A chemical park safety monitoring method based on the Internet of Things
By switching to the satellite communication network in the Internet of Things system in the chemical park, the problem of interference or blocking of monitoring equipment is solved, ensuring smooth communication and security of monitoring equipment is achieved, and the impact of network attacks is reduced.
Patent Information
- Application Number
- CN202411292216.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-14
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2044-09-14
AI Technical Summary
Network security issues under the intelligent control of chemical parks, especially the inability to monitor in time, resulting in the interference of monitoring equipment or blocking, which poses security risks.
Receive abnormal information through service management entities and switch to non-terrestrial network services, such as satellite communication, to ensure smooth communication of monitoring terminals and reduce the impact of network attacks.
It effectively reduces the safety hazards caused by signal interference or shielding of monitoring equipment in chemical parks, ensures the normal transmission of monitoring video streams, and improves security and stability.
Smart Images

Figure CN119136165B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of Internet of Things, and in particular to a chemical park safety monitoring method and system based on the Internet of Things. Background Art
[0002] Chemical parks are a vital component of industrial production, and their safe operation is crucial to a country's economic development and social stability. With the continuous advancement of technology, chemical parks have gradually adopted intelligent and unmanned operations, effectively improving production efficiency, reducing human error, and ensuring the safety and stability of the production process. However, the implementation of intelligent control also brings new security issues, particularly network security.
[0003] Specifically, intelligent control in chemical parks primarily involves connecting various sensors, actuators, controllers, and other devices to a network, enabling information exchange and collaborative work between devices. This intelligent control approach can effectively improve production efficiency, reduce human error, and ensure the safety and stability of the production process. However, the implementation of intelligent control also brings new security issues, particularly network security. If an attacker launches a cyberattack on a chemical park, interfering with the signal through methods such as signal jamming and shielding, the monitoring equipment within the park will be disrupted, rendering it unable to monitor properly. Consequently, in intelligent and unmanned scenarios, it is impossible to promptly determine whether any unauthorized individuals have entered the park, potentially impacting or even endangering production, posing a security risk.
[0004] Therefore, for chemical parks, how to take effective safety measures to reduce safety risks is a current research issue. Summary of the Invention
[0005] The embodiments of the present application provide a chemical park security monitoring method and system based on the Internet of Things, which are used to reduce security risks by switching networks with different communication modes.
[0006] To achieve the above objectives, this application adopts the following technical solutions:
[0007] In a first aspect, a chemical park security monitoring method based on the Internet of Things is provided, the method comprising: a service management entity receiving exception information reported from a first access point, wherein the exception information is used to indicate that a communication abnormality has occurred in multiple terminals accessing the first access point, the signal range of the first access point covers the chemical park, and the first access point provides terrestrial network services; if a monitoring terminal among the multiple terminals meets a preset condition, the service management entity determines that a security abnormality has occurred in the monitoring terminal; in the event of a security abnormality occurring in the monitoring terminal, the service management entity instructs a second access point capable of providing non-terrestrial network services to provide the non-terrestrial network services to the multiple terminals, the signal range of the second access point covering the chemical park.
[0008] Optionally, the preset conditions satisfied by the monitoring terminal among multiple terminals include one or more of the following: the number of monitoring terminals is greater than or equal to a first upper limit number; or; when the number of multiple terminals is greater than or equal to a second upper limit number, the proportion of the number of monitoring terminals in the multiple terminals is greater than or equal to the upper limit of the number proportion; or; the number of monitoring terminals is greater than or equal to the first upper limit number, and the number of multiple terminals is greater than or equal to the second upper limit number.
[0009] Optionally, the method also includes: the service management entity obtains the respective contexts of the multiple terminals from the service management entity locally or from the data management network element based on the respective identifiers of the multiple terminals in the exception information; the service management entity determines the terminals among the multiple terminals whose device types are non-mobile and have visual monitoring capabilities based on the respective device types of the terminals in the respective contexts of the multiple terminals, wherein the terminals whose device types are non-mobile and have visual monitoring capabilities are monitoring terminals.
[0010] Optionally, if the monitoring terminal among multiple terminals meets the preset conditions, the service management entity determines that a security anomaly occurs in the monitoring terminal, including: if the monitoring terminal among multiple terminals meets the preset conditions, the service management entity determines whether the monitoring terminal is located in an area with a high security level, wherein the area with a high security level refers to an area with a security level greater than the level threshold; if the monitoring terminal is located in an area with a high security level, the service management entity determines that a security anomaly occurs in the monitoring terminal.
[0011] Optionally, the service management entity determines whether the monitoring terminal is located in an area with a high security level, including: the service management entity obtains information about the monitoring service of the application network element for the monitoring terminal from the application network element serving the monitoring terminal based on the identification of the monitoring terminal, wherein the monitoring service of the application network element for the monitoring terminal indicates that the monitoring service needs to be executed by the monitoring terminal, and the information about the monitoring service of the application network element for the monitoring terminal is used to indicate the multiple areas covered by the service and the respective security levels of the multiple areas; the service management entity determines one or more areas in the multiple areas where the monitoring terminal is located, if the number of areas with high security levels in one or more areas exceeds a preset number threshold, the service management entity determines that the monitoring terminal is located in the area with a high security level, otherwise, the service management entity determines that the monitoring terminal is not located in the area with a high security level.
