Distributed network access method and system
Through a distributed network access method, the edge access gateway broadcasts node status information and scores to select the best access node, solving the access bottleneck and delay problems of the traditional centralized network access architecture, achieving efficient, autonomous and secure access for terminal devices, and improving system stability and data continuity.
Patent Information
- Application Number
- CN202510895875.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-09-19
AI Technical Summary
Traditional centralized network access architecture is prone to access bottlenecks, link congestion, high switching delays and control failures when faced with a large number of terminal devices. It lacks terminal adaptability and access quality assessment mechanisms, and cannot meet the requirements of smart cities for highly available and resilient network access.
By obtaining the network topology provisioning information of the gateway, the edge access gateway periodically broadcasts node status information, uses the scoring function to select the best access node, and establishes and verifies the access request through a secure communication channel. Combined with resource status monitoring and load warning mechanisms, it generates an access migration strategy to achieve efficient, autonomous and secure access for terminal devices.
It enables efficient, autonomous and secure access of terminal devices in complex urban environments, alleviates access bottlenecks, improves the system's concurrent processing capabilities and operational stability, and ensures uninterrupted communications and data continuity.
Smart Images

Figure CN120675838A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of gateway connection, and in particular relates to a distributed network access method and system. Background Art
[0002] Amid the rapid development of smart cities, intelligent transportation, and the Internet of Things (IoT), the number of city-level sensing devices continues to grow. This is particularly true in smart streetlight systems, where the large number of deployed video surveillance terminals, environmental sensors, lighting control modules, and other terminal devices places higher demands on network access. Traditional centralized network access architectures typically rely on a small number of core gateways for unified terminal access and management. This approach is prone to access bottlenecks, link congestion, high switching latency, and control failures when faced with dense terminal populations, widespread spatial distribution, or sudden regional load fluctuations. These issues severely impact the system's real-time performance, reliability, and scalability.
[0003] At the same time, existing access methods often rely on pre-set fixed node connection paths, lacking terminal adaptability and access quality assessment mechanisms. This makes it impossible to dynamically optimize access paths based on the gateway's actual load, link quality, or deployment location. Furthermore, existing network architectures often rely on a disconnect-and-reconnect approach for terminal access migration, lacking an efficient migration mechanism. This often leads to data loss or control delays in scenarios like real-time video transmission and command control, making it difficult to meet the high-availability and resilient network access requirements of smart city infrastructure.
[0004] Therefore, there is an urgent need for a new network access method that can achieve distributed collaboration, terminal adaptive access, security authentication guarantee and uninterrupted access migration, so as to solve the technical problems existing in the existing technology, such as high access rigidity, weak scheduling capability, poor stability and interruption during migration, and provide a more efficient, flexible and secure solution for device access in complex urban Internet of Things environments. Summary of the Invention
[0005] The purpose of the embodiment of the present invention is to provide a distributed network access method, aiming to solve the problem raised in the third part of the background technology.
[0006] The embodiment of the present invention is implemented as follows: a distributed network access method and system, the method comprising: Obtaining network topology provisioning information for the gateway, the network topology provisioning information including the geographical deployment location of the edge access gateway and relay communication link information between adjacent gateways, the relay communication link information between adjacent gateways being used to determine whether wired and wireless relay communication is supported between the edge gateways; Multiple edge access gateways periodically broadcast their own node status information to obtain terminal status changes. When changes occur, they obtain broadcast signals from multiple gateways in real time and score each edge access gateway using a scoring function. The edge access gateway with the highest score is selected as the target access node, and an access request is sent to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. By comparing the monitoring results with the warning threshold, the controller generates an access migration strategy after receiving the warning signal by comprehensively evaluating the real-time status, geographical location and access load of adjacent gateways.
[0007] Preferably, the step of periodically broadcasting the node status information of the plurality of edge access gateways, obtaining the terminal status change, obtaining the broadcast signals of the plurality of gateways in real time when the change occurs, and scoring each edge access gateway by a scoring function specifically includes: Periodically broadcast node status information of the node through multiple edge access gateways, including its unique identifier, number of currently connected terminals, average response delay, remaining cache capacity, and signal strength reference value; Acquire terminal status changes, including startup and operation, and acquire broadcast signals from multiple gateways in real time when changes occur; Each edge access gateway is scored using a scoring function that includes three dimensions: signal strength, gateway current load level, and predicted path delay.
[0008] Preferably, the step of selecting the edge access gateway corresponding to the highest score as the target access node and initiating an access request to the gateway, and when the edge access gateway receives the request, decrypting and verifying the request and comparing the whitelist information at the same time specifically includes: Get the scoring results, select the edge access gateway with the highest score as the target access node, and initiate an access request to the gateway; When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. If the verification is successful, a symmetric key is generated between the gateway and the terminal. A secure communication channel is established based on the key, and subsequent data transmission and command issuance are carried out through the secure communication channel.
[0009] Preferably, the step of comparing the monitoring results with the warning threshold, and generating an access migration strategy by comprehensively evaluating the real-time status, geographical location, and access load of adjacent gateways after receiving the warning signal, specifically includes: Obtaining local resource status monitoring results, including the number of currently connected terminals and the average response delay, and obtaining an early warning threshold, which is a pre-set standard value; Compare the monitoring results with the warning threshold. If the monitoring results exceed the warning threshold, a load warning signal is generated and uploaded to the coordination controller. After receiving the warning signal, the controller comprehensively evaluates the real-time status, geographical location and access load of adjacent gateways. Generate an access migration strategy, wherein the access migration strategy is to switch to other idle nodes without interrupting communication.
[0010] Preferably, the access request includes unique identification information, geographic location information and a one-time authentication token of the terminal.
[0011] Another object of an embodiment of the present invention is to provide a distributed network access system, the system comprising: A gateway configuration basic module obtains network topology provisioning information of the gateway, wherein the network topology provisioning information includes the geographical deployment location of the edge access gateway and the relay communication link information between adjacent gateways. The relay communication link information between adjacent gateways is used to determine whether wired and wireless relay communication is supported between each edge gateway; The gateway scoring module periodically broadcasts its own node status information through multiple edge access gateways to obtain terminal status changes. When changes occur, it obtains the broadcast signals of multiple gateways in real time and scores each edge access gateway using a scoring function. The gateway connection module selects the edge access gateway corresponding to the highest score as the target access node and initiates an access request to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. The gateway migration module compares the monitoring results with the warning threshold. After receiving the warning signal, the controller generates an access migration strategy by comprehensively evaluating the real-time status, geographical location and access load of adjacent gateways.
[0012] Preferably, the gateway scoring module includes: A node status unit that periodically broadcasts its own node status information through multiple edge access gateways. The node information includes its unique identifier, the number of currently connected terminals, the average response delay, the remaining cache capacity, and the signal strength reference value; A terminal status unit, which obtains terminal status changes, including startup and operation, and obtains broadcast signals from multiple gateways in real time when changes occur; The gateway scoring unit scores each edge access gateway using a scoring function, where the scoring function includes three dimensions: signal strength, current gateway load level, and predicted path delay.
[0013] Preferably, the gateway connection module includes: The gateway connection unit obtains the scoring results, selects the edge access gateway corresponding to the highest score as the target access node, and initiates an access request to the gateway; Gateway key unit: When the edge access gateway receives a request, it decrypts and verifies the request and compares it with the whitelist information. If the verification is successful, a symmetric key is generated between the gateway and the terminal. The communication channel unit establishes a secure communication channel based on the key, and the secure communication channel is used for subsequent data transmission and command issuance.
