Rapid multi-laboratory dynamic inspection system

By using low-drift crystal oscillators to generate trusted timestamps in the multi-laboratory inspection system, and combining lightweight time base synchronization and time chain segment proof mechanisms, the problems of inconsistent clock references and redundant alarms are solved, time consistency and data deduplication across laboratories are achieved, and the system's scheduling efficiency and response accuracy are improved.

CN120639808APending Publication Date: 2025-09-12NANCHANG XIEDA TECH DEV CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510942824.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-09
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

There are problems with inconsistent clock references and redundant alarm data in the multi-laboratory inspection system, which makes data synchronization and scheduling difficult and makes it difficult to adapt to the complex alarm processing requirements under the heterogeneous distributed inspection system.

Method used

A low-drift crystal oscillator local clock source is used to generate a trusted timestamp, and combined with a lightweight time base synchronization mechanism and a time chain segment proof mechanism, data encapsulation and aggregation analysis are performed through a multi-source alarm aggregation and deduplication unit, task sorting is performed by a dynamic priority scheduling unit, and data consistency verification is performed by a chain traceability audit verification unit, thus achieving time consistency and data deduplication across laboratories.

Benefits of technology

It achieves unified and reliable time anchoring without external network synchronization, effectively removes redundant alarm data, and improves the scheduling efficiency and response accuracy of the multi-laboratory dynamic inspection system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639808A_ABST
    Figure CN120639808A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of multi-laboratory inspection, in particular to a quick multi-laboratory dynamic inspection system. The method comprises the following steps: a credible timestamp encapsulation unit encapsulates inspection alarm data of each laboratory into a time chain proving data packet in combination with a lightweight time base synchronization mechanism and a time chain segment proving mechanism; the multi-source alarm aggregation de-duplication unit is used for screening a time consistent candidate set, performing aggregation analysis on the time consistent candidate set, and establishing an alarm event similar graph of inspection alarm events; the dynamic priority scheduling unit analyzes a potential influence path of a main alarm event by using an alarm event propagation graph modeling mechanism, and performs dynamic priority ranking on the main alarm event to generate an inspection task queue; and the chained traceability audit verification unit performs chained traceability verification on the main alarm event and the subordinate alarm event and generates a tamper-proof audit record. According to the invention, rapid inspection of unified trusted time anchoring, alarm aggregation de-duplication and dynamic priority scheduling under multiple laboratories is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of multi-laboratory inspection, and in particular to a fast multi-laboratory dynamic inspection system. Background Art

[0002] In current technical fields such as industrial automation, environmental monitoring, emergency response, and equipment reliability testing, multi-laboratory joint inspection systems have gradually become an important model for solving cross-unit joint assessments, distributed anomaly detection, and collaborative laboratory management. Especially in high-risk and high-precision scenarios, each laboratory deploys different types of sensors and intelligent devices to perform periodic or event-driven alarm inspections on preset indicators, and simultaneously uploads relevant alarm information to a unified central platform for scheduling, analysis, and disposal. Multi-laboratory inspection systems usually need to achieve cross-node data fusion, unified alarm judgment, and dispatch instruction distribution, and have extremely high requirements for the time consistency and content consistency of alarm data.

[0003] In the process of synchronizing and scheduling alarm data among multiple laboratories, there are currently two key issues. First, due to the physical dispersion, unstable network connections, and the use of equipment from different manufacturers among multiple laboratories, the clock references are inconsistent, and the inspection alarm data lacks a unified and reliable time anchor point. Second, the same alarm event may be repeatedly reported in multiple laboratories with different trigger mechanisms or different parameter expressions, forming redundant alarm data sets with similar time but slightly different semantics. Existing technologies mostly focus on traditional time synchronization protocols or templated alarm merging mechanisms, which are difficult to adapt to the complex alarm processing requirements under heterogeneous distributed inspection systems. Summary of the Invention

[0004] The purpose of the present invention is to provide a fast multi-laboratory dynamic inspection system to solve the two key problems raised in the above background technology.

