Internet of Things control method and platform based on OpenHarmony

Through the Internet of Things control method based on OpenHarmony, the problems of equipment diversity, network dynamics and security threats in the prior art are solved, and the rapid access of equipment, security authentication, intelligent perception and global energy efficiency optimization are realized, and the compatibility, security and scalability of the system are improved.

CN119814596BActive Publication Date: 2025-05-09深圳宇翊技术股份有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510286999.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-05-09
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

The existing IoT control methods are difficult to cope with diversified device types and dynamically changing network environments, lack the unified abstraction and flexible calling mechanism of device capabilities, and face massive data processing and analysis bottlenecks, making it difficult to achieve intelligent perception and precise control, and there are real-time monitoring and rapid response needs that are difficult to meet security threats.

Method used

Based on OpenHarmony's IoT control method, it realizes fast access and security authentication of equipment through distributed discovery and lightweight authentication, builds dynamic device topology maps and virtualization layers, acquires multi-source sensor data and integrates processing, builds IoT scenario knowledge graphs, performs inference to obtain scenario control strategies, combines deep learning models and threat intelligence analysis to conduct security situation evaluation, conducts deep packet detection and abnormal behavior cluster analysis, generates network optimization strategies, and achieves global energy efficiency optimization through dual-cluster head structure and dynamic load balancing.

Benefits of technology

It realizes fast access and security authentication of heterogeneous devices, unified abstraction and management of physical devices, improves the scalability of the system and device interoperability, realizes intelligent perception and reasoning of complex IoT scenarios, enhances the system's security situation evaluation and defense capabilities, improves network fault diagnosis and optimization efficiency, realizes global energy efficiency optimization and extends the running time of the IoT system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814596B_ABST
    Figure CN119814596B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of Internet of Things, and discloses an Internet of Things control method and platform based on OpenHarmony, which includes: performing distributed discovery and lightweight authentication on Internet of Things devices, and building a dynamic device topology map; generating a device capability description file according to a set of authenticated devices, and creating a virtualization layer; acquiring multi-source sensor data from the virtualization layer and fusing and processing it to obtain a scene control strategy; collecting network data packets and extracting features at key nodes in the dynamic device topology map to obtain security situation assessment results; performing deep packet inspection based on the security situation assessment results and the scene control strategy, identifying abnormal behaviors, and generating a network optimization strategy; selecting cluster head nodes for load-balanced data transmission according to the network optimization strategy, and dynamically adjusting the node working mode and network topology structure to achieve global energy efficiency optimization, thereby achieving global energy efficiency optimization and extending the overall operation time of the Internet of Things system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things technology, and in particular to an Internet of Things control method and platform based on OpenHarmony. Background Art

[0002] With the rapid development of IoT technology, the number of smart devices has exploded, which has put forward higher requirements for unified and efficient device management and control. As an open source distributed operating system, OpenHarmony provides a good basic platform for IoT applications. However, in practical applications, problems such as device heterogeneity, network complexity and security threats still exist, which restricts the large-scale deployment and application of IoT systems.

[0003] Traditional IoT control methods often have difficulty coping with diverse device types and dynamically changing network environments, lacking a unified abstraction of device capabilities and a flexible calling mechanism. At the same time, as the scale of the IoT expands, the processing and analysis of massive data has become a bottleneck, making it difficult to achieve intelligent perception and precise control of complex scenarios. In addition, IoT systems are facing increasingly severe security threats, and existing security protection measures are difficult to meet the needs of real-time monitoring and rapid response in distributed environments. Summary of the invention

[0004] The present application provides an Internet of Things control method and platform based on OpenHarmony, thereby optimizing global energy efficiency and extending the overall operating time of the Internet of Things system.

[0005] In a first aspect, the present application provides an Internet of Things control method based on OpenHarmony, and the Internet of Things control method based on OpenHarmony includes:

[0006] Perform distributed discovery and lightweight authentication on IoT devices to obtain a set of authenticated devices, and build a dynamic device topology map based on the set of authenticated devices;

[0007] Generate a device capability description file according to the authentication device set, create a virtual device object according to the device capability description file, and build a virtualization layer;

[0008] Acquire multi-source sensor data from the virtualization layer and fuse them to construct an IoT scene knowledge graph, and perform reasoning based on the IoT scene knowledge graph to obtain a scene control strategy;

[0009] Collect network data packets and extract features at key nodes of the dynamic device topology map, input the extracted features into a deep learning model, and combine with threat intelligence analysis to obtain security situation assessment results;

[0010] Based on the security situation assessment result and the scenario control strategy, deep packet inspection is performed to identify abnormal behaviors, and clustering and root cause analysis are performed on the abnormal behaviors to generate a network optimization strategy;

[0011] According to the network optimization strategy, a cluster head node is selected to perform load-balanced data transmission, and the node working mode and network topology are dynamically adjusted to achieve global energy efficiency optimization.

[0012] The second aspect of the present application provides an Internet of Things control platform based on OpenHarmony, and the Internet of Things control platform based on OpenHarmony includes:

[0013] An authentication module is used to perform distributed discovery and lightweight authentication on IoT devices, obtain an authenticated device set, and construct a dynamic device topology map based on the authenticated device set;

[0014] A creation module, used to generate a device capability description file according to the authentication device set, and create a virtual device object according to the device capability description file to build a virtualization layer;

[0015] An inference module is used to obtain multi-source sensor data from the virtualization layer and fuse them, build an IoT scene knowledge graph, and perform inference based on the IoT scene knowledge graph to obtain a scene control strategy;

[0016] An extraction module is used to collect network data packets and extract features at key nodes of the dynamic device topology map, input the extracted features into a deep learning model, and combine with threat intelligence analysis to obtain a security situation assessment result;

[0017] An identification module, configured to perform deep packet inspection based on the security situation assessment result and the scenario control strategy, identify abnormal behaviors, cluster and perform root cause analysis on the abnormal behaviors, and generate a network optimization strategy;

[0018] The adjustment module is used to select cluster head nodes for load-balanced data transmission according to the network optimization strategy, and dynamically adjust the node working mode and network topology structure to achieve global energy efficiency optimization.

[0019] The third aspect of the present application provides an electronic device, comprising: a memory and at least one processor, wherein the memory stores instructions; the at least one processor calls the instructions in the memory so that the electronic device executes the above-mentioned OpenHarmony-based Internet of Things control method.

[0020] A fourth aspect of the present application provides a computer-readable storage medium, wherein instructions are stored in the computer-readable storage medium, and when the computer-readable storage medium is run on a computer, the computer executes the above-mentioned OpenHarmony-based Internet of Things control method.

[0021] Compared with the prior art, the present application has the following beneficial effects: through distributed discovery and lightweight authentication mechanism, fast access and security authentication of heterogeneous devices are realized, and the compatibility and security of the system are improved. The device capability description file and virtualization layer are adopted to realize the unified abstraction and management of physical devices, and enhance the scalability and device interoperability of the system. Based on multi-source sensor data fusion and knowledge graph construction, intelligent perception and reasoning of complex IoT scenarios are realized, and the scene understanding and decision-making ability of the system are improved. Combined with deep learning models and threat intelligence analysis, real-time assessment of network security situation is realized, and the system's identification and defense capabilities against potential security threats are enhanced. Through deep packet detection and abnormal behavior clustering analysis, accurate identification and root cause analysis of network anomalies are realized, and the efficiency of network fault diagnosis and optimization is improved. The dual cluster head structure and dynamic load balancing mechanism are adopted to realize efficient scheduling of network data transmission and improve the throughput and reliability of the system. Adaptive power control and dynamic topology adjustment strategies are adopted to optimize global energy efficiency and extend the overall operation time of the IoT system. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0023] The structures, proportions, sizes, etc. illustrated in the drawings of this specification are only used to match the contents disclosed in the specification so as to facilitate understanding and reading by persons familiar with this technology. They are not used to limit the conditions under which the present invention can be implemented, and therefore have no substantive technical significance. Any structural modification, change in proportion or adjustment of size, without affecting the effects and purposes that can be achieved by the present invention, should still fall within the scope of the technical contents disclosed by the present invention.

[0024] Figure 1 is a flow chart of an Internet of Things control method based on OpenHarmony provided by an embodiment of the present invention;

[0025] Figure 2 It is a schematic block diagram of the structure of an Internet of Things control platform based on OpenHarmony provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0026] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0027] The flowcharts shown in the accompanying drawings are only examples and do not necessarily include all the contents and operations / steps, nor must they be executed in the order described. For example, some operations / steps may also be decomposed, combined or partially merged, so the actual execution order may change according to actual conditions.

