A method for collaborative management of distributed DDC controllers in an open network

By constructing a three-dimensional topology map and dynamic trust assessment in an open network, combined with a lightweight communication protocol and event-driven architecture, the problem of insufficient trust management in distributed control systems is solved, achieving rapid response and enhanced security, and improving network resource utilization efficiency and task execution effectiveness.

CN120434631BActive Publication Date: 2026-02-13ANHUI DINGLI NETWORK TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510616454.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2026-02-13
Estimated Expiration
2045-05-14

AI Technical Summary

Technical Problem

Existing distributed control systems suffer from insufficient trust management in open network environments, resulting in an inability to respond promptly to dynamic changes in trust relationships between nodes, increasing the risk of network attacks, and affecting collaborative management efficiency and system security.

Method used

By constructing a 3D topology map based on Wi-Fi channel state information, dynamic trust assessment and node trust level output are performed. Dynamic key distribution is carried out by combining a lightweight communication protocol stack and elliptic curve cryptography algorithm. An event-driven architecture is deployed to switch communication interfaces. Task pre-allocation and arbitration mechanism adjustment are performed based on device capabilities, trust level and topology distance.

Benefits of technology

It enables rapid response to the network environment and enhances security, ensures the security of critical data, improves the overall trust and defense capabilities of the system, and enhances the utilization efficiency of network resources and the effectiveness of task execution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434631B_ABST
    Figure CN120434631B_ABST
Patent Text Reader

Abstract

The application discloses a kind of open network in distributed DDC controller collaborative management method and system, belong to wireless network security technical field, including according to open network in Wi-Fi channel state information constructs the three-dimensional topological map of controller and carries out dynamic trust evaluation, lightweight communication protocol stack is built in each distributed DDC controller node, generates distributed key pool based on elliptic curve encryption algorithm and implements dynamic key distribution;Distributed DDC controller resolves input instruction and switches communication interface;Task pre-allocation is carried out, and dynamic adjustment is carried out to the execution state of continuous monitoring task, and starts arbitration mechanism to carry out dynamic adjustment.The application not only optimizes the collaborative work capacity of distributed DDC controller, but also improves the security and resource utilization efficiency of network, so that the controller can be more flexible and efficient when coping with complex network environment, to bring more reliable use experience and higher security guarantee for users.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of wireless network security, and particularly relates to a distributed DDC controller cooperative management method in an open network. BACKGROUND

[0002] In today's industrial automation and intelligent control field, distributed control systems (DCS) are widely used for their high flexibility and scalability. In recent years, with the rapid development of Internet of Things (IoT) and intelligent manufacturing, the architecture of distributed control systems has been continuously optimized, realizing more efficient resource management and data flow. Representative technologies such as the cooperative working mode of central controller and multi-node controller, through real-time data collection and analysis, realize intelligent adaptation to complex dynamic environments. However, although the existing technology has made significant progress in system response speed, reliability and data throughput, it still faces problems of trust management and security. Especially in an open network environment, the trust relationship between nodes changes dynamically, often leading to potential security risks, bringing not small challenges to the normal operation of the system.

[0003] The current distributed control system mainly relies on fixed trust model and static key management mechanism, and the trust level evaluation of nodes is often single, such as based on historical behavior data of nodes or simple network intrusion detection algorithm. This method not only cannot dynamically adapt to the change of network environment, but also lacks flexible response ability to abnormal behavior. For example, when the behavior data of a node suddenly changes, the trust evaluation mechanism of the existing system may not react in time, so that the node is mistakenly considered safe, increasing the risk of network attack. In addition, the traditional key distribution method usually fails to fully utilize the relative trust level between nodes, making the key management process complex and error-prone. These deficiencies not only affect the cooperative management efficiency of distributed controllers, but also to some extent restrict the overall security of the system in an open network environment. SUMMARY

[0004] In view of the above existing problems, the technical problem solved by the application is: how to reasonably allocate and dynamically adjust tasks based on the ability, trust level and topological distance of nodes, in order to improve the utilization efficiency of network resources and the effectiveness of task execution; in multi-node cooperation, how to effectively detect conflicts and quickly and accurately solve them through arbitration mechanism, to ensure the stability and reliability of network operation.