[0005] To achieve the above objectives, the invention aims to provide a fast multi-laboratory dynamic inspection system, comprising:

[0006] Trusted timestamp encapsulation unit: The trusted timestamp encapsulation unit uses a low-drift crystal oscillator local clock source to generate the original timestamp, and combines a lightweight time base synchronization mechanism and a time chain segment proof mechanism to encapsulate each laboratory inspection alarm data into a time chain proof data packet, and embeds a unified time base field in each time chain proof data packet;

[0007] Multi-source alarm aggregation and deduplication unit: The multi-source alarm aggregation and deduplication unit is used to perform timestamp consistency detection on the time chain proof data packet to screen the time consistent candidate set, and use the Alarm-Fusion deduplication algorithm to aggregate and analyze the time consistent candidate set, establish the alarm event similarity graph of the inspection alarm event, and obtain the main alarm event;

[0008] Dynamic priority scheduling unit: The dynamic priority scheduling unit uses the alarm event propagation graph modeling mechanism to analyze the potential impact path of the main alarm event, calculates the comprehensive value score of the main alarm event, and dynamically prioritizes the main alarm events to generate an inspection task queue;

[0009] The chain traceability audit verification unit verifies the consistency of all patrol alarm data, performs chain traceability verification on the main alarm event and its subordinate alarm events, and generates tamper-proof audit records.

[0010] Preferably, the low-drift crystal oscillator local clock source is a hardware clock source constructed using a temperature-compensated crystal oscillator, which is used to provide a stable clock reference with long-term drift in a cross-laboratory deployment environment, and periodically refresh the original timestamp value through an embedded controller to obtain the original timestamp;

[0011] The original timestamp is the reference timestamp for collecting inspection alarm data in each laboratory.

[0012] Preferably, the lightweight time base synchronization mechanism specifically includes:

[0013] The control center periodically broadcasts beacon frames containing a unified time reference; each laboratory inspection device receives the beacon frame and compares it with the original timestamp to calculate the local clock drift ΔT; the exponential sliding average algorithm is used to correct the time deviation of the original timestamp to eliminate the local clock drift ΔT.

[0014] Preferably, the time chain segment proof mechanism is used to structure and encapsulate the inspection alarm data of each laboratory into a time chain proof data packet, as follows:

[0015] Add a hash summary field H to each patrol alarm data prev ;

[0016] Calculate the hash fingerprint value H through the anti-collision algorithm curr ;

[0017] Combine the original timestamp and inspection alarm data to build the four-tuple data structure {T,H prev ,H curr ,D}, T is the original timestamp, D is the inspection alarm data;

[0018] Among them, the inspection alarm data of each laboratory is obtained based on the perception and collection of distributed sub-inspection equipment, including alarm type label, alarm location code, equipment identification code and trigger parameter value range.

[0019] Preferably, in the multi-source alarm aggregation and deduplication unit, the timestamp consistency detection is specifically as follows:

[0020] Sort all time chain proof data packets in ascending order by original timestamp T;

[0021] Set a fixed time window Δt as the unit to divide the time interval, where the fixed time window Δt is smaller than the main control platform cycle;

[0022] If the time chain proof data packets in the same divided time interval are determined to be the same alarm event, then in the same alarm event, the set of inspection alarm data to which all time chain proof data packets belong constitutes a time consistency candidate set.

[0023] Preferably, the Alarm-Fusion deduplication algorithm is a multi-source alarm event fusion algorithm based on timestamp consistency and semantic feature clustering. The Alarm-Fusion deduplication algorithm analyzes the semantic similarity of patrol alarm data and constructs an alarm event similarity graph based on the time-consistent candidate set, as follows:

[0024] Extract the alarm type label, alarm location code, device identification code and trigger parameter value interval of all inspection alarm data in the time-consistent candidate set as feature vectors;

[0025] Use weighted vector edit distance to calculate the semantic similarity score between any two patrol alarm data in the time consistent candidate set;

[0026] A bidirectional edge relationship is constructed between two patrol alarm data whose semantic similarity score is greater than the set threshold to obtain an alarm event similarity graph;

[0027] The node with the largest degree in the alarm event similarity graph is extracted as the main alarm event, and the remaining nodes are subordinate alarm events. The edge relationship between the main alarm event and the subordinate alarm event is the master-slave relationship index.