[0012] Optionally, the service management entity instructs a second access point capable of providing non-terrestrial network services to provide non-terrestrial network services to multiple terminals, including: the service management entity determines whether multiple terminals have accessed the second access point through non-terrestrial network access; if multiple terminals have accessed the second access point through non-terrestrial network access, the service management entity instructs the second access point to provide enhanced services of the non-terrestrial network for the multiple terminals; if multiple terminals have not accessed the second access point through non-terrestrial network access, the service management entity instructs the second access point to access the multiple terminals through non-terrestrial network access, and provides enhanced services of the non-terrestrial network for the multiple terminals when all the terminals access the second access point.
[0013] Optionally, the service management entity determines whether multiple terminals have accessed the second access point through a non-terrestrial network access method, including: the service management entity determines whether there is an identifier of the second access point in the context of each of the multiple terminals; if there is an identifier of the second access point in the context of each of the multiple terminals, it indicates that the multiple terminals have accessed the second access point through the non-terrestrial network access method; if there is no identifier of the second access point in the context of each of the multiple terminals, it indicates that the multiple terminals have not accessed the second access point through the non-terrestrial network access method.
[0014] Optionally, the service management entity instructs the second access point to provide enhanced services of the non-terrestrial network for multiple terminals, including: the service management entity sends indication information to the second access point, wherein the indication information carries multiple terminals and information for indicating enhanced services to jointly indicate that the second access point needs to provide enhanced services of the non-terrestrial network for multiple terminals, and the enhanced service of the non-terrestrial network means that the second access point needs to establish two or more connections for each of the multiple terminals at the same time.
[0015] Optionally, the service management entity instructs the second access point to access multiple terminals through a non-terrestrial network access method, and provides enhanced services of the non-terrestrial network for the multiple terminals when the multiple terminals all access the second access point, including: the service management entity selects an access network device related to the first access point, wherein the access network device related to the first access point is the second access point; the service management entity sends indication information to the second access point, wherein the indication information carries multiple terminals, information for indicating that the terminals are accessed through a non-terrestrial network method, and information for indicating enhanced services to jointly indicate that the second access point needs to access the multiple terminals through a non-terrestrial network access method, and when the multiple terminals all access the second access point, provides enhanced services of the non-terrestrial network for the multiple terminals, and the enhanced service of the non-terrestrial network means that the second access point needs to establish two or more connections for each of the multiple terminals at the same time.
[0016] Optionally, the abnormality information includes at least one of the following information: an identifier of the first access point, identifiers of each of the multiple terminals, or signal strength change information of each of the multiple terminals, where the signal strength change information of each of the multiple terminals is used to indicate that the communication signal strengths of each of the multiple terminals have changed from being higher than an upper communication limit to being lower than a lower communication limit; and the at least one piece of information is used to jointly indicate that a communication abnormality has occurred in the multiple terminals accessing the first access point.
[0017] On the second aspect, a remote visual security prevention and command and dispatch device based on 5G enhancement is provided, which is configured as follows: a service management entity receives abnormal information reported from a first access point, wherein the abnormal information is used to indicate that communication abnormalities have occurred in multiple terminals accessing the first access point, the signal range of the first access point covers the chemical park, and the first access point provides ground network services; if the monitoring terminal among the multiple terminals meets the preset conditions, the service management entity determines that a security abnormality has occurred in the monitoring terminal; in the event of a security abnormality in the monitoring terminal, the service management entity instructs a second access point capable of providing non-ground network services to provide non-ground network services to multiple terminals, and the signal range of the second access point covers the chemical park.
[0018] Optionally, the preset conditions satisfied by the monitoring terminal among multiple terminals include one or more of the following: the number of monitoring terminals is greater than or equal to a first upper limit number; or; when the number of multiple terminals is greater than or equal to a second upper limit number, the proportion of the number of monitoring terminals in the multiple terminals is greater than or equal to the upper limit of the number proportion; or; the number of monitoring terminals is greater than or equal to the first upper limit number, and the number of multiple terminals is greater than or equal to the second upper limit number.
[0019] Optionally, the device is configured as a service management entity that obtains the respective contexts of multiple terminals from the service management entity locally or from a data management network element based on the respective identifiers of the multiple terminals in the exception information; the service management entity determines the terminal whose device type is non-mobile and has visual monitoring capability among the multiple terminals based on the respective device types of the terminals in the respective contexts of the multiple terminals, wherein the terminal whose device type is non-mobile and has visual monitoring capability is a monitoring terminal.
[0020] Optionally, the device is configured as follows: if the monitoring terminal among multiple terminals meets preset conditions, the service management entity determines whether the monitoring terminal is located in an area with a high security level, wherein the area with a high security level refers to an area with a security level greater than a level threshold; if the monitoring terminal is located in an area with a high security level, the service management entity determines that a security abnormality has occurred in the monitoring terminal.