[0005] To solve the above technical problems, a distributed DDC controller cooperative management method in an open network is proposed, which comprises,

[0006] The three-dimensional topology map of the controller is constructed according to Wi-Fi channel state information in an open network, dynamic trust evaluation is carried out based on node historical behavior data, and a node trust level is output; a lightweight communication protocol stack is built in each distributed DDC controller node, the protocol stack includes three communication interfaces, namely, an instant interface, an aggregation interface and a coordination interface, a distributed key pool is generated based on an elliptic curve encryption algorithm, and dynamic key distribution is implemented according to the node trust level; the distributed DDC controller analyzes input instructions, deploys an event-driven architecture in the protocol stack, and switches the communication interface according to the input instructions; task pre-allocation is performed according to device capability, trust level and topology distance, the execution state of continuous monitoring tasks is dynamically adjusted, and an arbitration mechanism is started to dynamically adjust.

[0007] As a preferred scheme of the distributed DDC controller cooperative management method in an open network, the Wi-Fi channel state information includes that each node continuously scans the CSI data of the surrounding AP, extracts the signal arrival angle and time delay characteristics, and solves the three-dimensional coordinates of the node by using the least square method according to the Wi-Fi channel state information, so as to establish the three-dimensional topology map of the controller.

[0008] The node historical behavior data includes historical response time delay and data integrity rate.

[0009] As a preferred scheme of the distributed DDC controller cooperative management method in an open network, the output node trust level includes that double-channel trust evaluation is carried out based on node historical behavior data, wherein the double-channel includes a real-time channel and an accumulated channel.

[0010] Instantaneous abnormal behavior is monitored in real time through the real-time channel, and the trust value is deducted each time abnormal behavior is detected. Meanwhile, a trend index of the data integrity rate within a specified time is counted by using a sliding window through the accumulated channel, and the historical index is counted by taking the specified time as a window.

[0011] The basic trust value is calculated by assigning weights to the historical index, and the final trust level score is output according to the basic trust value.

[0012] When the trust level score triggers a low trust threshold, an isolation program of the node and the controller to which the node belongs is started, the node trust level is output, and is marked to the topology map.

[0013] As a preferred scheme of the distributed DDC controller cooperative management method in an open network, the dynamic key distribution includes that a hierarchical key system constructed based on an elliptic curve encryption algorithm includes a root key and a session key, the root key is jointly kept by the highest trust node in the topology map, and a threshold signature mechanism is adopted.

[0014] The session key is dynamically assigned with encryption strength through the trust level, when the node trust level is greater than or equal to the high trust threshold, a 256-bit key and a complete protocol stack function are used;

[0015] When the low trust threshold is less than or equal to the node trust level and less than the high trust threshold, the key validity period is limited and the management instruction is disabled;

[0016] When the node trust level is less than the low trust threshold, only a temporary key is assigned and the session duration is compressed.

[0017] As a preferred scheme of the distributed DDC controller cooperative management method in an open network, wherein: the switching of the communication interface according to the input instruction comprises deploying an event-driven architecture in the protocol stack, the distributed DDC controller parses the input instruction, parses the instruction header field, extracts the instruction characteristics of the urgency, data volume and associated node number, and standardizes the instruction characteristics;

[0018] The standardized instruction characteristics are converted into a feature vector, an improved weighted Jaccard algorithm is called to calculate the initial correlation between events, the final correlation result is dynamically corrected by combining the trust level, and the protocol stack three communication interface switching is performed according to the dynamically corrected final correlation result;

[0019] When the final correlation result is greater than or equal to a preset first correlation threshold, the current controller interface is switched to an instant interface and an instant mode is adopted;

[0020] When the preset second correlation threshold is less than or equal to the final correlation result and less than the preset first correlation threshold, the current controller is switched to an aggregation interface and an aggregation mode is adopted;

[0021] When the final correlation result is less than the preset second correlation threshold, the current controller is switched to a cooperative interface and a cooperative mode is adopted.