[0028] Preferably, in the dynamic priority scheduling unit, the alarm event propagation graph modeling mechanism is a directed graph structure modeling method constructed based on the alarm position codes and original timestamps between the main alarm events in the patrol alarm data, which is used to identify the potential impact paths of the main alarm events in each laboratory space; the alarm event propagation graph modeling mechanism is specifically as follows:

[0029] A potential impact path diagram is constructed based on the spatial adjacency dimension and the temporal proximity dimension, with the main alarm events as nodes in the diagram. If the alarm location codes of two main alarm events belong to the same physical space topologically connected area, and the interval between the original timestamps of the two main alarm events is less than the set propagation delay threshold, a directed edge is established between the two nodes, and finally a potential impact path diagram is obtained. The direction of the directed edge is from the main alarm event node with an earlier original timestamp to the main alarm event node with a later original timestamp.

[0030] Preferably, the comprehensive value score of the main alarm event is calculated as follows:

[0031] S value =w1·L impact +w2·C device +w3·R position +w4·F topo ;

[0032] Among them, S value Score for comprehensive value; L impact C is the longest path length of the main alarm event in the propagation diagram; device The criticality coefficient of the equipment associated with the main alarm event; R position Risk area score for the alarm location code; F topo The connectivity factor of the main alarm event in the spatial topological structure; w1, w2, w3 and w4 are all weight coefficients.

[0033] Preferably, the inspection task queue is used to construct a multi-laboratory dynamic inspection scheduling strategy, and the specific generation steps are as follows:

[0034] Score all main alarm events according to their comprehensive value S value Sort in descending order and set the dynamic task execution threshold S th , for one of the main alarm events when S value >S th When the main alarm event is detected, it is marked as a high-priority task and added to the front of the queue. The remaining main alarm events are arranged in ascending order according to the original timestamps to fill the end of the queue.

[0035] Preferably, the chain traceability audit verification unit includes a full data consistency verification module and a master-slave alarm traceability audit module;

[0036] Among them, the full data consistency verification module is used to perform hash chain structure verification on all time chain proof data packets. If any two adjacent time chain proof data packets meet H prev ≠H curr , then it is determined that data tampering has occurred and an audit anomaly label is generated;

[0037] The master-slave alarm tracing audit module is used to perform chain tracing verification on the master alarm event and its slave alarm events and generate tamper-proof audit records, as follows:

[0038] Traverse the time chain proof data packets of all main alarm events and their subordinate alarm events to verify whether the original timestamp satisfies the monotonically increasing relationship; use the chain hash structure to recalculate the hash fingerprint value H curr ;Write the master-slave relationship index between the main alarm event and the slave alarm event into the audit log structure to generate tamper-proof audit records.

[0039] Compared with the prior art, the above technical solution of the present invention has the following beneficial technical effects:

[0040] 1. In this invention, based on a low-drift crystal oscillator local clock source and a time chain certification mechanism, unified and trusted time anchoring of inspection alarm data can be achieved without external network synchronization, solving the problems of large clock drift and time misalignment in multiple laboratories.

[0041] 2. In the present invention, based on timestamp consistency and Alarm-Fusion deduplication algorithm, master-slave index division and cluster deduplication are realized for inspection alarm data that are repeatedly reported and semantically similar in multiple laboratories, effectively avoiding scheduling task redundancy, resource waste and misadjustment risks, and improving the overall scheduling efficiency and response accuracy of the multi-laboratory dynamic inspection system. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Figure 1 A functional block diagram of an embodiment of the present invention;

[0043] Figure numerals: 1. Trusted timestamp encapsulation unit; 2. Multi-source alarm aggregation and deduplication unit; 3. Dynamic priority scheduling unit; 4. Chain traceability audit verification unit; 41. Full data consistency verification module; 42. Master-slave alarm traceability audit module. DETAILED DESCRIPTION

[0044] Example 1, as Figure 1 As shown, a fast multi-laboratory dynamic inspection system is provided, including:

[0045] Trusted timestamp encapsulation unit 1 uses a low-drift crystal oscillator local clock source to generate the original timestamp, and combines a lightweight time base synchronization mechanism and a time chain segment proof mechanism to encapsulate each laboratory inspection alarm data into a time chain proof data packet, and embeds a unified time base field in each time chain proof data packet;

[0046] The low-drift crystal oscillator local clock source is a hardware clock source constructed using a temperature-compensated crystal oscillator, which is used to provide a stable clock reference with long-term drift in a cross-laboratory deployment environment, and periodically refresh the original timestamp value through the embedded controller to obtain the original timestamp;

[0047] The original timestamp is the reference timestamp for collecting inspection alarm data in each laboratory.

