Safety monitoring management method and system for intelligent box lock integrated money box
Through a multi-level architecture that coordinates edge computing and fog computing, the security status of the smart box is monitored and responded in real time, and the security risks caused by network delay in the existing technology are solved, achieving more timely, comprehensive and efficient security monitoring and management.
Patent Information
- Application Number
- CN202510428750.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-04-08
AI Technical Summary
The existing smart box security monitoring management solutions rely on cloud computing, resulting in increased latency when network is unstable or congested, which may lead to inability to respond in real time, posing a major security risk.
Using a multi-level architecture that coordinates edge computing and fog computing, the edge computing unit deployed on the box acquires multimodal sensor data in real time, and performs primary feature extraction and abnormal event response. The fog computing node conducts advanced feature extraction and spatiotemporal correlation analysis, identify mass security risk events, and dynamically adjusts security policies.
Real-time perception of the security status of the model box and timely response to regional risks, overcome the security risks caused by network delays in traditional cloud computing solutions, significantly enhance the security protection capabilities of the smart model box, and eliminate potential security risks.
Smart Images

Figure CN119941092A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of financial security technology, and in particular to a security monitoring and management method and system for a smart box with integrated lock. Background Art
[0002] The transportation, dispatching, and storage of cash boxes are extremely important links in the daily operations of banks, and they undertake the key task of the safe circulation of funds. With the continuous development of financial business and the improvement of security management requirements, the traditional cash box transportation management method has gradually exposed problems such as information opacity, low dispatching efficiency, and high security risks. In this context, the smart box-lock integrated cash box, as a new type of financial security equipment, integrates advanced locking technology and intelligent management system, which can not only enhance the physical security of the cash box, but also realize real-time monitoring and remote management of the cash box status through seamless connection with the online platform.
[0003] In the existing technology, the security monitoring and management solutions for smart cash boxes mainly rely on cloud computing for data processing. Data needs to be transmitted from the smart lock to the cloud for processing and the results are returned. However, this process is greatly affected by the network conditions. When the network is unstable or congested, the delay increases, which can easily lead to the inability of security monitoring to respond in real time, and the best processing time may be missed, posing a major security risk. Summary of the invention
[0004] The present application provides a security monitoring management method and system for a smart cash box with integrated lock and box, which are used to enhance the security protection capability of the smart cash box and eliminate potential safety hazards.
[0005] In a first aspect, the present application provides a security monitoring and management method for a smart box-lock integrated cash box, the security monitoring method being applied to a target system, the target system comprising an edge computing unit deployed on the cash box and a fog computing node configured in a regional network, the method comprising: The edge computing unit acquires multimodal sensor data of the cash box in real time, wherein the multimodal sensor data includes vibration data, temperature data, location data, biometric data, and unlocking status data; The edge computing unit performs real-time analysis on the multimodal sensor data according to a preset abnormality threshold, and detects and responds to single-point abnormal events of the cash box; The edge computing unit performs local primary feature extraction on the multimodal sensor data, and uploads the extracted primary feature vector to the fog computing node; The fog computing node performs advanced feature extraction and spatiotemporal correlation analysis on the primary feature vectors uploaded by all money boxes in the regional network to identify whether there is a mass security risk event; If so, the fog computing node dynamically adjusts the security policy level of all cash boxes in the regional network to the highest level.
[0006] Optionally, the method further includes: The edge computing unit determines the current usage scenario of the cash box according to the multimodal sensor data; The edge computing unit performs real-time analysis on the multimodal sensor data according to a preset abnormal threshold, detects and responds to a single-point abnormal event of the cash box, including: The edge computing unit dynamically determines a preset abnormal threshold according to the usage scenario, and performs real-time analysis on the multimodal sensor data according to the preset abnormal threshold to detect and respond to single-point abnormal events of the cash box.
[0007] Optionally, the edge computing unit performs local primary feature extraction on the multimodal sensor data and uploads the extracted primary feature vector to the fog computing node, including: The edge computing unit calls a predefined attention strategy according to the usage scenario to assign a target weight to the multimodal sensor data, and performs weighted processing on the multimodal sensor data based on the target weight; The edge computing unit performs local primary feature extraction on the weighted multimodal sensor data, and uploads the extracted primary feature vector to the fog computing node.
[0008] Optionally, the fog computing node performs advanced feature extraction and spatiotemporal correlation analysis on the primary feature vectors uploaded by all money boxes in the regional network to identify whether there is a mass security risk event, including: The fog computing node obtains a matching risk assessment model according to the usage scenario, wherein the risk assessment model is an artificial intelligence model trained based on historical data; The fog computing node inputs the primary feature vectors uploaded by all the money boxes in the regional network into the risk assessment model for high-level feature extraction and spatiotemporal correlation analysis to identify whether there is a mass safety risk event in the usage scenario.
[0009] Optionally, the fog computing node obtains a matching risk assessment model according to the usage scenario, including: The fog computing node obtains a matching risk assessment model from a pre-trained scenario basic model library according to the usage scenario and the primary feature vector. The scenario basic model library includes a shared basic model with a residual temporal convolutional network as a backbone network and at least two lightweight scenario-specific branch models. The risk assessment model is obtained by combining the shared basic model and the scenario-specific branch model.
[0010] Optionally, after the fog computing node dynamically adjusts the security policy level of all cash boxes in the regional network to the highest level, the method further includes: The fog computing node uploads the relevant data of the mass security risk event to the cloud for analysis and verification, and maintains or restores the security policy level of all boxes in the regional network according to the instructions fed back by the cloud.
