5G-R network situation awareness method based on distributed monitoring and multi-source information fusion

Through distributed monitoring and multi-source information fusion technology, real-time acquisition and intelligent analysis of multi-source heterogeneous data of 5G-R networks has been solved, and the problem of insufficient real-time and fusion capabilities of data in the existing technology has been achieved, and the full network coverage and efficient fault location of 5G-R network are achieved, meeting the high reliability and low latency requirements of railway scenarios.

CN120238929APending Publication Date: 2025-07-01BEIJING JIAOTONG UNIV +1

Patent Information

Application Number
CN202510713636.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing technology is difficult to meet the real-time monitoring requirements of multi-source heterogeneous data in 5G-R networks, and lacks distributed monitoring and multi-source information fusion capabilities, resulting in low fault positioning efficiency, insufficient real-time performance and weak visual support, which cannot meet the high reliability and low latency requirements of railway scenarios.

Method used

Multi-source heterogeneous data is collected in real time through distributed monitoring devices, combined with multi-source information fusion technologies such as Pearson correlation coefficient, FP-Growth algorithm and artificial intelligence models (such as Bayesian analysis, time-sequence point process, Hawkes theory, logistic regression graph neural network, etc.), multi-dimensional data processing and intelligent analysis are realized, supporting cross-region data sharing and visual situational awareness.

Benefits of technology

It realizes full network coverage and low-latency data acquisition of 5G-R network, improves the accuracy and efficiency of fault location, meets the low-latency and high reliability requirements of railway scenarios, and improves operation and maintenance efficiency and decision-making support capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238929A_ABST
    Figure CN120238929A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of 5G-R network detection and monitoring, discloses a 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion, and aims at solving the problems that a 5G-R network is large in scale, high in dynamic performance and complex in data isomerism. Multi-source data of a core network, a wireless network, special equipment, interface monitoring, detection equipment, a GIS and the like are collected in real time; according to the method, technologies such as Pearson's correlation coefficients, FP-Growth, Bayesian analysis, a time sequence point process, a Hookes theory, a Gaussian mixture model, a decision tree, S-ARIMA, Boxplot, N-sigma, iForest, regression analysis, a neural network and KL divergence are combined to realize multi-source data fusion, intelligent analysis and visual perception, including network alarm, application quality, operation and maintenance and resource management. According to the method, the comprehensiveness, the real-time performance, the fault diagnosis accuracy and the operation and maintenance efficiency of the 5G-R network are improved, and the requirements of low delay and high reliability of a railway scene are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of 5G-R network detection and monitoring, and in particular to a 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion. Background Art

[0002] With the rapid development of 5G networks and the gradual deployment of 5G-R (5G dedicated mobile communication for railways) technology, the scale and complexity of the network are increasing. As an important part of the future intelligent railway communication infrastructure, the 5G-R network carries the key tasks of driving safety data transmission, low-latency communication and massive device connection. It is widely used in high-speed railways, heavy-load railways and conventional railways. In particular, it must meet the high reliability requirements of supporting high-speed train communications, train operation control and vehicle-ground coordination in complex railway scenarios. Therefore, ensuring the stability, reliability and efficiency of the 5G-R network has become a technical problem that needs to be solved urgently.

[0003] Traditional network monitoring systems mainly rely on centralized monitoring and a single data source to monitor the basic status of the network in real time through the network management center (OMC) or network management tools (such as SNMP, Syslog protocol). Although this method can meet basic needs in small networks, it faces many challenges when dealing with large-scale, dynamically changing 5G-R networks:

[0004] Limited data sources: Traditional systems rely on low-density data sources, such as single device logs or performance indicators, which make it difficult to cover the entire network operation status of the 5G-R network, especially in cross-railway bureau and cross-region scenarios where data collection is incomplete.

[0005] Lack of real-time performance: Centralized monitoring leads to data transmission and processing delays, which makes it difficult to meet the low latency (<1ms) and high real-time performance requirements of 5G-R networks, such as the instant perception of signal quality in high-speed train communications.

[0006] Difficulty in managing complexity: 5G-R networks involve multi-dimensional data sources such as core networks, wireless networks, dedicated equipment, and interface monitoring. Their heterogeneity and high dynamics (such as network slicing and business traffic fluctuations) increase the difficulty of monitoring. Traditional methods cannot achieve comprehensive integration and intelligent analysis of multi-source data.

[0007] Low fault location efficiency: Existing systems mostly monitor a single aspect and lack the ability to make cross-regional, multi-module collaborative decisions and full network situation awareness, resulting in a long time and low accuracy in root cause diagnosis.

[0008] In recent years, China has made many technological breakthroughs in the field of railway private network detection and monitoring technologies. For example, progress has been made in the full-life cycle monitoring of railway infrastructure and the perception of network security threats. However, for the monitoring of 5G-R networks, especially the multi-source data collection and analysis, breakthroughs still need to be achieved in the major key technologies of distributed monitoring, data fusion, and intelligent analysis to meet the requirements of the efficient and stable operation of railway private networks.

[0009] In the existing technologies, the disclosed patents and research have provided partial solutions for network monitoring, but there are still the following deficiencies:

[0010] For example, the Chinese patent with the publication number CN111641653A proposes a network security threat situation awareness system based on a cloud platform. Its function layer includes a data collection layer, a situation analysis layer, a situation evaluation layer, and a situation display layer. The data collection layer collects network basic data through the Syslog protocol, the SNMP protocol, and network security management tools, and uses a feature fusion method to evaluate the security situation. However, this system is designed for traditional computer networks and has significant differences from the characteristics of 5G-R networks (such as low latency, high concurrency, and massive device connections). Moreover, it is different from the present invention in terms of data collection objects (only security logs) and methods, and cannot meet the real-time monitoring requirements of multi-source heterogeneous data in 5G-R networks.