[0048] In this embodiment, the local time generation mechanism adopted by the trusted timestamp encapsulation unit 1 is based on an embedded local clock source constructed with a set of low-drift crystal oscillators. The frequency deviation rate of the crystal oscillator under a standard experimental environment of 25°C does not exceed ±5ppm. It can achieve long-term stable output of the time base of each inspection node without an external network connection, and embed the time value into the sampled data through hardware-level time caching to form the original timestamp field.

[0049] In this embodiment, the lightweight time base synchronization mechanism specifically includes:

[0050] The control center periodically broadcasts beacon frames containing a unified time reference; each laboratory inspection device receives the beacon frame and compares it with the original timestamp to calculate the local clock drift ΔT; the exponential sliding average algorithm is used to correct the time deviation of the original timestamp to eliminate the local clock drift ΔT.

[0051] In this embodiment, the control center is a unified scheduling and time publishing node deployed in the multi-laboratory inspection network, which is used to periodically broadcast synchronization control information to each sub-inspection device, distribute a unified time base, provide a centralized time anchor point and alarm event scheduling commands; the beacon frame containing the unified time base is a time synchronization broadcast message generated by the control center, which contains the current standard timestamp field and frame sequence number field of the central control node, and is used to be received by each laboratory inspection device and then compared with the original time value generated locally to realize local clock deviation correction; the exponential sliding average algorithm is a low-computational synchronous filtering method for dynamically correcting the local time error of the device, which is used to suppress time fluctuation jitter, enhance time convergence stability, and avoid resource consumption caused by high-frequency communication.

[0052] In this embodiment, the time chain segment proof mechanism is used to structure and encapsulate the inspection alarm data of each laboratory into a time chain proof data packet, as follows:

[0053] Add a hash summary field H to each patrol alarm data prev ;

[0054] Calculate the hash fingerprint value H using the collision-resistant algorithm SHA-256 curr , hash fingerprint value H curr Used to identify the uniqueness of the current data content and serve as the hash summary field H of the next data prev , build chain tracking capabilities;

[0055] In the process of patrol alarm data encapsulation, the hash summary field H of the previous data is first added to the current patrol alarm data. prev This field is used as a chain connection identifier between the current inspection alarm data and the previous inspection alarm data. If it is the first element of the chain, then Hprev Set to the initialization seed value; otherwise H prev Equal to the hash fingerprint value H of the previous inspection alarm data curr ;

[0056] Combine the original timestamp and inspection alarm data to build the four-tuple data structure {T,H prev ,H curr ,D}, T is the original timestamp, D is the inspection alarm data;

[0057] Among them, the inspection alarm data of each laboratory is obtained based on the perception and collection of distributed sub-inspection equipment, including alarm type label, alarm location code, equipment identification code and trigger parameter value range.

[0058] In this embodiment, the inspection alarm data of each laboratory is used as the original payload content body of the chain proof structure when constructing, and as the input source for hash summary calculation;

[0059] Alarm type labels include high temperature alarms and voltage anomalies; the alarm location code indicates the physical / spatial location where the alarm occurs, such as a laboratory code or sub-device number; the device identification code is an identifier that uniquely identifies the device that the alarm originated from, such as an RFID or MAC address; the trigger parameter value interval is used to record the data interval that causes the alarm, such as the temperature interval [80°C, 100°C].

[0060] In this embodiment, the anti-collision algorithm adopts the SHA-256 algorithm to ensure that H curr uniqueness and tampering difficulty, thus forming a chain anti-counterfeiting structure.

