A safety monitoring and management method and system for an intelligent integrated box lock box

Through the collaborative architecture of edge computing units and fog computing nodes, multimodal sensor data can be analyzed in real time, quickly respond to single-point abnormalities and identify group risks, solving security risks caused by cloud computing delays, and achieving efficient security monitoring and management of smart boxes.

CN119941092BActive Publication Date: 2025-07-18CLP FINANCIAL EQUIP SYST (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510428750.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-18
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

The security monitoring and management solution of the existing smart box relies on cloud computing, resulting in increased network latency and inability to respond to security threats in real time, posing security risks.

Method used

Edge computing units are used to analyze multimodal sensor data in real time, detect single-point abnormal events, and perform advanced feature extraction and spatiotemporal correlation analysis through fog computing nodes, identify group security risks, and dynamically adjust security strategies.

Benefits of technology

Real-time perception of the safety status of the model box and timely response to regional risks are achieved, the security protection capabilities of the smart model box are enhanced, and potential safety hazards are eliminated.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119941092B_ABST
    Figure CN119941092B_ABST
Patent Text Reader

Abstract

The present application discloses a safety monitoring and management method and system for an intelligent box with an integrated lock, which is used to enhance the safety protection ability of the intelligent box and eliminate potential safety hazards. The method of the present application includes: the edge computing unit obtains multi-modal sensor data of the box in real time; the edge computing unit performs real-time analysis on the multi-modal sensor data according to a preset abnormal threshold to detect and respond to single-point abnormal events of the box; the edge computing unit performs local primary feature extraction on the multi-modal sensor data and uploads the extracted primary feature vectors to the fog computing node; the fog computing node performs high-level feature extraction and spatio-temporal correlation analysis on the primary feature vectors uploaded by all boxes in the regional network to identify whether there are group safety risk events; if so, the fog computing node dynamically adjusts the safety policy level of all boxes in the regional network to the highest level.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of financial security technologies, and in particular, to a security monitoring and management method and system for an intelligent box lock integrated box. Background Art

[0002] The transportation, scheduling, and storage of the box are extremely important links in the daily operations of banks, undertaking the key task of the safe circulation of funds. With the continuous development of financial business and the improvement of security management requirements, the traditional box transportation management method has gradually exposed problems such as opaque information, low scheduling efficiency, and high security risks. Against this background, the intelligent box lock integrated box, as a new type of financial security device, integrates advanced lock technologies and intelligent management systems, which can not only enhance the physical security of the box, but also realize the real-time monitoring and remote management of the box status through seamless connection with the online platform.

[0003] In the prior art, the security monitoring and management solution for intelligent boxes mainly relies on cloud computing for data processing, and the data needs to be transmitted from the intelligent box lock to the cloud for processing and the results are returned. However, this process is greatly affected by the network condition. When the network is unstable or congested, the delay increases, which easily leads to the inability of the security monitoring to respond in real time, and may miss the best processing opportunity, posing a greater security hazard. Summary of the Invention

[0004] This application provides a security monitoring and management method and system for an intelligent box lock integrated box, which is used to enhance the security protection ability of the intelligent box and eliminate potential security hazards.

[0005] In the first aspect of this application, a security monitoring and management method for an intelligent box lock integrated box is provided. The security monitoring method is applied to a target system, and the target system includes an edge computing unit deployed on the box and a fog computing node configured in the regional network. The method includes:

[0006] The edge computing unit obtains the multi-modal sensor data of the box in real time, and the multi-modal sensor data includes vibration data, temperature data, position data, biometric data, and unlocking status data;

[0007] The edge computing unit performs real-time analysis on the multi-modal sensor data according to a preset anomaly threshold, detects and responds to the single-point anomaly event of the box;

[0008] The edge computing unit performs local primary feature extraction on the multi-modal sensor data, and uploads the extracted primary feature vector to the fog computing node;

[0009] The fog computing node performs advanced feature extraction and spatio-temporal correlation analysis on the primary feature vectors uploaded by all the cash boxes within the regional network to identify whether there are group security risk events;

[0010] If there are, the fog computing node dynamically adjusts the security policy levels of all the cash boxes within the regional network to the highest level.

[0011] Optionally, the method further includes:

[0012] The edge computing unit determines the current usage scenario of the cash box according to the multimodal sensor data;

[0013] The edge computing unit performs real-time analysis on the multimodal sensor data according to a preset anomaly threshold to detect and respond to the single-point anomaly events of the cash box, including:

[0014] The edge computing unit dynamically determines the preset anomaly threshold according to the usage scenario, and performs real-time analysis on the multimodal sensor data according to the preset anomaly threshold to detect and respond to the single-point anomaly events of the cash box.

[0015] Optionally, the edge computing unit performs local primary feature extraction on the multimodal sensor data and uploads the extracted primary feature vectors to the fog computing node, including:

[0016] The edge computing unit calls a predefined attention strategy according to the usage scenario to assign target weights to the multimodal sensor data, and performs weighted processing on the multimodal sensor data based on the target weights;

[0017] The edge computing unit performs local primary feature extraction on the weighted multimodal sensor data and uploads the extracted primary feature vectors to the fog computing node.

[0018] Optionally, the fog computing node performs advanced feature extraction and spatio-temporal correlation analysis on the primary feature vectors uploaded by all the cash boxes within the regional network to identify whether there are group security risk events, including:

[0019] The fog computing node obtains a matching risk assessment model according to the usage scenario, and the risk assessment model is an artificial intelligence model trained based on historical data;

[0020] The fog computing node inputs the primary feature vectors uploaded by all the cash boxes within the regional network into the risk assessment model for advanced feature extraction and spatio-temporal correlation analysis to identify whether there are group security risk events under the usage scenario.

