Cloud edge interaction system based on MQTT

Through the MQTT-based cloud-edge interactive system, the data processing of the edge computing layer and in-depth analysis of the cloud computing layer are used to solve the real-time and scalability problems of the Internet of Things system, and efficient and reliable data transmission and processing are achieved.

CN120455452APending Publication Date: 2025-08-08HONGZHENG ENERGY STORAGE (NANJING) DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510505537.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

There are problems in existing Internet of Things and cloud computing systems such as low data processing efficiency, insufficient real-time, strong network dependence and limited system scalability.

Method used

The cloud-edge interaction system based on MQTT is adopted, including the edge device layer, the edge computing layer, the MQTT message broker layer and the cloud computing layer, and data transmission and processing are carried out through the MQTT protocol. The edge computing layer performs data cleaning, protocol parsing and local analysis, the MQTT message broker layer realizes high concurrency processing and message persistent storage, and the cloud computing layer performs in-depth data analysis and control instruction generation.

Benefits of technology

It improves the real-time and response speed of the Internet of Things system, reduces data transmission delay, optimizes resource utilization efficiency, enhances the reliability and scalability of the system, and ensures reliable transmission of messages and data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455452A_ABST
    Figure CN120455452A_ABST
Patent Text Reader

Abstract

The invention provides an MQTT-based cloud edge interaction system. The MQTT-based cloud edge interaction system comprises an edge device layer, an edge computing layer, an MQTT message proxy layer and a cloud computing layer. The edge device layer is composed of Internet of Things devices, collects data and sends messages through an MQTT protocol. And the edge computing layer is deployed at a position close to the equipment layer, receives the message, performs data cleaning, protocol analysis, local analysis and decision making, and performs two-way communication with the cloud through the message agent layer. And the message agent layer is responsible for receiving and routing forwarding messages and is realized based on themes. And the cloud computing layer subscribes to a specified theme, receives the processed data, executes deep data analysis, generates a control instruction, and issues the control instruction to the edge computing layer through the proxy layer. The real-time performance and the resource utilization efficiency of the system can be improved, and the overall performance and the reliability of the system are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet of Things and cloud computing technology, and more specifically, to a cloud-edge interaction system based on MQTT. Background Art

[0002] In the context of the convergence of the Internet of Things (IoT) and cloud computing, existing systems often employ a centralized architecture, transmitting data collected by large numbers of IoT devices directly to the cloud for processing and analysis. While this architecture leverages the cloud's powerful computing capabilities, it suffers from issues such as high data transmission latency, high bandwidth usage, and slow response times in scenarios requiring high real-time performance. Furthermore, traditional data transmission protocols for communication between IoT devices and the cloud may not be able to efficiently handle the concurrent connections and message delivery of massive numbers of devices. Furthermore, centralized architectures are highly dependent on the network, compromising system reliability in the event of network instability or bandwidth constraints.

[0003] During the process of implementing the embodiments of the present invention, the inventors discovered that the prior art has at least the following problems or defects: low data processing efficiency, insufficient real-time performance, strong dependence on the network, and limited system scalability. Summary of the Invention

[0004] The present invention provides a cloud-edge interaction system based on MQTT, comprising:

[0005] Edge device layer, edge computing layer, MQTT message broker layer, and cloud computing layer;

[0006] The edge device layer is composed of multiple IoT devices, and the IoT devices are configured to collect data and send MQTT messages to the edge computing layer via the MQTT protocol;

[0007] The edge computing layer is deployed close to the edge device layer and is configured to receive MQTT messages sent by the edge device layer, perform data cleaning, protocol parsing, local analysis and decision-making, and conduct two-way communication with the cloud computing layer through the MQTT message proxy layer;

[0008] The MQTT message proxy layer is configured to receive and route MQTT messages from the edge device layer and the edge computing layer, wherein the routing and forwarding are implemented based on MQTT message topics;

[0009] The cloud computing layer is configured to subscribe to a specified topic of the MQTT message proxy layer, receive data processed by the edge computing layer, perform deep data analysis and generate control instructions, and send them to the edge computing layer through the MQTT message proxy layer.

[0010] Furthermore, the IoT devices at the edge device layer include sensors and smart terminals. The IoT devices encapsulate collected data as a payload of an MQTT message and set the message subject to at least one combination of device type, device identifier, and data type.

[0011] Furthermore, the data cleaning of the edge computing layer includes filtering out noise data and invalid data, the local analysis includes anomaly detection and real-time data visualization based on preset rules, and the edge computing layer is also configured to generate local control instructions based on the processing results or upload processed data to the cloud computing layer.

[0012] Furthermore, the MQTT message proxy layer adopts a high-concurrency processing mechanism, a message persistent storage mechanism, and a topic matching routing mechanism to ensure the reliable transmission of MQTT messages.