[0061] In this embodiment, the encapsulated time chain certification data packet is used to implement time consistency protection and data tampering protection in the entire process of data reporting, main alarm event aggregation, scheduling priority calculation and audit verification in the multi-laboratory dynamic inspection system, and ensure that the inspection data has reliable time traceability and integrity verification capabilities in a cross-laboratory environment.

[0062] Multi-source alarm aggregation and deduplication unit 2 is used to perform timestamp consistency detection on the time chain proof data packet to screen the time consistent candidate set, and use the Alarm-Fusion deduplication algorithm to perform aggregation analysis on the time consistent candidate set, establish the alarm event similarity graph of the inspection alarm event and obtain the main alarm event;

[0063] In this embodiment, in the multi-source alarm aggregation and deduplication unit 2, the timestamp consistency detection is specifically as follows:

[0064] Sort all time chain proof data packets in ascending order based on the original timestamp T: Receive multiple time chain proof data packets from different laboratories. Each data packet contains its corresponding original timestamp field. To ensure the comparability and consistency of the time sequence, the system sorts all time chain proof data packets in ascending order according to the original timestamp T to obtain an ordered data sequence.

[0065] In this embodiment, the timestamp consistency check is specifically as follows: all time chain proof data packets are sorted in ascending order according to the original timestamp T; a fixed time window Δt is set as a unit to divide the time interval, where the fixed time window Δt is less than the main control platform cycle; if the time chain proof data packets in the same divided time interval are determined to be the same alarm event, then in the same alarm event, the set of inspection alarm data to which all time chain proof data packets belong constitutes a time consistency candidate set.

[0066] Set a fixed time window Δt and divide the time intervals based on the time window: Set a fixed time window Δt according to the processing cycle of the main control platform. This value should be less than the minimum data processing cycle of the main control platform to meet the event density resolution requirements. Each time interval is regarded as a potential alarm event window in the same period.

[0067] Classify time chain proof packets that fall into the same time interval as the same alarm event: traverse all sorted time chain proof packets and determine their belonging time interval based on their original timestamps. All time chain packets in the same interval are preliminarily regarded as time-related packets of the same alarm event.

[0068] Constructing a time-consistent candidate set: For each time interval that is determined to be the same alarm event, the set of inspection alarm data associated with the time chain proof data packet contained therein is defined as a time-consistent candidate set.

[0069] In this embodiment, the Alarm-Fusion deduplication algorithm is a multi-source alarm event fusion algorithm based on timestamp consistency and semantic feature clustering. The Alarm-Fusion deduplication algorithm analyzes the semantic similarity of inspection alarm data based on the time-consistent candidate set and constructs an alarm event similarity graph, as follows:

[0070] Extract the alarm type label, alarm location code, device identification code and trigger parameter value interval of all inspection alarm data in the time-consistent candidate set as feature vectors;

[0071] The weighted vector edit distance is used to calculate the semantic similarity score between any two patrol alarm data in the time consistent candidate set, as follows:

[0072] In the time-consistent candidate set, any two patrol alarm data D m and D nThe corresponding eigenvectors are F m and F n , define its weighted vector edit distance d mn for:

[0073]

[0074] Among them, R is the number of feature dimensions, which is equal to 4; r is the feature dimension index; w r is the weighting coefficient of each feature dimension, which is used to control its relative importance in semantic similarity; f m,r Inspection alarm data D m In the equation, the rth characteristic component; f n,r Inspection alarm data D n In the equation, the rth characteristic component; δ(·,·) is the distance function, which is as follows:

[0075] Categorical features use 0-1 discrimination; spatial encoding uses spatial hierarchical matching distance; numerical features use normalized Euclidean distance;

[0076] Finally, two patrol alarm data D m and D n The semantic similarity score is defined as S mn :

[0077] S mn =exp(-γ·d mn );

[0078] Where γ is an adjustable scaling factor;

[0079] A bidirectional edge relationship is constructed between two patrol alarm data whose semantic similarity score is greater than the set threshold to obtain an alarm event similarity graph;

[0080] The node with the largest degree in the alarm event similarity graph is extracted as the main alarm event, and the remaining nodes are subordinate alarm events. The edge relationship between the main alarm event and the subordinate alarm event is the master-slave relationship index.

