A security integration platform architecture based on intelligent access and control unit
Through the security integrated platform architecture based on intelligent access and control units, unified access and edge computing of each subsystem in the rail transit system is realized, equipment redundancy and resource waste are solved, system reliability and response speed are improved, and construction and maintenance costs are reduced.
Patent Information
- Application Number
- CN202110066612.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-01-19
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2041-01-19
AI Technical Summary
The independent access and independent networking of each subsystem in the rail transit system leads to serious equipment redundancy, increasing construction and maintenance costs, serious waste of resources, lack of horizontal convergence of information flow, and the control flow cannot sink to the edge, extending the system linkage path.
It adopts a security integration platform architecture based on intelligent access and control units, including iACU main body, linkage engine, access gateway, site-level, line-level and road network-level security integration platforms. Through layered design and edge computing, unified access and data processing of each subsystem is realized.
Reduce the number of access equipment and total wiring, reduce energy consumption and maintenance costs, improve resource utilization and system response speed, promote the integration of resources across majors and systems, and reduce construction and maintenance investment.
Smart Images

Figure CN114866861B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security technology, and in particular to a security integration platform architecture based on an intelligent access and control unit. Background Art
[0002] With the rapid development of information technology, information services have penetrated into all aspects of people's lives, and higher requirements have been put forward for the reliability and integration of information systems, especially in the rail transit industry. Each subsystem is independently accessed, independently networked, and self-contained. In particular, the redundancy of equipment on the access side is serious, which increases the current construction cost of rail transit and the subsequent spare parts maintenance cost. The waste of resources is particularly serious. At the same time, the information flow lacks horizontal convergence, and the control flow cannot be sunk to the edge, which greatly extends the path of multi-system linkage. For this reason, the present invention realizes unified access of each subsystem element and performs edge computing processing through the device, thereby improving the level of access concentration, reducing access equipment and the resulting inventory maintenance and other investments, improving resource intensive utilization, improving the response speed of the system, and improving the reliability of the security integration platform and access network to solve the above problems. Summary of the Invention
[0003] In view of the deficiencies of the prior art, the present invention provides a security integration platform architecture based on an intelligent access and control unit to solve the problems raised in the above background technology.
[0004] To achieve the above-mentioned objectives, the present invention provides the following technical solutions: a security integration platform architecture based on an intelligent access and control unit, comprising an iACU main body, a linkage engine, an access gateway, a site-level security integration platform, a line-level security integration platform and a road network-level security integration platform, wherein the road network-level security integration platform is electrically connected to the line-level security integration platform, the line-level security integration platform is electrically connected to the site-level security integration platform, and the site-level security integration platform is electrically connected to the iACU main body, a linkage engine and an access gateway are deployed on the iACU main body, and the iACU main body is composed of an interface board, a switch board and a main control board, and the interface board realizes access to optical ports, electrical ports, 232 / 485 serial ports and DI / DO ports.
[0005] To further optimize this technical solution, the interface board can realize the access of optical ports, electrical ports, 232 / 485 serial ports and DI / DO ports, and the access capacity can be expanded to meet different access requirements. The switch board independently realizes the data exchange of the three-layer switch, including support for VLAN, STP / RSTP, and IGMP Snooping protocols. The main control board is based on ARM architecture and runs embedded system software to realize data caching and data edge processing.
[0006] To further optimize this technical solution, the iACU main body refers to an integrated access and edge computing device based on ARM architecture.
[0007] To further optimize this technical solution, the linkage engine refers to a software computing module for event linkage processing deployed on the iACU, the site-level security integration platform, the line-level security integration platform, and the road network-level security integration platform.
[0008] To further optimize this technical solution, the access gateway refers to an x86-based access device or iACU.
[0009] To further optimize this technical solution, the site-level security integration platform refers to the site-level security integration platform software and equipment installed in mainline stations, parking lots, vehicle depots, etc. in accordance with the requirements of public safety prevention and monitoring management and the requirements of "GB51151-2016".
[0010] To further optimize this technical solution, the line-level security integration platform refers to the line-level security integration platform software and equipment set up in the line center in accordance with the requirements of public security prevention and monitoring management and the requirements of "GB51151-2016".
[0011] To further optimize this technical solution, the road network-level security integration platform refers to the multi-line-level security integration platform software and equipment set up in the road network center in accordance with the requirements of public safety prevention, monitoring and management, and the requirements of "GB51151-2016".
