A cloud platform scheduling method and system based on multi-source IoT perception

By building a dynamically adjustable sensor topology network and a multi-dimensional coupling model, the network complexity and resource waste problems caused by the growth of the number of IoT devices are solved, the efficient use of cloud platform resources and data security are achieved, and the security and integrity of IoT perception data are ensured.

CN120281821BActive Publication Date: 2025-09-26JIEYANG HUAXUN NETWORK SERVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510507614.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-09-26
Estimated Expiration
2045-04-22

AI Technical Summary

Technical Problem

Traditional cloud platforms find it difficult to cope with the network topology complexity, resource waste and task execution delays caused by the explosive growth in the number of IoT devices, and it is difficult to ensure the security and integrity of multi-source IoT perception data.

Method used

Build a dynamically adjustable sensor topology network, adopt AES symmetric encryption protocol and dynamic key distribution, integrate core indicators in real time to establish a multi-dimensional coupling model, generate a dynamic priority matrix, perform security-aware partitioning management of encrypted computing resources, and implement fine-grained security isolation and closed-loop control.

Benefits of technology

It achieves efficient use of resources, prevents data leakage, maintains system performance and stability, and adapts to dynamically changing loads and security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281821B_ABST
    Figure CN120281821B_ABST
Patent Text Reader

Abstract

The present invention discloses a cloud platform scheduling method and system based on multi-source Internet of Things perception, relating to the field of cloud platform scheduling technology. The method comprises: constructing a dynamically adjustable sensor topology network, optimizing node communication paths, and adopting an AES symmetric encryption protocol to distribute real-time dynamic keys and synchronize topology updates; integrating core indicators in real time and establishing a multi-dimensional coupling model to generate a dynamic priority matrix; quantitatively analyzing the coupling relationship of the core indicators based on the dynamic priority matrix; performing security-aware dynamic partitioning management of encrypted computing resources based on historical data and real-time monitoring information, and dynamically allocating encrypted computing resources; constructing a closed-loop security control framework from the edge to the cloud, ensuring data flow security through end-to-end encrypted transmission, utilizing secure partitioning of encrypted computing resources to prevent cross-task interference, completing the fusion of multimodal data, and forming a closed-loop control mechanism with real-time feedback adjustment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud platform scheduling technology, and in particular to a cloud platform scheduling method and system based on multi-source Internet of Things perception. Background Art

[0002] With the development of the Internet of Things (IoT), the number of connected devices connected to cloud platforms has exploded. These devices are diverse, encompassing a wide range of sensors and smart terminals. Their performance, communication capabilities, and data generation rates vary significantly, resulting in complex and dynamically changing network topologies. This makes traditional static network topologies and fixed resource allocation strategies difficult to implement, easily leading to network congestion, resource waste, and task execution delays.

[0003] At the same time, the massive data generated by multi-source IoT perception contains a lot of sensitive information, such as personal privacy data and commercial confidential data, which faces security risks such as data leakage and tampering during the data transmission and processing stages. Different types of data have different security level requirements, and there is an urgent need for flexible and efficient security mechanisms to ensure data security and integrity.

[0004] Cloud platforms need to process a large number of tasks from numerous IoT devices. These tasks vary in priority, resource requirements, and execution time. Traditional resource scheduling methods are unable to fully consider the diversity and dynamics of tasks, and cannot achieve optimal resource allocation, which in turn causes system performance degradation and low resource utilization. Summary of the Invention

[0005] The purpose of the present invention is to provide a cloud platform scheduling method and system based on multi-source Internet of Things perception to solve the problems raised in the prior art.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a cloud platform scheduling method based on multi-source IoT perception, the method comprising:

[0007] Build a dynamically adjustable sensor topology network, optimize node communication paths, and use the AES symmetric encryption protocol for real-time dynamic key distribution and topology synchronization update mechanism. When the network topology increases or decreases nodes or the link quality changes, key updates and path reconstruction are automatically triggered.

[0008] Real-time integration of core indicators and establishment of a multi-dimensional coupling model to generate a dynamic priority matrix; the core indicators include data confidentiality level, real-time traffic forecast, and device health status; based on the dynamic priority matrix, quantitative analysis of the coupling relationship of the core indicators, classification of tasks into different risk levels, and generation of scheduling queues;

[0009] Based on historical data and real-time monitoring information, load change trends are predicted, and dynamic partition management and allocation of encryption computing resources are performed with security awareness.

[0010] Build a closed-loop security control architecture from the edge to the cloud, complete data desensitization and spatiotemporal alignment at the edge nodes, and implement fine-grained encrypted computing resource scheduling and security isolation at the platform level; ensure data flow security through end-to-end encrypted transmission, complete multimodal data fusion through secure partitioning of encrypted computing resources, and form a closed-loop control mechanism with real-time feedback adjustment.

