A traffic data management method based on data space access control
Patent Information
- Application Number
- CN202611140631.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-30
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2046-07-30
AI Technical Summary
[0005]针对现有技术所存在的上述缺点,本发明提供了一种基于数据空间访问控制的交通数据管理方法,能够有效解决目前因离散网格映射导致视频区域型数据连续性丢失、难以表达用户空间与时间动态变化以及因缺乏多次访问行为关联分析无法识别数据反推风险,造成数据访问碎片化、隐性越权防控的问题
引入数据源对象及其连续覆盖片段集对视频等区域型数据的连续空间表达,使访问控制不再依赖离散网格,基于真实覆盖范围匹配,保证返回数据的完整性与连续性,避免信息碎片化。构建权限空间场,使用户权限与空间位置、任务范围及时间动态耦合,描述移动终端和临时授权场景,避免传统全局权限模型带来的过度授权或误限问题。构建综合匹配度并实现分级数据释放,能够根据权限强度与数据敏感状态输出不同级别数据,在保证数据可用性的同时提升安全性。
Smart Images

Figure CN122674102B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of traffic data management technology, and specifically to a traffic data management method based on data space access control. Background Technology
[0002] Traffic data management methods simply bind data to a single spatial grid. However, video data inherently has regional coverage characteristics. The observation range of the same camera often spans multiple spatial units, and the target presents a continuous motion trajectory between different frames. If access control is still carried out using a single grid mapping method, the same continuous image will be split into multiple isolated segments. When the user requests a spatial matching with the data space, only part of the grid data is returned, resulting in problems such as information fragmentation, missing context, and broken trajectory.
[0003] On the other hand, existing permission models, which typically use global permission parameters, cannot accurately reflect the dynamic changes in user permissions across different spatial locations and task stages. For example, scenarios where traffic police mobile terminals can only access data within their own jurisdiction, or where emergency tasks require temporarily expanding the access scope, are difficult to accurately represent, easily leading to over-authorization or under-authorization. Currently, users may gradually piece together data from different spatial areas through multiple legitimate accesses, thereby indirectly reconstructing complete monitoring trajectories or sensitive information, resulting in the risk of data backtracking, which is currently not effectively identified.
[0004] In video data sensitivity testing, static labels or levels are often used, without considering the dynamic changes in sensitivity over time, target density, and scene, which leads to certain errors in the accuracy of access control policies. Summary of the Invention
[0005] To address the aforementioned shortcomings of existing technologies, this invention provides a traffic data management method based on data spatial access control. This method effectively solves the problems of fragmented data access and implicit overreach prevention caused by the loss of continuity in video regional data due to discrete grid mapping, difficulty in expressing dynamic changes in user space and time, and inability to identify data back-inference risks due to the lack of correlation analysis of multiple access behaviors.
[0006] To achieve the above objectives, the present invention provides the following technical solution: This invention provides a traffic data management method based on data space access control, comprising at least: Step 1: Obtain the data source identifier, data type, data source coverage area, data source baseline sensitivity status, data flow, and data source spatial location to construct the data source object; Step 2: Divide the traffic management area into spatial units and establish a spatial unit association matrix, then extract the set of continuous coverage segments; Step 3: Based on the user's identity identifier, determine the user's basic permission level, current location, effective time of the task, the user's jurisdiction, and the permitted scope of the task, construct a permission space field, and obtain the set of spaces that the user is allowed to access; Step 4: Calculate the coverage relationship function between the user request space and the data source coverage area, the continuity relationship function with the continuous coverage fragment set, the permission relationship function within the request space, the type relationship function between the request data type and the data source type, and the sensitivity relationship function between the user permissions and the current sensitive state of the data source. Combine the relationship functions to construct a comprehensive matching degree and determine the data level to be released. Step 5: Define each access behavior as a behavior segment, organize a set of behavior segment sequences within a sliding time window, construct an access space splicing graph, calculate the trajectory reconstruction coverage, time continuity index, path continuity index, and splicing expansion rate to obtain the risk intensity and map it to a risk space field. Combine the access frequency of each space point in the behavior segment sequence with its participation degree in the splicing space to update the permission space field within the allowed access space.
[0007] Furthermore, the method for establishing the spatial unit correlation matrix and extracting the set of continuous coverage segments is as follows: The traffic management area is divided into multiple spatial units, and all spatial units are combined into a spatial unit set. For each data source object, determine whether its coverage area intersects with each spatial unit. When a spatial unit intersects with the coverage area of the data source object: Determine that the spatial unit belongs to the coverage area of the data source object, and mark the corresponding position as associated in the data source object-spatial unit association matrix; otherwise, mark it as non-associated, thus forming the spatial unit association matrix. For video data, all spatial units in the associated state are extracted from the data source object-spatial unit association matrix, and clustered according to spatial adjacency relationships, including four-adjacency relationships or eight-adjacency relationships. Using spatial units as nodes and the edges between spatial units that satisfy adjacency relationships as connection relationships, all connected components are found by using depth-first search or disjoint-set data structure. The set of spatial units corresponding to each connected component is defined as a continuous covering segment, forming a set of continuous covering segments.
