval, and the unified security objects are written into the hierarchical security storage area of ​​the corresponding storage level on the cloud platform side, including:

[0137] The batch division rules are clearly defined. A unified security object within the same batch corresponds to the encapsulated results of all pending events generated by the same edge node within a fixed upload period. The upload period is set to 1 hour. Unified security objects within each batch are uniformly arranged in ascending order of their local monotonic count values. After batch division, the time reliability corresponding to all unified security objects within that batch is extracted, forming a time reliability set arranged in event order. All values ​​within the time reliability set are then sorted in ascending order to obtain an ordered time reliability sequence of length N, where N represents the total number of unified security objects within the batch. Based on the ordered time reliability sequence, the first and third quartiles of the batch are calculated using linear interpolation. The first quartile corresponds to the 25th quantile of the sequence, and the third quartile corresponds to the 75th quantile. The formula for calculating the quartile position is as follows:

[0138]

[0139] in Indicates the position of the corresponding quantile value. This represents the total length of the ordered time credibility sequence. Let p represent the target quantile value. When calculating the first quartile, p is set to 0.25, and when calculating the third quartile, p is set to 0.75. Based on the calculated quantile positions, the corresponding quantile values ​​are calculated using linear interpolation. The calculation formula is as follows:

[0140]

[0141] in Indicates the target quantile value. This indicates the floor function. This indicates the rounding up operation. This represents the value corresponding to the floor position in an ordered time credibility sequence. This represents the value corresponding to the floor position in the ordered time confidence sequence, used when calculating the first quartile. When calculating the third quartile corresponding to the first quartile... The third quartile is used; the linear interpolation method is used to calculate the quartiles, which can be adapted to sequences of any length. At the same time, the quartile statistics are not sensitive to extreme outliers and will not cause the overall shift of the classification threshold due to a few extremely low-confidence unified security objects. It can accurately reflect the overall distribution of time confidence within a batch and provide a reasonable judgment benchmark for classified storage. In the boundary scenario where the number of unified security objects within a batch is insufficient, when the length N of the ordered time confidence sequence within the batch is less than 4, the first quartile Q1 is directly assigned to the minimum value of the sequence, and the third quartile Q3 is assigned to the maximum value of the sequence, ensuring that stable classification judgment can still be completed in the boundary scenario.

[0142] After calculating the first and third quartiles, for each current unified security object within the batch, its storage level is determined based on its corresponding time reliability. If the time reliability of the current unified security object is lower than the first quartile, it is assigned to the lowest storage level and written to the verification security area on the cloud platform. The verification security area adopts an append-only object storage architecture, allowing only automatically executed data append operations, authorized auditor read-only verification operations, and causal repair operations after three levels of approval. Any form of modification, deletion, or overwriting is strictly prohibited. All causal repair operations generate immutable operation logs simultaneously and are stored in an independent audit system to ensure the full traceability of the data to be verified. If the time reliability of the current unified security object is greater than or equal to the first quartile but lower than the third quartile, it is assigned to the medium storage level and written to the controlled archive area on the cloud platform. The controlled archive area adopts a storage architecture that cannot be modified after writing, allowing authorized auditors to perform full audit queries and controlled access operations after double review and approval. After writing, access is prohibited. Any form of modification, deletion, or overwriting operation can only be performed by adding a description document associated with the object through a compliant supplementary process. This supplementary document cannot be modified or deleted. When the time reliability of the current unified security object is greater than or equal to the third or fourth quartile, the current unified security object is designated as the highest storage level and written to the immutable archive area on the cloud platform. The immutable archive area adopts a WORM immutable storage architecture that meets judicial evidence preservation requirements. Immutable locking is immediately enabled after the unified security object is written, with a locking period no less than the legally required evidence retention period for the corresponding scenario. During the locking period, only authorized personnel are allowed read-only audit access operations; any form of modification, deletion, overwriting, or adjustment is strictly prohibited. The unified security objects written to the immutable archive area can be directly used as valid evidence for event tracing, liability determination, and judicial litigation. After all unified security objects have been written in a tiered manner, a tiered storage list for that batch is generated synchronously. The list records the global serial number, time reliability, storage level, storage path, and write time of each unified security object. The list file is synchronously written to the immutable archive area for retention, ensuring that the entire batch storage process is traceable and auditable.

[0143] like Figure 2 The diagram shown is a functional block diagram of a cloud computing-based big data information security protection and storage system provided in an embodiment of the present invention.

[0144] In this embodiment, the functions of each module / unit are as follows:

[0145] The original sequence construction module is used to extract the original timestamps, local monotonic counts, time base states, main influence sector identifiers, and current environmental phase quantities of the events to be processed generated by edge nodes, and construct the original event sequence.