[0012] A security integration platform architecture based on an intelligent access and control unit, characterized in that a data stream processing method of the security integration platform based on iACU comprises the following steps:
[0013] The terminal's subsystem and site-level security integration platform, as well as other upper-layer platforms;
[0014] S1. Configure linkage rules and desktop plans within iACU on the site-level security integration platform;
[0015] S2. Configure cross-iACU linkage rules and desktop plans on the site-level security integration platform;
[0016] S3. Configure cross-site linkage rules and desktop plans on the line-level security integration platform;
[0017] S4. Configure a cross-line linkage rule set desktop plan on the road network-level security integration platform;
[0018] S5. When a terminal reports an alarm event, the data is cached, distributed, and processed on the iACU and distributed to the terminal's subsystem, site-level security integration platform, and other upper-level platforms;
[0019] S6. When the upper-layer platform fails offline or communication fails, data is cached and the data of the fault phase is re-uploaded after communication is restored, including alarm event data, terminal status data, and fault alarm data;
[0020] S7: After receiving the reported alarm event data, iACU decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage with the devices connected to iACU; and reports the data to the site-level security integration platform;
[0021] S8. After receiving the uplink data, the site-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage between different iACU devices within the site; and reports the data to the line-level security integration platform.
[0022] S9. After receiving the uplink data, the line-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage between different iACU devices across sites; and reports the data to the road network-level security integration platform;
[0023] S10. After receiving the uplink data, the road network-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage between different iACU downstream devices across the line.
[0024] Compared with the existing technology, the present invention provides a security integrated platform architecture based on intelligent access and control unit, which has the following beneficial effects:
[0025] The security integration platform architecture based on the intelligent access and control unit, the present invention introduces the iACU intelligent access and control unit equipment, especially its access board, switch board, and main control board's layered design, which improves the access diversity, access reliability, and diverse edge computing capabilities of the equipment. It realizes unified remote access of terminal devices of different subsystems and shared access channels, greatly reducing the number of access devices and the total amount of wiring, reducing energy consumption, spare parts inventory and maintenance manpower investment; through the linkage of hierarchical alarm events, the efficiency of desktop emergency plan linkage is improved; through the different edge computing modules installed on the main control board, various edge data processing is realized. Especially at the moment when rail cloud is becoming increasingly popular, the center's cloud computing is combined with the integrated access and control of the edge. This efficient fusion architecture can further promote the cross-disciplinary and cross-system integration of resources, save energy and reduce consumption, and reduce the current construction investment and later maintenance investment of rail transit. The cost advantage and technical advantages of this technical solution are very obvious. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 This is a schematic diagram of the iACU-based security integration platform architecture based on an intelligent access and control unit proposed in the present invention;
[0027] Figure 2 This is a block diagram of the main architecture of the iACU, a security integrated platform architecture based on intelligent access and control unit proposed in the present invention;
[0028] Figure 3 The data flow and control flow diagram of the iACU-based security integration platform based on the intelligent access and control unit security integration platform architecture proposed by the present invention;
[0029] Figure 4 This is a schematic diagram of the site-level access architecture of a traditional security integration platform based on an intelligent access and control unit proposed by the present invention. DETAILED DESCRIPTION
[0030] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0031] Please refer to Figure 1As shown: The present invention discloses a security integration platform architecture based on an intelligent access and control unit, including an iACU main body, a linkage engine, an access gateway, a site-level security integration platform, a line-level security integration platform, and a road network-level security integration platform. The road network-level security integration platform is electrically connected to the line-level security integration platform, the line-level security integration platform is electrically connected to the site-level security integration platform, and the site-level security integration platform is electrically connected to the iACU main body. The iACU main body is deployed with a linkage engine and an access gateway. The present invention introduces the iACU intelligent access and control unit device, especially its access board, switch board, and main control board. The layered design improves the access diversity, access reliability, and diverse edge computing capabilities of the device. It achieves unified remote access and shared access channels for terminal devices in different subsystems, greatly reducing the number of access devices and the total amount of wiring, reducing energy consumption, spare parts inventory, and maintenance manpower. Through the linkage of hierarchical alarm events, the efficiency of desktop emergency plan linkage is improved. Various edge data processing is achieved through the different edge computing modules installed in the main control board. Especially at the moment when rail cloud is becoming increasingly popular, the combination of central cloud computing and integrated access and control at the edge, this efficient fusion architecture can further promote the integration of resources across disciplines and systems, save energy and reduce consumption, and reduce the current construction investment and subsequent maintenance investment of rail transit. The cost and technical advantages of this technical solution are very obvious.
[0032] like Figure 2 As shown: the iACU body consists of an interface board, a switch board and a main control board. The interface board realizes the access of optical ports, electrical ports, 232 / 485 serial ports and DI / DO ports. The interface board can realize the access of optical ports, electrical ports, 232 / 485 serial ports and DI / DO ports, and the access capacity can be expanded to meet different access requirements. The switch board independently realizes the data exchange of the three-layer switch, including supporting VLAN, STP / RSTP, IGMP Snooping protocols. The main control board is based on ARM architecture and runs embedded system software to realize data caching and data edge processing, as shown below Figure 1 As shown in the figure: This device is deployed close to the terminal equipment, which greatly reduces the number of access devices and wiring. At the same time, based on the fault bypass function, it improves the reliability of the access network. It can also cache and forward data when a link communication failure occurs. At the same time, it can support data distribution on multiple northbound platforms and is flexible for expansion.