[0011] Furthermore, the Chinese patent with the publication number CN113159475A provides a full-life cycle monitoring platform for infrastructure, which includes a status perception system, a network transmission system, and a data analysis system, focusing on the status evaluation of multi-source data of railway infrastructure (such as bridges and tunnels) in high-altitude and cold environments. Although it involves railway scenarios, it mainly focuses on the status of physical infrastructure and does not involve the monitoring of 5G-R private networks and the dynamic detection of network devices, lacking the capabilities of distributed monitoring and multi-source information fusion.

[0012] Moreover, the patent with the publication number CN116896462A proposes a smart mine network situation awareness system based on network security management. By receiving security logs (such as Syslog and Netflow) generated by network devices, it uses association analysis (such as Apriori and FP-Growth algorithms) and graph database to mine data associations and identify data related to network attacks. Although this system has certain innovations in data association and analysis, its application scenario is limited to the smart mine network, which does not match the railway-specific requirements of 5G-R networks (such as vehicle-ground coordination and low-latency communication), and does not solve the problems of distributed monitoring and network-wide situation awareness.

[0013] In addition, the current 5G-R network monitoring work mainly focuses on a single aspect, such as network performance or security threats, and has not formed an overall solution for cross-railway administration, multi-source data fusion, multi-module collaborative decision-making, and multi-level network perception. The existing technologies still have limitations in the following aspects:

[0014] Insufficient multi-source data fusion: It is difficult to integrate multi-dimensional heterogeneous data from the core network, radio network, interface monitoring, detection devices, and GIS, resulting in incomplete situation awareness.

[0015] Limited intelligent analysis ability: Lack of intelligent analysis based on artificial intelligence (such as machine learning, deep learning) and advanced statistical models (such as point process in time series, Hawkes theory), making it difficult to achieve accurate anomaly detection, trend prediction, and root cause diagnosis of faults.

[0016] Weak visualization support: Existing systems mostly display data in the form of reports or simple charts, lacking multi-dimensional and visual situation awareness capabilities, and it is difficult to meet the needs of railway operation and maintenance personnel for real-time and interactive monitoring.

[0017] In response to the above challenges and deficiencies of the existing technologies, the present invention proposes a 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion. Summary of the Invention

[0018] The purpose of the present invention is to solve the corresponding technical problems raised in the above background technology, and provides a 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion.

[0019] The purpose of the present invention is achieved through the following solutions:

[0020] On the one hand, the solution of the present invention provides a 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion, including the following steps:

[0021] (1) Distributed data collection: Obtain the operation status information of the 5G-R network from multiple heterogeneous data sources through distributed collection devices, and the data sources include network device configuration data, alarm data, performance data, interface monitoring data, detection data, and auxiliary data;

[0022] (2) Data processing: Conduct centralized processing on the collected multi-source data, including data cleaning, data calculation, data association, and data reconstruction, and use data mining techniques to extract key features, trends, and patterns;

[0023] (3) Data sharing: Achieve seamless connection of data across regions and systems by uniformly storing, managing, and distributing multi-source data, and support collaborative analysis of real-time and historical data;

[0024] (4) Intelligent analysis: Based on artificial intelligence technology, perform anomaly detection, pattern recognition, and trend prediction on the processed data;

[0025] (5) Visualized situation awareness: Based on the results of intelligent analysis, achieve multi-dimensional situation awareness of network alarms, network operation quality, network operation and maintenance, and resource management through visualization technology.

[0026] Further, the distributed data collection in step (1) includes using terminal data collection devices, network data collection devices, interface monitoring devices, detection devices, and auxiliary collection devices, where:

[0027] The interface monitoring device collects northbound interface monitoring data, network-wide signaling, and service traffic monitoring data;

[0028] The detection device includes dynamic detection devices and static detection tools, which collect drive test data and third-party static detection data respectively.

[0029] Further, the data processing in step (2) includes:

[0030] Data cleaning: Process multi-source data through denoising and format conversion;

[0031] Data correlation: Use the Pearson correlation coefficient algorithm to calculate the linear relationship between alarm data and performance data. The formula is: , where r represents the Pearson correlation coefficient, which is used to measure the linear correlation between two sets of data; and respectively represent the th observation values in the two sets of data; and are respectively and means; is the total number of data samples;

[0032] Data mining: Use the FP-Growth algorithm to mine frequent item sets and association rules. The steps include constructing an FP tree and recursively mining frequent patterns.

[0033] Further, the intelligent analysis in step (4) includes root cause diagnosis of faults. The specific method is:

[0034] Use Bayesian divergence analysis to evaluate the correlation of fault events and calculate the conditional probability:

[0035] ;

[0036] Among them, represents the conditional probability of event A under the condition that event B occurs; Represents the likelihood probability of event B occurring under the condition that event A occurs; and are the prior probabilities of events A and B respectively;

[0037] Using a temporal point process (TPP) to analyze the failure time series, the intensity function is:

[0038] ;

[0039] where, represents the intensity of event occurrence at time t; is the baseline event occurrence rate, representing the basic intensity when there is no trigger; is the trigger function, describing the influence of the previous event on the current time t; N is the total number of historical events, is the time of the i-th historical event;

[0040] Based on Hawkes theory to identify the failure propagation path, the trigger function is:

[0041] ;

[0042] where, represents the trigger intensity parameter, used to measure the magnitude of the influence of event triggering; represents the decay rate parameter, used to describe the speed at which the trigger influence decays over time; represents the time difference between the current time t and the historical event time ;

[0043] Using a logistic regression graph neural network to predict the failure probability, the logistic regression formula is:

[0044] ;

[0045] where, represents the probability of failure occurrence x under the condition of the given input feature ; is the intercept term (bias term), is the regression coefficient, reflecting the influence of feature x on the failure probability; x is the input feature variable.

