Intelligent terminal safety communication method, system and device based on edge computing

Through the encrypted channel transmission between edge computing nodes and smart terminal devices and zero-trust architecture authentication, the problem of insufficient data transmission delay and security of smart terminal devices is solved, high-speed and high-reliability communication is achieved, operating costs are reduced, and complex network environments are adapted.

CN120474819APending Publication Date: 2025-08-12CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD

Patent Information

Application Number
CN202510831772.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The data transmission of existing smart terminal devices has problems such as high network latency, insufficient security, and insufficient flexibility and scalability of centralized architecture, which is difficult to meet the needs of high-speed and high-reliability communication.

Method used

Edge computing nodes and smart terminal devices are used to establish encrypted channels for data encryption transmission, and authenticate and authorize through zero-trust architecture. The operating status of edge computing nodes is monitored in real time, and abnormal warning is used to use remote management units to ensure data security, combining encrypted communication and differential privacy technology.

Benefits of technology

Significantly reduce network latency, improve communication efficiency and security, reduce data leakage risks, simplify system maintenance, enhance system reliability and flexibility, and adapt to network conditions and privacy regulations in different regions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474819A_ABST
    Figure CN120474819A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent terminal secure communication method, system and device based on edge computing, and relates to the technical field of secure communication. The method comprises the following steps: an edge computing node is in communication connection with intelligent terminal equipment through a secure communication module; after communication connection is established between the edge computing node and the intelligent terminal equipment, data encryption transmission is carried out between the edge computing node and the intelligent terminal equipment through an encryption channel; and in a data encryption transmission process between the edge computing node and the intelligent terminal equipment, monitoring an operation state of the edge computing node in real time, and when the operation state of the edge computing node is abnormal, sending a node abnormity early warning prompt to an operation and maintenance personnel terminal. The communication efficiency and safety of the intelligent terminal can be improved, and the requirements of the intelligent terminal for high-speed and high-reliability communication are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of secure communication technology, and in particular to a method, system and device for secure communication of smart terminals based on edge computing. Background Art

[0002] With the development of IoT technology, smart devices have become a key component of the IoT ecosystem. Smart devices include but are not limited to smartphones, wearables, smart home appliances, IoT sensors, and advanced AI-assisted systems. These devices continuously collect and generate large amounts of data during operation, including user location, device status, usage behavior, sensor data, and even voice and video recordings. This data from smart devices is primarily used for real-time monitoring, fault warnings, personalized services, content distribution, and intelligent interactive features. However, the collection and use of this data has also raised concerns about data privacy and security. Smart device data is sensitive because it may contain private information such as personal information, usage habits, and even user activity history. Currently, data from smart devices is mostly transmitted via wireless networks to centralized cloud servers for processing and storage. While centralized cloud servers offer powerful data processing and storage capabilities, they also have limitations, such as unstable data transmission, high latency, and security risks. Specifically, the main drawback of existing technologies is their over-reliance on centralized servers, which not only limits system performance but also increases security risks in data transmission and processing. Furthermore, centralized architectures lack sufficient flexibility and scalability, making them difficult to adapt to rapidly changing application needs and data growth.

[0003] Therefore, a new technical means is needed to overcome the limitations of existing technologies and provide a more secure, efficient and reliable terminal communication solution. Summary of the Invention

[0004] Purpose of the invention: A method, system and device for secure communication of smart terminals based on edge computing to solve the above-mentioned technical problems existing in the prior art.

[0005] The first aspect of the present invention provides a secure communication method for an intelligent terminal based on edge computing, comprising the following steps:

[0006] The edge computing node communicates with the smart terminal device through a secure communication module;

[0007] After establishing a communication connection between the edge computing node and the smart terminal device, encrypting and transmitting data between the edge computing node and the smart terminal device through an encrypted channel;

[0008] During the data encryption transmission process between the edge computing node and the smart terminal device, the operating status of the edge computing node is monitored in real time, and when there is an abnormality in the operating status of the edge computing node, a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

[0009] Furthermore, the edge computing node communicates with the smart terminal device through a secure communication module, including:

[0010] Performing initial information data configuration for the communication connection between the smart terminal device and the edge computing node, wherein the initial information data configuration includes but is not limited to IP address configuration, port number configuration, security policy configuration, encryption policy and protocol configuration, and authentication policy and key configuration;

[0011] Starting the secure communication module configured within the smart terminal device and the edge computing node, and performing authentication and authorization operations between the secure communication module configured within the smart terminal device and the edge computing node through a Zero Trust Architecture authentication method, thereby completing authentication and authorization between the secure communication module configured within the smart terminal device and the edge computing node;

[0012] After the secure communication module is started, the secure communication module is controlled to create an encrypted communication channel and an encrypted communication connection based on TLS and / or SSL between the smart terminal device and the edge computing node.

[0013] Furthermore, after establishing a communication connection between the edge computing node and the smart terminal device, performing encrypted data transmission between the edge computing node and the smart terminal device through an encrypted channel includes:

[0014] Before the edge computing node transmits data to the smart terminal device, controlling the smart terminal device to process and encrypt the sensitive data, and obtaining an encrypted data packet corresponding to the data to be transmitted;

[0015] The smart terminal device transmits the encrypted data packet corresponding to the data to be transmitted to the edge computing node through the encrypted channel created by the secure communication module;

[0016] After receiving the encrypted data packet corresponding to the data to be transmitted, the edge computing node decrypts the data packet to obtain data information corresponding to the data to be transmitted;

[0017] Performing data integrity verification on the data information corresponding to the data to be transmitted to obtain a data integrity verification result;

[0018] When the data integrity verification result indicates that the data information corresponding to the data to be transmitted is incomplete, a data incompleteness warning is issued.

[0019] Furthermore, during the data encryption transmission process between the edge computing node and the smart terminal device, the operating status of the edge computing node is monitored in real time, and when the operating status of the edge computing node is abnormal, a node abnormality warning prompt is sent to the operation and maintenance personnel terminal, including:

[0020] Control the remote management unit to monitor and collect the operating status parameters of the edge computing node during the communication process in real time under each operating unit time, wherein the operating status parameters include the number of thread locks, thread abnormal exit coefficient, memory utilization, and network signal strength fluctuation amplitude; and the operating unit time has a value range of 1s-10s;

[0021] The characteristic matrix is obtained by using the operating state parameters of the edge computing node in the communication process under each operating unit time, wherein the structure of the characteristic matrix is as follows:

[0022]

[0023] Where F represents the feature matrix; L(t1), L(t2), ..., L(t n ) represent the number of thread deadlocks from the first running unit time to the nth running unit time; E(t1), E(t2), ..., E(t n ) represent the thread abnormal exit coefficients corresponding to the first running unit time to the nth running unit time; M(t1), M(t2), ..., M(t n ) represent the memory utilization corresponding to the first running unit time to the nth running unit time; S(t1), S(t2), ..., S(t n ) represent the fluctuation amplitude of the network signal strength from the first operating unit time to the nth operating unit time;

[0024] The characteristic matrix is used to obtain the norm corresponding to the characteristic matrix, wherein the norm of the characteristic matrix is obtained by the following formula:

[0025]

[0026] Among them, ||F|| f represents the norm corresponding to the feature matrix; n represents the total number of running unit time; F ij represents the parameter data value corresponding to the i-th row and j-th column in the feature matrix F;

[0027] Obtain the row vector norm corresponding to each row vector for the feature matrix F; wherein the row vector norm is obtained by the following formula:

[0028]

[0029] Among them, ||F i || represents the row vector norm corresponding to the row vector of the i-th row in the feature matrix F; L(t i )、E(t i )、M(t i ) and S(t i ) represent the parameter values of the thread deadlock count, thread abnormal exit coefficient, memory utilization and network signal strength fluctuation amplitude contained in the row vector of the i-th row respectively;

[0030] The comprehensive operation evaluation parameter of the edge computing node is obtained by using the norm corresponding to the characteristic matrix and the row vector modulus corresponding to each row vector; wherein the comprehensive operation evaluation parameter is obtained by the following formula:

[0031]

[0032] Among them, Q represents the comprehensive operation evaluation parameter; ||F|| f Represents the norm corresponding to the feature matrix; ||F i || represents the row vector modulus corresponding to the row vector of the i-th row in the feature matrix F; n represents the total number of running unit time; σ(S) represents the standard deviation value corresponding to the fluctuation amplitude of the network signal strength; S p represents the average value of the network signal strength fluctuation amplitude; K represents the network signal fluctuation coefficient, and the network signal fluctuation coefficient is obtained by the following formula:

[0033]

[0034] Among them, K represents the network signal fluctuation coefficient; S z Indicates the median value of the network signal strength fluctuation range; S p Indicates the average value of the fluctuation amplitude of network signal strength;

[0035] The comprehensive operation evaluation parameter is compared with the preset evaluation parameter threshold. When the comprehensive operation evaluation parameter is lower than the preset evaluation parameter threshold, it is determined that there is an abnormality in the operation of the edge computing node, and a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

[0036] A second aspect of the present invention provides a secure communication system for smart terminals based on edge computing, the system comprising:

[0037] The communication connection module is used for the edge computing node to communicate with the intelligent terminal device through the secure communication module;

[0038] A data encryption transmission module is used to encrypt and transmit data between the edge computing node and the smart terminal device through an encrypted channel after a communication connection is established between the edge computing node and the smart terminal device;

[0039] The abnormality determination and warning module is used to monitor the operating status of the edge computing node in real time during the data encryption transmission between the edge computing node and the smart terminal device, and send a node abnormality warning prompt to the operation and maintenance personnel terminal when there is an abnormality in the operating status of the edge computing node.

[0040] Furthermore, the communication connection module includes:

[0041] An initial information data configuration module, configured to perform initial information data configuration for the communication connection between the intelligent terminal device and the edge computing node, wherein the initial information data configuration includes but is not limited to IP address configuration, port number configuration, security policy configuration, encryption policy and protocol configuration, and authentication policy and key configuration;

[0042] A startup operation module is used to start the secure communication module configured internally between the smart terminal device and the edge computing node, and perform authentication and authorization operations between the secure communication module configured internally between the smart terminal device and the edge computing node through a Zero Trust Architecture authentication method, thereby completing authentication and authorization between the secure communication module configured internally between the smart terminal device and the edge computing node;

[0043] A communication connection establishment module is used to control the secure communication module to create an encrypted communication channel and encrypted communication connection based on TLS and / or SSL between the smart terminal device and the edge computing node after the secure communication module is started.

[0044] Furthermore, the data encryption transmission module includes:

[0045] A data packet acquisition module is used to control the smart terminal device to process and encrypt sensitive data before the edge computing node transmits data to the smart terminal device, and obtain an encrypted data packet corresponding to the data to be transmitted;

[0046] A data transmission execution module, configured for transmitting the encrypted data packet corresponding to the data to be transmitted to the edge computing node via the encrypted channel created by the secure communication module;

[0047] A decryption module is used for the edge computing node to decrypt the encrypted data packet corresponding to the data to be transmitted after receiving the data packet to obtain data information corresponding to the data to be transmitted;

[0048] A data integrity verification module is used to perform data integrity verification on the data information corresponding to the data to be transmitted and obtain a data integrity verification result;

[0049] The data incomplete warning module is used to issue a data incomplete warning when the data integrity verification result indicates that the data information corresponding to the data to be transmitted is in a data incomplete state.

[0050] Furthermore, the abnormality determination and early warning module includes:

[0051] An operating status parameter acquisition module is used to control the remote management unit to monitor and collect the operating status parameters of the edge computing node during the communication process in real time for each operating unit time. The operating status parameters include the number of thread locks, thread abnormal exit coefficient, memory utilization, and network signal strength fluctuation amplitude. The operating unit time has a value range of 1s-10s.

[0052] The feature matrix acquisition module is used to obtain a feature matrix using the operating state parameters of the edge computing node during the communication process under each operating unit time, wherein the structure of the feature matrix is as follows:

[0053]

[0054] Where F represents the feature matrix; L(t1), L(t2), ..., L(t n ) represent the number of thread deadlocks from the first running unit time to the nth running unit time; E(t1), E(t2), ..., E(t n ) represent the thread abnormal exit coefficients corresponding to the first running unit time to the nth running unit time; M(t1), M(t2), ..., M(t n ) represent the memory utilization corresponding to the first running unit time to the nth running unit time; S(t1), S(t2), ..., S(t n ) represent the fluctuation amplitude of the network signal strength from the first operating unit time to the nth operating unit time;

[0055] A norm acquisition module is used to use the characteristic matrix to obtain the norm corresponding to the characteristic matrix, wherein the norm of the characteristic matrix is obtained by the following formula:

[0056]

[0057] Among them, ||F|| f represents the norm corresponding to the feature matrix; n represents the total number of running unit time; F ij represents the parameter data value corresponding to the i-th row and j-th column in the feature matrix F;

[0058] A row vector modulus acquisition module is used to obtain the row vector modulus corresponding to each row vector of the feature matrix F; wherein the row vector modulus is obtained by the following formula:

[0059]

[0060] Among them, ||F i || represents the row vector norm corresponding to the row vector of the i-th row in the feature matrix F; L(t i )、E(t i )、M(t i ) and S(t i ) represent the parameter values of the thread deadlock count, thread abnormal exit coefficient, memory utilization and network signal strength fluctuation amplitude contained in the row vector of the i-th row respectively;

[0061] A comprehensive operation evaluation parameter acquisition module is used to obtain the comprehensive operation evaluation parameters of the edge computing node using the norm corresponding to the feature matrix and the row vector modulus corresponding to each row vector; wherein the comprehensive operation evaluation parameters are obtained by the following formula:

[0062]

[0063] Among them, Q represents the comprehensive operation evaluation parameter; ||F|| f Represents the norm corresponding to the feature matrix; ||F i || represents the row vector modulus corresponding to the row vector of the i-th row in the feature matrix F; n represents the total number of running unit time; σ(S) represents the standard deviation value corresponding to the fluctuation amplitude of the network signal strength; S p represents the average value of the network signal strength fluctuation amplitude; K represents the network signal fluctuation coefficient, and the network signal fluctuation coefficient is obtained by the following formula:

[0064]

[0065] Among them, K represents the network signal fluctuation coefficient; S z Indicates the median value of the network signal strength fluctuation range; S p Indicates the average value of the fluctuation amplitude of network signal strength;

[0066] The abnormal warning execution module is used to compare the comprehensive operation evaluation parameter with the preset evaluation parameter threshold. When the comprehensive operation evaluation parameter is lower than the preset evaluation parameter threshold, it is determined that there is an abnormality in the operation of the edge computing node, and a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

[0067] The third aspect of the present invention proposes a smart terminal security communication device based on edge computing, which includes an edge computing node, a security communication module and a smart terminal device; wherein the edge computing node is communicated with the smart terminal device through the security communication module; and the security communication module is respectively arranged in the edge computing node and the smart terminal device.