[0033] like Figure 4As shown: video surveillance systems, security inspection and detection systems, access control systems, intrusion alarm systems, electronic patrol systems, parking lot management systems, etc. are all independently accessed. Access equipment includes optical fibers, optical fiber transceivers, splitters, pigtails, ONUs, layer 2 switches, layer 3 switches, routers, twisted pair cables, junction boxes, etc., as well as supporting power supply networks for these devices. There is a lot of repeated investment in the early stage, access equipment cannot be shared, and the later spare parts and maintenance costs are high. This architecture uses intelligent access and edge computing unit equipment (hereinafter referred to as iACU) to achieve unified access, data distribution, data edge caching, edge computing and other functions for many subsystem terminal devices. Based on the idea of fusion sharing and distribution, it improves resource utilization and improves the robustness and scalability of the system. The iACU is generally composed of an access board, a switch board, and a main control board. The access board provides access to optical ports, electrical ports, 232 / 485 serial ports, and DI / DO ports, and its access capacity can be expanded to meet different access requirements. The switch board independently implements the data exchange function of a three-layer switch, including support for VLAN, STP / RSTP, IGMP Snooping and other protocols. The main control board is based on the ARM architecture and runs embedded system software to implement data caching, data edge processing and other functions.
[0034] As a specific optimization solution for this embodiment, the iACU main body refers to an integrated access and edge computing device based on the ARM architecture.
[0035] As a specific optimization solution for this embodiment, the linkage engine refers to a software computing module for event linkage processing deployed on iACU, site-level security integration platform, line-level security integration platform, and road network-level security integration platform.
[0036] As a specific optimization solution of this embodiment, the access gateway refers to an x86-based access device or iACU.
[0037] As a specific optimization solution for this embodiment, the site-level security integration platform refers to the site-level security integration platform software and equipment set up in mainline stations, parking lots, vehicle depots, etc. in accordance with the requirements of public safety prevention and monitoring management and the requirements of "GB51151-2016".
[0038] As a specific optimization solution for this embodiment, the line-level security integration platform refers to the line-level security integration platform software and equipment set up in the line center in accordance with the requirements of public security prevention and monitoring management and the requirements of "GB51151-2016".
[0039] As a specific optimization solution for this embodiment, the road network-level security integration platform refers to the multi-line-level security integration platform software and equipment set up in the road network center in accordance with the requirements of public safety prevention and monitoring management and the requirements of "GB51151-2016".
[0040] like Figure 3 As shown: A security integration platform architecture based on intelligent access and control unit, and a security integration platform data stream processing method based on iACU, including the following steps:
[0041] S1. Configure linkage rules and desktop plans within iACU on the site-level security integration platform;
[0042] S2. Configure cross-iACU linkage rules and desktop plans on the site-level security integration platform;
[0043] S3. Configure cross-site linkage rules and desktop plans on the line-level security integration platform;
[0044] S4. Configure a cross-line linkage rule set desktop plan on the road network-level security integration platform;
[0045] S5. When a terminal reports an alarm event, the data is cached, distributed, and processed on the iACU and distributed to the terminal's subsystem, site-level security integration platform, and other upper-level platforms;
[0046] S6. When the upper-layer platform fails offline or communication fails, data is cached and the data of the fault phase is re-uploaded after communication is restored, including alarm event data, terminal status data, and fault alarm data;
[0047] S7: After receiving the reported alarm event data, iACU decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage with the devices connected to iACU; and reports the data to the site-level security integration platform;
[0048] S8. After receiving the uplink data, the site-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to realize the linkage of devices connected to different iACUs within the station; and reports the data to the line-level security integration platform; S9. After receiving the uplink data, the line-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to realize the linkage of devices connected to different iACUs across stations; and reports the data to the road network-level security integration platform; S10. After receiving the uplink data, the road network-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to realize the linkage of devices connected to different iACUs across lines.
[0049] The beneficial effects of the present invention are: the security integration platform architecture based on the intelligent access and control unit, the present invention introduces the iACU intelligent access and control unit equipment, especially its access board, switch board, and main control board layered design, which improves the access diversity, access reliability, and diverse edge computing capabilities of the equipment. It realizes unified remote access of terminal devices of different subsystems and shared access channels, greatly reducing the number of access devices and the total amount of wiring, reducing energy consumption, spare parts inventory and maintenance manpower investment; through the linkage of hierarchical alarm events, the efficiency of desktop plan linkage is improved; through the different edge computing modules installed on the main control board, various edge data processing is realized. Especially at the moment when rail cloud is becoming increasingly popular, the center's cloud computing is combined with the integrated access and control of the edge. This efficient fusion architecture can further promote the integration of resources across disciplines and systems, save energy and reduce consumption, and reduce the current construction investment and later maintenance investment of rail transit. The cost advantage and technical advantages of this technical solution are very obvious.