[0081] Dynamic priority scheduling unit 3 uses the alarm event propagation graph modeling mechanism to analyze the potential impact path of the main alarm event, calculates the comprehensive value score of the main alarm event, and dynamically prioritizes the main alarm events to generate an inspection task queue;

[0082] In this embodiment, in the dynamic priority scheduling unit 3, the alarm event propagation graph modeling mechanism is a directed graph structure modeling method constructed based on the alarm position codes and original timestamps between the main alarm events in the patrol alarm data, which is used to identify the potential impact paths of the main alarm events in each laboratory space. The alarm event propagation graph modeling mechanism is specifically as follows:

[0083] A potential impact path diagram is constructed based on the spatial adjacency dimension and the temporal proximity dimension, with the main alarm events as nodes in the diagram. If the alarm location codes of two main alarm events belong to the same physical space topologically connected area, and the interval between the original timestamps of the two main alarm events is less than the set propagation delay threshold, a directed edge is established between the two nodes, and finally a potential impact path diagram is obtained. The direction of the directed edge is from the main alarm event node with an earlier original timestamp to the main alarm event node with a later original timestamp.

[0084] In this embodiment, the spatial adjacency dimension is used to determine whether two main alarm events occur in areas that are directly connected or highly coupled in physical space. This is primarily based on the spatial structure of the alarm location codes to construct an adjacency relationship graph. The judgment is based on the following criteria: the alarm location codes have the same prefix; the alarm area numbers are in an adjacency matrix structure in the laboratory topology map; and the Euclidean distance after spatial mapping to a three-dimensional coordinate system meets the manually set standard.

[0085] The temporal proximity dimension is used to determine whether two main alarm events have a short time interval, and whether there may be a causal transmission or induction relationship; the judgment is based on the following: the difference between the original timestamps of the two main alarm events is less than the manually set temporal proximity threshold, which is determined according to the sensitivity of the alarm type.

[0086] In this embodiment, the comprehensive value score of the main alarm event is calculated as follows:

[0087] S value =w1·L impact +w2·C device +w3·R position +w4·F topo ;

[0088] Among them, S value Score for comprehensive value; L impact C is the longest path length of the main alarm event in the propagation diagram; device The criticality coefficient of the equipment associated with the main alarm event; R position Risk area score for the alarm location code; F topo The connectivity factor of the main alarm event in the spatial topological structure; w1, w2, w3 and w4 are all weight coefficients.

[0089] In this embodiment, the inspection task queue is used to construct a multi-laboratory dynamic inspection scheduling strategy, and the specific generation steps are as follows:

[0090] Score all main alarm events according to their comprehensive value S value Arrange in descending order and set the dynamic task execution threshold S th , for one of the main alarm events when Svalue >S th When the main alarm event is detected, it is marked as a high-priority task and added to the front of the queue. The remaining main alarm events are arranged in ascending order according to the original timestamps to fill the end of the queue.

[0091] Chain traceability audit verification unit 4: Chain traceability audit verification unit 4 verifies the consistency of all patrol alarm data, performs chain traceability verification on the main alarm event and its subordinate alarm events, and generates tamper-proof audit records;

[0092] In this embodiment, the chain traceability audit verification unit 4 includes a full data consistency verification module 41 and a master-slave alarm traceability audit module 42;

[0093] Among them, the full data consistency verification module 41 is used to perform hash chain structure verification on all time chain proof data packets. If any two adjacent time chain proof data packets meet H prev ≠H curr , then it is determined that data tampering has occurred and an audit anomaly label is generated;

[0094] In this embodiment, hash chain structure verification is a technical mechanism used to detect whether inspection alarm data has been tampered with or overwritten by rollback. Audit anomaly tags are structured traceability tags automatically generated for abnormal data nodes when the system detects a hash chain verification failure. They are used to record and locate chain breakage points. Audit anomaly tags are defined as a five-tuple structure:

[0095] AuditFlag={T err ,NodeID,ErrType,ChainIndex,HashPair};

[0096] Among them, AuditFlag is the audit exception label; T err is the timestamp of the original data when the exception occurred; NodeID is the laboratory or node ID of the data where the exception occurred; ErrType is the exception type; ChainIndex is the position number of the current exception data in the hash chain; HashPair is the hash summary field H containing the current inspection alarm data prev And the hash fingerprint value H of the previous inspection alarm data curr , used for audit verification.

