Elevator Internet of Things privacy protection method and system and electronic equipment
By dynamically adjusting the neural network pruning threshold, hierarchical scheduling communication and physical layer electromagnetic noise encryption, the computing efficiency and privacy protection of the elevator Internet of Things are optimized, and the problems of high computing load, large delay and privacy leakage in traditional solutions are solved, achieving efficient and secure elevator IoT data processing.
Patent Information
- Application Number
- CN202510757115.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-07-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the existing elevator IoT solutions, the traditional federated learning framework has too high computing load, inference delay exceeds the standard, privacy protection is insufficient, and centralized data processing has the risk of leakage, making it difficult to meet real-time and security requirements.
Parameter quantization and compression are performed by dynamically adjusting the neural network pruning threshold, hierarchically scheduling the federal communication protocol, combining homomorphic noise and differential privacy noise encryption, and physical layer electromagnetic noise generation dynamic key for encryption, optimize the privacy protection of the Internet of Things in the elevator.
It significantly reduces computing latency and communication overhead, improves computing speed and privacy protection capabilities, and realizes efficient and secure data transmission and processing of the elevator Internet of Things.
Smart Images

Figure CN120281579A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to privacy protection in the elevator Internet of Things, and particularly to a method, system, and electronic device for privacy protection in the elevator Internet of Things. Background Art
[0002] In the field of the elevator Internet of Things, federated learning technology has been gradually applied to collaborative analysis of multi-source data to improve fault detection capabilities. However, existing solutions have significant drawbacks: First, the traditional federated learning framework model has a large number of parameters, resulting in too high a computational load and an inference delay exceeding 300 ms when deployed on elevator edge devices, making it difficult to meet real-time requirements. Second, the privacy protection requirements for elevator multimodal data (such as vibration, video, and audio) vary significantly. Existing encryption methods are not optimized for the characteristics of sensor data, and it is difficult to balance efficiency and security with a general encryption strategy. In addition, there is a lack of protection for physical layer security during the data interaction process, and attackers can steal keys or reverse-infer sensitive information through electromagnetic side channels. More critically, the centralized data processing architecture leads to a risk of leakage of user behavior data (such as elevator riding records), and the limited resources of edge devices make the energy consumption and computing power requirements of traditional federated learning mismatched, seriously restricting the large-scale application of this technology in elevator scenarios. Summary of the Invention
[0003] To solve the above problems, the present invention provides a method, system, and electronic device for privacy protection in the elevator Internet of Things.
[0004] The present invention provides the following technical solutions: A method for privacy protection in the elevator Internet of Things includes the following steps: S1. Collect the real-time load of the elevator, dynamically adjust the neural network pruning threshold based on the real-time load of the elevator, and perform parameter quantization and compression on the local federated learning model; S2. According to the elevator operation stage and data priority, hierarchically schedule the federated communication protocol. The data priority is divided into high-priority data and low-priority data; the high-priority data is transmitted in real time, and the low-priority data is batch-encrypted and transmitted with a delay; S3. Add homomorphic noise to the gradient data during the local training stage, inject differential privacy noise during the cloud aggregation stage, and generate a dynamic key based on the electromagnetic noise of the elevator motor for physical layer encryption.
[0005] Further, the step of dynamically adjusting the neural network pruning threshold includes: (1) Collect the current load value of the elevator and calculate the load impact factor λ: ; where k is an adjustment coefficient with a value range of 1.5 to 3.0; current_load is the current load, and max_load is the designed maximum load; (2)Dynamically calculate the neural network pruning threshold threshold according to the load impact factor: ; Among them, α is the basic threshold (0.1 ≤ α ≤ 0.3), and β is the weight coefficient (0.4 ≤ β ≤ 0.6).
[0006] Thus, the number of model parameters is reduced by 30% - 70%, and the inference delay is reduced from 300ms to less than 50ms.
