Intelligent portable WiFi traffic monitoring method and system based on 5G
By setting up traffic statistics modules and edge computing nodes in 5G smart portable WiFi devices for streaming processing, combined with distributed deep learning model and blockchain technology, the problem of insufficient efficiency and security of intelligent portable WiFi traffic monitoring in the existing technology is solved, and efficient, intelligent and secure traffic monitoring and management is achieved.
Patent Information
- Application Number
- CN202510252054.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-03-05
AI Technical Summary
The existing intelligent portable WiFi traffic monitoring methods do not perform well in monitoring efficiency, security and resource utilization, and it is difficult to effectively monitor and manage the traffic of 5G portable WiFi devices.
A 5G-based intelligent portable WiFi traffic monitoring method is proposed. By setting up a traffic statistics module in a 5G intelligent portable WiFi device, data packets are captured in real time using an adaptive sampling rate mechanism, and streaming, data compression and standardization are performed on edge computing nodes to generate a subset of traffic data. Use distributed deep learning models to identify traffic, real-time early warning and hierarchical traffic control, and combine blockchain and quantum encryption technology to ensure data security and tamper-free.
It improves the efficiency and resource utilization of traffic monitoring, enhances the intelligence and security of the system, realizes real-time abnormal traffic detection and early warning, and ensures the security and integrity of the data.
Smart Images

Figure CN120075872A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of 5G technology, and particularly to an intelligent portable WiFi traffic monitoring method and system based on 5G. Background Art
[0002] Intelligent portable WiFi devices based on 5G have gradually become popular in recent years, providing users with a more convenient and high-speed network experience. The 5G-based portable WiFi devices can provide faster data transmission speeds than traditional 4G devices. The theoretical downlink rate can reach 10 Gbps, and generally several hundred Mbps or even higher in actual use, easily supporting high-definition video playback, 4K live broadcast, and large file downloads. These devices are usually designed to be lightweight and convenient to carry, without the need for installation and wiring, and can provide WiFi signals anytime and anywhere. Many 5G portable WiFi devices support large data packages, with a monthly data volume of up to 1500G or even more, meeting the long-term and large-data usage needs of users. Most devices can connect multiple devices simultaneously, usually about 32, meeting the needs of multiple people or multiple devices to access the Internet at the same time. The above characteristics of 5G portable WiFi devices also lead to the problem of easy traffic anomalies. The existing intelligent portable WiFi traffic monitoring methods do not perform well in terms of monitoring efficiency and security guarantee, and there is an urgent need for improvement. Summary of the Invention
[0003] Based on the above problems, the present invention proposes an intelligent portable WiFi traffic monitoring method and system based on 5G. Through the solution of the present invention, not only the monitoring efficiency and resource utilization rate are improved, but also the intelligence and security are enhanced.
[0004] In view of this, one aspect of the present invention proposes an intelligent portable WiFi traffic monitoring method based on 5G, including: Using a traffic statistics module set in the chipset of the first 5G intelligent portable WiFi device to capture data packets in real time by means of an adaptive sampling rate mechanism; wherein, the adaptive sampling rate mechanism dynamically adjusts the data packet capture frequency according to the network load status and traffic characteristics; When the data packet flows through the key nodes of the kernel protocol stack, extracting traffic data including timestamp, source and destination IP addresses, port numbers, protocol types, and data volume size; Transmitting the traffic data to an edge computing node deployed locally on the first 5G intelligent portable WiFi device; Using a streaming processing framework to perform real-time cleaning on the traffic data, removing duplicate, incorrect, and invalid traffic records, compressing and storing the cleaned traffic data using a data compression algorithm, and performing standardization processing on the compressed traffic data according to a preset classification rule to generate a traffic data subset; Obtain a traffic recognition result based on the subset of traffic data and a preset first traffic recognition model; When abnormal traffic is recognized, send a warning message through multiple user interfaces associated with the device, and at the same time activate the hierarchical traffic control mechanism built into the first 5G smart portable WiFi device to restrict or block the abnormal traffic; Extract the abnormal traffic characteristics and feedback them to the first traffic recognition model for model optimization; Allocate an independent network slice for traffic monitoring to achieve service isolation, and automatically adjust the slice configuration parameters based on a smart contract; Implement traffic data intercommunication between different operators through a cross-chain interoperability mechanism; Encrypt the traffic data, the traffic recognition result, and the warning record through quantum encryption technology, and use distributed ledger technology to package the encrypted data into blocks to build a blockchain ledger containing timestamps to achieve data anti-tampering; Collect the environmental data of surrounding Internet of Things devices, integrate the environmental data and traffic data for comprehensive analysis, and dynamically adjust the traffic allocation strategy based on the analysis results.
[0005] Optionally, the step of using an adaptive sampling rate mechanism to capture data packets in real time through a traffic statistics module set in the chipset of the first 5G smart portable WiFi device includes: Initialization configuration steps, including: setting a traffic statistics module in the chipset of the first 5G smart portable WiFi device; configuring initial sampling rate parameters in the traffic statistics module, including a reference sampling interval and a sampling window size; setting traffic thresholds, including a high-load threshold and a low-load threshold; initializing a sampling rate adjustment factor and an adjustment step size; Network status monitoring steps, including: monitoring the network interface status of the first 5G smart portable WiFi device in real time; obtaining the current network bandwidth utilization rate; detecting the length of the data packet queue; recording the network delay and packet loss rate; Load evaluation steps, including: calculating the network load index within the current time window; comparing the calculated load index with a preset threshold; determining whether the current network status belongs to high load, normal load, or low load; generating a load evaluation result; Sampling rate adaptive adjustment steps, including: dynamically calculating the optimal sampling rate according to the load evaluation result; when the load is higher than the high-load threshold, appropriately reduce the sampling rate to relieve the system pressure; when the load is lower than the low-load threshold, increase the sampling rate to obtain more detailed traffic information; ensure that the sampling rate adjustment is within the preset maximum and minimum ranges; Packet capture steps, including: setting a packet filter at the network interface driver layer; sampling the passing packets according to the current sampling rate; extracting the header information of the sampled packets; recording the timestamp information of the packets; Sampling optimization steps, including: adopting a differentiated sampling strategy for different types of network protocols; increasing the sampling priority for critical business traffic; adopting a predictive sampling mechanism for periodic traffic; dynamically adjusting the sampling window size; Resource monitoring steps, including: monitoring the CPU usage rate of the traffic statistics module; monitoring the memory buffer occupancy; triggering a protection mechanism when the system resources are close to the threshold; automatically adjusting the sampling parameters to balance the system load; Sampling quality assessment steps, including: calculating the representative indicators of the sampled data; evaluating the accuracy of the sampling results; analyzing the sampling bias; generating a sampling quality report.
[0006] Optionally, the step of performing real-time cleaning on the traffic data using a streaming processing framework, removing duplicate, error, and invalid traffic records, compressing and storing the cleaned traffic data using a data compression algorithm, and standardizing the compressed traffic data according to a preset classification rule to generate a traffic data subset includes: Streaming processing environment initialization steps, including: deploying a streaming processing framework at the edge computing node; configuring the data stream inlet and outlet nodes; setting the parallelism parameter of the data processing pipeline; initializing the data buffer and processing queue; Data stream access steps, including: establishing a data transmission channel with the traffic statistics module; sharding the received traffic data and adding it to the processing queue; assigning a unique identifier to each data shard; recording the data access timestamp; Real-time cleaning steps, including: detecting and deleting duplicate packet records: calculating the packet feature hash value, using a sliding time window for duplicate determination, and retaining the earliest valid record; identifying and filtering error data: verifying the packet integrity, validating the protocol field legality, and checking the address format validity; removing invalid traffic records: filtering out timeout packets, deleting incomplete session records, and removing data with abnormal lengths; Data compression steps, including: classifying and packing the cleaned data: grouping by protocol type, batch processing according to the time series, and establishing a data index structure; performing multi-level compression processing: first performing field-level compression, then block-level compression, and finally applying global compression; generating compression metadata: recording the compression algorithm parameters, saving the information required for decompression, and establishing a compressed data index; Standardization processing steps, including: performing data format unification: unifying the timestamp format, standardizing the address representation, and normalizing the protocol identifier; performing numerical normalization: calculating the statistical values of traffic characteristics, performing min-max normalization, and applying Z-score standardization; establishing a standardization mapping table: recording conversion parameters, saving the normalization range, and maintaining the feature mapping relationship; Flow data subset generation steps, including: classifying data according to preset rules: dividing based on the time dimension, grouping according to the protocol type, and clustering according to business characteristics; constructing a data subset index: creating a multi-dimensional index structure, establishing a fast retrieval table, and generating subset association relationships; optimizing the subset storage structure: implementing an incremental update mechanism, designing a caching strategy, and constructing a hierarchical storage structure; Quality control steps, including: monitoring the processing quality in real time: tracking the data loss rate, monitoring the processing delay, and evaluating the compression efficiency; performing exception handling: detecting processing exceptions, triggering a recovery mechanism, and recording exception logs; generating a quality report: counting processing metrics, analyzing performance bottlenecks, and providing optimization suggestions.
[0007] Optionally, the method for constructing the first traffic recognition model includes: Model initialization steps, including: initializing the global model architecture on the central server side, including a convolutional neural network module and a recurrent neural network module; the convolutional neural network module is used to extract the spatial features of traffic data, including multiple convolutional layers, pooling layers, and fully connected layers; the recurrent neural network module is used to extract the temporal features of traffic data, including LSTM or GRU units; distributing the initialized global model parameters to each 5G smart portable WiFi device participating in the training; Local training steps, including: each 5G smart portable WiFi device performing model training based on the local traffic data set; using batch normalization to process local data to eliminate the data distribution differences between devices; using differential privacy mechanism to protect privacy during the training process; calculating the gradient update value of the local model parameters; Parameter aggregation steps, including: each 5G smart portable WiFi device encrypting and transmitting the calculated gradient update value to the central server; the central server aggregating the gradient update values of all devices using a weighted average algorithm; updating the global model parameters; distributing the updated global model parameters to each participating device; Model optimization steps, including: setting a dynamic learning rate adjustment mechanism to adaptively adjust the learning rate according to the training progress; introducing an early stopping mechanism to stop training when the model performance no longer improves significantly; using Dropout technology to prevent model overfitting; using residual connections to optimize gradient propagation; Model evaluation steps, including: evaluating the model performance on the validation dataset; calculating evaluation metrics such as accuracy, recall, and F1-score; generating a confusion matrix to analyze the model prediction effect; deciding whether to continue training based on the evaluation results; obtaining the first traffic recognition model; Anomaly detection steps, including: inputting real-time traffic data into the trained model; extracting spatial features through a convolutional neural network; analyzing temporal patterns through a recurrent neural network; fusing the two types of features to determine abnormal traffic; Model deployment steps, including: converting the trained model into a lightweight format; deploying it to each 5G smart portable WiFi device; configuring model inference parameters; starting the online anomaly detection service.