[0014] Preferably, the gateway migration module includes: A status monitoring unit is configured to obtain a local resource status monitoring result, including the number of currently connected terminals and the average response delay, and obtain an early warning threshold value, which is a pre-set standard value; The load warning unit compares the monitoring results with the warning threshold. If the monitoring results exceed the warning threshold, a load warning signal is generated and uploaded to the coordination controller. After receiving the warning signal, the controller comprehensively evaluates the real-time status, geographical location and access load of adjacent gateways. The gateway migration unit generates an access migration strategy, wherein the access migration strategy is to switch to other idle nodes without interrupting communication.
[0015] Preferably, the access request includes unique identification information, geographic location information and a one-time authentication token of the terminal.
[0016] The present invention provides a distributed network access method that, by building a multi-edge access gateway status broadcast mechanism, terminal status perception and scoring selection logic, and an access process based on lightweight authentication and secure channel establishment, enables efficient, autonomous, and secure access of terminal devices to edge nodes. Compared to traditional centralized access architectures, this method effectively alleviates access bottlenecks and improves the system's overall concurrent processing capability and operational stability.
[0017] Through resource status monitoring and load early warning mechanisms, combined with the coordination controller's comprehensive assessment of adjacent node status, geographic location, and access load, dynamic terminal access migration and load balancing are achieved without interrupting communications. Dual-channel buffering and state synchronization ensure that the migration process is unaware of the terminal, preventing data loss and uninterrupted communications. This makes it particularly suitable for scenarios requiring high data continuity, such as streetlight video surveillance and urban sensor networks.
[0018] It has good deployment flexibility, migration smoothness and communication security, and can be widely used in smart cities, industrial Internet of Things, intelligent transportation and other occasions that require large-scale terminal remote access and edge collaborative processing. It has outstanding engineering practical value and promotion prospects. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 A flowchart of a distributed network access method provided by an embodiment of the present invention; Figure 2 A flowchart of the steps of periodically broadcasting node status information of multiple edge access gateways and scoring each edge access gateway using a scoring function provided by an embodiment of the present invention; Figure 3 A flowchart of the steps of decrypting and verifying the request and comparing the request with the whitelist information after receiving the request provided by the edge access gateway in an embodiment of the present invention; Figure 4 A flowchart of the steps for comparing monitoring results with warning thresholds and generating an access migration strategy after receiving a warning signal provided by an embodiment of the present invention; Figure 5 An architectural diagram of a distributed network access system provided by an embodiment of the present invention; Figure 6 An architectural diagram of a gateway scoring module provided in an embodiment of the present invention; Figure 7 An architectural diagram of a gateway connection module provided in an embodiment of the present invention; Figure 8 This is an architectural diagram of the gateway migration module provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0020] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0021] It is understood that the terms "first," "second," etc., used herein may be used to describe various elements, but unless otherwise specified, these elements are not limited by these terms. These terms are only used to distinguish a first element from another element. For example, a first xx script may be referred to as a second xx script, and similarly, a second xx script may be referred to as a first xx script without departing from the scope of this application.
[0022] like Figure 1 As shown, a distributed network access method provided by an embodiment of the present invention includes: S100, obtain the network topology provisioning information of the gateway, the network topology provisioning information includes the geographical deployment location of the edge access gateway and the relay communication link information between adjacent gateways, and the relay communication link information between adjacent gateways is used to determine whether wired and wireless relay communications are supported between each edge gateway.
[0023] In this step, the network topology provisioning information for the gateways is obtained. This information includes the geographic locations of multiple edge access gateways and information about relay communication links between adjacent gateways. The geographic locations of edge access gateways are typically calibrated using a GIS system. The specific blocks and road sections covered by each gateway, along with their GPS coordinates or location vectors in a city coordinate system, are recorded. This information is used to determine the "reachable area" constraints in subsequent terminal access decisions. This information can also be combined with terminal distribution heat maps to optimize layout and improve coverage balance.
[0024] The relay communication link information between adjacent gateways is used to determine whether each edge access gateway supports wired or wireless relay communication. The link information includes connection type, link bandwidth, delay estimation, stability level and priority parameters. For example, when two adjacent gateways are connected by a high-bandwidth, low-latency fiber link and are located in the same block, they can be configured as a group of active-standby collaborative nodes; if only low-speed wireless Mesh forwarding is supported between the two gateways, they can be enabled as emergency relay links when access is congested. Based on this type of topology diagram, the system can intelligently decide on migration targets and estimate relay path costs when terminals migrate, nodes go offline, or load balancing strategies are executed.
[0025] By pre-configuring this type of network topology information, the access controller can quickly decide on a migration plan during subsequent operation without having to dynamically detect the full network connection status, greatly improving the responsiveness and stability of access path switching. Especially in urban scenarios, when a temporary gateway failure or high concurrent connection demand occurs in a certain area, the system can quickly identify nearby auxiliary gateways with relay capabilities based on the topology map and establish a temporary access channel along the shortest path, achieving seamless handover without the terminal's awareness.
[0026] S200, periodically broadcasting the node status information of multiple edge access gateways to obtain terminal status changes, obtaining broadcast signals of multiple gateways in real time when changes occur, and scoring each edge access gateway through a scoring function.
[0027] In this step, multiple edge access gateways periodically broadcast their node status information. This information includes key parameters such as the gateway's unique identifier, the number of currently connected terminals, average link latency, cache utilization, and access channel strength estimates. This broadcast process is typically accomplished through lightweight methods such as UDP multicast within the local subnet, Bluetooth Low Energy (BLE) broadcasts, or LoRa spread-spectrum signals, enabling passive reception by all terminals within the coverage area. By default, terminal devices are in listening mode and continuously cache the status information received from multiple gateways during the most recent broadcast cycle.
[0028] When a terminal's status changes, such as initial startup, location change, degradation of the original connection, or active disconnection, the terminal immediately triggers the access evaluation process. During this process, the terminal extracts broadcast information from multiple edge access gateways from its cache and applies a pre-defined access scoring function to calculate it.
[0029] S300 , the edge access gateway corresponding to the highest score is selected as the target access node, and an access request is initiated to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information.
[0030] In this step, the edge access gateway corresponding to the highest score is used as the target access node. After the terminal completes the access scoring, the target access node will be determined based on the edge access gateway with the highest score, and an access request will be immediately initiated to the node. The access request includes the terminal's unique identifier, geographic location information, current timestamp, and a one-time authentication token encrypted by the terminal's local private key. To ensure access security and the authenticity of the request, the terminal uses asymmetric encryption to encapsulate the above request data to prevent it from being intercepted or tampered with during transmission. The request can be transmitted to the target edge gateway via UDP, MQTT, or TLS lightweight communication protocols to ensure a low-latency response.
[0031] After receiving the access request, the edge access gateway first uses the locally preset public key to decrypt the encrypted token, extract the original request data, and verify the validity of the timestamp and device identification. The timestamp must meet the maximum tolerance range with the current system time to prevent the old token from being maliciously replayed. The gateway then compares the device identification in the request with the locally maintained whitelist information. The whitelist is pre-issued by the central control platform and synchronized to each edge gateway. It contains the ID range of registered legal devices, the area information and access permission level. Only when the device ID is successfully matched in the whitelist and the location information is consistent with the area to which it belongs, the gateway will determine that the terminal has legal access qualifications.
[0032] S400 , comparing the monitoring results with the warning threshold, after receiving the warning signal, the controller generates an access migration strategy by comprehensively evaluating the real-time status, geographical location, and access load of adjacent gateways.