[0007] Hybrid quantization strategy: Use 8-bit fixed-point quantization for the fully connected layer, and retain 16-bit floating-point precision for the convolutional layer to balance computational efficiency and model accuracy.
[0008] Furthermore, the hierarchical scheduling federated communication protocol includes: The allocated bandwidth ratio in the uplink phase ≥ the first threshold (generally taken as 60%, which can also be adjusted as needed), the allocated bandwidth ratio in the docking phase ≥ the second threshold (generally taken as 60%, which can also be adjusted as needed), and the allocated bandwidth ratio in the downlink phase ≤ the third threshold (generally taken as 40%, which can also be adjusted as needed);
[0009] Mark the elevator vibration frequency and door switch timeout event as high-priority data, and the transmission interval ≤ the fourth threshold (generally taken as 1 second, which can also be adjusted as needed); Mark the normal operating temperature and energy consumption data as low-priority data, and the transmission interval ≥ the fifth threshold (generally taken as 5 minutes, which can also be adjusted as needed); Furthermore, the addition of the homomorphic noise satisfies: The noise variance is positively correlated with the data sensitivity, and the noise variance σ of sensitive data (such as elevator ride records) ≥ the sixth threshold (generally taken as 0.2, which can also be adjusted as needed); The noise distribution follows a Gaussian distribution N(0,σ 2 ), and is linearly superimposed with the gradient data.
[0010] Furthermore, the steps of the physical layer encryption include: Collect the electromagnetic noise waveform during the operation of the elevator motor through a Hall sensor; Perform a fast Fourier transform on the noise waveform to extract spectral features and generate a random number seed; Use an encryption algorithm to iteratively generate a dynamic session key, and the key update period ≤ the seventh threshold (generally taken as 10 seconds, which can also be adjusted as needed). The encryption algorithm can use the SHA-256 hash chain or other algorithms.
[0011] An elevator Internet of Things privacy protection system, including: Edge computing module: It is used to collect the real-time load of the elevator, dynamically adjust the neural network pruning threshold based on the real-time load of the elevator, and perform parameter quantization and compression on the local federated learning model; Communication scheduling module: It is used to hierarchically schedule the federated communication protocol according to the elevator operation stage and data priority. The data priority is divided into high-priority data and low-priority data; high-priority data is transmitted in real time, and low-priority data is batch-encrypted and transmitted with a delay; Privacy protection module: It is used to add homomorphic noise to the gradient data in the local training stage, inject differential privacy noise in the cloud aggregation stage, and generate a dynamic key based on the electromagnetic noise of the elevator motor for physical layer encryption.
[0012] Furthermore, the edge computing module further includes: an elevator vertical motion feature extraction sub-module (VFE), which adopts a hybrid architecture of gated convolutional neural network (Gated CNN) and bidirectional LSTM, and is used to capture the frequency domain features of car acceleration and guide rail vibration.
[0013] Furthermore, the physical key generator is specifically implemented as: An electromagnetic noise acquisition circuit with a sampling rate ≥ the eighth threshold (usually 100kHz, which can also be adjusted according to needs); A real-time spectrum analysis unit that extracts the characteristic peak in the frequency band of the ninth threshold (usually 1kHz - 10MHz, which can also be adjusted according to needs) as the entropy source; A key derivation function (KDF) module that supports iterative generation of session keys using encryption algorithms. The encryption algorithm can use HMAC-SHA256 or other algorithms.
[0014] Furthermore, the communication scheduling module supports: Protocol adaptation for multi-brand elevator controllers, including automatic conversion of OTAP protocol and Modbus protocol; Enable local caching when communication is interrupted, and encrypt and store data ≥ the tenth threshold (usually 72 hours, which can also be adjusted according to needs).