[0028] It should also be understood that the terms used in this application specification are only for the purpose of describing specific embodiments and are not intended to limit the application. As used in this application specification and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include plural forms.

[0029] It should be further understood that the term "and / or" used in the specification and appended claims of this application refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations. Figure 1 In the embodiment of the present application, an embodiment of the Internet of Things control method based on OpenHarmony includes:

[0030] Step 100: Perform distributed discovery and lightweight authentication on IoT devices to obtain an authenticated device set, and construct a dynamic device topology map based on the authenticated device set;

[0031] It is understandable that the execution subject of the present application can be an IoT control platform based on OpenHarmony, or a terminal or a server, which is not limited here. The present application embodiment is described by taking the server as the execution subject as an example.

[0032] Specifically, the distributed soft bus technology of OpenHarmony is used to broadcast the device discovery request in the local area network, so that the device discovery can be effectively performed in the network. Through the device discovery request, the IoT system receives the response information of each device in the local area network. The device response information includes the basic characteristics of the device, such as the device type, function description and unique identifier. The device response information is parsed, the relevant device information is extracted, and a list of devices to be authenticated is generated based on this information, including all devices that may be authenticated. A random challenge value is generated based on elliptic curve cryptography, and the random challenge value is sent to each device in the list. Elliptic curve cryptography is an efficient and secure cryptographic method that can reduce the computing and communication overhead while ensuring security. After receiving the random challenge value, each device to be authenticated uses its own private key to generate a signature, and returns the signature and the device's public key certificate to the system. After receiving this information, the system verifies the public key certificate provided by the device to ensure the legitimacy and validity of the device's identity and prevent unauthorized devices from joining the network. The verified public key certificate is regarded as a valid certificate, and the signature returned by the device is verified using the public key in the valid certificate. If the signature verification passes, the identity of the device is considered to have been confirmed, and the device is then added to the authentication device set. A session key is assigned to each device in the authentication device set, and an encrypted communication channel is established to effectively protect the confidentiality and integrity of data transmitted between devices. The initial network topology is constructed based on the graph theory algorithm, and the devices in the authentication device set are used as nodes of the network topology map, and the communication links between devices are used as edges of the topology map. The graph theory algorithm helps the system to initially build a reasonable network topology based on the connection relationship between devices and the quality of the communication link to ensure effective communication between devices. The dynamic update algorithm is used to monitor the online status and network connection of the device in real time. The dynamic update algorithm updates the status information of the device regularly or according to the trigger conditions, and adjusts the initial network topology in time according to the joining, leaving or changes of the communication link of the device. A dynamic device topology map is generated based on the results of real-time adjustment, which accurately reflects the distribution and connection status of each device in the current network.

[0033] Step 200: Generate a device capability description file according to the authentication device set, create a virtual device object according to the device capability description file, and build a virtualization layer;

[0034] Specifically, the capability detection is performed on each device in the authentication device set, and the original device capability data such as the basic information, function list, data interface and control command set of the device are extracted to reflect the specific performance and operable scope of the device. The predefined XML template is used to convert the original device capability data into a standardized XML format to generate a device capability description file. The XML format has good scalability and structural characteristics, and can describe the device capability data in a standardized form, which is convenient for system parsing and understanding. The device capability description file is parsed and semantically checked to verify the integrity of its structure and the consistency of its data, ensuring that the device capability description file has no format errors or logical problems. The verified device capability description file is regarded as a valid file, and a corresponding virtual device object is created for each physical device based on the valid device capability description file. In the process of creating a virtual device object, the communication protocol and data conversion logic of the device are encapsulated inside the virtual device object, and the physical device is linked to its corresponding virtual device object. The virtual device object simulates the behavior of the physical device and provides a unified interface to interact with the external system, so that the system can remain stable when the physical device changes, and improve the flexibility and scalability of the system. All virtual device objects are classified and organized, and a device object tree structure is constructed to achieve hierarchical management of devices. Create unified data access interface and control interface for virtual device objects. These interfaces constitute the device abstraction layer, so that upper-layer applications can interact with devices in a unified way. Implement the device capability registration mechanism based on the publish-subscribe model. This mechanism allows virtual device objects to dynamically register and update their capability information when device capabilities change. For example, when the function list of a device changes, the new capability information is published to the system through this mechanism, and other modules that have subscribed to the device capabilities can obtain the updated capability information in time and make corresponding adjustments. At the same time, in order to improve the flexibility of device capability calling, the reflection mechanism and dynamic proxy technology are used to realize the automatic discovery and calling of device capabilities. The reflection mechanism allows the system to obtain the device capability information at runtime, while the dynamic proxy technology can generate the corresponding proxy object according to the current device status and capability information, so as to realize the flexible calling of device capabilities. Through this mechanism, the changes of device capabilities can be dynamically adapted, and the device capabilities can be automatically discovered and called when needed. Complete the construction of the virtualization layer.

[0035] Step 300: Obtain multi-source sensor data from the virtualization layer and fuse them, build an IoT scene knowledge graph, and perform reasoning based on the IoT scene knowledge graph to obtain a scene control strategy;

[0036] It should be noted that the raw data of multi-source sensors are obtained through the data access interface of the virtualization layer. These data come from different types of sensor devices, covering multiple environmental parameters such as temperature, humidity, light intensity, motion detection, etc. The raw data are timestamped and cleaned. Timestamp alignment is to ensure the time consistency of each sensor data, while data cleaning includes operations such as removing outliers and filling missing data. After the preprocessing steps, a preprocessed data set with a unified format and time synchronization is obtained. The preprocessed data set is multi-scale decomposed by wavelet transform to extract time and frequency domain features. Wavelet transform is a mathematical tool that can analyze signals in both time and frequency domains. By multi-scale decomposition of signals, different frequency components in sensor data and time-varying features are effectively captured to obtain a feature vector set. The Kalman filter algorithm is used to fuse multi-sensor data on the feature vector set. Kalman filter is a recursive least squares estimation algorithm that can provide optimal state estimation in a noisy environment. Through this process, multi-source sensor data are fused into a unified environmental state representation. According to the predefined ontology model, the environmental state representation is mapped into semantic triples. Ontology model is a formal representation method that defines concepts, attributes and their relationships in a specific domain. By mapping the environmental state representation into semantic triples, semantic relationships between nodes can be constructed in the knowledge graph to generate an initial knowledge graph. Sparse representation learning is performed on the initial knowledge graph to convert the nodes and edges in the graph into low-dimensional vector representations. Sparse representation learning reduces the dimension of the graph representation while retaining its structural information and semantic information, making subsequent graph calculation and reasoning more efficient. Based on the low-dimensional vector representation of the graph, different scene patterns are identified in the knowledge graph. A scene pattern is a subgraph structure that reflects a specific environmental state or event. By identifying scene patterns, semantic information meaningful to a specific scene is extracted from a complex knowledge graph to form a scene semantic subgraph. The scene semantic subgraph is an abstract expression of the current environmental state, which contains the relationship between different entities in the environment and their evolution trend. Temporal reasoning and relational reasoning are performed on the scene semantic subgraph. Temporal reasoning refers to the system predicting the possible future evolution direction based on the temporal data of the current scene, while relational reasoning is to analyze the relationship between entities in the scene and their change trend. Through these two reasoning methods, the evolution prediction results of the scene are obtained. Based on the scene evolution prediction results, multi-step decision sequence analysis is performed to form a scene control strategy. Multi-step decision sequence analysis means that the system sequentially deduces the optimal decision for each time step while considering multiple time steps. By analyzing the impact of different decision sequences, the optimal scene control strategy is selected, including equipment switch control, parameter adjustment, early warning mechanism, etc.