[0008] Furthermore, the method for constructing the permission space field and obtaining the set of user-allowed access spaces is as follows: Based on the user's identity identifier, query the user's basic permission level, jurisdiction, task validity period, and task allowed scope; The user's current location is taken as the center of the permission space field, and the allowed range of the task is taken as the allowed access radius that expands outward from the user's current location. This makes the user's access permissions gradually decrease as the distance between the access request space and the user's current location increases. The system determines whether the requested space is within the user's jurisdiction based on the jurisdiction status indicator. Determine whether the current moment is within the valid time of the task by checking the time validity status; When the access request space exceeds the jurisdiction or the current time exceeds the task's validity period, the corresponding permission status becomes invalid. The basic permission level, jurisdiction indication status, time validity status, and distance decay status are combined to construct a permission space field; The spatial locations in the permission space field with permission values greater than zero are defined as the user-allowed access space set.
[0009] Furthermore, the method for constructing a comprehensive matching degree by integrating the aforementioned relational functions is as follows: For each user request, calculate the degree of overlap between the access request space and the data source coverage area, and use the degree of overlap as the coverage relationship function; Calculate the degree of overlap between the access request space and the set of continuous coverage segments, and use the degree of overlap as a continuous relationship function to characterize whether the access request space can form continuous and valid observation segments; The permission status of the permission space field is judged point by point within the access request space, and the position with the lowest permission status in the access request space is taken as the permission relationship function of the request space. This ensures that if there is a position with insufficient permissions in the access request space, the entire access request space cannot be regarded as fully authorized. The type relationship function is determined based on whether the request data type and the data source type are compatible; The function to determine the sensitivity relationship is valid when the permission relationship corresponding to the access request space is not lower than the current sensitivity state of the data source. The comprehensive matching degree is constructed by covering relation functions, continuous relation functions, permission relation functions, type relation functions, and sensitive relation functions.
[0010] Furthermore, the method for assembling the sequence of organizational behavior fragments within the sliding time window is as follows: Combine the access request space, access event, data source object identifier, and actual release level corresponding to a single access into a single line fragment; Multiple behavioral segments are organized according to a sliding time window to form a set of behavioral segment sequences to record a user's continuous access behavior over a period of time; the behavioral segments in the set of behavioral segment sequences are used as node sources for the construction of an access space mosaic; the access records of the same user to different data source objects at different time points are associated to retain the temporal, spatial, and release level information of the access behavior.
[0011] Furthermore, the specific process for establishing the aforementioned risk intensity includes: The access request space in the set of behavioral fragment sequences is used as the node of the access space splicing graph; When two access request spaces satisfy the spatial adjacency condition or the temporal continuity condition, an edge is established between the corresponding nodes. The spatial adjacency condition indicates that the minimum Euclidean distance between the two access request spaces is not greater than a preset value, and the temporal continuity condition is used to indicate that the two accesses occur sequentially in time. The largest connected subgraph is selected from the access space splicing graph, and the access request spaces in the largest connected subgraph are merged to form a splicing space, which represents whether the user can continuously access multiple data sources along adjacent spatial units in a short period of time. The coverage rate is reconstructed by calculating the trajectory based on the intersection of the access request space and the set of continuous coverage segments; Calculate time continuity index based on variance and standard deviation of adjacent access time intervals; The path continuity index is calculated based on whether there are edges connecting two adjacent visits in the access space splicing graph. The splicing expansion rate is calculated based on the relationship between the splicing space and the average area of a single requested space. The risk intensity is obtained based on the trajectory reconstruction coverage, time continuity index, path continuity index, and splicing expansion rate.
[0012] The technical solution provided by this invention has the following advantages compared with the known prior art: By introducing data source objects and their continuous coverage fragment sets to represent the continuous spatial structure of regional data such as video, access control no longer relies on discrete grids. Based on matching the actual coverage area, it ensures the integrity and continuity of returned data, avoiding information fragmentation. A permission space field is constructed, dynamically coupling user permissions with spatial location, task scope, and time, describing mobile terminals and temporary authorization scenarios, avoiding over-authorization or erroneous restriction problems caused by traditional global permission models. A comprehensive matching degree is built and hierarchical data release is implemented, capable of outputting different levels of data based on permission strength and data sensitivity, improving security while ensuring data availability.