[0046] Furthermore, the network alarm situation awareness in step (5) includes alarm analysis, and the specific method is: analyzing alarm correlation through the Pearson algorithm and the FP-Growth algorithm;

[0047] Adopting temporal analysis to detect periodic anomalies, using the S-ARIMA model to predict the alarm trend, the formula is:

[0048] ;

[0049] Among them, represents the value of the time series at time t; c is the constant term; is the autoregressive parameter, indicating the influence of the lag values in the past p time steps on the current value; is the moving average parameter, indicating the influence of the white noise in the past q time steps on the current value; is at time t of the white noise error term;

[0050] The KL divergence (Kullback-Leibler divergence) is used to evaluate the difference in data distribution, and the formula is:

[0051] ;

[0052] Among them, represents the KL divergence of the probability distribution P with respect to , which is used to measure the information difference between the two distributions; and are the probability densities of the two probability distributions on the event x respectively.

[0053] Furthermore, the network operation quality perception in step (5) includes quality difference analysis. The specific method is:

[0054] Use the Gaussian mixture model (GMM) for self-learning of the quality difference index threshold. The probability density function is:

[0055] ;

[0056] Among them, represents the probability density of the observed value x ; K is the number of Gaussian components; is the mixing weight of the k-th Gaussian component, satisfying is the probability density function of the k-th Gaussian component, where is the mean vector, is the covariance matrix;

[0057] Use the decision tree algorithm to bound the quality difference problem and calculate the splitting feature based on information entropy:

[0058] ;

[0059] The information gain formula is:

[0060] ;

[0061] Among them, represents the information entropy of the dataset S; is the probability of class i; Represents the information gain brought by feature A; Is a subset of the values of feature A being v, And Are the number of samples in the subset and the total set respectively.

[0062] Furthermore, the network operation and maintenance situation awareness in step (5) includes predictive maintenance and business dial testing verification. The specific method is as follows:

[0063] Use regression analysis to predict the fault trend. The linear regression model is:

[0064] ;

[0065] Among them, y is the predicted fault trend value; Is the intercept (bias term); Is the regression coefficient, reflecting the influence of the independent variable x on the dependent variable y; x is the input feature variable, such as equipment operation time or performance index; Is the random error term;

[0066] Use a neural network to mine non - linear fault patterns. The activation function is:

[0067] ;

[0068] Among them, Is the output of the sigmoid activation function, and x is the input value, used to map the input to the interval [0,1];

[0069] Business dial testing verification uses Boxplot to detect outliers. The interquartile range formula is:

[0070] ;

[0071] The outlier range is Among them, Is the interquartile range; And Are the first quartile and the third quartile of the data respectively;

[0072] Use the N - sigma method to identify fluctuations. The standardized score formula is:

[0073] ;

[0074] Among them, Z is the standardized score; x is the observed value; Is the mean; Is the standard deviation;

[0075] Use the iForest algorithm to detect outliers. The outlier score formula is:

[0076] ;

[0077] Among them, is the anomaly score of the sample x ; is the average path length of all trees in the isolation forest for the sample x ; is the number of samples corresponding average path length constant, is the total number of samples.

[0078] Furthermore, the resource management situation awareness in step (5) includes dynamic resource visualization, and the specific method is:

[0079] Calculate network slice metrics through background algorithms, and detect abnormal fluctuations using the N-sigma method. The formula is the same as above;

[0080] Generate network topology visualization based on GIS data, and use information entropy to evaluate data distribution:

[0081] ;

[0082] Among them, represents the information entropy of the random variable x ; is the probability of the event ; is the total number of possible events.

[0083] Furthermore, the intelligent analysis in step (4) also includes anomaly detection, and the specific method is:

[0084] Adopt the iForest algorithm to identify abnormal patterns. The anomaly score formula is the same as above;

[0085] Use the Boxplot method to detect performance metric outliers. The formula is the same as above;

[0086] Use KL divergence to evaluate the difference in abnormal distribution. The formula is the same as above.

[0087] The present invention also provides a 5G-R network situation awareness system, including:

[0088] Distributed data acquisition devices for collecting multi-source data;

[0089] Data sharing and processing platforms for data preprocessing and sharing;

[0090] Intelligent analysis module, integrating Pearson algorithm, FP-Growth, Bayesian analysis, Temporal Point Process (TPP), Hawkes theory, Logistic Regression Graph Neural Network, Gaussian Mixture Model (GMM), Decision Tree, S-ARIMA, Boxplot, N-sigma, iForest, Regression Analysis, Neural Network and KL divergence technology, to perform anomaly detection and prediction;

[0091] Situation awareness module, providing visual display of network alarms, quality, operation and maintenance, and resource management;

[0092] User interface layer, supporting real-time monitoring and decision-making.