[0022] As a preferred scheme of the distributed DDC controller cooperative management method in an open network, wherein: the task pre-allocation comprises implementing task management in the pre-allocation stage and the dynamic adjustment stage;

[0023] In the pre-allocation stage, the task demand document is parsed, the key constraints of device capability requirements, task timeliness and resource dependency are extracted, and an initial allocation scheme is generated:

[0024] The first priority is to match the device capability label;

[0025] The second priority is to select a node whose trust level is greater than or equal to the high trust threshold;

[0026] The third priority is to allocate nearby based on the distance on the three-dimensional topological map;

[0027] In the dynamic adjustment stage, the task execution state is continuously monitored, when an abnormal conflict is detected, an arbitration mechanism is triggered, the current task progress, the real-time state of the device, the latest information of the topology map are input, the arbitration decision is executed, the execution node is re-allocated and the data is rolled back.

[0028] As a preferred scheme of the open network distributed DDC controller cooperative management method, wherein: the arbitration mechanism comprises: calculating the topology sensitivity in the three-dimensional topology map, when an abnormal conflict is detected, the trust level of the conflict device is extracted, the influence entropy value of the task is calculated, and the scheme with the minimum entropy change is preferentially selected.

[0029] When there are two or more same minimum values, global arbitration is performed, cross-domain negotiation is initiated, all controllers exchange the trust level topology sensitivity of the topology map, a weighted voting mechanism is adopted, the scheme corresponding to the maximum weight value is selected, and the arbitration result is updated to the node in reverse through the protocol stack.

[0030] Another object of the present application is to provide an open network distributed DDC controller cooperative management system.

[0031] As a preferred scheme of the open network distributed DDC controller cooperative management system, characterized in that it comprises a topology map construction module, a key protection module, an instruction analysis module and a task allocation module.

[0032] The topology map construction module constructs a three-dimensional topology map of the controller according to the Wi-Fi channel state information in the open network, and outputs the trust level of the node based on the historical behavior data of the node.

[0033] The key protection module has a lightweight communication protocol stack built in each distributed DDC controller node, the protocol stack includes three communication interfaces, namely instant interface, aggregation interface and cooperation interface, a distributed key pool is generated based on elliptic curve encryption algorithm, and dynamic key distribution is implemented according to the trust level of the node.

[0034] The instruction analysis module, the distributed DDC controller analyzes the input instruction, deploys an event-driven architecture in the protocol stack, and switches the communication interface according to the input instruction.

[0035] The task allocation module performs task pre-allocation according to the device capacity, trust level and topology distance, continuously monitors the task execution state, and starts the arbitration mechanism for dynamic adjustment.

[0036] A computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the steps of the method when executing the computer program.

[0037] A computer readable storage medium stores a computer program, and the computer program implements the steps of the method when executed by a processor.

[0038] The present application has the following advantages: by collecting Wi-Fi channel state information (CSI) and node historical behavior data, dynamic trust evaluation and three-dimensional topology map construction are realized. This step works by jointly constructing a map, nodes can share their location information and signal characteristics, thereby enhancing the reliability of the network. In handling abnormal behavior, not only can it quickly respond, but also through real-time and cumulative channel evaluation mechanisms, it further improves the security and stability of the network, effectively preventing potential threats from malicious nodes, which directly improves the overall trust and security performance of the system.

[0039] By embedding a lightweight communication protocol stack and a dynamic key distribution based on node trust level, flexible and efficient secure communication is realized. By using different encryption strategies for nodes with different trust levels, the security of critical data and the rational use of resources are ensured. For example, high-trust nodes can use stronger encryption measures to protect information confidentiality, while low-trust nodes limit their permissions, which helps to reduce potential risks and improve the overall security and defense capabilities of the network system.

[0040] By parsing input instructions and switching communication interfaces, automatic adjustment of communication modes according to the urgency and data volume of different events is realized. The distributed controller can find the best balance between efficiency and security, especially in emergency situations, it can guarantee the real-time performance and response speed of instructions as much as possible, and enhance the flexibility of the system, so that it can switch operation modes autonomously according to actual needs, avoid resource waste, and improve the response ability to complex events.

[0041] By pre-allocating tasks based on device capabilities, trust levels and topology distances, intelligent scheduling of task management is realized. The introduction of the arbitration mechanism allows the system to quickly respond when detecting resource conflicts or trust level drops, thereby reducing potential task execution risks. BRIEF DESCRIPTION OF DRAWINGS

[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort on the basis of these drawings.

[0043] Figure 1 The overall flowchart of the method for cooperative management of distributed DDC controllers in an open network according to an embodiment of the present application is shown in FIG. 1.