[0011] According to the above solution, the construction of a dynamically adjustable sensor topology network includes:

[0012] A distributed consensus algorithm is used to synchronize the topological states between nodes. The optimal communication path is dynamically calculated based on link quality indicators, including signal strength, round-trip delay, and packet loss rate. The dynamic weight coefficient of each link and the optimal communication path are calculated using the following formula:

[0013] ;

[0014] Among them, W ij Expressed as the dynamic weight coefficient of the link from node i to node j; S ij It is represented by the signal strength of the link from node i to node j; D ij The round-trip delay of the data packet from node i to node j; L ij It is represented as the packet loss rate of the link from node i to node j; a, b and c are weighted coefficients, and a+b+c=1, which are used to adjust the importance of the link quality indicator;

[0015] Assign an independent AES symmetric encryption protocol encryption session key to each communication link and establish a mapping table between the key version number and the topology version number;

[0016] When a node failure is detected, the failure status is confirmed, and the adjacent nodes initiate local topology reconstruction and synchronously update the encryption session keys of the affected links; when a new node is detected, the validity of the node is verified through a two-way authentication mechanism, and a temporary encryption session key is assigned to the node. After completing the topology synchronization, the formal encryption session key is generated.

[0017] According to the above solution, the establishment of the multi-dimensional coupling model includes:

[0018] The data confidentiality level is quantitatively graded and assigned differentiated weight coefficients. The real-time traffic prediction includes predicting the network traffic load change trend in the future period through time series analysis. The device health status includes CPU usage, memory occupancy, battery remaining power, and device temperature.

[0019] A combined weighted algorithm is used to integrate the core indicators into a unified risk assessment value. The formula is as follows:

[0020] Score=α×C+β×(1-F)+γ×H+P_base;

[0021] Among them, Score represents the risk assessment value; C represents the data confidentiality level; α represents the data confidentiality level weight coefficient; F represents the real-time traffic prediction value; β represents the real-time traffic prediction value weight coefficient; H represents the equipment health status; γ represents the equipment health status weight coefficient; P_base represents the task basic risk assessment value;

[0022] The risk assessment values ​​are divided into risk levels of extremely low risk Q4, low risk Q3, medium risk Q2, high risk Q1 and extremely high risk Q0; different risk levels correspond to different encryption computing resource allocation strategies.

[0023] According to the above solution, the dynamic priority matrix includes:

[0024] Establish a mapping relationship between task types and core indicators, divide tasks into corresponding priority levels based on risk assessment values, and configure corresponding encryption computing resource preemption strategies and scheduling delay constraints for each priority level to form a multi-level scheduling queue with dynamic adjustment capabilities;

[0025] The multi-level scheduling queue includes: using a hybrid data structure of priority and time limit queues to manage task queues; recalculating the risk assessment value and priority level of each task every 5 minutes; setting up a priority promotion mechanism: when the waiting time of a task exceeds 80% of its time requirement, the priority is automatically increased by one level; high-priority tasks that are continuously executed for more than 3 scheduling cycles are automatically lowered in priority; and reserving a minimum guaranteed resource quota for high-risk and extremely high-risk tasks, which are not affected by priority scheduling.

[0026] According to the above solution, the security-aware dynamic partition management includes:

[0027] Analyze historical load data and, in combination with real-time monitored CPU utilization, memory occupancy, and network throughput indicators, predict the changing trend of encryption computing resource requirements for each computing unit; dynamically allocate encryption computing resources based on the risk assessment value and the changing trend of encryption computing resource requirements for each computing unit;

[0028] Implement security-aware dynamic partition management for encrypted computing resources, dividing them into multiple securely isolated security partitions, setting dynamic encryption computing resource quotas and access control policies for each security partition, and implementing differentiated encryption computing resource allocation based on risk levels;

[0029] The dynamic encryption calculation resource quota is calculated as follows:

[0030] Q ad =max(Q min ,Q in ×e -λ×R );

[0031] Among them, Q ad Indicates the adjusted security partition encryption computing resource quota; Q min Indicates the minimum guaranteed encryption computing resource quota for the security partition; Q in It is represented by the initial encryption computing resource quota; R is represented by the overall resource tension coefficient; λ is represented by the attenuation factor;

[0032] The security partitions include a high-security partition, a medium-security partition, and a general-purpose partition; the high-security partition handles high-risk and extremely high-risk tasks, the medium-security partition handles medium-risk tasks, and the general-purpose partition handles extremely low-risk and low-risk tasks;

[0033] Set dynamic resource quotas for each partition, including:

[0034] The high-security partition is initially allocated 40% of the encryption computing resources, with a minimum guarantee of 20% of the encryption computing resources; the medium-security partition is initially allocated 35% of the encryption computing resources, with a minimum guarantee of 15% of the encryption computing resources; the general partition is initially allocated 25% of the encryption computing resources, with no minimum guarantee.

[0035] According to the above solution, the dynamic allocation of encryption computing resources includes:

[0036] Real-time monitoring of encryption computing resource utilization indicators of each partition, wherein the encryption computing resource utilization indicators include encryption operation throughput, key exchange latency, and computing unit load rate;

[0037] Differentiated encryption computing resource allocation is implemented based on risk levels. When it is detected that the utilization rate of encryption computing resources in the general partition is lower than the threshold, idle encryption computing resources will be recycled to the shared resource pool. When recycling idle encryption computing resources, it is necessary to ensure that the minimum guaranteed quota of the high-security partition is not affected.