[0093] Compared with the prior art, the present invention has the following beneficial effects:

[0094] 1. The present invention deploys monitoring devices at multiple nodes (such as core network, radio network, base station, interface device) of the 5G-R network through distributed monitoring technology to collect multi-source heterogeneous data in real time, including network device configuration data, alarm data, performance data, interface monitoring data, detection data and GIS data, ensuring full network coverage and low-latency data acquisition. Combining multi-source information fusion technology (such as Pearson correlation coefficient, FP-Growth algorithm), integrating multi-dimensional data of the core network, radio network and dedicated devices, overcoming the disadvantages of limited data sources and insufficient real-time performance of traditional centralized monitoring, realizing comprehensive perception and rapid response to the operating state of the 5G-R network, and meeting the requirements of low latency (<1ms) and high reliability in railway scenarios;

[0095] 2. The present invention uses artificial intelligence and advanced statistical models (such as Bayesian divergence analysis, Temporal Point Process, Hawkes theory, Logistic Regression Graph Neural Network, Gaussian Mixture Model, S-ARIMA, iForest, etc.) to perform intelligent analysis on multi-source data, realizing anomaly detection, pattern recognition, trend prediction and root cause diagnosis of faults. For example, by and identifying the fault propagation path, and combining evaluating the fault correlation, significantly improving the accuracy and efficiency of fault location. Compared with the prior art, the present invention overcomes the limitation of single data source analysis, can predict potential faults (such as abnormal device load, degraded service quality), and provides strong support for predictive maintenance and network optimization;

[0096] 3. The present invention realizes multi-dimensional display of network alarms, operation quality, operation and maintenance, and resource management through visualization technology, using KL divergence (such as ) and information entropy (such as ) Evaluate the data integration, combine with the Ch data generation network to generate a topology graph. For example, when facing the three-dimensional human eyes in space-time, after the intersection, a surprising demand appears. As for the TD amber cloth, combine with the GIS data to generate a network topology graph to meet the needs of railway operation and maintenance personnel for real-time and interactive monitoring. For example, based on Boxplot and N-sigma (such as ) Detect performance anomalies, display alarm statistics and resource utilization rate through a large screen, significantly improve operation and maintenance efficiency and decision support capabilities, and overcome the deficiency of weak visualization support in the existing technology. BRIEF DESCRIPTION OF THE DRAWINGS

[0097] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0098] Figure 1 : Functional structure of the 5G-R network situation awareness system;

[0099] Figure 2 : Overall functional architecture of the 5G-R network situation awareness system;

[0100] Figure 3 : Schematic diagram of the 5G-R network situation awareness system based on multi-source data. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0101] The present invention provides a 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion. The following will describe its specific implementation process in detail in combination with the attached Figures 1 - 3 drawings and implementation cases, and explain the parameters in each formula in detail.

[0102] Embodiment: Distributed data collection: The first step of the present invention is distributed data collection. Obtain the operating status information from a variety of heterogeneous data sources of the 5G-R network through distributed collection devices, providing a basis for subsequent analysis.

[0103] Implementation process: Terminal data collection device: Deployed on terminal devices (such as user equipment, sensors), it collects the operating data of the terminal in real time, including performance data (such as throughput, latency, packet loss rate), configuration data (such as network parameters, channel settings), and alarm data (such as fault triggering, signal interruption). The collection frequency is once per second, and the data format is JSON or CSV.

[0104] Network data collection devices: Distributed on the core network, radio access network, and dedicated devices (such as base stations, core network elements, and bearer network devices), they collect status information. For example, they collect the RRC connection establishment success rate of base stations, PDU session establishment latency, and the load rate of the core network. The sampling interval is 5 seconds, and the data is transmitted through the SNMP protocol.

[0105] Interface monitoring devices: Through the northbound interface monitoring system, they collect network-wide signaling, traffic, and alarm data. For example, they use the Syslog protocol to obtain device logs or obtain performance metrics through the SNMP protocol. The collected content includes 5G control plane traffic, 5G user plane traffic, and network-wide signaling data, and the data volume can reach several TB per day.

[0106] Detection devices: Include dynamic detection devices (such as drive test vehicles) and static detection tools. Dynamic detection devices collect data such as network coverage, signal strength, and handover success rate along the railway line every hour; static detection tools collect base station static parameters (such as antenna configuration, frequency allocation) once a month.

[0107] Auxiliary collection devices: Collect GIS data (such as geographical location, railway distribution) and technical resume information (such as equipment installation records, maintenance history) to support the geographical correlation analysis of network topology and resource management. The data is updated in real time through the API interface.

[0108] Examples of data sources: OMC (Network Management Center) provides configuration data, alarm data, and performance data; TCE (Trace Collection Entity) provides monitoring data and network-wide signaling; MDT (Minimization of Drive Tests) data and wireless soft collection data are used for network coverage assessment. Through the above distributed collection method, it is ensured that multi-source heterogeneous data is collected in real time and comprehensively from multiple nodes across the network, laying a foundation for subsequent processing.

[0109] Data processing: Data processing is the centralized processing of the collected multi-source data, including data cleaning, data calculation, data association, and data reconstruction, and uses data mining techniques to extract key features, trends, and patterns.

[0110] Data cleaning: Denoise the multi-source data, remove noise data (such as outliers or redundant records), and identify and eliminate data that deviates from the mean by 3 times the standard deviation through statistical methods (such as mean filtering).

[0111] Convert data in CSV, JSON, or XML formats output by different devices into a unified structured format (such as table format) through format conversion to ensure data consistency. For example, convert the JSON format of base station alarm logs to CSV format, and the fields include timestamp, alarm type, device ID, etc.

[0112] Data Association: The Pearson correlation coefficient algorithm is used to calculate the linear relationship between alarm data and performance data. The formula is:

[0113] ;

[0114] where r represents the Pearson correlation coefficient, which is used to measure the linear correlation between two sets of data. The value range is [-1, 1]. 1 indicates a perfect positive correlation, -1 indicates a perfect negative correlation, and 0 indicates no correlation; and respectively represent the th observation values in the two sets of data, such as the base station throughput and the alarm frequency; and are respectively the and means of is the total number of data samples. For example, the total number of data samples collected every 5 seconds in a day is 17280.

[0115] Implementation Steps: Calculate the correlation between the base station throughput and the alarm frequency. If , it is considered that the two are highly correlated, and further analysis of potential causal relationships is required.