[0008] Optionally, the step of, when abnormal traffic is identified, sending a warning message through multiple user interfaces associated with the device, and at the same time activating the hierarchical traffic control mechanism built into the first 5G smart portable WiFi device to restrict or block the abnormal traffic, includes: Abnormal traffic feature extraction steps, including: obtaining the abnormal traffic data identified by the deep learning model; extracting key feature parameters of the abnormal traffic: traffic surge amplitude and duration, number of abnormal connections and port usage, packet content features; determining the hazard level of the abnormal traffic; generating an abnormal feature description report; Warning message generation steps, including: constructing a warning message template according to the abnormal level; integrating the specific manifestations of the abnormal traffic: abnormal type description, impact range assessment, potential risk analysis; generating warning suggestion measures; adding a timestamp and a unique identifier; Multi-interface warning push steps, including: device display screen push: displaying a warning icon, outputting a warning sound, triggering the indicator light to flash; mobile APP notification: sending a push notification, updating the APP interface status, displaying detailed abnormal information; Web management interface prompt: updating the dashboard status, displaying a warning pop-up window, providing detailed log viewing; Hierarchical traffic control mechanism initialization steps, including: establishing a traffic control policy table: defining control level thresholds, setting control action types, configuring control durations; initializing the traffic control module: loading control rules, setting priority orders, preparing control resources; Traffic control execution steps, including: mild anomaly handling: restricting the bandwidth of the suspicious IP, reducing the priority of the abnormal traffic, recording abnormal behaviors; moderate anomaly handling: blocking traffic on specific ports, restricting traffic of suspicious protocols, starting traffic redirection; severe anomaly handling: disconnecting abnormal connections, blocking relevant IP segments, activating the emergency response mechanism; Control effect evaluation steps, including: monitoring the traffic change after control: analyzing the traffic decline trend, evaluating the bandwidth recovery situation, and checking whether anomalies are eliminated; recording the effect of control measures: counting the blocking success rate, calculating the response delay, and evaluating the misjudgment situation; generating a control effect report; Adaptive optimization steps, including: dynamically adjusting the strategy according to the control effect: updating the control rules, optimizing the threshold settings, and adjusting the control intensity; optimizing the warning mechanism: improving the warning information content, adjusting the push frequency, and optimizing the display method.
[0009] Optionally, the steps of allocating an independent network slice for traffic monitoring to achieve service isolation and automatically adjusting the slice configuration parameters based on a smart contract include: Network slice initialization steps, including: creating a network slice dedicated to traffic monitoring in the 5G core network: allocating a slice identifier, setting the slice priority, and defining the slice resource quota; configuring slice isolation parameters: setting the resource isolation level, configuring the service isolation policy, and establishing a security isolation mechanism; initializing the basic service quality parameters: configuring the bandwidth limit, setting the delay requirement, and defining the reliability index; Smart contract deployment steps, including: deploying a slice management smart contract in the blockchain network: writing the contract code, setting the trigger conditions, and defining the execution rules; initializing the contract parameters: configuring the adjustment threshold, setting the decision rules, and defining the reward and punishment mechanism; establishing a contract call interface: configuring the interface permissions, setting the call method, and defining the data format; Slice monitoring steps, including: real-time collecting slice performance metrics: monitoring the resource utilization rate, recording the service quality parameters, and counting the business traffic situation; analyzing the slice operation status: evaluating the performance trend, detecting anomalies, and predicting the resource requirements; generating a monitoring report: summarizing the performance data, marking abnormal events, and calculating the health metrics; Smart contract triggering steps, including: checking the trigger conditions: judging the performance threshold, verifying the time condition, and confirming the trigger permission; collecting decision-making information: obtaining historical data, analyzing the current state, and predicting the future trend; executing the contract logic: calculating the adjustment plan, verifying the feasibility, and recording the execution process; Slice parameter adjustment steps, including: generating an adjustment instruction: determining the adjustment items, calculating the adjustment range, and setting the execution time; executing the parameter update: modifying the bandwidth configuration, adjusting the priority setting, and updating the resource quota; verifying the adjustment effect: checking whether the parameters take effect, monitoring the performance change, and evaluating the adjustment impact; Service migration steps, including: preparing the migration environment: evaluating the target slice capacity, planning the migration path, and preparing a rollback plan; executing the service migration: establishing a data channel, transferring the service traffic, and synchronizing the status information; verifying the migration result: checking the service continuity, confirming the data integrity, and evaluating the service quality; Continuous optimization steps, including: Collecting optimization data: Statistically analyzing adjustment effects, analyzing performance improvements, and recording problem feedback; Updating smart contracts: Optimizing decision rules, adjusting trigger conditions, and improving execution logic; Improving management strategies: Optimizing resource allocation, updating isolation strategies, and improving security mechanisms.
[0010] Optionally, the steps for achieving traffic data interconnection between different operators through the cross-chain interoperability mechanism include: Cross-chain network initialization steps, including: Deploying cross-chain protocols on each operator node: Configuring consensus mechanisms, setting communication protocols, and initializing key pairs; Establishing cross-chain gateways: Deploying gateway nodes, configuring routing rules, and setting security policies; Initializing inter-chain communication channels: Establishing P2P connections, configuring transmission protocols, and setting bandwidth parameters; Data standardization steps, including: Formulating cross-chain data format specifications: Defining data structures, standardizing field names, and setting data types; Establishing data mapping relationships: Configuring field mappings, setting conversion rules, and defining verification methods; Implementing data format conversion: Processing data encoding, converting data formats, and verifying conversion results; Identity authentication steps, including: Deploying a distributed identity system: Generating identity identifiers, configuring permission levels, and setting authentication rules; Implementing multi-chain identity mutual recognition: Exchanging identity credentials, verifying identity validity, and establishing trust relationships; Managing access permissions: Setting access policies, controlling data permissions, and recording access logs; Cross-chain data transmission steps, including: Initiating a data transmission request: Constructing a transmission request, signing request data, and selecting the target chain; Executing cross-chain transmission: Verifying request legality, encrypting data packets, and transmitting data content; Confirming data reception: Verifying data integrity, sending confirmation messages, and recording transmission status; Data consistency maintenance steps, including: Implementing atomic operations: Setting transaction boundaries, defining rollback mechanisms, and ensuring operation integrity; Maintaining data consistency: Synchronizing data states, handling conflict situations, and keeping data synchronized; Managing version control: Recording version information, tracking data changes, and maintaining update histories; Cross-chain invocation of smart contracts steps, including: Deploying cross-chain contracts: Writing contract code, setting invocation rules, and configuring execution environments; Implementing contract interoperability: Defining interface specifications, implementing invocation methods, and handling return results; Managing contract states: Synchronizing contract states, handling execution exceptions, and recording invocation logs; Performance optimization steps, including: Optimizing transmission efficiency: Implementing data sharding, compressing transmission content, and optimizing route selection; Improving processing performance: Processing requests in parallel, optimizing query efficiency, and implementing caching mechanisms; Monitoring system performance: Collecting performance metrics, analyzing bottleneck problems, and optimizing system configurations.
[0011] Optionally, the steps of encrypting the traffic data, the traffic recognition result, and the warning record through quantum encryption technology, and using distributed ledger technology to package the encrypted data into blocks to construct a blockchain ledger containing timestamps to achieve data anti-tampering include: The quantum key distribution step includes: initializing the quantum key distribution system: configuring quantum communication devices, establishing quantum channels, and setting key generation parameters; performing quantum key negotiation: generating a quantum bit sequence, measuring quantum states, and performing basis vector verification; generating a shared key: performing error correction coding, performing key extraction, and verifying key availability; The data preprocessing step includes: sorting out the original data: classifying traffic data, integrating traffic recognition results, and summarizing warning records; constructing a data structure: defining data formats, setting field attributes, and establishing index relationships; generating a data digest: calculating a hash value, adding a timestamp, and recording the data source; The quantum encryption step includes: encrypting data based on quantum keys: selecting an encryption algorithm, encrypting data in blocks, and generating ciphertext; performing integrity protection: calculating an authentication code, adding verification information, and generating a signature; managing the key state: updating the key usage status, recording the key version, and setting the key validity period; The block construction step includes: packaging encrypted data: organizing the block structure, setting the block header, and adding transaction content; generating a block identifier: calculating the block hash, linking to the previous block, and recording the block height; adding time proof: obtaining a trusted timestamp, signing the time proof, and verifying the time validity; The consensus verification step includes: initiating a consensus request: broadcasting block information, submitting a verification request, and waiting for node responses; performing the consensus process: verifying block validity, checking data integrity, and confirming the time order; reaching a consensus result: collecting verification results, counting consensus votes, and confirming the block status; The ledger maintenance step includes: updating the blockchain state: adding new blocks, updating link relationships, and maintaining the state tree; managing data indexes: establishing a retrieval table, updating the index structure, and optimizing query performance; performing ledger synchronization: broadcasting update information, synchronizing block data, and verifying the synchronization result; The audit and traceability step includes: providing a query interface: designing a query language, implementing a retrieval method, and configuring access permissions; supporting proof generation: constructing a proof path, generating a verification proof, and providing an audit report; maintaining historical records: recording operation logs, saving state snapshots, and supporting version backtracking.
[0012] Optionally, the steps of collecting environmental data of surrounding Internet of Things devices, fusing environmental data and traffic data for comprehensive analysis, and dynamically adjusting the traffic allocation strategy based on the analysis results include: Collect environmental data from surrounding Internet of Things devices; Collect network traffic data, including the number of user accesses, data transmission rate, and latency; Fuse the collected environmental data with the traffic data to form a comprehensive dataset; Conduct a comprehensive analysis of the comprehensive dataset and use data analysis algorithms to identify the relationship between environmental factors and traffic changes; Based on the results of the comprehensive analysis, dynamically adjust the traffic allocation strategy; Implement the adjusted traffic allocation strategy and continuously monitor its effect. According to real-time feedback, optimize the traffic allocation strategy to adapt to the changing environment and user needs.