[0038] According to the above solution, the data desensitization and spatiotemporal alignment are completed at the edge node, including:

[0039] The data desensitization includes implementing differentiated desensitization according to the risk level, establishing a mapping relationship between the desensitization level and the risk level, and dynamically adjusting the desensitization intensity;

[0040] The spatiotemporal alignment includes establishing a unified time base and spatial coordinate system, generating standardized spatiotemporal stamp metadata, and constructing a spatiotemporal index structure. The spatiotemporal index structure includes data aggregation of the same time window, data association of spatially adjacent nodes, and fast retrieval of spatiotemporal composite conditions.

[0041] Implement desensitizing integrity verification, detect spatiotemporal anomaly data, and maintain data traceability and tracking records.

[0042] According to the above solution, the implementation of fine-grained encryption computing resource scheduling and security isolation at the platform level includes:

[0043] The encryption computing resource scheduling includes triggering an encryption computing resource preemption strategy when the encryption computing resource demand of the task of the high-security partition exceeds the encryption computing resource quota. The encryption computing resource preemption strategy includes giving priority to allocating encryption computing resources in the shared resource pool. When the encryption computing resources in the shared resource pool are insufficient, the encryption computing resources of the task of the general partition are released. In the process of releasing the encryption computing resources, it is ensured that the encryption computing resource quota of the task of the high-security partition is not affected. After the preemption strategy is implemented, the preemption operation is recorded. The preemption operation includes the risk level of the preempted task, the amount of encryption computing resources released, the timestamp and the automatic recovery time.

[0044] The security isolation includes creating an operating environment with an independent security domain for each task based on risk assessment values ​​and real-time monitoring information, configuring fine-grained encryption computing resource access control policies, and the access control policies include encryption computing resource access rights, data read and write ranges, and communication whitelists; building a cross-task security isolation barrier to prevent unauthorized access and data leakage between tasks.

[0045] According to the above solution, the closed-loop control mechanism of real-time feedback adjustment includes:

[0046] Continuously collect topological network status, encryption computing resource utilization, and task queue backlogs, and trigger adaptive adjustments when abnormal conditions are detected; abnormal conditions include key exchange delay exceeding the maximum threshold, encryption computing resource demand exceeding the encryption computing resource quota, and queue task waiting time exceeding the maximum waiting threshold; adaptive adjustments include dynamic allocation of encryption computing resources, dynamic partition management, and dynamic adjustment of the optimal communication path;

[0047] The weighted algorithm parameters are iteratively optimized through a periodic optimization algorithm to adapt to dynamically changing loads and safety requirements.

[0048] A cloud platform scheduling system based on multi-source IoT perception, the system includes: a secure networking module, an intelligent scheduling module, a resource management module, an edge processing module and a security control module;

[0049] The secure networking module includes a topology optimization module, a key management module, and a self-healing control module. The topology optimization module synchronizes the topology status between nodes through a distributed consensus algorithm and dynamically calculates the optimal communication path based on link quality indicators. The key management module is used to allocate independent AES symmetric encryption protocol encryption session keys and establish a mapping relationship table between key version numbers and topology version numbers. The self-healing control module automatically triggers key updates and path reconstruction when nodes are added or removed or link quality changes occur in the network topology.

[0050] The intelligent scheduling module includes a risk assessment module, a priority module and a strategy optimization module; the risk assessment module generates a dynamic priority matrix and divides tasks into different risk levels; the security partitioning module divides tasks into security partitions based on the risk assessment module; the strategy optimization module periodically adjusts weight parameters;

[0051] The resource management module includes a partition monitoring module, a resource scheduling module, and a task preemption module; the partition monitoring module is used to monitor the encryption computing resource utilization indicators of each partition in real time; the resource scheduling module implements differentiated encryption computing resource allocation based on the risk assessment module and reclaims idle resources; the task preemption module triggers the encryption computing resource preemption strategy when the task encryption computing resource demand exceeds the encryption computing resource quota;

[0052] The edge processing module includes a data desensitization module, a spatiotemporal alignment module, and a verification module; the data desensitization module dynamically adjusts the data desensitization intensity based on the risk assessment module; the spatiotemporal alignment module establishes a unified time reference and spatial coordinate system and constructs a spatiotemporal index structure; the verification module performs desensitization integrity verification and detects spatiotemporal anomaly data;

[0053] The security control module includes an isolation module, an exception response module and a log module; the isolation module creates an independent security domain for the task and implements fine-grained access control; the exception response module is used to detect abnormal situations; the log module records preemption operations, which include the risk level of the preempted task, the amount of encryption computing resources released, the timestamp and the automatic recovery time, and completes the backtracking of the preemption operation.