[0044] Figure 2 The system scheme module diagram of the system for cooperative management of distributed DDC controllers in an open network according to an embodiment of the present application is shown in FIG. 2. DETAILED DESCRIPTION

[0045] In order to make the above objectives, features and advantages of the present application more apparent, the specific embodiments of the present application will be described in detail below with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present application.

[0046] In the following description, many specific details are set forth in order to provide a thorough understanding of the present application. However, the present application can be practiced without the specific details, which are not described herein. In other instances, well-known methods, procedures, components and circuits have not been described in detail so as not to obscure the present application.

[0047] Embodiment 1, with reference to Figure 1 The first embodiment of the present application provides a method for cooperative management of distributed DDC controllers in an open network, which comprises the following steps.

[0048] S1: Construct a three-dimensional topology map of the controller according to the Wi-Fi channel state information and the native data in the open network, and output a node trust level based on dynamic trust evaluation of node historical behavior data.

[0049] It should be noted that the Wi-Fi channel state information (CSI) is collected by continuously scanning the CSI data of the surrounding APs of each node, and the angle of arrival (AoA) and time delay characteristics are extracted.

[0050] The node measures CSI parameters of at least three fixed APs, solves the three-dimensional coordinates of the node by using a least square method, selects three APs with the strongest signals as the reference of the coordinate system (without prepositioning position information), all nodes share their own coordinates and measured AP-CSI characteristics, abnormal positioning results (for example, sudden data with a moving speed > 5 m / s) are excluded through consistency checking, and a three-dimensional topology map of the controller is established; the three-dimensional topology map constructed through Wi-Fi channel state information (CSI) can realize real-time understanding of the positions and states of devices in the network, and provide a basis for subsequent decision-making.

[0051] The node historical behavior data include, but are not limited to, historical response delay, data integrity rate and the like.

[0052] Further, based on the node historical behavior data, double-channel trust evaluation is performed, wherein the double-channel includes a real-time channel and a cumulative channel.

[0053] The real-time channel is used to monitor instantaneous abnormal behavior (for example, a sudden increase of 50% in the number of ARP requests per unit time, and a TCP retransmission rate > 15%), and the trust value is deducted by 5 points for each detected abnormality; at the same time, a trust value recovery mechanism (for example, +2 points automatically every hour without abnormality) is provided to avoid permanent punishment caused by occasional abnormality.

[0054] The cumulative channel is used to statistically calculate a trend index of the data integrity rate in the last one hour by using a sliding window; the historical index is calculated by taking one hour as a window, and includes the data integrity rate, response stability and topology consistency.

[0055] It should be noted that the data integrity rate = (number of successfully checked data packets / total received packet number) x 100;

[0056] The response stability = 1-(maximum delay-minimum delay) / average delay;

[0057] The topology consistency = reciprocal of the Euclidean distance between the current coordinate and the historical average coordinate;

[0058] The trust value is calculated by dynamically evaluating the historical index; the basic value is calculated by assigning weights to the historical index and summing them up, and the final trust level is The trust level (0-100 points) is updated every 5 minutes and marked on the topology map; when the trust threshold (60 points) is triggered, the node isolation program is started, the trust level of the node is output and marked on the topology map, which is used as a decision basis for subsequent key distribution; the node with a trust value lower than 60 points is automatically triggered to trigger the topology reconstruction process and isolate the current node and the controller; if the current node is lower than 60 points for more than three times, the current controller is disconnected, which can effectively prevent malicious nodes from damaging the stability of the network. The trust evaluation is performed based on the historical behavior data, real-time abnormality detection and cumulative data trend, the sensitivity of the system to abnormal behavior is improved, and the network security is enhanced.

[0059] S2: A lightweight communication protocol stack is built in each distributed DDC controller node, and the protocol stack includes three communication interfaces, namely, an instant interface, an aggregation interface, and a coordination interface;

[0060] A distributed key pool is generated based on an elliptic curve encryption algorithm, and dynamic key distribution is implemented according to a node trust level.