[0013] Another aspect of the present invention provides a 5G-based intelligent portable WiFi traffic monitoring system for implementing a 5G-based intelligent portable WiFi traffic monitoring method, which is characterized by including: a first 5G intelligent portable WiFi device provided with a traffic statistics module, an edge computing node, and a server; The traffic statistics module disposed within the chipset of the first 5G intelligent portable WiFi device is configured to: Use an adaptive sampling rate mechanism to capture data packets in real time; wherein, the adaptive sampling rate mechanism dynamically adjusts the data packet capture frequency according to the network load status and traffic characteristics; When the data packet flows through the key nodes of the kernel protocol stack, extract traffic data including timestamp, source and destination IP addresses, port numbers, protocol types, and data volume size; Transmit the traffic data to the edge computing node deployed locally on the first 5G intelligent portable WiFi device; The edge computing node is configured to: Use a streaming processing framework to perform real-time cleaning of the traffic data, remove duplicate, incorrect, and invalid traffic records, compress and store the cleaned traffic data using a data compression algorithm, and perform standardization processing on the compressed traffic data according to a preset classification rule to generate a traffic data subset; Obtain a traffic recognition result according to the traffic data subset and a preset first traffic recognition model; When abnormal traffic is recognized, send a warning message through multiple user interfaces associated with the device, and at the same time activate the hierarchical traffic control mechanism built in the first 5G intelligent portable WiFi device to restrict or block the abnormal traffic; Extract and feedback the abnormal traffic characteristics to the first traffic recognition model for model optimization; Allocate an independent network slice for traffic monitoring to achieve service isolation, and automatically adjust the slice configuration parameters based on a smart contract; Realize the intercommunication of traffic data between different operators through a cross-chain interoperability mechanism; Encrypt the traffic data, the traffic identification result and the warning record through quantum encryption technology, and use distributed ledger technology to package the encrypted data into blocks to construct a blockchain ledger containing timestamps, so as to achieve data anti-tampering; Collect the environmental data of surrounding Internet of Things devices, integrate the environmental data and traffic data for comprehensive analysis, and dynamically adjust the traffic allocation strategy based on the analysis results.
[0014] Adopt the technical solution of the present invention, a 5G-based intelligent portable WiFi traffic monitoring method, including: using a traffic statistics module set in the chipset of the first 5G intelligent portable WiFi device to capture data packets in real time by means of an adaptive sampling rate mechanism; wherein, the adaptive sampling rate mechanism dynamically adjusts the data packet capture frequency according to the network load status and traffic characteristics; when the data packet flows through the key nodes of the kernel protocol stack, extract traffic data including timestamps, source and destination IP addresses, port numbers, protocol types, and data volume sizes; transmit the traffic data to an edge computing node deployed locally on the first 5G intelligent portable WiFi device; use a streaming processing framework to perform real-time cleaning on the traffic data, remove duplicate, incorrect, and invalid traffic records, use a data compression algorithm to compress and store the cleaned traffic data, and perform standardization processing on the compressed traffic data according to a preset classification rule to generate a traffic data subset; obtain a traffic identification result according to the traffic data subset and a preset first traffic identification model; when abnormal traffic is identified, send a warning message through multiple user interfaces associated with the device, and at the same time activate the hierarchical traffic control mechanism built in the first 5G intelligent portable WiFi device to limit or block the abnormal traffic; extract and feedback the abnormal traffic characteristics to the first traffic identification model for model optimization; allocate an independent network slice for traffic monitoring to achieve service isolation, and automatically adjust the slice configuration parameters based on smart contracts; achieve traffic data intercommunication between different operators through a cross-chain interoperability mechanism; encrypt the traffic data, the traffic identification result and the warning record through quantum encryption technology, and use distributed ledger technology to package the encrypted data into blocks to construct a blockchain ledger containing timestamps, so as to achieve data anti-tampering; collect the environmental data of surrounding Internet of Things devices, integrate the environmental data and traffic data for comprehensive analysis, and dynamically adjust the traffic allocation strategy based on the analysis results. Improve the accuracy of traffic monitoring through adaptive sampling and federated learning, achieve multi-device collaborative learning, improve the efficiency of anomaly detection, and support intelligent traffic management and resource allocation; use streaming processing and data compression to reduce system overhead, and the edge computing architecture reduces data transmission latency, and network slicing technology guarantees the quality of monitoring services; quantum encryption technology protects data security, blockchain technology ensures data immutability, and multi-level anomaly protection mechanisms enhance network security; cross-chain interoperability supports a wider range of business scenarios, and Internet of Things collaboration enables more comprehensive monitoring. Brief Description of the Drawings
[0015] Figure 1 is a flowchart of a 5G-based intelligent portable Wi-Fi traffic monitoring method provided by an embodiment of the present invention; Figure 2 is a schematic block diagram of a 5G-based intelligent portable Wi-Fi traffic monitoring system provided by an embodiment of the present invention. Detailed Embodiments
[0016] In order to more clearly understand the above objects, features and advantages of the present invention, the present invention will be further described in detail below with reference to the drawings and specific embodiments. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments may be combined with each other.
[0017] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention may also be implemented in other ways different from those described herein. Therefore, the protection scope of the present invention is not limited by the specific embodiments disclosed below.
[0018] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally further include steps or units not listed, or may optionally further include other steps or units inherent to these processes, methods, products or devices.
[0019] The mention of "embodiment" in this article means that a specific feature, structure or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various places in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.
[0020] The following refers to Figures 1 to 2 to describe a 5G-based intelligent portable Wi-Fi traffic monitoring method and system provided according to some embodiments of the present invention.
[0021] As Figure 1 shown, an embodiment of the present invention provides a 5G-based intelligent portable Wi-Fi traffic monitoring method, including: Through the traffic statistics module set within the chipset of the first 5G smart portable Wi-Fi device, the packet capture mechanism adopts an adaptive sampling rate to capture data packets in real time; among them, the adaptive sampling rate mechanism dynamically adjusts the packet capture frequency according to the network load status and traffic characteristics. When the data packet flows through the key nodes of the kernel protocol stack, traffic data including timestamp, source and destination IP addresses, port numbers, protocol types, and data volume size are extracted. It can be understood that in this step, in the first 5G smart portable Wi-Fi device, the packet capture module is started to ensure that the device can monitor all data packets flowing through the kernel protocol stack; the key nodes in the kernel protocol stack are determined, such as the network interface layer, transport layer, and application layer, etc., to ensure that data packets are extracted at these nodes; the flow of data packets is monitored through the kernel network module to ensure that data extraction can be performed in a timely manner when the data packets pass through the key nodes; when the data packets pass through the key nodes, the following traffic data are extracted: timestamp (recording the time when the data packet arrives at the key node), source IP address (extracting the source IP address of the data packet), destination IP address (extracting the destination IP address of the data packet), source port number (extracting the source port number of the data packet), destination port number (extracting the destination port number of the data packet), protocol type (identifying the transport protocol used by the data packet (such as TCP, UDP, etc.)), data volume size (calculating the size of the data packet (in bytes)); the extracted traffic data is stored in the local database or sent to the edge computing node for further processing and analysis for subsequent traffic monitoring and anomaly detection; a real-time monitoring mechanism is implemented to regularly check the extracted data, generate traffic reports, and perform dynamic adjustment and optimization according to the traffic characteristics. By extracting traffic data at the key nodes of the kernel protocol stack in this step, the key information of the data packets can be comprehensively obtained, providing a rich data basis for subsequent traffic analysis; the information such as the timestamp, IP address, and port number extracted can help analyze the traffic pattern, identify normal and abnormal traffic, and improve the accuracy of traffic analysis; through real-time monitoring and data extraction, abnormal traffic and potential security threats can be discovered in a timely manner, enhancing the security of the network; through the analysis of traffic data, network bottlenecks and performance problems can be identified, and thus optimized to improve the overall performance of the network and the user experience.
[0022] The traffic data is transmitted to the edge computing node deployed locally in the first 5G smart portable Wi-Fi device. It is understandable that in this step, after the extraction of traffic data is completed, it is ensured that the extracted data (including timestamp, source and destination IP addresses, port numbers, protocol types, data volume size, etc.) undergoes preliminary processing and meets the requirements of the transmission format; in the first 5G intelligent portable WiFi device, the communication module with the edge computing node is started to establish a reliable network connection. Ensure the stability and security of the communication channel for subsequent data transmission; pack the prepared traffic data using an appropriate data format (such as JSON, XML, etc.) to facilitate parsing and processing at the edge computing node; send the packed traffic data to the edge computing node through the established communication channel (this process can use the TCP / UDP protocol for data transmission to ensure the integrity and accuracy of the data); after the edge computing node receives the data, send an acknowledgment message back to the first 5G intelligent portable WiFi device to ensure the successful data transmission; if the acknowledgment message is not received, re-transmit the data; after the edge computing node receives the traffic data, perform storage and further processing, including data cleaning, analysis, and storage, for subsequent traffic monitoring and anomaly detection. This step can achieve real-time processing and analysis of data by transmitting the traffic data to the edge computing node, improving the response speed of the system; processing data at the local edge computing node reduces the latency of data transmission to the remote server and improves the overall efficiency of the system; by processing data locally, the risk of data leakage during transmission is reduced, enhancing data security; the edge computing node can make intelligent decisions and resource allocations based on real-time traffic data, optimizing the use of network resources and improving network performance.