[0021] Optionally, the fog computing node obtains a matching risk assessment model according to the usage scenario, including:

[0022] The fog computing node obtains a matching risk assessment model from a pre-trained scenario-based model library according to the usage scenario and the primary feature vector. The scenario-based model library includes a shared basic model with a residual time series convolutional network as the backbone network and at least two lightweight scenario-specific branch models. The risk assessment model is obtained by combining the shared basic model and the scenario-specific branch models.

[0023] Optionally, after the fog computing node dynamically adjusts the security policy levels of all the boxes in the regional network to the highest level, the method further includes:

[0024] The fog computing node uploads the relevant data of the group security risk event to the cloud for analysis and verification, and maintains or restores the security policy levels of all the boxes in the regional network according to the instructions feedback by the cloud.

[0025] Optionally, the detecting and responding to the single-point abnormal event of the box includes:

[0026] If it is detected that the box has the single-point abnormal event, trigger the local alarm of the box and lock the physical unlocking function of the box.

[0027] The second aspect of the present application provides a security monitoring and management system for an intelligent box lock integrated box, including:

[0028] An edge computing unit deployed on the box and a fog computing node configured in the regional network;

[0029] The edge computing unit is used for:

[0030] Obtaining the multi-modal sensor data of the box in real time, where the multi-modal sensor data includes vibration data, temperature data, position data, biometric data, and unlocking state data; performing real-time analysis on the multi-modal sensor data according to a preset abnormal threshold, detecting and responding to the single-point abnormal event of the box; performing local primary feature extraction on the multi-modal sensor data, and uploading the extracted primary feature vector to the fog computing node;

[0031] The fog computing node is used for:

[0032] Performing high-level feature extraction and spatio-temporal correlation analysis on the primary feature vectors uploaded by all the boxes in the regional network, and identifying whether there is a group security risk event; if so, dynamically adjusting the security policy levels of all the boxes in the regional network to the highest level.

[0033] Optionally, the edge computing unit is specifically configured to:

[0034] Determine the current usage scenario of the money box according to the multimodal sensor data;

[0035] Dynamically determine a preset anomaly threshold according to the usage scenario, and perform real-time analysis on the multimodal sensor data according to the preset anomaly threshold to detect and respond to single-point anomaly events of the money box.

[0036] Optionally, the edge computing unit is further specifically configured to:

[0037] Call a predefined attention strategy according to the usage scenario to assign target weights to the multimodal sensor data, and perform weighted processing on the multimodal sensor data based on the target weights;

[0038] Perform local primary feature extraction on the weighted multimodal sensor data, and upload the extracted primary feature vectors to the fog computing node.

[0039] Optionally, the fog computing node is specifically configured to:

[0040] Obtain a matching risk assessment model according to the usage scenario, where the risk assessment model is an artificial intelligence model trained based on historical data;

[0041] Input the primary feature vectors uploaded by all the money boxes in the regional network into the risk assessment model for high-level feature extraction and spatio-temporal correlation analysis to identify whether there are group safety risk events in the usage scenario.

[0042] Optionally, the fog computing node is further specifically configured to:

[0043] Obtain a matching risk assessment model from a pre-trained scenario-based model library according to the usage scenario and the primary feature vectors. The scenario-based model library includes a shared basic model with a residual time series convolutional network as the backbone network and at least two lightweight scenario-specific branch models, and the risk assessment model is obtained by combining the shared basic model and the scenario-specific branch models.

[0044] Optionally, the fog computing node is further configured to:

[0045] Upload the relevant data of the group safety risk event to the cloud for analysis and verification, and maintain or restore the security policy level of all the money boxes in the regional network according to the instructions feedback from the cloud.

[0046] Optionally, the edge computing unit is further configured to:

[0047] If the single-point abnormal event is detected in the money box, the local alarm of the money box is triggered and the physical unlocking function of the money box is locked.

[0048] The third aspect of the present application provides a safety monitoring and management device for an intelligent box-lock integrated money box, and the device includes:

[0049] A processor, a memory, an input / output unit, and a bus;

[0050] The processor is connected to the memory, the input / output unit, and the bus;

[0051] The memory stores a program, and the processor calls the program to execute the safety monitoring and management method of an intelligent box-lock integrated money box according to the first aspect and any optional one in the first aspect.

[0052] The fourth aspect of the present application provides a computer-readable storage medium, and a program is stored on the computer-readable storage medium. When the program is executed on a computer, it executes the safety monitoring and management method of an intelligent box-lock integrated money box according to the first aspect and any optional one in the first aspect.

[0053] From the above technical solutions, it can be seen that the present application has the following advantages:

[0054] By adopting a multi-level architecture that combines edge computing and fog computing, the real-time perception of the safety status of the money box and the timely response to regional risks are realized. Specifically, by deploying an edge computing unit on the money box, the real-time analysis of multi-modal sensor data and the rapid response to single-point abnormal events are achieved, overcoming the security risks caused by network latency in traditional cloud computing solutions. At the same time, fog computing nodes are used for advanced feature extraction and spatio-temporal correlation analysis of money box data within the region, effectively identifying group safety risks and dynamically adjusting safety policies, so as to achieve more timely, comprehensive and efficient safety monitoring and management. The present application can not only respond to potential security threats in a timely manner, but also achieve regional collaborative defense, significantly enhancing the security protection ability of intelligent money boxes and eliminating potential security risks. Description of the Drawings

[0055] In order to more clearly illustrate the technical solutions in the present application, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0056] Figure 1 It is a schematic flowchart of an embodiment of a safety monitoring and management method for an intelligent box-lock integrated money box provided by the present application;

[0057] Figure 2 Another embodiment flowchart of the security monitoring and management method for an intelligent integrated box lock box provided by this application;

[0058] Figure 3 A schematic structural diagram of an embodiment of the security monitoring and management system for an intelligent integrated box lock box provided by this application;

[0059] Figure 4 A schematic structural diagram of an embodiment of the security monitoring and management device for an intelligent integrated box lock box provided by this application. Specific implementation manners

[0060] This application provides a security monitoring and management method and system for an intelligent integrated box lock box, which is used to enhance the security protection ability of the intelligent box and eliminate potential security hazards.