[0037] Step 400: Collect network data packets at key nodes of the dynamic device topology map and extract features, input the extracted features into a deep learning model, and combine with threat intelligence analysis to obtain security situation assessment results;

[0038] Specifically, the importance of each node is calculated according to the structural characteristics of the dynamic device topology graph. A variety of graph theory algorithms, such as degree centrality, betweenness centrality or eigenvector centrality, are used to quantify the relative importance of each node in the entire network structure. Based on the calculation results, nodes that play a key role in the network are selected, and network packet capture modules are deployed on these nodes to maximize the effectiveness of packet capture. The packet capture modules deployed on key nodes capture network packets passing through these nodes in real time. The captured network packets are subjected to protocol parsing and session reorganization. Protocol parsing refers to parsing packets according to the network protocols to which they belong (such as TCP, UDP, etc.) to extract information at each protocol level. Session reorganization is to reassemble packets belonging to the same session to form a complete communication record. Through these two steps, some basic features are extracted from the packets, such as source and destination addresses, port numbers, protocol types, and data load features. These features together constitute a feature matrix. The feature matrix is ​​subjected to dimensionality reduction processing to obtain a feature vector after dimensionality reduction. The feature vector after dimensionality reduction is input into the pre-trained deep learning model, and high-level semantic features are extracted from the feature vector to generate a feature graph. Perform time series feature analysis on the feature graph to capture the dynamic characteristics of network behavior over time, such as the gradual evolution of certain attack behaviors or the periodic characteristics of abnormal traffic, and obtain the network behavior sequence representation. Use the attention mechanism to perform weighted aggregation on the network behavior sequence representation, dynamically assign weights to different time series features, and generate global network behavior features. Perform similarity matching on the global network behavior features and the threat intelligence database updated in real time to identify potential threat patterns. The threat intelligence database stores known threat patterns and their feature descriptions, such as specific attack behaviors, malicious IP addresses, etc. Through similarity matching, known threats in the network can be quickly identified, and the early warning mechanism can be triggered when necessary. According to the identified potential threat patterns, combined with the network topology and device importance, the overall risk score of the system is calculated. Considering the possible impact of each threat on different devices or network areas, as well as the importance of the device in the entire network, the security risks currently faced by the system are comprehensively evaluated. Generate security situation assessment results.

[0039] Step 500: Perform deep packet inspection based on the security situation assessment results and the scenario control strategy to identify abnormal behaviors, cluster and analyze the root causes of the abnormal behaviors, and generate a network optimization strategy;

[0040] Specifically, the sensitivity threshold of deep packet inspection is set according to the security situation assessment results. The network traffic is sampled in layers, thereby reducing the amount of data and improving the analysis efficiency while ensuring the representativeness of the data. Layered sampling divides the data packets into different layers according to the different characteristics of the traffic (such as protocol type, packet size, time interval, etc.), and randomly extracts a certain proportion of data packet samples from each layer to obtain a comprehensive layered data packet sample set. The regular expression engine is used to match the protocol features of the layered data packet samples. The regular expression engine can parse the application layer payload content of the data packet through a predefined set of rules and extract content features containing useful information, such as HTTP request headers, URL paths, device identifiers, etc. These features can reflect the specific behavior of the data packet at the application layer and form a data packet content feature set. A baseline model of normal behavior is constructed based on the scenario control strategy. The baseline model is a description of various network behaviors of the system under normal conditions, which is defined by historical data and policy rules. The extracted data packet content feature set is analyzed for deviations from the baseline model to identify abnormal data packets that deviate from normal behavior, such as a sudden large amount of unknown protocol traffic, abnormal request frequency, or suspicious data transmission mode. The abnormal sequence detection algorithm based on recurrent neural network extracts the time series abnormal pattern of abnormal data packets, effectively capturing the pattern of abnormal data packets changing over time, such as the gradual escalation of a certain attack behavior or the repeated occurrence of periodic abnormal behavior. By analyzing the time series pattern, an abnormal behavior sequence describing the evolution process of abnormal behavior is generated. Multi-dimensional feature clustering is performed on the abnormal behavior sequence, and abnormal behaviors with similar features are classified into the same category to facilitate the identification of the same type of attack or abnormal behavior pattern. In the clustering process, the inter-cluster distance matrix is ​​calculated, and each element in the matrix represents the similarity or distance between two abnormal behavior clusters. Based on the inter-cluster distance matrix, a minimum spanning tree is constructed, and hierarchical clustering of abnormal behaviors is performed on this basis. Hierarchical clustering can divide complex abnormal behaviors into multiple levels and obtain different categories of abnormal behaviors, such as DDoS attacks, SQL injections, or malware propagation. Root cause analysis is performed on the abnormal behavior categories, and an abnormal propagation graph is constructed. The abnormal propagation graph is established based on the interaction relationship between the abnormal behavior sequence and the device, where the node represents the abnormal source or the affected device, and the edge represents the propagation path of the abnormal behavior. By analyzing the anomaly propagation graph, key anomaly sources are identified, that is, nodes or devices that play a key role in the propagation of abnormal behavior. Key anomaly sources are usually the initiation point of the attack or an important hub in the propagation. Combined with the network topology and key anomaly source information, network optimization strategies are generated. Network optimization strategies include a series of measures to improve network security and stability, such as traffic redirection, link isolation, and node reconfiguration.Traffic redirection directs abnormal traffic to dedicated defense nodes for processing, thereby avoiding affecting normal business; link isolation cuts off the connection between infected nodes and other nodes to prevent further spread of abnormal behavior; node reconfiguration adjusts the configuration of nodes with security risks to reduce their risk of attack.

[0041] Step 600: Select a cluster head node to perform load-balanced data transmission according to a network optimization strategy, and dynamically adjust the node working mode and network topology to achieve global energy efficiency optimization.

[0042] Specifically, according to the network optimization strategy, each node in the network is scored in multiple dimensions. The scoring indicators include the node's remaining energy, processing capacity, network connection stability, transmission rate, etc. Through multi-dimensional scoring, the fitness value of each node is calculated, which represents the node's potential as a cluster head node in the current network structure. Based on the fitness value, suitable main cluster head and deputy cluster head nodes are selected to build a dual cluster head structure. The purpose of the dual cluster head structure is to achieve task division and load sharing within a cluster. The main cluster head handles the main communication and data aggregation tasks, while the deputy cluster head serves as an auxiliary node to supplement and support when the main cluster head is overloaded or fails. Task weights are assigned to the main cluster head and the deputy cluster head to achieve load balancing between them. The allocation of task weights needs to take into account the capabilities of each node and the current network requirements. For example, the main cluster head undertakes a larger proportion of data transmission tasks, while the deputy cluster head mainly handles secondary tasks and data backup. Based on the task weight allocation, the dynamic time division multiple access protocol is used to schedule data transmission within the cluster. The dynamic time division multiple access protocol divides time into multiple time slots, and different nodes transmit data in the allocated time slots to avoid communication conflicts. A transmission time slot allocation table is generated based on the task weight and the amount of node data, listing the transmission arrangements of each node in each time slot. According to the generated transmission time slot allocation table, the transmission power of the node is dynamically adjusted. The adjustment of the transmission power needs to balance the relationship between the communication distance and energy consumption: a larger transmission power can improve the transmission distance and data stability, but it will also consume more energy; while a smaller transmission power saves energy, but it is easy to cause communication interruption or data loss. Through calculation and optimization, a reasonable power configuration plan is formulated for each node to ensure that data can be transmitted smoothly while minimizing energy consumption. On this basis, the working mode of the node is dynamically adjusted to generate a node state transition strategy including active, dormant and relay. Nodes in the active state transmit and process data in the predetermined time slot, while nodes in the dormant state temporarily stop communicating to save energy; nodes in the relay state are mainly used to forward data from other nodes, thereby expanding the network coverage or improving data transmission efficiency. Through the state transition strategy, the working mode of each node is dynamically adjusted according to the actual needs of the network, thereby optimizing the overall energy efficiency. Based on the node state transition strategy, the network structure is dynamically reconstructed. According to the current node state and connection relationship, the network topology is adjusted to achieve the best balance between performance and energy consumption. Based on the node state transition strategy, the connections in the network are added, deleted, modified and checked to form an optimized network topology. A distributed consensus algorithm is used to synchronously update routing information in the optimized network topology. The distributed consensus algorithm can ensure that all nodes in the network reach a consensus on the changes in routing information, avoid communication errors or data loss due to asynchrony, and form a globally consistent network view. Under the guidance of this view, each node performs data transmission and route selection to complete global energy efficiency optimization.

[0043] In the embodiment of the present application, through distributed discovery and lightweight authentication mechanism, fast access and security authentication of heterogeneous devices are achieved, and the compatibility and security of the system are improved. The device capability description file and virtualization layer are adopted to realize the unified abstraction and management of physical devices, and enhance the scalability and device interoperability of the system. Based on multi-source sensor data fusion and knowledge graph construction, intelligent perception and reasoning of complex IoT scenarios are realized, and the scene understanding and decision-making ability of the system are improved. Combined with deep learning models and threat intelligence analysis, real-time assessment of network security situation is realized, and the system's identification and defense capabilities against potential security threats are enhanced. Through deep packet detection and abnormal behavior clustering analysis, accurate identification and root cause analysis of network anomalies are achieved, and the efficiency of network fault diagnosis and optimization is improved. The dual cluster head structure and dynamic load balancing mechanism are adopted to realize efficient scheduling of network data transmission and improve the throughput and reliability of the system. Adaptive power control and dynamic topology adjustment strategies are adopted to achieve global energy efficiency optimization and extend the overall operation time of the IoT system.

