An electronic archive standardization packaging method and system based on space-time semantic fusion

CN122614788BActive Publication Date: 2026-09-15NANJING JIYANG WISDOM INFORMATION TECH RES INST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202611072769.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-07-20
Publication Date
2026-09-15
Estimated Expiration
2046-07-20

AI Technical Summary

Technical Problem

[0007]本发明的一个目的在于提出一种基于时空语义融合的电子档案标准化封装方法,针对现有技术在多源连续时空数据归档中缺乏标准化封装与自动合规校验机制、难以形成可审计证据链且难以实现流式数据到封装件的秒级转换的问题,提出了对多源连续时空数据流进行时间基准统一、空间坐标基准统一与格式规范化后按归档时间窗切分并融合生成时空语义元数据集,采用Sketch流式近似摘要生成封装预描述信息,基于密码学哈希构建可增量更新的Merkle哈希树输出根哈希与认证路径固化,并将固化信息代入合规规则库生成的可满足性模理论约束求解以输出合规校验报告,结合确定性编码、电子签名、可信时间戳与锚定存证生成封装件的技术方案,本发明具备秒级封装转换、合规自动校验、封装结果可验证可追溯且可审计的技术效果

Benefits of technology

1、实现连续时空数据的秒级归档封装转换:通过归档时间窗切分、多源时空语义元数据融合以及基于Sketch的流式近似摘要计算,使数据在产生过程中即可形成封装预描述信息,减少先落盘汇总再封装的批处理依赖,提升全链路归档时效性与连续性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122614788B_ABST
    Figure CN122614788B_ABST
Patent Text Reader

Abstract

The application discloses a kind of based on spatiotemporal semantic fusion electronic archives standardization packaging method, to solve the problems such as lack of standardization packaging and compliance check of multi-source continuous spatiotemporal data archiving, evidence chain is difficult to audit and difficult to second-level conversion, the application generates spatiotemporal semantic metadata set by time reference unification and space coordinate reference unification after cutting and fusing according to archiving time window, generates pre-description information using Sketch computing streaming approximate summary, constructs the root hash and authentication path solidification of incremental update Merkle hash tree output based on cryptography hash, and generates compliance check report using satisfiability modulo theories solver, realizes the technical effects such as second-level packaging conversion, compliance automatic check and the generation of verifiable and traceable package by combining deterministic encoding, electronic signature, trusted timestamp and anchoring evidence.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of electronic records management, and in particular to a standardized packaging method and system for electronic records based on spatiotemporal semantic fusion. Background Technology

[0002] Faced with the continuous generation of multi-source spatiotemporal data with timestamps and spatial locations, current technologies typically involve collecting and storing this data in a streaming manner on a business platform, then exporting it as files or batch datasets within a certain period. This is followed by the generation of directories and metadata, and the use of cryptographic hashing, electronic signatures, trusted timestamps, and blockchain notarization for integrity protection and post-event traceability. Simultaneously, to meet regulatory requirements, electronic record management systems are gradually introducing mechanisms such as encapsulation structures, metadata templates, format validation, and manual review to facilitate the archiving conversion of electronic documents into electronic record packages.

[0003] However, in archiving scenarios for continuous streaming spatiotemporal data such as low-altitude monitoring, existing technologies still have the following shortcomings: 1. The lack of automated standard encapsulation and compliance verification mechanisms means that the integrity, consistency, and traceability of metadata items often rely on manual configuration or post-event sampling, making it difficult to reliably prove authenticity, integrity, usability, and security.

[0004] 2. Multi-source continuous data usually needs to be aggregated and stored on disk before being packaged. The packaging and verification process is mainly batch-processed, which makes it difficult to achieve the second-level conversion of streaming data to electronic originals or electronic archive packages, resulting in limited timeliness and compliance rate of the entire archiving process.

[0005] 3. Existing integrity proofs mostly rely on file-level hashes or single-point signature timestamps, lacking auditable, recalculated, and segmented verification of evidence chain organization methods. They also lack the ability to locate and trace tampering across time windows and data segments, and the encapsulated results are difficult to form evidence that meets the requirements of judicial or regulatory audits.

[0006] Therefore, a standardized packaging method and system for electronic archives that can overcome the shortcomings of the existing technology is a problem that needs to be solved by those skilled in the art. Summary of the Invention

[0007] One objective of this invention is to propose a standardized encapsulation method for electronic archives based on spatiotemporal semantic fusion. Addressing the shortcomings of existing technologies in archiving multi-source continuous spatiotemporal data—namely, the lack of standardized encapsulation and automatic compliance verification mechanisms, the difficulty in forming auditable evidence chains, and the challenge of achieving second-level conversion from streaming data to encapsulated components—this invention proposes a method that unifies the time and spatial coordinate references and standardizes the format of multi-source continuous spatiotemporal data streams. The data is then segmented and fused according to the archiving time window to generate a spatiotemporal semantic metadata dataset. A Sketch streaming approximate digest is used to generate pre-description information for the encapsulation. A Merkle hash tree with incremental updates is constructed based on cryptographic hashing to output the root hash and authentication path. This solidified information is then substituted into the satisfiability modulo theory constraints generated by the compliance rule base to output a compliance verification report. Combining deterministic coding, electronic signatures, trusted timestamps, and anchored evidence storage to generate encapsulated components, this invention achieves the technical effects of second-level encapsulation conversion, automatic compliance verification, and verifiable, traceable, and auditable encapsulation results.

[0008] This invention provides a standardized packaging method for electronic archives based on spatiotemporal semantic fusion, comprising: S1. Acquire multi-source continuous spatiotemporal data streams generated by low-altitude monitoring scenarios, perform archiving preprocessing, and divide the multi-source continuous spatiotemporal data streams into at least one spatiotemporal data segment according to a preset archiving time window. Extract metadata for each spatiotemporal data segment and perform fusion processing based on time correlation and spatial correlation to generate a spatiotemporal semantic metadata dataset. S2. Perform Sketch-based streaming approximate summary calculation on each spatiotemporal data segment to obtain the streaming approximate summary corresponding to each spatiotemporal data segment. Generate encapsulated pre-description information based on the spatiotemporal semantic meta-dataset, each spatiotemporal data segment and each streaming approximate summary. S3. Calculate the cryptographic hash value for each spatiotemporal data segment in the encapsulated pre-description information, construct an incrementally updatable Merkle hash tree with each cryptographic hash value as the leaf node, output the root hash at the end of the archiving time window, and generate an authentication path for each spatiotemporal data segment to verify the root hash, thus forming solidified encapsulated pre-description information. S4. Generate a set of compliance constraints based on the preset compliance rule base, substitute the solidified encapsulated pre-description information into the set of compliance constraints, call the satisfiability modular theory solver to solve the problem, and obtain a compliance verification report. S5. Construct the encapsulated data to be signed based on the solidified encapsulation pre-description information and compliance verification report. Calculate the digest to be signed after deterministically encoding the encapsulated data to be signed. S6. Perform electronic signature calculation on the digest to be signed to obtain the signature value, apply for a trusted timestamp on the signature value to obtain a timestamp token, write the signature value and timestamp token into the data to be signed and encapsulate it to generate signed and encapsulated data. S7. Calculate the evidence digest for the signed and packaged data, submit it to the tamper-proof evidence storage system for anchored evidence storage to obtain evidence storage receipt, and write it into the signed and packaged data to generate a standardized packaged electronic archive.