[0013] Furthermore, the deep data analysis of the cloud computing layer includes time series model analysis, data mining to generate data sets, integrated learning model training and prediction, and the control instructions include resource allocation strategies and system optimization strategies.

[0014] Furthermore, the system also includes an identity authentication module, which is configured to perform connection authentication on the edge device layer, edge computing layer and cloud computing layer based on a certificate or username and password. Devices or services that fail to pass the authentication are prohibited from accessing the MQTT message agent layer.

[0015] Furthermore, the system also includes a data encryption module, which is configured to encrypt the transmission process of MQTT messages using the SSL / TLS protocol. The edge device layer and the edge computing layer perform encryption operations before sending data, and the cloud computing layer performs decryption operations after receiving data.

[0016] Furthermore, the system also includes an access control module, which is configured to limit the publishing and subscription operations of the edge device layer, edge computing layer and cloud computing layer on MQTT messages based on device identity and subject permissions.

[0017] Furthermore, the edge device layer is only allowed to publish topics associated with its own collected data, and the cloud computing layer is only allowed to subscribe to topics of data uploaded by the edge computing layer.

[0018] Furthermore, the deployment of the system includes:

[0019] Install the MQTT client library on the edge device layer and configure device identity information;

[0020] Deploy edge computing servers at the edge computing layer and configure data processing rules and algorithms;

[0021] Build a message proxy server at the MQTT message proxy layer and set authentication, encryption and access control policies;

[0022] Configure cloud servers and develop data analysis applications in the cloud computing layer.

[0023] The above-mentioned embodiments according to the present invention have at least the following beneficial effects: the MQTT-based cloud-edge interaction system of the present invention can effectively improve the real-time performance and response speed of the Internet of Things system. By performing data cleaning, protocol parsing and local analysis and decision-making at the edge computing layer, the system can quickly process the data collected by the edge device layer, reduce dependence on the cloud, thereby reducing data transmission delays and improving the overall operating efficiency of the system. In addition, the high concurrency processing mechanism and message persistent storage mechanism of the MQTT message agent layer can ensure the reliable transmission of messages, and can also guarantee the integrity of the data and the stability of the system even in the case of unstable network.

[0024] At the same time, this invention can also optimize resource allocation and system performance. The cloud computing layer's deep data analysis capabilities, such as time series model analysis, data mining, and ensemble learning model training, enable more accurate analysis and prediction of processed data, generating efficient resource allocation and system optimization strategies. This architecture not only improves resource utilization efficiency but also enhances the system's scalability and flexibility, adapting to IoT application scenarios of varying scale and complexity. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] The above and other objects, features and advantages of the exemplary embodiments of the present invention will become readily apparent by reading the following detailed description with reference to the accompanying drawings, in which several embodiments of the present invention are shown by way of example and not limitation, in which:

[0026] Figure 1 A schematic diagram of the structure of a cloud-edge interaction system based on MQTT provided in one embodiment of the present invention. DETAILED DESCRIPTION

[0027] The principles and spirit of the present invention will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are provided solely to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. Rather, these embodiments are provided to make the present invention more thorough and complete, and to fully convey the scope of the present invention to those skilled in the art.

[0028] Those skilled in the art will appreciate that the embodiments of the present invention may be implemented as a system, apparatus, device, method, or computer program product. Therefore, the present invention may be implemented in the following forms: entirely in hardware, entirely in software (including firmware, resident software, microcode, etc.), or in a combination of hardware and software.

[0029] It should be noted that any number of elements in the drawings is for illustration only and not for limitation, and any naming is only for distinction and does not have any limiting meaning.

[0030] Reference below Figure 1 , Figure 1 This is a schematic diagram of the structure of the cloud-edge interaction system based on MQTT provided by one embodiment of the present invention. Figure 1 As shown, a cloud-edge interaction system based on MQTT includes:

[0031] Edge device layer, edge computing layer, MQTT message broker layer, and cloud computing layer;

[0032] The edge device layer is composed of multiple IoT devices, and the IoT devices are configured to collect data and send MQTT messages to the edge computing layer via the MQTT protocol;

[0033] The edge computing layer is deployed close to the edge device layer and is configured to receive MQTT messages sent by the edge device layer, perform data cleaning, protocol parsing, local analysis and decision-making, and conduct two-way communication with the cloud computing layer through the MQTT message proxy layer;

[0034] The MQTT message proxy layer is configured to receive and route MQTT messages from the edge device layer and the edge computing layer, wherein the routing and forwarding are implemented based on MQTT message topics;

[0035] The cloud computing layer is configured to subscribe to a specified topic of the MQTT message proxy layer, receive data processed by the edge computing layer, perform deep data analysis and generate control instructions, and send them to the edge computing layer through the MQTT message proxy layer.

