A remote security management method and system

By setting up edge computing nodes and a multi-dimensional coupling matrix for devices inside the RV, autonomous emergency handling during network outages is achieved, solving the security risks of the RV remote monitoring system when the network is unstable, and improving the robustness of the system and the service life of the equipment.

CN122294181APending Publication Date: 2026-06-26RONGCHENG MOLIN OUTDOOR TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
RONGCHENG MOLIN OUTDOOR TECH CO LTD
Filing Date
2026-05-06
Publication Date
2026-06-26

Smart Images

  • Figure CN122294181A_ABST
    Figure CN122294181A_ABST
Patent Text Reader

Abstract

This application discloses a remote security management method and system. The method includes: deploying an edge computing node within the vehicle to receive remote control commands; before executing the command, acquiring the local real-time status parameters of the controlled device and performing security verification according to preset local security rules; and rejecting the command if it is determined that executing the command will violate the security rules. This application also discloses a system for implementing this method. By constructing an edge-first arbitration logic, this application solves the technical problem of traditional cloud control solutions losing security capabilities during network interruptions. Even during network interruptions, it can still independently execute local security rules, rejecting unreasonable commands and improving the system's security and robustness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of intelligent vehicle control technology, specifically relating to a method and system for remote vehicle safety management that combines edge computing and cloud services, and in particular a control architecture that can ensure the safety of local devices in the event of a network outage. Background Technology

[0002] As a mobile vehicle that combines the attributes of both a "house" and a "vehicle," a motorhome integrates complex electrical, plumbing, and HVAC systems. To enhance user experience and management convenience, existing motorhomes are generally equipped with remote monitoring systems, allowing users to view vehicle status in real time and issue control commands via mobile applications. These systems mostly employ a centralized cloud service architecture, where sensor data from inside the vehicle is collected and uploaded to a remote cloud server, and all control logic decisions and command issuance are handled by the cloud server.

[0003] However, the aforementioned technical solutions have an inherent drawback: their reliability is highly dependent on a continuous and stable network connection. RVs are often used in remote areas, mountainous regions, or rural areas where network signal coverage is typically poor or nonexistent. Once the communication link between the RV and the cloud server is interrupted, the entire remote monitoring system will malfunction. In this situation, if emergencies occur inside the vehicle, such as battery over-discharge, short circuits, or water tank leaks, the system will be unable to provide autonomous warnings or timely protective interventions, posing serious risks to vehicle equipment and even personal safety. Traditional control systems cannot perform localized, high-priority safety arbitration under network outage conditions; this is a technical problem that current technologies urgently need to solve.

[0004] Therefore, designing a remote control architecture that can ensure the core safety of RV local equipment and has autonomous emergency handling capabilities even under extreme conditions of network connection interruption has become an important challenge for those skilled in the art. Summary of the Invention

[0005] This invention solves the technical problem that existing vehicle remote monitoring systems rely too heavily on cloud connections, resulting in a loss of security capabilities when the network signal is poor or interrupted. It provides a vehicle remote security management method and system that can prioritize the security of local devices under any network conditions.

[0006] To achieve the above objectives, the present invention provides a remote security management method, comprising: An edge computing node is deployed inside the vehicle, and the edge computing node is electrically connected to and monitors multiple controlled devices inside the vehicle. A data communication link is established between the edge computing node, cloud service node, and mobile application terminal extension node via a wireless network. The edge computing node receives remote control commands from the cloud service node or the mobile application extension node; Before executing the remote control command, the edge computing node obtains local real-time status parameters of at least one of the controlled devices and performs security verification on the remote control command according to preset local security rules. When it is determined that executing the remote control command would violate the local security rules, the edge computing node refuses to execute the remote control command.

[0007] In a preferred embodiment, the local real-time status parameters include at least one of the following: the battery voltage value of the vehicle's main battery, the loop current value flowing through the main circuit, the water level sensor reading of the fresh water tank, or the water level sensor reading of the grey water tank.