[0013] By constructing an access space mosaic map through access behavior fragment sequences, and introducing trajectory reconstruction coverage, mosaic expansion rate, time continuity index, and path continuity index to analyze users' multiple access behaviors, we can identify whether users gradually mosaic larger spatial ranges through continuous access and form implicit unauthorized access risks. The risk intensity is mapped to the risk space field to locally and dynamically shrink the permission space field, accurately acting on the problem area without affecting normal access. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0015] Figure 1 This is a schematic diagram of the overall method of the present invention. Detailed Implementation
[0016] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0017] The present invention will be further described below with reference to embodiments.
[0018] Example 1 (see Figure 1 A traffic data management method based on data space access control, comprising at least: Step 1: Unify the raw data in the traffic scenario into a data source object with spatial coverage and sensitivity attributes. Construct the data source object. ,in This indicates the data source identifier, used to distinguish different cameras, radars, checkpoints, or other traffic data. The data type indicates whether the data source is video data, trajectory data, radar data, or other traffic data. The data source coverage area represents the actual spatial coverage of the data source. This represents the baseline sensitivity status of the data source, indicating the default sensitivity level of the data source under normal circumstances (video data - high sensitivity level; trajectory data - medium sensitivity level; radar data - low sensitivity level; the sensitivity level is also classified according to the area where the data source is located, for example, if it involves key intersections or public safety areas, the sensitivity level is increased, while the sensitivity level remains the same for regular road areas; it can also be determined based on whether the data contains sensitive information, for example: if it contains license plate recognition capabilities, the sensitivity level is increased; if it only contains traffic statistics information, the sensitivity level is decreased). The data stream at time t represents the raw data content output by the data source at the current time, such as video frames or radar echoes. Indicates the spatial location of the data source, describing the installation or deployment location of the data source in the transportation space, where i represents the data source index.
[0019] For video data, the coverage area is not a single grid, but a coverage area composed of multiple spatial units (the traffic management area is divided into multiple spatial units).
[0020] Based on the content of the current frame Update and get .in, This indicates the current sensitivity status of the data source, representing the real-time sensitivity level of the data source at the current moment due to factors such as license plate visibility and the temporal distribution of people. Assuming the current frame sensitivity state, for video data sources (for non-video data sources, such as trajectory and radar, if there is no dynamic content analysis, the baseline sensitivity state of the data source is directly taken), the frame sensitivity state is calculated at each time step based on the current frame image content. , This indicates the number of license plates detected in the current frame. This represents the maximum number of license plates. The current population density is calculated by dividing the number of people detected in the current frame by the coverage area of the data source. This is the reference population density for the data source under standard scenarios (such as weekdays from 10:00-11:00 or 15:00-16:00, a period of stable traffic flow without congestion or sudden events; the population density during this period is used as the reference population density). , These are the corresponding preset weight coefficients. This results in a collection of data source objects. and the current set of sensitive states This step ensures that subsequent access control is no longer based on abstract data labels, but rather on the computational data source object itself.
[0021] Step 2: Granting video data to a single grid results in fragmented images, missing context between adjacent grids, and loss of cross-spatial continuity. Therefore, the data source object is mapped to a specific spatial unit, and a set of continuously overlaid segments is further extracted. Specifically: The traffic management area is divided into multiple spatial units. And form a set of spatial units ; For each data source object Calculate its coverage area The intersection with each spatial unit, where: like This indicates that the spatial unit belongs to the coverage area of the data source object, and the corresponding element in the association matrix is... Otherwise This forms the data source object-spatial unit association matrix. .
[0022] For video data, it is also necessary to extract a set of continuously covered segments based on the spatial units that satisfy the connectivity relationship in the correlation matrix. Among them, the continuous coverage fragment set It is not a collection of individual discrete grid points, but a collection of continuous segments formed by adjacent spatial units covered by the same data source object, linked together according to spatial connectivity and temporal coherence, to depict the complete image continuity of the same camera in cross-grid scenes.
[0023] For each data source object, retrieve all rows that satisfy the condition in row i. spatial units Then, according to spatial adjacency (spatial units) Viewed as a grid diagram, with two spatial units and The conditions for defining adjacency can be: four-adjacency (sharing an edge, either vertically or horizontally); eight-adjacency (sharing an edge or a corner, including the diagonal). Four-adjacency is typically used to ensure that continuous coverage segments are coherent observation regions. Clustering (such as the connected component algorithm for undirected graphs) is then performed, using all elements in the i-th row that satisfy the condition... Each spatial cell in the spatial cell index set is a node. If two spatial cells are adjacent, an edge is created between them. All connected components are found using Depth-First Search (DFS) or Union-Find. Each connected component consists of a series of mutually reachable spatial cells, forming a continuous coverage segment. All continuous coverage segments constitute... .