[0015] Furthermore, the privacy protection module satisfies: The addition of gradient obfuscation noise is completed at the edge node, and the noise parameters are periodically sent from the cloud; The differential privacy parameters (ε, δ) are dynamically adjusted according to the data category. For fault data, ε ≤ the eleventh threshold (usually 0.3, which can also be adjusted according to needs), and for regular data, ε ≤ the twelfth threshold (usually 1.0, which can also be adjusted according to needs).
[0016] An electronic device, including: One or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned method.
[0017] A computer-readable storage medium having computer instructions stored thereon, which when executed by a processor implement the steps of the above method.
[0018] The beneficial effects of the present invention are as follows: (1) By dynamically adjusting the neural network pruning threshold, parameter quantization and compression of the local federated learning model are performed, improving the computing speed; (2) By hierarchical scheduling of the federated communication protocol, bandwidth resources are reasonably allocated to ensure efficient data transmission; (3) Privacy protection of the elevator Internet of Things is enhanced through physical layer encryption. Description of the Drawings
[0019] Figure 1 It is a flowchart of the method for protecting the privacy of the elevator Internet of Things according to the present invention; Figure 2 It is a module diagram of the system for protecting the privacy of the elevator Internet of Things according to the present invention. Detailed Embodiments
[0020] To further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following describes in detail the specific embodiments, structures, features and their effects of the present invention in conjunction with the accompanying drawings and preferred embodiments.
[0021] Through the optimization of the lightweight federated learning framework and the multi-layer privacy protection mechanism adapted to the elevator scenario, dual guarantees of distributed collaborative training and privacy security of elevator operation data are achieved.
[0022] The following further describes the embodiments of the present invention in multiple embodiments.
[0023] Embodiment 1 Such as Figure 1 , a method for protecting the privacy of the elevator Internet of Things, including the following steps: S1. Collect the real-time load of the elevator, dynamically adjust the neural network pruning threshold based on the real-time load of the elevator, and perform parameter quantization and compression on the local federated learning model; S2. According to the elevator operation stage and data priority, hierarchically schedule the federated communication protocol, and transmit the high-priority fault features in real time, and delay the transmission of the low-priority data after batch encryption; S3. Add homomorphic noise to the gradient data in the local training stage, inject differential privacy noise in the cloud aggregation stage, and generate a dynamic key based on the electromagnetic noise of the elevator motor for physical layer encryption.
[0024] The addition of homomorphic noise satisfies the following: The noise variance is positively correlated with the data sensitivity. For sensitive data (such as elevator riding records), the noise variance σ ≥ 0.2; The noise distribution follows a Gaussian distribution N(0, σ 2 ), and is linearly superimposed with the gradient data.
[0025] Specifically, 1. Local gradient obfuscation stage (edge node): (1) Noise generation and superposition: Gaussian noise is dynamically generated according to the sensitivity of the gradient data. The noise variance is positively correlated with the gradient standard deviation. The Gaussian noise is calculated by the formula: ; where the noise g i follows a Gaussian distribution N(0, σ 2 ), and for sensitive data (such as elevator riding records), the noise variance requirement is σ ≥ 0.2; the std() function is used to calculate the standard deviation; (2) Encrypted transmission: The obfuscated gradient data is encrypted by AES-256 and transmitted to the edge gateway through a TLS 1.3 secure channel to ensure the security of the transmission process.
[0026] 2. Inject differential privacy noise in the cloud aggregation stage. After the cloud server receives the encrypted gradients, it performs differential privacy protection and global model update: (1) Noise injection: Laplace noise is injected during cloud aggregation to meet the (ϵ, δ)-differential privacy requirement (by default, ϵ = 0.3, δ = 1e−5). The aggregation formula is: ; S is the gradient sensitivity, and N is the number of participating devices.
[0027] 3. Physical layer dynamic encryption (end-to-end protection): Use the electromagnetic noise (frequency band 10 kHz - 1 MHz) generated during the operation of the elevator motor as an entropy source, perform a fast Fourier transform (FFT) on the noise spectrum, extract the characteristic peak value as a random number seed, and use the SHA-256 hash chain to iteratively generate a dynamic session key: ; The key update period ≤ 10 seconds to prevent the risk of long-term key leakage.