[0036] It should be noted that the MQTT-based cloud-edge interaction system of the present invention includes an edge device layer, an edge computing layer, an MQTT message proxy layer and a cloud computing layer. The edge device layer is composed of multiple IoT devices, which send data to the edge computing layer through the MQTT protocol. The edge computing layer is deployed close to the edge device layer, responsible for receiving and processing these data, and then communicating bidirectionally with the cloud computing layer through the MQTT message proxy layer. The MQTT message proxy layer is responsible for receiving and routing these messages, and implementing routing based on the message topic. The cloud computing layer subscribes to the specified topic, receives the processed data, performs in-depth analysis and generates control instructions, which are sent to the edge computing layer through the MQTT message proxy layer.

[0037] Specifically, the edge device layer includes IoT devices such as sensors and smart terminals. These devices collect environmental data or device status data and encapsulate this data as the payload of MQTT messages. The MQTT protocol is a lightweight message transmission protocol suitable for low-bandwidth and unstable network environments. The edge computing layer is usually deployed close to the data source to reduce data transmission latency. The edge computing layer not only receives data but also performs tasks such as data cleaning, protocol parsing, local analysis, and decision-making. The MQTT message broker layer uses a high-concurrency processing mechanism and a message persistence storage mechanism to ensure reliable message transmission. The cloud computing layer receives and processes data uploaded by the edge computing layer by subscribing to designated topics of the MQTT message broker layer, and performs in-depth data analysis, such as time series model analysis and data mining.

[0038] Preferably, data cleaning at the edge computing layer includes filtering out noise data and invalid data, protocol parsing includes parsing of MQTT messages, and local analysis includes anomaly detection and real-time data visualization based on preset rules. The edge computing layer can also generate local control instructions based on the processing results or upload processed data to the cloud computing layer. The topic matching routing mechanism of the MQTT message proxy layer ensures that messages can be accurately transmitted to the cloud computing layer that subscribes to the topic. The deep data analysis of the cloud computing layer can include integrated learning model training and prediction, and the generated control instructions can include resource allocation strategies and system optimization strategies, which are sent to the edge computing layer through the MQTT message proxy layer to achieve control and optimization of edge devices.

[0039] In some embodiments, the IoT devices at the edge device layer include sensors and smart terminals. The IoT devices encapsulate collected data as the payload of an MQTT message and set the message subject to at least one combination of device type, device identifier, and data type.

[0040] It should be noted that the IoT devices at the edge device layer in the present invention include sensors and smart terminals. These devices can encapsulate the collected data into the payload of the MQTT message and set the message subject to at least one combination of the device type, device identifier and data type. IoT devices refer to devices that can be connected through a network and interact with data. Sensors are used to sense changes in the environment or physical quantities, such as temperature, humidity, pressure, etc., while smart terminals can be devices with computing and communication capabilities, such as smartphones and smart watches. The payload of an MQTT message refers to the data portion actually carried in the message, while the message subject is used to identify the content and source of the message, which facilitates routing and processing by the message proxy layer and the cloud computing layer.

[0041] Specifically, when encapsulating data, IoT devices can set the message subject based on the device type (such as sensor or smart terminal), device identification (such as the device's unique number), and data type (such as temperature data, humidity data, etc.). For example, a temperature sensor can set the message subject to sensor / temperature / 001, where sensor represents the device type, temperature represents the data type, and 001 represents the device identification. This topic setting method enables the message proxy layer to quickly identify the source and content of the message based on the topic and route it to the corresponding processing node. In actual applications, device types can include but are not limited to sensors, controllers, actuators, etc.; device identification can be the device's MAC address, serial number, or other unique identifier; and data types can cover a variety of forms such as environmental data, status data, and control instructions.

[0042] Preferably, IoT devices can also choose a more fine-grained topic setting method when encapsulating data based on actual needs. For example, for a multifunctional sensor, different types of measurement data can be set as different sub-topics, such as sensor / 001 / temperature and sensor / 001 / humidity, to more precisely control message routing and processing. In addition, to improve the flexibility and scalability of the system, devices can dynamically adjust message topics, such as changing the topic naming rules based on the device's operating status or user configuration instructions. In some application scenarios, the concept of a topic hierarchy can also be introduced, such as location / building / room / device / type. Through a multi-level topic structure, more complex routing strategies and data management functions can be implemented.

[0043] In some embodiments, the data cleaning of the edge computing layer includes filtering out noise data and invalid data, the local analysis includes anomaly detection and real-time data visualization based on preset rules, and the edge computing layer is also configured to generate local control instructions based on the processing results or upload processed data to the cloud computing layer.

[0044] It should be noted that the data cleaning of the edge computing layer in the present invention includes filtering noise data and invalid data, and the local analysis includes anomaly detection and real-time data visualization based on preset rules. The edge computing layer is also configured to generate local control instructions or upload processed data to the cloud computing layer based on the processing results. The edge computing layer is an intermediate layer located between the edge device layer and the cloud computing layer. Its main function is to perform preliminary processing and analysis on the data collected from the edge device layer to reduce the amount of data transmission and improve the real-time response capability of the system. Data cleaning refers to the removal of noise and invalid parts in the data to ensure the quality and availability of the data. Anomaly detection is to identify anomalies in the data through preset rules, while real-time data visualization is to display the processed data in an intuitive way to facilitate monitoring and decision-making.