[0024] In other words, the data source object—spatial unit association matrix Used to determine: which spatial units are covered by a given data source, and which are consecutively covered fragment sets. This step is used to determine whether these spatial units can be connected to form a continuous and valid observation area. The data source objects output in this step—the spatial unit correlation matrix and the set of continuous coverage fragments—serve as input for spatial matching and continuity determination of access requests, ensuring that subsequent authorization results are not fragmented authorizations, but authorizations based on true coverage continuity.
[0025] Step 3: User permissions can only be used as global scalars; they cannot express changes in the mobile terminal's location or the scope of temporary tasks. Therefore, user access conditions need to be expressed spatially and dynamically. Specifically: The user's basic permission level is determined based on the user's identity identifier (which is used to find the user's basic permission level, jurisdiction, task validity period, task allowed radius, and other attributes). (This indicates the user's initial authorization level. The basic permission level is normalized to the range of 0 to 1, for example, 0.8 for temporary staff and 1 for command center.) User's current location (Representing the user's dynamic geographical location), task validity period (Indicates whether the authorization is still valid at the current moment, possibly the start and end times of this temporary task), and the user's jurisdiction. (This represents the user's spatial permission boundaries within the legally or business-permitted scope. A jurisdiction is essentially a spatial area, such as the jurisdiction of the Haidian District police brigade; it's not a scalar value. It's a binary judgment to determine whether the requested coordinates are within the jurisdiction.) and the permitted scope of the task. (That is, the allowed radius of the task, which represents the spatial expansion range that the user is allowed to access in the current task state. It is the radius length radiating outward from the user's current location. Permissions decrease with distance within this radius, and permissions become 0 after exceeding the radius.) Construct the permission space field: The permission space field is used to describe the user's spatial location. The access permission strength determines whether access is possible and at what level. This represents the jurisdiction indicator function, if the coordinates If it belongs to the current jurisdiction, the value is 1; otherwise, the value is 0. This function indicates the validity of the authorization; it is 1 if the current time is within the authorization period, and 0 otherwise. This indicates the distance between the requested spatial coordinates and the user's current location. This is used to gradually reduce permissions with spatial distance, with permissions decreasing as the distance increases.
[0026] Therefore, the set of space that a user is allowed to access is defined as follows: In this embodiment, user permissions are no longer abstract global values, but spatial fields directly bound to geographical location, task timeliness and jurisdiction. This can accurately express the real scenario where traffic police mobile terminals automatically have their permissions revoked after leaving the jurisdiction, and emergency command vehicles temporarily obtain high-security access permissions around the accident site, which then decrease as they move.
[0027] Step 4: For each user request and data source object, calculate the access request space. With data source coverage area The degree of overlap is used to obtain the covering relationship function. This coverage relation function is used to characterize the request space and the data source. Spatial matching ratio between coverage areas (if the denominator is 0, a very small positive number needs to be added, which will not be elaborated in this embodiment). The intersection of the access request space and the set of continuous coverage fragments yields the continuous relation function. This continuous relation function is used to characterize whether the access request space can form a continuous and valid observation fragment, avoiding the authorization of only isolated fragments; Define the permission relationship function by taking the minimum value of the permission space field within the entire request space. If even one location in the request space lacks sufficient permissions, the entire request space cannot be considered fully authorized. Define type relationship functions based on whether the request data type and the data source type are compatible. If the two are compatible, take 1; otherwise, take 0. Then, the permission relationship function is compared with the current sensitive state of the data source, and a sensitive relationship function is defined. If the permission relationship function Greater than or equal to the current sensitivity state of the data source (If both the permission relationship function and the current sensitive state of the data source are normalized to a unified range), then the sensitivity relationship function is set to 1; otherwise, it is set to 0.
[0028] Finally, the product of the five defined functions can be used to establish a comprehensive matching degree, and then the data release results can be divided into multiple levels based on preset thresholds, including: When the overall matching degree is not less than the preset threshold A, the original data stream is output (release level is 1). When the overall matching degree is less than the preset threshold A and not less than the preset threshold B, the desensitized data is output (the release level is numerically 0.66). When the overall matching degree is less than the preset threshold B and not less than the preset threshold C, a metadata data packet (release level numeralized to 0.33) is output. The metadata data packet includes at least vehicle count, anonymized trajectory, event summary and time slice identifier, so as to retain certain traffic management information when the user's permissions are insufficient to access the original video.
[0029] When the overall matching degree is less than the preset threshold C, access is denied (the release level is set to 0).