[0061] It should be noted that a security monitoring and management method for an intelligent integrated box lock box provided by this application is applied to a target system. The target system includes an edge computing unit deployed on the box and a fog computing node configured in the regional network. Among them, the edge computing unit specifically refers to a small computing device installed on each intelligent box, which can integrate sensors, processors, and communication modules. The fog computing node specifically refers to a computing entity deployed in the regional network (between the edge device and the cloud), which can be deployed in bank branches, warehousing centers, mobile vehicles, etc. according to the usage scenario of the box. Specifically, it is not limited here. The fog computing node can establish connections with multiple edge computing units simultaneously through the regional network. Since the fog computing node is closer to the edge device, the data transmission distance is shortened, and lower latency and higher bandwidth can be achieved, meeting the requirements of applications with high real-time requirements.

[0062] Please refer to Figure 1 , Figure 1 An embodiment of the security monitoring and management method for an intelligent integrated box lock box provided by this application, the method includes:

[0063] 101. The edge computing unit obtains the multi-modal sensor data of the box in real time. The multi-modal sensor data includes vibration data, temperature data, position data, biometric data, and unlocking state data;

[0064] In the field of security monitoring of intelligent boxes, traditional solutions usually rely on a single type of sensor (such as the state of a mechanical lock or a camera) for status detection and transmit it remotely to the cloud for analysis. However, in actual applications, the box may face various threats, such as violent damage, fire, illegal movement, unauthorized access, etc. A single sensor cannot cover all scenarios. In order to achieve real-time and comprehensive monitoring of the box status, multi-modal sensor technology is introduced and combined with edge computing to achieve local real-time data collection.

[0065] Specifically, the edge computing unit is integrated on the cash box and equipped with a variety of sensor modules, including but not limited to: vibration sensors, such as accelerometers (MEMS type); temperature sensors, such as thermistors or infrared temperature measurement modules; position sensors, such as GPS modules or inertial navigation units; biometric sensors, such as fingerprint recognizers or iris scanners; unlocking state sensors, such as Hall sensors or microswitches. The edge computing unit is connected to the above sensors through a hardware interface and controls the sensors to collect multi-modal sensor data at a fixed frequency (such as 10 times per second or adjusted according to the usage scenario).

[0066] The multi-modal sensor data specifically includes: vibration data of the cash box collected by the vibration sensor, which can be used to detect violent attack behaviors; temperature data of the environment around the cash box collected by the temperature sensor, which can be used to detect abnormal situations such as fires; geographical location data of the cash box collected by the GPS module, which can be used to track the position of the cash box to prevent loss or theft; biometric data of the operator collected by the biometric module, such as fingerprints or face images, which can be used to verify the identity of the operator; and status data of the cash box lock collected by the unlocking state sensor, which can be used to detect illegal unlocking behaviors.

[0067] 102. The edge computing unit performs real-time analysis on the multi-modal sensor data according to the preset anomaly threshold to detect and respond to single-point anomaly events of the cash box;

[0068] In traditional security monitoring, the analysis of sensor data often relies on cloud or central server processing, which has problems such as high latency and strong network dependence. Especially in scenarios such as financial cash boxes, insufficient real-time performance may lead to a lag in the response to security incidents and cause significant losses. To detect and respond to anomaly events in a timely manner, the local data processing ability of edge computing can be utilized to directly perform real-time anomaly analysis at the cash box device end. Specifically, dynamic or static anomaly thresholds can be set for each type of sensor data according to security requirements. The edge computing unit obtains the sensor data in real time and compares it with the preset threshold. When the sensor data of the cash box exceeds the preset threshold, the edge computing unit determines that a single-point anomaly event has occurred. At this time, according to the preset response strategy, a response can be made to the single-point anomaly event, such as issuing an alarm, etc.

[0069] In practical applications, a dynamic threshold adjustment strategy can be adopted, that is, the threshold is automatically adjusted according to historical data and real-time situations, and multiple anomaly thresholds can be set, such as a warning threshold and an alarm threshold, and different response strategies are adopted according to different anomaly thresholds. In addition, multiple sensor data can be combined for comprehensive judgment to reduce the impact of false alarms of a single sensor and improve the accuracy of single-point anomaly event detection. By quickly judging anomalies through preset anomaly thresholds and taking local measures, real-time performance and independence can be guaranteed. In this process, the edge computing unit is specifically implemented relying on a simple comparison algorithm to ensure low latency and low power consumption, providing the first layer of security protection for the cash box.

[0070] 103. The edge computing unit performs local primary feature extraction on multi-modal sensor data and uploads the extracted primary feature vectors to the fog computing node;

[0071] The amount of original sensor data is large, and directly uploading a large amount of original data will occupy bandwidth. Moreover, the fog computing node is connected to multiple cash boxes (edge computing units) at the same time. If each cash box transmits complete data, it will inevitably lead to a sharp increase in network load, and then cause delays or communication failures. Therefore, in this embodiment, while detecting and responding to single-point anomaly events of the cash box, the edge computing unit also needs to perform local primary feature extraction on the obtained multi-modal sensor data to generate primary feature vectors.