[0054] Compared with the prior art, the present invention has the following beneficial effects:

[0055] 1. This invention uses real-time fusion core indicators to establish a multi-dimensional coupling model, generate a dynamic priority matrix, divide tasks into different risk levels, and implement differentiated encryption computing resource allocation based on risk levels, accurately allocating encryption computing resources, avoiding over-allocation or under-allocation of resources, and improving resource utilization efficiency;

[0056] 2. This invention adopts a multi-layered security mechanism, including data desensitization and spatiotemporal alignment at the edge nodes, end-to-end encrypted transmission, and fine-grained security isolation at the platform level, effectively preventing data leakage and cross-task interference;

[0057] 3. The present invention uses a closed-loop control mechanism with real-time feedback adjustment to continuously collect operating status indicators and task execution data, trigger adaptive adjustment, and maintain the high performance and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 This is a flowchart of the steps of a cloud platform scheduling method based on multi-source Internet of Things perception of the present invention. DETAILED DESCRIPTION

[0059] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0060] Example: Figure 1 As shown, the present invention provides a technical solution, a cloud platform scheduling method based on multi-source IoT perception, the method comprising the steps of:

[0061] S1. Build a dynamically adjustable sensor topology network, optimize node communication paths, and use the AES symmetric encryption protocol for real-time dynamic key distribution and topology synchronization update mechanisms. When the network topology sees node additions or subtractions or changes in link quality, key updates and path reconstruction are automatically triggered.

[0062] Specifically, for example, it is used in the industrial Internet of Things to monitor 200 sensor device nodes in a factory; a distributed consensus algorithm is used to synchronize the topological states between nodes, and the optimal communication path is dynamically calculated based on link quality indicators, which include signal strength, round-trip delay of data packets and packet loss rate, to calculate the dynamic weight coefficient and optimal communication path of each link; an independent AES symmetric encryption protocol encryption session key is assigned to each communication link, and a mapping relationship table between the key version number and the topology version number is established; when a node failure is detected, the failure state is confirmed, and the adjacent nodes initiate local topology reconstruction, and synchronously update the encryption session key of the affected link; when a new node is detected, the validity of the node is verified through a two-way authentication mechanism, and a temporary encryption session key is assigned to the node. After completing the topology synchronization, a formal encryption session key is generated; for example: when the sensor failure at node B is detected, the adjacent nodes A and C initiate local reconstruction, modify the original path node A-node B-node C to node A-node C, and synchronously update the encryption session key of the affected link.

[0063] S2. Real-time integration of core indicators and establishment of a multi-dimensional coupling model to generate a dynamic priority matrix; the core indicators include data confidentiality level, real-time traffic forecast, and device health status; based on the dynamic priority matrix, quantitative analysis of the coupling relationship of the core indicators is performed, tasks are divided into different risk levels, and a scheduling queue is generated;

[0064] Specifically, the data confidentiality level is quantitatively graded and assigned differentiated weight coefficients. The real-time traffic prediction includes predicting the network traffic load change trend in the future period through time series analysis. The device health status includes CPU usage, memory occupancy, battery remaining power and device temperature. A combined weighted algorithm is used to integrate the core indicators into a unified risk assessment value, and the formula is: Score=α×C+β×(1-F)+γ×H+P_base; where Score represents the risk assessment value; C represents the data confidentiality level; α represents the data confidentiality level weight coefficient; F represents the real-time traffic prediction value; β represents the real-time traffic prediction value weight coefficient; H represents the device health status; γ represents the device health status weight coefficient; P_base represents the task basic risk assessment value For example, the data confidentiality level is high confidentiality (C=8), the data transmission traffic is predicted to increase significantly (F=0.8), the device health status is: CPU usage is 70%, memory usage is 60%, the remaining battery power is 30%, and the device temperature is 50°C. The comprehensive assessment of the device health status is H=0.3; α=0.4, β=0.3, γ=0.2, and P_base=1. The risk assessment value of the task is calculated to be Score=0.4×8+0.3×(1-0.8)+0.2×0.3+1=4.4. According to the risk assessment value, the task belongs to medium risk (Q2). The risk assessment value is divided into risk levels of very low risk Q4, low risk Q3, medium risk Q2, high risk Q1, and very high risk Q0. Different risk levels correspond to different encryption computing resource allocation strategies.

[0065] Furthermore, a mapping relationship between task types and core indicators is established, tasks are divided into corresponding priority levels according to risk assessment values, and corresponding encryption computing resource preemption strategies and scheduling delay constraints are configured for each priority level to form a multi-level scheduling queue with dynamic adjustment capabilities; the multi-level scheduling queue includes managing task queues using a hybrid data structure of priority and time limit queues; recalculating the risk assessment value and priority level of each task every 5 minutes; setting a priority promotion mechanism: when the waiting time of a task exceeds 80% of its time requirement, the priority level is automatically increased by one level; high-priority tasks that are continuously executed for more than 3 scheduling cycles are automatically reduced in priority; and a minimum guaranteed resource quota is reserved for high-risk and extremely high-risk tasks, which are not affected by priority scheduling.