[0030] Step 5: A single access may be completely legal, but multiple consecutive accesses, when superimposed, can piece together originally discontinuous and incomplete data into a larger monitoring area, or even reconstruct vehicle trajectories or personnel movement paths. Current risk control may only consider the legality of a single request, making it difficult to identify cases where such legal actions are superimposed to form implicit unauthorized access, nor can it detect from the spatial structure whether a user is splicing regions. Therefore, this embodiment introduces a method to determine whether a user has the risk of splicing unauthorized access, and to characterize the formation process, spatial expansion degree, and continuity characteristics of this risk. The specific steps are as follows: Define each access action as a behavior fragment. , This represents the requested space corresponding to the k-th access. This represents the event that occurred during the k-th visit. This indicates the identifier of the data source object being accessed. This indicates the level of data actually released during this access, which is the level value corresponding to the release result mentioned above.
[0031] These behavioral fragments in a sliding time window Internal tissue access behavior fragment sequence set This describes a user's continuous access behavior over a period of time.
[0032] Subsequently, an access space mosaic graph was constructed using the sequence of behavioral fragments as the source of nodes. , where the set of nodes For each access request space, if two access request spaces satisfy the spatial adjacency condition... or time continuity condition ( , These represent the request spaces for two different accesses. This represents the distance between two access request spaces, using the minimum Euclidean distance. This represents a preset spatial distance threshold. If the minimum Euclidean distance between two access request spaces is less than this spatial distance threshold, they are considered to be spatially adjacent and may be being spliced. , These represent the times when the two visits occurred. This represents a preset time interval threshold. If the time interval between two visits is less than this threshold, they are considered to be consecutive in time and belong to the same behavioral burst period. In this case, an edge is established between the corresponding nodes. .
[0033] After construction, the largest connected subgraph in the access space splicing graph is taken and merged to obtain the splicing space. This splicing space represents whether the user continuously accesses multiple data sources along adjacent spatial units in a short period of time, thereby gradually splicing out a larger monitoring area.
[0034] 1) Calculate the trajectory reconstruction coverage by using the intersection of the behavior judgment sequence and the set of continuous coverage segments. The trajectory reconstruction coverage rate represents the degree to which user j (j represents the access user identifier, such as a traffic police terminal or command vehicle) reconstructs continuous coverage segments through multiple access behaviors within a time window of time t. The range is 0-1, and the larger the value, the more likely it is to piece together a complete trajectory. This represents the access request space variable, which belongs to the space corresponding to all behavior fragments in the set of access behavior fragment sequences, and is equal to... Data source object collection , represents the set of data source objects actually accessed by the user within the time window, and i represents the index of the data source object. It represents the union of all access requests made by a user within a time window, describing the spatial range covered by the user's cumulative access. This represents the set corresponding to all elements i in the data source object collection. Perform a union operation. The numerator represents the area of the spatial intersection between the union of all access request spaces of the user within the time window and the union of the continuous coverage segments corresponding to the data source accessed by the user. The denominator represents the area of the union of all continuous coverage segments corresponding to the data source object accessed by the user within the time window, describing the potential range of the complete continuous trajectory space that the user can stitch together. The trajectory reconstruction coverage rate measures the degree to which the user's access behavior utilizes the continuous coverage space. The numerator represents the effective portion of the user's actual access space that can be used for trajectory stitching, and the denominator represents the total continuous coverage space that the user can theoretically obtain through the accessed data sources. The ratio of the two describes whether the user has nearly completed the reconstruction of the continuous trajectory.
[0035] 2) Based on adjacent access time intervals The time continuity index is calculated using a time uniformity analysis method based on the coefficient of variation. , The variance representing the time interval between adjacent visits. Standard deviation This represents the average time interval between adjacent visits. It should be a very small positive number to avoid a denominator of 0 when all visits occur simultaneously or the average time interval is zero. This metric is used to reflect the effect of more uniform visit intervals. The closer to 1, the more disordered the access time intervals become. The closer it is to 0.
[0036] 3) Calculate the path continuity index based on sequence adjacency constraints. N represents the number of behavior segments within the current time window (by counting the edges between two adjacent visits; there are only N-1 sequence edges between N points, thus obtaining the proportion of adjacent visits with path continuity). This represents the sequence edge between the k-th behavior segment and the (k+1)-th behavior segment. If N is less than or equal to 1, the path continuity criterion is 1. This is an indicator function; it takes a value of 1 if two adjacent visits have an edge in the visited space of the graph, and 0 otherwise. This indicator characterizes the spatial continuity of the visit sequence; that is, it is considered to have path continuity only if two adjacent visits are spatially adjacent and connected in the graph. Therefore, for a visit to A1 first, followed by A2, if A1 and A2 are not interconnected, This will significantly reduce the risk, thus avoiding being judged as high-risk simply because of high frequency.