[0045] Specifically, the data cleaning process at the edge computing layer can filter out noisy data by setting thresholds. For example, for temperature data collected by sensors, if the difference between a data point and the previous and subsequent data points exceeds a set threshold, it can be identified as noisy and filtered out. Invalid data can be identified by checking data integrity and format. For example, data with missing or malformed data can be marked as invalid and discarded. Anomaly detection in local analysis can be based on preset rules. For example, when the temperature detected by a sensor exceeds a set threshold, the system can identify it as an anomaly and trigger an alert. Real-time data visualization can present data in the form of charts or dashboards. For example, a line chart can be used to display temperature data trends over time. After processing data, the edge computing layer can generate local control instructions based on preset logic. For example, if the temperature is detected to be too high, an instruction can be generated to control air conditioning equipment to cool down. Alternatively, the processed data can be uploaded to the cloud computing layer for further in-depth analysis.

[0046] Preferably, more complex algorithms can be used for data cleaning at the edge computing layer. For example, machine learning algorithms can be used to classify data, identify and filter abnormal data points. In terms of anomaly detection, time series analysis methods can be introduced to predict future data trends by modeling historical data, and actual data can be compared with predicted values to detect anomalies more accurately. For real-time data visualization, geographic information system (GIS) technology can be combined to combine data with geographic location information to display the distribution of data in the form of a map. In addition, the edge computing layer can also dynamically adjust the frequency and method of data upload according to the importance and urgency of the data. For example, high-priority data can be uploaded to the cloud in real time, while low-priority data can be uploaded after batch processing.

[0047] In some embodiments, the MQTT message proxy layer adopts a high-concurrency processing mechanism, a message persistent storage mechanism, and a topic matching routing mechanism to ensure reliable transmission of MQTT messages.

[0048] It should be noted that the MQTT message proxy layer in the present invention adopts a high-concurrency processing mechanism, a message persistent storage mechanism and a topic matching routing mechanism to ensure the reliable transmission of MQTT messages. The MQTT message proxy layer is the core component responsible for message forwarding and management in the system. Its function is to receive messages from the edge device layer and the edge computing layer, and route them to the correct recipient according to the message subject. The high-concurrency processing mechanism refers to the system's ability to process a large number of concurrent messages at the same time, which is crucial for the access and data transmission of massive devices in the Internet of Things environment. The message persistent storage mechanism ensures that messages will not be lost due to network failures or system anomalies during transmission, while the topic matching routing mechanism distributes messages to clients that subscribe to the topic according to the message subject, thereby achieving efficient message delivery.

[0049] Specifically, a high-concurrency processing mechanism can be implemented by adopting a multi-threaded or multi-process architecture. For example, an independent thread or process is assigned to each connected device to process messages, thereby improving the system's concurrent processing capabilities. The message persistence storage mechanism can store messages in a local database or distributed storage system. For example, a relational database or NoSQL database is used to save the message content until the message is successfully delivered. The topic matching routing mechanism can distribute messages to clients that have subscribed to the corresponding topic based on preset rules and pattern matching algorithms. For example, if a client subscribes to the topic sensor / #, all messages starting with sensor / will be routed to the client. In addition, the message proxy layer can also set message priorities, schedule and process messages according to priority, and ensure that important messages are transmitted first.

[0050] Preferably, the MQTT message proxy layer can further optimize its high-concurrency processing mechanism, for example, by introducing load balancing technology to evenly distribute messages to multiple processing nodes, thereby improving the overall performance and scalability of the system. The message persistence storage mechanism can adopt a redundant storage strategy to store messages in multiple copies to improve data reliability and fault tolerance. The topic matching routing mechanism can support more complex topic expressions, for example, supporting fuzzy matching and hierarchical topics, thereby achieving a more flexible message distribution strategy. In addition, the message proxy layer can also provide a message confirmation mechanism to ensure that the message is correctly received and processed during the transmission process. If the message is not confirmed within the specified time, it can be automatically retransmitted, further improving the reliability of message transmission.

[0051] In some embodiments, the deep data analysis of the cloud computing layer includes time series model analysis, data mining to generate data sets, integrated learning model training and prediction, and the control instructions include resource allocation strategies and system optimization strategies.

[0052] It should be noted that the deep data analysis of the cloud computing layer in the present invention includes time series model analysis, data mining to generate data sets, integrated learning model training and prediction, and the control instructions include resource allocation strategies and system optimization strategies. The cloud computing layer is the core processing unit of the system, responsible for deep analysis and processing of the processed data uploaded by the edge computing layer to extract valuable information and generate corresponding control instructions. Time series model analysis is a statistical analysis method based on time series data, which is used to predict future trends of data; data mining is the process of extracting useful information from large amounts of data; integrated learning model training and prediction is to improve the accuracy and stability of predictions by building multiple learning models and combining them. Control instructions are instructions generated based on the analysis results to guide system operation or resource allocation.