[0021] Optionally, the device is configured as follows: the service management entity obtains information about the monitoring service of the application network element for the monitoring terminal from the application network element serving the monitoring terminal based on the identification of the monitoring terminal, wherein the monitoring service of the application network element for the monitoring terminal indicates that the monitoring service needs to be executed by the monitoring terminal, and the information about the monitoring service of the application network element for the monitoring terminal is used to indicate the multiple areas covered by the service and the security levels of the multiple areas; the service management entity determines one or more areas in the multiple areas where the monitoring terminal is located, and if the number of areas with high security levels in one or more areas exceeds a preset number threshold, the service management entity determines that the monitoring terminal is located in the area with high security levels; otherwise, the service management entity determines that the monitoring terminal is not located in the area with high security levels.
[0022] Optionally, the device is configured as follows: the service management entity determines whether multiple terminals have accessed the second access point through a non-terrestrial network access method; if multiple terminals have accessed the second access point through a non-terrestrial network access method, the service management entity instructs the second access point to provide enhanced services of the non-terrestrial network for the multiple terminals; if multiple terminals have not accessed the second access point through a non-terrestrial network access method, the service management entity instructs the second access point to access the multiple terminals through a non-terrestrial network access method, and provides enhanced services of the non-terrestrial network for the multiple terminals when all the terminals access the second access point.
[0023] Optionally, the device is configured as follows: the service management entity determines whether there is an identifier of the second access point in the context of each of the multiple terminals; if there is an identifier of the second access point in the context of each of the multiple terminals, it indicates that the multiple terminals have accessed the second access point through a non-terrestrial network access method; if there is no identifier of the second access point in the context of each of the multiple terminals, it indicates that the multiple terminals have not accessed the second access point through a non-terrestrial network access method.
[0024] Optionally, the device is configured as follows: the service management entity sends indication information to the second access point, wherein the indication information carries multiple terminals and information for indicating enhanced services to jointly indicate that the second access point needs to provide enhanced services of non-terrestrial networks for multiple terminals, and the enhanced services of non-terrestrial networks mean that the second access point needs to establish two or more connections for each of the multiple terminals at the same time.
[0025] Optionally, the device is configured as follows: a service management entity selects an access network device associated with a first access point, wherein the access network device associated with the first access point is a second access point; the service management entity sends indication information to the second access point, wherein the indication information carries multiple terminals, information for indicating that the terminals are to be accessed through a non-terrestrial network, and information for indicating enhanced services to jointly indicate that the second access point needs to access the multiple terminals through a non-terrestrial network access method, and when the multiple terminals all access the second access point, provides enhanced services of the non-terrestrial network for the multiple terminals, wherein the enhanced service of the non-terrestrial network means that the second access point needs to establish two or more connections for each of the multiple terminals at the same time.
[0026] Optionally, the abnormality information includes at least one of the following information: an identifier of the first access point, identifiers of each of the multiple terminals, or signal strength change information of each of the multiple terminals, where the signal strength change information of each of the multiple terminals is used to indicate that the communication signal strengths of each of the multiple terminals have changed from being higher than an upper communication limit to being lower than a lower communication limit; and the at least one piece of information is used to jointly indicate that a communication abnormality has occurred in the multiple terminals accessing the first access point.
[0027] In summary, when the service management entity determines that a security anomaly has occurred in the monitoring terminal, or that the monitoring terminal has been interfered with or shielded by the signal through the abnormal information reported by the first access point providing terrestrial network services, the service management entity can instruct the second access point to provide non-terrestrial network services to multiple terminals, that is, satellite communication services to resolve security risks caused by interference or shielding of the terrestrial signals of the monitoring equipment, that is, to reduce the impact of network attacks by switching networks with different communication methods to reduce security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 A schematic diagram of the architecture of the Internet of Things system provided in an embodiment of the present application;
[0029] Figure 2 A schematic diagram of a process flow of a chemical park safety monitoring method based on the Internet of Things provided in an embodiment of the present application;
[0030] Figure 3 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0031] For ease of understanding, the technical terms involved in the embodiments of this application are first introduced below.
[0032] In the embodiment of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information (such as the first indication information, the second indication information, or the third indication information below) is called information to be indicated. In the specific implementation process, there are many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated can be directly indicated, such as the information to be indicated itself or the index of the information to be indicated. The information to be indicated can also be indirectly indicated by indicating other information, where there is an association between the other information and the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information can be achieved by means of the arrangement order of each piece of information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent. At the same time, the common parts of each piece of information can be identified and indicated uniformly to reduce the indication overhead caused by indicating the same information separately.
[0033] In addition, the specific indication method can also be various existing indication methods, such as but not limited to the above-mentioned indication methods and various combinations thereof. The specific details of the various indication methods can be referred to the prior art and will not be repeated herein. As can be seen from the above, for example, when it is necessary to indicate multiple information of the same type, there may be a situation where the indication methods for different information are different. In the specific implementation process, the required indication method can be selected according to specific needs. The embodiment of the present application does not limit the selected indication method. In this way, the indication method involved in the embodiment of the present application should be understood to cover various methods that can enable the party to be indicated to obtain the information to be indicated.
[0034] "Pre-definition" or "pre-configuration" can be implemented by pre-saving corresponding codes, tables or other methods that can be used to indicate relevant information in the device, and the embodiments of the present application do not limit the specific implementation method. Among them, "saving" can mean saving in one or more memories. The one or more memories can be set separately or integrated in an encoder or decoder, a processor, or a communication device. The one or more memories can also be partially set separately and partially integrated in a decoder, a processor, or a communication device. The type of memory can be any form of storage medium, and the embodiments of the present application do not limit this.