[0068] Furthermore, the edge computing-based smart terminal security communication device also includes a remote management unit, which is connected to the edge computing node through a network, wherein the remote management unit and the edge computing node are connected through a homogeneous VPN tunnel or SSH.

[0069] Beneficial effects:

[0070] The present invention proposes a method, system, and device for secure communication of smart terminals based on edge computing. By deploying computing nodes at the edge of the network and integrating large artificial intelligence models, data processing can be localized, significantly reducing network latency and improving response speed. The system uses encrypted communication, differential privacy technology, and trusted data transmission protocols to effectively improve the security of data transmission, reduce the risk of data leakage and tampering, and protect the privacy of smart terminal users. At the same time, the introduction of a remote management unit can simplify the maintenance and management of the system and enhance the reliability and flexibility of the system. In addition, the system design can optimize bandwidth usage, support complex computing tasks, and adapt to network conditions and privacy regulations in different regions, providing strong technical support for the development of smart terminals.

[0071] In general, the edge computing-based smart terminal secure communication method, system and device proposed in the present invention can not only improve the efficiency and security of smart terminal communication, but also reduce operating costs, meet the smart terminal's needs for high-speed and high-reliability communication, and demonstrate broad market application potential and significant socio-economic value. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] Figure 1 The present invention is a flowchart of the method.

[0073] Figure 2 This is a system block diagram of the system of the present invention. DETAILED DESCRIPTION

[0074] In the following description, numerous specific details are provided to provide a more thorough understanding of the present invention. However, it will be apparent to those skilled in the art that the present invention may be practiced without one or more of these details. In other instances, certain technical features well known in the art have not been described to avoid confusion with the present invention.

[0075] The embodiment of the present invention proposes a secure communication method for an intelligent terminal based on edge computing. As shown in 1, the secure communication method for an intelligent terminal based on edge computing includes:

[0076] S1. The edge computing node communicates with the smart terminal device through a secure communication module;

[0077] S2. After establishing a communication connection between the edge computing node and the smart terminal device, encrypt and transmit data between the edge computing node and the smart terminal device through an encrypted channel;

[0078] S3. During the data encryption transmission process between the edge computing node and the smart terminal device, the operating status of the edge computing node is monitored in real time, and when there is an abnormality in the operating status of the edge computing node, a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

[0079] The working principle of the above technical solution is as follows: This embodiment provides a secure communication method for smart terminals based on edge computing. The system corresponding to this secure communication method for smart terminals based on edge computing includes: edge computing nodes, a secure communication module, a trusted data transmission protocol, and a remote management unit. The edge computing nodes are the core of the system and are deployed at the edge of the network, as close as possible to the smart terminal devices. They are responsible for performing real-time data processing and storage tasks, reducing dependence on central servers and thus reducing network latency. Edge computing nodes have computing power and can run various applications and services. At the same time, edge computing nodes also have data caching capabilities, temporarily storing data from terminal devices until it can be securely transmitted to a cloud server or processed locally. At the same time, large artificial intelligence models are integrated into edge computing nodes, enabling them to quickly handle complex tasks such as image recognition, speech processing, and real-time data analysis. This enhances the intelligent processing capabilities of edge nodes.

[0080] The secure communication module is integrated into edge computing nodes and smart terminal devices and is responsible for establishing an encrypted communication channel. The secure communication module adopts a zero-trust architecture to ensure that each communication node is strictly authenticated and authorized, whether in edge computing nodes or between smart terminal devices, thereby further enhancing the security of the system. Data encryption technology (such as TLS, etc.) is used in the communication process and differential privacy technology is introduced to protect user privacy by adding noise to the data while still allowing useful analysis of the data. This can enhance the system's privacy protection capabilities when processing sensitive data, ensure that data is protected during transmission between smart terminal devices and edge computing nodes, prevent man-in-the-middle attacks and data tampering, and avoid user privacy leaks.

[0081] The Trusted Data Transmission Protocol complements the secure communication module to ensure the integrity and credibility of data transmission. It verifies the source and integrity of data through mechanisms such as digital signatures and message authentication codes, ensuring that data is not tampered with during transmission.

[0082] The remote management unit provides system administrators with an interface for remotely managing edge computing nodes. Through this unit, administrators can monitor the status of edge nodes, configure security policies, update software and firmware, and perform troubleshooting and system maintenance when necessary.

[0083] Edge computing nodes and smart terminal devices are connected through encrypted channels of secure communication modules to achieve real-time data collection and processing.

[0084] Edge computing nodes are connected to a remote management unit over a network, typically through a secure VPN tunnel or SSH connection, allowing administrators to remotely access and configure them.

[0085] The secure communication module is responsible for establishing an encrypted connection, while the trusted data transmission protocol implements data integrity verification and authentication on the connection. The two work together to provide end-to-end secure communication protection.

[0086] In this system, smart end devices first establish a secure connection with edge computing nodes via a secure communication module and then send data using a trusted data transmission protocol. Upon receiving the data, the edge computing node can immediately perform local processing, such as data analysis, decision support, or temporary storage. A remote management unit provides system administrators with comprehensive control over the edge computing nodes, including configuration updates, security policy enforcement, and performance monitoring.

[0087] The effect of the above technical solution is: by deploying computing nodes at the edge of the network and integrating large artificial intelligence models, data processing can be localized, which can significantly reduce network latency and improve response speed. The system uses encrypted communication, differential privacy technology, and trusted data transmission protocols to effectively improve the security of data transmission, reduce the risk of data leakage and tampering, and protect the privacy of smart terminal users. At the same time, the introduction of a remote management unit can simplify system maintenance and management, and enhance the system's reliability and flexibility. In addition, the system design can optimize bandwidth utilization, support complex computing tasks, and adapt to network conditions and privacy regulations in different regions, providing strong technical support for the development of smart terminals.

[0088] In general, the edge computing-based smart terminal secure communication method, system and device proposed in the present invention can not only improve the efficiency and security of smart terminal communication, but also reduce operating costs, meet the smart terminal's needs for high-speed and high-reliability communication, and demonstrate broad market application potential and significant socio-economic value.

[0089] In one embodiment of the present invention, an edge computing node communicates with a smart terminal device through a secure communication module, including:

[0090] S101. Performing initial information data configuration for the communication connection between the smart terminal device and the edge computing node, wherein the initial information data configuration includes but is not limited to IP address configuration, port number configuration, security policy configuration, encryption policy and protocol configuration, and authentication policy and key configuration;

[0091] S102: Start the secure communication module configured within the smart terminal device and the edge computing node, and perform authentication and authorization operations between the secure communication module configured within the smart terminal device and the edge computing node through a Zero Trust Architecture authentication method, thereby completing authentication and authorization between the secure communication module configured within the smart terminal device and the edge computing node;

[0092] S103: After the secure communication module is started, control the secure communication module to create an encrypted communication channel and an encrypted communication connection based on TLS and / or SSL between the smart terminal device and the edge computing node.

[0093] The working principle of the above technical solution is as follows: before establishing a communication connection, the initial information and data configuration between the intelligent terminal device and the edge computing node is first performed. This configuration includes but is not limited to IP addresses, port numbers, security policies, encryption policies and protocols, authentication policies and keys, etc. This configuration information provides the necessary network and security foundation for subsequent communication connections.