[0028] (2) Privacy budget allocation: The superposition of local Gaussian noise and cloud Laplace noise needs to meet the total privacy budget constraint. The linear superposition of the two noises still satisfies (ϵ, δ)-differential privacy, where the local noise variance and the cloud noise scale parameter need to be allocated proportionally.
[0029] The steps for dynamically adjusting the neural network pruning threshold include: (1) Collect the current load value of the elevator and calculate the load impact factor: ; where k is an adjustment coefficient with a value range of 1.5 to 3.0; current_load is the current load, and max_load is the designed maximum load; (2) Dynamically calculate the pruning threshold according to the load impact factor: threshold = α + β × λ where α is the basic threshold (0.1 ≤ α ≤ 0.3), and β is the weight coefficient (0.4 ≤ β ≤ 0.6).
[0030] By dynamically adjusting the neural network pruning threshold, parameter quantization and compression of the local federated learning model are performed, improving the calculation speed.
[0031] The hierarchical scheduling federated communication protocol includes: Mark the elevator vibration frequency and door switch timeout event as high-priority data, and the transmission interval ≤ 1 second; Mark the normal operating temperature and energy consumption data as low-priority data, and the transmission interval ≥ 5 minutes; Dynamically allocate communication bandwidth based on the elevator running direction (up / down), and the bandwidth allocation ratio in the up phase ≥ 60%.
[0032] The data hierarchical transmission mechanism is specifically shown in Table 1: Table 1 Data Hierarchical Transmission Mechanism Table:
[0033] Bandwidth dynamic allocation algorithm: Adjust the data transmission bandwidth according to the elevator running stage (up / down / stopping): Up phase: Allocate 60% of the bandwidth to the vibration sensor data; Stopping stage: Allocate 60% of the bandwidth to the transmission of key frames of the video stream.
[0034] Technical effect: The overall communication overhead is reduced by 45%, and the network utilization rate is increased to 92%.
[0035] Through the hierarchical scheduling federated communication protocol, bandwidth resources are reasonably allocated to ensure efficient data transmission.
[0036] The steps for physical layer encryption include: Collect the electromagnetic noise waveform during the operation of the elevator motor through a Hall sensor; Perform a fast Fourier transform on the noise waveform to extract spectral features and generate a random number seed; Use the SHA-256 hash chain to iteratively generate a dynamic session key, and the key update period ≤ 10 seconds.
[0037] Such as Figure 2 , an elevator Internet of Things privacy protection system, including: Edge computing module: used to collect the real-time load of the elevator, dynamically adjust the neural network pruning threshold based on the real-time load of the elevator, and perform parameter quantization and compression on the local federated learning model; Communication scheduling module: According to the elevator operation stage and data priority, hierarchically schedule the federated communication protocol. The data priority is divided into high-priority data and low-priority data; high-priority data is transmitted in real time, and low-priority data is encrypted in batches and transmitted with a delay; Privacy protection module: used to add homomorphic noise to the gradient data during the local training stage, inject differential privacy noise during the cloud aggregation stage, and generate a dynamic key based on the electromagnetic noise of the elevator motor for physical layer encryption.
[0038] The edge computing module further includes: A hybrid architecture of a gated convolutional neural network (Gated CNN) and a bidirectional LSTM; Elevator vertical motion feature extraction sub-module (VFE), used to capture the frequency domain features of car acceleration and guide rail vibration.
[0039] The physical key generator is specifically implemented as: Electromagnetic noise acquisition circuit, sampling rate ≥ 100kHz; Real-time spectrum analysis unit, extracting the characteristic peak in the 1kHz - 10MHz frequency band as the entropy source; Key derivation function (KDF) module, supporting the HMAC-SHA256 algorithm to iteratively generate a session key.