[0072] Specifically, the edge computing unit performs specific processing on multi-modal data such as vibration, temperature, position, biometric recognition, and unlocking status. For example, calculate the maximum value and frequency of vibration data, and the mean value and change rate of temperature data within a 1-second window. The edge computing unit combines the extracted various features into primary feature vectors, and then encrypts and uploads these primary feature vectors to the fog computing node through a lightweight communication protocol (such as MQTT).

[0073] 104. The fog computing node performs advanced feature extraction and spatio-temporal correlation analysis on the primary feature vectors uploaded by all cash boxes in the regional network to identify whether there are group security risk events;

[0074] The fog computing node receives the primary feature vectors uploaded by all the cash boxes connected within the regional network, and performs preprocessing operations such as data cleaning and format conversion. Thereafter, the primary feature vectors are deeply processed to extract more complex high-level feature vectors, and spatio-temporal correlation analysis is carried out. Among them, the primary feature vector is the basic data feature directly obtained from the data source (sensor), which is a simple transformation or extraction of the original data and reflects the basic attributes of the data. The high-level feature vector refers to the feature extracted after deeply processing the primary feature vector, which involves more complex combination and analysis of the primary feature vector. Spatio-temporal correlation analysis refers to analyzing the correlation of events in time and space, that is, combining the information of the two dimensions of time and space to analyze the high-level feature vector, and identifying the potential correlation between data, including the aggregation degree of similar events in time and space, the causal relationship between events, etc.

[0075] Since the fog computing node is connected to multiple cash boxes at the same time, it can deduce the possibility of group threats from these scattered anomalies. Specifically, the fog computing node evaluates whether there are group security risk events for all the cash boxes connected within the regional network according to the extracted high-level feature vectors and the spatio-temporal correlation therein. If the high-level feature vectors show that the abnormal characteristics of multiple cash boxes are similar, it indicates that there may be a common triggering factor. Spatio-temporal correlation analysis can further verify whether this similarity is concentrated in time and space. If so, the probability of group risk increases significantly.

[0076] For example, in the scenario of bank cash transportation, if the fog computing node analyzes and finds that multiple cash boxes within the regional network report similar abnormal trajectories and unauthorized unlocking attempts during the same period, it can be inferred that this may be a coordinated attack rather than an isolated event. If the evaluation result meets the preset conditions (such as the number of abnormal devices > 3 and the spatio-temporal correlation > 0.8), it is marked as a group security risk event, and step 105 is executed at this time.

[0077] 105. If there is such a situation, the fog computing node dynamically adjusts the security policy level of all the cash boxes within the regional network to the highest level.

[0078] If a group security risk event is identified in step 104, it indicates that the threat has spread from a single point to the regional level, and stronger protection measures are needed to contain the risk spread. At this time, the fog computing node dynamically adjusts the security policy level of all the cash boxes within the regional network to the highest level, that is, quickly improves the security protection level of all the cash boxes within the region and reduces potential losses. This highest security level involves more stringent verification and restriction measures (such as multi-factor authentication or locking function), that is, activates all the security measures of the cash box, so as to effectively resist further attacks and ensure the security of the cash box and its contents.

[0079] Although the highest level provides the strongest protection, its high resource consumption and strict restrictions will significantly affect normal operation and user convenience, and may misjudge normal events due to over-sensitivity. Through single-point abnormal event detection by the edge computing unit and group risk event assessment by the fog computing node, hierarchical response is achieved. The security policy level of all cash boxes in the area is only dynamically adjusted to the highest level when a group threat is confirmed. This approach not only avoids unnecessary resource waste but also ensures strong protection at critical moments.

[0080] In this embodiment, a multi-level architecture that combines edge computing and fog computing is adopted to achieve real-time perception of the security status of the cash box and timely response to regional risks. Specifically, by deploying edge computing units on the cash box, real-time analysis of multi-modal sensor data and rapid response to single-point abnormal events are realized, overcoming the security risks caused by network latency in traditional cloud computing solutions. At the same time, fog computing nodes are used for advanced feature extraction and spatio-temporal correlation analysis of cash box data within the area, effectively identifying group security risks and dynamically adjusting security policies, so as to achieve more timely, comprehensive and efficient security monitoring and management. This application can not only respond to potential security threats in a timely manner but also achieve regional collaborative defense, significantly enhancing the security protection ability of intelligent cash boxes and eliminating potential security risks.

[0081] The following will detail a security monitoring and management method for an intelligent box lock integrated cash box provided by this application. Please refer to Figure 2 , Figure 2 This is another embodiment of a security monitoring and management method for an intelligent box lock integrated cash box provided by this application. The method includes:

[0082] 201. The edge computing unit real-time obtains multi-modal sensor data of the cash box. The multi-modal sensor data includes vibration data, temperature data, location data, biometric data, and unlocking status data;

[0083] In this embodiment, step 201 is similar to step 101 in the foregoing embodiment, and will not be elaborated here.

[0084] 202. The edge computing unit determines the current usage scenario of the cash box according to the multi-modal sensor data;

[0085] In this embodiment, considering that the cash box has different requirements and focuses on security monitoring in different usage scenarios, such as warehousing scenarios, transportation scenarios, handover scenarios, etc. For example, temperature and vibration anomalies need to be concerned in the warehousing scenario, location deviation needs to be monitored in the transportation scenario, and biometric identification needs to be verified in the handover scenario. Therefore, before detecting single-point abnormal events, the edge computing unit can determine the current usage scenario of the cash box according to the multi-modal sensor data, so as to combine the focuses of different usage scenarios in subsequent steps for security monitoring and management.