[0053] Specifically, time series model analysis can employ the ARIMA (Autoregressive Integrated Moving Average) model or other time series analysis methods to model historical data time series and predict future data trends. Data mining can include techniques such as cluster analysis and association rule mining. For example, cluster analysis can be used to classify data into different categories to better understand the data distribution characteristics. Ensemble learning model training can employ algorithms such as random forests and gradient boosting trees, combining multiple weak learners to improve the model's predictive performance. Generated control instructions can include resource allocation strategies, such as dynamically adjusting the sampling frequency of edge devices or allocating computing resources. System optimization strategies can include optimizing data transmission paths or adjusting the processing rules of the edge computing layer. The parameters of these analysis and control strategies can be set based on the actual application scenario. For example, the parameters of the time series model can be adjusted based on the seasonality and trend of the data, and the parameters of the ensemble learning model can be optimized through methods such as cross-validation.

[0054] Preferably, the deep data analysis of the cloud computing layer can be further combined with deep learning technology, for example, using long short-term memory networks (LSTM) or convolutional neural networks (CNN) to model and predict time series data to improve the accuracy and efficiency of the analysis. In terms of data mining, more advanced algorithms such as density-based clustering algorithm (DBSCAN) or frequent pattern mining algorithm (Apriori) can be introduced to adapt to different types of data sets and analysis requirements. For the generation of control instructions, the resource allocation strategy can be dynamically adjusted according to the real-time analysis results, for example, automatically allocating computing tasks or adjusting network bandwidth according to the load conditions of the equipment. In addition, the system can also introduce an adaptive mechanism to automatically optimize the control strategy according to the operating status and performance indicators of the system to improve the overall performance and adaptability of the system.

[0055] In some embodiments, the system also includes an identity authentication module, which is configured to perform connection authentication on the edge device layer, edge computing layer and cloud computing layer based on a certificate or username and password. Devices or services that fail to pass the authentication are prohibited from accessing the MQTT message agent layer.

[0056] It should be noted that the system in the present invention also includes an identity authentication module, which is configured to perform connection authentication for the edge device layer, edge computing layer and cloud computing layer based on certificates or usernames and passwords. Devices or services that have not passed the authentication are prohibited from accessing the MQTT message broker layer. The identity authentication module is an important part of the system security mechanism. Its function is to ensure that only authorized devices and services can access the system, thereby preventing unauthorized access and data leakage. Certificate authentication is an authentication method based on digital certificates, which verifies the identity of a device or service through an encryption mechanism of public and private keys; username and password authentication is to authenticate the identity through a preset username and password. These two authentication methods can be used alone or in combination to improve the security of the system.

[0057] Specifically, the identity authentication module can adopt a variety of technical means during the implementation process. For certificate authentication, the X.509 digital certificate standard can be used. The device needs to provide a certificate when accessing the system. The authentication module confirms the identity of the device by verifying the validity of the certificate (such as the certificate authority, certificate validity period, certificate revocation status, etc.). For username and password authentication, a hash algorithm can be used to encrypt and store the password, and compare it during authentication. In terms of parameter settings, certificate authentication requires the configuration of the public key of the certificate authority (CA) to verify the legitimacy of the certificate; username and password authentication requires setting the complexity requirements of the username and password, such as password length, character types included, etc. In addition, the identity authentication module can also set parameters such as authentication timeout and number of retries to prevent brute force attacks.

[0058] Preferably, the identity authentication module can further enhance the security of the system. For example, in certificate authentication, a two-way authentication mechanism can be introduced, that is, not only the device's certificate is verified, but the device is also required to verify the server's certificate, thereby preventing man-in-the-middle attacks. For username and password authentication, multi-factor authentication (MFA), such as SMS verification code, fingerprint recognition or one-time password (OTP), can be combined to further improve the security of authentication. In addition, the identity authentication module can also be combined with the access control module to assign different permissions according to the identity and role of the device. For example, devices at the edge device layer are only allowed to publish data, while services at the cloud computing layer are only allowed to subscribe to data. This fine-grained permission management can effectively prevent unauthorized operations and further improve the security and reliability of the system.

[0059] In some embodiments, the system also includes a data encryption module, which is configured to encrypt the transmission process of MQTT messages using the SSL / TLS protocol. The edge device layer and the edge computing layer perform encryption operations before sending data, and the cloud computing layer performs decryption operations after receiving the data.