[0033] In this step, the edge access gateway continuously monitors its local operating status by comparing monitoring results with warning thresholds. It also records real-time operational metrics such as the number of connected terminals, average data response latency, and cache occupancy. If any of these metrics exceeds the preset warning threshold, the gateway immediately generates a load alarm and reports it to the upper-level regional coordination controller as an event report. Warning thresholds can be customized based on the characteristics of different gateway types and service areas, supporting regular remote adjustment or dynamic self-learning optimization.
[0034] After receiving a load warning from an edge gateway, the controller immediately starts the access migration evaluation process, comprehensively retrieves the status of the surrounding neighboring nodes of the warning gateway, builds a migration optimization model based on the above multi-dimensional indicators, and uses a greedy or weighted regression algorithm to calculate the target gateway set that is most suitable for sharing the load.
[0035] like Figure 2 As shown, as a preferred embodiment of the present invention, the steps of periodically broadcasting the node status information of multiple edge access gateways, obtaining terminal status changes, obtaining broadcast signals of multiple gateways in real time when changes occur, and scoring each edge access gateway using a scoring function specifically include: S201 , periodically broadcasting node status information of the node through multiple edge access gateways, where the node information includes its unique identifier, number of currently connected terminals, average response delay, remaining cache capacity, and signal strength reference value.
[0036] In this step, multiple edge access gateways periodically broadcast their node status information. The broadcast period can be set to a fixed interval (e.g., every 5 seconds) or dynamically adjusted (e.g., adaptive based on load fluctuations). Each broadcast packet contains a set of standardized node status fields that reflect the current gateway's operational capabilities and access availability, including but not limited to parameters such as the unique identifier (Node_ID), the number of currently connected terminals, the average response delay, the remaining cache capacity, and the signal strength reference value.
[0037] Among them, the unique identifier is used to distinguish the logical position of each gateway in the wide-area deployment; the number of connected terminals reflects the load level of the current node and can be used to predict access congestion; the average response delay is calculated by the local communication module periodically to measure the round-trip time (RTT) of terminal interaction; the remaining cache capacity represents whether the current gateway's local storage resources have the ability to carry new data streams; the signal strength reference value (such as RSSI or SNR) is derived by the gateway based on historical access terminal feedback statistics, which is used to indicate the wireless coverage quality of the node in a specific area.
[0038] For example, edge gateway A broadcasts the following information: {Node_ID: "GW_A01", Number of Access Points: 42, Average Latency: 78ms, Cache Remaining: 120MB, Reference Signal Strength: -65dBm}. Meanwhile, gateway B broadcasts: {Node_ID: "GW_B05", Number of Access Points: 18, Average Latency: 43ms, Cache Remaining: 320MB, Reference Signal Strength: -72dBm}. The streetlight terminals receiving the broadcast construct a scoring function based on these parameters and select the most suitable target node for access, thereby dynamically optimizing access paths and balancing system resource scheduling.
[0039] S202: Acquire a terminal status change, where the status change includes startup and operation, and acquire broadcast signals of multiple gateways in real time when a change occurs.
[0040] In this step, terminal status changes are detected. These primarily include startup status changes and operational status changes. A startup status change refers to the initial power-on or reset of a terminal device. Operational status changes can occur in scenarios such as fine-tuning the device's position, signal attenuation, abnormal response from the currently connected gateway, task load switching, or enabling or disabling an acquisition module. If the system detects any of these status changes, it deems the terminal to be potentially unstable and requires a re-determination of the access path.
[0041] To this end, upon sensing a status change, the terminal immediately switches to broadcast listening mode, receiving broadcast signals from multiple edge access gateways within its coverage area in real time via the wireless interface. This reception process is typically limited to a short time window (e.g., 2-3 seconds) to gather as much gateway status information as possible while keeping power consumption low. The received broadcast signal contains fields such as each gateway's unique identifier, current load, latency level, buffer capacity, and reference channel strength, providing the terminal with the foundational data for subsequent access scoring.
[0042] For example, a street lamp terminal restarts due to power outage. After entering the initialization state, it immediately scans the surrounding gateway broadcasts and finds that the signal strengths of gateways A and B are -60dBm and -68dBm respectively, with delays of 50ms and 30ms respectively. The terminal combines the scoring function to determine that B is more suitable as an access node, and then initiates an access request to it.
[0043] S203 , scoring each edge access gateway using a scoring function, where the scoring function includes three dimensions: signal strength, current gateway load level, and predicted path delay.
[0044] In this step, each edge access gateway is scored using a scoring function that comprehensively considers three key dimensions: signal strength, the gateway's current load level, and predicted path latency. Each dimension reflects a different aspect of access quality. Signal strength (such as RSSI or SNR) represents the reliability of the physical link; load level, typically calculated as the ratio of the current number of connected terminals to the maximum capacity, reflects the availability of access resources; and predicted path latency, derived from historical communication delays, queuing wait times, and forwarding performance modeling, is used to determine the potential response speed of data transmission.
[0045] The scoring function can be set as a weighted model in the following form: Score value = w1 × signal strength normalization value + w2 × (1 − load ratio) + w3 × (1 / path delay); Among them, w1, w2, and w3 are weight coefficients preset by the system or adaptively adjusted to ensure the emphasis of access quality factors in different business scenarios.
[0046] For example, for video surveillance terminals that require high image stream stability, the weight of the path delay item can be increased; while for terminals that periodically report sensor data, the emphasis can be placed on load balancing and signal strength stability. A terminal scans gateways A and B: A's signal strength is -62dBm (converted to 0.85), the load is 80% (0.2 available), and the delay is 80ms; B's signal strength is -70dBm (converted to 0.65), the load is 50% (0.5 available), and the delay is 40ms. If the system weights are set to w1:w2:w3 = 0.3:0.3:0.4, Gateway A's score is approximately 0.3 × 0.85 + 0.3 × 0.2 + 0.4 × (1 / 80) ≈ 0.255 + 0.06 + 0.005 = 0.32; Gateway B's score is approximately 0.3 × 0.65 + 0.3 × 0.5 + 0.4 × (1 / 40) ≈ 0.195 + 0.15 + 0.01 = 0.355. Therefore, the terminal selects Gateway B as its access target.
[0047] like Figure 3 As shown, as a preferred embodiment of the present invention, the edge access gateway corresponding to the highest score is used as the target access node, and an access request is initiated to the gateway. When the edge access gateway receives the request, the request is decrypted and verified, and the step of comparing the whitelist information is specifically included: S301 , obtaining a scoring result, selecting an edge access gateway corresponding to the highest score as a target access node, and initiating an access request to the gateway.
[0048] In this step, the terminal obtains the scoring results, stores them in a local cache, and sorts them within a preset scoring evaluation window (e.g., 1 second). The highest-scoring edge access gateway is selected as the optimal access target. This scoring not only reflects the overall service quality of each gateway but also indirectly reflects its load pressure and connection stability. Therefore, selecting the gateway with the highest score helps optimize the terminal's communication experience and data transmission efficiency after access.
[0049] The terminal then immediately initiates an access request to the target gateway. This request, encapsulated in a structured data packet, contains information such as the terminal's unique identifier, an encrypted authentication token, current location information, and the timestamp of the most recent score. This request is sent via a lightweight communication protocol, ensuring real-time access and low overhead. Furthermore, to improve connection success rates, the terminal can configure a timeout retransmission mechanism. If no response is received from the gateway within a set time limit, the scoring list is re-evaluated and the next candidate node is selected for access.
[0050] For example, a streetlight terminal listens to three gateway broadcasts and scores them, finding Gateway A with a score of 0.62, B with a score of 0.73, and C with a score of 0.58. The terminal determines Gateway B as optimal and immediately sends an access request to it. If B does not respond within 500ms, the terminal retransmits the request to Gateway A, which has the second-highest score. This score-driven access selection mechanism dynamically optimizes access distribution based on node status, achieving self-balancing access and improving access success rates in large-scale terminal environments.