[0146] The initial time generation module is used to establish a causal edge set based on the order of occurrence of events to be processed, and input the original timestamp, local monotonic count value, time base state, main influence sector identifier and current environmental phase quantity into the particle swarm algorithm model to generate the initial reliable time of the events to be processed.

[0147] The logical time reconstruction module is used to apply a monotonically increasing constraint to the initial trusted time, reconstruct the final trusted logical time of the event to be processed, and calculate the corresponding time trustworthiness based on the violation cases of the final trusted logical time in the causal edge set.

[0148] The data security encapsulation module is used to embed the final trusted logical time and time trustworthiness into the hash link and key derivation process, to securely encapsulate the data payload corresponding to the event to be processed, and to generate a unified security object.

[0149] The hierarchical security storage module is used to statistically analyze the time reliability of the same batch of unified security objects, determine the storage level of the unified security objects based on the statistically obtained distribution interval, and write the unified security objects into the hierarchical security storage area of ​​the corresponding storage level on the cloud platform side.

[0150] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

Claims

1. A method for big data information security protection and storage based on cloud computing, characterized in that, Includes the following steps: S1. Extract the original timestamps, local monotonic counts, time base states, main affected sector identifiers, and current environmental phase quantities of the events to be processed generated by the edge nodes to construct the original event sequence; S2. Establish a causal edge set based on the order of occurrence of the events to be processed, and input the original timestamp, local monotonic count value, time base state, main influence sector identifier and current environmental phase quantity into the particle swarm algorithm model to generate the initial reliable time of the events to be processed. S3. Apply a monotonically increasing constraint to the initial trusted time, reconstruct the final trusted logical time of the event to be processed, and calculate the corresponding time trustworthiness based on the violation cases of the final trusted logical time in the causal edge set. S4. Embed the final trusted logical time and time trustworthiness into the hash link and key derivation process, and perform secure encapsulation of the data payload corresponding to the event to be processed to generate a unified security object. S5. Statistically analyze the time reliability of the same batch of unified security objects, determine the storage level of the unified security objects based on the statistically obtained distribution interval, and write the unified security objects into the hierarchical security storage area of ​​the corresponding storage level on the cloud platform side.

2. The method for big data information security protection and storage based on cloud computing according to claim 1, characterized in that, Extract the original timestamps, local monotonic counts, time base states, main affected sector identifiers, and current environmental phase quantities of the events to be processed generated by the edge nodes to construct the original event sequence, including: For each event to be processed, the original timestamp and local monotonic count value are extracted as the original time series features, the time base state is extracted as the time base attribute, and the main influence sector identifier and the current environmental phase quantity are extracted as the environmental association attribute. Using the events to be processed in a steady-state synchronous time base state, calculate the baseline ratio between monotonic counts and time; Calculate the environmental phase center quantity of the corresponding main affected sector based on the current environmental phase quantity belonging to the same main affected sector identifier; Based on the angular difference between the current environmental phase quantity and the environmental phase center quantity, generate the environmental sector correlation quantity corresponding to each event to be processed; The timing residual is constructed using the original timestamp and the local monotonic count value, and the steady-state residual scale is calculated based on the timing residual under steady-state synchronous time base state. The original event sequence is constructed by associating and encapsulating the original timestamp, local monotonic count value, time base state, main influential sector identifier, current environmental phase quantity, baseline ratio, environmental sector correlation quantity, and steady-state residual scale according to the event correspondence.

3. The method for big data information security protection and storage based on cloud computing according to claim 2, characterized in that, The initial trusted time for generating events to be processed includes: Based on the necessary sequential relationship of the events to be processed in the data processing flow, establish a set of causal edges pointing from preceding events to subsequent events; The phase correction values ​​of multiple main influence sectors and the correction amplitude coefficients corresponding to different time base states are used as search variables for the particle swarm algorithm model. Calculate the time correction amount corresponding to each event to be processed based on the correction amplitude coefficient, environmental sector correlation, steady-state residual scale, and phase correction amount; The original timestamp is corrected based on the time correction amount to obtain the initial reliable time under the corresponding search variable; Particle swarm optimization is performed with the objective function minimized as the guide. The initial credible time corresponding to the optimal search result is selected as the initial credible time of the event to be processed. The objective function comprehensively evaluates the degree of residual deviation between the initial credible time of adjacent events to be processed and the baseline ratio, as well as the degree of order violation of the initial credible time under the causal edge set constraint.