[0011] Optionally, the detecting and responding to a single point abnormal event of the cash box includes: If the single-point abnormal event is detected in the cash box, a local alarm of the cash box is triggered and the physical unlocking function of the cash box is locked.
[0012] The second aspect of the present application provides a security monitoring and management system for a smart box with integrated box lock, comprising: Edge computing units deployed on cash boxes and fog computing nodes configured in regional networks; The edge computing unit is used for: Acquire multimodal sensor data of the cash box in real time, the multimodal sensor data including vibration data, temperature data, location data, biometric data and unlocking status data; perform real-time analysis on the multimodal sensor data according to a preset abnormality threshold, detect and respond to single-point abnormal events of the cash box; perform local primary feature extraction on the multimodal sensor data, and upload the extracted primary feature vector to the fog computing node; The fog computing node is used for: The primary feature vectors uploaded by all cash boxes in the regional network are subjected to advanced feature extraction and spatiotemporal correlation analysis to identify whether there is a mass security risk event; if so, the security policy level of all cash boxes in the regional network is dynamically adjusted to the highest level.
[0013] Optionally, the edge computing unit is specifically used for: Determining a current usage scenario of the cash box according to the multimodal sensor data; A preset abnormal threshold is dynamically determined according to the usage scenario, and the multimodal sensor data is analyzed in real time according to the preset abnormal threshold to detect and respond to single-point abnormal events of the cash box.
[0014] Optionally, the edge computing unit is further used for: Invoking a predefined attention strategy according to the usage scenario to assign a target weight to the multimodal sensor data, and performing weighted processing on the multimodal sensor data based on the target weight; The weighted multimodal sensor data is subjected to local primary feature extraction, and the extracted primary feature vector is uploaded to the fog computing node.
[0015] Optionally, the fog computing node is specifically used for: Acquire a matching risk assessment model according to the usage scenario, wherein the risk assessment model is an artificial intelligence model trained based on historical data; The primary feature vectors uploaded by all the money boxes in the regional network are input into the risk assessment model for high-level feature extraction and spatiotemporal correlation analysis to identify whether there are group safety risk events in the usage scenario.
[0016] Optionally, the fog computing node is further used for: According to the usage scenario and the primary feature vector, a matching risk assessment model is obtained from a pre-trained scenario basic model library, wherein the scenario basic model library includes a shared basic model with a residual temporal convolutional network as the backbone network and at least two lightweight scenario-specific branch models, and the risk assessment model is obtained by combining the shared basic model and the scenario-specific branch model.
[0017] Optionally, the fog computing node is further used for: The relevant data of the mass security risk event is uploaded to the cloud for analysis and verification, and the security policy level of all cash boxes in the regional network is maintained or restored according to the instructions fed back by the cloud.
[0018] Optionally, the edge computing unit is further used for: If the single-point abnormal event is detected in the cash box, a local alarm of the cash box is triggered and the physical unlocking function of the cash box is locked.
[0019] A third aspect of the present application provides a security monitoring and management device for a smart box-lock integrated box, the device comprising: Processor, memory, input-output unit, and bus; The processor is connected to the memory, the input and output unit, and the bus; The memory stores a program, and the processor calls the program to execute the first aspect and any optional method for security monitoring and management of an intelligent box with integrated box lock in the first aspect.
[0020] The fourth aspect of the present application provides a computer-readable storage medium, on which a program is stored. When the program is executed on a computer, the program executes the first aspect and a security monitoring and management method for an intelligent box with integrated box lock as optional in the first aspect.
[0021] It can be seen from the above technical solutions that this application has the following advantages: A multi-level architecture that combines edge computing with fog computing is adopted to achieve real-time perception of the security status of cash boxes and timely response to regional risks. Specifically, by deploying edge computing units on the cash boxes, real-time analysis of multimodal sensor data and rapid response to single-point abnormal events are achieved, overcoming the security risks of traditional cloud computing solutions caused by network delays. At the same time, fog computing nodes are used to perform advanced feature extraction and spatiotemporal correlation analysis of cash box data in the region, effectively identify group security risks, and dynamically adjust security policies, thereby achieving more timely, comprehensive and efficient security monitoring and management. This application can not only respond to potential security threats in a timely manner, but also achieve regional collaborative defense, significantly enhancing the security protection capabilities of smart cash boxes and eliminating potential security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solution in the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0023] Figure 1 A schematic flow chart of an embodiment of a security monitoring and management method for a smart box-lock integrated box provided in this application; Figure 2 A flowchart of another embodiment of a security monitoring and management method for a smart box-lock integrated box provided by the present application; Figure 3 A schematic diagram of the structure of an embodiment of a security monitoring and management system for a smart box with integrated box lock provided in this application; Figure 4 A schematic structural diagram of an embodiment of a security monitoring and management device for a smart box-lock integrated box provided in the present application. DETAILED DESCRIPTION
[0024] The present application provides a security monitoring management method and system for a smart cash box with integrated lock and box, which are used to enhance the security protection capability of the smart cash box and eliminate potential safety hazards.