[0051] S302, when the edge access gateway receives the request, the access request contains the terminal's unique identification information, geographic location information and one-time authentication token. The request is decrypted and verified, and compared with the whitelist information. If the verification is successful, a symmetric key is generated between the gateway and the terminal.
[0052] In this step, after receiving the request, the edge access gateway first parses the access request, extracting the terminal's unique identification information (such as the device ID or MAC address), geographic location information (such as GPS coordinates or logical area number), and a one-time authentication token. The one-time authentication token is generated by the terminal using an asymmetric encryption algorithm based on the local private key, the current timestamp, and the session random number. It is used to ensure the authenticity, uniqueness, and timeliness of the request source and prevent replay attacks or forged connections. The gateway decrypts the token using a locally pre-set public key and verifies that the timestamp is within the allowable offset range (e.g., ±5 seconds) to ensure that the authentication token is still valid.
[0053] After decrypting the token, the gateway compares the terminal's unique identifier contained in the request with a locally stored whitelist of devices. This whitelist, typically issued by a central control platform, records information such as the ID, region, and access permission level of all authorized devices. During the comparison process, if the device ID is not on the authorized list or the location information does not match the device's pre-registered region, the gateway immediately denies the access request and logs the exception. If all verifications pass, the terminal is deemed legitimate.
[0054] After authentication, the gateway and terminal initiate a key negotiation process, using Diffie-Hellman key exchange or a pre-shared key algorithm to generate a set of session-specific symmetric keys. This key is used for subsequent data encryption transmission, command control, and status feedback, ensuring the confidentiality and integrity of the communication link. For example, when a legitimate terminal LT-102 located in the designated area "North Zone 1" requests access from the edge gateway GW-03, the gateway decrypts its authentication token and successfully compares it to the whitelist. It then immediately generates a symmetric key and initiates TLS channel encrypted communication, achieving secure and low-latency data exchange.
[0055] S303: Establish a secure communication channel based on the key, and use the secure communication channel for subsequent data transmission and command issuance.
[0056] In this step, a secure communication channel is established using the key. This channel is built on a lightweight encryption transport protocol, such as DTLS (Datagram Transport Layer Security) or an adaptive protocol stack based on TLS / SSL. The previously negotiated symmetric key is used to encrypt and integrity-verify subsequent communications in real time. This encrypted channel supports bidirectional communication and is resistant to eavesdropping, tampering, and replay, effectively ensuring the security and confidentiality of data during transmission.
[0057] Once a secure communication channel is established, the terminal will regularly report operational data, such as light intensity, monitoring image summaries, and sensor status, through this channel. It can also asynchronously receive remote control commands from the edge gateway. These control commands, which can include adjusting the capture frequency, switching operating modes, and restarting the device, are all sent within the channel in an encrypted format and accompanied by an integrity check code. The terminal will only execute them after verification, preventing forged or intercepted commands from causing abnormal operations.
[0058] For example, after connecting to gateway GW-A, a streetlight monitoring terminal uploads collected brightness and image feature information every 30 seconds via a secure channel. If an emergency in that area requires a change in monitoring level, the platform sends an "increase image sampling frequency" command to GW-A through the controller, which then forwards it to the terminal via a secure channel. The terminal verifies the legitimacy of the command and then executes the task adjustment, ensuring the reliability and security of remote control.
[0059] like Figure 4 As shown, as a preferred embodiment of the present invention, the comparison of the monitoring results with the warning threshold, after receiving the warning signal, the controller generates an access migration strategy by comprehensively evaluating the real-time status, geographical location and access load of the adjacent gateway, specifically including: S401, obtaining a local resource status monitoring result, the monitoring result including the number of currently connected terminals and the average response delay, and obtaining an early warning threshold, the early warning threshold being a preset standard value.
[0060] In this step, local resource status monitoring results are obtained. These include at least two key metrics: the number of currently connected terminals and average response latency. The number of connected terminals is calculated by counting the number of devices currently communicating with the gateway, reflecting the node's load level. The average response latency is calculated based on the round-trip time (RTT) sampled between the terminal and the gateway, reflecting the real-time nature and processing capabilities of the access communication. The monitoring period can be set to every 5 to 10 seconds, flexibly adjusted based on device type and service requirements, ensuring real-time visibility into operational status.
[0061] A set of warning thresholds are configured for the aforementioned monitoring indicators. These thresholds are standard values pre-set by the platform or controller during deployment based on node capacity, service levels, and scenario requirements. For example, if a certain edge gateway model supports a maximum of 100 terminals, its connection warning threshold can be set to 90. A latency warning threshold of over 100ms can be set to indicate performance degradation. If any indicator in the real-time monitoring results exceeds the corresponding warning threshold, the gateway will immediately trigger a warning event report, which can be used as a trigger for access migration or system regulation.
[0062] For example, the edge gateway GW-12 is currently connected to 85 terminals, and the average response delays in the past two rounds are 95ms and 112ms respectively. Since the set connection number warning threshold is 90 and the delay threshold is 100ms, the system determines that GW-12 is close to the critical state of congestion and immediately reports an early warning event to the regional coordination controller, providing a basis for subsequent access migration, load transfer or temporary expansion decisions. This mechanism ensures the transparency and dynamic control capabilities of the network operation status, and is one of the core components that supports the stability of distributed access in the present invention.
[0063] S402, compare the monitoring results with the warning threshold. If the monitoring results exceed the warning threshold, a load warning signal is generated and the information is uploaded to the coordination controller. After receiving the warning signal, the controller comprehensively evaluates the real-time status, geographical location and access load of the adjacent gateways.
[0064] In this step, the monitoring results are compared with warning thresholds. If any key metric (such as the number of currently connected terminals or average response latency) exceeds the corresponding threshold, the node is determined to be under high load or experiencing performance degradation. At this point, the gateway immediately generates a load warning signal. This signal contains the unique identifier of the current node, the type of metric that triggered the warning, its specific value, a timestamp, and a snapshot of the most recent complete status information. This warning information is reported to the regional coordination controller via an encrypted channel, which triggers the access migration assessment process.
[0065] After receiving the load warning signal, the coordination controller will quickly retrieve the neighboring node information of the warning gateway and perform a comprehensive evaluation process. The evaluation content includes: the current number of connections and load rate of the neighboring gateway, the recent average delay level, the available cache capacity, and the path distance or physical reachability between the geographical location and the warning terminal. At the same time, the controller will also refer to historical access stability data, such as whether a candidate gateway has been marked as a "suboptimal node" due to access failure or high packet loss rate. By integrating this information, the controller selects one or more candidate gateways as target migration nodes based on priority rules or weighted scoring models.
[0066] For example, if the number of connections to edge gateway GW-05 surges to 95 within 5 seconds, exceeding its set threshold of 90, and the average response latency rises to 115ms, exceeding the 100ms latency threshold, the system triggers a double alert and sends it to the controller. The controller then queries the neighboring GW-03 and GW-06. GW-03 currently has only 40% load and is closest to the alert terminal, with a latency of less than 50ms. The controller then issues a migration command, directing some terminals to switch access to GW-03, thereby alleviating access pressure on GW-05 and optimizing overall service quality.
[0067] S403: Generate an access migration strategy, wherein the access migration strategy is to switch to another idle node without interrupting communication.
[0068] In this step, the access migration strategy is generated, including the identification information of the migration target node, the recommended migration terminal list, the migration execution time window, the key negotiation instructions and the channel warm-up parameters, etc., to ensure that the migration process is safe, coherent and efficient.