4. The method for big data information security protection and storage based on cloud computing according to claim 3, characterized in that, Reconstruct the final reliable logical time of the event to be processed, including: The initial trusted time of the first event to be processed in the original event sequence is taken as the final trusted logical time of that event. For each subsequent event to be processed in the original event sequence, obtain the initial reliable time of the event itself, and the final reliable logical time of the previous event to be processed plus the time increment determined by the baseline ratio and the monotonic count difference of adjacent events to be processed. The larger of the initial trusted time and the final trusted logical time of the previous pending event, plus the time increment, is taken as the final trusted logical time of the current pending event.

5. A method for big data information security protection and storage based on cloud computing according to claim 4, characterized in that, The temporal reliability is calculated based on the violation cases of the final reliable logical time in the causal edge set, including: For the current pending event, iterate through all causal edges in the causal edge set that start or end with the current pending event; The cumulative difference between the final credible logical time of the current pending event and the final credible logical time of the associated pending events, which are reversed under the causal edge constraint, is used to obtain the causal violation quantity. By combining the final reliable logical time difference, baseline ratio, steady-state residual scale, and causal violation quantity of the current pending event, the time reliability of the current pending event is calculated through a preset exponential decay relationship. The larger the causal violation quantity, the lower the output time reliability.

6. The method for big data information security protection and storage based on cloud computing according to claim 1, characterized in that, The data payload corresponding to the event to be processed is securely encapsulated to generate a unified security object, including: Get the data summary corresponding to the current pending event; The integrity link value of the previous pending event, the data digest of the current pending event, the final trusted logical time, and the time trustworthiness are combined and hashed to generate the integrity link value of the current pending event. Using the preset root key, the integrity link value of the previous event to be processed, and the final trusted logical time, the object key of the current event to be processed is generated through the key derivation function; The data payload, integrity link value, final trusted logical time, and time trustworthiness are encrypted using the object key to generate an encrypted payload. The encrypted payload, integrity link value, final trusted logical time, and time trustworthiness are combined to generate a unified security object.

7. A method for big data information security protection and storage based on cloud computing according to claim 1, characterized in that, Establish a set of causal edges, including: Determine whether the first event necessarily occurs before the second event in the data processing flow; If the judgment result is yes, add a causal edge from the first event to the second event in the causal edge set; Among them, the necessary sequential relationship in the data processing flow includes at least one of the following: local data writing precedes cloud upload confirmation, local alarm generation precedes cloud reception, and local audit record generation precedes cloud solidification.

8. A method for big data information security protection and storage based on cloud computing according to claim 1, characterized in that, Write the unified security object into the hierarchical security storage area corresponding to the storage level on the cloud platform side, including: Calculate the first and third quartiles of the time confidence level for all uniform security objects in the same batch; When the time credibility of the current unified security object is lower than the first quartile, the current unified security object is determined as the lowest storage level and written into the security area to be verified, so that the security area to be verified can only perform append, verification and causal repair operations. When the time credibility of the current unified security object is greater than or equal to the first quartile and lower than the third quartile, the current unified security object is determined to be of medium storage level and written to the controlled archive area so that the controlled archive area allows audit queries and controlled access operations to be performed. When the time credibility of the current unified security object is greater than or equal to the third quartile, the current unified security object is determined as the highest storage level and written into the immutable archive area as the final evidence object.

9. A cloud computing-based big data information security protection and storage system, used to execute the cloud computing-based big data information security protection and storage method according to any one of claims 1-8, characterized in that, include: The original sequence construction module is used to extract the original timestamps, local monotonic counts, time base states, main influence sector identifiers, and current environmental phase quantities of the events to be processed generated by edge nodes, and construct the original event sequence. The initial time generation module is used to establish a causal edge set based on the order of occurrence of events to be processed, and input the original timestamp, local monotonic count value, time base state, main influence sector identifier and current environmental phase quantity into the particle swarm algorithm model to generate the initial reliable time of the events to be processed. The logical time reconstruction module is used to apply a monotonically increasing constraint to the initial trusted time, reconstruct the final trusted logical time of the event to be processed, and calculate the corresponding time trustworthiness based on the violation cases of the final trusted logical time in the causal edge set. The data security encapsulation module is used to embed the final trusted logical time and time trustworthiness into the hash link and key derivation process, to securely encapsulate the data payload corresponding to the event to be processed, and to generate a unified security object. The hierarchical security storage module is used to statistically analyze the time reliability of the same batch of unified security objects, determine the storage level of the unified security objects based on the statistically obtained distribution interval, and write the unified security objects into the hierarchical security storage area of ​​the corresponding storage level on the cloud platform side.