[0044] In a specific embodiment, the process of executing step 100 may specifically include the following steps:

[0045] Adopt OpenHarmony's distributed soft bus technology to broadcast device discovery requests in the local area network, obtain device response information, parse the device response information, extract device type, function description and unique identifier, and generate a list of devices to be authenticated;

[0046] Generate a random challenge value based on elliptic curve cryptography, and send the random challenge value to each device in the list of devices to be authenticated;

[0047] Receive the signature and public key certificate returned by the device in the list of devices to be authenticated, verify the public key certificate, obtain a valid certificate, and use the public key in the valid certificate to verify the signature. After the verification is passed, add the corresponding device to the authentication device set;

[0048] Assign a session key to each device in the authentication device set, establish an encrypted communication channel, and build an initial network topology based on a graph theory algorithm, with the devices in the authentication device set as nodes and the communication links between devices as edges;

[0049] A dynamic update algorithm is used to monitor the online status of devices and changes in network connections in real time, adjust the initial network topology, and generate a dynamic device topology map.

[0050] Specifically, the distributed soft bus technology of OpenHarmony is used to broadcast the device discovery request in the local area network. Distributed soft bus technology supports cross-device and cross-platform collaborative communication, so that different types of devices can interact through standardized protocols. When the device receives the device discovery request, it generates a response message and returns it to the main device that sent the request. The response message usually contains basic information about the device, such as the device type (such as sensor, actuator, controller, etc.), functional description (such as measuring temperature, humidity, light, etc.) and unique identifier (usually the device's MAC address or other unique identifier). The device response information is parsed, and key fields such as the device type, functional description and unique identifier are extracted from the response information. All extracted device information is summarized to generate a list of devices to be authenticated. The list contains all devices that are available in the current local area network and have responded to the discovery request. Generate a random challenge value based on elliptic curve cryptography, and send the random challenge value to each device in the list of devices to be authenticated. Elliptic curve cryptography is a public key encryption algorithm, and the generated random challenge value is expressed as:

[0051] ;

[0052] in, is the random challenge value, is a private random number. is the base point on the elliptic curve. After each device to be authenticated receives the challenge value, it signs the value with its private key and returns the signature result together with the device's public key certificate to the master device. After receiving this information, the master device verifies the public key certificate provided by the device to ensure that the identity of the device is authentic and valid. The process of verifying a public key certificate usually involves checking whether the issuer of the certificate is trustworthy and whether the certificate is within the validity period. If the certificate verification passes, it is considered a valid certificate. Use the public key in the valid certificate to verify the signature returned by the device. Assume that the signature verification formula is:

[0053] ;

[0054] in, is the signature verification result, is the public key of the device. If the verification is successful, it means that the identity of the device has been confirmed and the device is added to the authentication device set. A session key is assigned to each device in the authentication device set to establish an encrypted communication channel. The distribution of session keys is implemented based on the Diffie-Hellman key exchange protocol. Each device generates a temporary key pair and sends its public key to the master device. The master device generates a temporary key pair and sends its public key to the device. Both parties calculate the shared session key based on the other party's public key and their own private key. This process is expressed by the following formula:

[0055] ;

[0056] in, is the shared session key, is the temporary private key of the device. is the public key of the master device. The initial network topology is constructed based on the graph theory algorithm. All authenticated devices are regarded as nodes in the graph, and the communication links between devices are the edges in the graph. The minimum spanning tree algorithm, such as the Kruskal algorithm or the Prim algorithm, is used to construct the topology, so as to achieve the connectivity of all devices at the cost of as few communication links as possible. The network topology is adjusted in real time. The dynamic update algorithm is used to monitor the online status of the device and the changes in network connection in real time. This monitoring is achieved through the heartbeat mechanism or the device status report mechanism. The heartbeat mechanism means that each device sends a heartbeat signal to the master device at a certain time interval to indicate that it is online. If the master device does not receive the heartbeat signal of a device within the set time, it is considered that the device is offline and needs to be removed from the topology. For new devices, the master device will also include them in the topology when it detects that they have joined. As devices continue to join, leave or change their status, the initial network topology is no longer suitable for the current network status. The network topology is adjusted based on the dynamic update algorithm. For example, when a key device is offline, a new communication path or cluster head device is reselected to ensure the connectivity of the network and the stability of data transmission. After dynamic adjustment, a dynamic device topology map is generated to reflect the status and connection status of each device in the current network in real time.

[0057] In a specific embodiment, the process of executing step 200 may specifically include the following steps:

[0058] Perform capability detection on each device in the authentication device set, extract the basic information, function list, data interface and control command set of the device, and generate original device capability data;

[0059] Using a predefined XML template, the original device capability data is converted into a standardized XML format to obtain a device capability description file;

[0060] Perform syntax analysis and semantic checking on the device capability description file, verify the structural integrity and data consistency, generate a valid device capability description file, and create a corresponding virtual device object for each physical device based on the valid device capability description file, encapsulating the device communication protocol and data conversion logic;

[0061] Classify and organize virtual device objects, build a device object tree structure, implement hierarchical management of devices, create a unified data access interface and control interface for virtual device objects, and build a device abstraction layer;

[0062] The device capability registration mechanism is implemented based on the publish-subscribe model, allowing virtual device objects to dynamically register and update their capability information. At the same time, the reflection mechanism and dynamic proxy technology are used to realize the automatic discovery and call of device capabilities and complete the construction of the virtualization layer.

[0063] Specifically, the capability detection is performed on each device in the authentication device set, and the basic information, function list, data interface and control command set of each device are extracted to generate the original device capability data. By establishing communication with each device, the capability information is parsed from the response returned by the device. The original device capability data is converted into a standardized XML format using a predefined XML template. XML (Extensible Markup Language) is suitable for describing various aspects of device capabilities due to its good structural characteristics. The predefined XML template defines the structure of the device capability description file and the format of each field to obtain the device capability description file. For example, the template includes a device basic information node, a function list node, a data interface node and a control command set node. The device capability description file is parsed and semantically checked. The grammatical analysis is to ensure that the structure of the XML file conforms to the predefined rules, such as the correct use of each tag, the matching of the data format, etc. The semantic check is to verify whether the data logic in the file is correct. For example, whether the function list and control command set of a device correspond to each other, whether the data interface description is consistent with the protocol actually used by the device, etc. Through the check, a valid device capability description file is generated. Based on the valid device capability description file, a corresponding virtual device object is created for each physical device. The virtual device object is an abstract encapsulation of the physical device, which contains all the functions and interfaces of the device, and also encapsulates the communication protocol and data conversion logic of the device. The complexity of the physical device is hidden inside the virtual device object, so that the system can interact with the device through a standardized interface. The virtual device objects are classified and organized to build a device object tree structure. The device object tree structure is a structural method that hierarchically manages all virtual device objects according to their types, functions or logical relationships. For example, all sensor devices constitute one subtree, and all control devices constitute another subtree. In each subtree, the specific functions, location and other information of the device are further divided. A unified data access interface and control interface are created for the virtual device object to build a device abstraction layer. At the same time, the device capability registration mechanism is implemented based on the publish-subscribe mode, allowing the virtual device object to dynamically register and update its capability information. The publish-subscribe mode allows the virtual device object to dynamically register and update its capability information when the device capability changes. For example, when a device adds a new function to its function list, it notifies other components in the system of this change by publishing a capability update message. Other modules that have subscribed to the device capability information, such as controllers or monitoring modules, can obtain this change in time and handle it accordingly. Reflection mechanism and dynamic proxy technology are used. The reflection mechanism allows the system to dynamically obtain the capability information and interface methods of virtual device objects at runtime, so as to automatically generate the interface and logic of device operation by analyzing the device capability description file without modifying the system code.Dynamic proxy technology can generate corresponding proxy objects based on the current device status and capability information. For example, when the communication method of a device changes from MQTT to HTTP, the dynamic proxy mechanism automatically switches to the new communication method without modifying the underlying logic. This mechanism enables the system to automatically adjust its operation mode when the device capabilities change, thereby realizing automatic discovery and invocation of device capabilities.

[0064] In a specific embodiment, the process of executing step 300 may specifically include the following steps:

[0065] Obtain the raw data of multi-source sensors from the data access interface of the virtualization layer, align the timestamps of the raw data and clean the data to obtain the preprocessed data set;

[0066] Wavelet transform is used to perform multi-scale decomposition on the preprocessed data set, and time-frequency domain features are extracted to obtain a feature vector set. Multi-sensor data fusion is performed on the feature vector set based on the Kalman filter algorithm to generate a unified environmental state representation.