[0069] To ensure uninterrupted communication, the system utilizes a dual-channel buffering mechanism and data state mirroring technology. Before migration, the original connecting gateway establishes a temporary collaborative channel with the target gateway, maintaining forwarding services for the migrating terminal and synchronizing terminal status information (such as authentication records, session keys, and cached data pointers) with the target gateway. Once the target gateway completes state takeover, the terminal automatically switches to the encrypted channel and resumes sending and receiving data, without the need for reconnection or reauthentication. The entire migration process occurs in the background, oblivious to the terminal, ensuring uninterrupted and unlost critical data (such as video streams and real-time sensor data).
[0070] For example, if a streetlight video surveillance terminal, LT-018, is currently connected to GW-02 and experiences a load warning, the coordination controller evaluates the connection and selects the adjacent, lower-load node, GW-04, as the target access point. The system initiates the migration process, establishing a temporary synchronization channel between GW-02 and GW-04 and forwarding LT-018's encrypted session parameters and upload cache data to GW-04. After LT-018 completes the automatic handshake switch, video data uploads proceed smoothly, and the system ultimately releases the connection resources on GW-02, completing the migration successfully.
[0071] like Figure 5 As shown, a distributed network access system provided by an embodiment of the present invention includes: The gateway configuration basic module 100 is used to obtain the network topology provisioning information of the gateway, wherein the network topology provisioning information includes the geographical deployment location of the edge access gateway and the relay communication link information between adjacent gateways. The relay communication link information between adjacent gateways is used to determine whether wired and wireless relay communications are supported between each edge gateway.
[0072] In this system, the gateway configuration basic module 100 obtains the gateway's network topology pre-configuration information, which includes the geographic deployment locations of multiple edge access gateways and information about relay communication links between adjacent gateways. The geographic deployment locations of edge access gateways are typically calibrated using a GIS system, which records the specific blocks and road sections covered by each gateway, along with their GPS coordinates or location vectors in a city coordinate system. This information is used to determine the "reachable area" constraints in subsequent terminal access decisions. This information can also be combined with terminal distribution heat maps to optimize layout and improve coverage balance.
[0073] The relay communication link information between adjacent gateways is used to determine whether each edge access gateway supports wired or wireless relay communication. The link information includes connection type, link bandwidth, delay estimation, stability level and priority parameters. For example, when two adjacent gateways are connected by a high-bandwidth, low-latency fiber link and are located in the same block, they can be configured as a group of active-standby collaborative nodes; if only low-speed wireless Mesh forwarding is supported between the two gateways, they can be enabled as emergency relay links when access is congested. Based on this type of topology diagram, the system can intelligently decide on migration targets and estimate relay path costs when terminals migrate, nodes go offline, or load balancing strategies are executed.
[0074] By pre-configuring this type of network topology information, the access controller can quickly decide on a migration plan during subsequent operation without having to dynamically detect the full network connection status, greatly improving the responsiveness and stability of access path switching. Especially in urban scenarios, when a temporary gateway failure or high concurrent connection demand occurs in a certain area, the system can quickly identify nearby auxiliary gateways with relay capabilities based on the topology map and establish a temporary access channel along the shortest path, achieving seamless handover without the terminal's awareness.
[0075] The gateway scoring module 200 is used to periodically broadcast its own node status information through multiple edge access gateways, obtain terminal status changes, obtain broadcast signals of multiple gateways in real time when changes occur, and score each edge access gateway using a scoring function.
[0076] In this system, the gateway scoring module 200 periodically broadcasts its own node status information through multiple edge access gateways. This node status information includes key parameters such as the gateway's unique identifier, the number of currently connected terminals, average link latency, cache utilization, and access channel strength estimates. The broadcast process is typically completed using lightweight methods such as UDP multicast within the local subnet, BLE broadcast, or LoRa spread spectrum signals, enabling passive reception by all terminals waiting to access within the coverage area. Terminal devices are in listening mode by default and continuously cache the status information of multiple gateways received during the most recent broadcast cycle.
[0077] When a terminal's status changes, such as initial startup, location change, degradation of the original connection, or active disconnection, the terminal immediately triggers the access evaluation process. During this process, the terminal extracts broadcast information from multiple edge access gateways from its cache and applies a pre-defined access scoring function to calculate it.
[0078] The gateway connection module 300 is used to select the edge access gateway corresponding to the highest score as the target access node and initiate an access request to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information.
[0079] In this system, the gateway connection module 300 uses the edge access gateway corresponding to the highest score as the target access node. After the terminal completes the access scoring, it will determine the target access node based on the edge access gateway with the highest score and immediately initiate an access request to the node. The access request includes the terminal's unique identifier, geographic location information, current timestamp, and a one-time authentication token generated by encrypting the terminal's local private key. To ensure access security and the authenticity of the request, the terminal uses asymmetric encryption to encapsulate the above request data to prevent it from being intercepted or tampered with during transmission. The request can be transmitted to the target edge gateway via UDP, MQTT, or TLS lightweight communication protocols to ensure a low-latency response.
[0080] After receiving the access request, the edge access gateway first uses the locally preset public key to decrypt the encrypted token, extract the original request data, and verify the validity of the timestamp and device identification. The timestamp must meet the maximum tolerance range with the current system time to prevent the old token from being maliciously replayed. The gateway then compares the device identification in the request with the locally maintained whitelist information. The whitelist is pre-issued by the central control platform and synchronized to each edge gateway. It contains the ID range of registered legal devices, the area information and access permission level. Only when the device ID is successfully matched in the whitelist and the location information is consistent with the area to which it belongs, the gateway will determine that the terminal has legal access qualifications.
[0081] The gateway migration module 400 is used to compare the monitoring results with the warning threshold. After receiving the warning signal, the controller generates an access migration strategy by comprehensively evaluating the real-time status, geographical location and access load of adjacent gateways.
[0082] In this system, the gateway migration module 400 compares monitoring results with warning thresholds. The edge access gateway continuously monitors its local operating status and records, in real time, operational metrics such as the number of currently connected terminals, average data response latency, and cache occupancy. If any of these metrics exceeds a preset warning threshold, the gateway immediately generates a load alarm and reports it to the higher-level regional coordination controller as an event report. Warning thresholds can be customized based on the characteristics of different gateway types and service areas, supporting regular remote adjustment or dynamic self-learning optimization.
[0083] After receiving a load warning from an edge gateway, the controller immediately starts the access migration evaluation process, comprehensively retrieves the status of the surrounding neighboring nodes of the warning gateway, builds a migration optimization model based on the above multi-dimensional indicators, and uses a greedy or weighted regression algorithm to calculate the target gateway set that is most suitable for sharing the load.
[0084] like Figure 6As shown, as a preferred embodiment of the present invention, the gateway scoring module 200 includes: The node status unit 201 is configured to periodically broadcast its own node status information through multiple edge access gateways. The node information includes its unique identifier, number of currently connected terminals, average response delay, remaining cache capacity, and signal strength reference value.
[0085] In this module, the node status unit 201 periodically broadcasts its node status information through multiple edge access gateways. The broadcast period can be set to a fixed interval (e.g., every 5 seconds) or dynamically adjusted (e.g., adaptive based on load fluctuations). Each broadcast packet contains a set of standardized node status fields that reflect the current gateway's operational capabilities and access availability, including but not limited to parameters such as a unique identifier (Node_ID), the number of currently connected terminals, average response latency, remaining cache capacity, and a signal strength reference value.