[0094] Activate the secure communication modules within smart devices and edge computing nodes. These modules handle encryption, decryption, authentication, and authorization during communications. Adopting a Zero Trust Architecture (Zero Trust Architecture) authentication approach, the secure communication modules within smart devices and edge computing nodes undergo rigorous authentication and authorization. The core principle of Zero Trust Architecture is "never trust, always verify," requiring authentication and authorization regardless of the device or user's location within the network to ensure secure communications.

[0095] After the secure communication module is activated and authentication and authorization are completed, it controls these modules to establish an encrypted communication channel based on TLS (Transport Layer Security) and / or SSL (Secure Sockets Layer) between the smart terminal device and the edge computing node. TLS and SSL protocols provide encrypted data transmission, ensuring the confidentiality and integrity of communication data during transmission.

[0096] The above technical solution achieves the following benefits: Through a zero-trust authentication approach, only authenticated and authorized devices can participate in communications, effectively preventing unauthorized access and data leakage. Using TLS and / or SSL encryption protocols, data is encrypted for transmission, preventing easy decryption even if intercepted during transmission, thus ensuring data confidentiality and integrity. Communication between edge computing nodes and smart end devices occurs directly over an encrypted channel, reducing network transmission latency and bandwidth consumption, thereby improving communication efficiency. This technical solution supports a variety of encryption strategies and protocol configurations, allowing for flexible selection and adjustment based on actual needs to meet the secure communication requirements of diverse scenarios. As the number of smart end devices and edge computing nodes increases, this solution can be easily expanded and upgraded to accommodate more complex network environments. Centralized management of initial information data configuration and secure communication modules simplifies operations and maintenance processes and reduces costs. When an edge computing node experiences an operational anomaly, early warning alerts are sent to operations and maintenance personnel, facilitating rapid problem location and resolution.

[0097] In one embodiment of the present invention, after establishing a communication connection between the edge computing node and the smart terminal device, encrypting and transmitting data between the edge computing node and the smart terminal device through an encrypted channel includes:

[0098] S201. Before data transmission between the edge computing node and the smart terminal device, control the smart terminal device to process and encrypt sensitive data, and obtain an encrypted data packet corresponding to the data to be transmitted;

[0099] S202. The smart terminal device transmits the encrypted data packet corresponding to the data to be transmitted to the edge computing node through the encrypted channel created by the secure communication module;

[0100] S203. After receiving the encrypted data packet corresponding to the data to be transmitted, the edge computing node decrypts the data packet to obtain data information corresponding to the data to be transmitted;

[0101] S204: Perform data integrity verification on the data information corresponding to the data to be transmitted to obtain a data integrity verification result;

[0102] S205: When the data integrity verification result indicates that the data information corresponding to the data to be transmitted is incomplete, a data incompleteness warning is issued.

[0103] The above technical solution works as follows: Before data transmission, the smart terminal device first processes and encrypts the sensitive data to be transmitted. This step ensures the confidentiality of the data during transmission and prevents data leakage. The encryption process may involve the use of symmetric encryption algorithms (such as AES) or asymmetric encryption algorithms (such as RSA), depending on security requirements and resource constraints. After encryption is completed, the smart terminal device generates an encrypted data packet, ready for transmission over an encrypted channel.

[0104] The smart terminal device transmits the encrypted data packet to the edge computing node through an encrypted channel created by a previously established secure communication module based on security protocols such as TLS / SSL. This encrypted channel protects data from eavesdropping or tampering during transmission. After receiving the encrypted data packet, the edge computing node decrypts the data using the corresponding decryption key. The decryption process mirrors the encryption process on the smart terminal device, ensuring accurate data restoration. After decryption is complete, the edge computing node obtains the data information corresponding to the original data to be transmitted.

[0105] To ensure that the data has not been tampered with during transmission, the edge computing node performs integrity verification on the decrypted data. This typically involves calculating a hash value of the data using a hash function (such as SHA-256) and comparing it with the hash value of the original data. If the hash values match, the data is intact; if they do not, it indicates that the data may have been tampered with during transmission.

[0106] When the data integrity verification results indicate that the data is incomplete (i.e., the hash values are inconsistent), the edge computing node will trigger a data incompleteness warning mechanism. This warning mechanism may include sending an alert to operations personnel, recording logs, suspending data transmission, and other measures so that timely measures can be taken to address potential security risks.

[0107] The above technical solution achieves the following: data encryption and transmission through encrypted channels ensure the confidentiality and integrity of data during transmission, effectively preventing data leakage and tampering. Although the encryption and decryption processes increase computing overhead, localizing the processing between edge computing nodes and smart terminal devices reduces data transmission latency and bandwidth consumption, improving overall transmission efficiency. The data integrity verification mechanism ensures that received data has not been tampered with, enhancing data credibility and availability. The data incompleteness warning mechanism can promptly detect and respond to potential security risks, providing timely security protection and emergency response measures for operation and maintenance personnel. Through the implementation of the above technical solution, the stability and reliability of the communication connection between edge computing nodes and smart terminal devices have been improved, providing strong support for the stable operation of the entire system.

[0108] In one embodiment of the present invention, during data encryption transmission between the edge computing node and the smart terminal device, the operating status of the edge computing node is monitored in real time, and when the operating status of the edge computing node is abnormal, a node abnormality warning prompt is sent to the operation and maintenance personnel terminal, including:

[0109] S301, control the remote management unit to monitor and collect in real time the operating status parameters of the edge computing node during the communication process under each operating unit time, wherein the operating status parameters include the number of thread locks, the thread abnormal exit coefficient, the memory utilization rate, and the network signal strength fluctuation range; and the operating unit time has a value range of 1s-10s;

[0110] S302: Obtain a feature matrix using the operating state parameters of the edge computing node during the communication process under each operating unit time, wherein the structure of the feature matrix is as follows:

[0111]

[0112] Where F represents the feature matrix; L(t1), L(t2), ..., L(t n ) represent the number of thread deadlocks from the first running unit time to the nth running unit time; E(t1), E(t2), ..., E(t n ) represent the thread abnormal exit coefficients corresponding to the first running unit time to the nth running unit time; M(t1), M(t2), ..., M(t n ) represent the memory utilization corresponding to the first running unit time to the nth running unit time; S(t1), S(t2), ..., S(t n ) represent the fluctuation amplitude of the network signal strength from the first operating unit time to the nth operating unit time;

[0113] S303: Using the characteristic matrix, obtain the norm corresponding to the characteristic matrix, wherein the norm of the characteristic matrix is obtained by the following formula:

[0114]

[0115] Among them, ||F|| f represents the norm corresponding to the feature matrix; n represents the total number of running unit time; F ij represents the parameter data value corresponding to the i-th row and j-th column in the feature matrix F;

[0116] S304. Obtain the row vector norm corresponding to each row vector of the characteristic matrix F; wherein the row vector norm is obtained by the following formula:

[0117]

[0118] Among them, ||F i || represents the row vector norm corresponding to the row vector of the i-th row in the feature matrix F; L(t i )、E(t i )、M(t i ) and S(t i ) represent the parameter values of the thread deadlock count, thread abnormal exit coefficient, memory utilization and network signal strength fluctuation amplitude contained in the row vector of the i-th row respectively;