[0009] Optionally, S1 includes: The multi-source continuous spatiotemporal data stream is acquired, and the timestamps of each data source in the multi-source continuous spatiotemporal data stream are time-aligned to the same time base. The spatial location information of each data source in the multi-source continuous spatiotemporal data stream is unified into a single spatial coordinate reference through spatial reference unification processing. The multi-source continuous spatiotemporal data stream is subjected to normalization processing based on a preset data format; According to a preset archiving time window, the multi-source continuous spatiotemporal data stream after completing the time alignment processing, the spatial reference unification processing, and the normalization processing is segmented to obtain at least one spatiotemporal data segment. For each spatiotemporal data segment, time information, spatial location information, acquisition device information, and business event information are extracted, and the business event information is fused based on time correlation and spatial correlation to generate the spatiotemporal semantic metadata dataset.

[0010] Optionally, S2 includes: For each spatiotemporal data segment, the segment content of the spatiotemporal data segment is parsed into multiple data units according to a preset granularity; A fixed-length counting array is initialized for the spatiotemporal data segment, and multiple preset hash functions are selected; For each data unit, the multiple sets of hash functions are input to obtain multiple hash values. The update position in the counting array is determined according to each hash value. The count value corresponding to the update position is cumulatively updated until the fragment content processing of the spatiotemporal data segment within the archiving time window is completed, and the streaming approximate digest corresponding to the spatiotemporal data segment is obtained. The streaming approximate digest is the updated counting array. Within the archiving time window, the count array corresponding to each of the spatiotemporal data segments is continuously updated to form streaming processing; Based on the spatiotemporal semantic metadata, each spatiotemporal data segment, and each streaming approximate summary, encapsulation pre-description information is generated. The encapsulation pre-description information includes segment identification information, archive time window identification information, the spatiotemporal semantic metadata, and the streaming approximate summary corresponding to each spatiotemporal data segment.

[0011] Optionally, S3 includes: Read the encapsulation pre-description information and determine the leaf node order of each spatiotemporal data segment according to the segment identification information of the spatiotemporal data segment; For each of the aforementioned spatiotemporal data segments, a preset cryptographic hash algorithm is used to calculate the cryptographic hash value corresponding to the spatiotemporal data segment based on the segment content of the spatiotemporal data segment; Using each of the cryptographic hash values ​​as leaf nodes, an incrementally updatable Merkle hash tree is constructed. When a new spatiotemporal data segment is received within the archive time window, the cryptographic hash value corresponding to the new spatiotemporal data segment is written into the Merkle hash tree in the order of the leaf nodes, and the hash values ​​of intermediate nodes are updated layer by layer from the corresponding leaf nodes upwards until the root node is updated. At the end of the archiving time window, output the root hash corresponding to the Merkle hash tree; For each spatiotemporal data segment, an authentication path for verifying the root hash is generated based on the Merkle hash tree. The authentication path includes the hash values ​​of each level of sibling nodes from the leaf node corresponding to the spatiotemporal data segment to the root node, as well as the node position identification information corresponding to the hash values ​​of each level of sibling nodes. The output includes the root hash and the authentication path of the solidified encapsulated pre-description information.

[0012] Optionally, S4 includes: Read the rule entries corresponding to the authenticity requirements, integrity requirements, availability requirements, security requirements and traceability requirements from the preset compliance rule base, and convert each rule entry into a satisfiability modular theory constraint expression to generate a compliance constraint set, wherein each rule entry includes a constraint type identifier, a constraint action field identifier and a constraint condition; The solidified encapsulated pre-description information is parsed into a set of fields to be verified. The set of fields to be verified includes the spatiotemporal semantic meta-dataset, the streaming approximate digest, the root hash, and the authentication path. A variable mapping relationship consistent with the satisfiability modular theory constraint expression is established for each field in the set of fields to be verified. Substitute the field values ​​from the set of fields to be verified into the variable mapping relationship to form the solution input of the satisfiability modular theory solver. The satisfiability modular theory solver is invoked to solve the input and obtain compliance conclusions. Based on the solution results, the identification information of constraint violations is located. When the compliance conclusion indicates that there is a violation of constraints, a list of metadata items to be supplemented is determined based on the identification information of the violation of constraints; The compliance conclusion, the identification information of the violation of constraints, and the list of metadata items to be supplemented are combined to generate a compliance verification report; Furthermore, the rule entries in the compliance rule base carry rule version identifiers and effective time information. When generating the compliance constraint set, the rule version identifiers are written into the compliance verification report, and the intermediate results of the previous time window are reused for multiple consecutive archive time windows to perform incremental solving.

[0013] Optionally, S5 includes: Read the compliance verification report and obtain the spatiotemporal data fragment, the spatiotemporal semantic metadata, the streaming approximate digest, the root hash, and the authentication path from the solidified encapsulated pre-description information; The spatiotemporal data fragment, the spatiotemporal semantic metadata dataset, the streaming approximate digest, the root hash, the authentication path, and the compliance verification report are arranged in a preset encapsulation field order to form encapsulated data to be signed. Perform deterministic encoding processing on the data to be signed, wherein the deterministic encoding processing includes serializing the field names, field values ​​and field order in the data to be signed according to a preset character encoding to generate an encoding result; The cryptographic hash of the encoded result is calculated to obtain the digest to be signed.

[0014] Optionally, S6 includes: Read the encapsulated data to be signed and the digest to be signed; Based on a preset signature key, an electronic signature calculation is performed on the digest to be signed to generate a signature value, and the signature value is associated with the digest to be signed and stored in the encapsulated data to be signed; The signature value is sent to a trusted timestamp service to request a trusted timestamp, and a timestamp token returned by the trusted timestamp service is received. The timestamp token includes timestamp information and verification information corresponding to the signature value. The timestamp token is written into the unsigned encapsulated data to generate signed encapsulated data.

[0015] Optionally, S7 includes: Read the signed and encapsulated data, and calculate the evidence digest from the signed and encapsulated data using a preset digest algorithm; The evidence summary, together with the package identification information used to identify the signed and packaged data, shall be submitted to the tamper-proof evidence storage system. Receive the evidence storage receipt returned by the tamper-proof evidence storage system. The evidence storage receipt includes the evidence storage summary, evidence storage time information, and verification information for verifying that the evidence storage summary has been successfully anchored for evidence storage. The evidence receipt is written into the signed and packaged data to generate a standardized packaged electronic file.