[0023] Adopt a streaming processing framework to perform real-time cleaning on the traffic data, remove duplicate, incorrect, and invalid traffic records, use a data compression algorithm to compress and store the cleaned traffic data, and perform standardization processing on the compressed traffic data according to a preset classification rule to generate a traffic data subset; According to the traffic data subset and a preset first traffic recognition model (a distributed deep learning model based on the federated learning framework, which integrates a convolutional neural network and a recurrent neural network), obtain a traffic recognition result; It is understandable that in this step, a subset of the cleaned and standardized traffic data is extracted from the storage system to ensure that the data format matches the input requirements of the first traffic recognition model; under the federated learning framework, a preset first traffic recognition model is loaded, which combines a convolutional neural network (CNN) and a recurrent neural network (RNN) for traffic recognition; necessary preprocessing is performed on the extracted subset of traffic data, including: feature extraction (using CNN to extract features from traffic data to identify key features), sequence processing (using RNN to process the extracted feature sequences to capture the temporal information in traffic data); the preprocessed data is input into the loaded traffic recognition model for inference calculation to obtain traffic recognition results. This process should ensure the inference efficiency and accuracy of the model; the traffic recognition results output by the model are analyzed to evaluate the accuracy and effectiveness of the recognition. If necessary, subsequent result optimization or model parameter adjustment can be carried out; the traffic recognition results are stored in the database for subsequent query and analysis; at the same time, the recognition results are fed back to the federated learning framework for continuous optimization and update of the model. The model architecture combining CNN and RNN in this step can effectively extract the spatial and temporal features in traffic data, thereby improving the accuracy of traffic recognition; the distributed deep learning model based on the federated learning framework can share the learning results between different data sources, enhancing the adaptability of the model to new traffic patterns; through the mechanism of federated learning, data is processed locally, avoiding the centralized storage and transmission of data, enhancing data privacy protection; the fast traffic recognition ability enables the system to monitor network traffic in real time and detect abnormal traffic and potential security threats in a timely manner.
[0024] When abnormal traffic is identified, warning messages are sent through multiple user interfaces associated with the device, and at the same time, the built-in hierarchical traffic control mechanism of the first 5G smart portable WiFi device is activated to restrict or block the abnormal traffic; The abnormal traffic features are extracted and fed back to the first traffic recognition model for model optimization; It is understandable that after identifying abnormal traffic, first extract the features of this traffic. The extracted features should include the key attributes of the traffic, such as traffic source, destination, packet size, protocol type, timestamp, etc.; format the extracted abnormal traffic features to ensure that they meet the input requirements of the first traffic recognition model (this may include steps such as data type conversion and feature standardization for easy model processing); establish a feedback mechanism to transmit the formatted abnormal traffic feature data to the first traffic recognition model (this process can be achieved through API calls or direct data transmission to ensure the timeliness and accuracy of the data; after the first traffic recognition model receives the feedback of abnormal traffic features, it receives and stores the data. The model will use these new features for training to optimize its recognition ability; after receiving the new feature data, start the training process of the model. By using these feature data, the model will adjust its parameters to improve the recognition accuracy and efficiency of abnormal traffic; after completing the model training, conduct model verification and evaluation; use the test set to test the optimized model and evaluate its performance improvement in identifying abnormal traffic. In this step, by feeding back the abnormal traffic features to the traffic recognition model, the model can learn new traffic patterns, thereby improving its recognition accuracy; the model can self-optimize according to the changing network environment and traffic features, enhancing its adaptability to new types of abnormal traffic; through continuous feature feedback and model updates, ensure that the traffic recognition model always remains in the best state and can respond to new security threats in real time; the optimized model can more effectively identify and respond to abnormal traffic, improving the overall network security and stability.
[0025] Allocate an independent network slice for traffic monitoring to achieve service isolation, and automatically adjust the slice configuration parameters based on smart contracts; Realize the interconnection of traffic data between different operators through a cross-chain interoperability mechanism; Encrypt the traffic data, the traffic recognition result, and the warning record through quantum encryption technology, and use distributed ledger technology to package the encrypted data into blocks to construct a blockchain ledger containing timestamps to achieve data anti-tampering; Collect the environmental data of surrounding Internet of Things devices, integrate the environmental data and traffic data for comprehensive analysis, and dynamically adjust the traffic allocation strategy based on the analysis results.
[0026] In the embodiments of the present invention, the accuracy of traffic monitoring is improved through adaptive sampling and federated learning, multi-device collaborative learning is achieved, the efficiency of anomaly detection is enhanced, and intelligent traffic management and resource allocation are supported; stream processing and data compression are adopted to reduce system overhead, the edge computing architecture reduces data transmission latency, and network slicing technology ensures the quality of monitoring services; quantum encryption technology protects data security, blockchain technology ensures data immutability, and a multi-level anomaly protection mechanism enhances network security; cross-chain interoperability supports a wider range of business scenarios, and IoT collaboration enables more comprehensive monitoring.
[0027] In some possible embodiments of the present invention, it further includes steps of visualization and interaction, specifically including: generating a 3D dynamic traffic visualization interface using image processing technology; integrating a voice recognition module to support voice command query and control; and displaying the specific causes of abnormal traffic through an interpretability module. In this solution, multi-modal interaction improves the usability of the system, visual display enhances data understanding, and interpretability design increases user trust.
[0028] In some possible embodiments of the present invention, it further includes steps of continuous optimization, specifically including: regularly collecting user feedback and new network attack characteristics, using data analysis technology to evaluate the existing monitoring effect, and updating model parameters and monitoring strategies according to the evaluation results. The continuous optimization mechanism of this solution ensures the long-term effectiveness of the system.
[0029] In some possible embodiments of the present invention, the step of using an adaptive sampling rate mechanism to capture data packets in real time through a traffic statistics module provided in the chipset of the first 5G smart portable WiFi device includes: Initialization configuration steps, including: setting a traffic statistics module in the chipset of the first 5G smart portable WiFi device; configuring initial sampling rate parameters in the traffic statistics module, including a reference sampling interval and a sampling window size; setting traffic thresholds, including a high-load threshold and a low-load threshold; initializing a sampling rate adjustment factor and an adjustment step size; Network status monitoring steps, including: real-time monitoring of the network interface status of the first 5G smart portable WiFi device; obtaining the current network bandwidth utilization rate; detecting the length of the data packet queue; recording network latency and packet loss rate; Load evaluation steps, including: calculating network load metrics within the current time window; comparing the calculated load metrics with preset thresholds; determining whether the current network status belongs to high load, normal load, or low load conditions; generating a load evaluation result; Sampling rate adaptive adjustment steps, including: dynamically calculating the optimal sampling rate according to the load evaluation result; when the load is higher than the high load threshold, appropriately reducing the sampling rate to relieve system pressure; when the load is lower than the low load threshold, increasing the sampling rate to obtain more detailed traffic information; ensuring that the sampling rate adjustment is within the preset maximum and minimum ranges; Packet capture steps, including: setting a packet filter at the network interface driver layer; sampling the passing packets according to the current sampling rate; extracting the header information of the sampled packets; recording the timestamp information of the packets; Sampling optimization steps, including: adopting a differentiated sampling strategy for different types of network protocols; increasing the sampling priority for critical business traffic; adopting a predictive sampling mechanism for periodic traffic; dynamically adjusting the sampling window size; Resource monitoring steps, including: monitoring the CPU usage rate of the traffic statistics module; monitoring the memory buffer occupancy; triggering a protection mechanism when the system resources are close to the threshold; automatically adjusting the sampling parameters to balance the system load; Sampling quality evaluation steps, including: calculating the representative indicators of the sampling data; evaluating the accuracy of the sampling results; analyzing the sampling deviation; generating a sampling quality report.
[0030] The solution of this embodiment adjusts the sampling strategy in real time according to the network load, avoids resource waste or data loss caused by a fixed sampling rate, and realizes the dynamic balance between the sampling rate and the network state; reduces the system resource occupancy, optimizes the packet processing efficiency, and reduces unnecessary data storage; ensures the representativeness of the sampling data, improves the accuracy of traffic statistics, and supports fine-grained traffic analysis; optimizes the system resource allocation, avoids performance bottlenecks, and improves the overall operation efficiency of the device; supports multi-protocol traffic monitoring, adapts to different network environments, and facilitates function expansion and optimization.
[0031] In some possible embodiments of the present invention, the steps of using a streaming processing framework to perform real-time cleaning on the traffic data, removing duplicate, incorrect, and invalid traffic records, compressing and storing the cleaned traffic data using a data compression algorithm, and performing standardization processing on the compressed traffic data according to a preset classification rule to generate a traffic data subset include: Streaming processing environment initialization steps, including: deploying a streaming processing framework at the edge computing node; configuring the data stream inlet and outlet nodes; setting the parallelism parameter of the data processing pipeline; initializing the data buffer and processing queue; Data stream access steps, including: establishing a data transmission channel with the traffic statistics module; fragmenting the received traffic data and adding it to the processing queue; assigning a unique identifier to each data fragment; recording the data access timestamp; Real-time cleaning steps, including: detecting and deleting duplicate packet records: calculating the hash value of packet features, using a sliding time window for duplicate determination, and retaining the earliest valid record; identifying and filtering error data: verifying the integrity of packets, validating the legality of protocol fields, and checking the validity of address formats; eliminating invalid traffic records: filtering out timeout packets, deleting incomplete session records, and removing data with abnormal lengths; Data compression steps, including: classifying and packing the cleaned data: grouping by protocol type, processing in batches according to the time series, and establishing a data index structure; performing multi-level compression processing: first performing field-level compression, then block-level compression, and finally applying global compression; generating compression metadata: recording compression algorithm parameters, saving the information required for decompression, and establishing an index for the compressed data; Standardization processing steps, including: performing unified data format: unifying the timestamp format, standardizing the address representation, and normalizing the protocol identifier; performing numerical normalization: calculating the statistical values of traffic features, performing min-max normalization, and applying Z-score standardization; establishing a standardization mapping table: recording conversion parameters, saving the normalization range, and maintaining the feature mapping relationship; Flow data subset generation steps, including: classifying data according to preset rules: dividing based on the time dimension, grouping according to protocol type, and clustering according to business characteristics; constructing an index for the data subset: creating a multi-dimensional index structure, establishing a fast retrieval table, and generating subset association relationships; optimizing the storage structure of the subset: implementing an incremental update mechanism, designing a caching strategy, and constructing a hierarchical storage structure; Quality control steps, including: real-time monitoring of processing quality: tracking the data loss rate, monitoring processing latency, and evaluating compression efficiency; performing exception handling: detecting processing exceptions, triggering a recovery mechanism, and recording exception logs; generating a quality report: counting processing metrics, analyzing performance bottlenecks, and providing optimization suggestions.
[0032] The solution of this embodiment realizes real-time cleaning of data through streaming processing. The multi-level compression strategy significantly reduces the storage space, and parallel processing improves the system throughput; effectively removes duplicate and error data, standardization processing ensures data consistency, and classified storage improves data availability; reduces the storage space occupation, reduces the data transmission load, and improves the query and retrieval efficiency.