[0061] Further, the dynamic key distribution includes constructing a hierarchical key system including a root key and a session key based on an elliptic curve encryption (SM2 algorithm);

[0062] The root key adopts a (3, 2) threshold threshold signature (TSS) mechanism, and the root key is jointly kept by the top three highest trust nodes in a topology map;

[0063] The session key is dynamically allocated with encryption strength according to the trust level, specifically:

[0064] When the node trust level is greater than or equal to a high trust threshold, a 256-bit key and a complete protocol stack function are used;

[0065] When the low trust threshold is less than or equal to the node trust level and less than the high trust threshold, the key validity period is limited (for example, 1 hour, which is manually set according to the application scenario) and the management instruction is disabled;

[0066] When the node trust level is less than the low trust threshold, only a temporary key is allocated and the session duration is compressed to 30 seconds; wherein the high trust threshold is 80 minutes, and the low trust threshold is 60 minutes.

[0067] The key distribution is bound to the topology state, when a new node is accessed, the neighbor node group key rotation is triggered, after the node is offline for a long time, the related key fragments are automatically invalidated, and when the mobile controller position offset is more than 5 meters, a temporary device fingerprint is generated, wherein the temporary device fingerprint is in the form of Hash (node ID + coordinate + timestamp), to avoid forgery.

[0068] The elliptic curve encryption algorithm and the dynamic key distribution mechanism are used to ensure that appropriate keys are distributed under different trust levels, improve the security and efficiency of the system, quickly adapt to environmental changes, reduce the potential attack surface, and protect the data transmission in the controller from attacks and theft.

[0069] S3: The distributed DDC controller parses the input instruction, deploys an event-driven architecture in the protocol stack, and switches the communication interface according to the input instruction.

[0070] It should be noted that the switching of the communication interface according to the input instruction includes deploying an event-driven architecture in the protocol stack, a distributed DDC controller parses the input instruction, parses the instruction header field, extracts the instruction characteristics of the urgency, data volume, and number of associated nodes, and standardizes the instruction characteristics, converts the standardized instruction characteristics into a feature vector, and calls an improved weighted Jaccard algorithm to calculate the initial relevance between events:

[0071]

[0072] wherein, is the initial relevance, is the current event task feature vector (i.e., the standardized instruction characteristics), is the historical reference event task feature vector (taken from the mean of similar tasks), is the feature weight (for example, the urgency weight can be 0.5, the data volume weight can be 0.3, and the number of associated nodes weight can be 0.2); is the average time consumption of the historical event tasks of the current node, is the maximum allowable time consumption of the system preset for similar event tasks, and n is the number of different event tasks and i is the variable index;

[0073] It should be noted that the urgency weight (0.5) has the highest priority in the timeliness of the instruction in the industrial control scene (such as the emergency stop instruction requiring millisecond-level response), and the weight accounts for 50%, which reflects the emphasis on safety, in line with the weight allocation convention of the IEC 62443 standard for critical instructions; the data volume weight (0.3) affects the bandwidth occupation, but the real-time requirement is lower than the urgency, and the 30% weight balances resource occupation and efficiency; the number of nodes weight (0.2) reflects the task complexity, and the 20% weight avoids excessive dispersion of attention.

[0074] Combined with dynamic correction of trust level:

[0075]

[0076] wherein, is the final relevance result, is the score of the node trust level, is the channel quality compensation value calculated according to the packet error rate; it should be noted that 0.8 is a set reference value corresponding to the minimum trusted node of the high trust threshold of 80 points, ensuring that even if the node just meets the standard (80 points), it still retains 80% of the basic relevance weight, avoiding frequent mode switching caused by trust fluctuations; 0.2 is the slope, and the coefficient increases by 0.01 (0.2 / 20) for every 1 point increase in trust points, so that a 100-point node obtains full correction (0.8+0.2=1.0), simplifying the calculation while embodying the principle of decision priority of high-trust nodes.

[0077] Switching three communication interfaces of the protocol stack according to the dynamically corrected result, wherein the event modes corresponding to the instant interface, the aggregation interface and the coordination interface are instant mode, aggregation mode and coordination mode respectively;

[0078] When the final correlation result is greater than or equal to a preset first correlation threshold, the current controller interface is switched to the instant interface, and the instant mode is adopted;

[0079] When the preset second correlation threshold is less than or equal to the final correlation result and the final correlation result is less than the preset first correlation threshold, the current controller is switched to the aggregation interface, and the aggregation mode is adopted;

[0080] When the final correlation result is less than the preset second correlation threshold, the current controller is switched to the coordination interface, and the coordination mode is adopted; if the result of the interface to be switched is consistent with the current interface, no conversion is needed, and the current interface is kept unchanged; wherein the preset first correlation threshold and the preset second correlation threshold are preset by the back-end controller;

[0081] Specifically, the instant mode is set to preempt a dedicated time slot, disable data compression, and enable end-to-end confirmation;

[0082] The aggregation mode is set to enable difference encoding and perform batch signature verification;

[0083] The coordination mode is set to establish a temporary storage pool, enable memory sharing and a delayed confirmation mechanism.