[0025] It should be noted that the security monitoring and management method of a smart box-lock integrated cash box provided in the present application is applied to a target system, and the target system includes an edge computing unit deployed on the cash box and a fog computing node configured in a regional network. Among them, the edge computing unit specifically refers to a small computing device installed on each smart cash box, which can integrate sensors, processors and communication modules. The fog computing node specifically refers to a computing entity deployed in a regional network (between the edge device and the cloud), which can be deployed in bank branches, storage centers, mobile vehicles, etc. according to the use scenario of the cash box, and is not specifically limited here. The fog computing node can establish connections with multiple edge computing units at the same time through the regional network. Since the fog computing node is closer to the edge device, the data transmission distance is shortened, and lower latency and higher bandwidth can be achieved to meet applications with high real-time requirements.
[0026] See also Figure 1 , Figure 1 An embodiment of a security monitoring and management method for a smart box-lock integrated box provided in the present application includes: 101. The edge computing unit obtains multimodal sensor data of the cash box in real time. The multimodal sensor data includes vibration data, temperature data, location data, biometric data, and unlocking status data; In the field of security monitoring of smart cash boxes, traditional solutions usually rely on a single type of sensor (such as mechanical lock status or camera) to detect the status and transmit it remotely to the cloud for analysis. However, in actual applications, cash boxes may face a variety of threats, such as violent destruction, fire, illegal movement, unauthorized access, etc., and a single sensor cannot cover all scenarios. In order to achieve real-time and comprehensive monitoring of the status of cash boxes, multimodal sensor technology is introduced, and edge computing is combined to achieve localized real-time data collection.
[0027] Specifically, the edge computing unit is integrated into the box and equipped with a variety of sensor modules, including but not limited to: vibration sensor: such as accelerometer (MEMS type); temperature sensor: such as thermistor or infrared temperature measurement module; position sensor: such as GPS module or inertial navigation unit; biometric sensor: such as fingerprint reader or iris scanner; unlocking state sensor: such as Hall sensor or micro switch. The edge computing unit is connected to the above sensors through a hardware interface, and controls the sensors to collect multimodal sensor data at a fixed frequency (such as 10 times per second or adjusted according to the usage scenario).
[0028] The multimodal sensor data specifically includes: the vibration data of the cash box collected by the vibration sensor, which can be used to detect violent attacks; the temperature data of the cash box's surrounding environment collected by the temperature sensor, which can be used to detect abnormal conditions such as fire; the geographic location data of the cash box collected by the GPS module, which can be used to track the location of the cash box to prevent loss or theft; the biometric data of the operator collected by the biometric module, such as fingerprints or facial images, can be used to verify the identity of the operator; the status data of the cash box lock collected by the unlocking status sensor can be used to detect illegal unlocking.
[0029] 102. The edge computing unit performs real-time analysis on the multimodal sensor data according to a preset abnormal threshold, and detects and responds to single-point abnormal events of the cash box; In traditional security monitoring, the analysis of sensor data often relies on cloud or central server processing, which has problems such as high latency and strong network dependence. Especially in scenarios such as financial cash boxes, insufficient real-time performance may lead to delayed response to security incidents, resulting in significant losses. In order to detect abnormal events in a timely manner and respond, the localized data processing capabilities of edge computing can be used to directly perform real-time abnormal analysis on the cash box device side. Specifically, dynamic or static abnormal thresholds can be set for each type of sensor data according to security requirements. The edge computing unit obtains sensor data in real time and compares it with the preset threshold. When the sensor data of the cash box exceeds the preset threshold, the edge computing unit determines that a single-point abnormal event has occurred. At this time, the single-point abnormal event can be responded to according to the preset response strategy, such as issuing an alarm.
[0030] In practical applications, a dynamic threshold adjustment strategy can be adopted, that is, the threshold is automatically adjusted according to historical data and real-time conditions, and multiple abnormal thresholds can be set, such as warning thresholds and alarm thresholds, and different response strategies can be adopted according to different abnormal thresholds. In addition, a variety of sensor data can be combined for comprehensive judgment to reduce the impact of false alarms from a single sensor and improve the accuracy of single-point abnormal event detection. By quickly judging abnormalities and taking local measures by presetting abnormal thresholds, real-time and independence can be guaranteed. In this process, the specific implementation of the edge computing unit relies on a simple comparison algorithm to ensure low latency and low power consumption, providing the first layer of security protection for the cash box.
[0031] 103. The edge computing unit extracts local primary features from the multimodal sensor data and uploads the extracted primary feature vectors to the fog computing node; The amount of raw sensor data is large, and uploading a large amount of raw data directly will occupy bandwidth. The fog computing node is connected to multiple cash boxes (edge computing units) at the same time. If each cash box transmits complete data, it will inevitably cause a surge in network load, which will lead to delays or communication failures. Therefore, in this embodiment, while detecting and responding to single-point abnormal events of cash boxes, the edge computing unit also needs to perform primary feature extraction on the acquired multimodal sensor data locally to generate a primary feature vector.
[0032] In terms of specific implementation, the edge computing unit performs specific processing on multimodal data such as vibration, temperature, position, biometrics, and unlocking status. For example, the maximum value and frequency of vibration data, the mean and rate of change of temperature data, etc. are calculated within a 1-second window. The edge computing unit combines the various extracted features into primary feature vectors, and then encrypts and uploads these primary feature vectors to the fog computing node through a lightweight communication protocol (such as MQTT).