[0033] In some possible implementation manners of the present invention, the method for constructing the first traffic recognition model includes: Model initialization steps, including: initializing the global model architecture on the central server side, including a convolutional neural network module and a recurrent neural network module; the convolutional neural network module is used to extract the spatial features of traffic data, including multiple convolutional layers, pooling layers and fully connected layers; the recurrent neural network module is used to extract the temporal features of traffic data, including LSTM or GRU units; distributing the initialized global model parameters to each 5G smart portable Wi-Fi device participating in the training; Local training steps, including: each 5G smart portable Wi-Fi device performs model training based on the local traffic data set; uses batch normalization to process local data to eliminate the difference in data distribution between devices; uses differential privacy mechanism to protect privacy during the training process; calculates the gradient update value of the local model parameters; Parameter aggregation steps, including: each 5G smart portable Wi-Fi device encrypts and transmits the calculated gradient update value to the central server; the central server uses a weighted average algorithm to aggregate the gradient update values of all devices; updates the global model parameters; distributes the updated global model parameters to each participating device; Model optimization steps, including: setting a dynamic learning rate adjustment mechanism to adaptively adjust the learning rate according to the training progress; introducing an early stopping mechanism to stop training when the model performance no longer improves significantly; using Dropout technology to prevent model overfitting; using residual connections to optimize gradient propagation; Model evaluation steps, including: evaluating the model performance on the validation data set; calculating evaluation metrics such as accuracy, recall rate, and F1 score; generating a confusion matrix to analyze the model prediction effect; deciding whether to continue training according to the evaluation results; obtaining the first traffic recognition model; Anomaly detection steps, including: inputting real-time traffic data into the trained model; extracting spatial features through a convolutional neural network; analyzing temporal patterns through a recurrent neural network; fusing the two types of features to determine abnormal traffic; Model deployment steps, including: converting the trained model into a lightweight format; deploying it to each 5G smart portable Wi-Fi device; configuring model inference parameters; starting an online anomaly detection service.
[0034] The solution of this embodiment realizes collaborative learning among devices, makes full use of decentralized data resources, protects user privacy, and the original data does not need to leave the local device. It reduces the computing load and storage pressure of a single device. The combination of spatial features and temporal features improves the accuracy of anomaly detection, and the dynamic learning rate and early stopping mechanism optimize the model convergence effect. Residual connections and Dropout techniques enhance the generalization ability of the model. It supports the dynamic addition of new participating devices, and the model can be continuously optimized and updated to adapt to the traffic characteristics of different scenarios. The lightweight model deployment reduces the occupation of device resources, batch training improves the computing efficiency, and the optimized parameter aggregation mechanism reduces the communication overhead. Differential privacy protects the security of user data, encrypted transmission ensures the security of the model update process, and the distributed architecture enhances the fault tolerance of the system.
[0035] In some possible embodiments of the present invention, the step of, when an abnormal traffic is identified, sending a warning message through multiple user interfaces associated with the device and simultaneously activating the hierarchical traffic control mechanism built in the first 5G smart portable WiFi device to restrict or block the abnormal traffic includes: The abnormal traffic feature extraction step includes: obtaining the abnormal traffic data identified by the deep learning model; extracting the key feature parameters of the abnormal traffic: the amplitude and duration of traffic surge, the number of abnormal connections and port usage, the content features of data packets; determining the hazard level of the abnormal traffic; generating an abnormal feature description report; It can be understood that in the embodiments of the present invention, the historical traffic data can be analyzed, and according to the traffic analysis results, the hazard levels of abnormal traffic can be divided into mild anomalies, moderate anomalies, and severe anomalies. Of course, the hazard levels of abnormal traffic can also be divided into other types according to other methods, and the embodiments of the present invention are not limited thereto.
[0036] The warning message generation step includes: constructing a warning message template according to the abnormal level; integrating the specific manifestations of the abnormal traffic: abnormal type description, impact range assessment, potential risk analysis; generating warning suggestion measures; adding a timestamp and a unique identifier; The multi-interface warning push step includes: device display screen push: displaying a warning icon, outputting a warning sound, and triggering the indicator light to flash; mobile APP notification: sending a push notification, updating the APP interface status, and displaying detailed abnormal information; Web management interface prompt: updating the dashboard status, displaying a warning pop-up window, and providing detailed log viewing; The hierarchical traffic control mechanism initialization step includes: establishing a traffic control policy table: defining control level thresholds, setting control action types, and configuring control durations; initializing the traffic control module: loading control rules, setting priority orders, and preparing control resources; Traffic control execution steps, including: Mild anomaly handling: restricting the bandwidth of suspicious IPs, reducing the priority of abnormal traffic, and recording abnormal behaviors; Moderate anomaly handling: blocking traffic on specific ports, restricting traffic of suspicious protocols, and initiating traffic redirection; Severe anomaly handling: disconnecting abnormal connections, blocking relevant IP segments, and activating the emergency response mechanism; It can be understood that a suspicious IP refers to an IP address that exhibits anomalies or potential threats during network activities, and its characteristics include but are not limited to: frequent login failures (multiple failed login attempts from the same IP address may indicate a brute-force attack); abnormal data traffic (the traffic of this IP address is significantly higher than the normal level, which may be involved in data leakage or DDoS attacks); communication with known malicious addresses (if this IP address has communication records with known malicious IP addresses, it may indicate its participation in malicious activities); using uncommon ports or protocols (suspicious IPs may use uncommon ports or protocols for communication, which may be the behavioral characteristics of attackers); and so on. A suspicious protocol refers to a protocol that exhibits anomalies or potential threats during network communication, and its characteristics include but are not limited to: using outdated or insecure protocols (such as old protocols like POP3, IMAP, and SMTP, which may be exploited by attackers for password spraying attacks); abnormal protocol usage patterns (for example, a certain protocol is frequently used during unusual time periods, or is called in a manner that does not conform to normal business logic); association with suspicious IPs (if the usage of a certain protocol is combined with the activities of a suspicious IP, it may indicate that the protocol is being used for malicious purposes); and so on.
[0037] Control effect evaluation steps, including: Monitoring traffic changes after control: analyzing the traffic decline trend, evaluating the bandwidth recovery situation, and checking whether anomalies are eliminated; Recording the effects of control measures: counting the blocking success rate, calculating the response delay, and evaluating misjudgment situations; Generating a control effect report; Adaptive optimization steps, including: Dynamically adjusting strategies according to control effects: updating control rules, optimizing threshold settings, and adjusting control intensity; Optimizing the early warning mechanism: improving the content of early warning messages, adjusting the push frequency, and optimizing the display method.
[0038] The solution of this embodiment realizes real-time early warning of abnormal traffic, supports multi-channel synchronous notifications to ensure that control measures take effect in a timely manner; realizes hierarchical and precise control, reduces the impact of misjudgment, and improves control efficiency; multi-interface collaborative display, with clear and intuitive early warning information, and little impact on normal business during the control process; the control mechanism is stable and reliable, supports automatic recovery in case of failure, and has emergency handling capabilities; control strategies are adaptively adjusted, the early warning mechanism is continuously optimized, and it supports handling complex scenarios.
[0039] In some possible embodiments of the present invention, the steps of allocating an independent network slice for traffic monitoring to achieve service isolation and automatically adjusting slice configuration parameters based on a smart contract include: Network slice initialization steps, including: creating a network slice dedicated to traffic monitoring in the 5G core network: allocating a slice identifier, setting slice priority, defining slice resource quotas; configuring slice isolation parameters: setting the resource isolation level, configuring service isolation policies, establishing a security isolation mechanism; initializing basic quality of service parameters: configuring bandwidth limits, setting latency requirements, defining reliability metrics; Smart contract deployment steps, including: deploying a slice management smart contract in the blockchain network: writing contract code, setting trigger conditions, defining execution rules; initializing contract parameters: configuring adjustment thresholds, setting decision rules, defining reward and punishment mechanisms; establishing a contract call interface: configuring interface permissions, setting call methods, defining data formats; Slice monitoring steps, including: real-time collecting slice performance metrics: monitoring resource utilization, recording quality of service parameters, statistically analyzing traffic conditions; analyzing the slice operating status: evaluating performance trends, detecting anomalies, predicting resource requirements; generating a monitoring report: summarizing performance data, marking abnormal events, calculating health metrics; Smart contract triggering steps, including: checking trigger conditions: judging performance thresholds, verifying time conditions, confirming trigger permissions; collecting decision-making information: obtaining historical data, analyzing the current state, predicting future trends; executing contract logic: calculating adjustment plans, verifying feasibility, recording the execution process; Slice parameter adjustment steps, including: generating adjustment instructions: determining adjustment items, calculating adjustment amplitudes, setting execution times; executing parameter updates: modifying bandwidth configurations, adjusting priority settings, updating resource quotas; verifying adjustment effects: checking parameter effectiveness, monitoring performance changes, evaluating the impact of adjustments; Service migration steps, including: preparing the migration environment: evaluating the target slice capacity, planning the migration path, preparing a rollback plan; executing service migration: establishing a data channel, transferring traffic, synchronizing status information; verifying migration results: checking service continuity, confirming data integrity, evaluating quality of service; Continuous optimization steps, including: collecting optimization data: statistically analyzing adjustment effects, analyzing performance improvements, recording problem feedback; updating the smart contract: optimizing decision rules, adjusting trigger conditions, improving execution logic; improving management strategies: optimizing resource allocation, updating isolation policies, improving security mechanisms.
[0040] The solution of this embodiment realizes the complete isolation of the traffic monitoring service, ensures the stability of the monitoring service, and avoids mutual interference between services; it realizes the automatic adjustment of slice parameters, reduces the need for manual intervention, and improves the management efficiency; it ensures the service quality of the monitoring service, improves the resource utilization efficiency, and supports dynamic load balancing.