[0035] The "protocol" involved in the embodiments of the present application may refer to a protocol family in the communication field, a standard protocol with a similar protocol family frame structure, or a related protocol used in future communication systems. The embodiments of the present application do not make specific limitations on this.
[0036] In the embodiments of the present application, descriptions such as "when...", "in the case of...", "if" and "if" all mean that the device will perform corresponding processing under certain objective circumstances. It does not limit the time, nor does it require the device to perform judgment actions when implemented, nor does it mean that there are other limitations.
[0037] In the description of the embodiments of the present application, unless otherwise specified, " / " indicates that the objects associated with each other are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present application is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. A and B can be singular or plural. In addition, in the description of the embodiments of the present application, unless otherwise specified, "multiple" refers to two or more than two. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with basically the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit differences. At the same time, in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a concrete way for easy understanding.
[0038] The network architecture and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Ordinary technicians in this field will know that with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0039] To facilitate understanding of the embodiments of the present application, first Figure 2 The communication system shown in FIG is used as an example to describe in detail the communication system applicable to the embodiment of the present application. Figure 2 A schematic diagram of the architecture of a communication system applicable to the chemical park safety monitoring method based on the Internet of Things provided in an embodiment of the present application.
[0040] like Figure 2 As shown, the Internet of Things system mainly includes: a service management entity and an access point.
[0041] The service management entity may be a device that controls and manages the access point, such as a device / entity that manages the domain.
[0042] There can be multiple access points, such as multiple nodes of different types. For example, there can be a first access point and a second access point. The first access point can be a terrestrial access point, such as a ground base station, gateway, or access point, which provides terrestrial network services. In other words, a terminal can access the first access point via a terrestrial network. The second access point can be a satellite access point. Satellites have data processing capabilities and have base station functions or partial base station functions. In other words, satellites can be considered base stations. In other words, the second access point can provide non-terrestrial network services. In other words, a terminal can access the second access point via a non-terrestrial network.
[0043] It's understandable that the above description uses satellites as an example. Satellites can also be replaced with other high altitude platform stations (HAPS) or drones. Satellites can also be further categorized as medium-orbit satellites, high-orbit satellites, inclined geostationary orbit satellites, and geostationary orbit satellites.
[0044] The following will be combined Figure 2 The interaction process between the various network elements / devices in the aforementioned IoT system is specifically described through a method embodiment. The IoT-based chemical park safety monitoring method provided in the embodiments of this application can be applied to the aforementioned IoT system and specifically applied to the various scenarios / processes mentioned in the aforementioned IoT system, which are described in detail below.
[0045] Figure 2 A schematic diagram of a process flow of a chemical park safety monitoring method based on the Internet of Things provided in an embodiment of the present application. The process flow of the chemical park safety monitoring method based on the Internet of Things is as follows:
[0046] S301: A service management entity receives abnormal information reported from a first access point.
[0047] The abnormality information is used to indicate that a communication abnormality has occurred with multiple terminals accessing a first access point, which provides terrestrial network services. For example, the abnormality information includes at least one of the following: an identifier of the first access point, identifiers of each of the multiple terminals, or signal strength change information for each of the multiple terminals. The signal strength change information for each of the multiple terminals indicates that the communication signal strengths of each of the multiple terminals have changed from being above an upper communication limit to being below a lower communication limit. Thus, this at least one piece of information can be used to collectively indicate that a communication abnormality has occurred with the multiple terminals accessing the first access point.
[0048] Exemplarily, the multiple terminals include UE1-UE6, a total of 6 UEs, and the signal strength change information of each UE1-UE6 can indicate that the signal strength of each UE1-UE6 (such as the reference signal strength continuously measured by the first access point) changes from above the communication upper limit value to below the communication lower limit value, and remains below the communication lower limit value for a preset period of time, thereby indicating that the communication of UE1-UE6 may be maliciously interfered with by an attacker.
[0049] S302: If the monitoring terminal among the multiple terminals meets the preset conditions, the service management entity determines that a security abnormality occurs in the monitoring terminal.
[0050] The preset conditions satisfied by the monitoring terminal among multiple terminals may include one or more of the following: the number of monitoring terminals is greater than or equal to the first upper limit number; or; when the number of multiple terminals is greater than or equal to the second upper limit number, the proportion of the number of monitoring terminals in the multiple terminals is greater than or equal to the upper limit of the number proportion; or; the number of monitoring terminals is greater than or equal to the first upper limit number, and the number of multiple terminals is greater than or equal to the second upper limit number; that is, when the number or proportion satisfies the above conditions, the service management entity can determine that the monitoring terminal among multiple terminals meets the preset conditions.
[0051] Continuing with the above example, the first upper limit number is 3, the upper limit number ratio may be 50%, and the second upper limit number is 6. If UE1, UE2, and UE4 among UE1-UE6 are monitoring terminals, the service management entity may determine that the number of monitoring terminals is equal to the first upper limit number, that is, 3, or the service management entity may determine that the ratio of the number of monitoring terminals 3 in the 6 UEs is equal to the upper limit number ratio, that is, 50%, or the service management entity may determine that the number of monitoring terminals 3 is equal to the first upper limit number, and the number of 6 UEs is equal to the second upper limit number, that is, 6.