[0084] According to the urgency of the event and the amount of data, the interface is dynamically adjusted to ensure that the system can respond to important instructions at the fastest speed, improve the overall operation efficiency of the system, automatically identify and optimize the event relationship through the weighted Jaccard algorithm, help to reduce conflicts and risky operations in system operation, improve decision-making quality, dynamically correct the protocol switching combined with the correlation result and the node trust level to ensure that high-trust nodes execute tasks first, and ensure the safety and reliability of the tasks.

[0085] S4: Pre-allocating tasks according to device capabilities, trust levels and topological distances, dynamically adjusting the execution status of continuous monitoring tasks, and starting an arbitration mechanism for dynamic adjustment.

[0086] Further, the task management of the pre-allocation stage and the dynamic adjustment stage is implemented;

[0087] In the pre-allocation stage, the task requirement document is parsed, the device capability requirements (such as precision, power, etc.), the task timeliness (such as the deadline window), and the key constraints of the resource dependency relationship are extracted, and an initial allocation scheme is generated:

[0088] The first priority is to directly match the device capability label;

[0089] The second priority is to select a node whose trust level is greater than or equal to a high trust threshold value;

[0090] The third priority is to allocate the task in proximity based on a distance on the three-dimensional topology map.

[0091] In the dynamic adjustment stage, the task execution state is continuously monitored, and when the following conflicts are detected: resource overrun (for example, CPU > 90% for 10 seconds), communication delay exceeding a threshold value (for example, communication delay exceeding 200 ms), and trust level falling below an alarm line, the arbitration mechanism is triggered, the input parameters include the current task progress, the real-time state of the device, and the latest information of the topology map, and the arbitration decision is executed.

[0092] It should be noted that the arbitration mechanism includes calculating the topology sensitivity in the three-dimensional topology map, extracting the trust level of the conflict device when the conflict is detected, calculating the influence entropy value of each strategy, and preferentially selecting the scheme with the smallest entropy change.

[0093] When there are multiple same minimum values, global arbitration is performed, cross-domain negotiation is initiated, the trust distribution and topology sensitivity of the topology map are exchanged between the domain controllers, a weighted voting mechanism is adopted, the voting weight is the product of the inverse of the topology sensitivity of the domain and the average of the node trust levels, the scheme corresponding to the maximum weight value is selected, and the arbitration result is updated to the access control strategy of each node through the protocol stack in reverse.

[0094] The topology sensitivity in the three-dimensional topology map is calculated based on the sum of the weighted scores of the node Euclidean distance and the node strength in the three-dimensional topology map.

[0095] By analyzing the task requirements, combining the node capabilities, trust levels, and distances, intelligent pre-allocation can be performed to improve the success rate of the task and the resource utilization efficiency, realize continuous monitoring and arbitration mechanism, and timely adjust when the resources are overrunning or the trust is falling, thereby enhancing the stability and reliability of the entire controller cooperation, allowing cross-domain negotiation and information sharing between different controllers, using weighted voting to ensure the selection of the best decision, and enhancing the integration and freedom of the entire controller cooperation.

[0096] Embodiment 2, the second embodiment of the present application, which is different from the previous embodiment:

[0097] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the part of the technical solutions that essentially contribute to the prior art or the part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.

[0098] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered a list of executable instructions for implementing logic functions, and can be specifically embodied in any computer-readable medium for use by an instruction execution system, apparatus, or device, such as a computer-based system, a system including a processor, or other system that can fetch the instructions from the instruction execution system, apparatus, or device and execute the instructions, or in conjunction with these instructions execution systems, apparatuses, or devices. For the purpose of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport programs for use by an instruction execution system, apparatus, or device, or in conjunction with these instruction execution systems, apparatuses, or devices.