[0116] Data Mining: Use the FP-Growth algorithm to mine frequent item sets and association rules. The specific steps are as follows:

[0117] Determine the minimum support threshold (such as 0.01) and count the alarm data;

[0118] Construct a frequent pattern tree (FP tree) to compress data and store frequent items. For example, record the frequent combinations of base station failures and signal interruptions;

[0119] Recursively mine the FP tree to extract frequent item sets (such as "Base Station A Failure + Signal Interruption" with a support of 0.015) and association rules (such as "Base Station A Failure → Signal Interruption" with a confidence of 0.85).

[0120] Application Scenario: Identify the alarm combinations that frequently occur across the network and their associations with network failures for optimizing alarm management.

[0121] Data Reconstruction: According to the Pearson correlation coefficient and the FP-Growth mining results, associate multi-source data and reconstruct it into a structured data set. For example, integrate base station alarm data, performance data, and interface monitoring data into a time series table with fields including timestamp, alarm type, throughput, latency, etc., to support subsequent intelligent analysis.

[0122] Data Sharing: Data sharing realizes collaborative analysis across regions and systems by uniformly storing, managing, and distributing multi-source data.

[0123] Implementation process: Establish a centralized data sharing platform, and use a distributed database (such as Hadoop HDFS) and cloud storage technology to store real-time and historical data. The storage capacity supports several terabytes of data per day.

[0124] Use a message queue (such as Apache Kafka) to achieve real-time data distribution, ensure seamless data transfer between different network regions (such as railway backbone networks and local area networks), and control the transmission delay within 100 ms.

[0125] Support cross-system data interaction. For example, integrate the configuration data of OMC and the monitoring data of TCE, and provide a unified data view for the intelligent analysis module through the API interface.

[0126] Application scenarios: Real-time data is used for dynamic response to network alarms. For example, distribute base station alarm data to the operation and maintenance team; historical data is used for trend prediction and fault cause analysis. For example, analyze the network performance changes in the past 30 days.

[0127] Intelligent analysis: Intelligent analysis performs anomaly detection, pattern recognition, trend prediction, and fault diagnosis based on artificial intelligence technology.

[0128] Fault root cause diagnosis: Bayesian divergence analysis: Evaluate the correlation of fault events and calculate the conditional probability:

[0129] ;

[0130] Among them, represents the conditional probability of event A under the condition that event B occurs. For example, the probability of base station fault A when network coverage drops B occurs; represents the likelihood probability of event B under the condition that event A occurs; and are the prior probabilities of events A and B respectively, obtained based on historical data statistics. For example, assume , , , then , indicating a high correlation between base station faults and coverage drops.

[0131] Implementation steps: Input base station alarm logs and performance data, calculate the correlation between base station faults and network coverage drops. If , then trigger further diagnosis.

[0132] Temporal Point Process (TPP): Analyze the fault time series, and the intensity function is:

[0133] ;

[0134] Among them, Denote the event occurrence intensity at time t, such as the occurrence frequency of base station failures; is the baseline event incidence rate, which is obtained based on historical data (e.g., 0.5 failures per hour); is the triggering function, which describes the impact of the previous event on the current time t; N is the total number of historical events, is the time of the i-th historical event.

[0135] Implementation steps: Collect the base station failure timestamps in the past 24 hours, set , and fit through historical data to predict the failure probability in the next 1 hour.

[0136] Hawkes theory: Identify the failure propagation path, and the triggering function is:

[0137] ;

[0138] Among them, represents the triggering intensity parameter, and its value range is [0, 1]. For example, 0.7 indicates a strong triggering impact; represents the decay rate parameter, and its value range is [0, 1]. For example, 0.7 indicates that the triggering impact decays slowly over time; is the time difference (in hours) between the current time t and the historical event time .

[0139] Implementation steps: Input the base station failure time series, set , , calculate the failure propagation path, and identify the key failure sources (such as core network element failures leading to base station chain reactions).

[0140] Logistic regression graph neural network: Predict the failure probability, and the logistic regression formula is:

[0141] ;

[0142] Among them, represents the probability of failure occurrence under the condition of the given input feature x; is the intercept term (bias term), and its value is obtained by fitting through training data (such as -0.5); is the regression coefficient, which reflects the impact of the feature x on the failure probability, and is obtained based on the device load rate data (such as 0.3); x is the input feature variable, such as the device load rate (0% - 100%).

[0143] Implementation steps: Input the base station load rate data for 24 hours, train the model to predict the failure probability, and if , then trigger an early warning.

[0144] Alarm analysis: Pearson algorithm and FP-Growth: Analyze alarm correlation. For example, calculate the correlation between the base station throughput and the alarm frequency. If , then further use FP-Growth to mine frequent item sets, such as the support of "throughput drop + signal interruption" is 0.015,

[0145] S-ARIMA model: Predict the alarm trend. The formula is:

[0146] ;

[0147] Among them, is the time series value, such as the number of alarms every 5 seconds; c is the constant term, with a value of 0; is the autoregressive parameter, fitted based on historical data (such as ); is the moving average parameter (such as ); is the white noise error term, following a Gaussian distribution with a mean of 0 and a variance of 1.

[0148] Implementation steps: Input the alarm time series of the past 24 hours, set , , predict the number of alarms in the next 1 hour. If the predicted value exceeds the threshold (such as 10 times / hour), trigger an alarm.

[0149] KL divergence: Evaluate the difference in data distribution. The formula is:

[0150] ;

[0151] Among them, represents the KL divergence of the probability distribution P relative to , used to measure the information difference between the two distributions; and are the probability densities of the normal distribution and the current distribution at the event (such as the alarm type), respectively. For example, is the alarm distribution in the past 24 hours, is the alarm distribution in the current 1 hour. If , then a distribution anomaly is detected.