[0052] In an embodiment of the present application, the service management entity can obtain the respective configuration information of the multiple terminals in the local service management entity based on the respective identifiers of the multiple terminals in the abnormal information. The service management entity can determine the terminal whose device type is a non-mobile device with visual monitoring capability among the multiple terminals based on the respective device types of the terminals in the respective configuration information of the multiple terminals, wherein the terminal whose device type is a non-mobile device with visual monitoring capability is a monitoring terminal. For example, the device type information can be represented by a 2-bit element in the context, such as 00 represents a terminal whose device type is a mobile device, such as a conventional UE, 01 represents a terminal whose device type is a mobile device with visual monitoring capability, such as a mobile monitoring robot, and 10 represents a terminal whose device type is a non-mobile device with visual monitoring capability, that is, a monitoring terminal in an embodiment of the present application, such as a fixed monitoring camera.
[0053] In an embodiment of the present application, if a monitoring terminal among multiple terminals meets a preset condition, the service management entity determines that a security anomaly has occurred in the monitoring terminal, including: if a monitoring terminal among multiple terminals meets the preset condition, the service management entity may determine whether the monitoring terminal is located in a high-security level area, where a high-security level area refers to an area with a security level greater than a level threshold. If the monitoring terminal is located in the high-security level area, the service management entity determines that a security anomaly has occurred in the monitoring terminal.
[0054] For example, the service management entity obtains information about the monitoring service of the application network element (such as the AF mentioned above) for the monitoring terminal from the application network element serving the monitoring terminal based on the identifier of the monitoring terminal. The service management entity is locally configured with a correspondence between the identifier of the terminal and the identifier of the application function serving the terminal. In this way, the service management entity can determine the application network element serving the monitoring terminal and request the application network element to provide information about the monitoring service of the application network element for the monitoring terminal. The monitoring service of the application network element for the monitoring terminal indicates that the monitoring service needs to be executed by the monitoring terminal. The information about the monitoring service of the application network element for the monitoring terminal is used to indicate the multiple areas covered by the service and the security levels of each of the multiple areas. Since the service management entity already performs mobility management on the monitoring terminal and knows the locations of each monitoring terminal, the service management entity can determine one or more areas where the monitoring terminal is located in multiple areas. If the number of high-security areas in one or more areas exceeds a preset number threshold, the service management entity determines that the monitoring terminal is located in an area with a high security level. Otherwise, the service management entity determines that the monitoring terminal is not located in an area with a high security level.
[0055] Continuing with the above example, UE1 is located in area 1, UE2 is located in area 2, and UE4 is located in area 2. If area 1 and area 2 are high security level areas, and the preset number threshold is 1, it means that the preset number threshold is exceeded, and the service management entity determines that the monitoring terminal is located in a high security level area.
[0056] S303: When a security anomaly occurs in the monitoring terminal, the service management entity instructs a second access point capable of providing non-terrestrial network services to provide non-terrestrial network services to multiple terminals.
[0057] The service management entity may determine whether the plurality of terminals have accessed the second access point via a non-terrestrial network access method. For example, the service management entity may determine whether the contexts of the plurality of terminals contain an identifier of the second access point (or, in other words, an identifier of an access network device capable of providing non-terrestrial network services). If the contexts of the plurality of terminals contain an identifier of the second access point, then the plurality of terminals have accessed the second access point via a non-terrestrial network access method. Otherwise, if the contexts of the plurality of terminals do not contain an identifier of the second access point, then the plurality of terminals have not accessed the second access point via a non-terrestrial network access method.
[0058] On this basis, if multiple terminals have accessed the second access point via a non-terrestrial network, the service management entity instructs the second access point to provide enhanced services for the non-terrestrial network for the multiple terminals. For example, the service management entity may send indication information to the second access point. The indication information carries multiple terminals and information indicating the enhanced services, thereby jointly instructing the second access point to provide enhanced services for the multiple terminals. Enhanced services for the non-terrestrial network mean that the second access point needs to establish two or more connections simultaneously for each of the multiple terminals. For example, the network defaults to terminals that can access the network via a non-terrestrial network having multiple antenna panels. In this case, based on the indication information, the second access point can send requests to establish enhanced services to each of the multiple terminals. In this case, since the communication frequency band of the second access point is typically different from that of the first access point, the second access point can communicate normally with the multiple terminals without interference. In this way, multiple terminals can respond to the request and establish two or more connections with the second access point simultaneously, which can also be understood as dual or multi-connection.
[0059] It is understandable that since ground communications are interfered with, it is necessary to establish dual or multiple connections to increase the bandwidth of satellite communications to ensure that the monitoring terminal can still transmit the surveillance video stream it shoots normally. In other words, remote visual security prevention and command and dispatch are achieved through satellite network communications, ensuring that the surveillance video stream can still be transmitted safely and normally.
[0060] It is understandable that the establishment of each connection can reuse the existing connection establishment method, such as end-to-end connection, PC5 connection, air interface connection, etc., which will not be described in detail.