[0066] S3, based on historical data and real-time monitoring information, predicts load change trends, performs security-aware dynamic partition management of encryption computing resources, and dynamically allocates encryption computing resources;

[0067] Specifically, historical load data is analyzed, and combined with real-time monitoring of CPU utilization, memory occupancy and network throughput indicators, the changing trend of encryption computing resource demand of each computing unit is predicted; combined with the risk assessment value and the changing trend of encryption computing resource demand of each computing unit, encryption computing resources are dynamically allocated; security-aware dynamic partition management is implemented for encryption computing resources, which are divided into multiple security-isolated security partitions, dynamic encryption computing resource quotas and access control policies are set for each security partition, and differentiated encryption computing resource allocation is implemented based on risk level; the security partitions include high-security partitions, medium-security partitions and general partitions; the high-security partition handles high-risk and extremely high-risk tasks, the medium-security partition handles medium-risk tasks, and the general partition handles extremely low-risk and low-risk tasks; dynamic resource quotas are set for each partition, specifically including: the high-security partition is initially allocated 40% of encryption computing resources, with a minimum guarantee of 20% of encryption computing resources; the medium-security partition is initially allocated 35% of encryption computing resources, with a minimum guarantee of 15% of encryption computing resources; the general partition is initially allocated 25% of encryption computing resources, with no minimum guarantee.

[0068] Furthermore, the encryption computing resource utilization indicators of each partition are monitored in real time, and the encryption computing resource utilization indicators include encryption operation throughput, key exchange delay and computing unit load rate; differentiated encryption computing resource allocation is implemented based on risk level, and when it is detected that the encryption computing resource utilization of the general partition is lower than the threshold, the idle encryption computing resources are recycled to the shared resource pool; when the idle encryption computing resources are recycled, it is necessary to ensure that the minimum guaranteed quota of the high-security partition is not affected; for example: the encryption operation throughput of the general partition is 500 times / second, the key exchange delay is 100 milliseconds, and the computing unit load rate is 30%, which is lower than the set threshold, and the idle encryption computing resources, such as 10% of the encryption computing resources, are recycled to the shared resource pool. During the recycling process, it is ensured that the minimum guaranteed encryption computing resource quota of the high-security partition task is not affected.

[0069] S4. Build a closed-loop security control architecture from the edge to the cloud, perform data desensitization and spatiotemporal alignment at the edge, and implement fine-grained encrypted computing resource scheduling and security isolation at the platform level. Ensure data flow security through end-to-end encrypted transmission, and achieve multimodal data fusion through secure partitioning of encrypted computing resources, forming a closed-loop control mechanism with real-time feedback adjustment.

[0070] Specifically, the data desensitization includes implementing differentiated desensitization according to the risk level, establishing a mapping relationship between the desensitization level and the risk level, and dynamically adjusting the desensitization intensity; the spatiotemporal alignment includes establishing a unified time reference and spatial coordinate system, generating standardized spatiotemporal stamp metadata, and constructing a spatiotemporal index structure. The spatiotemporal index structure includes data aggregation of the same time window, data association of spatially adjacent nodes, and rapid retrieval of spatiotemporal composite conditions; implementing desensitization integrity verification, detecting spatiotemporal abnormal data, and maintaining data traceability and tracking records.

[0071] Specifically, the encryption computing resource scheduling includes triggering an encryption computing resource preemption strategy when the encryption computing resource demand of a task in a high-security partition exceeds the encryption computing resource quota. The encryption computing resource preemption strategy includes giving priority to allocating encryption computing resources in a shared resource pool. When the encryption computing resources in the shared resource pool are insufficient, the encryption computing resources of the task in the general partition are released. In the process of releasing encryption computing resources, the encryption computing resource quota of the task in the high-security partition is ensured to be unaffected. For example, when the encryption computing resource demand of a production process data processing task in a high-security partition exceeds the encryption computing resource quota, the encryption computing resource preemption strategy is triggered to give priority to allocating encryption computing resources in the shared resource pool. After the preemption strategy is implemented, the preemption operation is recorded. The preemption operation includes the risk level of the preempted task, the amount of encryption computing resources released, the timestamp, and the automatic recovery time. The security isolation includes creating an operating environment with an independent security domain for each task based on risk assessment values ​​and real-time monitoring information, configuring a fine-grained encryption computing resource access control strategy, and the access control strategy includes encryption computing resource access rights, data read and write ranges, and communication whitelists. A cross-task security isolation barrier is constructed to prevent unauthorized access and data leakage between tasks.

[0072] Specifically, the topology network status, encryption computing resource utilization and task queue backlog are continuously collected, and when an abnormal situation is detected, adaptive adjustment is triggered; the abnormal situation includes key exchange delay exceeding the maximum threshold, encryption computing resource demand exceeding the encryption computing resource quota and queue task waiting time exceeding the maximum waiting threshold; the adaptive adjustment includes dynamic allocation of encryption computing resources, dynamic partition management and dynamic adjustment of the optimal communication path; iteratively optimizes weighted algorithm parameters through periodic optimization algorithm to adapt to dynamically changing load and security requirements; for example, adjusts the α, β and γ weight coefficients every hour to adapt to dynamically changing load and security requirements. This is only an example and is not limited.