[0119] S305. Obtain a comprehensive operation evaluation parameter of the edge computing node using the norm corresponding to the characteristic matrix and the row vector modulus corresponding to each row vector; wherein the comprehensive operation evaluation parameter is obtained by the following formula:

[0120]

[0121] Among them, Q represents the comprehensive operation evaluation parameter; ||F|| f Represents the norm corresponding to the feature matrix; ||F i || represents the row vector modulus corresponding to the row vector of the i-th row in the feature matrix F; n represents the total number of running unit time; σ(S) represents the standard deviation value corresponding to the fluctuation amplitude of the network signal strength; S p represents the average value of the network signal strength fluctuation amplitude; K represents the network signal fluctuation coefficient, and the network signal fluctuation coefficient is obtained by the following formula:

[0122]

[0123] Among them, K represents the network signal fluctuation coefficient; S z Indicates the median value of the network signal strength fluctuation range; S pIndicates the average value of the fluctuation amplitude of network signal strength;

[0124] S306. Compare the comprehensive operation evaluation parameter with a preset evaluation parameter threshold. When the comprehensive operation evaluation parameter is lower than the preset evaluation parameter threshold, it is determined that there is an abnormality in the operation of the edge computing node, and a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

[0125] The working principle of this technical solution is that, through a remote management unit, the system monitors and collects key operating status parameters of edge computing nodes during communication in real time within each operating unit (1-10 seconds), including the number of thread locks, the coefficient of abnormal thread exits, memory utilization, and the fluctuation range of network signal strength. These parameters can fully reflect the operational health of edge computing nodes.

[0126] Using the collected operating status parameters, the system constructs a feature matrix F. This matrix arranges the parameter values at each operating unit time in chronological order, providing a data basis for subsequent anomaly detection.

[0127] The norm of the feature matrix is calculated using a formula to measure the "size" or "strength" of the entire matrix. The row vector modulus corresponding to each row vector in the feature matrix is then calculated to assess the overall deviation of the node's operating state within each unit of operating time.

[0128] Combining the norm of the feature matrix, the norm of the row vector, and the network signal fluctuation coefficient (taking into account the impact of network signals on the operating status), a specific formula is used to calculate the comprehensive operation evaluation parameter Q of the edge computing node. This parameter comprehensively reflects the operating status of the node in multiple dimensions.

[0129] The calculated comprehensive operation evaluation parameter Q is compared with the preset evaluation parameter threshold. If Q is lower than the threshold, it is determined that there is an abnormality in the edge computing node operation, and a node abnormality warning prompt is immediately sent to the operation and maintenance personnel terminal so that timely measures can be taken to deal with it.

[0130] The above technical solution achieves the following: By monitoring the operating status parameters of edge computing nodes in real time, the system can promptly detect potential operational anomalies and send early warning alerts to operations and maintenance personnel, enabling rapid response and resolution. By comprehensively considering multiple operational status parameters, such as the number of thread lockouts, thread abnormal exit coefficient, memory utilization, and network signal strength fluctuations, a feature matrix is constructed and comprehensively evaluated, improving the accuracy and comprehensiveness of anomaly detection. By setting preset evaluation parameter thresholds and parameters such as operating unit time, the system can be adjusted and optimized based on actual operating conditions to suit different application scenarios and requirements. By promptly detecting and resolving operational anomalies in edge computing nodes, this technical solution helps improve the stability and reliability of the entire system and reduce the risks of business interruption and data loss caused by node failures. Through automated monitoring and early warning mechanisms, the workload of manual inspections and troubleshooting is reduced, lowering operation and maintenance costs. It also improves operation and maintenance efficiency and accuracy.

[0131] At the same time, by combining the Frobenius norm of the characteristic matrix, the eigenvector modulus at each time point, the standard deviation and median value of the signal fluctuation, the comprehensive operation evaluation parameter value can perform a multi-dimensional comprehensive evaluation of the operation quality of the edge computing node: Specifically, by using the Frobenius norm, the formula can quantify the overall "energy" or intensity of all operating status parameters, reflecting the overall operating status of the node during the monitoring period. This enables the formula to capture the average performance level of the node throughout the entire time period, highlighting its stability and reliability. By summing the inverse of the eigenvector modulus at each time point, the formula performs additional processing on drastic changes in the operating status (such as extreme situations at certain time points). This processing method increases the formula's sensitivity to outliers and can quickly identify and reflect the impact of abnormal events on the overall quality of the node.

[0132] At the same time, by combining the standard deviation of signal fluctuations with the coefficient of fluctuation, the formula provides a more complex way to analyze signal stability. The standard deviation reflects the severity of signal fluctuations, while the coefficient of fluctuation quantifies the central tendency of signal fluctuations (the difference between the median and the average). This dual analysis can comprehensively evaluate the impact of signal stability and instability on communication quality. The above formula can respond sensitively to drastic changes in the amplitude of signal fluctuations and non-centrality (discreteness). This enhanced sensitivity enables the formula to more accurately reflect the communication quality of edge computing nodes under different network conditions, especially in high-interference or unstable network environments, which can help identify potential problems in advance.

[0133] The combined use of multiple components in the formula enables dynamic monitoring and real-time response to the operating status of edge computing nodes. When a node experiences an anomaly or experiences significant signal fluctuations, the formula's calculation result rapidly degrades, prompting system or maintenance personnel to take timely action. This real-time monitoring and response mechanism helps improve system stability and reliability, reducing service interruptions or data loss caused by node failures or performance issues.

[0134] Furthermore, the parameter settings in the formula are highly adaptable, allowing them to adjust to varying network environments and node status. This design allows the formula to be applied in a variety of complex scenarios, including the Industrial Internet of Things, intelligent transportation systems, and cloud-edge collaborative computing, providing greater adaptability. Furthermore, by observing changes in the Q value, operations and maintenance personnel can quickly understand the operating status of edge computing nodes and make timely maintenance decisions. A low Q value indicates a node anomaly, prompting further inspection and maintenance; a high Q value indicates normal node operation, minimizing unnecessary intervention. The design of the above formula supports intelligent management and optimization of edge computing nodes. By automatically calculating the Q value and monitoring its changing trends, the system can self-adjust and optimize resource allocation, improving overall performance. This intelligent management not only reduces the complexity of manual operations but also improves the overall operational efficiency of the system.

[0135] Because the formula integrates multiple operating status parameters and their interrelationships, it provides a comprehensive node performance analysis tool. By analyzing Q-value changes and their driving factors, developers and operations personnel can identify specific parameters or components that require optimization and implement targeted system improvements. The formula is also designed to support preventative maintenance and performance prediction. By continuously monitoring and analyzing Q-values, the system can predict potential failures or performance issues and take proactive measures to repair or optimize them, thereby improving overall system reliability and stability.

[0136] The formula for comprehensive operational evaluation parameters has significant technical benefits, including comprehensive, multi-dimensional assessment of edge computing node operational quality, enhanced signal fluctuation analysis capabilities, improved system stability and reliability, enhanced operational efficiency and intelligent management capabilities, and provided a basis for system optimization and improvement. These benefits make the formula not only theoretically innovative but also broadly applicable and adaptable in practical applications, enabling effective application in a variety of complex and dynamic computing environments.