[0086] Among them, the unique identifier is used to distinguish the logical position of each gateway in the wide-area deployment; the number of connected terminals reflects the load level of the current node and can be used to predict access congestion; the average response delay is calculated by the local communication module periodically to measure the round-trip time (RTT) of terminal interaction; the remaining cache capacity represents whether the current gateway's local storage resources have the ability to carry new data streams; the signal strength reference value (such as RSSI or SNR) is derived by the gateway based on historical access terminal feedback statistics, which is used to indicate the wireless coverage quality of the node in a specific area.
[0087] For example, edge gateway A broadcasts the following information: {Node_ID: "GW_A01", Number of Access Points: 42, Average Latency: 78ms, Cache Remaining: 120MB, Reference Signal Strength: -65dBm}. Meanwhile, gateway B broadcasts: {Node_ID: "GW_B05", Number of Access Points: 18, Average Latency: 43ms, Cache Remaining: 320MB, Reference Signal Strength: -72dBm}. The streetlight terminals receiving the broadcast construct a scoring function based on these parameters and select the most suitable target node for access, thereby dynamically optimizing access paths and balancing system resource scheduling.
[0088] The terminal status unit 202 is used to obtain terminal status changes, including startup and operation, and to obtain broadcast signals of multiple gateways in real time when changes occur.
[0089] In this module, the terminal status unit 202 acquires terminal status changes, which primarily include startup status changes and operational status changes. A startup status change refers to the initial power-on or reset of a terminal device; an operational status change includes scenarios such as fine-tuning the device's position, signal attenuation, abnormal response from the currently connected gateway, task load switching, or enabling or disabling the acquisition module. When the system detects any of these status changes, it deems the terminal to be potentially unstable and requires a re-determination of the access path.
[0090] To this end, upon sensing a status change, the terminal immediately switches to broadcast listening mode, receiving broadcast signals from multiple edge access gateways within its coverage area in real time via the wireless interface. This reception process is typically limited to a short time window (e.g., 2-3 seconds) to gather as much gateway status information as possible while keeping power consumption low. The received broadcast signal contains fields such as each gateway's unique identifier, current load, latency level, buffer capacity, and reference channel strength, providing the terminal with the foundational data for subsequent access scoring.
[0091] For example, a street lamp terminal restarts due to power outage. After entering the initialization state, it immediately scans the surrounding gateway broadcasts and finds that the signal strengths of gateways A and B are -60dBm and -68dBm respectively, with delays of 50ms and 30ms respectively. The terminal combines the scoring function to determine that B is more suitable as an access node, and then initiates an access request to it.
[0092] The gateway scoring unit 203 is configured to score each edge access gateway using a scoring function, where the scoring function includes three dimensions: signal strength, current gateway load level, and predicted path delay.
[0093] In this module, the gateway scoring unit 203 scores each edge access gateway using a scoring function. This scoring function comprehensively considers three key dimensions: signal strength, the gateway's current load level, and predicted path delay. Each dimension reflects a different aspect of access quality. Signal strength (such as RSSI or SNR) represents the reliability of the physical link; load level, typically calculated as the ratio of the current number of connected terminals to the maximum capacity, reflects the availability of access resources; and predicted path delay, derived from historical communication delays, queuing wait times, and forwarding performance modeling, is used to determine the potential response speed of data transmission.
[0094] The scoring function can be set as a weighted model in the following form: Score value = w1 × signal strength normalization value + w2 × (1 − load ratio) + w3 × (1 / path delay); Among them, w1, w2, and w3 are weight coefficients preset by the system or adaptively adjusted to ensure the emphasis of access quality factors in different business scenarios.
[0095] For example, for video surveillance terminals that require high image stream stability, the weight of the path delay item can be increased; while for terminals that periodically report sensor data, the emphasis can be placed on load balancing and signal strength stability. A terminal scans gateways A and B: A's signal strength is -62dBm (converted to 0.85), the load is 80% (0.2 available), and the delay is 80ms; B's signal strength is -70dBm (converted to 0.65), the load is 50% (0.5 available), and the delay is 40ms. If the system weights are set to w1:w2:w3 = 0.3:0.3:0.4, Gateway A's score is approximately 0.3 × 0.85 + 0.3 × 0.2 + 0.4 × (1 / 80) ≈ 0.255 + 0.06 + 0.005 = 0.32; Gateway B's score is approximately 0.3 × 0.65 + 0.3 × 0.5 + 0.4 × (1 / 40) ≈ 0.195 + 0.15 + 0.01 = 0.355. Therefore, the terminal selects Gateway B as its access target.
[0096] like Figure 7 As shown, as a preferred embodiment of the present invention, the gateway connection module 300 includes: The gateway connection unit 301 is configured to obtain the scoring result, select the edge access gateway corresponding to the highest score as the target access node, and initiate an access request to the gateway.
[0097] In this module, the gateway connection unit 301 obtains the scoring results. The terminal stores the scoring results in a local cache and sorts them within a preset scoring evaluation window (e.g., 1 second). The highest-scoring edge access gateway is selected as the optimal access target. This scoring result not only reflects the overall service quality of each gateway but also indirectly reflects its load pressure and connection stability. Therefore, selecting the gateway with the highest score helps optimize the terminal's communication experience and data transmission efficiency after access.
[0098] The terminal then immediately initiates an access request to the target gateway. This request, encapsulated in a structured data packet, contains information such as the terminal's unique identifier, an encrypted authentication token, current location information, and the timestamp of the most recent score. This request is sent via a lightweight communication protocol, ensuring real-time access and low overhead. Furthermore, to improve connection success rates, the terminal can configure a timeout retransmission mechanism. If no response is received from the gateway within a set time limit, the scoring list is re-evaluated and the next candidate node is selected for access.
[0099] For example, a streetlight terminal listens to three gateway broadcasts and scores them, finding Gateway A with a score of 0.62, B with a score of 0.73, and C with a score of 0.58. The terminal determines Gateway B as optimal and immediately sends an access request to it. If B does not respond within 500ms, the terminal retransmits the request to Gateway A, which has the second-highest score. This score-driven access selection mechanism dynamically optimizes access distribution based on node status, achieving self-balancing access and improving access success rates in large-scale terminal environments.
[0100] The gateway key unit 302 is used to decrypt and verify the request after the edge access gateway receives the request, which contains the terminal's unique identification information, geographic location information and one-time authentication token, and compare it with the whitelist information. If the verification is successful, a symmetric key is generated between the gateway and the terminal.
[0101] In this module, upon receiving a request, the gateway key unit 302 first parses the access request, extracting the terminal's unique identification information (such as a device ID or MAC address), geographic location information (such as GPS coordinates or logical area number), and a one-time authentication token. This token is generated by the terminal using an asymmetric encryption algorithm based on the terminal's local private key, the current timestamp, and a session random number. This ensures the authenticity, uniqueness, and timeliness of the request source, preventing replay attacks or forged connections. The gateway decrypts the token using a locally pre-configured public key and verifies that the timestamp is within a permissible offset (e.g., ±5 seconds) to ensure the token is still valid.
[0102] After decrypting the token, the gateway compares the terminal's unique identifier contained in the request with a locally stored whitelist of devices. This whitelist, typically issued by a central control platform, records information such as the ID, region, and access permission level of all authorized devices. During the comparison process, if the device ID is not on the authorized list or the location information does not match the device's pre-registered region, the gateway immediately denies the access request and logs the exception. If all verifications pass, the terminal is deemed legitimate.
