A security situation data analysis platform based on cloud computing
By setting the data throughput curve and security threshold in the edge computing layer of the security system, effective response to burst traffic is achieved, and the problem of data processing delay in the face of a sudden increase in data volume is solved, ensuring the real-time and responsiveness of the system.
Patent Information
- Application Number
- CN202411391481.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-08
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-10-08
AI Technical Summary
When the existing security systems face the sudden and continuous increase in data volume, they lack effective prediction mechanisms and response methods, resulting in delays in data processing and affecting their response capabilities to important events.
A security situation data analysis platform based on cloud computing is designed. By setting the curve of data throughput over time in the edge computing layer, calculating the average slope, and setting a security threshold. When the data throughput exceeds the threshold, the edge node initiates a computing resource request to the cloud computing layer and uploads the original security data for processing.
When facing burst traffic, ensure that the security system can process data in a timely manner to avoid data processing in a timely manner due to traffic surges, resulting in untimely data processing due to edge node loads.
Smart Images

Figure CN119211235B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security technology, and in particular to a security situation data analysis platform based on cloud computing. Background Art
[0002] Smart security is a series of systems that use modern information technology means such as artificial intelligence, cloud computing, big data, etc. to conduct all-round monitoring, early warning, prevention, control, and disposal of security precautions, making people's lives safer, more convenient, and more comfortable.
[0003] Most security systems in current technology adopt a collaborative working mode of edge nodes and cloud computing platforms, that is, raw security data is continuously collected through sensors, and all these security data are unified and summarized to the edge nodes in the area. The data is first pre-processed and preliminarily analyzed at the edge nodes, and only key information is transmitted to the cloud for further analysis, storage or processing.
[0004] There are certain technical problems in the collaborative working mode of edge computing and cloud computing platforms. Specifically, the data throughput of edge devices is not constant during their working cycle. When the number of target people in image data or video streams increases significantly within a specific period of time, the resulting continuous increase in data volume may cause delays in real-time data processing in the security system, thereby affecting its ability to respond to important events. Therefore, the existing security system lacks effective prediction mechanisms and response methods when dealing with sudden and continuous increases in data volume. Summary of the invention
[0005] The purpose of the present invention is to provide a cloud computing-based security situation data analysis platform to solve the above technical problems:
[0006] The purpose of the present invention can be achieved through the following technical solutions:
[0007] A cloud computing-based security situation data analysis platform includes the following modules: a data collection module, an edge computing layer and a cloud computing layer, wherein the edge computing layer includes multiple edge nodes, a single edge node is connected to multiple data collection modules, and the cloud computing layer is connected to multiple edge nodes. The system also includes:
[0008] A data collection module, used to obtain original security data and upload the original security data to the connected edge node, wherein the original security data includes pictures, videos, etc.;
[0009] The edge computing layer sets the responsibility area of a single edge node and obtains the data throughput of any edge node within the calibration period. It generates a curve F1(t) showing the data throughput changing over time. It obtains the starting point, peak point, valley point and end point in the curve F1(t) and marks them as feature points. It calculates the slope K between any adjacent feature points and calculates the average slope K of the curve F1(t) based on the slope K. i According to the calculation formula The safety threshold a is calculated, where n is the number of feature points. The detection period T is set with the current time node h as the starting point, and the curve F2(t´) of data throughput changing with time is obtained, t´∈[h,h+T]. According to the calculation formula K j =[F2(h+T)-F2(h)] / T to calculate the average slope K j , when K j ≥|aK i |, the edge node initiates a computing resource request to the cloud computing layer, and uploads the original security data obtained in the subsequent detection cycle. j <|aK i |, the edge node does not make a computing resource request;
[0010] The cloud computing layer is used to receive the original security data of all edge nodes that initiate computing resource requests, process the original security data, and generate a data report based on the data processing results.
[0011] As a further solution of the present invention: in the edge computing layer, the calibration period is the actual running time.
[0012] As a further solution of the present invention: in the edge computing layer, the division of the responsibility area of the edge node is based on the street area division of urban planning.
[0013] As a further solution of the present invention: in the edge computing layer, the first-order derivative of the curve F1 (t) at each point is calculated. When the first-order derivative at that time point changes from positive to negative, the point is marked as a peak point. When the first-order derivative at that time point changes from negative to positive, the point is marked as a valley point.