[0008] In a preferred embodiment, the local security rules include a set of preset rules, which define the security threshold range of the local real-time status parameters; the security verification step specifically involves determining whether the expected status parameters after executing the remote control command exceed the security threshold range.

[0009] In a preferred embodiment, the method further includes: the cloud service node training and generating a device multidimensional coupling matrix based on the collected historical vehicle operation data, the device multidimensional coupling matrix quantifying the dependency weights and safe operation timing constraints among the multiple controlled devices in terms of electrical load, thermodynamic conduction and water flow; the cloud service node periodically synchronizing the device multidimensional coupling matrix and distributing it to the edge computing node.

[0010] In a preferred embodiment, when communication between the edge computing node and the cloud service node is interrupted, the edge computing node uses the most recently successfully synchronized device multidimensional coupling matrix as the basis for performing local security arbitration.

[0011] In a preferred embodiment, the method further includes: when the edge computing node detects that the local real-time status parameter triggers an emergency protection condition, activating a built-in cascading safety shutdown engine.

[0012] In a preferred embodiment, after the cascaded safety shutdown engine is started, it analyzes the aforementioned device multidimensional coupling matrix to generate a linear action sequence that includes the device shutdown order and delay time.

[0013] In a preferred embodiment, the cascaded safety shutdown engine constructs a directed acyclic graph of the controlled devices in the current active state and their dependencies, and performs a topological sorting algorithm on the directed acyclic graph to generate the linear action sequence without dependency conflicts.

[0014] In a preferred embodiment, the method further includes: after the edge computing node executes each shutdown action in the linear action sequence, monitoring the physical parameters of the associated controlled device in real time, and using the physical parameters as physical credentials to satisfy the removal of dependencies in the device's multidimensional coupling matrix, thereby forming a closed-loop verification.

[0015] In a preferred embodiment, the physical parameter is the output current waveform of a current sensor. When the output current waveform switches from a load state characteristic to an no-load state characteristic, it is determined that the corresponding controlled device has been successfully turned off.

[0016] Accordingly, the present invention also provides a remote safety management and control system, comprising: an edge computing node, the edge computing node including a processor and a memory, the memory storing a computer program, and the computer program being executed by the processor to implement the steps of the vehicle remote safety management and control method as described in any of the above embodiments.

[0017] Compared with existing technologies, the advantages of this invention are as follows: By constructing an "edge-first" control arbitration logic, even when the vehicle is completely disconnected from the network, the edge computing node can still independently execute the highest priority local safety rules, and intervene in a timely manner in sudden dangerous situations such as short circuits, water leaks, and battery depletion, effectively solving the technical pain point of traditional cloud control solutions malfunctioning when there is no network. The edge computing node is given the right to veto remote commands, and can reject unreasonable commands that may damage the vehicle's local system based on local real-time status data, thereby ensuring the safety of the core energy system and critical equipment, and significantly improving the robustness of the entire control system. Furthermore, by introducing a cloud-trained multi-dimensional coupling matrix for devices and a cascaded safety shutdown engine running at the edge, the traditional emergency power-off is upgraded to an orderly shutdown process that follows the physical characteristics of the devices. This method can avoid secondary damage to the devices caused by improper shutdown timing, thereby extending the service life of the devices and reducing maintenance costs. Attached Figure Description

[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a schematic diagram of a three-layer architecture of a remote security management system provided in an embodiment of the present invention.

[0020] Figure 2 This is an edge-first arbitration flowchart of a remote security management method provided in an embodiment of the present invention.

[0021] Figure 3 This is a block diagram of the internal functional modules of the edge computing node provided in an embodiment of the present invention.

[0022] Figure 4 This is a flowchart of the cascaded safety shutdown engine provided in an embodiment of the present invention. Detailed Implementation

[0023] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.

[0024] This embodiment provides a vehicle remote safety management system and method with physical safety perception and intelligent decision-making capabilities. By constructing a cloud-edge-device collaborative architecture and granting the edge device the highest security decision-making authority, the system ensures the safe operation of vehicles in various network environments.