[0103] After authentication, the gateway and terminal initiate a key negotiation process, using Diffie-Hellman key exchange or a pre-shared key algorithm to generate a set of session-specific symmetric keys. This key is used for subsequent data encryption transmission, command control, and status feedback, ensuring the confidentiality and integrity of the communication link. For example, when a legitimate terminal LT-102 located in the designated area "North Zone 1" requests access from the edge gateway GW-03, the gateway decrypts its authentication token and successfully compares it to the whitelist. It then immediately generates a symmetric key and initiates TLS channel encrypted communication, achieving secure and low-latency data exchange.
[0104] The communication channel unit 303 is used to establish a secure communication channel based on the key, which is used for subsequent data transmission and command issuance.
[0105] In this module, the communication channel unit 303 establishes a secure communication channel based on the key. This channel is built on a lightweight encryption transport protocol, such as DTLS (Datagram Transport Layer Security) or an adaptive protocol stack based on TLS / SSL. It uses the previously negotiated symmetric key to perform real-time encryption and integrity verification on subsequent communications. This encrypted channel supports bidirectional communication and is resistant to eavesdropping, tampering, and replay, effectively ensuring the security and confidentiality of data content during transmission.
[0106] Once a secure communication channel is established, the terminal will regularly report operational data, such as light intensity, monitoring image summaries, and sensor status, through this channel. It can also asynchronously receive remote control commands from the edge gateway. These control commands, which can include adjusting the capture frequency, switching operating modes, and restarting the device, are all sent within the channel in an encrypted format and accompanied by an integrity check code. The terminal will only execute them after verification, preventing forged or intercepted commands from causing abnormal operations.
[0107] For example, after connecting to gateway GW-A, a streetlight monitoring terminal uploads collected brightness and image feature information every 30 seconds via a secure channel. If an emergency in that area requires a change in monitoring level, the platform sends an "increase image sampling frequency" command to GW-A through the controller, which then forwards it to the terminal via a secure channel. The terminal verifies the legitimacy of the command and then executes the task adjustment, ensuring the reliability and security of remote control.
[0108] like Figure 8 As shown, as a preferred embodiment of the present invention, the gateway migration module 400 includes: The status monitoring unit 401 is configured to obtain local resource status monitoring results, including the number of currently connected terminals and the average response delay, and obtain an early warning threshold value, which is a preset standard value.
[0109] In this module, the status monitoring unit 401 obtains local resource status monitoring results, including at least two key indicators: the number of currently connected terminals and average response delay. The number of connected terminals is calculated by counting the number of devices currently connected to the gateway maintaining communication, reflecting the node's load level. The average response delay is calculated based on the round-trip time (RTT) sampling between the terminal and the gateway, reflecting the real-time nature and processing capacity of the access communication. The monitoring period can be set to every 5 to 10 seconds, flexibly adjusted based on device type and service requirements, to ensure real-time monitoring of operational status.
[0110] A set of warning thresholds are configured for the aforementioned monitoring indicators. These thresholds are standard values pre-set by the platform or controller during deployment based on node capacity, service levels, and scenario requirements. For example, if a certain edge gateway model supports a maximum of 100 terminals, its connection warning threshold can be set to 90. A latency warning threshold of over 100ms can be set to indicate performance degradation. If any indicator in the real-time monitoring results exceeds the corresponding warning threshold, the gateway will immediately trigger a warning event report, which can be used as a trigger for access migration or system regulation.
[0111] For example, the edge gateway GW-12 is currently connected to 85 terminals, and the average response delays in the past two rounds are 95ms and 112ms respectively. Since the set connection number warning threshold is 90 and the delay threshold is 100ms, the system determines that GW-12 is close to the critical state of congestion and immediately reports an early warning event to the regional coordination controller, providing a basis for subsequent access migration, load transfer or temporary expansion decisions. This mechanism ensures the transparency and dynamic control capabilities of the network operation status, and is one of the core components that supports the stability of distributed access in the present invention.
[0112] The load warning unit 402 is used to compare the monitoring results with the warning threshold. If the monitoring results exceed the warning threshold, a load warning signal is generated and the information is uploaded to the coordination controller. After receiving the warning signal, the controller comprehensively evaluates the real-time status, geographical location and access load of the adjacent gateways.
[0113] In this module, the load warning unit 402 compares monitoring results with warning thresholds. If any key metric (such as the number of currently connected terminals or average response latency) exceeds the corresponding threshold, the node is determined to be under high load or experiencing performance degradation. At this point, the gateway immediately generates a load warning signal containing the node's unique identifier, the type of metric that triggered the warning, its specific value, a timestamp, and a snapshot of the most recent complete status information. This warning information is reported to the regional coordination controller via an encrypted channel, triggering the access migration assessment process.
[0114] After receiving the load warning signal, the coordination controller will quickly retrieve the neighboring node information of the warning gateway and perform a comprehensive evaluation process. The evaluation content includes: the current number of connections and load rate of the neighboring gateway, the recent average delay level, the available cache capacity, and the path distance or physical reachability between the geographical location and the warning terminal. At the same time, the controller will also refer to historical access stability data, such as whether a candidate gateway has been marked as a "suboptimal node" due to access failure or high packet loss rate. By integrating this information, the controller selects one or more candidate gateways as target migration nodes based on priority rules or weighted scoring models.
[0115] For example, if the number of connections to edge gateway GW-05 surges to 95 within 5 seconds, exceeding its set threshold of 90, and the average response latency rises to 115ms, exceeding the 100ms latency threshold, the system triggers a double alert and sends it to the controller. The controller then queries the neighboring GW-03 and GW-06. GW-03 currently has only 40% load and is closest to the alert terminal, with a latency of less than 50ms. The controller then issues a migration command, directing some terminals to switch access to GW-03, thereby alleviating access pressure on GW-05 and optimizing overall service quality.
[0116] The gateway migration unit 403 is configured to generate an access migration strategy, wherein the access migration strategy is to switch to another idle node without interrupting communication.
[0117] In this module, the gateway migration unit 403 generates access migration strategies, identification information of the migration target node, a list of recommended migration terminals, a migration execution time window, key negotiation instructions, and channel warm-up parameters, etc., to ensure that the migration process is safe, coherent, and efficient.
[0118] To ensure uninterrupted communication, the system utilizes a dual-channel buffering mechanism and data state mirroring technology. Before migration, the original connecting gateway establishes a temporary collaborative channel with the target gateway, maintaining forwarding services for the migrating terminal and synchronizing terminal status information (such as authentication records, session keys, and cached data pointers) with the target gateway. Once the target gateway completes state takeover, the terminal automatically switches to the encrypted channel and resumes sending and receiving data, without the need for reconnection or reauthentication. The entire migration process occurs in the background, oblivious to the terminal, ensuring uninterrupted and unlost critical data (such as video streams and real-time sensor data).
[0119] For example, if a streetlight video surveillance terminal, LT-018, is currently connected to GW-02 and experiences a load warning, the coordination controller evaluates the connection and selects the adjacent, lower-load node, GW-04, as the target access point. The system initiates the migration process, establishing a temporary synchronization channel between GW-02 and GW-04 and forwarding LT-018's encrypted session parameters and upload cache data to GW-04. After LT-018 completes the automatic handshake switch, video data uploads proceed smoothly, and the system ultimately releases the connection resources on GW-02, completing the migration successfully.
[0120] In one embodiment, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are performed: Obtaining network topology provisioning information for the gateway, the network topology provisioning information including the geographical deployment location of the edge access gateway and relay communication link information between adjacent gateways, the relay communication link information between adjacent gateways being used to determine whether wired and wireless relay communication is supported between the edge gateways; Multiple edge access gateways periodically broadcast their own node status information to obtain terminal status changes. When changes occur, they obtain broadcast signals from multiple gateways in real time and score each edge access gateway using a scoring function. The edge access gateway with the highest score is selected as the target access node, and an access request is sent to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. By comparing the monitoring results with the warning threshold, the controller generates an access migration strategy after receiving the warning signal by comprehensively evaluating the real-time status, geographical location and access load of adjacent gateways.