[0050] The relevant modules involved in this system are all hardware system modules or functional modules that combine computer software programs or protocols with hardware in the existing technology. The computer software programs or protocols involved in the functional modules are themselves technologies that are well known to those skilled in the art and are not improvements to this system. The improvements to this system are the interaction or connection relationships between the modules, that is, improvements to the overall structure of the system to solve the corresponding technical problems to be solved by this system.
[0051] It is worth noting that in the embodiment of the above-mentioned search device, the various units and modules included are only divided according to functional logic, but are not limited to the above-mentioned division, as long as the corresponding functions can be achieved; in addition, the specific names of the functional units are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention.
[0052] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments. Without departing from the concept of the present invention, it may also include many other equivalent embodiments, and the scope of the present invention is determined by the scope of the appended claims.
Claims
1. A security integration platform architecture based on intelligent access and control unit, including iACU main body, linkage engine, access gateway, site-level security integration platform, line-level security integration platform and road network-level security integration platform, characterized by: The road network-level security integration platform is electrically connected to the line-level security integration platform, the line-level security integration platform is electrically connected to the site-level security integration platform, and the site-level security integration platform is electrically connected to the iACU body. The iACU body is deployed with a linkage engine and an access gateway. The iACU body consists of an interface board, a switch board, and a main control board. The interface board enables access to optical ports, electrical ports, 232 / 485 serial ports, and DI / DO ports. The interface board can realize the access of optical port, electrical port, 232 / 485 serial port and DI / DO port, and the access capacity is scalable to meet different access requirements. The switch board independently realizes the data exchange of the three-layer switch, including supporting VLAN, STP / RSTP, and IGMP Snooping protocols. The main control board is based on ARM architecture and runs embedded system software to realize data caching and data edge processing. The iACU main body refers to the integrated access and edge computing device based on the ARM architecture; The linkage engine refers to the software computing module for event linkage processing deployed on the iACU, site-level security integration platform, line-level security integration platform, and road network-level security integration platform; The access gateway refers to an x86-based access device or iACU.
2. The security integrated platform architecture based on intelligent access and control unit according to claim 1, characterized in that: The site-level security integration platform refers to the site-level security integration platform software and equipment installed at mainline stations, parking lots, vehicle depots, etc. in accordance with the requirements of public safety prevention and monitoring management.
3. The security integrated platform architecture based on intelligent access and control unit according to claim 1, characterized in that: The line-level security integration platform refers to the line-level security integration platform software and equipment set up in the line center according to the requirements of public safety prevention and monitoring management.
4. The security integrated platform architecture based on intelligent access and control unit according to claim 1, characterized in that: The road network-level security integration platform refers to the multi-line-level security integration platform software and equipment set up in the road network center according to the requirements of public safety prevention, monitoring and management.
5. The security integrated platform architecture based on intelligent access and control unit according to claim 1, characterized in that: The data stream processing method of the security integration platform based on iACU includes the following steps: S1. Configure linkage rules and desktop plans within iACU on the site-level security integration platform; S2. Configure cross-iACU linkage rules and desktop plans on the site-level security integration platform; S3. Configure cross-site linkage rules and desktop plans on the line-level security integration platform; S4. Configure a cross-line linkage rule set desktop plan on the road network-level security integration platform; S5. When a terminal reports an alarm event, the data is cached, distributed, and processed on the iACU and distributed to the terminal's subsystem, site-level security integration platform, and other upper-level platforms; S6. When the upper-layer platform fails offline or communication fails, data is cached and the data of the fault phase is re-uploaded after communication is restored, including alarm event data, terminal status data, and fault alarm data; S7: After receiving the reported alarm event data, iACU decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage with the devices connected to iACU; and reports the data to the site-level security integration platform; S8. After receiving the uplink data, the site-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage between different iACU devices within the site; and reports the data to the line-level security integration platform. S9. After receiving the uplink data, the line-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage between different iACU devices across sites; and reports the data to the road network-level security integration platform; S10. After receiving the uplink data, the road network-level security integration platform decides whether to start the linkage engine based on the linkage rules and desktop plan configuration to achieve linkage between different iACU downstream devices across the line.
Citation Information
Patent Citations
Rail traffic security and protection integrated platform with linkage and disaster-preventing emergency functions
CN108572606A
Communication manager device of integrated optical fiber ring function
CN206640581U