[0137] The embodiment of the present invention proposes a smart terminal secure communication system based on edge computing, such as Figure 2 As shown, the smart terminal secure communication system based on edge computing includes:

[0138] The communication connection module is used for the edge computing node to communicate with the intelligent terminal device through the secure communication module;

[0139] A data encryption transmission module is used to encrypt and transmit data between the edge computing node and the smart terminal device through an encrypted channel after a communication connection is established between the edge computing node and the smart terminal device;

[0140] The abnormality determination and warning module is used to monitor the operating status of the edge computing node in real time during the data encryption transmission between the edge computing node and the smart terminal device, and send a node abnormality warning prompt to the operation and maintenance personnel terminal when there is an abnormality in the operating status of the edge computing node.

[0141] The system corresponding to the edge computing-based secure communication method for smart terminals includes: edge computing nodes, secure communication modules, trusted data transmission protocols, and remote management units. Edge computing nodes are the core of the system and are deployed at the edge of the network, as close as possible to smart terminal devices. They are responsible for performing real-time data processing and storage tasks, reducing reliance on central servers and thus reducing network latency. Edge computing nodes have the computing power to run various applications and services. They also have data caching capabilities, temporarily storing data from terminal devices until it can be securely transmitted to cloud servers or processed locally. At the same time, integrating large artificial intelligence models into edge computing nodes enables them to quickly handle complex tasks such as image recognition, voice processing, and real-time data analysis. This enhances the intelligent processing capabilities of edge nodes.

[0142] The secure communication module is integrated into edge computing nodes and smart terminal devices and is responsible for establishing an encrypted communication channel. The secure communication module adopts a zero-trust architecture to ensure that each communication node is strictly authenticated and authorized, whether in edge computing nodes or between smart terminal devices, thereby further enhancing the security of the system. Data encryption technology (such as TLS, etc.) is used in the communication process and differential privacy technology is introduced to protect user privacy by adding noise to the data while still allowing useful analysis of the data. This can enhance the system's privacy protection capabilities when processing sensitive data, ensure that data is protected during transmission between smart terminal devices and edge computing nodes, prevent man-in-the-middle attacks and data tampering, and avoid user privacy leaks.

[0143] The Trusted Data Transmission Protocol complements the secure communication module to ensure the integrity and credibility of data transmission. It verifies the source and integrity of data through mechanisms such as digital signatures and message authentication codes, ensuring that data is not tampered with during transmission.

[0144] The remote management unit provides system administrators with an interface for remotely managing edge computing nodes. Through this unit, administrators can monitor the status of edge nodes, configure security policies, update software and firmware, and perform troubleshooting and system maintenance when necessary.

[0145] Edge computing nodes and smart terminal devices are connected through encrypted channels of secure communication modules to achieve real-time data collection and processing.

[0146] Edge computing nodes are connected to a remote management unit over a network, typically through a secure VPN tunnel or SSH connection, allowing administrators to remotely access and configure them.

[0147] The secure communication module is responsible for establishing an encrypted connection, while the trusted data transmission protocol implements data integrity verification and authentication on the connection. The two work together to provide end-to-end secure communication protection.

[0148] In this system, smart end devices first establish a secure connection with edge computing nodes via a secure communication module and then send data using a trusted data transmission protocol. Upon receiving the data, the edge computing node can immediately perform local processing, such as data analysis, decision support, or temporary storage. A remote management unit provides system administrators with comprehensive control over the edge computing nodes, including configuration updates, security policy enforcement, and performance monitoring.

[0149] The effect of the above technical solution is: by deploying computing nodes at the edge of the network and integrating large artificial intelligence models, data processing can be localized, which can significantly reduce network latency and improve response speed. The system uses encrypted communication, differential privacy technology, and trusted data transmission protocols to effectively improve the security of data transmission, reduce the risk of data leakage and tampering, and protect the privacy of smart terminal users. At the same time, the introduction of a remote management unit can simplify system maintenance and management, and enhance the system's reliability and flexibility. In addition, the system design can optimize bandwidth utilization, support complex computing tasks, and adapt to network conditions and privacy regulations in different regions, providing strong technical support for the development of smart terminals.

[0150] In general, the edge computing-based smart terminal secure communication method, system and device proposed in the present invention can not only improve the efficiency and security of smart terminal communication, but also reduce operating costs, meet the smart terminal's needs for high-speed and high-reliability communication, and demonstrate broad market application potential and significant socio-economic value.

[0151] In one embodiment of the present invention, the communication connection module includes:

[0152] An initial information data configuration module, configured to perform initial information data configuration for the communication connection between the intelligent terminal device and the edge computing node, wherein the initial information data configuration includes but is not limited to IP address configuration, port number configuration, security policy configuration, encryption policy and protocol configuration, and authentication policy and key configuration;

[0153] A startup operation module is used to start the secure communication module configured internally between the smart terminal device and the edge computing node, and perform authentication and authorization operations between the secure communication module configured internally between the smart terminal device and the edge computing node through a Zero Trust Architecture authentication method, thereby completing authentication and authorization between the secure communication module configured internally between the smart terminal device and the edge computing node;

[0154] A communication connection establishment module is used to control the secure communication module to create an encrypted communication channel and encrypted communication connection based on TLS and / or SSL between the smart terminal device and the edge computing node after the secure communication module is started.

[0155] The working principle of the above technical solution is as follows: before establishing a communication connection, the initial information and data configuration between the intelligent terminal device and the edge computing node is first performed. This configuration includes but is not limited to IP addresses, port numbers, security policies, encryption policies and protocols, authentication policies and keys, etc. This configuration information provides the necessary network and security foundation for subsequent communication connections.

[0156] Activate the secure communication modules within smart devices and edge computing nodes. These modules handle encryption, decryption, authentication, and authorization during communications. Adopting a Zero Trust Architecture (Zero Trust Architecture) authentication approach, the secure communication modules within smart devices and edge computing nodes undergo rigorous authentication and authorization. The core principle of Zero Trust Architecture is "never trust, always verify," requiring authentication and authorization regardless of the device or user's location within the network to ensure secure communications.

[0157] After the secure communication module is activated and authentication and authorization are completed, it controls these modules to establish an encrypted communication channel based on TLS (Transport Layer Security) and / or SSL (Secure Sockets Layer) between the smart terminal device and the edge computing node. TLS and SSL protocols provide encrypted data transmission, ensuring the confidentiality and integrity of communication data during transmission.

[0158] The above technical solution achieves the following benefits: Through a zero-trust authentication approach, only authenticated and authorized devices can participate in communications, effectively preventing unauthorized access and data leakage. Using TLS and / or SSL encryption protocols, data is encrypted for transmission, preventing easy decryption even if intercepted during transmission, thus ensuring data confidentiality and integrity. Communication between edge computing nodes and smart end devices occurs directly over an encrypted channel, reducing network transmission latency and bandwidth consumption, thereby improving communication efficiency. This technical solution supports a variety of encryption strategies and protocol configurations, allowing for flexible selection and adjustment based on actual needs to meet the secure communication requirements of diverse scenarios. As the number of smart end devices and edge computing nodes increases, this solution can be easily expanded and upgraded to accommodate more complex network environments. Centralized management of initial information data configuration and secure communication modules simplifies operations and maintenance processes and reduces costs. When an edge computing node experiences an operational anomaly, early warning alerts are sent to operations and maintenance personnel, facilitating rapid problem location and resolution.