[0016] On the other hand, the present invention also provides a standardized packaging system for electronic archives based on spatiotemporal semantic fusion, comprising: The data acquisition and preprocessing module is used to acquire multi-source continuous spatiotemporal data streams generated by low-altitude monitoring scenarios, perform archiving preprocessing, and segment the data into at least one spatiotemporal data segment according to a preset archiving time window. The spatiotemporal semantic fusion module is used to extract metadata from each spatiotemporal data segment and perform fusion processing based on time and spatial correlation to generate a spatiotemporal semantic metadata dataset. The streaming pre-encapsulation module is used to perform streaming approximate digest calculation based on Sketch on each spatiotemporal data segment to obtain a streaming approximate digest, and generate encapsulation pre-description information based on the spatiotemporal semantic metadata dataset, each spatiotemporal data segment, and each streaming approximate digest. The Merkle hardening module is used to calculate the cryptographic hash value of each spatiotemporal data segment and construct an incrementally updatable Merkle hash tree, which is then processed within the archiving time window. The module outputs a root hash and generates authentication paths for each spatiotemporal data fragment to form a solidified encapsulated pre-description information. The compliance verification module generates a set of compliance constraints based on a preset compliance rule base, substitutes the solidified encapsulated pre-description information, and calls a satisfiability modulus solver to obtain a compliance verification report. The signature encapsulation module constructs the encapsulated data to be signed based on the solidified encapsulated pre-description information and the compliance verification report, deterministically encodes it, calculates the digest to be signed, electronically signs the digest, applies a trusted timestamp, and writes the signature value and timestamp token to generate signed encapsulated data. The anchoring and evidence storage module calculates the evidence storage digest for the signed encapsulated data and submits it to an immutable evidence storage system for anchoring and evidence storage, obtains an evidence storage receipt, and writes it to generate a standardized electronic archive encapsulation.

[0017] The beneficial effects of this invention are: 1. Achieve second-level archiving and encapsulation transformation of continuous spatiotemporal data: By segmenting the archiving time window, fusing multi-source spatiotemporal semantic metadata, and performing streaming approximate summary calculation based on Sketch, the data can form encapsulated pre-description information during the generation process, reducing the batch processing dependency of first storing and summarizing on disk and then encapsulating, and improving the timeliness and continuity of the entire archiving chain.

[0018] 2. Form a verifiable, locatable, and auditable chain of integrity and traceability evidence: Calculate cryptographic hashes on data fragments and construct incrementally updatable Merkle hash trees, outputting root hashes and authentication paths, enabling any fragment to be independently recalculated and verified and supporting tamper location, thereby enhancing the integrity proof capability and traceability of the packaged components.

[0019] 3. Enhance the automation and interpretability of archiving compliance: Convert the compliance rule base into satisfiability model theoretical constraints and call the solver to generate compliance verification reports. It can automatically provide compliance conclusions, violation constraint identifiers, and a list of metadata items to be supplemented. Combine deterministic coding, electronic signatures, trusted timestamps, and anchored evidence to improve authenticity, security, and reliability as audit evidence. Attached Figure Description

[0020] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings: Figure 1 This is a flowchart of a standardized packaging method for electronic archives based on spatiotemporal semantic fusion proposed in this invention. Detailed Implementation

[0021] The present invention will now be described in further detail with reference to the accompanying drawings. These drawings are simplified schematic diagrams, illustrating only the basic structure of the invention, and therefore only show the components relevant to the invention.

[0022] refer to Figure 1 A standardized packaging method for electronic archives based on spatiotemporal semantic fusion includes: S1. Acquire multi-source continuous spatiotemporal data streams generated by low-altitude monitoring scenarios, perform archiving preprocessing, and divide the multi-source continuous spatiotemporal data streams into at least one spatiotemporal data segment according to a preset archiving time window. Extract metadata for each spatiotemporal data segment and perform fusion processing based on time correlation and spatial correlation to generate a spatiotemporal semantic metadata dataset. S2. Perform Sketch-based streaming approximate summary calculation on each spatiotemporal data segment to obtain the streaming approximate summary corresponding to each spatiotemporal data segment. Generate encapsulated pre-description information based on the spatiotemporal semantic meta-dataset, each spatiotemporal data segment and each streaming approximate summary. S3. Calculate the cryptographic hash value for each spatiotemporal data segment in the encapsulated pre-description information, construct an incrementally updatable Merkle hash tree with each cryptographic hash value as the leaf node, output the root hash at the end of the archiving time window, and generate an authentication path for each spatiotemporal data segment to verify the root hash, thus forming solidified encapsulated pre-description information. S4. Generate a set of compliance constraints based on the preset compliance rule base, substitute the solidified encapsulated pre-description information into the set of compliance constraints, call the satisfiability modular theory solver to solve the problem, and obtain a compliance verification report. S5. Construct the encapsulated data to be signed based on the solidified encapsulation pre-description information and compliance verification report. Calculate the digest to be signed after deterministically encoding the encapsulated data to be signed. S6. Perform electronic signature calculation on the digest to be signed to obtain the signature value, apply for a trusted timestamp on the signature value to obtain a timestamp token, write the signature value and timestamp token into the data to be signed and encapsulate it to generate signed and encapsulated data. S7. Calculate the evidence digest for the signed and packaged data, submit it to the tamper-proof evidence storage system for anchored evidence storage to obtain evidence storage receipt, and write it into the signed and packaged data to generate a standardized packaged electronic archive.