[0037] 4) Calculate the splicing expansion rate , This represents the splicing space, describing the spatial region obtained by selecting the largest connected subgraph in the access space splicing graph and performing a union operation on all access request spaces within it. , This represents the largest connected subset in the access spatial mosaic graph. This represents the overall spatial range obtained by the user through multiple visits and concatenation. This represents the area of the space requested in the k-th request. The splicing expansion rate represents the ratio of the spliced space area to the average area of a single request, reflecting the overall space formed by multiple access requests within a time window. It indicates whether multiple local requests have spliced together a region much larger than a single request. For example, when a user splices together a large region through multiple small region requests, this ratio will be greater than 1.
[0038] 5) Then, establish the risk intensity based on the four indicators. , This indicates that the results are limited to the range of 0-1. Therefore, when spatial expansion, coverage utilization, temporal continuity, and path continuity are simultaneously satisfied, a typical implicit behavior pattern is identified. This pattern involves users expanding spatially through multiple seemingly independent and legitimate accesses, maintaining temporal continuity, and utilizing continuously observed areas in terms of coverage, gradually reconstructing the complete monitoring range or target trajectory. By fusing these multidimensional features into risk intensity, and by retrospectively analyzing the access process from the access structure, implicit unauthorized behavior can be identified and quantified early in its formation. The key to this step is introducing the splicing expansion rate as a core spatial expansion indicator into risk analysis. This not only focuses on whether the access is continuous but also identifies whether the access is continuously expanding its scope, improving the accuracy of identifying progressive splicing-type unauthorized behavior.
[0039] Furthermore, if the risk only generates a single global value (risk intensity, which reflects the overall risk level of a user's access behavior without distinguishing risk differences in different spatial locations, and therefore can only uniformly adjust the user's overall permissions when adjusting permissions), it's possible that if a user is judged as abnormal in a sensitive area, their entire permission will be reduced, preventing them from working normally in other legitimate areas. This approach may not be suitable for mobile terminals and emergency vehicles, which have spatial dynamism (referring to the characteristic that the geographical location of the access subject continuously changes over time, causing their accessible spatial range and permission constraints to change dynamically over time). Therefore, the risk must be applied to specific spatial units and consistent with the permission spatial field. Thus, the risk is transformed from a global quantity into a spatially distributed quantity, and a local contraction of the permission spatial field is performed accordingly. Specifically: The obtained risk intensity is combined with the frequency of visits to each spatial point in the behavioral segment sequence and the degree of participation in the splicing space to generate a risk spatial field. Represents the user's spatial location The intensity of the implicit risk of overstepping authority Representing a spatial point The number of times it is accessed and covered within the time window. This indicates the total number of access coverages within the time window. This risk spatial field is precisely located to a specific spatial unit, used to identify locations where risks are concentrated.
[0040] Subsequently, only in the allowed access space Local updates to the permission space field, i.e., for any The updated permission space field For spaces that are not allowed access. The spatial points, then remain Unchanged. Therefore, instead of making uniform adjustments to overall user permissions, adjustments will only be made to the allowed access areas. Within this framework, the permission space field is locally updated. Specifically, for spatial regions that exhibit significant splicing and expansion behavior in step five (corresponding to a high splicing and expansion rate) and form effective overlap in continuous coverage segments (corresponding to a high trajectory reconstruction coverage rate), the permission strength of these regions is proportionally reduced through weight modulation using the risk space field. For spatial regions that do not participate in splicing and expansion or do not possess continuous coverage utilization characteristics, their original permissions remain unchanged. In this way, when a user attempts to continuously expand their access range along a certain spatial path, the spatial points along that path will gradually accumulate risk and form high-risk areas. The corresponding permission space field is compressed, thereby inhibiting the user's ability to continue splicing and expanding access through that path.
[0041] Meanwhile, since areas where expansion behavior has not occurred are not involved in risk mapping, users maintain stable permissions in other normal business areas, avoiding business interruptions caused by traditional global demotion. This achieves control from detecting expansion behavior to restricting expansion paths, ensuring that risks are not only identified but also precisely targeted to their spatial location. Without affecting overall availability, it effectively blocks the spatial expansion of implicit unauthorized behavior, improving the ability to finely control complex and dynamic access behaviors. The updated permission risk field will be used as input for the next round of access authorization, re-entering steps three and four to form control rules for access, release, behavior analysis, risk mapping, partial updates, and re-access. This continuously suppresses implicit unauthorized risks without affecting normal business access.