[0159] In one embodiment of the present invention, the data encryption transmission module includes:

[0160] A data packet acquisition module is used to control the smart terminal device to process and encrypt sensitive data before the edge computing node transmits data to the smart terminal device, and obtain an encrypted data packet corresponding to the data to be transmitted;

[0161] A data transmission execution module, configured for transmitting the encrypted data packet corresponding to the data to be transmitted to the edge computing node via the encrypted channel created by the secure communication module;

[0162] A decryption module is used for the edge computing node to decrypt the encrypted data packet corresponding to the data to be transmitted after receiving the data packet to obtain data information corresponding to the data to be transmitted;

[0163] A data integrity verification module is used to perform data integrity verification on the data information corresponding to the data to be transmitted and obtain a data integrity verification result;

[0164] The data incomplete warning module is used to issue a data incomplete warning when the data integrity verification result indicates that the data information corresponding to the data to be transmitted is in a data incomplete state.

[0165] The above technical solution works as follows: Before data transmission, the smart terminal device first processes and encrypts the sensitive data to be transmitted. This step ensures the confidentiality of the data during transmission and prevents data leakage. The encryption process may involve the use of symmetric encryption algorithms (such as AES) or asymmetric encryption algorithms (such as RSA), depending on security requirements and resource constraints. After encryption is completed, the smart terminal device generates an encrypted data packet, ready for transmission over an encrypted channel.

[0166] The smart terminal device transmits the encrypted data packet to the edge computing node through an encrypted channel created by a previously established secure communication module based on security protocols such as TLS / SSL. This encrypted channel protects data from eavesdropping or tampering during transmission. After receiving the encrypted data packet, the edge computing node decrypts the data using the corresponding decryption key. The decryption process mirrors the encryption process on the smart terminal device, ensuring accurate data restoration. After decryption is complete, the edge computing node obtains the data information corresponding to the original data to be transmitted.

[0167] To ensure that the data has not been tampered with during transmission, the edge computing node performs integrity verification on the decrypted data. This typically involves calculating a hash value of the data using a hash function (such as SHA-256) and comparing it with the hash value of the original data. If the hash values match, the data is intact; if they do not, it indicates that the data may have been tampered with during transmission.

[0168] When the data integrity verification results indicate that the data is incomplete (i.e., the hash values are inconsistent), the edge computing node will trigger a data incompleteness warning mechanism. This warning mechanism may include sending an alert to operations personnel, recording logs, suspending data transmission, and other measures so that timely measures can be taken to address potential security risks.

[0169] The above technical solution achieves the following: data encryption and transmission through encrypted channels ensure the confidentiality and integrity of data during transmission, effectively preventing data leakage and tampering. Although the encryption and decryption processes increase computing overhead, localizing the processing between edge computing nodes and smart terminal devices reduces data transmission latency and bandwidth consumption, improving overall transmission efficiency. The data integrity verification mechanism ensures that received data has not been tampered with, enhancing data credibility and availability. The data incompleteness warning mechanism can promptly detect and respond to potential security risks, providing timely security protection and emergency response measures for operation and maintenance personnel. Through the implementation of the above technical solution, the stability and reliability of the communication connection between edge computing nodes and smart terminal devices have been improved, providing strong support for the stable operation of the entire system.

[0170] In one embodiment of the present invention, the abnormality determination and early warning module includes:

[0171] An operating status parameter acquisition module is used to control the remote management unit to monitor and collect the operating status parameters of the edge computing node during the communication process in real time for each operating unit time. The operating status parameters include the number of thread locks, thread abnormal exit coefficient, memory utilization, and network signal strength fluctuation amplitude. The operating unit time has a value range of 1s-10s.

[0172] The feature matrix acquisition module is used to obtain a feature matrix using the operating state parameters of the edge computing node during the communication process under each operating unit time, wherein the structure of the feature matrix is as follows:

[0173]

[0174] Where F represents the feature matrix; L(t1), L(t2), ..., L(t n ) represent the number of thread deadlocks from the first running unit time to the nth running unit time; E(t1), E(t2), ..., E(t n ) represent the thread abnormal exit coefficients corresponding to the first running unit time to the nth running unit time; M(t1), M(t2), ..., M(t n ) represent the memory utilization corresponding to the first running unit time to the nth running unit time; S(t1), S(t2), ..., S(t n ) represent the fluctuation amplitude of the network signal strength from the first operating unit time to the nth operating unit time;

[0175] A norm acquisition module is used to use the characteristic matrix to obtain the norm corresponding to the characteristic matrix, wherein the norm of the characteristic matrix is obtained by the following formula:

[0176]

[0177] Among them, ||F|| f represents the norm corresponding to the feature matrix; n represents the total number of running unit time; F ij represents the parameter data value corresponding to the i-th row and j-th column in the feature matrix F;

[0178] A row vector modulus acquisition module is used to obtain the row vector modulus corresponding to each row vector of the feature matrix F; wherein the row vector modulus is obtained by the following formula:

[0179]

[0180] Among them, ||F i|| represents the row vector norm corresponding to the row vector of the i-th row in the feature matrix F; L(t i )、E(t i )、M(t i ) and S(t i ) represent the parameter values of the thread deadlock count, thread abnormal exit coefficient, memory utilization and network signal strength fluctuation amplitude contained in the row vector of the i-th row respectively;

[0181] A comprehensive operation evaluation parameter acquisition module is used to obtain the comprehensive operation evaluation parameters of the edge computing node using the norm corresponding to the feature matrix and the row vector modulus corresponding to each row vector; wherein the comprehensive operation evaluation parameters are obtained by the following formula:

[0182]

[0183] Among them, Q represents the comprehensive operation evaluation parameter; ||F|| f Represents the norm corresponding to the feature matrix; ||F i || represents the row vector modulus corresponding to the row vector of the i-th row in the feature matrix F; n represents the total number of running unit time; σ(S) represents the standard deviation value corresponding to the fluctuation amplitude of the network signal strength; S p represents the average value of the network signal strength fluctuation amplitude; K represents the network signal fluctuation coefficient, and the network signal fluctuation coefficient is obtained by the following formula:

[0184]

[0185] Among them, K represents the network signal fluctuation coefficient; S z Indicates the median value of the network signal strength fluctuation range; S p Indicates the average value of the fluctuation amplitude of network signal strength;

[0186] The abnormal warning execution module is used to compare the comprehensive operation evaluation parameter with the preset evaluation parameter threshold. When the comprehensive operation evaluation parameter is lower than the preset evaluation parameter threshold, it is determined that there is an abnormality in the operation of the edge computing node, and a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

[0187] The working principle of this technical solution is that, through a remote management unit, the system monitors and collects key operating status parameters of edge computing nodes during communication in real time within each operating unit (1-10 seconds), including the number of thread locks, the coefficient of abnormal thread exits, memory utilization, and the fluctuation range of network signal strength. These parameters can fully reflect the operational health of edge computing nodes.

[0188] Using the collected operating status parameters, the system constructs a feature matrix F. This matrix arranges the parameter values at each operating unit time in chronological order, providing a data basis for subsequent anomaly detection.

[0189] The norm of the feature matrix is calculated using a formula to measure the "size" or "strength" of the entire matrix. The row vector modulus corresponding to each row vector in the feature matrix is then calculated to assess the overall deviation of the node's operating state within each unit of operating time.

[0190] Combining the norm of the feature matrix, the norm of the row vector, and the network signal fluctuation coefficient (taking into account the impact of network signals on the operating status), a specific formula is used to calculate the comprehensive operation evaluation parameter Q of the edge computing node. This parameter comprehensively reflects the operating status of the node in multiple dimensions.