[0040] The communication scheduling module supports: Protocol adaptation of multi-brand elevator controllers, including automatic conversion of OTAP protocol and Modbus protocol; Enable local caching when the communication is interrupted, and encrypt and store data ≥ 72 hours.
[0041] The privacy protection module satisfies: The addition of gradient obfuscation noise is completed at the edge node, and the noise parameters are periodically sent from the cloud; The differential privacy parameters (ε, δ) are dynamically adjusted according to the data category, ε ≤ 0.3 for fault data, and ε ≤ 1.0 for regular data.
[0042] The electromagnetic noise of the elevator motor is true random data, and the privacy protection of the elevator Internet of Things is strengthened through physical layer encryption based on the electromagnetic noise of the elevator motor.
[0043] In this embodiment, the training of the elevator anomaly detection federated model includes: (1) Hardware deployment Edge node: Equipped with NVIDIA Jetson Xavier NX (computing power 21 TOPS); Cloud server: Configured with dual Intel Xeon CPUs + 4 × A100 GPUs, and an aggregation server and a key management module are deployed.
[0044] (2) Data processing flow Step 1: Data collection and preprocessing 1) Vibration sensor: Sampling rate 10 kHz, extract frequency domain features (FFT transformation); 2) Camera: Extract 5 key frames per second (resolution 640 × 480), and use MobileNetV3 to extract features; The video stream metadata is encrypted through an XOR mask, and the mask key is dynamically generated by physical noise and updated every 30 minutes.
[0045] 3) Microphone: Segment the audio (each segment is 2 s), and extract MFCC features.
[0046] Step 2: Local model training 1) Model architecture: Lightweight CNN (4-layer convolution) + LSTM (2-layer) hybrid network; 2) Loss function: Weighted cross-entropy (weight the rare fault category by 3 times); 3) Optimizer: AdamW (learning rate 0.001, weight decay 1e-4).
[0047] Step 3: Upload security parameters 1) Elevator terminal → Edge gateway: Send encrypted gradients (AES-256 + homomorphic noise); 2) Edge gateway → Cloud server: Aggregate gradients and add Laplace noise; 3) Cloud server → Elevator terminal: Send down the updated global model.
[0048] An electronic device includes: One or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described above.
[0049] In the embodiments provided in this application, it should be understood that the disclosed method and system can also be implemented in other ways. The method and system embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions, and operations of the method, system, method, and computer program product according to multiple embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0050] In addition, in each embodiment of this application, the various functional modules can be integrated together to form an independent part, or each module can exist separately, or two or more modules can be integrated to form an independent part.
[0051] On the other hand, a computer-readable storage medium stores computer instructions, and when the instructions are executed by a processor, the steps of the above-mentioned method are implemented. When the computer program is executed by a processor, the method of any one of the above first aspects is implemented. If the function is implemented in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory 101 (ROM, Read-Only Memory), random access memory 101 (RAM, Random Access Memory), magnetic disks, or optical discs that can store program code.
[0052] The above are only the preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Although the present invention has been disclosed above with the preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some changes or modifications to equivalent embodiments with equivalent changes within the scope of the technical solution of the present invention. However, as long as it does not depart from the content of the technical solution of the present invention, any brief modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention still fall within the scope of the technical solution of the present invention.
Claims
1. An elevator Internet of Things privacy protection method, characterized in that, It includes the following steps: S1. Collect the real-time load of the elevator, dynamically adjust the neural network pruning threshold based on the real-time load of the elevator, and perform parameter quantization and compression on the local federated learning model; S2. According to the elevator operation stage and data priority, hierarchically schedule the federated communication protocol. The data priority is divided into high-priority data and low-priority data; high-priority data is transmitted in real time, and low-priority data is batch-encrypted and transmitted with a delay; S3. Add homomorphic noise to the gradient data in the local training stage, inject differential privacy noise in the cloud aggregation stage, and generate a dynamic key based on the electromagnetic noise of the elevator motor for physical layer encryption.