[0073] The present invention provides another technical solution, a risk level of a cloud platform scheduling method based on multi-source IoT perception; this is only for illustration and not for limitation;

[0074] Very High Risk Q0: 8-10 points; data confidentiality is high. Real-time traffic forecasts indicate high network traffic load and poor equipment health, which could have serious consequences. Significant cryptographic computing resources must be allocated to ensure data security and task execution. Examples include tasks involving core business secrets and critical equipment failure warnings.

[0075] High-risk Q1: 6-7.9 points; data requires certain confidentiality, traffic load is increasing, device health status has certain risks, and requires more encryption computing resources. Examples include processing important business data and monitoring some key equipment.

[0076] Medium-risk Q2: 4-5.9 points; data confidentiality is average, traffic load is relatively stable, device health is normal but fluctuates, and medium-level encryption computing resources are allocated. For example: statistical analysis tasks for general business data.

[0077] Low-risk Q3: 2-3.9 points; data confidentiality is low, traffic load is light, device health is good, and minimal cryptographic computing resources are required. For example, this task involves monitoring the operating status of common equipment.

[0078] Very Low Risk Q4: 0-1.9 points; data has almost no confidentiality requirements, traffic load is stable and small, device health is excellent, and only a small amount of encryption computing resources are required. For example: tasks for collecting routine data such as ambient temperature and humidity.

[0079] The present invention provides another technical solution, a preemptive strategy for a cloud platform scheduling method based on multi-source IoT perception;

[0080] In the intelligent industrial control scenario, the high-security partition is initially allocated 40% of the encryption computing resources, with a minimum guarantee of 20%; the medium-security partition is initially allocated 35% of the encryption computing resources, with a minimum guarantee of 15%; the general partition is initially allocated 25% of the encryption computing resources, with no minimum guarantee;

[0081] The general partition utilization rate is monitored to be 22%, which is lower than the set threshold. 5% of the idle encryption computing resources are recycled to the shared resource pool, leaving 20% ​​of the general partition quota.

[0082] When the encryption computing resource demand of tasks in the high-security partition reaches 60% of the total resources, the encryption computing resource quota is exceeded, triggering the encryption computing resource preemption policy;

[0083] Execute the resource preemption strategy, giving priority to the shared resource pool. Previously, the idle resources of the general partition were 5%, which were immediately allocated to the high-security partition. At this time, the high-security partition is occupied by 45% but less than 60%, requiring cross-partition preemption.

[0084] Calculate the additional preemption amount required: 60% - 45% = 15%;

[0085] Sequential preemption prioritizes 15% of the general partition's encryption computing resource quota. After the release, the general partition remains: 20% - 15% = 5%, while the high-security partition currently occupies 60%.

[0086] During the preemption operation, ensure that at least 20% of the high-security partition is always available and not preempted, and that the medium-security partition maintains a minimum guarantee of 15%;

[0087] After the preemption strategy is implemented, the preemption operation is recorded, which includes the risk level of the preempted task, the amount of encryption computing resources released, the timestamp and the automatic recovery time.

[0088] The present invention provides another technical solution, a cloud platform scheduling system based on multi-source IoT perception, which includes: a security networking module, an intelligent scheduling module, a resource management module, an edge processing module and a security control module;

[0089] The secure networking module includes a topology optimization module, a key management module, and a self-healing control module. The topology optimization module synchronizes the topology status between nodes through a distributed consensus algorithm and dynamically calculates the optimal communication path based on link quality indicators. The key management module is used to allocate independent AES symmetric encryption protocol encryption session keys and establish a mapping relationship table between key version numbers and topology version numbers. The self-healing control module automatically triggers key updates and path reconstruction when nodes are added or removed or link quality changes occur in the network topology.

[0090] The intelligent scheduling module includes a risk assessment module, a priority module and a strategy optimization module; the risk assessment module generates a dynamic priority matrix and divides tasks into different risk levels; the security partitioning module divides tasks into security partitions based on the risk assessment module; the strategy optimization module periodically adjusts weight parameters;

[0091] The resource management module includes a partition monitoring module, a resource scheduling module, and a task preemption module; the partition monitoring module is used to monitor the encryption computing resource utilization indicators of each partition in real time; the resource scheduling module implements differentiated encryption computing resource allocation based on the risk assessment module and reclaims idle resources; the task preemption module triggers the encryption computing resource preemption strategy when the task encryption computing resource demand exceeds the encryption computing resource quota;

[0092] The edge processing module includes a data desensitization module, a spatiotemporal alignment module, and a verification module; the data desensitization module dynamically adjusts the data desensitization intensity based on the risk assessment module; the spatiotemporal alignment module establishes a unified time reference and spatial coordinate system and constructs a spatiotemporal index structure; the verification module performs desensitization integrity verification and detects spatiotemporal anomaly data;

[0093] The security control module includes an isolation module, an exception response module and a log module; the isolation module creates an independent security domain for the task and implements fine-grained access control; the exception response module is used to detect abnormal situations; the log module records preemption operations, which include the risk level of the preempted task, the amount of encryption computing resources released, the timestamp and the automatic recovery time, and completes the backtracking of the preemption operation.