[0086] Different usage scenarios correspond to specific sensor data patterns. For example, in the warehousing scenario, the cash box is stationary, with a fixed position, small vibration and temperature changes, and few unlocking times. In the transportation scenario, the cash box is moving, with a continuously changing position, frequent vibration, and possible temperature fluctuations. In the handover scenario, the cash box is briefly stationary, with frequent biometric recognition and unlocking events, and the position may be slightly adjusted. The edge computing unit can analyze the multi-modal data obtained in real time, extract scene features, and match the usage scenario using rules or simple classification models. In addition, the fog computing node can also uniformly specify the usage scenario of the cash box in a pre-determined area in advance.

[0087] 203. The edge computing unit dynamically determines a preset anomaly threshold according to the usage scenario, and performs real-time analysis on the multi-modal sensor data according to the preset anomaly threshold to detect and respond to single-point anomaly events of the cash box;

[0088] In different usage scenarios, the normal range of sensor data may be different, so the criteria for the preset anomaly threshold should also be different. For example, high vibration during transportation may be normal, but it may be a dangerous signal in warehousing. The edge computing unit dynamically adjusts the threshold according to the current usage scenario of the cash box, determines the preset anomaly threshold matching the usage scenario, and then compares the obtained multi-modal sensor data with the corresponding preset anomaly threshold to detect and respond to single-point anomaly events of the cash box, so as to improve the accuracy and robustness of single-point anomaly event detection.

[0089] In some specific embodiments, if a single-point anomaly event of the cash box is detected, the local alarm of the cash box is triggered and the physical unlocking function of the cash box is locked. That is, an alarm is issued through an audible and visual alarm at the local of the cash box, and the cash box is prevented from being opened by a physical key or manually in a mechanical or electronic manner to prevent illegal opening. After locking the physical unlocking function of the cash box, a corresponding unlocking mechanism needs to be provided, such as opening the cash box through an authorized remote instruction or a specific unlocking password.

[0090] 204. The edge computing unit calls a predefined attention strategy according to the usage scenario to assign target weights to the multi-modal sensor data, and performs weighted processing on the multi-modal sensor data based on the target weights;

[0091] 205. The edge computing unit performs local primary feature extraction on the weighted multi-modal sensor data, and uploads the extracted primary feature vectors to the fog computing node;

[0092] In the primary feature extraction stage, the influence of the usage environment can also be introduced. That is, the attention strategies for each usage scenario can be predefined. In the attention strategies, different weights are assigned to the multimodal sensor data under different usage scenarios, and the sum of the weights is 1, reflecting the relative importance of the data of each modal sensor. The edge computing unit then calls the corresponding attention strategy according to the usage scenario, assigns target weights to the multimodal sensor data and performs weighted processing, including multiplying each sensor data by the corresponding target weight value, so as to significantly improve the attention to key data. Subsequently, primary feature extraction is carried out and uploaded to the fog computing node.

[0093] Due to the limited resources of the edge computing unit, weighted processing avoids excessive analysis of low-priority data and reduces the computational overhead. Moreover, the weighted multimodal sensor data can better reflect the scene-specific anomalies, making the results of primary feature extraction more representative and facilitating the subsequent analysis of the fog computing node.

[0094] 206. The fog computing node obtains a matching risk assessment model according to the usage scenario. The risk assessment model is an artificial intelligence model trained based on historical data;

[0095] Under different usage scenarios, the risk factors and risk levels may vary. For example, during transportation, the money box is more likely to be stolen or violently attacked; while during storage, the money box is more vulnerable to natural disasters such as fires or floods. Therefore, according to the usage scenario of the money box, the corresponding artificial intelligence risk assessment model can be trained in combination with historical data, the trained artificial intelligence risk assessment model is stored in the fog computing node, and classified according to the usage scenario. The fog computing node then calls the corresponding artificial intelligence risk assessment model from the storage according to the current usage scenario of the money box to perform the subsequent steps.

[0096] Considering that when there are many usage scenarios, directly training independent and complete artificial intelligence risk assessment models for different usage scenarios will cause resource waste and may have weak generalization ability. Therefore, in some specific embodiments, a solution of forming a scene-based model library based on a shared basic model and a scenario-specific branch model is proposed, that is, the fog computing node obtains a matching risk assessment model from the pre-trained scene-based model library according to the usage scenario and the primary feature vector.

[0097] Specifically, the scenario-based model library contains a shared base model (extracting general features such as time series patterns) and multiple scenario-specific branch models (for warehousing, transportation, and handover). Among them, the shared base model adopts a multi-task pre-training framework and is trained based on the common features of all scenarios in historical data (such as vibration spectrum baseline, GPS trajectory smoothness). Specifically, the shared base model uses a Residual Temporal Convolutional Network (ResTCN) as the backbone network, which can contain 5 residual blocks, each consisting of 1D convolution, BatchNorm, and ReLU, for extracting general spatio-temporal features across scenarios. The shared base model only needs to be trained once and can be reused by multiple scenario-specific branch models. Each scenario-specific branch model contains a lightweight adaptation layer (such as a 2-layer fully connected network), with the input being the high-level features output by the shared model and the output being the probability of a group safety risk event occurring.

[0098] It should be noted that during the training phase of the scenario-specific branch model, the weights of the shared base model need to be fixed, and only the parameters of the branch model are updated to prevent catastrophic forgetting. The specific division of the training data for the scenario-specific branch model can be as follows:

[0099] Transportation branch: Data on the vibration, acceleration, and route deviation of the money box during historical transportation.