[0152] Network operation quality perception (quality difference analysis): GMM algorithm: Perform self-learning of the quality difference index threshold. The probability density function is:

[0153] ;

[0154] Among them, Represents the probability density of the observed value x (such as service latency); K is the number of Gaussian components, set to 3; is the mixing weight of the k-th Gaussian component, satisfying

[0155] , for example 、 、 is the probability density function of the k-th Gaussian component, where is the mean vector

[0156] (such as 、 ), is the covariance matrix (such as a diagonal matrix, ).

[0157] Implementation steps: Input 24-hour service latency data, train the GMM model, determine the threshold (such as mean + 3 standard deviations), if the latency exceeds 35ms, then mark it as poor quality.

[0158] Decision tree algorithm: Define the problem of poor quality boundary, calculate the splitting feature based on information entropy:

[0159] ;

[0160] The information gain formula is:

[0161] ;

[0162] Among them, represents the information entropy of the dataset S (such as service latency samples); is the probability of class i (such as normal / abnormal); represents the information gain brought by feature A (such as latency value); is the subset of the values v of feature A, and are the number of samples of the subset and the total set respectively. For example, input latency data, construct a decision tree, if the latency > 35ms, then classify it as abnormal and output the reason for poor quality (such as network congestion).

[0163] Network operation and maintenance situation awareness (predictive maintenance and business dial test verification):

[0164] Regression analysis: Predict the fault trend, and the linear regression model is:

[0165] ;

[0166] Among them, y is the predicted fault trend value, such as the number of faults in the next 24 hours; is the intercept, and the value is fitted based on historical data (such as 5); is the regression coefficient, reflecting the impact of the independent variable x (such as the equipment operation time, unit: hour) on y, and the fitting value (such as 0.2); is the random error term, following a Gaussian distribution with a mean of 0 and a variance of 1.

[0167] Implementation steps: Input the equipment operation time and the number of failures in the past 30 days, train the model to predict the number of future failures, and if the predicted value > 10 times / day, trigger a maintenance warning.

[0168] Neural network: Mine non-linear fault patterns, and the activation function is:

[0169] ;

[0170] where is the output of the sigmoid activation function, x is the input value (such as the equipment load rate), used to map the input to the [0,1] interval. Through training with a multi-layer neural network (input layer, hidden layer, output layer), the number of hidden layer nodes is 64, the learning rate is set to 0.01, and training is carried out for 1000 rounds.

[0171] Implementation steps: Input the equipment load rate and historical fault data, predict the fault probability, and if the probability > 0.7, trigger a warning.

[0172] Business dial test verification: Boxplot: Detect outliers, and the interquartile range formula is:

[0173] ;

[0174] The outlier range is where is the interquartile range; and are the first and third quartiles respectively.

[0175] For example, input 24-hour performance KPI (throughput) data, calculate , , then , the outlier range is [20Mbps, 100Mbps], and if the observed value < 20Mbps or > 100Mbps, it is marked as an outlier.

[0176] N-sigma: Identify fluctuations, and the standardized score formula is: ;

[0177] where Z is the standardized score; x is the observed value, such as throughput; is the mean, taking a value based on historical data (such as 60Mbps); is the standard deviation, taking a value (such as 10Mbps). If

[0178] , it is marked as an anomaly.

[0179] iForest: Detect anomalies, and the anomaly score formula is:

[0180] ;

[0181] Among them, is the anomaly score of sample x, with a value range of [0, 1]. The higher the score, the more anomalous; is the average path length of all trees of sample x in the isolation forest; is the number of samples The average path length constant of (such as 1000 samples) is calculated as ;

[0182] Among them, is the harmonic number.

[0183] Implementation steps: Input performance KPl data, set the number of subsamples to 256, the number of trees to 100, calculate the anomaly score, if , it is marked as an anomaly.

[0184] Resource management situation awareness: Dynamic resource visualization: Calculate network slice metrics through background algorithms, and use the N-sigma method to detect abnormal fluctuations. The formula is the same as above.

[0185] Network topology visualization: Generate a visualization graph based on GIS data and network device topology data, and evaluate the data distribution in combination with information entropy:

[0186] ;

[0187] Among them, represents the information entropy of the random variable X (such as resource utilization rate); is the probability of the event (such as the utilization rate interval); is the total number of possible events (such as 10 utilization rate intervals). For example, calculate the distribution of resource utilization rate. If , the distribution is relatively concentrated, and there may be a resource bottleneck.

[0188] Visualization situation awareness: Visualization situation awareness is based on the results of intelligent analysis and realizes multi-dimensional network management through visualization technology.

[0189] Network alarm situation awareness: Provide a display of the entire network's alarms, including multi-dimensional alarm analysis of the railway backbone network and local area network. Use a large screen to display alarm statistics (bar chart) and root cause diagnosis results (relationship diagram), and detect distribution anomalies in combination with KL divergence. For example, input 24-hour alarm data. If , the abnormal area is marked on the map.

[0190] Network operation quality perception: Based on GMM and decision tree, evaluate the quality of network elements, network and services, and generate a quality evaluation report (pie chart). For example, input 5G user plane code stream data, train the GMM model to determine the threshold. If the latency > 35ms, it is marked as a red area on the dashboard, and the reason (such as network congestion) is output in combination with the decision tree.

[0191] Network operation and maintenance situation perception: Realize intelligent inspection and predictive maintenance, and display the construction, obstacle and work order progress through visualization (Gantt chart). Use Boxplot and N-sigma to detect performance anomalies. For example, input base station KPI data. If , the abnormal base station is marked on the map.