[0094] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above and that the invention can be embodied in other specific forms without departing from the spirit or essential characteristics of the invention. Therefore, the embodiments should be considered in all respects as illustrative and non-restrictive, and the scope of the invention is defined by the appended claims, not the foregoing description, and all variations within the meaning and range of equivalents of the claims are intended to be included therein. Any reference sign in a claim should not be construed as limiting the claim to which it relates.

Claims

1. A cloud platform scheduling method based on multi-source IoT perception, characterized by: The method includes: Build a dynamically adjustable sensor topology network, optimize node communication paths, and use the AES symmetric encryption protocol for real-time dynamic key distribution and topology synchronization update mechanism. When the network topology increases or decreases nodes or the link quality changes, key updates and path reconstruction are automatically triggered. The construction of a dynamically adjustable sensor topology network includes: A distributed consensus algorithm is used to synchronize the topological states between nodes. The optimal communication path is dynamically calculated based on link quality indicators, including signal strength, round-trip delay, and packet loss rate. The dynamic weight coefficient of each link and the optimal communication path are calculated. Assign an independent AES symmetric encryption protocol encryption session key to each communication link and establish a mapping table between the key version number and the topology version number; When a node failure is detected, the failure status is confirmed, and the adjacent nodes initiate local topology reconstruction and synchronously update the encryption session key of the affected link. When a new node is detected, the validity of the node is verified through a two-way authentication mechanism, and a temporary encryption session key is assigned to the node. After the topology synchronization is completed, the official encryption session key is generated. Real-time integration of core indicators and establishment of a multi-dimensional coupling model to generate a dynamic priority matrix; the core indicators include data confidentiality level, real-time traffic forecast, and device health status; based on the dynamic priority matrix, quantitative analysis of the coupling relationship of the core indicators, classification of tasks into different risk levels, and generation of scheduling queues; Based on historical data and real-time monitoring information, load change trends are predicted, and dynamic partition management and allocation of encryption computing resources are performed with security awareness. Build a closed-loop security control architecture from the edge to the cloud, complete data desensitization and spatiotemporal alignment at the edge nodes, and implement fine-grained encrypted computing resource scheduling and security isolation at the platform level; ensure data flow security through end-to-end encrypted transmission, complete multimodal data fusion through secure partitioning of encrypted computing resources, and form a closed-loop control mechanism with real-time feedback adjustment.

2. The cloud platform scheduling method based on multi-source IoT perception according to claim 1, characterized in that: The multi-dimensional coupling model is established, comprising: The data confidentiality level is quantitatively graded and assigned differentiated weight coefficients. The real-time traffic prediction includes predicting the network traffic load change trend in the future period through time series analysis. The device health status includes CPU usage, memory occupancy, battery remaining power, and device temperature. A combined weighted algorithm is used to integrate the core indicators into a unified risk assessment value; the risk assessment value is divided into risk levels of extremely low risk, low risk, medium risk, high risk and extremely high risk; different risk levels correspond to different encryption computing resource allocation strategies.

3. The cloud platform scheduling method based on multi-source IoT perception according to claim 2, characterized in that: The dynamic priority matrix includes: Establish a mapping relationship between task types and core indicators, divide tasks into corresponding priority levels according to risk assessment values, configure corresponding encryption computing resource preemption strategies and scheduling delay constraints for each priority level, and form a multi-level scheduling queue with dynamic adjustment capabilities.

4. The cloud platform scheduling method based on multi-source IoT perception according to claim 1, characterized in that: The security-aware dynamic partition management includes: Analyze historical load data and, in combination with real-time monitored CPU utilization, memory occupancy, and network throughput indicators, predict the changing trend of encryption computing resource requirements for each computing unit; dynamically allocate encryption computing resources based on the risk assessment value and the changing trend of encryption computing resource requirements for each computing unit; Implement security-aware dynamic partition management for encrypted computing resources, dividing them into multiple securely isolated security partitions, setting dynamic encryption computing resource quotas and access control policies for each security partition, and implementing differentiated encryption computing resource allocation based on risk levels; The security partition includes a high-security partition, a medium-security partition and a general-purpose partition; the high-security partition handles high-risk and extremely high-risk tasks, the medium-security partition handles medium-risk tasks, and the general-purpose partition handles extremely low-risk and low-risk tasks.

5. The cloud platform scheduling method based on multi-source IoT perception according to claim 4 is characterized in that: The dynamic allocation of encryption computing resources includes: Real-time monitoring of encryption computing resource utilization indicators of each partition, wherein the encryption computing resource utilization indicators include encryption operation throughput, key exchange latency, and computing unit load rate; Differentiated encryption computing resource allocation is implemented based on risk levels. When it is detected that the utilization rate of encryption computing resources in the general partition is lower than the threshold, idle encryption computing resources will be recycled to the shared resource pool. When recycling idle encryption computing resources, it is necessary to ensure that the minimum guaranteed quota of the high-security partition is not affected.