[0042] Finally, this embodiment may further include outputting corresponding data packets based on the authorization results and data release level in step four, and simultaneously generating audit records. These audit records at least include the data source identifier, access request space, actual release level, access time, visitor identifier, the set of spatial units involved, and information on high-risk areas in the risk space field. These audit records are used for subsequent tracing and monitoring, and also serve as input for constructing behavioral fragment sequences within the next time window, ensuring that the access space mosaic and risk intensity calculation in step five are based on real historical access trajectories. Thus, this invention can both output target data and retain traceable control evidence.
[0043] Furthermore, if the aforementioned function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0044] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-including system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0045] More specific examples of computer-readable media (a non-exhaustive list) include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.
[0046] Furthermore, in order to provide a concise description of exemplary embodiments, not all features of actual embodiments (i.e., those features that are not relevant to the best mode of carrying out the invention as currently considered, or those features that are not relevant to implementing the invention) may be omitted.
[0047] It should be understood that numerous specific implementation decisions can be made during the development of any practical implementation, such as in any engineering or design project. Such development efforts may be complex and time-consuming, but for those skilled in the art who benefit from this disclosure, the development effort will be a routine work of design, manufacturing, and production without requiring much experimentation.
[0048] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions will not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.
Claims
1. A traffic data management method based on data spatial access control, characterized in that, include: Step 1: Obtain the data source identifier, data type, data source coverage area, data source baseline sensitivity status, data flow, and data source spatial location to construct the data source object; Step 2: Divide the traffic management area into spatial units and establish a spatial unit association matrix, then extract the set of continuous coverage segments; Step 3: Based on the user's identity identifier, determine the user's basic permission level, current location, effective time of the task, the user's jurisdiction, and the permitted scope of the task, construct a permission space field, and obtain the set of spaces that the user is allowed to access; Step 4: Calculate the coverage relationship function between the user request space and the data source coverage area, the continuity relationship function with the continuous coverage fragment set, the permission relationship function within the access request space, the type relationship function between the request data type and the data source type, and the sensitivity relationship function between the user permissions and the current sensitive state of the data source. Combine the relationship functions to construct a comprehensive matching degree and determine the data level to be released. Step 5: Define each access behavior as a behavior segment, organize a set of behavior segment sequences within a sliding time window, construct an access space splicing graph, calculate the trajectory reconstruction coverage, time continuity index, path continuity index, and splicing expansion rate to obtain the risk intensity and map it into a risk space field. Combine the access frequency of each space point in the behavior segment sequence with its participation degree in the splicing space to update the permission space field within the allowed access space. The product of the five defined functions is used to establish a comprehensive matching degree. Based on a preset threshold, the data release results are divided into multiple levels, including: When the overall matching degree is not less than the first preset threshold, the original data stream is output and the release level is the highest release level; When the overall matching degree is less than the first preset threshold and not less than the second preset threshold, the de-identified data is output. When the overall matching degree is less than the second preset threshold and not less than the third preset threshold, a meta data packet is output, and the meta data packet includes at least vehicle count, anonymized trajectory, event summary and time slice identifier. Access is denied when the overall matching degree is less than the third preset threshold. The updated permission space field will be used as input for the next round of access authorization, re-entering steps three and four to form control rules for access, release, behavior analysis, risk mapping, partial update, and re-access.
2. The traffic data management method according to claim 1, characterized in that, The method for establishing the spatial unit correlation matrix and extracting the set of continuous coverage segments is as follows: The traffic management area is divided into multiple spatial units, and all spatial units are combined into a spatial unit set. For each data source object, determine whether its coverage area intersects with each spatial unit. When a spatial unit intersects with the coverage area of the data source object: Determine that the spatial unit belongs to the coverage area of the data source object, and mark the corresponding position as associated in the data source object-spatial unit association matrix; otherwise, mark it as non-associated, thus forming the spatial unit association matrix. For video data, all spatial units in an associated state are extracted from the data source object-spatial unit association matrix and clustered according to spatial adjacency relationships; Using spatial units as nodes and the edges between spatial units that satisfy adjacency relationships as connection relationships, all connected components are found by using depth-first search or disjoint-set data structure. The set of spatial units corresponding to each connected component is defined as a continuous covering segment, forming a set of continuous covering segments.
3. The traffic data management method according to claim 1, characterized in that, The method for constructing the permission space field and obtaining the set of user-allowed access spaces is as follows: Based on the user's identity identifier, query the user's basic permission level, jurisdiction, task validity period, and task allowed scope; The user's current location is taken as the center of the permission space field, and the allowed range of the task is taken as the allowed access radius that expands outward from the user's current location. This makes the user's access permissions gradually decrease as the distance between the access request space and the user's current location increases. The system determines whether the requested space is within the user's jurisdiction based on the jurisdiction status indicator. Determine whether the current moment is within the valid time of the task by checking the time validity status; When the access request space exceeds the jurisdiction or the current time exceeds the task's validity period, the corresponding permission status becomes invalid. The basic permission level, jurisdiction indication status, time validity status, and distance decay status are combined to construct a permission space field; The spatial locations in the permission space field with permission values greater than zero are defined as the user-allowed access space set.