[0192] Resource management situation perception: Provide visual displays of static, dynamic resources and network topology (heat map, topology map). Generate a network topology map associated with geographical locations based on GIS data, and evaluate resource distribution in combination with information entropy. For example, input resource utilization data. If , the resource bottleneck area is highlighted in the topology map.

[0193] System implementation: The implementation of the present invention is a 5G-R network situation awareness system, including the following modules: Distributed data collection device: Deployed on network nodes (such as base stations, core network elements), uses sensors and network management interfaces to collect multi-source data, and the data is transmitted through the 5G network, updated once per second.

[0194] Data sharing and processing platform: Adopts a distributed database (such as Hadoop HDFS) and cloud storage technology, stores several TB of data daily, and realizes real-time distribution through Kafka, with a latency < 100ms.

[0195] Intelligent analysis module: Integrates Pearson algorithm, FP-Growth, Bayesian analysis, temporal point process (TPP), Hawkes theory, logistic regression graph neural network, Gaussian mixture model (GMM), decision tree, S-ARIMA, Boxplot, N-sigma, iForest, regression analysis, neural network and KL divergence technology, runs on a GPU server, and the processing time < 1 second per batch.

[0196] Situation awareness module: Displays the analysis results through the Web front-end and large screen, uses D3.js and ECharts to generate visual charts, and supports real-time refresh (once every 5 seconds).

[0197] User interface layer: Provides Web and mobile interfaces, supports real-time monitoring, alarm viewing and decision support, and the response time < 500ms.

[0198] Implementation Case: Taking the railway 5G-R network as an example, the specific applications of each functional module are described in detail as follows:

[0199] Network Alarm Situation Awareness: Collect alarm data from the core network and radio network (100,000 pieces per day), calculate the correlation between throughput and alarm frequency using the Pearson algorithm. If , then further use FP-Growth to mine frequent item sets, and find that the support degree of "throughput decrease + signal interruption" is 0.015. Use S-ARIMA to predict the number of alarms in the next 1 hour. If the predicted value > 10 times / hour, then trigger an alarm and mark the abnormal base station on the map. Use KL divergence to evaluate the alarm distribution. If , then it is detected that the distribution is abnormal and a report is output.

[0200] Network Operation Quality Awareness: Collect 5G user plane code stream and control plane code stream data (5TB per day), use GMM to train the quality difference model, and set , , , and determine that the delay threshold is 35ms. If the delay > 35ms, then use decision tree to analyze the reason, and based on information entropy and gain , it is output that network congestion is the main reason.

[0201] Network Operation and Maintenance Situation Awareness: Collect base station performance KPIs (1 million pieces per day), use Boxplot to detect throughput anomalies, calculate , , , and the abnormal range is [20Mbps, 100Mbps]. If the observed value < 20Mbps, use N-sigma to calculate , and mark it as abnormal. Use regression analysis to predict the number of faults, and set , . If the predicted value > 10 times / day, then trigger a maintenance warning. Use iForest to detect abnormal load rates. If , then mark it as an abnormal base station.

[0202] Resource Management Situation Awareness: Collect resource utilization data of network devices and SIM cards (500,000 pieces per day), use N-sigma to calculate , and detect resource bottlenecks. Generate a topology map based on GIS data, and use information entropy to evaluate the resource distribution. If , then highlight the bottleneck area in the topology map.

[0203] Through the above detailed implementation methods, the present invention realizes the all-round situation awareness of the 5G-R network, and improves the network stability and operation and maintenance efficiency.

[0204] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion, characterized in that It includes the following steps: (1) Distributed data collection: Obtain the operation status information of the 5G-R network from multiple heterogeneous data sources through distributed collection devices. The data sources include network device configuration data, alarm data, performance data, interface monitoring data, detection data, and auxiliary data; (2) Data processing: Centralize the processing of the collected multi-source data, including data cleaning, data calculation, data association, and data reconstruction, and use data mining techniques to extract key features, trends, and patterns; (3) Data sharing: Achieve seamless connection of data across regions and systems by uniformly storing, managing, and distributing multi-source data, and support collaborative analysis of real-time and historical data; (4) Intelligent analysis: Perform anomaly detection, pattern recognition, and trend prediction on the processed data based on artificial intelligence technology; (5) Visualized situation awareness: Based on the results of intelligent analysis, realize multi-dimensional situation awareness of network alarms, network operation quality, network operation and maintenance, and resource management through visualization technology.

2. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, characterized in that, The distributed data collection in step (1) includes using terminal data collection devices, network data collection devices, interface monitoring devices, detection devices, and auxiliary collection devices, where: The interface monitoring device collects northbound interface monitoring data, full-network signaling, and service traffic monitoring data; The detection device includes dynamic detection devices and static detection tools, which respectively collect road test data and third-party static detection data.

3. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, characterized in that, The data processing in step (2) includes: Data cleaning: Process multi-source data through denoising and format conversion; Data association: Use the Pearson correlation coefficient algorithm to calculate the linear relationship between alarm data and performance data. The formula is: ; Among them, r represents the Pearson correlation coefficient, which is used to measure the linear correlation between two sets of data; and respectively represent the th observations in the two sets of data; and are respectively the and means of; is the total number of data samples; Data mining: Use the FP-Growth algorithm to mine frequent item sets and association rules. The steps include constructing an FP tree and recursively mining frequent patterns.

4. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, characterized in that, The intelligent analysis in step (4) includes root cause diagnosis of faults. The specific method is: Use Bayesian divergence analysis to evaluate the relevance of fault events and calculate the conditional probability: ; Among them, represents the conditional probability of event A given that event B has occurred; represents the likelihood probability of event B given that event A has occurred; and are the prior probabilities of events A and B; Use a temporal point process to analyze the fault time series. The intensity function is: ; Among them, represents the event occurrence intensity at time t; is the baseline event incidence rate, representing the basic intensity without triggering; is the trigger function, describing the influence of the previous event on the current time t; N is the total number of historical events, is the time of the i-th historical event; Identify the fault propagation path based on the Hawkes theory. The triggering function is: ; Among them, represents the trigger intensity parameter, which is used to measure the magnitude of the impact of event triggering; represents the decay rate parameter, which is used to describe the speed at which the trigger impact decays over time; represents the time difference between the current time t and the historical event time ; Use a logistic regression graph neural network to predict the fault probability. The logistic regression formula is: ; Among them, represents the probability of a fault occurring under the condition of a given input feature x ; is the intercept term (bias term), is the regression coefficient, reflecting the influence of feature x on the fault probability; x is the input feature variable.

5. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, characterized in that, The network alarm situation awareness in step (5) includes alarm analysis. The specific method is: Analyze alarm relevance through the Pearson algorithm and the FP-Growth algorithm; Use time series analysis to detect periodic anomalies and use the S-ARIMA model to predict alarm trends. The formula is: ; where, represents the value of the time series at time t; c is the constant term; is the autoregressive parameter, indicating the impact of the lagged values in the past p time steps on the current value; is the moving average parameter, indicating the impact of the white noise in the past q time steps on the current value; is the white noise error term at time t; Use KL divergence to evaluate the difference in data distribution. The formula is: ; Among them, represents the KL divergence of the probability distribution P with respect to , which is used to measure the information difference between the two distributions; and are the probability densities of the two probability distributions on the event x, respectively.

6. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, wherein, The network operation quality awareness in step (5) includes quality difference analysis. The specific method is: Use a Gaussian mixture model for self-learning of quality difference index thresholds. The probability density function is: ; Among them, represents the probability density of the observed value x; K is the number of Gaussian components; is the mixing weight of the k-th Gaussian component, satisfying is the probability density function of the k-th Gaussian component, where is the mean vector, is the covariance matrix; Use a decision tree algorithm to delimit quality difference problems and calculate split features based on information entropy: ; The information gain formula is: ; Among them, represents the information entropy of the dataset S; is the probability of class i; represents the information gain brought by feature A; is a subset of the values v of feature A, and are the number of samples in the subset and the total set, respectively.

7. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, characterized in that The network operation and maintenance situation awareness in step (5) includes predictive maintenance and service dial test verification. The specific method is: Use regression analysis to predict fault trends. The linear regression model is: ; Among them, y is the predicted fault trend value; is the intercept (bias term); is the regression coefficient, reflecting the influence of the independent variable x on the dependent variable y; x is the input feature variable, such as equipment operation time or performance index; is the random error term; Use a neural network to mine non-linear fault patterns. The activation function is: ; Among them, is the output of the sigmoid activation function, and x is the input value, which is used to map the input to the interval [0, 1]; Business dial test verification uses Boxplot to detect outliers, and the interquartile range formula is: ; The abnormal range is , where is the interquartile range; and are the first quartile and the third quartile of the data, respectively; Use the N-sigma method to identify fluctuations, and the standardized score formula is: ; Among them, Z is the standardized score; x is the observed value; is the mean value; is the standard deviation; Adopt the iForest algorithm to detect anomalies, and the anomaly score formula is: ; Among them, is the anomaly score of sample x; is the average path length of all trees of sample x in the isolation forest; is the number of samples corresponding average path length constant, is the total number of samples.

8. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, characterized in that, The resource management situation awareness in step (5) includes dynamic resource visualization, and the specific method is: Calculate network slice metrics through background algorithms, and use the N-sigma method to detect abnormal fluctuations. The formula is the same as above; Generate network topology visualization based on GIS data, and use information entropy to evaluate data distribution: ; Among them, represents the information entropy of the random variable X; is the probability of the event ; is the total number of possible events.

9. The 5G-R network situation awareness method based on distributed monitoring and multi-source information fusion according to claim 1, characterized in that, The intelligent analysis in step (4) also includes anomaly detection, and the specific method is: Adopt the iForest algorithm to identify anomaly patterns, and the anomaly score formula is the same as above; Use the Boxplot method to detect performance metric outliers. The formula is the same as above; Use KL divergence to evaluate the difference in abnormal distribution. The formula is the same as above.

10. A 5G-R network situation awareness system based on the method according to any one of claims 1-9, characterized in that, Include: Distributed data acquisition devices for collecting multi-source data; Data sharing and processing platforms for data preprocessing and sharing; Intelligent analysis modules that integrate Pearson algorithms, FP-Growth, Bayesian analysis, point process in time series, Hawkes theory, logical regression graph neural networks, Gaussian mixture models, decision trees, S-ARIMA, Boxplot, N-sigma, iForest, regression analysis, neural networks, and KL divergence techniques to perform anomaly detection and prediction; Situation awareness modules that provide visual displays of network alarms, quality, operation and maintenance, and resource management; User interface layers that support real-time monitoring and decision-making.

Citation Information

Patent Citations

  • A network security situation awareness method and system based on a fusion decision

    CN109766695A

  • Network lag prediction method and device, electronic equipment, medium and program product

    CN116915630A

  • Prediction model generation method and device, article recommendation method and device, equipment and medium

    CN117290599A

  • Computer network security analysis method and system based on big data

    CN118555117A

  • Intelligent root cause analysis and alarm method based on unsupervised decision model

    CN119691699A

Cited By

  • Concentrator network switching decision-making system and method based on communication quality evaluation

    CN120786360A

  • Fault root cause positioning method and system for server cluster

    CN120915654A

  • A method and system for failure root cause localization for server clusters

    CN120915654B

  • Railway communication network early warning method and system based on intrusion detection

    CN121174152A