[0097] The master-slave alarm tracing audit module 42 is used to perform chain tracing verification on the master alarm event and its slave alarm events and generate tamper-proof audit records, as follows:

[0098] Traverse the time chain proof data packets of all main alarm events and their subordinate alarm events to verify whether the original timestamp satisfies the monotonically increasing relationship; use the chain hash structure to recalculate the hash fingerprint value H curr;Write the master-slave relationship index between the main alarm event and the slave alarm event into the audit log structure to generate tamper-proof audit records;

[0099] In this embodiment, tamper-proof audit records are structured records of each processing step of each inspection alarm data from collection, aggregation, deduplication, scheduling to audit verification during the dynamic inspection of multiple laboratories, and are stored after being encrypted and encapsulated using a chain hash structure and a trusted timestamp.

[0100] The embodiments of the present invention are described in detail above with reference to the accompanying drawings, but the present invention is not limited thereto. Various changes can be made within the scope of knowledge possessed by those skilled in the art without departing from the spirit of the present invention.

Claims

1. A fast multi-laboratory dynamic inspection system, characterized by: include: The trusted timestamp encapsulation unit (1) generates an original timestamp using a low-drift crystal oscillator local clock source, and encapsulates each laboratory inspection alarm data into a time chain certification data packet in combination with a lightweight time base synchronization mechanism and a time chain segment certification mechanism, and embeds a unified time base field in each time chain certification data packet; The multi-source alarm aggregation and deduplication unit (2) is used to perform a timestamp consistency test on the time chain proof data packet to screen a time consistent candidate set, and use the Alarm-Fusion deduplication algorithm to perform aggregation analysis on the time consistent candidate set, establish an alarm event similarity graph of the patrol alarm event, and obtain the main alarm event; The dynamic priority scheduling unit (3) uses the alarm event propagation graph modeling mechanism to analyze the potential impact path of the main alarm event, calculates the comprehensive value score of the main alarm event, and dynamically prioritizes the main alarm event to generate an inspection task queue; The chain traceability audit verification unit (4) performs consistency verification on all patrol alarm data, performs chain traceability verification on the main alarm event and its subordinate alarm events, and generates tamper-proof audit records.

2. The fast multi-laboratory dynamic inspection system according to claim 1 is characterized in that: The low-drift crystal oscillator local clock source is a hardware clock source constructed using a temperature-compensated crystal oscillator, which is used to provide a stable clock reference with long-term drift in a cross-laboratory deployment environment, and periodically refresh the original timestamp value through the embedded controller to obtain the original timestamp; The original timestamp is the reference timestamp for collecting inspection alarm data in each laboratory.

3. The fast multi-laboratory dynamic inspection system according to claim 2 is characterized in that: The lightweight time base synchronization mechanism specifically includes: The control center periodically broadcasts beacon frames containing a unified time reference; each laboratory inspection device receives the beacon frame and compares it with the original timestamp to calculate the local clock drift ΔT; the exponential sliding average algorithm is used to correct the time deviation of the original timestamp to eliminate the local clock drift ΔT.

4. The fast multi-laboratory dynamic inspection system according to claim 3 is characterized in that: The time chain segment proof mechanism is used to structure and encapsulate the inspection alarm data of each laboratory into a time chain proof data packet, as follows: Add a hash summary field H to each patrol alarm data prev ; Calculate the hash fingerprint value H through the anti-collision algorithm curr ; Combine the original timestamp and inspection alarm data to build the four-tuple data structure {T,H prev ,H curr ,D}, T is the original timestamp, D is the inspection alarm data; Among them, the inspection alarm data of each laboratory is obtained based on the perception and collection of distributed sub-inspection equipment, including alarm type label, alarm location code, equipment identification code and trigger parameter value range.

5. The fast multi-laboratory dynamic inspection system according to claim 4 is characterized in that: In the multi-source alarm aggregation and deduplication unit (2), the timestamp consistency detection is specifically as follows: Sort all time chain proof data packets in ascending order based on the original timestamp T; Set a fixed time window Δt as the unit to divide the time interval, where the fixed time window Δt is smaller than the main control platform cycle; If the time chain proof data packets in the same divided time interval are determined to be the same alarm event, then in the same alarm event, the set of inspection alarm data to which all time chain proof data packets belong constitutes a time consistency candidate set.