[0060] It should be noted that the system in the present invention also includes a data encryption module, which is configured to use the SSL / TLS protocol to encrypt the transmission process of the MQTT message. The function of the data encryption module is to ensure that the data transmitted between the edge device layer, the edge computing layer and the cloud computing layer is not stolen or tampered with during the transmission process, thereby ensuring the data security and privacy of the system. The SSL / TLS protocol is a widely used network security protocol that provides security for network communications by encrypting communication data, verifying the identities of both communicating parties, and ensuring the integrity of the data. In the present invention, the edge device layer and the edge computing layer perform encryption operations before sending data, and the cloud computing layer performs decryption operations after receiving the data, thereby ensuring the security of the data during transmission.

[0061] Specifically, the data encryption module needs to configure the relevant parameters of the SSL / TLS protocol during the implementation process. For example, it is necessary to select a suitable encryption algorithm, such as AES (Advanced Encryption Standard) or RSA (asymmetric encryption algorithm), and set the length of the encryption key. It is generally recommended to use a 128-bit or higher strength key to ensure the security of the encryption. At the same time, the certificate of the certificate authority (CA) needs to be configured to establish a trust relationship between the communicating parties. In actual applications, the data encryption module can integrate SSL / TLS libraries, such as OpenSSL or mbed TLS, in the MQTT client at the edge device layer and the edge computing layer, and enable SSL / TLS support in the MQTT server at the cloud computing layer. In addition, it is also necessary to set the encryption suite (CipherSuite), which defines the combination of encryption algorithms, key exchange algorithms, and message authentication algorithms to ensure the security and compatibility of communications.

[0062] Preferably, the data encryption module can be further optimized to improve the security and performance of the system. For example, two-way SSL / TLS authentication can be adopted, that is, not only the server's certificate is verified, but the client is also required to provide a certificate, thereby further enhancing the security of communication. In addition, a session cache mechanism can be introduced to reduce repeated handshake processes and improve communication efficiency. In terms of key management, encryption keys can be updated regularly to prevent the risks brought by key leakage. For lightweight devices at the edge device layer, lightweight encryption algorithms such as ECC (elliptic curve cryptography) can be used to reduce computing and storage overhead. At the same time, a hardware security module (HSM) can also be combined to store and manage keys to further improve the security of the keys.

[0063] In some embodiments, the system further includes an access control module configured to restrict the publishing and subscription operations of the edge device layer, edge computing layer, and cloud computing layer on MQTT messages based on device identity and topic permissions.

[0064] It should be noted that the system in the present invention also includes an access control module, which is configured to limit the publishing and subscription operations of the edge device layer, edge computing layer and cloud computing layer on MQTT messages based on device identity and subject permissions. The access control module is an important part of the system security mechanism. Its function is to ensure that only authorized devices and services can operate on messages of specific topics, thereby preventing unauthorized data access and potential security risks. Device identity refers to the unique identification of the device, such as device ID or certificate information; subject permissions refer to the range of message topics that the device or service is allowed to operate. By managing subject permissions, fine-grained access control can be achieved.

[0065] Specifically, the access control module needs to identify and verify the device identity during the implementation process. For example, the device identity can be identified by means of device ID, certificate, or username and password. Topic permissions can be managed through an access control list (ACL), which defines the range of topics that each device or service is allowed to access. In terms of parameter settings, the access control module can be configured to allow or deny specific devices from publishing or subscribing to certain topics. For example, devices at the edge device layer can be set to only allow the publication of topics associated with their own collected data, while services at the cloud computing layer are only allowed to subscribe to data topics processed by the edge computing layer. In addition, the access control module can also be combined with the identity authentication module to ensure that only devices and services that have passed identity authentication can perform message operations.

[0066] Preferably, the access control module can further refine its functions to improve the security and flexibility of the system. For example, role-based access control (RBAC) can be introduced to assign different roles to different types of devices and services, and define their access rights based on the roles. This can simplify permission management while improving the scalability of the system. In addition, the access control module can support dynamic permission adjustment and update the permission settings in real time based on the operating status of the device or the user's configuration instructions. For example, when abnormal behavior is detected, the access rights of the device can be temporarily restricted until the problem is resolved. For the management of topic permissions, the concept of wildcards or hierarchical topics can be introduced to allow devices to subscribe to or publish a wider range of topics while ensuring the accuracy of permission control.

[0067] In some embodiments, the edge device layer is only allowed to publish topics associated with its own collected data, and the cloud computing layer is only allowed to subscribe to topics of data uploaded by the edge computing layer.

[0068] It should be noted that in the present invention, the edge device layer is only allowed to publish topics associated with its own collected data, and the cloud computing layer is only allowed to subscribe to topics of data uploaded by the edge computing layer. This access control strategy is one of the specific implementation methods of the access control module, which aims to further enhance the security of the system and the controllability of data by limiting the permissions for message publishing and subscription. The edge device layer publishes topics associated with its own collected data, which means that the device can only send messages related to its functions and collection scope, avoiding the unauthorized release of data. The cloud computing layer subscribes to the topic of data uploaded by the edge computing layer, which ensures that the cloud only receives data processed and verified by the edge computing layer, improving the accuracy and security of the data.