[0014] As a further solution of the present invention: in the edge computing layer, the slope K between any two adjacent points of the curve F1(t) of the data throughput changing over time is calculated as follows: ; Among them, F1 (t a ) represents the data throughput recorded at time a, F(t a-1 ) represents the data throughput recorded at time a-1.
[0015] As a further solution of the present invention: in the edge computing layer, the average slope K is calculated by the slope K between adjacent time points. i , where the average slope K i The calculation formula is as follows: ; Where b is the slope K between any b-th adjacent feature points.
[0016] As a further solution of the present invention: in the edge node, after the detection period T ends, a new detection period T is re-set with the current time node h+T as the starting point.
[0017] As a further solution of the present invention: in the cloud computing layer, by obtaining the original security data of all edge nodes that initiate computing resource requests, the data of different edge nodes are distinguished according to the edge node identifiers uploaded with the original security data, the data of different edge nodes are allocated to different processing queues, the data in each processing queue is processed in parallel, the processing results are summarized and a data report is generated.
[0018] Beneficial effects of the present invention: The present invention collects raw data through monitoring equipment through a data collection module, the edge node is connected to multiple data collection modules, receives raw security data for preprocessing, obtains the throughput change function of the historical working cycle to calculate the average slope K, sets the security threshold a, sets the detection cycle T with the current time node h as the starting point, and calculates the average slope K of the throughput change function in the detection cycle. j Compared with the historical average slope, when K j ≥|aK i |, the edge node initiates a computing resource request to the cloud computing layer, and uploads the original security data obtained in the subsequent detection cycle. j <|aK i |, the edge node does not make a computing resource request, the cloud computing layer is used to receive the original security data of all edge nodes that initiate computing resource requests, process the original security data and generate a data report based on the data processing results. The present invention can ensure that the security system can process data in a timely manner when facing burst traffic, and avoid untimely data processing caused by edge node load due to a surge in traffic. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The present invention will be further described below in conjunction with the accompanying drawings.
[0020] Figure 1 It is a structural schematic diagram of a security situation data analysis platform based on cloud computing of the present invention. DETAILED DESCRIPTION
[0021] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0022] The data throughput of edge devices is not constant during their working cycle. When the number of people in the image data or video stream increases significantly during a specific period of time, the resulting increase in data throughput may affect the real-time performance of data processing. This shows that existing technologies lack effective prediction mechanisms when dealing with sudden increases in data throughput.
[0023] In order to effectively prevent the increase in data throughput of edge nodes from affecting the real-time performance of data processing, the present invention sets a threshold through a custom calculation formula. When the data throughput of the edge node exceeds the threshold, the original security data of the next detection cycle is uploaded to the cloud computing layer for processing.
[0024] See also Figure 1 As shown, the present invention is a security situation data analysis platform based on cloud computing, comprising the following modules: a data collection module, an edge computing layer and a cloud computing layer, wherein the edge computing layer comprises a plurality of edge nodes, a single edge node is connected to a plurality of data collection modules, and the cloud computing layer is connected to a plurality of edge nodes, characterized in that the system further comprises:
[0025] A data collection module, used to obtain original security data and upload the original security data to the connected edge node, wherein the original security data includes pictures, videos, etc.;
[0026] The edge computing layer sets the responsibility area of a single edge node and obtains the data throughput of any edge node within the calibration period. It generates a curve F1(t) showing the data throughput changing over time. It obtains the starting point, peak point, valley point and end point in the curve F1(t) and marks them as feature points. It calculates the slope K between any adjacent feature points and calculates the average slope K of the curve F1(t) based on the slope K. i According to the calculation formula The safety threshold a is calculated, where n is the number of feature points. The detection period T is set with the current time node h as the starting point, and the curve F2(t´) of data throughput changing with time is obtained, t´∈[h,h+T]. According to the calculation formula K j =[F2(h+T)-F2(h)] / T to calculate the average slope K j , when K j ≥|aK i|, the edge node initiates a computing resource request to the cloud computing layer, and uploads the original security data obtained in the subsequent detection cycle. j <|aK i |, the edge node does not make a computing resource request;
[0027] The cloud computing layer is used to receive the original security data of all edge nodes that initiate computing resource requests, process the original security data, and generate a data report based on the data processing results.