[0061] If multiple terminals do not access the second access point through a non-terrestrial network access method, the service management entity instructs the second access point to access the multiple terminals through a non-terrestrial network access method, and provides enhanced services of the non-terrestrial network to the multiple terminals when the multiple terminals are all connected to the second access point. For example, the service management entity selects an access network device related to the first access point, such as selecting an access network device that has a corresponding relationship with the first access point. The access network device related to the first access point is the second access point. The service management entity can send indication information to the second access point. The indication information carries multiple terminals, information for instructing the terminals to access through a non-terrestrial network method, and information for instructing enhanced services to jointly indicate that the second access point needs to access the multiple terminals through a non-terrestrial network access method, and provides enhanced services of the non-terrestrial network to the multiple terminals when the multiple terminals are all connected to the second access point. The enhanced service of the non-terrestrial network means that the second access point needs to establish two or more RRC connections for each of the multiple terminals at the same time. In this way, the second access point can, based on the indication information, indicate to multiple terminals that they need to access the second access point. That is, the second access point unicasts trigger information to each of the multiple terminals, enabling the multiple terminals to initiate random access to the second access point using a non-terrestrial network method based on the trigger information, thereby accessing the second access point. Subsequently, the second access point can send requests to establish enhanced services to each of the multiple terminals. In response, the multiple terminals can simultaneously establish two or more RRC connections with the second access point in response to the requests.
[0062] In summary, when the service management entity determines that a security anomaly has occurred in the monitoring terminal, or that the monitoring terminal has been interfered with or shielded by the signal through the abnormal information reported by the first access point providing terrestrial network services, the service management entity can instruct the second access point to provide non-terrestrial network services to multiple terminals, that is, satellite communication services to resolve security risks caused by interference or shielding of the terrestrial signals of the monitoring equipment, that is, to reduce the impact of network attacks by switching networks with different communication methods to reduce security risks.
[0063] Combination of the above Figure 3 The chemical park safety monitoring method based on the Internet of Things provided by the embodiment of the present application is described in detail. The following describes an apparatus for executing the chemical park safety monitoring method based on the Internet of Things provided by the embodiment of the present application.
[0064] The apparatus is configured as follows: a service management entity receives exception information reported from a first access point, wherein the exception information is used to indicate that a communication abnormality has occurred in multiple terminals accessing the first access point, and the first access point provides terrestrial network services; if a monitoring terminal among the multiple terminals meets a preset condition, the service management entity determines that a security abnormality has occurred in the monitoring terminal; and if a security abnormality has occurred in the monitoring terminal, the service management entity instructs a second access point capable of providing non-terrestrial network services to provide the non-terrestrial network services to the multiple terminals.
[0065] Optionally, the preset conditions satisfied by the monitoring terminal among multiple terminals include one or more of the following: the number of monitoring terminals is greater than or equal to a first upper limit number; or; when the number of multiple terminals is greater than or equal to a second upper limit number, the proportion of the number of monitoring terminals in the multiple terminals is greater than or equal to the upper limit of the number proportion; or; the number of monitoring terminals is greater than or equal to the first upper limit number, and the number of multiple terminals is greater than or equal to the second upper limit number.
[0066] Optionally, the device is configured as a service management entity that obtains the respective contexts of multiple terminals from the service management entity locally or from a data management network element based on the respective identifiers of the multiple terminals in the exception information; the service management entity determines the terminal whose device type is non-mobile and has visual monitoring capability among the multiple terminals based on the respective device types of the terminals in the respective contexts of the multiple terminals, wherein the terminal whose device type is non-mobile and has visual monitoring capability is a monitoring terminal.
[0067] Optionally, the device is configured as follows: if the monitoring terminal among multiple terminals meets preset conditions, the service management entity determines whether the monitoring terminal is located in an area with a high security level, wherein the area with a high security level refers to an area with a security level greater than a level threshold; if the monitoring terminal is located in an area with a high security level, the service management entity determines that a security abnormality has occurred in the monitoring terminal.
[0068] Optionally, the device is configured as follows: the service management entity obtains information about the monitoring service of the application network element for the monitoring terminal from the application network element serving the monitoring terminal based on the identification of the monitoring terminal, wherein the monitoring service of the application network element for the monitoring terminal indicates that the monitoring service needs to be executed by the monitoring terminal, and the information about the monitoring service of the application network element for the monitoring terminal is used to indicate the multiple areas covered by the service and the security levels of the multiple areas; the service management entity determines one or more areas in the multiple areas where the monitoring terminal is located, and if the number of areas with high security levels in one or more areas exceeds a preset number threshold, the service management entity determines that the monitoring terminal is located in the area with high security levels; otherwise, the service management entity determines that the monitoring terminal is not located in the area with high security levels.
[0069] Optionally, the device is configured as follows: the service management entity determines whether multiple terminals have accessed the second access point through a non-terrestrial network access method; if multiple terminals have accessed the second access point through a non-terrestrial network access method, the service management entity instructs the second access point to provide enhanced services of the non-terrestrial network for the multiple terminals; if multiple terminals have not accessed the second access point through a non-terrestrial network access method, the service management entity instructs the second access point to access the multiple terminals through a non-terrestrial network access method, and provides enhanced services of the non-terrestrial network for the multiple terminals when all the terminals access the second access point.