[0100] Warehousing branch: Warehouse temperature and humidity, access control switch records.

[0101] Handover branch: Face recognition matching rate at the handover point, geographical location compliance, time window compliance.

[0102] When performing the matching of the risk assessment branch model, the fog node receives the labels and primary feature vectors of the usage scenarios uploaded by the money box, maps them to scenario meta-feature vectors through a pre-trained meta-feature encoder, and then performs similarity matching between the generated scenario meta-features and the meta-features of each branch model registered in the scenario-based model library. If the highest similarity ≥ 0.85, it is determined as a high-confidence match, and the corresponding branch model can be directly loaded at this time; if the similarity is between 0.6 and 0.85, the closest branch is loaded and lightweight fine-tuning is triggered. Specifically, operations such as contrast regularization and dynamic pruning can be performed, that is, when there are partial feature offsets between the current usage scenario and the pre-trained branch, the model performance can be rapidly improved with limited resources through local parameter adjustment.

[0103] In step 206, the fog computing node utilizes an artificial intelligence (AI) model to evaluate the security risks under different usage scenarios (such as transportation, warehousing, and handover) by analyzing the data from the money box sensors (such as vibration, temperature, location, etc.). These AI models are trained based on historical data and can extract key information and identify potential group security risk events, such as theft or fire. By learning the patterns in historical data, AI can predict possible problems. For example, in the transportation scenario, abnormal vibration may imply a theft risk; in the warehousing scenario, too high temperature may indicate a fire hazard. Such a design enables AI to quickly determine whether there is a security threat to the money box based on real-time data and scenario characteristics, thereby enhancing security.

[0104] The design of the AI model is divided into two core parts: a shared basic model and a scenario-specific branch model. The shared basic model is a general feature extraction tool, trained based on the historical data of all scenarios, and uses a residual temporal convolutional network (ResTCN) to analyze the common features of time and space data, such as vibration patterns or location change trends. This model is trained only once and can be reused for all scenarios, thus saving computing resources. The scenario-specific branch model, on the other hand, conducts refined analysis for specific scenarios, calculates specific risk probabilities using the advanced features extracted by the shared model. Each scenario is equipped with a small neural network (usually two layers), and only the data related to that scenario is trained. For example, the transportation scenario focuses on vibration and route deviation, the warehousing scenario focuses on temperature and humidity changes, and the handover scenario focuses on the compliance of time and location. During training, the weights of the shared model remain fixed, and only the parameters of the branch model are adjusted, which is both efficient and does not interfere with the stability of the general features.

[0105] In practical applications, the fog computing node intelligently matches and adjusts the model according to the current scenario information. Specifically, when the similarity between the scenario features and the pre-trained model is ≥ 0.85, the matching branch model is directly called for risk assessment; when the similarity is between 0.6 and 0.85, the closest model is loaded and fine-tuned by slightly adjusting the parameters to adapt to the current scenario. This method takes into account both speed and accuracy, and at the same time has the flexibility to handle new scenarios. Through the combined design of "general core + dedicated branch", the AI model can intelligently select the appropriate analysis strategy according to the scenario requirements, accurately predict the security risks of the money box, and effectively ensure its security in transportation, warehousing, and handover and other links.

[0106] 207. The fog computing node inputs the primary feature vectors uploaded by all the money boxes within the regional network into the risk assessment model for advanced feature extraction and spatio-temporal correlation analysis to identify whether there are group security risk events under the usage scenario;

[0107] The fog computing node inputs the primary feature vectors uploaded by all the money boxes within the regional network into the risk assessment model. The risk assessment model not only performs general feature extraction but also extracts more discriminative features according to its training objective, i.e., risk identification in specific usage scenarios. For example, in the transportation scenario, the model may pay more attention to feature combinations related to theft or violent attacks, such as continuous abnormal vibration patterns within a specific time period and the deviation of the money box from the predetermined route as indicated by the location information. The spatio-temporal correlation analysis is also carried out based on the knowledge of the risk assessment model, and the model will consider the potential security risks in specific scenarios. For example, in the warehousing scenario, it focuses on abnormalities in environmental factors such as temperature and humidity and judges the relevance to risks such as fire; in the transportation scenario, it focuses on the situation of deviating from the predetermined route and analyzes the relevance to theft risks. Using a risk assessment model matching the specific usage scenario can targetedly extract high-level features and perform spatio-temporal correlation analysis, thereby more accurately identifying group security risk events.

[0108] For the solution of the scenario-based model library, in some specific embodiments, the fog computing node first performs high-level feature extraction on the primary feature vectors through a shared basic model to extract general spatio-temporal features, which may specifically include statistical feature vectors, temporal feature vectors, and spatial feature vectors. Then, the high-level features output by the shared basic model are input into an exclusive branch model matching the current usage scenario for spatio-temporal correlation analysis, and a group correlation index is output. The group correlation index specifically includes:

[0109] 1. The spatio-temporal aggregation degree index, which is used to measure the aggregation degree of multiple money boxes in time and space. By analyzing the time series features (such as periodicity and volatility) and spatial distribution features (such as density and position correlation) of the data, it is judged whether there is an abnormal aggregation phenomenon.

[0110] 2. The causal chain strength index, which is used to evaluate whether there is a causal relationship between multiple money boxes. For example, whether the state change of a certain money box triggers a chain reaction of other money boxes.

[0111] 3. The similarity index, which is used to measure the similarity of the behavior patterns of multiple money boxes, such as the consistency of features such as transportation routes and operation frequencies.

[0112] Finally, based on these group correlation indexes, it can be comprehensively judged whether there is a group security risk event in the current usage scenario.