[0041] In some possible embodiments of the present invention, the steps of realizing the interconnection of traffic data between different operators through the cross-chain interoperability mechanism include: Cross-chain network initialization steps, including: deploying cross-chain protocols at each operator node: configuring a consensus mechanism, setting communication protocols, and initializing key pairs; establishing a cross-chain gateway: deploying gateway nodes, configuring routing rules, and setting security policies; initializing the inter-chain communication channel: establishing P2P connections, configuring transmission protocols, and setting bandwidth parameters; Data standardization steps, including: formulating cross-chain data format specifications: defining data structures, standardizing field names, and setting data types; establishing data mapping relationships: configuring field mappings, setting conversion rules, and defining verification methods; implementing data format conversion: processing data encoding, converting data formats, and verifying conversion results; Identity authentication steps, including: deploying a distributed identity system: generating identity identifiers, configuring permission levels, and setting authentication rules; realizing multi-chain identity mutual recognition: exchanging identity credentials, verifying the validity of identities, and establishing trust relationships; managing access permissions: setting access policies, controlling data permissions, and recording access logs; Cross-chain data transmission steps, including: initiating a data transmission request: constructing a transmission request, signing the request data, and selecting the target chain; performing cross-chain transmission: verifying the legitimacy of the request, encrypting the data packet, and transmitting the data content; confirming data reception: verifying data integrity, sending confirmation information, and recording the transmission status; Data consistency maintenance steps, including: implementing atomic operations: setting transaction boundaries, defining rollback mechanisms, and ensuring the integrity of operations; maintaining data consistency: synchronizing data states, handling conflict situations, and keeping data synchronized; managing version control: recording version information, tracking data changes, and maintaining update histories; Smart contract cross-chain invocation steps, including: deploying cross-chain contracts: writing contract codes, setting invocation rules, and configuring execution environments; realizing contract interoperability: defining interface specifications, implementing invocation methods, and processing return results; managing contract states: synchronizing contract states, handling execution exceptions, and recording invocation logs; Performance optimization steps, including: optimizing transmission efficiency: implementing data sharding, compressing transmission content, and optimizing route selection; improving processing performance: processing requests in parallel, optimizing query efficiency, and implementing a caching mechanism; monitoring system performance: collecting performance metrics, analyzing bottleneck problems, and optimizing system configurations.
[0042] The solution of this embodiment realizes data interconnection between different operators, supports the docking of heterogeneous blockchain systems, and ensures the reliability of data exchange; ensures the security of cross-chain data transmission, realizes complete identity authentication, and protects the privacy of sensitive data; improves data transmission efficiency, optimizes processing performance, and reduces system overhead; supports the access of new operators, adapts to different protocol standards, and facilitates function expansion; ensures data consistency, supports atomic operations, and provides reliable state synchronization.
[0043] In some possible implementation manners of the present invention, the step of encrypting the traffic data, the traffic recognition result, and the warning record through quantum encryption technology, and using distributed ledger technology to package the encrypted data into blocks to construct a blockchain ledger including a timestamp to achieve data anti-tampering includes: The quantum key distribution step includes: initializing the quantum key distribution system: configuring quantum communication devices, establishing a quantum channel, and setting key generation parameters; performing quantum key negotiation: generating a quantum bit sequence, measuring the quantum state, and performing basis vector verification; generating a shared key: performing error correction coding, performing key extraction, and verifying the availability of the key; The data preprocessing step includes: sorting the original data: classifying traffic data, integrating traffic recognition results, and summarizing warning records; constructing a data structure: defining a data format, setting field attributes, and establishing an index relationship; generating a data digest: calculating a hash value, adding a timestamp, and recording the data source; The quantum encryption step includes: encrypting data based on a quantum key: selecting an encryption algorithm, encrypting data in blocks, and generating ciphertext; performing integrity protection: calculating an authentication code, adding check information, and generating a signature; managing the key state: updating the key usage status, recording the key version, and setting the key validity period; The block construction step includes: packaging encrypted data: organizing the block structure, setting the block header, and adding transaction content; generating a block identifier: calculating the block hash, linking to the previous block, and recording the block height; adding time proof: obtaining a trusted timestamp, signing the time proof, and verifying the time validity; The consensus verification step includes: initiating a consensus request: broadcasting block information, submitting a verification request, and waiting for a node response; performing a consensus process: verifying the validity of the block, checking data integrity, and confirming the time sequence; reaching a consensus result: collecting verification results, counting consensus votes, and confirming the block status; The ledger maintenance step includes: updating the blockchain state: adding a new block, updating the link relationship, and maintaining the state tree; managing the data index: establishing a retrieval table, updating the index structure, and optimizing the query performance; performing ledger synchronization: broadcasting update information, synchronizing block data, and verifying the synchronization result; Audit traceability steps, including: providing a query interface: designing a query language, implementing a retrieval method, and configuring access permissions; supporting proof generation: constructing a proof path, generating a verification proof, and providing an audit report; maintaining historical records: recording operation logs, saving status snapshots, and supporting version backtracking.
[0044] The solution of this embodiment realizes quantum-level encryption protection, ensures data integrity, and prevents data tampering; provides a provable time proof, realizes non-repudiation of data, and supports complete audit traceability; improves data processing efficiency, optimizes the storage structure, and enhances query performance; supports dynamic node access, adapts to the expansion of business scale, and facilitates function upgrade.
[0045] In some possible embodiments of the present invention, the step of collecting environmental data of surrounding Internet of Things devices, fusing the environmental data and traffic data for comprehensive analysis, and dynamically adjusting the traffic allocation strategy based on the analysis results includes: Collect environmental data from surrounding Internet of Things devices (such as sensors, cameras, etc.) (these data may include information such as temperature, humidity, air quality, light intensity, etc.); Collect network traffic data, including the access volume of users, data transmission rate, and latency (these data will be used for subsequent analysis); Fuse the collected environmental data and traffic data to form a comprehensive data set (this step requires standardizing and formatting the data to ensure the effective combination of data from different sources); Conduct comprehensive analysis on the comprehensive data set, and use data analysis algorithms (such as machine learning models) to identify the relationship between environmental factors and traffic changes (this analysis will help understand the traffic change trend under different environmental conditions); Based on the results of the comprehensive analysis, dynamically adjust the traffic allocation strategy (for example, in a high-temperature or high-humidity environment, it may be necessary to prioritize the traffic of certain key applications or adjust the bandwidth allocation according to user needs); Implement the adjusted traffic allocation strategy and continuously monitor its effect. According to real-time feedback, optimize the traffic allocation strategy to adapt to the changing environment and user needs.
[0046] The solution of this embodiment can allocate network resources more reasonably through the fusion analysis of environmental data and traffic data, improving the utilization efficiency of overall resources; dynamically adjusting the traffic allocation strategy can optimize network performance and enhance the user experience according to environmental changes and user needs; the system can respond to environmental changes in real time, quickly adjust the strategy, enhancing the adaptability and flexibility of the network; the insights provided by data analysis support more intelligent decision-making, helping operators better manage network traffic. By collecting environmental data of surrounding Internet of Things devices, fusing environmental data and traffic data for comprehensive analysis, and dynamically adjusting the traffic allocation strategy based on the analysis results, the implementation steps not only improve resource utilization and user experience, but also enhance the flexibility and intelligent decision-making ability of the system.
[0047] Please refer to Figure 2 , another embodiment of the present invention provides a 5G-based intelligent portable WiFi traffic monitoring system for implementing a 5G-based intelligent portable WiFi traffic monitoring method, including: a first 5G intelligent portable WiFi device, an edge computing node, and a server, which are provided with a traffic statistics module; The traffic statistics module disposed in the chipset of the first 5G intelligent portable WiFi device is configured to: Use an adaptive sampling rate mechanism to capture data packets in real time; wherein, the adaptive sampling rate mechanism dynamically adjusts the data packet capture frequency according to the network load status and traffic characteristics; When the data packet flows through the key nodes of the kernel protocol stack, extract traffic data including timestamp, source and destination IP addresses, port numbers, protocol types, and data volume size; Transmit the traffic data to the edge computing node deployed locally on the first 5G intelligent portable WiFi device; The edge computing node is configured to: Use a streaming processing framework to perform real-time cleaning on the traffic data, remove duplicate, incorrect, and invalid traffic records, compress and store the cleaned traffic data using a data compression algorithm, and perform standardization processing on the compressed traffic data according to a preset classification rule to generate a traffic data subset; According to the traffic data subset and a preset first traffic recognition model (a distributed deep learning model based on the federated learning framework, which integrates a convolutional neural network and a recurrent neural network), obtain a traffic recognition result; When abnormal traffic is identified, send a warning message through multiple user interfaces associated with the device, and at the same time activate the hierarchical traffic control mechanism built in the first 5G intelligent portable WiFi device to restrict or block the abnormal traffic; Extract and feedback the abnormal traffic characteristics to the first traffic recognition model for model optimization; Allocate an independent network slice for traffic monitoring to achieve service isolation, and automatically adjust the slice configuration parameters based on smart contracts; Implement traffic data interconnection between different operators through a cross-chain interoperability mechanism; Encrypt the traffic data, the traffic recognition result, and the warning record through quantum encryption technology, and use distributed ledger technology to package the encrypted data into blocks to construct a blockchain ledger containing timestamps to achieve data anti-tampering; Collect the environmental data of surrounding Internet of Things devices, integrate the environmental data and traffic data for comprehensive analysis, and dynamically adjust the traffic allocation strategy based on the analysis results.
[0048] It should be known that Figure 2 The block diagram of the 5G-based intelligent portable WiFi traffic monitoring system shown is only for illustration, and the number of each module shown does not limit the protection scope of the present invention. The 5G-based intelligent portable WiFi traffic monitoring system provided in this embodiment can be used to execute the implementation solutions of the corresponding 5G-based intelligent portable WiFi traffic monitoring method. For the specific implementation process, please refer to the descriptions of each method embodiment, which will not be elaborated here.
[0049] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0050] In the above embodiments, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0051] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the above division of units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical or other form.
[0052] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0053] In addition, in each embodiment of this application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0054] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the above-mentioned methods in each embodiment of this application. The aforementioned memory includes: USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs and other media that can store program codes.
[0055] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory, and the memory can include: flash drives, read-only memories (abbreviation: ROM), random access memories (abbreviation: RAM), magnetic disks, or optical discs, etc.
[0056] The above has introduced the embodiments of this application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
[0057] Although the present invention is disclosed as above, the present invention is not limited thereto. Any person skilled in the art can easily conceive of changes or substitutions without departing from the spirit and scope of the present invention, and can make various modifications and alterations, including combinations of the above different functions and implementation steps, including software and hardware implementation manners, all within the protection scope of the present invention.