[0033] 104. The fog computing node performs advanced feature extraction and spatiotemporal correlation analysis on the primary feature vectors uploaded by all the money boxes in the regional network to identify whether there are mass security risk events; The fog computing node receives primary feature vectors uploaded by all connected boxes in the regional network, and performs preprocessing operations such as data cleaning and format conversion. After that, the primary feature vectors are deeply processed to extract more complex advanced feature vectors, and perform spatiotemporal correlation analysis. Among them, the primary feature vector is the basic data feature obtained directly from the data source (sensor). It is a simple conversion or extraction of the original data, reflecting the basic properties of the data. The advanced feature vector refers to the feature extracted after deep processing of the primary feature vector, involving more complex combination and analysis of the primary feature vector. Spatiotemporal correlation analysis refers to analyzing the correlation of events in time and space, that is, combining information in the two dimensions of time and space, analyzing the advanced feature vectors, and identifying the potential correlation between data, including the degree of aggregation of similar events in time and space, and the causal relationship between events.
[0034] Since the fog computing node is connected to multiple cash boxes at the same time, it can deduce the possibility of group threats from these scattered anomalies. Specifically, the fog computing node evaluates whether there are group security risk events in all cash boxes connected in the regional network based on the extracted high-level feature vectors and the spatiotemporal correlations therein. If the high-level feature vectors show that the abnormal characteristics of multiple cash boxes are similar, it indicates that there are potential common triggering factors. The spatiotemporal correlation analysis can further verify whether this similarity is concentrated in time and space. If so, the probability of group risk increases significantly.
[0035] For example, in a cash transportation scenario in a bank, if the fog computing node analysis finds that multiple cash boxes in the regional network report abnormal trajectory similarity and unauthorized unlocking attempts in the same period, it can be inferred that this may be a coordinated attack rather than an isolated incident. If the evaluation result meets the preset conditions (such as the number of abnormal devices > 3 and the spatiotemporal correlation > 0.8), it is marked as a group security risk event, and step 105 is executed.
[0036] 105. If it exists, the fog computing node dynamically adjusts the security policy level of all boxes in the regional network to the highest level.
[0037] If a mass security risk event is identified in step 104, it indicates that the threat has expanded from a single point to the regional level, and stronger protection measures are needed to curb the spread of risks. At this time, the fog computing node dynamically adjusts the security policy level of all cash boxes in the regional network to the highest level, that is, quickly improves the security protection level of all cash boxes in the region and reduces potential losses. This highest security level involves stricter verification and restriction measures (such as multiple authentication or locking functions), that is, all security measures of the cash box are activated, so as to effectively resist further attacks and ensure the safety of the cash box and its contents.
[0038] Although the highest level provides the strongest protection, its high resource consumption and strict restrictions will significantly affect normal operation and user convenience, and may misjudge normal events due to oversensitivity. Through the single-point abnormal event detection of the edge computing unit and the group risk event assessment of the fog computing node, a hierarchical response is achieved. Only when a group threat is confirmed, the security policy level of all boxes in the area is dynamically adjusted to the highest level. This method avoids unnecessary waste of resources and ensures that strong protection can be provided at critical moments.
[0039] In this embodiment, a multi-level architecture that collaborates with edge computing and fog computing is adopted to achieve real-time perception of the security status of cash boxes and timely response to regional risks. Specifically, by deploying edge computing units on the cash boxes, real-time analysis of multimodal sensor data and rapid response to single-point abnormal events are achieved, overcoming the security risks of traditional cloud computing solutions caused by network delays. At the same time, fog computing nodes are used to perform advanced feature extraction and spatiotemporal correlation analysis of cash box data in the region, effectively identify group security risks, and dynamically adjust security policies, thereby achieving more timely, comprehensive and efficient security monitoring and management. This application can not only respond to potential security threats in a timely manner, but also achieve regional collaborative defense, significantly enhancing the security protection capabilities of smart cash boxes and eliminating potential security risks.
[0040] The following is a detailed description of the security monitoring and management method for a smart box-lock integrated box provided by this application. Please refer to Figure 2 , Figure 2Another embodiment of a security monitoring and management method for a smart box-lock integrated box provided by the present application includes: 201. The edge computing unit obtains multimodal sensor data of the cash box in real time, and the multimodal sensor data includes vibration data, temperature data, location data, biometric data, and unlocking status data; In this embodiment, step 201 is similar to step 101 in the aforementioned embodiment and will not be described again here.
[0041] 202. The edge computing unit determines the current usage scenario of the cash box according to the multimodal sensor data; In this embodiment, it is considered that the cash box has different requirements and focuses on security monitoring in different usage scenarios, such as warehousing, transportation, and handover scenarios. For example, the warehousing scenario needs to pay attention to temperature and vibration anomalies, the transportation scenario needs to monitor position offset, and the handover scenario needs to verify biometrics. Therefore, before detecting a single-point abnormal event, the edge computing unit can determine the current usage scenario of the cash box based on the multimodal sensor data, so as to perform security monitoring management in the subsequent steps in combination with the focus of different usage scenarios.
[0042] Different usage scenarios correspond to specific sensor data patterns. For example, in the storage scenario, the cash box is stationary, fixed in position, with little vibration and temperature change, and few unlocking times. In the transportation scenario, the cash box is moving, the position is constantly changing, the vibration is frequent, and the temperature may fluctuate. In the handover scenario, the cash box is stationary for a short time, biometric identification and unlocking events are frequent, and the position may be slightly adjusted. The edge computing unit can analyze the multimodal data obtained in real time, extract scene features, and match the usage scenarios using rules or simple classification models. In addition, the fog computing node can pre-specify the usage scenarios of the cash boxes in the specified area.