[0069] Specifically, when devices in the edge device layer publish messages, their topics should be strictly associated with the data type and device identification of the data they collect. For example, the device identification of a temperature sensor is sensor001, and the data type it collects is temperature, then the topic of its published message can be set to sensor001 / temperature. This topic naming method not only clarifies the source of the data, but also makes it easier for the edge computing layer and the cloud computing layer to classify and process messages. The topic subscribed by the cloud computing layer should be consistent with the topic of the data uploaded by the edge computing layer. For example, the edge computing layer uploads the processed data with the topic processed / temperature, then the cloud computing layer should subscribe to this topic to receive the data. In terms of parameter settings, the access control module can be configured to only allow devices in the edge device layer to publish topics that match their device identification and data type, while restricting the cloud computing layer to subscribe to specific topics that have been processed by the edge computing layer.

[0070] Preferably, the access control module can further refine the management of topic access rights. For example, dynamic topic permissions can be set for devices at the edge device layer, and the range of topics allowed to be published can be adjusted in real time according to the operating status of the device or environmental changes. For the cloud computing layer, a multi-level subscription mechanism can be introduced to allow the cloud to subscribe to topics at different levels based on the importance and processing priority of the data. For example, the cloud can subscribe to the processed / temperature / high-priority topic to obtain high-priority data, and subscribe to the processed / temperature / low-priority topic to obtain low-priority data. In addition, a topic access log function can be introduced to record the behavior of devices publishing and subscribing to topics, which is convenient for system administrators to monitor and audit, and to promptly detect and handle abnormal access behaviors.

[0071] In some embodiments, deployment of the system includes:

[0072] Install the MQTT client library on the edge device layer and configure device identity information;

[0073] Deploy edge computing servers at the edge computing layer and configure data processing rules and algorithms;

[0074] Build a message proxy server at the MQTT message proxy layer and set authentication, encryption and access control policies;

[0075] Configure cloud servers and develop data analysis applications in the cloud computing layer.

[0076] It should be noted that the deployment of the system in the present invention involves the specific configuration and implementation steps of the edge device layer, edge computing layer, MQTT message proxy layer and cloud computing layer. The edge device layer needs to install the MQTT client library and configure the device identity information so that the device can communicate with the system through the MQTT protocol; the edge computing layer needs to deploy the edge computing server and configure the data processing rules and algorithms to realize local processing and analysis of data; the MQTT message proxy layer needs to build a message proxy server and set up authentication, encryption and access control policies to ensure the secure transmission and reliable routing of messages; the cloud computing layer needs to configure the cloud server and develop data analysis applications to complete in-depth data analysis and control instruction generation. These deployment steps ensure that the overall architecture of the system can operate efficiently and securely.

[0077] Specifically, deployment at the edge device layer requires installing a client library that supports the MQTT protocol for each IoT device, such as open-source libraries like Paho MQTT or Eclipse Mosquitto, and configuring unique device identities, such as device IDs or certificates. Deploying the edge computing layer requires selecting an appropriate hardware platform (such as an industrial-grade server or embedded device) and developing or deploying data processing rules and algorithms based on the application scenario. For example, scripts for data cleansing and anomaly detection can be written in Python or C++. Deploying the MQTT message broker layer requires setting up a message broker server, such as EMQX or RabbitMQ, and configuring relevant security policies, including SSL / TLS encryption, access control lists (ACLs), and user authentication mechanisms. Deploying the cloud computing layer requires configuring a high-performance cloud server, developing data analysis applications based on time series analysis, data mining, or machine learning, and ensuring that they seamlessly integrate with the MQTT message broker layer. Regarding parameter settings, computing resources and network bandwidth should be appropriately allocated for each layer based on the system's scale and requirements.

[0078] Preferably, the deployment of the system can be further optimized to improve performance and scalability. For example, at the edge device layer, a lightweight MQTT client library can be used to adapt to resource-constrained devices, and a firmware update mechanism can be used to ensure timely upgrades of device software. At the edge computing layer, containerization technology (such as Docker) can be introduced to deploy data processing applications for rapid expansion and management. The MQTT message broker layer can adopt a distributed architecture, such as an EMQX cluster, to support concurrent connections and message processing for large-scale devices. The cloud computing layer can use cloud-native technologies (such as Kubernetes) to deploy and manage applications, while combining elastic computing resources (such as AWS Auto Scaling or Alibaba Cloud Elastic Scaling) to meet performance requirements under different loads. In addition, the system can also introduce monitoring and log management tools, such as Prometheus and ELKStack, to monitor the system's operating status in real time and record key information to facilitate troubleshooting and performance optimization.