[0099] More specific examples (a non-exhaustive list) of the computer-readable medium include the following: an electrical connection having one or more wires (electrical devices), a portable computer diskette (magnetic devices), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CD ROM). In addition, the computer readable medium can even be paper or other suitable medium on which the program can be printed, because the program can be electronically obtained, for example, by optical scanning of the paper or other medium, followed by editing, interpreting, or otherwise processing, if necessary, in other suitable ways, to be electronically obtained, and then stored in the computer memory.

[0100] It should be understood that various parts of the present application can be realized in hardware, software, firmware or a combination thereof. In the above embodiments, a plurality of steps or methods can be realized in software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if realized in hardware, and as in another embodiment, it can be realized by any one or a combination of the following technologies known in the art: discrete logic circuit with logic gate circuit for implementing logic functions on data signals, application specific integrated circuit with suitable combination logic gate circuit, programmable gate array (PGA), field programmable gate array (FPGA), etc.

[0101] Embodiment 3, refer to Figure 2 As a third embodiment of the present application, the embodiment provides a distributed DDC controller cooperative management system in an open network, comprising a topology map construction module, a key protection module, an instruction analysis module and a task allocation module.

[0102] The topology map construction module constructs a three-dimensional topology map of the controller according to the Wi-Fi channel state information in the open network, and performs dynamic trust evaluation based on historical behavior data of the nodes to output a node trust level.

[0103] The key protection module has a lightweight communication protocol stack built in each distributed DDC controller node, the protocol stack includes three communication interfaces, namely an instant interface, an aggregation interface and a cooperation interface, generates a distributed key pool based on an elliptic curve encryption algorithm, and implements dynamic key distribution according to the node trust level.

[0104] The instruction analysis module analyzes the input instruction of the distributed DDC controller, deploys an event-driven architecture in the protocol stack, and switches the communication interface according to the input instruction.

[0105] The task allocation module pre-allocates tasks according to the device capability, trust level and topology distance, dynamically adjusts the execution state of the continuous monitoring task, and starts an arbitration mechanism for dynamic adjustment.

[0106] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, it should be understood by those skilled in the art that the technical solutions of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical solutions of the present application, and they should be covered in the scope of the claims of the present application.

Claims

1. A method for collaborative management of distributed DDC controllers in an open network, characterized in that: include, A three-dimensional topology map of the controller is constructed based on the Wi-Fi channel state information in the open network, and the node trust level is output based on the node's historical behavior data for dynamic trust assessment. The output node trust level includes a dual-channel trust assessment based on the node's historical behavior data, wherein the dual channels include a real-time channel and an cumulative channel. Real-time monitoring of instantaneous abnormal behavior is conducted through a real-time channel. Trust value is deducted for each abnormal behavior detected. At the same time, a trend indicator of data integrity rate within a specified time period is statistically analyzed through a cumulative channel using a sliding window. Historical indicators are also statistically analyzed using the specified time period as a window. A basic trust value is calculated by assigning weights to historical indicators, and a final trust level score is output based on the basic trust value. When the trust level score triggers a low trust threshold, the isolation procedure for the node and its controller is initiated, the node's trust level is output and marked on the topology map; Each distributed DDC controller node has a built-in lightweight communication protocol stack, which includes three types of communication interfaces: instant interface, aggregation interface, and cooperative interface. A distributed key pool is generated based on the elliptic curve cryptography algorithm, and dynamic key distribution is implemented according to the node trust level. The distributed DDC controller parses input commands, deploys an event-driven architecture in the protocol stack, and switches communication interfaces according to the input commands. Tasks are pre-assigned based on equipment capabilities, trust levels, and topology distances. The task execution status is dynamically adjusted and continuously monitored. An arbitration mechanism is initiated for dynamic adjustments. The arbitration mechanism includes calculating the topological sensitivity in the three-dimensional topological map, extracting the trust level of the conflicting device when an abnormal conflict is detected, calculating the impact entropy value of the task, and prioritizing the solution with the smallest entropy change. When two or more identical minimum values ​​exist, global arbitration is performed to initiate cross-domain negotiation. All controllers exchange the trust level and topology sensitivity of the topology map, and a weighted voting mechanism is adopted to select the scheme corresponding to the largest weight value. The arbitration result is updated to the nodes in reverse through the protocol stack.