[0023] In this specific embodiment, S1 includes: The system acquires multi-source continuous spatiotemporal data streams through a unified message bus connected to low-altitude monitoring services. These data streams consist of radar track data sources, ADS-B track data sources, and photoelectric target detection data sources, with each data record carrying at least a data source identifier. Local timestamp of data source Spatial location information field and data acquisition device identifier; The system uses the UTC reference clock provided by the IEEE 1588-2008 Precision Time Protocol as a unified time base, and applies this to each data source. Establish a time alignment model to uniformly convert its local timestamps to reference timestamps. The conversion relationship is as follows: ; in, This represents a reference timestamp after being unified to the UTC reference clock, measured in microseconds. Indicates data source The output local timestamp is measured in microseconds. Indicates data source The clock drift coefficient, Indicates data source Clock offset relative to the UTC reference clock Indicates the data source identifier; The system collects time synchronization data once at the start and end of each archiving time window. and ,in and These represent the data sources during the two data collection sessions, respectively. Local timestamp, and These represent the corresponding UTC reference timestamps, and are obtained based on the two sets of synchronization pairs. and Then, time alignment is performed on all records of the data source within the archive time window; The system unifies the spatial coordinate reference to the WGS-84 geodetic coordinate system and standardizes spatial location information into triplets. ,in Indicates latitude, Indicates longitude. To represent the ellipsoidal height, the system first converts non-WGS-84 output data records to WGS-84 geodetic coordinates according to the equipment installation calibration parameters. The calibration parameters include the coordinates of the fixed installation point and attitude angle of the acquisition device under WGS-84, which are stored in the device information table. The WGS-84 ellipsoid parameters are taken as the semi-major axis. Meter and flatness To ensure consistency in coordinate transformation; The system then performs normalization processing on the multi-source continuous spatiotemporal data stream using a preset data format. The normalization processing serializes each data record into a unified record structure and fixes the field order. The unified record structure includes at least a fragment identification information field, a data source identification field, a reference timestamp field, a WGS-84 spatial location information field, a data acquisition device information field, and a business event information field. The business event information field includes at least an event type code, a target identifier, and an event confidence level. The system sets the archiving time window to a fixed-length, non-overlapping time window, with the time window length set to... The system uses seconds and aligns the time window to the UTC whole minute boundary as the starting point, and uses the reference timestamp of each record as the reference time stamp. Data within the archived time window is written into the same spatiotemporal data segment, and segment identification information is generated for that segment. The segment identification information consists of the archived time window identification information and the data source identification information. The fragments are spliced ​​together to ensure their uniqueness. For each spatiotemporal data segment, the system extracts time information as the minimum and maximum reference timestamps within that segment to form a time range, and extracts spatial location information as the data within that segment. The range of values ​​is defined and a spatial range is formed. The information of the acquisition equipment is extracted as the equipment model, equipment serial number, installation point coordinates and attitude angle corresponding to the acquisition equipment identifier in the equipment information table. The information of the business events is extracted as all event type codes, target identifiers and event confidence levels in the segment. Within the same archive time window, the system performs business event fusion processing based on time and spatial correlation. The time correlation is determined by the difference between the reference timestamps of two records being no more than 2 seconds, which is used as the criterion for determining whether the two records are candidates for the same event. The spatial correlation is determined by the geodetic distance between two records on the WGS-84 ellipsoid being no more than 50 meters and the elevation difference between the two ellipsoids being no more than 30 meters, which is used as the criterion for determining whether the two records are candidates for the same event. The system aggregates cross-data source candidate records that meet the above time and spatial correlation requirements according to the target identifier to generate fusion events. The system writes the event time range, fusion spatial location, participating data source set, participating acquisition device set, and fusion confidence of the fusion events into the spatiotemporal semantic metadata dataset. The spatiotemporal semantic metadata dataset is organized with the archive time window identifier information as the index and associated with each corresponding spatiotemporal data segment for subsequent encapsulation and pre-description information generation.

[0024] In this specific embodiment, S2 includes: The system establishes a Sketch status for each spatiotemporal data segment, which corresponds one-to-one with its segment identifier information, and continuously updates it within the archiving time window; The content of the spatiotemporal data segment is formed by sequentially appending the unified record structure in step S1. The system parses the segment content into multiple data units with "single unified record" as the preset granularity. ,in Indicates the first Each data unit is a byte string, which is obtained by serializing the fields of a unified record structure in a fixed field order and used as input to Sketch. The serialization rules are as follows: field names are encoded in UTF-8, numeric fields are represented in IEEE 754 binary and use big-endian byte order, and string fields are encoded in UTF-8 and bounded by a length prefix, thereby ensuring that the same unified record structure is calculated consistently across different nodes. ; The system implements Sketch as Count-MinSketch and initializes a fixed-length count array for each spatiotemporal data segment. ,in It is a one-dimensional array with length . The array elements are unsigned 32-bit integer counters, all initialized to 0; System selection Group hash function And perform multi-hash location update for each data unit, where Indicates the hash function number and The hash function The SipHash-2-4 message authentication hash is used with a built-in 128-bit key. As the hash key and As a domain separator, it is concatenated into the data unit. The final input is used to form four independent sets of mappings; For each data unit The rules for calculating the location index and performing cumulative updates are as follows: ; in, Representing data unit In the Group hash function downmapped to count array The update position index and the value range is 0 to Indicates a byte string Hash function The calculated 64-bit unsigned integer hash output, This represents the modulo operation. Represents a counting array Length, Represents a counting array In the index The count value at that location, This indicates an in-place update of the count value. This represents the maximum saturation value for an unsigned 32-bit integer to avoid count overflow. This indicates that the smaller of the two values ​​is taken to achieve saturation accumulation; The system uses a counter array for each spatiotemporal data segment within the archive time window. Incremental cumulative updates are maintained and executed synchronously with the appending of fragment content, so that a streaming approximate digest of the fragment can be obtained before the archiving time window ends. The streaming approximate digest is defined as the count array corresponding to the current time of the archiving time window. A snapshot is taken and then solidified into a final snapshot at the end of the time window; The system aggregates the final snapshots of each spatiotemporal data segment within the same archiving time window and combines them with the spatiotemporal semantic metadata dataset to generate encapsulated pre-description information. This encapsulated pre-description information is a structured data object containing archiving time window identifier information, segment identifier information for each spatiotemporal data segment, a streaming approximate summary field corresponding one-to-one with the segment identifier information, and a spatiotemporal semantic metadata dataset field corresponding one-to-one with the archiving time window identifier information. The streaming approximate summary field carries a counting array using a fixed-length binary sequence. All count values ​​and indexed from 0 to Sequential writing ensures consistency in subsequent processing when recalculating the Sketch state.

[0025] In this specific embodiment, S3 includes: The system reads the encapsulation pre-description information at the end of the archiving time window and determines the scope of this solidification operation based on the archiving time window identifier information therein. Then, it determines the leaf node order of the Merkle hash tree according to the fragment identifier information of each spatiotemporal data fragment. The leaf node order adopts the order after sorting the fragment identifier information in lexicographical ascending order to ensure that different computing nodes obtain consistent leaf arrangement under the same encapsulation pre-description information input. The system performs cryptographic hash calculation on the content of each spatiotemporal data segment to obtain a cryptographic hash value, and writes the cryptographic hash value as the corresponding leaf node into an incrementally updatable Merkle hash tree. The content of the segment is a unified record structure sequence of the segment formed in step S1 and continuously appended in step S2. When calculating the cryptographic hash value, the original byte sequence of the segment content is directly used as input to avoid encoding differences. The system uses SHA-256 as the default cryptographic hash algorithm and organizes node hashes using a binary Merkle structure. The node calculation rules are as follows: ; in, This indicates the SHA-256 hash function with an output length of 256 bits. This indicates the order of the leaf nodes. A sequence of bytes containing the contents of a spatiotemporal data segment. Indicates by The calculated first The hash value of each leaf node. This represents the Merkle hash tree. Layer The node hash value of each node and Corresponding leaf layer and satisfying and They represent The corresponding left and right child node indices at the next level. This means concatenating the hash byte string of the left child node and the hash byte string of the right child node in order to obtain the input byte string of the parent node; The system implements incremental updates by "appending leaves and updating layer by layer". When a new spatiotemporal data fragment is received within the archive time window, the system first inserts it into a specific position in the leaf node order based on the fragment identifier information and calculates its leaf node hash value. Then, along the path from the leaf layer to the root layer, the hash values ​​of the affected intermediate nodes are recalculated layer by layer until the root node is reached; When a right child node is missing when calculating the parent node at a certain layer, the system will take the hash of the right child node to be the same as the hash of the left child node to complete the deterministic calculation of the parent node, thereby ensuring that the calculation rule of the root hash is unique under any number of leaves. The system outputs the root hash of the Merkle hash tree at the end of the archiving time window. ,in Defined as the node hash value of the highest-level and unique node, and... Write the root hash field of the solidified encapsulation pre-description information; The system then generates a root hash for each spatiotemporal data segment to verify the hash. The authentication path records the hash value of the sibling node and the node position identifier information of the fragment at each layer, from the leaf layer to the root layer. The node position identifier information takes the value L or R, which respectively indicates that the recorded sibling node is the left sibling or the right sibling at that layer. The system binds and stores the authentication path of each fragment with the fragment identifier information and writes it into the authentication path field of the solidified encapsulated pre-description information, thereby outputting a value containing the root hash. And the pre-description information of the solidified packaging for each certification path.