[0113] 208. If so, the fog computing node dynamically adjusts the security policy level of all the money boxes within the regional network to the highest level;

[0114] In this embodiment, step 208 is similar to step 105 in the foregoing embodiment and will not be elaborated here.

[0115] 209. The fog computing node uploads the relevant data of the group security risk event to the cloud for analysis and verification, and maintains or restores the security policy level of all cash boxes in the regional network according to the instructions feedback from the cloud.

[0116] Although the fog computing node can initially identify group security risk events, there may be misjudgments. The cloud usually has more powerful computing and storage capabilities and can perform more complex data analysis and decision-making. Therefore, the fog computing node can upload the relevant data of the group security risk event to the cloud for further analysis and verification. The cloud can obtain more comprehensive data information, such as the security situation in other regions, the latest security threat intelligence, etc., so as to more accurately evaluate the group security risk event. According to the results of the analysis and verification, the cloud issues instructions to the fog computing node. The types of instructions include: maintaining the security policy level: confirming the existence of a group security risk event and maintaining the current security policy level (the highest level); restoring the security policy level: confirming the non-existence of a group security risk event or the risk has been lifted, and restoring the security policy level to the previous state. After receiving the instruction, the fog computing node adjusts the security policy level of all cash boxes in the regional network according to the instruction requirements to prevent resource waste caused by overprotection.

[0117] In this embodiment, by deploying an edge computing unit on the cash box, real-time analysis of multi-modal sensor data and rapid response to single-point abnormal events are realized, overcoming the security risks caused by network latency in traditional cloud computing solutions. The edge computing unit can dynamically determine the preset abnormal threshold according to the current usage scenario of the cash box, and perform real-time analysis on the multi-modal sensor data accordingly, improving the accuracy and robustness of single-point abnormal event detection. At the same time, the edge computing unit can also call the predefined attention strategy according to the usage scenario to assign target weights to the multi-modal sensor data, and perform weighted processing on the multi-modal sensor data based on the target weights, avoiding over-analysis of low-priority data, reducing the computational overhead, making the primary feature extraction result more representative, and facilitating the subsequent analysis of the fog computing node. The fog computing node is used for high-level feature extraction and spatio-temporal correlation analysis of the cash box data in the region, effectively identifying group security risks, and dynamically adjusting the security policy, so as to achieve more timely, comprehensive and efficient security monitoring and management. The fog computing node can obtain a matching risk assessment model according to the usage scenario, so as to more accurately identify group security risk events. This embodiment can not only respond to potential security threats in a timely manner, but also achieve regional collaborative defense, significantly enhancing the security protection ability of the intelligent cash box and eliminating potential security risks.

[0118] The following will provide a detailed description of a security monitoring and management system for an intelligent lock-integrated cash box provided by the present application. Please refer to Figure 3 , Figure 3Another embodiment of the security monitoring and management system for an intelligent box lock integrated box provided by this application, the system includes:

[0119] An edge computing unit 301 deployed on the box and a fog computing node 302 configured within the regional network;

[0120] The edge computing unit 301 is used for:

[0121] Obtain multi-modal sensor data of the box in real time, where the multi-modal sensor data includes vibration data, temperature data, location data, biometric data, and unlocking status data; perform real-time analysis on the multi-modal sensor data according to a preset anomaly threshold, detect and respond to single-point anomaly events of the box; perform local primary feature extraction on the multi-modal sensor data, and upload the extracted primary feature vectors to the fog computing node 302;

[0122] The fog computing node 302 is used for:

[0123] Perform high-level feature extraction and spatio-temporal correlation analysis on the primary feature vectors uploaded by all boxes within the regional network, and identify whether there are group security risk events; if so, dynamically adjust the security policy level of all boxes within the regional network to the highest level.

[0124] Optionally, the edge computing unit 301 is specifically used for:

[0125] Determine the current usage scenario of the box according to the multi-modal sensor data;

[0126] Dynamically determine the preset anomaly threshold according to the usage scenario, and perform real-time analysis on the multi-modal sensor data according to the preset anomaly threshold, detect and respond to single-point anomaly events of the box.

[0127] Optionally, the edge computing unit 301 is specifically further used for:

[0128] Call a predefined attention policy according to the usage scenario to assign target weights to the multi-modal sensor data, and perform weighted processing on the multi-modal sensor data based on the target weights;

[0129] Perform local primary feature extraction on the weighted multi-modal sensor data, and upload the extracted primary feature vectors to the fog computing node 302.

[0130] Optionally, the fog computing node 302 is specifically used for:

[0131] Obtain a matching risk assessment model according to the usage scenario, where the risk assessment model is an artificial intelligence model trained based on historical data;

[0132] Input the primary feature vectors uploaded by all the money safes within the regional network into a risk assessment model for advanced feature extraction and spatio-temporal correlation analysis to identify whether there are group security risk events in the usage scenario.

[0133] Optionally, the fog computing node 302 is further configured to:

[0134] According to the usage scenario and the primary feature vectors, obtain a matching risk assessment model from a pre-trained scenario-based model library. The scenario-based model library includes a shared basic model with a residual temporal convolutional network as the backbone network and at least two lightweight scenario-specific branch models. The risk assessment model is obtained by combining the shared basic model and the scenario-specific branch models.

[0135] Optionally, the fog computing node 302 is further configured to:

[0136] Upload the relevant data of the group security risk event to the cloud for analysis and verification, and maintain or restore the security policy level of all the money safes within the regional network according to the instructions feedback from the cloud.

[0137] Optionally, the edge computing unit 301 is further configured to:

[0138] If a single-point anomaly event is detected in the money safe, trigger the local alarm of the money safe and lock the physical unlocking function of the money safe.