[0043] 203. The edge computing unit dynamically determines a preset abnormal threshold according to the usage scenario, and performs real-time analysis on the multimodal sensor data according to the preset abnormal threshold to detect and respond to single-point abnormal events of the cash box; The normal range of sensor data may be different in different usage scenarios, so the standards for preset abnormal thresholds should also be different. For example, high vibration during transportation may be a normal phenomenon, but it may be a danger signal in warehousing. The edge computing unit dynamically adjusts the threshold according to the current usage scenario of the cash box, determines the preset abnormal threshold that matches the usage scenario, and then compares the acquired multimodal sensor data with the corresponding preset abnormal threshold to detect and respond to single-point abnormal events of the cash box, so as to improve the accuracy and robustness of single-point abnormal event detection.
[0044] In some specific embodiments, if a single-point abnormal event is detected in the cash box, a local alarm of the cash box is triggered and the physical unlocking function of the cash box is locked. That is, an alarm is sounded by an audible and visual alarm at the cash box, and the cash box is prevented from being opened by a physical key or manually by mechanical or electronic means to prevent illegal opening. After the physical unlocking function of the cash box is locked, a corresponding unlocking mechanism needs to be provided, such as an authorized remote command or a specific unlocking password to open the cash box.
[0045] 204. The edge computing unit calls a predefined attention strategy according to the usage scenario to assign a target weight to the multimodal sensor data, and performs weighted processing on the multimodal sensor data based on the target weight; 205. The edge computing unit performs local primary feature extraction on the weighted multimodal sensor data, and uploads the extracted primary feature vector to the fog computing node; In the primary feature extraction stage, the influence of the usage environment can also be introduced. That is, the attention strategy for each usage scenario can be pre-defined. The attention strategy assigns different weights to the multimodal sensor data in different usage scenarios. The sum of the weights is 1, reflecting the relative importance of each modality sensor data. The edge computing unit calls the corresponding attention strategy according to the usage scenario, assigns target weights to the multimodal sensor data and performs weighted processing, including multiplying each sensor data by the corresponding target weight value, thereby significantly improving the attention to key data. Then the primary feature extraction is performed and uploaded to the fog computing node.
[0046] Due to the limited resources of edge computing units, weighted processing avoids over-analysis of low-priority data and reduces computing overhead. In addition, weighted multimodal sensor data can better reflect scene-specific anomalies, making the primary feature extraction results more representative and convenient for subsequent analysis of fog computing nodes.
[0047] 206. The fog computing node obtains a matching risk assessment model according to the usage scenario. The risk assessment model is an artificial intelligence model trained based on historical data. Risk factors and risk levels may vary in different usage scenarios. For example, during transportation, cash boxes are more vulnerable to theft or violent attacks; during storage, cash boxes are more vulnerable to natural disasters such as fire or floods. Therefore, according to the usage scenario of the cash box, the corresponding artificial intelligence risk assessment model can be trained in combination with historical data, and the trained artificial intelligence risk assessment model can be stored in the fog computing node and classified according to the usage scenario. The fog computing node calls the corresponding artificial intelligence risk assessment model from the storage according to the current usage scenario of the cash box to execute the subsequent steps.
[0048] Considering that when there are many usage scenarios, directly training independent complete artificial intelligence risk assessment models for different usage scenarios will cause a waste of resources and the generalization ability may be weak. Therefore, in some specific embodiments, a solution is proposed to form a scenario basic model library based on a shared basic model and a scenario-specific branch model, that is, the fog computing node obtains a matching risk assessment model from the pre-trained scenario basic model library according to the usage scenario and the primary feature vector.
[0049] Specifically, the scenario basic model library contains a shared basic model (to extract common features, such as time series patterns) and multiple scenario-specific branch models (for warehousing, transportation, and handover). Among them, the shared basic model adopts a multi-task pre-training framework and is trained based on the common features of all scenarios in historical data (such as vibration spectrum baseline and GPS trajectory smoothness). The shared basic model specifically uses the residual temporal convolutional network (ResTCN) as the backbone network, which can contain 5 residual blocks, each of which consists of 1D convolution, BatchNorm and ReLU, to extract common spatiotemporal features across scenarios. The shared basic model only needs to be trained once and can be reused by multiple scenario-specific branch models. Each scenario-specific branch model contains a lightweight adaptation layer (such as a 2-layer fully connected network), the input is the high-level features output by the shared model, and the output is the probability of a mass safety risk event.
[0050] It should be noted that during the training phase of the scene-specific branch model, the weights of the shared base model need to be fixed, and only the branch model parameters need to be updated to prevent catastrophic forgetting. The training data division for the scene-specific branch model can be specifically: Transportation branch: historical data on box vibration, acceleration, and route deviation during transportation; Warehouse branch: Warehouse temperature and humidity, access control switch records; Handover branch: face recognition matching rate at the handover point, geographic location compliance, and time window compliance.
[0051] When matching the risk assessment branch model, the fog node receives the label and primary feature vector of the usage scenario uploaded by the cash box, maps it to the scene meta-feature vector through the pre-trained meta-feature encoder, and then performs similarity matching between the generated scene meta-features and the meta-features of each branch model registered in the scene basic model library. If the highest similarity is ≥0.85, it is judged as a high-confidence match, and the corresponding branch model can be directly loaded at this time; if the similarity is between 0.6 and 0.85, the closest branch is loaded and lightweight fine-tuning is triggered. Specifically, operations such as comparative regularization and dynamic pruning can be performed. That is, when there is a partial feature offset between the current usage scenario and the pre-trained branch, local parameter adjustment can be used to achieve rapid improvement of model performance under limited resources.