6. The cloud platform scheduling method based on multi-source IoT perception according to claim 1, characterized in that: The data desensitization and spatiotemporal alignment are completed at the edge node, including: The data desensitization includes implementing differentiated desensitization according to the risk level, establishing a mapping relationship between the desensitization level and the risk level, and dynamically adjusting the desensitization intensity; The spatiotemporal alignment includes establishing a unified time base and spatial coordinate system, generating standardized spatiotemporal stamp metadata, and constructing a spatiotemporal index structure. The spatiotemporal index structure includes data aggregation of the same time window, data association of spatially adjacent nodes, and fast retrieval of spatiotemporal composite conditions. Implement desensitizing integrity verification, detect spatiotemporal anomaly data, and maintain data traceability and tracking records.

7. The cloud platform scheduling method based on multi-source IoT perception according to claim 4, characterized in that: Implementing fine-grained encryption computing resource scheduling and security isolation at the platform level includes: The encryption computing resource scheduling includes triggering an encryption computing resource preemption strategy when the encryption computing resource demand of the task of the high-security partition exceeds the encryption computing resource quota. The encryption computing resource preemption strategy includes giving priority to allocating encryption computing resources in the shared resource pool. When the encryption computing resources in the shared resource pool are insufficient, the encryption computing resources of the task of the general partition are released. In the process of releasing the encryption computing resources, it is ensured that the encryption computing resource quota of the task of the high-security partition is not affected. After the preemption strategy is implemented, the preemption operation is recorded. The preemption operation includes the risk level of the preempted task, the amount of encryption computing resources released, the timestamp and the automatic recovery time. The security isolation includes creating an operating environment with an independent security domain for each task based on risk assessment values ​​and real-time monitoring information, configuring fine-grained encryption computing resource access control policies, and the access control policies include encryption computing resource access rights, data read and write ranges, and communication whitelists; building a cross-task security isolation barrier to prevent unauthorized access and data leakage between tasks.

8. The cloud platform scheduling method based on multi-source IoT perception according to claim 1, characterized in that: The closed-loop control mechanism of real-time feedback adjustment includes: Continuously collect topological network status, encryption computing resource utilization, and task queue backlogs, and trigger adaptive adjustments when abnormal conditions are detected; abnormal conditions include key exchange delay exceeding the maximum threshold, encryption computing resource demand exceeding the encryption computing resource quota, and queue task waiting time exceeding the maximum waiting threshold; adaptive adjustments include dynamic allocation of encryption computing resources, dynamic partition management, and dynamic adjustment of the optimal communication path; The weighted algorithm parameters are iteratively optimized through a periodic optimization algorithm to adapt to dynamically changing loads and safety requirements.

9. A cloud platform scheduling system based on multi-source IoT perception, applied to a cloud platform scheduling method based on multi-source IoT perception as claimed in any one of claims 1 to 8, characterized in that: The system includes: a security networking module, an intelligent scheduling module, a resource management module, an edge processing module and a security control module; The secure networking module includes a topology optimization module, a key management module, and a self-healing control module. The topology optimization module synchronizes the topology status between nodes through a distributed consensus algorithm and dynamically calculates the optimal communication path based on link quality indicators. The key management module is used to allocate independent AES symmetric encryption protocol encryption session keys and establish a mapping relationship table between key version numbers and topology version numbers. The self-healing control module automatically triggers key updates and path reconstruction when nodes are added or removed or link quality changes occur in the network topology. The intelligent scheduling module includes a risk assessment module, a security partitioning module and a strategy optimization module; the risk assessment module generates a dynamic priority matrix and divides tasks into different risk levels; the security partitioning module divides tasks into security partitions based on the risk assessment module; and the strategy optimization module periodically adjusts weight parameters; The resource management module includes a partition monitoring module, a resource scheduling module, and a task preemption module; the partition monitoring module is used to monitor the encryption computing resource utilization indicators of each partition in real time; the resource scheduling module implements differentiated encryption computing resource allocation based on the risk assessment module and reclaims idle resources; the task preemption module triggers the encryption computing resource preemption strategy when the task encryption computing resource demand exceeds the encryption computing resource quota; The edge processing module includes a data desensitization module, a spatiotemporal alignment module, and a verification module; the data desensitization module dynamically adjusts the data desensitization intensity based on the risk assessment module; the spatiotemporal alignment module establishes a unified time reference and spatial coordinate system and constructs a spatiotemporal index structure; the verification module performs desensitization integrity verification and detects spatiotemporal anomaly data; The security control module includes an isolation module, an exception response module and a log module; the isolation module creates an independent security domain for the task and implements fine-grained access control; the exception response module is used to detect abnormal situations; the log module records preemption operations, which include the risk level of the preempted task, the amount of encryption computing resources released, the timestamp and the automatic recovery time, and completes the backtracking of the preemption operation.

Citation Information

Patent Citations

  • Multi-modal information composite perception and fusion architecture and method based on cloud edge collaboration

    CN114971574A

  • Customer information management method based on cloud environment and related device

    CN119128431A