[0121] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the processor performs the following steps: Obtaining network topology provisioning information for the gateway, the network topology provisioning information including the geographical deployment location of the edge access gateway and relay communication link information between adjacent gateways, the relay communication link information between adjacent gateways being used to determine whether wired and wireless relay communication is supported between the edge gateways; Multiple edge access gateways periodically broadcast their own node status information to obtain terminal status changes. When changes occur, they obtain broadcast signals from multiple gateways in real time and score each edge access gateway using a scoring function. The edge access gateway with the highest score is selected as the target access node, and an access request is sent to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. By comparing the monitoring results with the warning threshold, the controller generates an access migration strategy after receiving the warning signal by comprehensively evaluating the real-time status, geographical location and access load of adjacent gateways.
[0122] It should be understood that, although the various steps in the flow chart of each embodiment of the present invention are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence according to the order indicated by the arrows. Unless otherwise specified herein, the execution of these steps is not strictly limited in order, and these steps can be performed in other orders. Moreover, at least a portion of the steps in each embodiment may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0123] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing the relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When executed, the program can include the processes of the above-described method embodiments. Any reference to memory, storage, database, or other media used in the various embodiments provided herein may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), RAMbus direct RAM (RDRAM), direct RAMbus dynamic RAM (DRDRAM), and RAMbus dynamic RAM (RDRAM).
[0124] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0125] The above-described embodiments merely illustrate several implementations of the present invention, and while their descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make numerous variations and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be determined by the appended claims.
[0126] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A distributed network access method, characterized in that: The method comprises: Obtaining network topology provisioning information for the gateway, the network topology provisioning information including the geographical deployment location of the edge access gateway and relay communication link information between adjacent gateways, the relay communication link information between adjacent gateways being used to determine whether wired and wireless relay communication is supported between the edge gateways; Multiple edge access gateways periodically broadcast their own node status information to obtain terminal status changes. When changes occur, they obtain broadcast signals from multiple gateways in real time and score each edge access gateway using a scoring function. The edge access gateway with the highest score is selected as the target access node, and an access request is sent to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. By comparing the monitoring results with the warning threshold, the controller generates an access migration strategy after receiving the warning signal by comprehensively evaluating the real-time status, geographical location and access load of adjacent gateways.
2. A distributed network access method according to claim 1, characterized in that: The steps of periodically broadcasting node status information of multiple edge access gateways to obtain terminal status changes, obtaining broadcast signals of multiple gateways in real time when changes occur, and scoring each edge access gateway using a scoring function specifically include: Periodically broadcast node status information of the node through multiple edge access gateways, including its unique identifier, number of currently connected terminals, average response delay, remaining cache capacity, and signal strength reference value; Acquire terminal status changes, including startup and operation, and acquire broadcast signals from multiple gateways in real time when changes occur; Each edge access gateway is scored using a scoring function that includes three dimensions: signal strength, gateway current load level, and predicted path delay.
3. A distributed network access method according to claim 1, characterized in that: The step of selecting the edge access gateway corresponding to the highest score as the target access node and initiating an access request to the gateway, and decrypting and verifying the request and comparing the request with the whitelist information after the edge access gateway receives the request, specifically includes: Get the scoring results, select the edge access gateway with the highest score as the target access node, and initiate an access request to the gateway; When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. If the verification is successful, a symmetric key is generated between the gateway and the terminal. A secure communication channel is established based on the key, and subsequent data transmission and command issuance are carried out through the secure communication channel.
4. A distributed network access method according to claim 1, characterized in that: The step of comparing the monitoring results with the warning threshold and generating an access migration strategy by comprehensively evaluating the real-time status, geographic location, and access load of adjacent gateways after receiving the warning signal specifically includes: Obtaining local resource status monitoring results, including the number of currently connected terminals and the average response delay, and obtaining an early warning threshold, which is a pre-set standard value; Compare the monitoring results with the warning threshold. If the monitoring results exceed the warning threshold, a load warning signal is generated and uploaded to the coordination controller. After receiving the warning signal, the controller comprehensively evaluates the real-time status, geographical location and access load of adjacent gateways. Generate an access migration strategy, wherein the access migration strategy is to switch to other idle nodes without interrupting communication.
5. A distributed network access method according to claim 3, characterized in that: The access request includes the unique identification information, geographic location information and a one-time authentication token of the terminal.
6. A distributed network access system, characterized in that: The system comprises: A gateway configuration basic module obtains network topology provisioning information of the gateway, wherein the network topology provisioning information includes the geographical deployment location of the edge access gateway and the relay communication link information between adjacent gateways. The relay communication link information between adjacent gateways is used to determine whether wired and wireless relay communication is supported between each edge gateway; The gateway scoring module periodically broadcasts its own node status information through multiple edge access gateways to obtain terminal status changes. When changes occur, it obtains the broadcast signals of multiple gateways in real time and scores each edge access gateway using a scoring function. The gateway connection module selects the edge access gateway corresponding to the highest score as the target access node and initiates an access request to the gateway. When the edge access gateway receives the request, it decrypts and verifies the request and compares it with the whitelist information. The gateway migration module compares the monitoring results with the warning threshold. After receiving the warning signal, the controller generates an access migration strategy by comprehensively evaluating the real-time status, geographical location and access load of adjacent gateways.
7. A distributed network access system according to claim 6, characterized in that: The gateway scoring module includes: A node status unit that periodically broadcasts its own node status information through multiple edge access gateways. The node information includes its unique identifier, the number of currently connected terminals, the average response delay, the remaining cache capacity, and the signal strength reference value; A terminal status unit, which obtains terminal status changes, including startup and operation, and obtains broadcast signals from multiple gateways in real time when changes occur; The gateway scoring unit scores each edge access gateway using a scoring function, where the scoring function includes three dimensions: signal strength, current gateway load level, and predicted path delay.
8. A distributed network access system according to claim 7, characterized in that: The gateway connection module includes: The gateway connection unit obtains the scoring results, selects the edge access gateway corresponding to the highest score as the target access node, and initiates an access request to the gateway; Gateway key unit: When the edge access gateway receives a request, it decrypts and verifies the request and compares it with the whitelist information. If the verification is successful, a symmetric key is generated between the gateway and the terminal. The communication channel unit establishes a secure communication channel based on the key, and the secure communication channel is used for subsequent data transmission and command issuance.
9. A distributed network access system according to claim 8, characterized in that: The gateway migration module includes: A status monitoring unit is configured to obtain a local resource status monitoring result, including the number of currently connected terminals and the average response delay, and obtain an early warning threshold value, which is a pre-set standard value; The load warning unit compares the monitoring results with the warning threshold. If the monitoring results exceed the warning threshold, a load warning signal is generated and uploaded to the coordination controller. After receiving the warning signal, the controller comprehensively evaluates the real-time status, geographical location and access load of adjacent gateways. The gateway migration unit generates an access migration strategy, wherein the access migration strategy is to switch to other idle nodes without interrupting communication.
10. A distributed network access system according to claim 9, characterized in that: The access request includes the unique identification information, geographic location information and a one-time authentication token of the terminal.
Citation Information
Cited By
Power distribution network intelligent switch control method and system considering communication fault
CN121036357A
Intelligent lighting network node management method, bridge end compiler, medium and system
CN121486807A
Intelligent lighting network node management method, bridge-side compiler, medium, and system
CN121486807B