[0052] In step 206, the fog computing node uses artificial intelligence (AI) models to analyze cash box sensor data (such as vibration, temperature, location, etc.) to evaluate its security risks in different usage scenarios (such as transportation, warehousing, and handover). These AI models are trained based on historical data and can extract key information and identify potential mass security risk events, such as theft or fire. By learning patterns in historical data, AI can predict possible problems. For example, in a transportation scenario, abnormal vibration may indicate the risk of theft; in a warehousing scenario, excessive temperature may indicate a fire hazard. This design enables AI to quickly determine whether there is a security threat to the cash box based on real-time data and scenario characteristics, thereby improving security.
[0053] The design of the AI model is divided into two core parts: a shared base model and a scenario-specific branch model. The shared base model is a general feature extraction tool that is trained based on historical data from all scenarios and uses a residual temporal convolutional network (ResTCN) to analyze common features of temporal and spatial data, such as vibration patterns or position change trends. The model is only trained once and can be reused for all scenarios, saving computing resources. The scenario-specific branch model performs refined analysis on specific scenarios and uses high-level features extracted by the shared model to calculate specific risk probabilities. Each scenario is equipped with a small neural network (usually two layers) that only trains data related to that scenario. For example, the transportation scenario focuses on vibration and route deviation, the warehousing scenario focuses on temperature and humidity changes, and the handover scenario focuses on time and location compliance. During training, the weights of the shared model remain fixed, and only the branch model parameters are adjusted, which is both efficient and does not interfere with the stability of the general features.
[0054] In actual applications, fog computing nodes intelligently match and adjust models based on current scene information. Specifically, when the similarity between scene features and pre-trained models is ≥0.85, the matching branch model is directly called for risk assessment; when the similarity is between 0.6 and 0.85, the closest model is loaded and fine-tuned to adapt to the current scene by slightly adjusting parameters. This method takes into account both speed and accuracy, while having the flexibility to respond to new scenarios. Through the combined design of "general core + dedicated branch", the artificial intelligence model can intelligently select appropriate analysis strategies according to scene requirements, accurately predict the safety risks of cash boxes, and effectively ensure their safety in transportation, warehousing, and handover.
[0055] 207. The fog computing node inputs the primary feature vectors uploaded by all the money boxes in the regional network into the risk assessment model for advanced feature extraction and spatiotemporal correlation analysis to identify whether there are group security risk events in the usage scenario; The fog computing node inputs the primary feature vectors uploaded by all cash boxes in the regional network into the risk assessment model. The risk assessment model does not only perform general feature extraction, but also extracts more discriminative features according to its training goal (i.e., risk identification in a specific usage scenario). For example, in the transportation scenario, the model may pay more attention to feature combinations related to theft or violent attacks, such as continuous abnormal vibration patterns within a specific time period, and location information showing that the cash box deviates from the scheduled route. Spatiotemporal correlation analysis is also based on the knowledge of the risk assessment model, and the model will consider the security risks that may exist in specific scenarios. For example, in the warehousing scenario, pay attention to abnormal environmental factors such as temperature and humidity, and judge the correlation with risks such as fire; in the transportation scenario, pay attention to deviations from the scheduled route and analyze the correlation with theft risks. Using a risk assessment model that matches a specific usage scenario can extract high-level features in a targeted manner and perform spatiotemporal correlation analysis, so as to more accurately identify mass security risk events.
[0056] In some specific embodiments of the scenario basic model library solution, the fog computing node first extracts advanced features from the primary feature vector through the shared basic model to extract common spatiotemporal features, which may include statistical feature vectors, time series feature vectors, and spatial feature vectors. The advanced features output by the shared basic model are then input into the exclusive branch model that matches the current usage scenario to perform spatiotemporal correlation analysis and output group correlation indicators, which specifically include: 1. The spatiotemporal aggregation index is used to measure the degree of aggregation of multiple boxes in time and space. By analyzing the time series characteristics (such as periodicity and volatility) and spatial distribution characteristics (such as density and location correlation) of the data, it is determined whether there is abnormal aggregation.
[0057] 2. Causal chain strength index, which is used to evaluate whether there is a causal relationship between multiple boxes, for example, whether the status change of a certain box triggers a chain reaction in other boxes.
[0058] 3. Similarity index, which is used to measure the similarity of behavior patterns of multiple boxes, such as the consistency of characteristics such as transportation path and operation frequency.
[0059] Finally, based on these group correlation indicators, it is possible to comprehensively judge whether there is a group safety risk event in the current usage scenario.
[0060] 208. If so, the fog computing node dynamically adjusts the security policy level of all boxes in the regional network to the highest level; In this embodiment, step 208 is similar to step 105 in the aforementioned embodiment and will not be described again here.
[0061] 209. The fog computing node uploads the relevant data of mass security risk events to the cloud for analysis and verification, and maintains or restores the security policy level of all boxes in the regional network according to the instructions fed back by the cloud.
[0062] Although fog computing nodes can initially identify mass security risk events, there may be misjudgments. The cloud usually has more powerful computing and storage capabilities and can perform more complex data analysis and decision-making. Therefore, fog computing nodes can upload relevant data of mass security risk events to the cloud for further analysis and verification. The cloud can obtain more comprehensive data information, such as the security situation in other areas, the latest security threat intelligence, etc., so as to make a more accurate assessment of mass security risk events. Based on the results of analysis and verification, the cloud sends instructions to the fog computing nodes. The instruction types include: Maintain security policy level: confirm that there is a mass security risk event and maintain the current security policy level (highest level); restore security policy level: confirm that there is no mass security risk event or the risk has been resolved, and restore the security policy level to the previous state. After receiving the instruction, the fog computing node adjusts the security policy level of all boxes in the regional network according to the instruction requirements to prevent waste of resources due to excessive protection.