[0028] It can be understood that the present invention collects raw data through monitoring equipment through the data collection module, the edge node is connected to multiple data collection modules, receives the raw security data for preprocessing, obtains the throughput change function of the historical working cycle to calculate the average slope K, sets the security threshold a, sets the detection cycle T with the current time node h as the starting point, and calculates the average slope K of the throughput change function in the detection cycle. j Compared with the historical average slope, when K j ≥|aK i |, the edge node initiates a computing resource request to the cloud computing layer, and uploads the original security data obtained in the subsequent detection cycle. j <|aK i |, the edge node does not make a computing resource request, the cloud computing layer is used to receive the original security data of all edge nodes that initiate computing resource requests, process the original security data and generate a data report based on the data processing results. The present invention can ensure that the security system can process data in a timely manner when facing burst traffic, and avoid untimely data processing caused by edge node load due to a surge in traffic.
[0029] In a preferred embodiment of the present invention, in the edge computing layer, the calibration period is the actual running time.
[0030] It is understandable that using the actual running time can ensure that the system can respond to changes in a timely manner and adapt to the dynamic environment, thereby improving the real-time and accuracy of data processing. Adjustments can be made based on data feedback to improve the accuracy and reliability of the system, especially in scenarios where the environment changes frequently. The dynamic adjustment of the actual running time enables the system to better adapt to the needs of different application scenarios and enhances the flexibility and scalability of the system.
[0031] In a preferred embodiment of the present invention, in the edge computing layer, the division of the responsibility area of the edge node is based on the street area division of urban planning.
[0032] It is understandable that assigning computing tasks to nodes closer to the data collection module can reduce the distance of data transmission, thereby reducing response time and improving real-time performance. Each edge node is responsible for data processing in a specific area, which can improve the processing efficiency of local data and reduce the burden on the central server. Regional division makes services for specific areas more accurate.
[0033] In a preferred embodiment of the present invention, in the edge computing layer, the first-order derivative of the curve F1 (t) at each point is calculated. When the first-order derivative at that time point changes from positive to negative, the point is marked as a peak point. When the first-order derivative at that time point changes from negative to positive, the point is marked as a valley point.
[0034] It is understandable that by identifying peaks and valleys, we can better understand system load and performance changes, thereby providing a basis for resource allocation and scheduling and optimizing the decision-making process. By analyzing historical data, it is helpful to establish a more accurate prediction model, predict future load changes in advance, and make corresponding plans. Formulate strategies based on real data analysis results to improve the scientificity and accuracy of predictions.
[0035] In a preferred embodiment of the present invention, in the edge computing layer, the slope K between any two adjacent points of the curve F1(t) of the data throughput variation over time is calculated as follows: ; Among them, F1 (t a ) represents the data throughput recorded at time a, F(t a-1 ) represents the data throughput recorded at time a-1.
[0036] It can be understood that the slope K reflects the rate of change of data throughput, and the change trend of the data throughput of the edge node can be understood in real time, and abnormal situations can be quickly identified. By analyzing the change trend of the slope of different detection cycles, future load conditions can be predicted, helping to reasonably allocate resources and avoid system overload. Understanding the speed of throughput changes helps to dynamically adjust resource configuration and improve resource utilization. Long-term tracking of slope changes can identify continuous trends and provide a basis for the design of the present invention.
[0037] In a preferred embodiment of the present invention, in the edge computing layer, the average slope K is calculated by the slope K between adjacent time points. i , where the average slope K i The calculation formula is as follows: Where b is the slope K between any b-th adjacent feature points.
[0038] It is understandable that the average slope can reduce the noise impact of the slope of a single detection cycle, making the overall trend clearer, thereby more accurately reflecting the throughput changes of edge nodes. By analyzing the average slope, the change trend of data throughput can be more comprehensively evaluated, helping to identify performance bottlenecks and optimization opportunities. The average slope helps to identify long-term trends and periodic changes, providing a basis for future load forecasting.
[0039] In a preferred embodiment of the present invention, in the cloud computing layer, by obtaining the original security data of all edge nodes that initiate computing resource requests, the data of different edge nodes are distinguished according to the edge node identifiers uploaded with the original security data, the data of different edge nodes are allocated to different processing queues, the data in each processing queue is processed in parallel, the processing results are summarized and a data report is generated.