[0139] In the system of this embodiment, the functions of each unit correspond to the steps in the foregoing Figure 1 or Figure 2 The method embodiment shown, which will not be elaborated here.

[0140] This application also provides a security monitoring and management device for an intelligent box lock integrated money safe. Please refer to Figure 4 , Figure 4 As shown in an embodiment of a security monitoring and management device for an intelligent box lock integrated money safe provided by this application. The device includes:

[0141] A processor 401, a memory 402, an input / output unit 403, and a bus 404;

[0142] The processor 401 is connected to the memory 402, the input / output unit 403, and the bus 404;

[0143] The memory 402 stores a program, and the processor 401 calls the program to execute any one of the security monitoring and management methods for an intelligent box lock integrated money safe as described above.

[0144] This application also relates to a computer-readable storage medium. A program is stored on the computer-readable storage medium. When the program runs on a computer, the computer is enabled to execute any one of the security monitoring and management methods for an intelligent box lock integrated money safe as described above.

[0145] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0146] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.

[0147] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0148] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.

[0149] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, and other media that can store program codes.

Claims

1. A safety monitoring and management method for an intelligent box with an integrated lock, characterized in that, The described security monitoring and management method is applied to a target system, which includes an edge computing unit deployed on a cash box and a fog computing node configured within a regional network. The method includes: The edge computing unit real-time obtains multimodal sensor data of the cash box, and the multimodal sensor data includes vibration data, temperature data, location data, biometric data, and unlocking status data; The edge computing unit determines the current usage scenario of the cash box according to the multimodal sensor data; The edge computing unit dynamically determines a preset anomaly threshold according to the usage scenario, and performs real-time analysis on the multimodal sensor data according to the preset anomaly threshold to detect and respond to single-point anomaly events of the cash box; The edge computing unit performs local primary feature extraction on the multimodal sensor data and uploads the extracted primary feature vectors to the fog computing node; The fog computing node obtains a matching risk assessment model according to the usage scenario, and the risk assessment model is an artificial intelligence model trained based on historical data; The fog computing node inputs the primary feature vectors uploaded by all cash boxes within the regional network into the risk assessment model for high-level feature extraction and spatio-temporal correlation analysis to identify whether there are group security risk events in the usage scenario; If so, the fog computing node dynamically adjusts the security policy levels of all cash boxes within the regional network to the highest level.

2. The safety monitoring and management method according to claim 1, characterized in that The edge computing unit performs local primary feature extraction on the multimodal sensor data and uploads the extracted primary feature vectors to the fog computing node, including: The edge computing unit calls a predefined attention strategy according to the usage scenario to assign target weights to the multimodal sensor data, and performs weighted processing on the multimodal sensor data based on the target weights; The edge computing unit performs local primary feature extraction on the weighted multimodal sensor data and uploads the extracted primary feature vectors to the fog computing node.

3. The security monitoring and management method according to claim 1, characterized in that The fog computing node obtains a matching risk assessment model according to the usage scenario, including: The fog computing node obtains a matching risk assessment model from a pre-trained scenario-based model library according to the usage scenario and primary feature vectors. The scenario-based model library contains a shared basic model with a residual time series convolutional network as the backbone network and at least two lightweight scenario-specific branch models. The risk assessment model is obtained by combining the shared basic model and the scenario-specific branch models.

4. The security monitoring and management method according to claim 1, characterized in that, After the fog computing node dynamically adjusts the security policy levels of all cash boxes within the regional network to the highest level, the method further includes: The fog computing node uploads the relevant data of the group security risk event to the cloud for analysis and verification, and maintains or restores the security policy levels of all cash boxes within the regional network according to the instructions feedback from the cloud.

5. The safety monitoring and management method according to any one of claims 1 to 4, characterized in that, The detecting and responding to single-point anomaly events of the cash box includes: If the single-point abnormal event is detected in the cash box, the local alarm of the cash box is triggered and the physical unlocking function of the cash box is locked.

6. A safety monitoring and management system for an intelligent box with an integrated lock, characterized in that, The security monitoring and management system includes an edge computing unit deployed on the cash box and a fog computing node configured in the regional network; The edge computing unit is used for: Obtaining the multi-modal sensor data of the cash box in real time, where the multi-modal sensor data includes vibration data, temperature data, position data, biometric data, and unlocking status data; determining the current usage scenario of the cash box according to the multi-modal sensor data; dynamically determining a preset abnormal threshold according to the usage scenario, and performing real-time analysis on the multi-modal sensor data according to the preset abnormal threshold to detect and respond to the single-point abnormal event of the cash box; performing local primary feature extraction on the multi-modal sensor data, and uploading the extracted primary feature vectors to the fog computing node; The fog computing node is used for: Obtaining a matching risk assessment model according to the usage scenario, where the risk assessment model is an artificial intelligence model trained based on historical data; inputting the primary feature vectors uploaded by all the cash boxes in the regional network into the risk assessment model for advanced feature extraction and spatio-temporal correlation analysis to identify whether there is a group security risk event in the usage scenario; if so, dynamically adjusting the security policy level of all the cash boxes in the regional network to the highest level.

7. An intelligent box lock integrated box security monitoring and management device, characterized in that, The security monitoring and management device includes: A processor, a memory, an input / output unit, and a bus; The processor is connected to the memory, the input / output unit, and the bus; The memory stores a program, and the processor calls the program to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, A program is stored on the computer-readable storage medium, and when the program is executed on a computer, it executes the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Security data storage and computing method based on Internet of Things fog computing-edge computing

    CN110213036A

  • Real-time monitoring platform based on financial information abnormal state

    CN116506304A