[0025] Reference Figure 1 The vehicle remote safety management system in this embodiment adopts a three-layer heterogeneous node architecture, specifically including: edge computing node 101, cloud service node 102, and mobile application terminal extension node 103.

[0026] Edge computing node 101 is located inside the vehicle and serves as the local control core of the entire system. It can be physically integrated into the vehicle's central touchscreen host or a standalone embedded controller. Edge computing node 101 establishes electrical connections and data communication with multiple controlled devices 104 within the vehicle via wired or wireless means. These controlled devices 104 include, but are not limited to, inverters, battery management systems, solar controllers, diesel heaters, water pumps, lighting systems, and solenoid valves.

[0027] Cloud service node 102 is typically deployed on a remote server and possesses powerful computing and storage capabilities. It establishes a data communication link with edge computing node 101 via a wireless network. Cloud service node 102 is primarily responsible for receiving historical vehicle operation data periodically uploaded by edge computing node 101, performing long-term storage, big data analysis, and machine learning model training, but does not directly participate in emergency safety control.

[0028] Mobile application extension node 103 is an application running on a smart terminal device. Through the human-machine interface provided by this node, users can remotely view the vehicle's real-time status information and generate and send remote control commands.

[0029] The system also includes a power supply module for providing stable power to the various electronic components.

[0030] Reference Figure 3 The internal structure of the edge computing node 101 will be described in detail below. In this embodiment, the edge computing node 101 includes a processor 301 and a non-volatile memory 302 connected to the processor 301 for storing the operating system, applications, and critical configuration data, especially preset local security logic.

[0031] The edge computing node 101 also integrates multiple communication interfaces 303. For example, it communicates with the vehicle chassis control network segment via a controller area network bus interface; connects to the main equipment network segment of the living area via an RS485 bus interface; and connects to some low-speed sensors and actuators via a local interconnect network bus. Simultaneously, it communicates remotely with the cloud service node 102 and the mobile application extension node 103 via a mobile communication module. Furthermore, the edge computing node 101 also includes multiple sensor interfaces 304 for connecting various sensors to collect local real-time status parameters.

[0032] In this embodiment, the sensors connected to the sensor interface 304 may include: a voltage sensor for monitoring the main battery voltage, a Hall current sensor for monitoring the main circuit current, and a photoelectric level sensor for monitoring the liquid level in the clean water tank or grey water tank. The physical quantities collected by these sensors constitute local real-time status parameters. It should be noted that the above sensor types are merely examples, and this application is not limited thereto; those skilled in the art can implement this application using other types of sensors.

[0033] Based on the above system architecture, the workflow of the vehicle remote safety management method provided by this invention is as follows: Figure 2 As shown, the specific steps include: The system establishes a communication link. Edge computing node 101 establishes a wireless data communication link with cloud service node 102 and mobile application extension node 103 through its built-in communication interface 303. Simultaneously, it maintains communication with multiple controlled devices 104 within the vehicle via a bus, continuously monitoring their operational status.

[0034] Edge computing node 101 receives remote control commands. These commands can be sent via mobile application extension node 103, forwarded by cloud service node 102, or sent directly to edge computing node 101 in LAN mode.

[0035] Performing local security checks. This is a core step of the invention, embodying the "edge-first" arbitration logic. Before executing any received remote control command, the processor 301 of the edge computing node 101 performs security checks. Specifically, the processor 301 obtains at least one local real-time status parameter of the controlled device 104 associated with the command through the sensor interface 304. For example, if the command is "turn on the water heater," the key local real-time status parameter is the battery voltage value of the vehicle's main battery.

[0036] Simultaneously, the processor 301 retrieves preset local security rules from the non-volatile memory 302. These rules can be a set of rules, stored in the form of a lookup table or rule script. This set of rules defines the security threshold ranges for critical state parameters. For example, a rule could be defined as: "When the main battery voltage is below 11.8V, prohibit the startup of any device with a power greater than 500W."

[0037] Processor 301 makes a decision. It determines whether the expected state parameters after executing the remote control command will exceed the safety threshold range defined by the local safety rules. For example, if starting the water heater causes the voltage to drop instantly to below 11.8V when the battery voltage is 11.9V, it is determined to be a violation of the local safety rules.