[0067] According to the predefined ontology model, the environment state representation is mapped into semantic triples to construct the initial knowledge graph, and sparse representation learning is performed on the initial knowledge graph to obtain low-dimensional vector representations of graph nodes and edges;

[0068] Based on low-dimensional vector representation, the scene patterns in the recognition graph are formed into scene semantic subgraphs, and temporal reasoning and relational reasoning are performed on the scene semantic subgraphs to obtain the scene evolution prediction results.

[0069] A multi-step decision sequence analysis is performed based on the scenario evolution prediction results to form a scenario control strategy.

[0070] Specifically, the raw data of multi-source sensors are obtained from the data access interface of the virtualization layer. These data come from different types of sensors, such as temperature sensors, humidity sensors, light sensors, gas sensors, etc., and are presented in a unified interface format through the virtualization layer, which is convenient for the system to collect and process data. The raw data is timestamped and cleaned to obtain a preprocessed data set. The preprocessed data set is decomposed at multiple scales using wavelet transform. Wavelet transform decomposes sensor data into components of different scales, corresponding to high-frequency and low-frequency information in the data. Multiscale decomposition can reveal the hidden time series change patterns and spectral features in the data. For each decomposition scale, a set of feature vectors in the time-frequency domain is extracted, where each feature vector represents the time series data feature at that scale. The Kalman filter algorithm is used to fuse the feature vector set for multi-sensor data. Kalman filtering is a recursive least squares estimation algorithm that can provide optimal state estimation in a noisy dynamic environment. Through the Kalman filter algorithm, the feature vectors of different sensors at the same time point are fused to obtain a unified environmental state representation. The Kalman filter process is expressed as the following recursive formula:

[0071] ;

[0072] in, Indicates at time The best estimate of the system state, is based on the predicted state at the previous moment. is the Kalman gain, which measures the relationship between prediction error and observation error, It is at the moment The observed value of is an observation matrix, which represents the relationship between the system state and the observation. Through the recursive update process, the weights are dynamically adjusted between multiple sensor observation data to obtain a smooth and reliable representation of the environment state. The environment state representation is mapped into semantic triples according to the predefined ontology model to construct the initial knowledge graph. The ontology model is a formal representation method that defines the concepts, attributes and their relationships in a specific field. The fusion data of multi-source sensors is converted into predefined concepts and relationships. Sparse representation learning is performed on the initial knowledge graph to convert the nodes and edges in the graph into low-dimensional vector representations. The low-dimensional vector representation can significantly reduce the complexity of the data while maintaining the original semantic information. The sparse representation learning process is implemented by graph embedding algorithms, such as Node2Vec or GraphSAGE. The graph embedding algorithm can embed the nodes in the knowledge graph into a low-dimensional vector space, where the vector of each node represents its structural features and semantic information in the graph. Based on the low-dimensional vector representation, different scene patterns are identified in the knowledge graph to form scene semantic subgraphs. A scene pattern refers to a group of graph substructures with similar semantic and structural features, reflecting a specific environmental state or device interaction relationship. Perform temporal reasoning and relational reasoning on the scene semantic subgraph to obtain the scene evolution prediction results. Temporal reasoning refers to predicting the possible future evolution direction based on the temporal data of the current scene. Relational reasoning is to analyze the relationship between the various devices in the scene and their changing trends. Through these two reasoning methods, the scene evolution prediction results are generated. Based on the scene evolution prediction results, multi-step decision sequence analysis is performed to form a scene control strategy. Multi-step decision sequence analysis refers to the deduction of the optimal decision for each time step in sequence while considering multiple time steps. By analyzing the impact of different decision sequences, the optimal scene control strategy is selected.

[0073] In a specific embodiment, the process of executing step 400 may specifically include the following steps:

[0074] According to the structural characteristics of the dynamic device topology, the importance of nodes is calculated, and key nodes are selected to deploy network packet capture modules;

[0075] Perform protocol parsing and session reorganization on the captured network data packets, extract source and destination addresses, port numbers, protocol types, and data load features to form a feature matrix, and perform dimensionality reduction on the feature matrix to obtain a feature vector after dimensionality reduction;

[0076] The reduced feature vector is input into the pre-trained deep learning model to extract high-level semantic features, generate feature graphs, and perform temporal feature analysis on the feature graphs to obtain a network behavior sequence representation.

[0077] Based on the attention mechanism, the network behavior sequence representation is weighted and aggregated to generate global network behavior features. The global network behavior features are then matched with the threat intelligence database updated in real time to identify potential threat patterns.

[0078] Based on the identified potential threat patterns, combined with the network topology and device importance, the overall risk score of the system is calculated to generate a security situation assessment result.

[0079] Specifically, the dynamic device topology is a representation of all devices and their communication links in the IoT system, reflecting the connection relationship and communication status of each node (device) in the current network. In order to identify nodes that play an important role in the overall operation of the network, the centrality index in graph theory is used to measure the importance of each node. These indicators include degree centrality (measures the number of nodes directly connected to a node), betweenness centrality (measures the role of a node in the information flow path in the network) and eigenvector centrality (measures the connection between a node and other important nodes). For example, by analyzing the dynamic device topology, some key nodes are found, such as gateway nodes as data aggregation points, or routing nodes connecting multiple subnets. Once these nodes are abnormal or attacked, they will affect the normal operation of the entire network. Therefore, it is preferred to deploy network packet capture modules at key nodes to monitor their communication behavior. Protocol parsing and session reorganization are performed on the captured network packets. Protocol parsing refers to decomposing the data packets according to the network protocols to which they belong (such as TCP, UDP, HTTP, etc.) to extract specific information at each protocol level. Session reorganization is to reassemble multiple data packets belonging to the same session in chronological order to form a complete communication record. This process helps the system better understand the interaction between different devices and identify potential threat patterns. After completing protocol parsing and session reorganization, extract the source and destination addresses, port numbers, protocol types, and data load characteristics of each data packet, and organize this information into a feature matrix. The feature matrix is ​​a multidimensional data structure, in which each row represents a data packet or a session, and each column represents a feature of the data packet or session, such as source IP, destination IP, source port, destination port, protocol type, data length, load content, etc. Perform dimensionality reduction on the feature matrix. While retaining the key information in the feature matrix, reduce the dimension of the data and reduce the computational complexity. Dimensionality reduction algorithms include principal component analysis and linear discriminant analysis. Through these algorithms, extract the low-dimensional feature vector that best represents the data characteristics in the feature matrix. Assume that the feature vector after dimensionality reduction is expressed as:

[0080] ;

[0081] in, is the eigenvector after dimensionality reduction, It is the feature value on different dimensions, which together describe the main features of the data packet or session. The feature vector after dimensionality reduction is input into the pre-trained deep learning model to extract high-level semantic features. The deep learning model uses convolutional neural networks or long short-term memory networks, etc. These models can automatically learn complex features in the data and map them to a new feature space. Through the processing of the deep learning model, a feature graph is generated, in which each node represents the high-level semantic features of a data packet or session, and the edges between nodes represent the association between different data packets or sessions. The feature graph is analyzed for time series features to identify the behavior sequence patterns in the network. By analyzing the time series features of data packets or sessions, potential abnormal behavior patterns can be identified. For example, a DDoS attack is manifested as a large number of data packets concentrated on a target node within a certain period of time, while a worm propagation attack is manifested as a sudden and substantial increase in the number of sessions of a certain node. Through time series feature analysis, the nodes and edges in the feature graph are converted into network behavior sequence representations, capturing the data flow patterns and their evolution trends at different time points in the network. The network behavior sequence representation is weighted and aggregated based on the attention mechanism. According to the changes in the current network environment, the weights of different behavior sequences are dynamically adjusted to generate global network behavior features. The global network behavior features are similarly matched with the threat intelligence database that is updated in real time to identify potential threat patterns. The threat intelligence database stores known threat patterns and their feature descriptions, such as certain specific types of attack behaviors, malicious IP addresses, known vulnerability exploits, etc. Through similarity matching, it is possible to quickly identify whether there are known threat patterns in the network and trigger an early warning mechanism when necessary. Assume that the feature vector of a malicious network behavior is , the current global network behavior characteristics are , then we measure their similarity by calculating the cosine similarity between the two vectors:

[0082] Similarity ;

[0083] in, represents the dot product of vectors, and Respectively represent the modulus length of the vector. The value range of cosine similarity is [-1, 1]. The closer the value is to 1, the more similar the two are. When the similarity exceeds a preset threshold, the system considers that there are signs of the threat pattern in the current network and records this potential threat in the system. According to the identified potential threat pattern, combined with the network topology and device importance, the overall risk score of the system is calculated to generate a security situation assessment result. The calculation of the risk score takes into account multiple factors, including the severity of the threat pattern, the importance of key nodes, the connectivity of the current network, etc. Each identified threat pattern is scored, and the weighted average of these scores is performed on the entire network to obtain the risk score of the current network. A security situation report is generated based on the assessment results, and corresponding protection suggestions are provided, such as strengthening firewall rules, isolating attacked nodes, optimizing network topology, etc.