[0040] It is understandable that distinguishing the data of different edge nodes by identification and assigning them to independent processing queues will help achieve more orderly and efficient data management. By processing data in multiple processing queues in parallel, the data processing speed can be significantly improved, the response time can be shortened, and real-time requirements can be met. Parallel processing can make better use of computing resources, improve the overall resource utilization of the system, and reduce processing costs. As the number of edge nodes uploading data increases, the processing queues and computing resources can be flexibly expanded to meet the growing security data processing needs. Aggregating the results of each processing queue to generate a data report can provide a more comprehensive security situation analysis and help decision makers make more effective decisions.
[0041] The above is a detailed description of an embodiment of the present invention, but the content is only a preferred embodiment of the present invention and cannot be considered to limit the scope of implementation of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.
Claims
1. A cloud computing-based security situation data analysis platform, comprising the following modules: a data collection module, an edge computing layer and a cloud computing layer, wherein: The edge computing layer includes multiple edge nodes, a single edge node is connected to multiple data collection modules, and the cloud computing layer is connected to multiple edge nodes, characterized in that: A data collection module, used to obtain original security data and upload the original security data to the connected edge node, wherein the original security data includes pictures and videos; The edge computing layer sets the responsibility area of a single edge node and obtains the data throughput of any edge node within the calibration period. It generates a curve F1(t) showing the data throughput changing over time. It obtains the starting point, peak point, valley point and end point in the curve F1(t) and marks them as feature points. It calculates the slope K between any adjacent feature points. b , through the slope K b Calculate the average slope K of curve F1(t) i According to the calculation formula Calculate the safety threshold a, Where n is the number of feature points; Set the detection period T with the current time node h as the starting point, and obtain the curve F2(t´) of data throughput changing with time, t´∈[h,h+T]. According to the calculation formula K j =[F2(h+T)-F2(h)] / T to calculate the average slope K j , when K j ≥|aK i |, the edge node initiates a computing resource request to the cloud computing layer, and uploads the original security data obtained in the subsequent detection cycle. j <|aK i |, the edge node does not make a computing resource request; The cloud computing layer is used to receive the original security data of all edge nodes that initiate computing resource requests, process the original security data, and generate a data report based on the data processing results.
2. A cloud computing-based security situation data analysis platform according to claim 1, characterized in that: In the edge computing layer, the calibration period is the actual running time.
3. The cloud computing-based security situation data analysis platform according to claim 1, characterized in that: In the edge computing layer, the division of the responsibility area of the edge node is based on the street area division of urban planning.
4. The cloud computing-based security situation data analysis platform according to claim 1, characterized in that: In the edge computing layer, the first-order derivative of the curve F1 (t) at each point is calculated. When the first-order derivative at that time point changes from positive to negative, the point is marked as a peak point. When the first-order derivative at that time point changes from negative to positive, the point is marked as a valley point.
5. The cloud computing-based security situation data analysis platform according to claim 1, characterized in that: In the edge computing layer, the slope K between any two adjacent points of the curve F1(t) of the data throughput variation over time is b The calculation formula is as follows: ; Among them, F1 (t b ) represents the data throughput recorded at the bth feature point, F(t b-1 ) represents the data throughput recorded at the b-1th feature point.
6. The cloud computing-based security situation data analysis platform according to claim 1, characterized in that: In the edge computing layer, the slope K between adjacent time points is b Calculate the average slope K i , where the average slope K i The calculation formula is as follows: ; Among them, K b is the slope between any b-th adjacent feature points.
7. The cloud computing-based security situation data analysis platform according to claim 1, characterized in that: In the edge node, after the detection period T ends, a new detection period T is set again with the current time node h+T as the starting point.
8. The cloud computing-based security situation data analysis platform according to claim 1, characterized in that: In the cloud computing layer, by obtaining the original security data of all edge nodes that initiate computing resource requests, the data of different edge nodes are distinguished according to the edge nodes to which the original security data is uploaded, the data of different edge nodes are allocated to different processing queues, the data in each processing queue is processed in parallel, the processing results are summarized and a data report is generated.
Citation Information
Patent Citations
Side cloud cooperation system and working method based on information physical fusion
CN112600891A
Abnormal event monitoring method and device, equipment and medium
CN114968743A