[0026] In this specific embodiment, S4 includes: At the end of the archiving time window, the system reads the solidified encapsulated pre-description information and parses it into a set of fields to be verified. This set of fields includes the archiving time window identifier, fragment identifiers for each spatiotemporal data segment, a spatiotemporal semantic metadata set, approximate summaries for each streaming data segment, the root hash, and each authentication path. The root hash is denoted as... This represents the 256-bit root hash value output by SHA-256 and originates from the root hash field of the pre-description information. The system reads rule entries from the compliance rule base and forms a rule index table, with each rule entry carrying a rule identifier. Constraint type identifier Constraint Field Identifier Constraint condition (cond), rule version identifier Effective date information ,in A unique identifier string representing a rule entry. A classification identifier indicating a value that falls under one of the requirements of authenticity, integrity, availability, security, and traceability. This represents the field identifier string in the set of fields to be validated. This represents a Boolean decision condition consisting of an operator and a threshold or an enumerated set. This represents the version number of the rule entry and is a monotonically increasing integer. The UTC reference timestamp indicating when the rule entry takes effect is measured in microseconds. The system reads the end reference timestamp of the current archive time window. ,in This refers to the UTC reference timestamp used to identify the end time of the archive time window after time alignment in step S1. The system only selects those that meet the requirements. The rule entries are designated as the effective rule entries for this time window, and the effective rule entries are identified by the rule identifier. Retrieve version number after deduplication The largest entry is designated as the final rule entry; The system converts the final rule entries into satisfiability modular theory constraint expressions to generate a set of compliance constraints, and establishes variable mapping relationships for the set of fields to be verified. These variable mapping relationships identify each field. Mapped to a unique SMT variable with a fixed theoretical type, where reference timestamp fields are mapped to integer types in microseconds, and spatial range fields are mapped to integer types in microseconds. Latitude and longitude are stored in degrees as the quantization unit, and ellipsoidal height is stored in centimeters as the quantization unit. Hash fields are mapped to a fixed-length bit vector type and the root hash is... Mapped to The streaming approximate summary field is mapped to a length of An unsigned 32-bit integer array where the value of each element is limited to a range of 1. The authentication path field is mapped to a sequence consisting of sibling node hashes and node location identifiers, and the path length is additionally extracted as an integer field for constraint verification. The system identifies based on the constraint type. Constraints These are compiled into existence constraints, value range constraints, set membership constraints, length constraints, and cross-field consistency constraints, respectively. The cross-field consistency constraints include consistency constraints between fragment identifier information and archive time window identifier information, value range constraints for authentication path node location identifier information, and root hash constraints. For bit-width constraints, the system writes the above compilation results into the solution input using SMT-LIBv2 syntax and calls the satisfiability modular theory solver Z3 4.12.2 to solve the problem; For ease of description, the system will denote the set of compliance constraints as... Let the set of field assignment assertions formed by substituting the values ​​of the set of fields to be verified into the variable mapping relationship be denoted as . And the solver's input is denoted as in, This represents the overall logical formula submitted to the satisfiability modular theory solver. Let represent the set of compliance constraints derived from the final rule entries, and be the set of conjunctions of a Boolean formula. This represents the set of equation assignment assertions for SMT variables based on the field values ​​obtained from parsing the pre-description information of the solidified package, and is also the set of conjunctive terms of a Boolean formula. The logical AND operation is used to... and Conjunction; During the solution process, the system binds a traceable hypothesis literal to each final rule entry and enables a non-satisfied core return mechanism. When the solution result is unsatisfied, the system reads the non-satisfied core and maps it back to the rule identifier that violates the constraint. Constraint Action Field Identifier and based on the constraint type identifier Constraint Action Field Identifier Generate a list of metadata items to be supplemented, the list of metadata items to be supplemented being identified by fields. The entry includes the location path of the field within the encapsulated pre-description information to support autocomplete and manual review; The system will identify compliance conclusions and rules that violate constraints. Field identifiers that violate constraints List of metadata items to be supplemented, rule version identifier (ver) and effective time information of the final rule entries. Both should be included in the compliance verification report; When the system performs incremental solving over multiple consecutive archive time windows, it reuses intermediate results from the previous time window. Specifically, it maintains the same Z3 solver instance in memory and updates the variable declarations and compliance constraint sets. As a persistent context, when processing the next archiving time window, a new set of field assignment assertions is pushed to the solver instance only through the incremental interface. It then triggers a solution process, and upon obtaining a compliance conclusion or a conclusion that the core requirement is not met, immediately pops up the set of field assignment assertions. To return to only contain The persistent context allows for the reuse of learned clauses and simplification results within the solver to achieve incremental solving across time windows when the set of rule entries remains unchanged. Furthermore, it enables solving when the final set of rule entries is affected by changes in the rule version identifier (ver) or effective time information. When changes occur and updates are made, the persistent context is rebuilt and the updated rule version identifier is written into the new compliance verification report to ensure the traceability of the verification basis.