[0084] In a specific embodiment, the process of executing step 500 may specifically include the following steps:

[0085] According to the security situation assessment results, the sensitivity threshold of deep packet inspection is set, and the network traffic is sampled in layers to obtain layered data packet samples;

[0086] A regular expression engine is used to match protocol features of layered data packet samples, extract application layer payload content, and form a data packet content feature set;

[0087] Build a normal behavior baseline model based on the scenario control strategy, analyze the deviation between the data packet content feature set and the baseline model, and identify abnormal data packets;

[0088] The abnormal sequence detection algorithm based on recurrent neural network extracts the time sequence abnormal pattern of abnormal data packets and generates abnormal behavior sequences;

[0089] Perform multi-dimensional feature clustering on abnormal behavior sequences to form abnormal behavior clusters, calculate the inter-cluster distance matrix, and build a minimum spanning tree based on the inter-cluster distance matrix to perform hierarchical clustering on abnormal behaviors and obtain abnormal behavior categories;

[0090] Perform root cause analysis on abnormal behavior categories, build an abnormal propagation graph, identify key abnormal sources, and generate network optimization strategies including traffic redirection, link isolation, and node reconfiguration based on the key abnormal sources and abnormal propagation graph in combination with the network topology.

[0091] Specifically, the sensitivity threshold of deep packet inspection is set according to the security situation assessment results, and the network traffic is sampled in layers to obtain representative layered data packet samples. When the system detects a potential threat in the network, the sensitivity threshold of deep packet inspection is increased, so that more attention is paid to subtle abnormal traffic characteristics when sampling data. When the network condition is normal, the sensitivity threshold is appropriately lowered to reduce unnecessary resource consumption. The process of layered sampling is to divide the network traffic into different layers according to different traffic characteristics (such as protocol type, packet size, source and destination address, etc.), and randomly extract a certain proportion of packet samples from each layer to form a comprehensive layered packet sample set. The regular expression engine is used to match the protocol features of the layered packet samples, extract the application layer load content and form a packet content feature set. The regular expression engine can quickly identify key information in the data packet, such as HTTP request header, URL path, device identifier, etc. through a predefined set of rules. Through these rules, the application layer load information in the data packet is structured and converted into a packet content feature set that is convenient for subsequent analysis. A normal behavior baseline model is constructed based on the scenario control strategy. The process of constructing the normal behavior baseline model is based on the statistical characteristics of normal network behavior in different application scenarios. The scenario control strategy usually contains network traffic characteristics in different time periods and different device interaction situations. By combining the statistical analysis of historical data and the scenario control strategy, a baseline model reflecting normal network behavior is constructed. The packet content feature set extracted from the layered packet sample is analyzed for deviation from the baseline model to identify abnormal packets that deviate from the normal behavior pattern. The degree of deviation is measured by calculating the distance between the packet content feature set and the baseline model. Let the feature vector be , the mean vector of the baseline model is , then the deviation metric is expressed using the Euclidean distance:

[0092] ;

[0093] in, Represents the deviation distance between the feature set of the data packet content and the baseline model, is the first feature vector eigenvalues, is the first value in the mean vector of the baseline model characteristic value. When the deviation distance When a certain preset threshold is exceeded, the data packet is considered to be an abnormal data packet and recorded for further analysis. For the identified abnormal data packets, the abnormal sequence detection algorithm based on the recurrent neural network extracts the time series abnormal pattern and generates an abnormal behavior sequence. The recurrent neural network is a deep learning model for processing time series data, which can capture the dynamic characteristics of data packets changing over time and identify the potential patterns therein. The abnormal data packets are input into the recurrent neural network model in chronological order, and the model extracts the abnormal behavior sequence according to the feature vector and time information of the data packets. The abnormal behavior sequence is clustered by multi-dimensional features, and abnormal behavior sequences with similar features are classified into the same category to identify the same type of attack or abnormal behavior pattern. In the clustering process, the similarity between each abnormal behavior sequence is calculated, and the sequences with high similarity are clustered together. For example, the abnormal behavior sequence of DDoS attack usually has the characteristics of high frequency and large number of network requests, while data theft behavior may be manifested as a series of small-scale but persistent data transmission characteristics. Different types of abnormal behaviors are clustered into different abnormal behavior clusters. In order to analyze the relationship between different abnormal behavior clusters, the distance matrix between clusters is calculated. Each element of the inter-cluster distance matrix represents the similarity or distance between two abnormal behavior clusters. The closer the distance between two clusters, the more similar their abnormal behavior characteristics are. For example, one abnormal behavior cluster may represent a large number of devices accessing the same server at the same time, while another cluster represents a large number of devices sending data out at the same time. Based on the inter-cluster distance matrix, a minimum spanning tree is constructed, and the abnormal behaviors are hierarchically clustered on this basis. The minimum spanning tree is a tree structure that can connect all nodes and has the smallest total edge weight. Through the construction of the minimum spanning tree, all abnormal behavior clusters are hierarchically divided according to similarity to obtain different categories of abnormal behaviors. Root cause analysis is performed on each abnormal behavior category to find the root cause of the abnormal behavior. Based on the time sequence of the abnormal behavior sequence and the network topology, an abnormal propagation graph is constructed. The abnormal propagation graph is a directed graph in which nodes represent abnormal sources or affected devices, and edges represent the propagation path of abnormal behaviors. For example, if a device is identified as the source of abnormal behavior and its abnormal behavior affects other devices through network connections, then the device will be marked as a root node in the abnormal propagation graph, and the affected devices will be marked as leaf nodes. By analyzing the anomaly propagation graph, key anomaly sources are identified, that is, those devices or nodes that pose a major threat to the entire network security. Based on the information of key anomaly sources and anomaly propagation graphs, combined with the network topology, network optimization strategies are generated. These strategies include traffic redirection, link isolation, and node reconfiguration. Traffic redirection directs abnormal traffic to a dedicated defense node for processing to avoid affecting normal business; link isolation cuts off the connection between the infected node and other nodes to prevent the further spread of abnormal behavior; node reconfiguration is to adjust the configuration of nodes with security risks to reduce their risk of being attacked.Through these network optimization strategies, current security threats can be effectively alleviated and the overall network security and anti-attack capabilities can be improved.

[0094] In a specific embodiment, the process of executing step 600 may specifically include the following steps:

[0095] Based on the network optimization strategy, the network nodes are scored in multiple dimensions to obtain the node fitness value. According to the node fitness value, the main cluster head and the deputy cluster head are selected to build a dual cluster head structure.

[0096] Assign task weights to the dual cluster heads to achieve load balancing between the primary and secondary cluster heads, and use the dynamic time division multiple access protocol to schedule data transmission within the cluster based on the task weights and generate a transmission time slot allocation table;

[0097] According to the transmission time slot allocation table, the node transmission power is dynamically adjusted to obtain the node power configuration plan, and the node working mode is dynamically adjusted to generate node state transition strategies including active, dormant and relay;

[0098] Based on the node state transition strategy, the network structure is dynamically reconstructed to obtain the optimized network topology. The distributed consensus algorithm is used to synchronously update the routing information in the optimized network topology to form a globally consistent network view and complete global energy efficiency optimization.