Claims
1. A 5G-based intelligent portable WiFi traffic monitoring method, characterized in that: include: The traffic statistics module in the chipset of the first 5G smart portable WiFi device is used to capture data packets in real time using an adaptive sampling rate mechanism; wherein the adaptive sampling rate mechanism dynamically adjusts the frequency of data packet capture according to network load status and traffic characteristics; When the data packet flows through the key nodes of the kernel protocol stack, the flow data including timestamp, source and destination IP address, port number, protocol type, and data volume are extracted; Transmitting the traffic data to an edge computing node deployed locally on the first 5G smart portable WiFi device; Using a streaming processing framework to clean the traffic data in real time, remove duplicate, erroneous and invalid traffic records, compress and store the cleaned traffic data using a data compression algorithm, and standardize the compressed traffic data according to preset classification rules to generate a traffic data subset; Obtaining a flow identification result according to the flow data subset and a preset first flow identification model; When abnormal traffic is identified, a warning message is issued through multiple user interfaces associated with the device, and the built-in hierarchical traffic control mechanism of the first 5G smart portable WiFi device is activated to limit or block the abnormal traffic; Extracting abnormal traffic features and feeding them back to the first traffic identification model for model optimization; Allocate independent network slices for traffic monitoring to achieve service isolation, and automatically adjust slice configuration parameters based on smart contracts; Realize traffic data intercommunication between different operators through cross-chain interoperability mechanism; The traffic data, the traffic identification results and the warning records are encrypted by quantum encryption technology, and the encrypted data are packaged into blocks by using distributed ledger technology to construct a blockchain ledger containing a timestamp to achieve data tamper-proofing; Collect environmental data from surrounding IoT devices, integrate environmental data with traffic data for comprehensive analysis, and dynamically adjust traffic allocation strategies based on the analysis results.
2. The 5G-based smart portable WiFi traffic monitoring method according to claim 1 is characterized in that: The step of capturing data packets in real time by using an adaptive sampling rate mechanism through a traffic statistics module set in a chipset of the first 5G smart portable WiFi device includes: The initialization configuration step includes: setting a traffic statistics module in the chipset of the first 5G smart portable WiFi device; configuring initial sampling rate parameters in the traffic statistics module, including a reference sampling interval and a sampling window size; setting traffic thresholds, including a high load threshold and a low load threshold; initializing a sampling rate adjustment factor and an adjustment step size; The network status monitoring step includes: real-time monitoring of the network interface status of the first 5G smart portable WiFi device; obtaining the current network bandwidth utilization; detecting the length of the data packet queue; and recording the network delay and packet loss rate; The load evaluation step includes: calculating the network load index within the current time window; comparing the calculated load index with a preset threshold; determining whether the current network state is a high load, a normal load or a low load; and generating a load evaluation result; The sampling rate adaptive adjustment steps include: dynamically calculating the optimal sampling rate according to the load evaluation results; when the load is higher than the high load threshold, appropriately reducing the sampling rate to reduce system pressure; when the load is lower than the low load threshold, increasing the sampling rate to obtain more detailed traffic information; ensuring that the sampling rate is adjusted within the preset maximum and minimum ranges; The data packet capture step includes: setting a data packet filter at the network interface driver layer; sampling the passing data packets according to the current sampling rate; extracting the header information of the sampled data packets; recording the timestamp information of the data packets; Sampling optimization steps include: adopting differentiated sampling strategies for different types of network protocols; increasing sampling priority for key business traffic; adopting a predictive sampling mechanism for periodic traffic; and dynamically adjusting the sampling window size; Resource monitoring steps include: monitoring the CPU usage of the traffic statistics module; monitoring the memory buffer occupancy; triggering the protection mechanism when the system resources are close to the threshold; automatically adjusting the sampling parameters to balance the system load; The sampling quality assessment steps include: calculating representative indicators of sampling data; evaluating the accuracy of sampling results; analyzing sampling deviations; and generating a sampling quality report.
3. The 5G-based smart portable WiFi traffic monitoring method according to claim 2 is characterized in that: The step of using a streaming processing framework to clean the flow data in real time, removing duplicate, erroneous and invalid flow records, compressing and storing the cleaned flow data using a data compression algorithm, and standardizing the compressed flow data according to a preset classification rule to generate a flow data subset includes: The steps of initializing the streaming processing environment include: deploying the streaming processing framework on the edge computing node; configuring the data flow inlet and outlet nodes; setting the parallelism parameters of the data processing pipeline; initializing the data buffer and processing queue; The data stream access step includes: establishing a data transmission channel with the traffic statistics module; slicing the received traffic data and adding it to the processing queue; assigning a unique identifier to each data slice; and recording a data access timestamp; The real-time cleaning steps include: detecting and deleting duplicate data packet records: calculating the data packet feature hash value, using the sliding time window to make duplicate determinations, and retaining the earliest valid records; identifying and filtering erroneous data: verifying the integrity of the data packet, verifying the legitimacy of the protocol field, and checking the validity of the address format; eliminating invalid traffic records: filtering timed data packets, deleting incomplete session records, and removing data of abnormal length; The data compression steps include: classifying and packaging the cleaned data: grouping by protocol type, batch processing by time series, and establishing a data index structure; performing multi-level compression processing: first performing field-level compression, then performing block-level compression, and finally applying global compression; generating compression metadata: recording compression algorithm parameters, saving information required for decompression, and establishing a compressed data index; The standardization processing steps include: performing data format unification: unifying the timestamp format, standardizing address representation, and normalizing protocol identification; performing numerical normalization: calculating the statistical value of traffic characteristics, performing minimum-maximum normalization, and applying Z-score normalization; establishing a standardized mapping table: recording conversion parameters, saving normalization ranges, and maintaining feature mapping relationships; The steps of generating traffic data subsets include: classifying data according to preset rules: dividing based on time dimension, grouping according to protocol type, and clustering according to business characteristics; building data subset indexes: creating multidimensional index structures, establishing fast retrieval tables, and generating subset association relationships; optimizing subset storage structures: implementing incremental update mechanisms, designing cache strategies, and building hierarchical storage structures; Quality control steps include: real-time monitoring of processing quality: tracking data loss rate, monitoring processing delay, and evaluating compression efficiency; performing exception handling: detecting processing exceptions, triggering recovery mechanisms, and recording exception logs; generating quality reports: statistical processing indicators, analyzing performance bottlenecks, and providing optimization suggestions.
4. The 5G-based smart portable WiFi traffic monitoring method according to claim 3 is characterized in that: The method for constructing the first traffic identification model includes: The model initialization step includes: initializing the global model architecture on the central server side, including a convolutional neural network module and a recurrent neural network module; the convolutional neural network module is used to extract the spatial features of the traffic data, including multiple convolutional layers, pooling layers and fully connected layers; the recurrent neural network module is used to extract the temporal features of the traffic data, including LSTM or GRU units; distributing the initialized global model parameters to each 5G smart portable WiFi device participating in the training; The local training steps include: each 5G smart portable WiFi device performs model training based on the local traffic data set; uses batch normalization to process local data to eliminate data distribution differences between devices; uses differential privacy mechanisms to protect the privacy of the training process; and calculates the gradient update values of local model parameters. The parameter aggregation step includes: each 5G smart portable WiFi device encrypts and transmits the calculated gradient update value to the central server; the central server uses a weighted average algorithm to aggregate the gradient update values of all devices; updates the global model parameters; and distributes the updated global model parameters to each participating device; The model optimization steps include: setting up a dynamic learning rate adjustment mechanism to adaptively adjust the learning rate according to the training progress; introducing an early stopping mechanism to stop training when the model performance is no longer significantly improved; using Dropout technology to prevent model overfitting; using residual connections to optimize gradient propagation; The model evaluation steps include: evaluating the model performance on the validation data set; calculating the accuracy, recall rate, F1 score and other evaluation indicators; generating a confusion matrix to analyze the model prediction effect; deciding whether to continue training based on the evaluation results; and obtaining the first traffic recognition model; The anomaly detection steps include: inputting real-time traffic data into the trained model; extracting spatial features through convolutional neural networks; analyzing time series patterns through recurrent neural networks; and fusing two types of features to determine abnormal traffic. The model deployment steps include: converting the trained model into a lightweight format; deploying it to each 5G smart portable WiFi device; configuring model inference parameters; and starting the online anomaly detection service.
5. The 5G-based smart portable WiFi traffic monitoring method according to claim 4 is characterized in that: The step of issuing a warning message through multiple user interfaces associated with the device when abnormal traffic is identified, and activating the built-in hierarchical traffic control mechanism of the first 5G smart portable WiFi device to limit or block the abnormal traffic includes: The abnormal traffic feature extraction step includes: obtaining abnormal traffic data identified by the deep learning model; extracting key characteristic parameters of abnormal traffic: traffic surge magnitude and duration, abnormal number of connections and port usage, and data packet content characteristics; determining the hazard level of abnormal traffic; and generating an abnormal feature description report; The steps of generating early warning information include: constructing early warning information template according to the abnormal level; integrating the specific manifestations of abnormal traffic: abnormal type description, impact range assessment, potential risk analysis; generating early warning recommended measures; adding timestamp and unique identifier; Multi-interface warning push steps include: device display screen push: display warning icon, output warning sound, trigger indicator light flashing; mobile APP notification: send push notification, update APP interface status, display detailed abnormal information; Web management interface prompt: update dashboard status, display warning pop-up window, and provide detailed log viewing; The steps of initializing the hierarchical flow control mechanism include: establishing a flow control strategy table: defining control level thresholds, setting control action types, and configuring control durations; initializing the flow control module: loading control rules, setting priority orders, and preparing control resources; Traffic control execution steps include: mild exception handling: limit the bandwidth of suspicious IPs, reduce the priority of abnormal traffic, and record abnormal behavior; moderate exception handling: block specific port traffic, limit suspicious protocol traffic, and start traffic redirection; severe exception handling: disconnect abnormal connections, block related IP segments, and activate emergency response mechanisms; The control effect evaluation steps include: monitoring the traffic changes after control: analyzing the traffic decline trend, evaluating the bandwidth recovery situation, and checking whether the anomaly has been eliminated; recording the effect of the control measures: statistically analyzing the blocking success rate, calculating the response delay, and evaluating the misjudgment situation; generating a control effect report; The adaptive optimization steps include: dynamically adjusting strategies based on control effects: updating control rules, optimizing threshold settings, and adjusting control intensity; optimizing early warning mechanisms: improving early warning information content, adjusting push frequency, and optimizing display methods.