[0027] In this specific embodiment, S5 includes: The system reads the compliance verification report and retrieves from the solidified encapsulated pre-description information each spatiotemporal data fragment, spatiotemporal semantic meta-dataset, each streaming approximate digest, root hash, and each authentication path corresponding to the same archive time window identifier information; The system constructs the data to be signed according to the preset encapsulation field order. ,in The data is structured and the fields are ordered in a fixed order: package identifier, archive time window identifier, spatiotemporal semantic metadata, number of fragments, fragment detail list, root hash, and compliance verification report. The fragment detail list is arranged in the order of the leaf nodes determined in step S3, and each fragment detail contains fragment identifier, fragment content length, fragment content byte sequence, streaming approximate digest length, streaming approximate digest byte sequence, authentication path length, and authentication path entry sequence. The authentication path entry sequence is arranged in a hierarchical order from the leaf layer to the root layer, and each entry contains the sibling node hash value and node position identifier information. The system encapsulates data to be signed. Perform deterministic encoding to obtain the encoded result. The deterministic encoding employs a fixed TLV serialization rule and simultaneously encodes field names, field values, and field order. The TLV serialization rule is for... Each field is written in a 5-tuple of "field name length, field name, field type code, field value length, field value" in the field order. The field name is encoded in UTF-8 and is an unsigned 16-bit integer in big-endian byte order. The field type code is an unsigned 8-bit integer used to distinguish between integer, fixed-length byte string, variable-length byte string, and sequence types. The field value is an unsigned 32-bit integer in big-endian byte order. The encoding method of the field value is determined by the field type code. Integer fields are written in unsigned 64-bit big-endian encoding. Fixed-length byte string fields are directly written to their original byte sequence and their length is limited by the field value length. Variable-length byte string fields are written with the field value length first and then the byte sequence to ensure recalculation of boundaries. Sequence type fields are written with the number of elements first and then recursively written to their subfield TLV sequence in element order. Throughout the encoding process, no whitespace characters, optional fields, or key sorting are introduced. The encoding relies entirely on the preset encapsulation field order to ensure that the same input yields a unique result. ; The system encodes the results. Calculate the cryptographic hash to obtain the digest to be signed. The calculation relationship is as follows: ,in, This indicates a digest to be signed, which is a 256-bit byte string. This refers to the SHA-256 hash function. Indicates the data to be encapsulated for signature. The byte sequence obtained by performing deterministic encoding This indicates the packaged data to be signed, which consists of pre-description information of the solidified package and a compliance verification report in the order of preset packaged fields.

[0028] In this specific embodiment, S6 includes: The system reads the data to be signed and encapsulated. and the summary to be signed ,in This represents a structured data object composed of predefined encapsulated fields in a specific order. Indicates to The 256-bit byte string digest obtained by SHA-256 calculation after performing deterministic encoding; The system has a pre-installed electronic signature private key in the hardware security module. And solidify the corresponding public key. With key identifier ,in This refers to the private key Ed25519. Indicates and The paired Ed25519 public key, where `kid` represents the identifier string used to locate the key and certificate chain within the encapsulated data, and the system calls the Ed25519 signature algorithm to process the digest to be signed. Perform electronic signature calculation to obtain the signature value The calculation relationship is as follows: ; in, This represents the signature value and is a 64-byte string. Indicates the use of private key The algorithm process for performing Ed25519 signature operations. This indicates the Ed25519 private key stored in the hardware security module. Indicates a summary to be signed; The system writes the signature algorithm identifier alg as the string Ed25519, and sets alg, kid, pk, and Write the encapsulated data to be signed The signature information field in the code is used to form a "signature value associated with a digest to be signed", where alg is used to specify the signature verification algorithm. Used for subsequent third-party verification and validation, and written in 32-byte raw public key format. The system also writes the signature certificate chain field to carry the signature. The bound X.509 certificate chain byte sequence provides identity verifiability; the system verifies the signature value. Calculate signature verification digest And As a message imprint for a trusted timestamp request, Indicates to The byte sequence is a 256-bit byte string calculated using SHA-256. The system generates a timestamp request according to RFC3161 and sends it to a trusted timestamp service via HTTPS. The timestamp request always includes a hash algorithm identifier (SHA256) and a message imprint. Request random numbers and the certificate request flag certReq ,in This represents a 64-bit unsigned integer generated by the system-safe random number generator and kept unique in this request to prevent replay. The system receives a timestamp token returned by the trusted timestamp service. ,in It is an RFC3161 TimeStampToken binary structure and contains at least timestamp information. Token serial number Message Imprint Echo value, trusted timestamp service signature value and trusted timestamp service certificate ,in This represents the UTC time generated by the trusted timestamp service. This indicates the unique serial number of the token. This represents the signature value of the token content provided by the trusted timestamp service. Indicates that it is used for verification The certificate byte sequence; The system performs a certain procedure before writing. A consistency check is performed, and the token is only accepted after the check passes. This consistency check includes at least verifying that the token's status is granted and verifying the echoes within the token. Request a random number The message imprint echoed within the verification token is consistent with the locally calculated one. ,check can be Verification passed and Within its validity period; The system will use timestamp tokens Write the encapsulated data to be signed The timestamp information field is set to bind, and the timestamp binding object identifier is written as bind. To indicate Bound to signature value Generate signed and encapsulated data and It contains all fields used for recalculating signatures and verifying the validity of timestamps.

[0029] In this specific embodiment, S7 includes: The system reads signed and encapsulated data. ,in This indicates that the encapsulated data has been written with the signature value in the signature information field and the timestamp token in the timestamp information field; The system Perform deterministic encoding consistent with step S5 to obtain the encoding result. ,in This indicates that the serialization is performed according to the TLV serialization rules. The unique byte sequence obtained by serializing the field name, field value, and field order; The system encodes the results. Calculate the evidence summary The calculation relationship is as follows: ; in, This represents a proof digest and is a 256-bit string. This refers to the SHA-256 hash function. This indicates that the data has been signed and encapsulated. The deterministic encoded result byte sequence, This indicates that the data has been signed and encapsulated; The system generates the package identifier information PID and writes the PID to the package. The package identifier field contains a fixed-length 32-byte string, which is calculated by SHA-256 after concatenating the archive time window identifier information and the root hash field in a fixed order to ensure uniqueness within the same archive time window. The system calls the evidence submission interface of the tamper-proof evidence preservation system via HTTPS and submits an evidence preservation request. The evidence preservation request always includes encapsulation identifier information. Evidence summary The digest algorithm identifier sha256 and the submitter identifier sid, where sid is a submitter identity identifier string pre-registered in the tamper-proof evidence storage system; The tamper-proof evidence storage system will ( ) after receiving the evidence storage request. The record is written to its append-only immutable ledger and triggers the anchoring process, which aggregates the written record into the anchoring batch and generates an anchoring batch identifier. With anchored batch root summary ,in A unique identifier string generated by an immutable evidence storage system. To cover all of this anchoring batch according to The root digest is obtained by constructing a Merkle structure after lexicographical sorting and then calculating it using SHA-256. The system receives the evidence storage receipt returned by the tamper-proof evidence storage system. The evidence receipt Fixed information includes package identifier (PID) and evidence digest. Information on the time of evidence storage Anchored batch identifier (AID), Anchored batch root summary Used to Verified Anchoring verification information And the signature value of the receipt content in the tamper-proof evidence storage system. Rather than verifying certificates ,in This indicates that the immutable evidence storage system records the UTC timestamp of the evidence being written into the ledger. The authentication path sequence includes a sibling node hash value and node location identifier information for each entry, thus supporting independent third-party recalculation and verification. For an immutable evidence storage system The signature value is used to prove the origin of the receipt and that it has not been tampered with. For verification The certificate byte sequence; The system checks the evidence receipt before writing. Perform a consistency check and require the check to pass before accepting the receipt. The consistency check includes at least the following: within With local Consistency, Verification within Local Evidence Summary Consistency, Verification can be Verification passed and During its validity period, and based on With AP Perform a recalculation verification to confirm that the anchoring verification information is available; The system will verify the evidence receipt. Write The evidence receipt field will anchor the batch identifier. Write to anchor index fields to support subsequent retrieval and auditing, and generate standardized electronic archive packages.