[0079] The above-mentioned various embodiments of the present invention have the following beneficial effects: the MQTT-based cloud-edge interaction system of the present invention can significantly improve the real-time performance and response speed of the Internet of Things system. By performing data cleaning, protocol parsing and local analysis and decision-making at the edge computing layer, the system can quickly process the data collected by the edge device layer, reduce dependence on the cloud, thereby reducing data transmission delays and improving the overall operating efficiency of the system. In addition, the high concurrency processing mechanism and message persistent storage mechanism of the MQTT message agent layer can ensure the reliable transmission of messages, and can guarantee the integrity of the data and the stability of the system even in the case of unstable network.

[0080] At the same time, the present invention can also optimize resource allocation and system performance. The deep data analysis functions of the cloud computing layer, such as time series model analysis, data mining, and integrated learning model training, can perform more accurate analysis and prediction of processed data, and generate efficient resource allocation strategies and system optimization strategies. The identity authentication module and data encryption module can enhance the security of the system, ensuring that only authenticated devices and services can access the system, and encrypt data transmission through the SSL / TLS protocol to prevent data leakage. The access control module can restrict message publishing and subscription operations based on device identity and subject permissions, further improving the security and reliability of the system.

[0081] Furthermore, the storage medium of the embodiment of the present application stores program instructions that can implement all the above methods, wherein the program instructions can be stored in the above storage medium in the form of a software product, including a number of instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, or a terminal device such as a computer, a server, a mobile phone, or a tablet.

[0082] The above descriptions are merely some preferred embodiments of the present invention and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present invention is not limited to the technical solutions formed by a specific combination of the above-mentioned technical features, but should also encompass other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the above-mentioned inventive concept. For example, a technical solution formed by mutually replacing the above-mentioned features with (but not limited to) technical features having similar functions disclosed in the embodiments of the present invention.

Claims

1. A cloud-edge interaction system based on MQTT, characterized in that: Includes edge device layer, edge computing layer, MQTT message broker layer and cloud computing layer; The edge device layer is composed of multiple IoT devices, and the IoT devices are configured to collect data and send MQTT messages to the edge computing layer via the MQTT protocol; The edge computing layer is deployed close to the edge device layer and is configured to receive MQTT messages sent by the edge device layer, perform data cleaning, protocol parsing, local analysis and decision-making, and conduct two-way communication with the cloud computing layer through the MQTT message proxy layer; The MQTT message proxy layer is configured to receive and route MQTT messages from the edge device layer and the edge computing layer, wherein the routing and forwarding are implemented based on MQTT message topics; The cloud computing layer is configured to subscribe to a specified topic of the MQTT message proxy layer, receive data processed by the edge computing layer, perform deep data analysis and generate control instructions, and send them to the edge computing layer through the MQTT message proxy layer.

2. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The IoT devices at the edge device layer include sensors and smart terminals. The IoT devices encapsulate collected data as the payload of an MQTT message and set the message subject to at least one combination of device type, device identifier, and data type.

3. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The data cleaning of the edge computing layer includes filtering out noisy data and invalid data, the local analysis includes anomaly detection and real-time data visualization based on preset rules, and the edge computing layer is also configured to generate local control instructions based on the processing results or upload processed data to the cloud computing layer.

4. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The MQTT message proxy layer adopts a high-concurrency processing mechanism, a message persistent storage mechanism, and a topic matching routing mechanism to ensure the reliable transmission of MQTT messages.

5. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The deep data analysis of the cloud computing layer includes time series model analysis, data mining to generate data sets, integrated learning model training and prediction, and the control instructions include resource allocation strategies and system optimization strategies.

6. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The system also includes an identity authentication module, which is configured to perform connection authentication on the edge device layer, edge computing layer and cloud computing layer based on a certificate or username and password. Devices or services that fail to pass the authentication are prohibited from accessing the MQTT message broker layer.

7. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The system also includes a data encryption module, which is configured to encrypt the transmission process of MQTT messages using the SSL / TLS protocol. The edge device layer and the edge computing layer perform encryption operations before sending data, and the cloud computing layer performs decryption operations after receiving data.

8. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The system also includes an access control module, which is configured to limit the publishing and subscription operations of the edge device layer, edge computing layer and cloud computing layer on MQTT messages based on device identity and subject permissions.

9. The MQTT-based cloud-edge interaction system according to claim 8, characterized in that: The edge device layer is only allowed to publish topics associated with its own collected data, and the cloud computing layer is only allowed to subscribe to topics of data uploaded by the edge computing layer.

10. The MQTT-based cloud-edge interaction system according to claim 1, characterized in that: The deployment of the system includes: Install the MQTT client library on the edge device layer and configure device identity information; Deploy edge computing servers at the edge computing layer and configure data processing rules and algorithms; Build a message proxy server at the MQTT message proxy layer and set authentication, encryption and access control policies; Configure cloud servers and develop data analysis applications in the cloud computing layer.

Citation Information

Patent Citations

  • Predictive maintenance system and method for power transformation equipment in edge computing scene

    CN118869512A

  • Data real-time analysis and decision-making system based on edge intelligent Internet of Things

    CN119603297A