[0063] In this embodiment, by deploying edge computing units on cash boxes, real-time analysis of multimodal sensor data and rapid response to single-point abnormal events are achieved, overcoming the security risks caused by network delays in traditional cloud computing solutions. The edge computing unit can dynamically determine the preset abnormal threshold according to the current usage scenario of the cash box, and perform real-time analysis of multimodal sensor data based on this, thereby improving the accuracy and robustness of single-point abnormal event detection. At the same time, the edge computing unit can also call the predefined attention strategy according to the usage scenario to assign target weights to multimodal sensor data, and perform weighted processing on multimodal sensor data based on the target weights, avoiding over-analysis of low-priority data, reducing computing overhead, making the primary feature extraction results more representative, and facilitating subsequent analysis by fog computing nodes. Fog computing nodes are used to perform advanced feature extraction and spatiotemporal correlation analysis of cash box data in the region, effectively identify group safety risks, and dynamically adjust security policies, thereby achieving more timely, comprehensive and efficient security monitoring management. Fog computing nodes can obtain matching risk assessment models based on usage scenarios, thereby more accurately identifying group safety risk events. This embodiment can not only respond to potential security threats in a timely manner, but also achieve regional collaborative defense, significantly enhance the security protection capabilities of smart cash boxes, and eliminate potential security risks.
[0064] The following is a detailed description of the security monitoring and management system for a smart box with integrated lock provided by this application. Please refer to Figure 3 , Figure 3Another embodiment of a security monitoring and management system for a smart box-lock integrated box provided by the present application includes: The edge computing unit 301 deployed on the cash box and the fog computing node 302 configured in the regional network; The edge computing unit 301 is used for: Acquire multimodal sensor data of the cash box in real time, the multimodal sensor data including vibration data, temperature data, location data, biometric data and unlocking status data; perform real-time analysis on the multimodal sensor data according to a preset abnormality threshold, detect and respond to single-point abnormal events of the cash box; perform local primary feature extraction on the multimodal sensor data, and upload the extracted primary feature vector to the fog computing node 302; The fog computing node 302 is used for: Advanced feature extraction and spatiotemporal correlation analysis are performed on the primary feature vectors uploaded by all cash boxes in the regional network to identify whether there are mass security risk events; if so, the security policy level of all cash boxes in the regional network is dynamically adjusted to the highest level.
[0065] Optionally, the edge computing unit 301 is specifically used for: Determine the current usage scenario of the cash box based on multimodal sensor data; The preset abnormal threshold is dynamically determined according to the usage scenario, and the multimodal sensor data is analyzed in real time according to the preset abnormal threshold to detect and respond to single-point abnormal events of the cash box.
[0066] Optionally, the edge computing unit 301 is further configured to: Calling a predefined attention strategy according to the usage scenario to assign a target weight to the multimodal sensor data, and performing weighted processing on the multimodal sensor data based on the target weight; The weighted multimodal sensor data is subjected to local primary feature extraction, and the extracted primary feature vector is uploaded to the fog computing node 302 .
[0067] Optionally, the fog computing node 302 is specifically used for: Obtain a matching risk assessment model based on the usage scenario. The risk assessment model is an artificial intelligence model trained based on historical data. The primary feature vectors uploaded by all the money boxes in the regional network are input into the risk assessment model for advanced feature extraction and spatiotemporal correlation analysis to identify whether there are collective safety risk events in the usage scenario.
[0068] Optionally, the fog computing node 302 is further configured to: According to the usage scenario and primary feature vector, a matching risk assessment model is obtained from the pre-trained scenario basic model library. The scenario basic model library contains a shared basic model with a residual temporal convolutional network as the backbone network and at least two lightweight scenario-specific branch models. The risk assessment model is obtained by combining the shared basic model and the scenario-specific branch model.
[0069] Optionally, the fog computing node 302 is further used for: Upload relevant data of mass security risk events to the cloud for analysis and verification, and maintain or restore the security policy level of all boxes in the regional network according to the instructions fed back by the cloud.
[0070] Optionally, the edge computing unit 301 is further used for: If a single-point abnormal event is detected in the cash box, the cash box local alarm will be triggered and the physical unlocking function of the cash box will be locked.
[0071] In this embodiment, the functions of each unit are the same as those described above. Figure 1 or Figure 2 The steps in the method embodiment shown correspond to each other and will not be repeated here.
[0072] This application also provides a security monitoring and management device for a smart box with integrated lock. Figure 4 , Figure 4 An embodiment of a security monitoring and management device for a smart box-lock integrated box provided in this application includes: Processor 401, memory 402, input and output unit 403, bus 404; The processor 401 is connected to the memory 402, the input and output unit 403 and the bus 404; The memory 402 stores a program, and the processor 401 calls the program to execute any of the above-mentioned security monitoring and management methods for smart box-lock-integrated boxes.
[0073] The present application also relates to a computer-readable storage medium on which a program is stored. When the program is run on a computer, the computer executes any of the above-mentioned methods for security monitoring and management of smart box-lock-integrated boxes.
[0074] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0075] In the several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0076] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0077] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0078] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, read-only memory), random access memory (RAM, random access memory), disk or optical disk, etc. Various media that can store program codes.