[0070] Optionally, the device is configured as follows: the service management entity determines whether there is an identifier of the second access point in the context of each of the multiple terminals; if there is an identifier of the second access point in the context of each of the multiple terminals, it indicates that the multiple terminals have accessed the second access point through a non-terrestrial network access method; if there is no identifier of the second access point in the context of each of the multiple terminals, it indicates that the multiple terminals have not accessed the second access point through a non-terrestrial network access method.
[0071] Optionally, the device is configured as follows: the service management entity sends an indication message to the second access point, wherein the indication message jointly indicates that the second access point needs to provide enhanced services of non-terrestrial networks for multiple terminals by carrying multiple terminals and information for indicating enhanced services, and the enhanced services of non-terrestrial networks mean that the second access point needs to establish two or more RRC connections for each of the multiple terminals at the same time.
[0072] Optionally, the device is configured as follows: a service management entity selects an access network device associated with a first access point, wherein the access network device associated with the first access point is a second access point; the service management entity sends indication information to the second access point, wherein the indication information carries multiple terminals, information for indicating that the terminals are to be accessed through a non-terrestrial network, and information for indicating enhanced services to jointly indicate that the second access point needs to access the multiple terminals through a non-terrestrial network access method, and when the multiple terminals all access the second access point, provides enhanced services of the non-terrestrial network for the multiple terminals, and the enhanced services of the non-terrestrial network mean that the second access point needs to establish two or more RRC connections for each of the multiple terminals at the same time.
[0073] Optionally, the abnormality information includes at least one of the following information: an identifier of the first access point, identifiers of each of the multiple terminals, or signal strength change information of each of the multiple terminals, where the signal strength change information of each of the multiple terminals is used to indicate that the communication signal strengths of each of the multiple terminals have changed from being higher than an upper communication limit to being lower than a lower communication limit; and the at least one piece of information is used to jointly indicate that a communication abnormality has occurred in the multiple terminals accessing the first access point.
[0074] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. For example, the electronic device may be a network device, or a chip (system) or other component or assembly that can be set in a network device. Figure 3 As shown, electronic device 400 may include a processor 401. Optionally, electronic device 400 may further include a memory 402 and / or a transceiver 403. Processor 401 is coupled to memory 402 and transceiver 403, for example, via a communication bus.
[0075] The following combination Figure 3 The components of the electronic device 400 are described in detail.
[0076] The processor 401 is the control center of the electronic device 400 and can be a single processor or a collective term for multiple processing elements. For example, the processor 401 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0077] Optionally, the processor 401 can execute various functions of the electronic device 400 by running or executing the software program stored in the memory 402 and calling the data stored in the memory 402, such as executing the above Figure 3 The chemical park safety monitoring method based on the Internet of Things is shown.
[0078] In a specific implementation, as an embodiment, the processor 401 may include one or more CPUs, such as Figure 3 CPU0 and CPU1 are shown in FIG.
[0079] In a specific implementation, as an embodiment, the electronic device 400 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0080] The memory 402 is used to store the software program for executing the solution of the present application, and the execution is controlled by the processor 401. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0081] Alternatively, the memory 402 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 402 may be integrated with the processor 401 or exist independently and accessed through the interface circuit ( Figure 3 (not shown) is coupled to the processor 401, which is not specifically limited in this embodiment of the present application.
[0082] Transceiver 403 is used for communication with other electronic devices. For example, if electronic device 400 is a terminal, transceiver 403 can be used to communicate with a network device or another terminal device. For another example, if electronic device 400 is a network device, transceiver 403 can be used to communicate with a terminal or another network device.
[0083] Optionally, the transceiver 403 may include a receiver and a transmitter ( Figure 3 (not shown separately in the figure). The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0084] Optionally, the transceiver 403 may be integrated with the processor 401 or may exist independently and communicate with the electronic device 400 through an interface circuit ( Figure 3 (not shown) is coupled to the processor 401, which is not specifically limited in this embodiment of the present application.
[0085] It is understandable that Figure 3 The structure of the electronic device 400 shown in the figure does not constitute a limitation on the electronic device. The actual electronic device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0086] In addition, the technical effects of the electronic device 400 can refer to the technical effects of the methods described in the above method embodiments, and will not be repeated here.
[0087] It should be understood that the processor in the embodiments of the present application may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0088] It should also be understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0089] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer program are loaded or executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center via a wired (such as infrared, wireless, microwave, etc.) method. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more available media sets. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0090] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0091] In this application, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0092] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0093] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0094] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0095] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0096] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0097] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0098] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0099] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
Claims
1. A chemical park safety monitoring method based on the Internet of Things, characterized in that: The method comprises: The service management entity receives abnormality information reported from a first access point, wherein the abnormality information indicates that abnormality has occurred in communications of multiple terminals accessing the first access point, the signal range of the first access point covers the chemical park, and the first access point provides services of a terrestrial network; If the monitoring terminal among the multiple terminals meets the preset condition, the service management entity determines that a security abnormality occurs in the monitoring terminal; In the event of a security anomaly at the monitoring terminal, the service management entity instructs a second access point capable of providing non-terrestrial network services to provide non-terrestrial network services to the multiple terminals, wherein the signal range of the second access point covers the chemical park; The monitoring terminal among the multiple terminals meets the preset conditions including one or more of the following: The number of monitoring terminals is greater than or equal to a first upper limit; or; When the number of the plurality of terminals is greater than or equal to the second upper limit, the proportion of the monitoring terminals in the plurality of terminals is greater than or equal to the upper limit; or; The number of the monitoring terminals is greater than or equal to the first upper limit, and the number of the plurality of terminals is greater than or equal to the second upper limit; The method further comprises: The service management entity obtains, according to the identifiers of the multiple terminals in the exception information, the contexts of the multiple terminals from the service management entity locally or from a data management network element; The service management entity determines, according to the device types of the respective terminals in the respective contexts of the plurality of terminals, a terminal whose device type is non-mobile and has a visual monitoring capability among the plurality of terminals, wherein the terminal whose device type is non-mobile and has a visual monitoring capability is the monitoring terminal; If the monitoring terminal among the multiple terminals meets the preset condition, the service management entity determines that a security abnormality occurs in the monitoring terminal, including: If the monitoring terminal among the multiple terminals meets the preset condition, the service management entity determines whether the monitoring terminal is located in an area with a high security level, wherein the area with a high security level refers to an area with a security level greater than a level threshold; If the monitoring terminal is located in an area with a high security level, the service management entity determines that a security anomaly occurs in the monitoring terminal.