4. The traffic data management method according to claim 1, characterized in that, The method for constructing a comprehensive matching degree by integrating the aforementioned relational functions is as follows: For each user request, calculate the degree of overlap between the access request space and the data source coverage area, and use the degree of overlap as the coverage relationship function; Calculate the degree of overlap between the access request space and the set of continuous coverage segments, and use the degree of overlap as a continuous relationship function to characterize whether the request space can form continuous and valid observation segments; The permission status of the permission space field is judged point by point within the access request space, and the position with the lowest permission status in the access request space is taken as the permission relationship function of the request space. This ensures that if there is a position with insufficient permissions in the access request space, the entire access request space cannot be regarded as fully authorized. The type relationship function is determined based on whether the request data type and the data source type are compatible; The function to determine the sensitivity relationship is valid when the permission relationship corresponding to the access request space is not lower than the current sensitivity state of the data source. The comprehensive matching degree is constructed by covering relation functions, continuous relation functions, permission relation functions, type relation functions, and sensitive relation functions.
5. The traffic data management method according to claim 1, characterized in that, The method for assembling the sequence of organizational behavior fragments within the sliding time window is as follows: Combine the access request space, access event, data source object identifier, and actual release level corresponding to a single access into a single line fragment; Multiple behavioral segments are organized according to a sliding time window to form a set of behavioral segment sequences to record a user's continuous access behavior over a period of time; the behavioral segments in the set of behavioral segment sequences are used as node sources for the construction of an access space mosaic; the access records of the same user to different data source objects at different time points are associated to retain the temporal, spatial, and release level information of the access behavior.
6. The traffic data management method according to claim 1, characterized in that, The specific process for establishing the aforementioned risk intensity includes: The access request space in the set of behavioral fragment sequences is used as the node of the access space splicing graph; When two access request spaces satisfy the spatial adjacency condition or the temporal continuity condition, an edge is established between the corresponding nodes. The spatial adjacency condition indicates that the minimum Euclidean distance between the two access request spaces is not greater than a preset value, and the temporal continuity condition is used to indicate that the two accesses occur sequentially in time. Take the largest connected subgraph from the access space splicing graph, and merge the access request spaces in the largest connected subgraph to form the splicing space; The coverage rate is reconstructed by calculating the trajectory based on the intersection of the access request space and the set of continuous coverage segments; Calculate time continuity index based on variance and standard deviation of adjacent access time intervals; The path continuity index is calculated based on whether there are edges connecting two adjacent visits in the access space splicing graph. The splicing expansion rate is calculated based on the relationship between the splicing space and the average area of the space requested in a single access session. The risk intensity is obtained based on the trajectory reconstruction coverage, time continuity index, path continuity index, and splicing expansion rate.
7. The traffic data management method according to claim 1, characterized in that, It also includes the method for constructing the current sensitive state of the data source: The baseline sensitivity state of the data source object is compared with the current frame sensitivity state obtained from the current data content, and the larger of the two values is taken as the current sensitivity state of the data source at that moment. For video data, the sensitivity state of the current frame is calculated at each time step based on the image content of the current frame. The specific calculation method is as follows: Collect the number of license plates detected in the current frame, and normalize the number of license plates to the maximum number of license plates. Collect the population density in the current frame, and normalize the population density to the reference population density. Assign weight coefficients to each, and calculate the comprehensive sensitivity value by weighting. The overall sensitivity value is compared with the value 1, and the smaller value is taken as the sensitivity state of the current frame.
8. The traffic data management method according to claim 1, characterized in that, Also includes: The permission space field is only locally updated based on the risk space field within the allowed access space. When the risk space field value corresponding to a certain space point increases, the permission status at that space point is reduced. For space points that do not belong to the allowed access space, the permission status remains unchanged; The updated permission space field is used as the input for the next round of access authorization, and the process of determining permission relationships, comprehensive matching degree and data release is re-entered to construct control rules for access, release, behavior analysis, risk mapping, partial update and access. An audit record is generated based on the data release results, and the audit record shall include at least the data source identifier, access request space, actual release level, access time, visitor identifier, set of spatial units involved, and high-risk areas in the risk space field; The audit logs are used to trace historical access patterns and serve as input for constructing a set of behavioral fragment sequences within the next time window.
Citation Information
Patent Citations
City data adaptive privacy protection method and system based on dynamic security grading driving
CN121723516A
AI information enhancement method based on power grid equipment identity authentication and spatial interconnection
CN122473406A