6. The 5G-based smart portable WiFi traffic monitoring method according to claim 5 is characterized in that: The steps of allocating independent network slices for traffic monitoring to achieve service isolation and automatically adjusting slice configuration parameters based on smart contracts include: The network slice initialization steps include: creating a network slice dedicated to traffic monitoring in the 5G core network: assigning slice identifiers, setting slice priorities, and defining slice resource quotas; configuring slice isolation parameters: setting resource isolation levels, configuring service isolation policies, and establishing security isolation mechanisms; initializing basic service quality parameters: configuring bandwidth limits, setting latency requirements, and defining reliability indicators; The smart contract deployment steps include: deploying the slice management smart contract in the blockchain network: writing the contract code, setting the trigger conditions, and defining the execution rules; initializing the contract parameters: configuring the adjustment threshold, setting the decision rules, and defining the reward and punishment mechanism; establishing the contract call interface: configuring the interface permissions, setting the call method, and defining the data format; Slice monitoring steps include: real-time collection of slice performance indicators: monitoring resource utilization, recording service quality parameters, and counting business traffic; analyzing slice operation status: evaluating performance trends, detecting anomalies, and predicting resource requirements; generating monitoring reports: summarizing performance data, marking abnormal events, and calculating health indicators; The steps of triggering a smart contract include: checking trigger conditions: judging performance thresholds, verifying time conditions, and confirming trigger permissions; collecting decision information: obtaining historical data, analyzing current status, and predicting future trends; executing contract logic: calculating adjustment plans, verifying feasibility, and recording the execution process; The slice parameter adjustment steps include: generating adjustment instructions: determining the adjustment items, calculating the adjustment range, and setting the execution time; executing parameter updates: modifying bandwidth configuration, adjusting priority settings, and updating resource quotas; verifying the adjustment effect: checking the effectiveness of parameters, monitoring performance changes, and evaluating the impact of adjustments; The steps of business migration include: preparing the migration environment: evaluating the target slice capacity, planning the migration path, and preparing the rollback plan; executing business migration: establishing data channels, transferring business traffic, and synchronizing status information; verifying the migration results: checking business continuity, confirming data integrity, and evaluating service quality; Continuous optimization steps include: collecting optimization data: statistical adjustment effects, analyzing performance improvements, and recording problem feedback; updating smart contracts: optimizing decision rules, adjusting trigger conditions, and improving execution logic; improving management strategies: optimizing resource allocation, updating isolation strategies, and improving security mechanisms.
7. The 5G-based smart portable WiFi traffic monitoring method according to claim 6 is characterized in that: The steps of realizing traffic data intercommunication between different operators through the cross-chain interoperability mechanism include: The steps of cross-chain network initialization include: deploying cross-chain protocols on each operator's node: configuring consensus mechanism, setting communication protocol, initializing key pair; establishing cross-chain gateway: deploying gateway node, configuring routing rules, setting security policy; initializing inter-chain communication channel: establishing P2P connection, configuring transmission protocol, setting bandwidth parameters; Data standardization steps include: formulating cross-chain data format specifications: defining data structure, standardizing field naming, and setting data types; establishing data mapping relationships: configuring field mapping, setting conversion rules, and defining verification methods; implementing data format conversion: processing data encoding, converting data formats, and verifying conversion results; The identity authentication steps include: deploying a distributed identity system: generating identity tags, configuring permission levels, and setting authentication rules; achieving multi-chain identity mutual recognition: exchanging identity credentials, verifying identity validity, and establishing trust relationships; managing access rights: setting access policies, controlling data permissions, and recording access logs; The steps of cross-chain data transmission include: initiating a data transmission request: constructing a transmission request, signing the request data, and selecting the target chain; executing cross-chain transmission: verifying the legitimacy of the request, encrypting the data packet, and transmitting the data content; confirming data reception: verifying data integrity, sending confirmation information, and recording the transmission status; Data consistency maintenance steps include: Implementing atomic operations: setting transaction boundaries, defining rollback mechanisms, and ensuring operation integrity; Maintaining data consistency: synchronizing data status, handling conflicts, and keeping data synchronized; Managing version control: recording version information, tracking data changes, and maintaining update history; The steps of cross-chain smart contract calls include: deploying cross-chain contracts: writing contract code, setting call rules, and configuring the execution environment; implementing contract interoperability: defining interface specifications, implementing call methods, and processing return results; managing contract status: synchronizing contract status, handling execution exceptions, and recording call logs; The performance optimization steps include: optimizing transmission efficiency: implementing data sharding, compressing transmission content, and optimizing routing selection; improving processing performance: processing requests in parallel, optimizing query efficiency, and implementing a caching mechanism; monitoring system performance: collecting performance indicators, analyzing bottleneck problems, and optimizing system configuration.
8. The 5G-based smart portable WiFi traffic monitoring method according to claim 7 is characterized in that: The steps of encrypting the traffic data, the traffic identification results and the warning records by using quantum encryption technology, packaging the encrypted data into blocks by using distributed ledger technology, and constructing a blockchain ledger containing a timestamp to achieve data tamper-proofing include: The quantum key distribution steps include: initializing the quantum key distribution system: configuring quantum communication equipment, establishing quantum channels, and setting key generation parameters; performing quantum key negotiation: generating quantum bit sequences, measuring quantum states, and performing basis vector verification; generating shared keys: performing error correction coding, performing key extraction, and verifying key availability; Data preprocessing steps include: arranging raw data: classifying traffic data, integrating traffic identification results, and summarizing warning records; building data structure: defining data format, setting field attributes, and establishing index relationships; generating data summaries: calculating hash values, adding timestamps, and recording data sources; The quantum encryption steps include: encrypting data based on quantum keys: selecting encryption algorithms, encrypting data in blocks, and generating ciphertext; performing integrity protection: calculating authentication codes, adding verification information, and generating signatures; managing key status: updating key usage status, recording key versions, and setting key validity periods; The steps of block construction include: Packing encrypted data: organizing block structure, setting block header, adding transaction content; generating block identifier: calculating block hash, linking previous block, recording block height; adding time proof: obtaining trusted timestamp, signing time proof, and verifying time validity; The consensus verification steps include: initiating a consensus request: broadcasting block information, submitting a verification request, and waiting for node responses; executing the consensus process: verifying block validity, checking data integrity, and confirming time sequence; reaching a consensus result: collecting verification results, counting consensus votes, and confirming block status; The ledger maintenance steps include: updating the blockchain status: adding new blocks, updating link relationships, and maintaining the status tree; managing data indexes: establishing retrieval tables, updating index structures, and optimizing query performance; performing ledger synchronization: broadcasting update information, synchronizing block data, and verifying synchronization results; The audit tracing steps include: providing a query interface: designing a query language, implementing retrieval methods, and configuring access permissions; supporting proof generation: building a proof path, generating verification proofs, and providing audit reports; maintaining historical records: recording operation logs, saving status snapshots, and supporting version backtracking.
9. The 5G-based smart portable WiFi traffic monitoring method according to claim 8 is characterized in that: The steps of collecting environmental data of surrounding IoT devices, integrating environmental data with traffic data for comprehensive analysis, and dynamically adjusting the traffic allocation strategy based on the analysis results include: Collect environmental data from surrounding IoT devices; Collect network traffic data, including user visits, data transmission rate, and latency; Fusing the collected environmental data with the flow data to form a comprehensive data set; Comprehensive analysis of the comprehensive data set, using data analysis algorithms to identify the relationship between environmental factors and flow changes; Dynamically adjust traffic distribution strategies based on comprehensive analysis results; Implement the adjusted traffic distribution strategy and continuously monitor its effect. Based on real-time feedback, optimize the traffic distribution strategy to adapt to the changing environment and user needs.
10. A 5G-based smart portable WiFi traffic monitoring system, used to execute the 5G-based smart portable WiFi traffic monitoring method according to any one of claims 1 to 9, characterized in that: include: The first 5G smart portable WiFi device, edge computing node and server equipped with a traffic statistics module; The traffic statistics module provided in the chipset of the first 5G smart portable WiFi device is configured as follows: Adopting an adaptive sampling rate mechanism to capture data packets in real time; wherein the adaptive sampling rate mechanism dynamically adjusts the frequency of data packet capture according to network load status and traffic characteristics; When the data packet flows through the key nodes of the kernel protocol stack, the flow data including timestamp, source and destination IP address, port number, protocol type, and data volume are extracted; Transmitting the traffic data to an edge computing node deployed locally on the first 5G smart portable WiFi device; The edge computing node is configured as: Using a streaming processing framework to clean the traffic data in real time, remove duplicate, erroneous and invalid traffic records, compress and store the cleaned traffic data using a data compression algorithm, and standardize the compressed traffic data according to preset classification rules to generate a traffic data subset; Obtaining a flow identification result according to the flow data subset and a preset first flow identification model; When abnormal traffic is identified, a warning message is issued through multiple user interfaces associated with the device, and the built-in hierarchical traffic control mechanism of the first 5G smart portable WiFi device is activated to limit or block the abnormal traffic; Extracting abnormal traffic features and feeding them back to the first traffic identification model for model optimization; Allocate independent network slices for traffic monitoring to achieve service isolation, and automatically adjust slice configuration parameters based on smart contracts; Realize traffic data intercommunication between different operators through cross-chain interoperability mechanism; The traffic data, the traffic identification results and the warning records are encrypted by quantum encryption technology, and the encrypted data are packaged into blocks by using distributed ledger technology to construct a blockchain ledger containing a timestamp to achieve data tamper-proofing; Collect environmental data from surrounding IoT devices, integrate environmental data with traffic data for comprehensive analysis, and dynamically adjust traffic allocation strategies based on the analysis results.
Citation Information
Patent Citations
Method and system for detecting and tracing malicious encrypted network traffic
CN115426137A
Multi-network hybrid acceleration method and system
CN117914790A
Data visualization network security detection method based on block chain
CN118826999A
Full-link monitoring method and system for state application in edge distribution scene
CN119127614A
Dynamic traffic scheduling method and system based on SD-WAN technology
CN119232666A
Cited By
Data security processing method and system
CN120415925A
Network load balancing algorithm based on credential platform and credential terminal
CN120474980A
Method for correspondingly managing IPV4 and IPV6 addresses of same user of network dual stacks
CN120729831A
Task collaborative management method and system based on offline application
CN120780424A
Energy data dynamic encryption method and system based on edge computing
CN120896748A