6. The fast multi-laboratory dynamic inspection system according to claim 5 is characterized in that: The Alarm-Fusion deduplication algorithm is a multi-source alarm event fusion algorithm based on timestamp consistency and semantic feature clustering. The Alarm-Fusion deduplication algorithm analyzes the semantic similarity of inspection alarm data based on the time-consistent candidate set and constructs an alarm event similarity graph, as follows: Extract the alarm type label, alarm location code, device identification code and trigger parameter value interval of all inspection alarm data in the time-consistent candidate set as feature vectors; Use weighted vector edit distance to calculate the semantic similarity score between any two patrol alarm data in the time consistent candidate set; A bidirectional edge relationship is constructed between two patrol alarm data whose semantic similarity score is greater than the set threshold to obtain an alarm event similarity graph; The node with the largest degree in the alarm event similarity graph is extracted as the main alarm event, and the remaining nodes are subordinate alarm events. The edge relationship between the main alarm event and the subordinate alarm event is the master-slave relationship index.

7. The fast multi-laboratory dynamic inspection system according to claim 6 is characterized in that: In the dynamic priority scheduling unit (3), the alarm event propagation graph modeling mechanism is a directed graph structure modeling method based on the alarm position codes and original timestamps between the main alarm events in the patrol alarm data, which is used to identify the potential impact paths of the main alarm events in each laboratory space; the alarm event propagation graph modeling mechanism is specifically as follows: A potential impact path diagram is constructed based on the spatial adjacency dimension and the temporal proximity dimension, with the main alarm events as nodes in the diagram. If the alarm location codes of two main alarm events belong to the same physical space topologically connected area, and the interval between the original timestamps of the two main alarm events is less than the set propagation delay threshold, a directed edge is established between the two nodes, and finally a potential impact path diagram is obtained. The direction of the directed edge is from the main alarm event node with an earlier original timestamp to the main alarm event node with a later original timestamp.

8. The fast multi-laboratory dynamic inspection system according to claim 7 is characterized in that: The comprehensive value score of the main alarm event is calculated as follows: S value =w1·l impact +w2·C device +w3·R position +w4·F topo ; Among them, S value Score for comprehensive value; L impact C is the longest path length of the main alarm event in the propagation diagram; device The criticality coefficient of the equipment associated with the main alarm event; R position Risk area score for the alarm location code; F topo The connectivity factor of the main alarm event in the spatial topological structure; w1, w2, w3 and w4 are all weight coefficients.

9. The fast multi-laboratory dynamic inspection system according to claim 8, characterized in that: The inspection task queue is used to construct a multi-laboratory dynamic inspection scheduling strategy. The specific generation steps are as follows: Score all main alarm events according to their comprehensive value S value Sort in descending order and set the dynamic task execution threshold S th , for one of the main alarm events when S value >S th When the main alarm event is detected, it is marked as a high-priority task and added to the front of the queue. The remaining main alarm events are arranged in ascending order according to the original timestamps to fill the end of the queue.

10. The fast multi-laboratory dynamic inspection system according to claim 9 is characterized in that: The chain-type retrospective audit verification unit (4) includes a full data consistency verification module (41) and a master-slave alarm retrospective audit module (42); Among them, the full data consistency verification module (41) is used to perform hash chain structure verification on all time chain proof data packets. If any two adjacent time chain proof data packets meet H prev ≠H curr , then it is determined that data tampering has occurred and an audit anomaly label is generated; The master-slave alarm tracing audit module (42) is used to perform chain tracing verification on the master alarm event and its slave alarm events and generate tamper-proof audit records, as follows: Traverse the time chain proof data packets of all main alarm events and their subordinate alarm events to verify whether the original timestamp satisfies the monotonically increasing relationship; use the chain hash structure to recalculate the hash fingerprint value H curr ;Write the master-slave relationship index between the main alarm event and the slave alarm event into the audit log structure to generate tamper-proof audit records.