2. The method according to claim 1, wherein The step of dynamically adjusting the neural network pruning threshold includes: (1) Collect the current load value of the elevator and calculate the load impact factor λ: ; where k is an adjustment coefficient; current_load is the current load, and max_load is the designed maximum load; (2) Dynamically calculate the neural network pruning threshold threshold according to the load impact factor: ; where α is the basic threshold and β is the weight coefficient.
3. The method according to claim 1, characterized in that, The hierarchically scheduled federated communication protocol includes: Dynamically allocate communication bandwidth based on the elevator operation stage. The elevator operation stage is divided into the upward stage and the downward stage. The bandwidth allocation ratio in the upward stage is ≥ the first threshold, the bandwidth allocation ratio in the docking stage is ≥ the second threshold, and the bandwidth allocation ratio in the downward stage is ≤ the third threshold; Mark the elevator vibration frequency and door switch timeout event as high-priority data, and the transmission interval is ≤ the fourth threshold; Mark the normal operating temperature and energy consumption data as low-priority data, and the transmission interval is ≥ the fifth threshold.
4. The method according to claim 1, wherein The addition of the homomorphic noise satisfies: the noise variance is positively correlated with the data sensitivity, and the noise variance σ of the sensitive data is ≥ the sixth threshold.
5. The method according to claim 1, characterized in that, The step of physical layer encryption includes: Collect the electromagnetic noise waveform during the operation of the elevator motor through a Hall sensor; Perform a fast Fourier transform on the noise waveform to extract spectral features and generate a random number seed; Use an encryption algorithm to iteratively generate a dynamic session key, and the key update period is ≤ the seventh threshold.
6. An elevator Internet of Things privacy protection system, characterized in that, It includes: Edge computing module: used to collect the real-time load of the elevator, dynamically adjust the neural network pruning threshold based on the real-time load of the elevator, and perform parameter quantization and compression on the local federated learning model; Communication scheduling module: used to hierarchically schedule the federated communication protocol according to the elevator operation stage and data priority. The data priority is divided into high-priority data and low-priority data; high-priority data is transmitted in real time, and low-priority data is batch-encrypted and transmitted with a delay; Privacy protection module: used to add homomorphic noise to the gradient data in the local training stage, inject differential privacy noise in the cloud aggregation stage, and generate a dynamic key based on the electromagnetic noise of the elevator motor for physical layer encryption.
7. The system according to claim 6, wherein The edge computing module further includes: an elevator vertical motion feature extraction sub-module, used to capture the car acceleration and the vibration frequency domain feature of the guide rail.
8. The system according to claim 6, wherein The physical key generator is specifically implemented as: Electromagnetic noise acquisition circuit, with a sampling rate ≥ the eighth threshold; Real-time spectrum analysis unit, extracting the feature peak of the ninth threshold frequency band as the entropy source; Key derivation function module, supporting the encryption algorithm to iteratively generate the session key.
9. The system according to claim 6, wherein The communication scheduling module supports: Protocol adaptation of multi-brand elevator controllers, including automatic conversion between OTAP protocol and Modbus protocol; Enable local cache during communication interruption, and encrypt and store data ≥ the tenth threshold.
10. The system according to claim 6, wherein The privacy protection module satisfies: The addition of gradient obfuscation noise is completed at the edge node, and the noise parameters are periodically sent from the cloud; The differential privacy parameters (ε, δ) are dynamically adjusted according to the data category, ε of fault data ≤ the eleventh threshold, and ε of regular data ≤ the twelfth threshold.
11. An electronic device, characterized in that, including: One or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-5.
12. A computer-readable storage medium having computer instructions stored thereon, characterized in that, When the instruction is executed by the processor, it implements the steps of the method according to any one of claims 1-5.
Citation Information
Patent Citations
Private data protection method and system based on homomorphic encryption and federated learning
CN119513919A