Claims
1. A security monitoring and management method for a smart box with integrated box lock, characterized in that: The security monitoring management method is applied to a target system, wherein the target system includes an edge computing unit deployed on a cash box and a fog computing node configured in a regional network, and the method includes: The edge computing unit acquires multimodal sensor data of the cash box in real time, wherein the multimodal sensor data includes vibration data, temperature data, location data, biometric data, and unlocking status data; The edge computing unit performs real-time analysis on the multimodal sensor data according to a preset abnormality threshold, and detects and responds to single-point abnormal events of the cash box; The edge computing unit performs local primary feature extraction on the multimodal sensor data, and uploads the extracted primary feature vector to the fog computing node; The fog computing node performs advanced feature extraction and spatiotemporal correlation analysis on the primary feature vectors uploaded by all money boxes in the regional network to identify whether there is a mass security risk event; If so, the fog computing node dynamically adjusts the security policy level of all cash boxes in the regional network to the highest level.
2. The security monitoring management method according to claim 1, characterized in that: The method further comprises: The edge computing unit determines the current usage scenario of the cash box according to the multimodal sensor data; The edge computing unit performs real-time analysis on the multimodal sensor data according to a preset abnormal threshold, detects and responds to a single-point abnormal event of the cash box, including: The edge computing unit dynamically determines a preset abnormal threshold according to the usage scenario, and performs real-time analysis on the multimodal sensor data according to the preset abnormal threshold to detect and respond to single-point abnormal events of the cash box.
3. The security monitoring management method according to claim 2, characterized in that: The edge computing unit extracts local primary features from the multimodal sensor data and uploads the extracted primary feature vectors to the fog computing node, including: The edge computing unit calls a predefined attention strategy according to the usage scenario to assign a target weight to the multimodal sensor data, and performs weighted processing on the multimodal sensor data based on the target weight; The edge computing unit performs local primary feature extraction on the weighted multimodal sensor data, and uploads the extracted primary feature vector to the fog computing node.
4. The security monitoring management method according to claim 2, characterized in that: The fog computing node performs advanced feature extraction and spatiotemporal correlation analysis on the primary feature vectors uploaded by all money boxes in the regional network to identify whether there is a mass security risk event, including: The fog computing node obtains a matching risk assessment model according to the usage scenario, wherein the risk assessment model is an artificial intelligence model trained based on historical data; The fog computing node inputs the primary feature vectors uploaded by all the money boxes in the regional network into the risk assessment model for high-level feature extraction and spatiotemporal correlation analysis to identify whether there is a mass safety risk event in the usage scenario.
5. The security monitoring management method according to claim 4, characterized in that: The fog computing node obtains a matching risk assessment model according to the usage scenario, including: The fog computing node obtains a matching risk assessment model from a pre-trained scenario basic model library according to the usage scenario and the primary feature vector. The scenario basic model library includes a shared basic model with a residual temporal convolutional network as a backbone network and at least two lightweight scenario-specific branch models. The risk assessment model is obtained by combining the shared basic model and the scenario-specific branch model.
6. The security monitoring management method according to claim 1, characterized in that: After the fog computing node dynamically adjusts the security policy level of all cash boxes in the regional network to the highest level, the method further includes: The fog computing node uploads the relevant data of the mass security risk event to the cloud for analysis and verification, and maintains or restores the security policy level of all boxes in the regional network according to the instructions fed back by the cloud.
7. The safety monitoring management method according to any one of claims 1 to 6, characterized in that: The detecting and responding to a single point abnormal event of the cash box includes: If the single-point abnormal event is detected in the cash box, a local alarm of the cash box is triggered and the physical unlocking function of the cash box is locked.
8. A security monitoring and management system for a smart box with integrated box lock, characterized in that: The security monitoring management system includes an edge computing unit deployed on the cash box and a fog computing node configured in the regional network; The edge computing unit is used for: Acquire multimodal sensor data of the cash box in real time, the multimodal sensor data including vibration data, temperature data, location data, biometric data and unlocking status data; perform real-time analysis on the multimodal sensor data according to a preset abnormality threshold, detect and respond to single-point abnormal events of the cash box; perform local primary feature extraction on the multimodal sensor data, and upload the extracted primary feature vector to the fog computing node; The fog computing node is used for: The primary feature vectors uploaded by all cash boxes in the regional network are subjected to advanced feature extraction and spatiotemporal correlation analysis to identify whether there is a mass security risk event; if so, the security policy level of all cash boxes in the regional network is dynamically adjusted to the highest level.
9. A security monitoring and management device for a smart box-lock integrated box, characterized in that: The safety monitoring device comprises: Processor, memory, input-output unit, and bus; The processor is connected to the memory, the input and output unit, and the bus; The memory stores a program, and the processor calls the program to execute the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a program, and when the program is executed on a computer, the method according to any one of claims 1 to 7 is performed.
Citation Information
Patent Citations
Security data storage and computing method based on Internet of Things fog computing-edge computing
CN110213036A
Real-time monitoring platform based on financial information abnormal state
CN116506304A
Cash box state control method and system based on Internet of Things and edge calculation
CN116523474A
Intelligent construction site construction safety monitoring cloud edge collaborative early warning system based on edge mobile monitoring station and control system and control method of intelligent construction site construction safety monitoring cloud edge collaborative early warning system
CN118433231A
Multi-mode intelligent security method and system driven by brain-like edge calculation
CN119625961A