[0038] The instruction will be executed or rejected based on the judgment result. If the judgment result is negative, the processor 301 controls the corresponding controlled device 104 to execute the instruction. If the judgment result is positive, the edge computing node 101 will refuse to execute the remote control instruction and may selectively send a rejection feedback message and reason to the mobile application extension node 103 and / or cloud service node 102.

[0039] Through the above process, this system ensures that the vehicle's local security always has the highest priority, regardless of network conditions, thus preventing damage to the vehicle from unreasonable remote commands.

[0040] To further enhance the system's intelligence and the sophistication of equipment protection, this embodiment also introduces a deep security mechanism that combines cloud knowledge with edge execution.

[0041] The concept of a device multidimensional coupling matrix is ​​introduced. Cloud service node 102 includes a training module for machine learning based on historical data. This module is responsible for analyzing historical operating and fault data collected from a large number of similar vehicles to identify the hidden dependencies and safe operating sequences among different controlled devices 104 in multiple dimensions, such as electrical load, thermodynamic conduction, and water flow. For example, data analysis reveals that "after the diesel heater is shut off, its internal combustion chamber requires the cooling fan to continue operating for at least 3 minutes before safe power disconnection; otherwise, carbon buildup is likely." This knowledge is quantified into dependency weights and timing constraints, and constructed into a device multidimensional coupling matrix.

[0042] Logically, the multidimensional coupling matrix of this device can be represented as a weighted directed graph. ,in Represents a set of device nodes. This represents the set of dependencies between them. Specifically, the matrix is ​​stored in the non-volatile memory 302 of the edge computing node 101 in a lightweight file format or adjacency list, and each entry contains the following key fields: source device ID, target device ID, dependency type, dependency strength, security timing window, and fallback rule.

[0043] The training module of cloud service node 102 periodically updates the device multidimensional coupling matrix and synchronously distributes it to edge computing node 101 via an encrypted communication link. When communication between edge computing node 101 and cloud service node 102 is interrupted, it will use the most recently successfully synchronized matrix version as the basis for performing local complex security arbitration, ensuring the continuity of knowledge.

[0044] In the processor 301 of the edge computing node 101, a cascaded safety shutdown engine module 305 also runs. This engine module is configured to be activated when local real-time status parameters are detected and preset emergency protection conditions are triggered. These emergency protection conditions can be a "severely low battery" alarm issued by the battery management system, or a "one-click exit" command issued via the mobile application extension node 103 or the in-vehicle screen.

[0045] Reference Figure 4 The workflow of the cascaded safety shutdown engine 305 is as follows: Step S401, the engine is activated (emergency protection condition detected): When an emergency protection condition is detected, the engine will intercept all direct power-off commands.

[0046] Step S402, parsing the coupling matrix and constructing the dependency graph: The engine retrieves the device multidimensional coupling matrix stored in non-volatile memory 302. Then, it traverses the set of all currently active device nodes and constructs a directed acyclic graph containing only these active devices based on the dependencies defined in the coupling matrix.

[0047] Step S403: Perform topology sorting to generate a shutdown sequence: The engine performs a topology sorting algorithm on the constructed directed acyclic graph. The principle of topology sorting is that device nodes with no in-degree should be shut down first. In this way, the engine can generate a linear sequence of actions that is conflict-free and conforms to physical safety specifications. This sequence not only defines the shutdown order of the devices, but may also include delay times determined by a safety timing window. For example, a safe shutdown sequence might be: first turn off the faucet, then turn off the water pump after a 500-millisecond delay, then wait for the diesel heater fan to stop, and finally cut off the main power supply to the living area.