2. The method for collaborative management of distributed DDC controllers in an open network as described in claim 1, characterized in that: The Wi-Fi channel state information includes: each node continuously scans the CSI data of surrounding APs, extracts the signal angle of arrival and delay characteristics, and uses the least squares method to solve the three-dimensional coordinates of the nodes based on the Wi-Fi channel state information to establish a three-dimensional topology map of the controller. The node's historical behavior data includes historical response latency and data integrity rate.

3. The method for collaborative management of distributed DDC controllers in an open network as described in claim 2, characterized in that: The dynamic key distribution includes a hierarchical key system based on elliptic curve cryptography, comprising a root key and a session key. The root key is jointly kept by the highest trusted node in the topology map and employs a threshold signature mechanism. The session key is dynamically assigned encryption strength based on the trust level. When the node's trust level is greater than or equal to the high trust threshold, a 256-bit key and the full protocol stack functionality are used. When the low trust threshold is less than or equal to the node trust level and less than the high trust threshold, limit the key validity period and disable management commands. When the node's trust level is less than the low trust threshold, only temporary keys are allocated and the session duration is compressed.

4. The method for collaborative management of distributed DDC controllers in an open network as described in claim 3, characterized in that: The step of switching communication interfaces based on input instructions includes deploying an event-driven architecture in the protocol stack, having a distributed DDC controller parse the input instructions, parse the instruction header fields, extract instruction features such as urgency, data volume, and number of associated nodes, and standardize the instruction features. The standardized instruction features are converted into feature vectors, the improved weighted Jaccard algorithm is called to calculate the initial correlation between events, the final correlation result is dynamically corrected based on the trust level, and the three communication interfaces of the protocol stack are switched according to the dynamically corrected final correlation result. When the final correlation result is greater than or equal to the preset first correlation threshold, the current controller interface will be switched to the real-time interface and the real-time mode will be adopted. When the preset second association threshold is less than or equal to the final association result and less than the preset first association threshold, the current controller will be switched to the aggregation interface and the aggregation mode will be adopted. When the final correlation result is less than the preset second correlation threshold, the current controller will be switched to the collaborative interface and the collaborative mode will be adopted.

5. The method for collaborative management of distributed DDC controllers in an open network as described in claim 4, characterized in that: The task pre-allocation includes task management in the implementation pre-allocation phase and the dynamic adjustment phase; In the pre-allocation phase, the task requirement document is parsed to extract key constraints such as equipment capability requirements, task timeliness, and resource dependencies, and an initial allocation plan is generated. The first priority is to match the device capability tags; The second priority is to select nodes whose trust level is greater than or equal to the high trust threshold; The third priority is to allocate based on proximity on the 3D topology map; During the dynamic adjustment phase, the task execution status is continuously monitored. When an abnormal conflict is detected, the arbitration mechanism is triggered. The current task progress, real-time device status, and the latest topology map information are input to execute the arbitration decision, reallocate the execution node, and roll back the data.

6. A system employing a distributed DDC controller collaborative management method in an open network as described in any one of claims 1 to 5, characterized in that: It includes a topology map construction module, a key protection module, an instruction parsing module, and a task allocation module; The topology map construction module constructs a three-dimensional topology map of the controller based on the Wi-Fi channel status information in the open network, and performs dynamic trust assessment based on the node's historical behavior data to output the node's trust level. The key protection module has a lightweight communication protocol stack built into each distributed DDC controller node. The protocol stack includes three communication interfaces: instant interface, aggregation interface, and collaborative interface. It generates a distributed key pool based on the elliptic curve cryptography algorithm and implements dynamic key distribution according to the node trust level. The instruction parsing module parses input instructions using the distributed DDC controller, deploys an event-driven architecture in the protocol stack, and switches communication interfaces based on the input instructions. The task allocation module pre-allocates tasks based on device capabilities, trust levels, and topology distance, dynamically adjusts and continuously monitors task execution status, and initiates an arbitration mechanism for dynamic adjustment.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the distributed DDC controller collaborative management method in an open network according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the distributed DDC controller collaborative management method in an open network according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method and system for cooperative work of distributed DDC controllers

    CN111885205A

  • Distributed DDC controller efficient collaborative management method and system

    CN119126562A