[0030] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any equivalent substitutions or modifications made by those skilled in the art within the scope of the technology disclosed in the present invention, based on the technical solution and inventive concept of the present invention, should be covered within the scope of protection of the present invention.

[0031] This invention combines spatiotemporal semantic fusion, Sketch streaming pre-packaging, incrementally updatable Merkle solidification, compliance verification based on satisfiability modulus theory, and signature timestamps and anchored evidence storage in an orderly manner. This allows continuously generated multi-source spatiotemporal data to synchronously form encapsulated pre-description information within the archiving time window. At the end of the time window, a recalculated and verifiable root hash and authentication path are output to solidify integrity. Then, an interpretable compliance verification report is generated by solving compliance rule constraints. Finally, after deterministic encoding, electronic signatures, trusted timestamps, and tamper-proof evidence anchoring are completed. This simultaneously improves the timeliness of encapsulation conversion, the provability of archiving compliance, and the evidentiary capabilities of authenticity, integrity, usability, security, and traceability.

[0032] This invention addresses the technical challenges of continuous streaming archiving by making adaptive improvements to the algorithm structure: First, it adopts a two-layer digest structure of "approximate digest pre-encapsulation plus cryptographic solidification," enabling high-throughput streaming scenarios to first obtain a stable pre-description in a low-overhead manner, and then complete auditable solidification at the time window boundary using a Merkle tree, balancing second-level processing and evidence strength; Second, it structures the compliance rule base into a constraint set and establishes field variable mapping, so that compliance judgments are given by a recalculated solution process, while supporting the reuse of rule version identifiers and intermediate results across time windows to achieve incremental solution, thereby reducing the verification cost of continuous archiving and improving the end-to-end compliance rate and traceability.

Claims

1. A standardized packaging method for electronic archives based on spatiotemporal semantic fusion, characterized in that, include: S1. Acquire multi-source continuous spatiotemporal data streams generated by low-altitude monitoring scenarios, perform archiving preprocessing, and divide the multi-source continuous spatiotemporal data streams into at least one spatiotemporal data segment according to a preset archiving time window. Extract metadata for each spatiotemporal data segment and perform fusion processing based on time correlation and spatial correlation to generate a spatiotemporal semantic metadata dataset. S2. Perform Sketch-based streaming approximate summary calculation on each spatiotemporal data segment to obtain the streaming approximate summary corresponding to each spatiotemporal data segment. Generate encapsulated pre-description information based on the spatiotemporal semantic meta-dataset, each spatiotemporal data segment and each streaming approximate summary. S3. Calculate the cryptographic hash value for each spatiotemporal data segment in the encapsulated pre-description information, construct an incrementally updatable Merkle hash tree with each cryptographic hash value as the leaf node, output the root hash at the end of the archiving time window, and generate an authentication path for each spatiotemporal data segment to verify the root hash, thus forming solidified encapsulated pre-description information. S4. Generate a set of compliance constraints based on the preset compliance rule base, substitute the solidified encapsulated pre-description information into the set of compliance constraints, call the satisfiability modular theory solver to solve the problem, and obtain a compliance verification report. S5. Construct the encapsulated data to be signed based on the solidified encapsulation pre-description information and compliance verification report. Calculate the digest to be signed after deterministically encoding the encapsulated data to be signed. S6. Perform electronic signature calculation on the digest to be signed to obtain the signature value, apply for a trusted timestamp on the signature value to obtain a timestamp token, write the signature value and timestamp token into the data to be signed and encapsulate it to generate signed and encapsulated data. S7. Calculate the evidence digest for the signed and packaged data, submit it to the tamper-proof evidence storage system for anchored evidence storage to obtain evidence storage receipt, and write it into the signed and packaged data to generate a standardized packaged electronic archive.

2. The standardized packaging method for electronic archives based on spatiotemporal semantic fusion according to claim 1, characterized in that, S1 includes: The multi-source continuous spatiotemporal data stream is acquired, and the timestamps of each data source in the multi-source continuous spatiotemporal data stream are unified to the same time base for time alignment. The spatial location information of each data source in the multi-source continuous spatiotemporal data stream is unified into a single spatial coordinate reference through spatial reference unification processing. The multi-source continuous spatiotemporal data stream is subjected to normalization processing based on a preset data format; According to a preset archiving time window, the multi-source continuous spatiotemporal data stream after completing the time alignment processing, the spatial reference unification processing, and the normalization processing is segmented to obtain at least one spatiotemporal data segment. For each spatiotemporal data segment, time information, spatial location information, acquisition device information, and business event information are extracted, and the business event information is fused based on time correlation and spatial correlation to generate the spatiotemporal semantic metadata dataset.

3. The electronic archive standardization packaging method based on spatiotemporal semantic fusion according to claim 1, characterized in that, S2 include: For each spatiotemporal data segment, the segment content of the spatiotemporal data segment is parsed into multiple data units according to a preset granularity; A fixed-length counting array is initialized for the spatiotemporal data segment, and multiple preset hash functions are selected; For each data unit, the multiple sets of hash functions are input to obtain multiple hash values. The update position in the counting array is determined according to each hash value. The count value corresponding to the update position is cumulatively updated until the fragment content processing of the spatiotemporal data segment within the archiving time window is completed, and the streaming approximate digest corresponding to the spatiotemporal data segment is obtained. The streaming approximate digest is the updated counting array. Within the archiving time window, the count array corresponding to each of the spatiotemporal data segments is continuously updated to form streaming processing; Based on the spatiotemporal semantic metadata, each spatiotemporal data segment, and each streaming approximate summary, encapsulation pre-description information is generated. The encapsulation pre-description information includes segment identification information, archive time window identification information, the spatiotemporal semantic metadata, and the streaming approximate summary corresponding to each spatiotemporal data segment.