[0048] Step S404, Execute Sequence and Perform Closed-Loop Verification: Based on the generated linear action sequence, processor 301 sends shutdown commands to the relevant controlled devices 104 sequentially through the control actuator. This process forms a tight closed-loop verification with real-time sensor data. After each shutdown action in the execution sequence, processor 301 monitors the physical parameters of the associated controlled devices in real time and uses the changes in these parameters as physical evidence of the removal of dependencies in the coupling matrix. For example, after shutting down the cooling fan of the diesel heater, the system continuously monitors its loop current through a Hall current sensor. Only when the current waveform switches from the characteristics of a load state to the characteristics of an no-load state does the system determine that the fan has successfully stopped rotating and continue to execute the next action in the sequence.

[0049] This mechanism ensures that the shutdown operation follows prior knowledge of equipment protection while adapting to actual response delays caused by factors such as equipment aging, thus achieving intelligent and safe shutdown.

[0050] In summary, this invention, by constructing an edge computing-first, cloud-edge collaborative intelligent management and control system, not only solves the core pain point of lack of vehicle security in network-free environments, but also elevates security protection to a new level of refinement and intelligence by introducing a device coupling knowledge base and a cascade shutdown engine, significantly improving vehicle safety, reliability, and equipment lifespan.

[0051] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A remote security management method, characterized in that, include: An edge computing node is deployed inside the vehicle, and the edge computing node is electrically connected to and monitors multiple controlled devices inside the vehicle. A data communication link is established between the edge computing node, cloud service node, and mobile application terminal extension node via a wireless network. Receive remote control commands from the cloud service node or the mobile application extension node; Before executing the remote control command, at least one local real-time status parameter of the controlled device is obtained, and the remote control command is security verified according to preset local security rules. If it is determined that executing the remote control command would violate the local security rules, the execution of the remote control command is refused.

2. The method according to claim 1, characterized in that, The local real-time status parameters include at least one of the following: the battery voltage value of the vehicle's main battery, the loop current value flowing through the main circuit, the water level sensor reading of the fresh water tank, or the water level sensor reading of the grey water tank.

3. The method according to claim 1, characterized in that, The local security rules include a set of preset rules, which define the security threshold range of the local real-time status parameters; the security verification step specifically involves determining whether the expected status parameters after executing the remote control command exceed the security threshold range.

4. The method according to claim 1, characterized in that, Also includes: Based on the collected historical vehicle operation data, a multidimensional coupling matrix of devices is trained and generated. The multidimensional coupling matrix of devices quantifies the dependence weights and safe operation timing constraints among the multiple controlled devices in terms of electrical load, thermodynamic conduction and water flow. The device's multidimensional coupling matrix is ​​periodically synchronized and distributed to the edge computing node.

5. The method according to claim 4, characterized in that, When communication between the edge computing node and the cloud service node is interrupted, the most recently successfully synchronized device multidimensional coupling matrix is ​​used as the basis for performing local security arbitration.

6. The method according to claim 4, characterized in that, Also includes: When the edge computing node detects that the local real-time status parameters trigger emergency protection conditions, it activates the built-in cascading safety shutdown engine.

7. The method according to claim 6, characterized in that, After the cascaded safety shutdown engine is started, it analyzes the device multidimensional coupling matrix to generate a linear action sequence containing the device shutdown order and delay time. The cascaded safety shutdown engine constructs a directed acyclic graph (DAG) of the controlled devices in the current active state and their dependencies, and performs a topological sorting algorithm on the DAG to generate the linear action sequence without dependency conflicts.

8. The method according to claim 7, characterized in that, Also includes: After the edge computing node executes each shutdown action in the linear action sequence, the physical parameters of the associated controlled device are monitored in real time, and the physical parameters are used as physical credentials to satisfy the removal of dependencies in the device's multidimensional coupling matrix, forming a closed-loop verification.

9. The method according to claim 8, characterized in that, The physical parameter is the output current waveform of the current sensor. When the output current waveform switches from the load state characteristic to the no-load state characteristic, it is determined that the corresponding controlled device has been successfully turned off.

10. A remote security management and control system, characterized in that, The method includes an edge computing node, which includes a processor and a memory. The memory stores a computer program, which, when executed by the processor, implements the steps of the vehicle remote safety management method as described in any one of claims 1 to 9.