[0099] Specifically, network nodes are scored in multiple dimensions based on the network optimization strategy to obtain the fitness value of each node. The fitness value calculation takes into account indicators in multiple dimensions, which usually include the node's remaining energy, computing power, communication quality, the node's historical data transmission volume, and the connection stability of the node with other nodes. The contribution of each dimension's indicator to the fitness value is achieved through weighted average. The fitness value is , then the calculation formula of the fitness value is expressed as:

[0100] ;

[0101] in, Indicates The weight of the dimension indicator, Representation Node In the Ratings on the dimensions, is the total number of dimensions. In this way, the comprehensive fitness value of each node is calculated , and sort the fitness values ​​of all nodes to select nodes suitable for serving as the main cluster head and the deputy cluster head. When selecting the main cluster head and the deputy cluster head, the node with a higher fitness value is preferred as the main cluster head, and the node with a slightly lower but still higher fitness value is used as the deputy cluster head. The purpose of building a dual cluster head structure is to improve the reliability and load balancing ability of the network. The main cluster head is responsible for the main data aggregation, control and management tasks, while the deputy cluster head takes over part of the tasks of the main cluster head when the main cluster head is overloaded, fails or lacks energy, thereby ensuring the stable operation of the network. In order to achieve load balancing between the main and deputy cluster heads, task weights are assigned to the dual cluster heads. The assignment of task weights is based on the fitness values ​​of the dual cluster heads and the current task load of the network. Usually, the task weight of the main cluster head will be slightly higher than that of the deputy cluster head to undertake the main network management and data transmission tasks; the deputy cluster head mainly undertakes data backup, redundant communication and emergency response tasks. For example, assuming that the task weight of the main cluster head is , the task weight of the deputy cluster head is , then set and , thereby achieving reasonable load balancing in task allocation. Based on the task weight, the dynamic time division multiple access protocol is used to schedule data transmission within the cluster. The dynamic time division multiple access protocol divides time into multiple time slots, and each time slot is allocated to a specific node for data transmission. The dynamic time division multiple access protocol can dynamically adjust the time slot allocation according to the changes of nodes in the network to avoid communication conflicts and waste of resources. The system generates a transmission time slot allocation table based on the task weight and the task load of each node. For example, the main cluster head has a higher weight, so it is allocated a larger number of time slots in order to handle more communication tasks; while the secondary cluster head is allocated fewer time slots to communicate as the backup node of the main cluster head. Assume that the node The number of time slots allocated in a certain period is , then the transmission time slot allocation table is represented by a matrix:

[0102] ;

[0103] in, Indicates The number of time slots allocated to a node in the current scheduling cycle, is the total number of nodes in the cluster. In this way, effective management and scheduling are achieved on time slot resources, thereby improving communication efficiency. According to the transmission time slot allocation table, the transmission power of each node is dynamically adjusted to optimize communication energy consumption. The size of the transmission power directly affects the effective range and energy consumption of communication. The greater the power, the longer the communication distance, but at the same time the higher the energy consumption. A trade-off is made between communication needs and energy consumption. The adjustment of the transmission power is determined based on the number of time slots allocated to the node and the distance from the cluster head. Assume that the node The transmission power is , then it is expressed as:

[0104] ;

[0105] in, Is a node The number of time slots allocated, Is a node The distance between the cluster head and the cluster head. Function Used to describe the relationship between the number of time slots and distance on the transmission power. For example, when When it is larger, increase appropriately To ensure the quality of communication; When less, reduce To reduce energy consumption. Through the dynamic power adjustment mechanism, the energy consumption of nodes is reduced as much as possible while ensuring the communication quality, thereby extending the life cycle of the network. The working mode of the node is dynamically adjusted to optimize energy consumption and communication efficiency. The adjustment strategy of the working mode includes three states: active, dormant and relay. Nodes in the active state transmit and process data in the predetermined time slot; nodes in the dormant state temporarily stop communicating to save energy; and nodes in the relay state are mainly used to forward data from other nodes, thereby expanding the coverage of the network or improving data transmission efficiency. Dynamically switch between these three states according to the task load, energy state and network topology of the node. For example, when a node is allocated a small number of time slots in multiple cycles, it is switched to the dormant state; when a node is far away from the cluster head but close to other nodes, it is set to the relay state to forward data from other nodes. Based on the node state transition strategy, the network structure is dynamically reconstructed to obtain the optimized network topology. The reconstruction of the network topology takes into account the current state and connection of the nodes, removes the dormant nodes from the topology, and adjusts the location and connection mode of the relay nodes to ensure the connectivity and communication quality of the network. The goal of network topology reconstruction is to enable the network to maintain high communication efficiency and reliability at the lowest possible energy consumption. A distributed algorithm is used to synchronously update routing information between nodes in the network to ensure that all nodes can understand the current network structure and communication path in a timely manner and form a globally consistent network view. A distributed consensus algorithm is used to synchronously update routing information. The distributed consensus algorithm can reach a consensus among multiple nodes to ensure that each node can perform routing selection and data transmission based on the same network view. For example, using the Raft algorithm, a node in the network is responsible for initiating routing update requests as a leader and synchronizing the latest routing information to all other nodes (called followers). If the majority of nodes (usually more than half of the nodes) agree to the update request, it is considered that the routing update has reached a consensus, and all nodes will update their local routing tables. This enables the system to maintain a globally consistent network view when nodes frequently join, leave, or switch states, thereby achieving stable and efficient communication management. Through the above steps, the system can achieve global energy efficiency optimization in a complex and changeable IoT environment.

[0106] The above describes the IoT control method based on OpenHarmony in the embodiment of the present application. The following describes the IoT control platform 10 based on OpenHarmony in the embodiment of the present application. Figure 2 In the embodiment of the present application, an embodiment of the Internet of Things control platform 10 based on OpenHarmony includes:

[0107] The authentication module 11 is used to perform distributed discovery and lightweight authentication on IoT devices, obtain an authenticated device set, and construct a dynamic device topology map based on the authenticated device set;

[0108] A creation module 12, used to generate a device capability description file according to the authentication device set, and create a virtual device object according to the device capability description file to build a virtualization layer;

[0109] The reasoning module 13 is used to obtain multi-source sensor data from the virtualization layer and perform fusion processing, build an IoT scene knowledge graph, and perform reasoning based on the IoT scene knowledge graph to obtain a scene control strategy;

[0110] An extraction module 14 is used to collect network data packets and extract features at key nodes of the dynamic device topology map, input the extracted features into a deep learning model, and combine with threat intelligence analysis to obtain security situation assessment results;

[0111] The identification module 15 is used to perform deep packet inspection based on the security situation assessment results and the scenario control strategy, identify abnormal behaviors, cluster and analyze the root causes of abnormal behaviors, and generate network optimization strategies;

[0112] The adjustment module 16 is used to select cluster head nodes for load-balanced data transmission according to the network optimization strategy, and dynamically adjust the node working mode and network topology structure to achieve global energy efficiency optimization.

[0113] Through the collaboration of the above components, distributed discovery and lightweight authentication mechanisms, fast access and secure authentication of heterogeneous devices are achieved, improving the compatibility and security of the system. The device capability description file and virtualization layer are used to achieve unified abstraction and management of physical devices, enhancing the scalability and device interoperability of the system. Based on multi-source sensor data fusion and knowledge graph construction, intelligent perception and reasoning of complex IoT scenarios are achieved, improving the system's scenario understanding and decision-making capabilities. Combined with deep learning models and threat intelligence analysis, real-time assessment of network security situation is achieved, enhancing the system's ability to identify and defend against potential security threats. Through deep packet inspection and abnormal behavior clustering analysis, accurate identification and root cause analysis of network anomalies are achieved, improving the efficiency of network fault diagnosis and optimization. The dual cluster head structure and dynamic load balancing mechanism are used to achieve efficient scheduling of network data transmission, improving the throughput and reliability of the system. Adaptive power control and dynamic topology adjustment strategies are used to optimize global energy efficiency and extend the overall operation time of the IoT system.

[0114] The present application also provides an electronic device, which includes a memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the processor executes the steps of the Internet of Things control method based on OpenHarmony in the above-mentioned embodiments.

[0115] The present application also provides a computer-readable storage medium, which may be a non-volatile computer-readable storage medium or a volatile computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When the instructions are executed on a computer, the computer executes the steps of the Internet of Things control method based on OpenHarmony.

[0116] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, platforms and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0117] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions to enable an electronic device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., various media that can store program codes.

[0118] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An Internet of Things control method based on OpenHarmony, characterized in that: The method comprises: Perform distributed discovery and lightweight authentication on IoT devices to obtain a set of authenticated devices, and build a dynamic device topology map based on the set of authenticated devices; Generate a device capability description file according to the authentication device set, create a virtual device object according to the device capability description file, and build a virtualization layer; Acquire multi-source sensor data from the virtualization layer and fuse them to construct an IoT scene knowledge graph, and perform reasoning based on the IoT scene knowledge graph to obtain a scene control strategy; Collect network data packets and extract features at key nodes of the dynamic device topology map, input the extracted features into a deep learning model, and combine with threat intelligence analysis to obtain security situation assessment results; Based on the security situation assessment result and the scenario control strategy, deep packet inspection is performed to identify abnormal behaviors, and clustering and root cause analysis are performed on the abnormal behaviors to generate a network optimization strategy; According to the network optimization strategy, a cluster head node is selected to perform load-balanced data transmission, and the node working mode and network topology are dynamically adjusted to achieve global energy efficiency optimization.