2. The method according to claim 1, characterized in that The service management entity determines whether the monitoring terminal is located in an area with a high security level, including: The service management entity obtains, from an application network element serving the monitoring terminal, information about a monitoring service of the application network element for the monitoring terminal based on the identifier of the monitoring terminal, wherein the monitoring service of the application network element for the monitoring terminal indicates that the monitoring service needs to be performed by the monitoring terminal, and the information about the monitoring service of the application network element for the monitoring terminal is used to indicate multiple areas covered by the service and respective security levels of the multiple areas; The service management entity determines one or more areas where the monitoring terminal is located in the multiple areas, If the number of high security level areas in the one or more areas exceeds a preset number threshold, the service management entity determines that the monitoring terminal is located in the high security level area; otherwise, the service management entity determines that the monitoring terminal is not located in the high security level area.
3. The method according to claim 1, characterized in that The service management entity instructing a second access point capable of providing a non-terrestrial network service to provide the non-terrestrial network service for the multiple terminals, including: determining, by the service management entity, whether the plurality of terminals have accessed the second access point in a non-terrestrial network access manner; If the plurality of terminals have accessed the second access point through a non-terrestrial network access mode, the service management entity instructs the second access point to provide enhanced services of the non-terrestrial network for the plurality of terminals; If the multiple terminals do not access the second access point through the non-terrestrial network access method, the service management entity instructs the second access point to access the multiple terminals through the non-terrestrial network access method, and provides enhanced services of the non-terrestrial network for the multiple terminals when the multiple terminals all access the second access point.
4. The method according to claim 3, characterized in that The service management entity determines whether the plurality of terminals have accessed the second access point in a non-terrestrial network access manner, including: Determining, by the service management entity, whether there is an identifier of the second access point in the context of each of the plurality of terminals; If the identifier of the second access point is included in the context of each of the multiple terminals, it indicates that the multiple terminals have accessed the second access point through a non-terrestrial network access method; if the identifier of the second access point is not included in the context of each of the multiple terminals, it indicates that the multiple terminals have not accessed the second access point through a non-terrestrial network access method.
5. The method according to claim 4, characterized in that The service management entity instructing the second access point to provide the plurality of terminals with enhanced services of the non-terrestrial network, including: The service management entity sends indication information to the second access point, where the indication information carries the multiple terminals and information indicating an enhanced service, thereby jointly indicating that the second access point needs to provide enhanced services of a non-terrestrial network for the multiple terminals, where the enhanced service of the non-terrestrial network means that the second access point needs to simultaneously establish two or more connections for each of the multiple terminals.
6. The method according to claim 4, characterized in that The service management entity instructs the second access point to access the multiple terminals through a non-terrestrial network access method, and provides enhanced services of the non-terrestrial network for the multiple terminals when the multiple terminals all access the second access point, including: The service management entity selects an access network device associated with the first access point, wherein the access network device associated with the first access point is the second access point; The service management entity sends indication information to the second access point, wherein the indication information carries the multiple terminals, information for instructing the terminals to access the terminal in a non-terrestrial network manner, and information for instructing enhanced services, thereby jointly indicating that the second access point needs to access the multiple terminals in a non-terrestrial network access manner, and provides enhanced services of the non-terrestrial network for the multiple terminals when the multiple terminals all access the second access point, where the enhanced services of the non-terrestrial network mean that the second access point needs to simultaneously establish two or more connections for each of the multiple terminals.
7. The method according to any one of claims 1 to 6, characterized in that The abnormality information includes at least one of the following information: an identifier of the first access point, identifiers of each of the multiple terminals, or signal strength change information of each of the multiple terminals, where the signal strength change information of each of the multiple terminals is used to indicate that the communication signal strengths of each of the multiple terminals have changed from being above an upper communication limit to being below a lower communication limit; the at least one item of information is used to jointly indicate that a communication abnormality has occurred in the multiple terminals accessing the first access point.
Citation Information
Patent Citations
Inland ship intelligent terminal 4G and Beidou short message communication switching method and device
CN112672294A
Network adjustment method and device, gateway and computer readable storage medium
CN114584413A