4. The standardized packaging method for electronic archives based on spatiotemporal semantic fusion according to claim 1, characterized in that, S3 includes: Read the encapsulation pre-description information and determine the leaf node order of each spatiotemporal data segment according to the segment identification information of the spatiotemporal data segment; For each of the aforementioned spatiotemporal data segments, a preset cryptographic hash algorithm is used to calculate the cryptographic hash value corresponding to the spatiotemporal data segment based on the segment content of the spatiotemporal data segment; Using each of the cryptographic hash values ​​as leaf nodes, an incrementally updatable Merkle hash tree is constructed. When a new spatiotemporal data segment is received within the archive time window, the cryptographic hash value corresponding to the new spatiotemporal data segment is written into the Merkle hash tree in the order of the leaf nodes, and the hash values ​​of intermediate nodes are updated layer by layer from the corresponding leaf nodes upwards until the root node is updated. At the end of the archiving time window, output the root hash corresponding to the Merkle hash tree; For each spatiotemporal data segment, an authentication path for verifying the root hash is generated based on the Merkle hash tree. The authentication path includes the hash values ​​of each level of sibling nodes from the leaf node corresponding to the spatiotemporal data segment to the root node, as well as the node position identification information corresponding to the hash values ​​of each level of sibling nodes. The output includes the root hash and the authentication path of the solidified encapsulated pre-description information.

5. The standardized packaging method for electronic archives based on spatiotemporal semantic fusion according to claim 1, characterized in that, S4 includes: Read the rule entries corresponding to the authenticity requirements, integrity requirements, availability requirements, security requirements and traceability requirements from the preset compliance rule base, and convert each rule entry into a satisfiability modular theory constraint expression to generate a compliance constraint set, wherein each rule entry includes a constraint type identifier, a constraint action field identifier and a constraint condition; The solidified encapsulated pre-description information is parsed into a set of fields to be verified. The set of fields to be verified includes the spatiotemporal semantic meta-dataset, the streaming approximate digest, the root hash, and the authentication path. A variable mapping relationship consistent with the satisfiability modular theory constraint expression is established for each field in the set of fields to be verified. Substitute the field values ​​from the set of fields to be verified into the variable mapping relationship to form the solution input of the satisfiability modular theory solver. The satisfiability modular theory solver is invoked to solve the input and obtain compliance conclusions. Based on the solution results, the identification information of constraint violations is located. When the compliance conclusion indicates that there is a violation of constraints, a list of metadata items to be supplemented is determined based on the identification information of the violation of constraints; The compliance conclusion, the identification information of the violation of constraints, and the list of metadata items to be supplemented are combined to generate a compliance verification report.

6. The standardized packaging method for electronic archives based on spatiotemporal semantic fusion according to claim 1, characterized in that, S5 include: Read the compliance verification report and obtain the spatiotemporal data fragment, the spatiotemporal semantic metadata, the streaming approximate digest, the root hash, and the authentication path from the solidified encapsulated pre-description information; The spatiotemporal data fragment, the spatiotemporal semantic metadata dataset, the streaming approximate digest, the root hash, the authentication path, and the compliance verification report are arranged in a preset encapsulation field order to form encapsulated data to be signed. Perform deterministic encoding processing on the data to be signed, wherein the deterministic encoding processing includes serializing the field names, field values ​​and field order in the data to be signed according to a preset character encoding to generate an encoding result; The cryptographic hash of the encoded result is calculated to obtain the digest to be signed.

7. The electronic archive standardization packaging method based on spatiotemporal semantic fusion according to claim 1, characterized in that, S6 include: Read the encapsulated data to be signed and the digest to be signed; Based on a preset signature key, an electronic signature calculation is performed on the digest to be signed to generate a signature value, and the signature value is associated with the digest to be signed and stored in the encapsulated data to be signed; The signature value is sent to a trusted timestamp service to request a trusted timestamp, and a timestamp token returned by the trusted timestamp service is received. The timestamp token includes timestamp information and verification information corresponding to the signature value. The timestamp token is written into the unsigned encapsulated data to generate signed encapsulated data.

8. The standardized packaging method for electronic archives based on spatiotemporal semantic fusion according to claim 1, characterized in that, S7 includes: Read the signed and encapsulated data, and calculate the evidence digest from the signed and encapsulated data using a preset digest algorithm; The evidence summary, together with the package identification information used to identify the signed and packaged data, shall be submitted to the tamper-proof evidence storage system. Receive the evidence storage receipt returned by the tamper-proof evidence storage system. The evidence storage receipt includes the evidence storage summary, evidence storage time information, and verification information for verifying that the evidence storage summary has been successfully anchored for evidence storage. The evidence receipt is written into the signed and packaged data to generate a standardized packaged electronic file.

9. A standardized packaging method for electronic archives based on spatiotemporal semantic fusion according to claim 5, characterized in that, The rule entries in the compliance rule base carry rule version identifiers and effective time information. When generating a compliance constraint set, the rule version identifiers are written into the compliance verification report, and the intermediate results of the previous time window are reused for multiple consecutive archive time windows to perform incremental solving.

10. A standardized packaging system for electronic archives based on spatiotemporal semantic fusion, used to execute the standardized packaging method for electronic archives based on spatiotemporal semantic fusion as described in any one of claims 1 to 9, characterized in that, include: The data acquisition and preprocessing module is used to acquire multi-source continuous spatiotemporal data streams generated in low-altitude monitoring scenarios, perform archiving preprocessing, and divide the data into at least one spatiotemporal data segment according to a preset archiving time window. The spatiotemporal semantic fusion module is used to extract metadata from each spatiotemporal data fragment and perform fusion processing based on time and spatial correlation to generate a spatiotemporal semantic metadata dataset. The streaming pre-encapsulation module is used to perform streaming approximate summary calculation based on Sketch on each spatiotemporal data segment to obtain streaming approximate summary, and generate encapsulation pre-description information based on the spatiotemporal semantic metadata dataset, each spatiotemporal data segment and each streaming approximate summary; The Merkle solidification module is used to calculate the cryptographic hash value of each spatiotemporal data fragment and build an incrementally updatable Merkle hash tree. It outputs the root hash at the end of the archiving time window and generates an authentication path for each spatiotemporal data fragment to form solidified encapsulated pre-description information. The compliance verification module is used to generate a set of compliance constraints based on a preset compliance rule library, substitute the solidified encapsulated pre-description information into it and call the satisfiability model theory solver to solve it, and obtain a compliance verification report. The signature encapsulation module is used to construct the encapsulated data to be signed based on the solidified encapsulation pre-description information and compliance verification report, deterministically encode it and calculate the digest to be signed, electronically sign the digest to be signed and apply for a trusted timestamp, and write the signature value and timestamp token to generate the signed encapsulated data. The anchored evidence module is used to calculate the evidence digest of the signed and packaged data and submit it to the tamper-proof evidence storage system for anchored evidence storage, obtain the evidence storage receipt and write it to generate a standardized packaged electronic archive.

Citation Information

Patent Citations

  • Vehicle information management method and system based on smart contract

    CN121051173A

  • Electronic archive data processing method and device

    CN121834005A