2. The Internet of Things control method based on OpenHarmony according to claim 1, characterized in that: The distributed discovery and lightweight authentication of IoT devices are performed to obtain an authenticated device set, and a dynamic device topology map is constructed according to the authenticated device set, including: Adopt OpenHarmony's distributed soft bus technology to broadcast device discovery requests in the local area network, obtain device response information, parse the device response information, extract device type, function description and unique identifier, and generate a list of devices to be authenticated; Generate a random challenge value based on elliptic curve cryptography, and send the random challenge value to each device in the list of devices to be authenticated; Receive the signature and public key certificate returned by the device in the list of devices to be authenticated, verify the public key certificate to obtain a valid certificate, and use the public key in the valid certificate to verify the signature. After the verification is passed, add the corresponding device to the authentication device set; Assigning a session key to each device in the authentication device set, establishing an encrypted communication channel, and constructing an initial network topology structure based on a graph theory algorithm, with the devices in the authentication device set as nodes and the communication links between the devices as edges; A dynamic update algorithm is used to monitor the online status of devices and changes in network connections in real time, adjust the initial network topology structure, and generate a dynamic device topology map.

3. The Internet of Things control method based on OpenHarmony according to claim 1, characterized in that: The generating of a device capability description file according to the authentication device set, creating a virtual device object according to the device capability description file, and constructing a virtualization layer includes: Performing capability detection on each device in the authentication device set, extracting basic information, function list, data interface and control command set of the device, and generating original device capability data; Using a predefined XML template, the original device capability data is converted into a standardized XML format to obtain a device capability description file; Performing syntax analysis and semantic checking on the device capability description file, verifying structural integrity and data consistency, generating a valid device capability description file, and creating a corresponding virtual device object for each physical device based on the valid device capability description file, encapsulating device communication protocol and data conversion logic; Classifying and organizing the virtual device objects, constructing a device object tree structure, realizing hierarchical management of devices, and creating a unified data access interface and control interface for the virtual device objects to construct a device abstraction layer; The device capability registration mechanism is implemented based on the publish-subscribe model, allowing virtual device objects to dynamically register and update their capability information. At the same time, the reflection mechanism and dynamic proxy technology are used to realize the automatic discovery and call of device capabilities and complete the construction of the virtualization layer.

4. The Internet of Things control method based on OpenHarmony according to claim 1, characterized in that: The method of acquiring multi-source sensor data from the virtualization layer and fusing and processing it, constructing an IoT scene knowledge graph, and performing reasoning based on the IoT scene knowledge graph to obtain a scene control strategy includes: Acquire the raw data of multi-source sensors from the data access interface of the virtualization layer, perform time stamp alignment and data cleaning on the raw data, and obtain a preprocessed data set; Using wavelet transform to perform multi-scale decomposition on the preprocessed data set, extracting time-frequency domain features to obtain a feature vector set, and performing multi-sensor data fusion on the feature vector set based on a Kalman filter algorithm to generate a unified environmental state representation; According to a predefined ontology model, the environment state representation is mapped into a semantic triple, an initial knowledge graph is constructed, and sparse representation learning is performed on the initial knowledge graph to obtain a low-dimensional vector representation of graph nodes and edges; Recognize the scene pattern in the atlas based on the low-dimensional vector representation to form a scene semantic subgraph, and perform temporal reasoning and relational reasoning on the scene semantic subgraph to obtain a scene evolution prediction result; A multi-step decision sequence analysis is performed based on the scenario evolution prediction results to form a scenario control strategy.

5. The Internet of Things control method based on OpenHarmony according to claim 1, characterized in that: The network data packets are collected and features are extracted at the key nodes of the dynamic device topology map, the extracted features are input into the deep learning model, and the security situation assessment results are obtained by combining threat intelligence analysis, including: According to the structural characteristics of the dynamic device topology diagram, the importance of nodes is calculated, and key nodes are selected to deploy network data packet capture modules; Perform protocol parsing and session reorganization on the captured network data packets, extract source and destination addresses, port numbers, protocol types, and data load features to form a feature matrix, and perform dimensionality reduction processing on the feature matrix to obtain a feature vector after dimensionality reduction; Inputting the dimension-reduced feature vector into a pre-trained deep learning model, extracting high-level semantic features, generating a feature graph, and performing temporal feature analysis on the feature graph to obtain a network behavior sequence representation; Based on the attention mechanism, the network behavior sequence representation is weightedly aggregated to generate global network behavior features, and the global network behavior features are matched with the threat intelligence database updated in real time for similarity to identify potential threat patterns; Based on the identified potential threat patterns, combined with the network topology and device importance, the overall risk score of the system is calculated to generate a security situation assessment result.

6. The Internet of Things control method based on OpenHarmony according to claim 1, characterized in that: The performing of deep packet inspection based on the security situation assessment result and the scenario control strategy, identifying abnormal behaviors, clustering and root cause analysis of the abnormal behaviors, and generating a network optimization strategy includes: According to the security situation assessment result, a sensitivity threshold of deep packet inspection is set, and network traffic is sampled in layers to obtain layered data packet samples; Using a regular expression engine to perform protocol feature matching on the layered data packet samples, extracting application layer payload content, and forming a data packet content feature set; Building a normal behavior baseline model based on the scenario control strategy, performing deviation analysis between the data packet content feature set and the baseline model, and identifying abnormal data packets; An abnormal sequence detection algorithm based on a recursive neural network extracts a time sequence abnormal pattern from the abnormal data packet to generate an abnormal behavior sequence; Performing multi-dimensional feature clustering on the abnormal behavior sequence to form abnormal behavior clusters, and calculating the inter-cluster distance matrix, and constructing a minimum spanning tree based on the inter-cluster distance matrix, performing hierarchical clustering on the abnormal behavior, and obtaining abnormal behavior categories; Perform root cause analysis on the abnormal behavior categories, construct an abnormal propagation graph, identify key abnormal sources, and generate network optimization strategies including traffic redirection, link isolation, and node reconfiguration based on the key abnormal sources and the abnormal propagation graph in combination with the network topology.

7. The Internet of Things control method based on OpenHarmony according to claim 1, characterized in that: The method of selecting a cluster head node for load-balanced data transmission according to the network optimization strategy and dynamically adjusting the node working mode and network topology structure to achieve global energy efficiency optimization includes: Based on the network optimization strategy, the network nodes are scored in multiple dimensions to obtain the node fitness value, and according to the node fitness value, the main cluster head and the secondary cluster head are selected to construct a dual cluster head structure; Assigning task weights to the dual cluster heads to achieve load balancing between the primary and secondary cluster heads, and based on the task weights, using a dynamic time division multiple access protocol to schedule data transmission within the cluster and generate a transmission time slot allocation table; According to the transmission time slot allocation table, the node transmission power is dynamically adjusted to obtain a node power configuration plan, and the working mode of the node is dynamically adjusted to generate a node state transition strategy including active, dormant and relay; Based on the node state transition strategy, the network structure is dynamically reconstructed to obtain an optimized network topology, and a distributed consensus algorithm is used to synchronously update routing information in the optimized network topology to form a globally consistent network view and complete global energy efficiency optimization.

8. An Internet of Things control platform based on OpenHarmony, characterized in that: Used to execute the Internet of Things control method based on OpenHarmony as described in any one of claims 1 to 7, the platform includes: An authentication module is used to perform distributed discovery and lightweight authentication on IoT devices, obtain an authenticated device set, and construct a dynamic device topology map based on the authenticated device set; A creation module, used to generate a device capability description file according to the authentication device set, and create a virtual device object according to the device capability description file to build a virtualization layer; An inference module is used to obtain multi-source sensor data from the virtualization layer and fuse them, build an IoT scene knowledge graph, and perform inference based on the IoT scene knowledge graph to obtain a scene control strategy; An extraction module is used to collect network data packets and extract features at key nodes of the dynamic device topology map, input the extracted features into a deep learning model, and combine with threat intelligence analysis to obtain a security situation assessment result; An identification module, configured to perform deep packet inspection based on the security situation assessment result and the scenario control strategy, identify abnormal behaviors, cluster and perform root cause analysis on the abnormal behaviors, and generate a network optimization strategy; The adjustment module is used to select cluster head nodes for load-balanced data transmission according to the network optimization strategy, and dynamically adjust the node working mode and network topology structure to achieve global energy efficiency optimization.

9. An electronic device, characterized in that: The electronic device comprises: a memory and at least one processor, wherein instructions are stored in the memory; The at least one processor calls the instructions in the memory so that the electronic device executes the Internet of Things control method based on OpenHarmony as described in any one of claims 1-7.

10. A computer-readable storage medium having instructions stored thereon, characterized in that: When the instructions are executed by the processor, the Internet of Things control method based on OpenHarmony as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method and system for establishing virtual network on basis of multi-grit abstract theory

    CN103001823A

  • Multi-layer gradually-enhanced geological disaster knowledge graph and automatic completion method of multi-layer gradually-enhanced geological disaster knowledge graph

    CN111639196A