[0191] The calculated comprehensive operation evaluation parameter Q is compared with the preset evaluation parameter threshold. If Q is lower than the threshold, it is determined that there is an abnormality in the edge computing node operation, and a node abnormality warning prompt is immediately sent to the operation and maintenance personnel terminal so that timely measures can be taken to deal with it.

[0192] The above technical solution achieves the following: By monitoring the operating status parameters of edge computing nodes in real time, the system can promptly detect potential operational anomalies and send early warning alerts to operations and maintenance personnel, enabling rapid response and resolution. By comprehensively considering multiple operational status parameters, such as the number of thread lockouts, thread abnormal exit coefficient, memory utilization, and network signal strength fluctuations, a feature matrix is constructed and comprehensively evaluated, improving the accuracy and comprehensiveness of anomaly detection. By setting preset evaluation parameter thresholds and parameters such as operating unit time, the system can be adjusted and optimized based on actual operating conditions to suit different application scenarios and requirements. By promptly detecting and resolving operational anomalies in edge computing nodes, this technical solution helps improve the stability and reliability of the entire system and reduce the risks of business interruption and data loss caused by node failures. Through automated monitoring and early warning mechanisms, the workload of manual inspections and troubleshooting is reduced, lowering operation and maintenance costs. It also improves operation and maintenance efficiency and accuracy.

[0193] At the same time, by combining the Frobenius norm of the characteristic matrix, the eigenvector modulus at each time point, the standard deviation and median value of the signal fluctuation, the comprehensive operation evaluation parameter value can perform a multi-dimensional comprehensive evaluation of the operation quality of the edge computing node: Specifically, by using the Frobenius norm, the formula can quantify the overall "energy" or intensity of all operating status parameters, reflecting the overall operating status of the node during the monitoring period. This enables the formula to capture the average performance level of the node throughout the entire time period, highlighting its stability and reliability. By summing the inverse of the eigenvector modulus at each time point, the formula performs additional processing on drastic changes in the operating status (such as extreme situations at certain time points). This processing method increases the formula's sensitivity to outliers and can quickly identify and reflect the impact of abnormal events on the overall quality of the node.

[0194] At the same time, by combining the standard deviation of signal fluctuations with the coefficient of fluctuation, the formula provides a more complex way to analyze signal stability. The standard deviation reflects the severity of signal fluctuations, while the coefficient of fluctuation quantifies the central tendency of signal fluctuations (the difference between the median and the average). This dual analysis can comprehensively evaluate the impact of signal stability and instability on communication quality. The above formula can respond sensitively to drastic changes in the amplitude of signal fluctuations and non-centrality (discreteness). This enhanced sensitivity enables the formula to more accurately reflect the communication quality of edge computing nodes under different network conditions, especially in high-interference or unstable network environments, which can help identify potential problems in advance.

[0195] The combined use of multiple components in the formula enables dynamic monitoring and real-time response to the operating status of edge computing nodes. When a node experiences an anomaly or experiences significant signal fluctuations, the formula's calculation result rapidly degrades, prompting system or maintenance personnel to take timely action. This real-time monitoring and response mechanism helps improve system stability and reliability, reducing service interruptions or data loss caused by node failures or performance issues.

[0196] Furthermore, the parameter settings in the formula are highly adaptable, allowing them to adjust to varying network environments and node status. This design allows the formula to be applied in a variety of complex scenarios, including the Industrial Internet of Things, intelligent transportation systems, and cloud-edge collaborative computing, providing greater adaptability. Furthermore, by observing changes in the Q value, operations and maintenance personnel can quickly understand the operating status of edge computing nodes and make timely maintenance decisions. A low Q value indicates a node anomaly, prompting further inspection and maintenance; a high Q value indicates normal node operation, minimizing unnecessary intervention. The design of the above formula supports intelligent management and optimization of edge computing nodes. By automatically calculating the Q value and monitoring its changing trends, the system can self-adjust and optimize resource allocation, improving overall performance. This intelligent management not only reduces the complexity of manual operations but also improves the overall operational efficiency of the system.

[0197] Because the formula integrates multiple operating status parameters and their interrelationships, it provides a comprehensive node performance analysis tool. By analyzing Q-value changes and their driving factors, developers and operations personnel can identify specific parameters or components that require optimization and implement targeted system improvements. The formula is also designed to support preventative maintenance and performance prediction. By continuously monitoring and analyzing Q-values, the system can predict potential failures or performance issues and take proactive measures to repair or optimize them, thereby improving overall system reliability and stability.

[0198] The formula for comprehensive operational evaluation parameters has significant technical benefits, including comprehensive, multi-dimensional assessment of edge computing node operational quality, enhanced signal fluctuation analysis capabilities, improved system stability and reliability, enhanced operational efficiency and intelligent management capabilities, and provided a basis for system optimization and improvement. These benefits make the formula not only theoretically innovative but also broadly applicable and adaptable in practical applications, enabling effective application in a variety of complex and dynamic computing environments.

[0199] An embodiment of the present invention proposes a smart terminal security communication device based on edge computing, which includes an edge computing node, a security communication module and a smart terminal device; wherein the edge computing node is communicated with the smart terminal device through the security communication module; and the security communication module is respectively arranged in the edge computing node and the smart terminal device.

[0200] Among them, the edge computing-based smart terminal security communication device also includes a remote management unit, which is connected to the edge computing node through a network, wherein the remote management unit and the edge computing node are connected through a homogeneous VPN tunnel or SSH.

[0201] The system corresponding to the edge computing-based secure communication method for smart terminals includes: edge computing nodes, secure communication modules, trusted data transmission protocols, and remote management units. Edge computing nodes are the core of the system and are deployed at the edge of the network, as close as possible to smart terminal devices. They are responsible for performing real-time data processing and storage tasks, reducing reliance on central servers and thus reducing network latency. Edge computing nodes have the computing power to run various applications and services. They also have data caching capabilities, temporarily storing data from terminal devices until it can be securely transmitted to cloud servers or processed locally. At the same time, integrating large artificial intelligence models into edge computing nodes enables them to quickly handle complex tasks such as image recognition, voice processing, and real-time data analysis. This enhances the intelligent processing capabilities of edge nodes.

[0202] The secure communication module is integrated into edge computing nodes and smart terminal devices and is responsible for establishing an encrypted communication channel. The secure communication module adopts a zero-trust architecture to ensure that each communication node is strictly authenticated and authorized, whether in edge computing nodes or between smart terminal devices, thereby further enhancing the security of the system. Data encryption technology (such as TLS, etc.) is used in the communication process and differential privacy technology is introduced to protect user privacy by adding noise to the data while still allowing useful analysis of the data. This can enhance the system's privacy protection capabilities when processing sensitive data, ensure that data is protected during transmission between smart terminal devices and edge computing nodes, prevent man-in-the-middle attacks and data tampering, and avoid user privacy leaks.

[0203] The Trusted Data Transmission Protocol complements the secure communication module to ensure the integrity and credibility of data transmission. It verifies the source and integrity of data through mechanisms such as digital signatures and message authentication codes, ensuring that data is not tampered with during transmission.

[0204] The remote management unit provides system administrators with an interface for remotely managing edge computing nodes. Through this unit, administrators can monitor the status of edge nodes, configure security policies, update software and firmware, and perform troubleshooting and system maintenance when necessary.

[0205] Edge computing nodes and smart terminal devices are connected through encrypted channels of secure communication modules to achieve real-time data collection and processing.

[0206] Edge computing nodes are connected to a remote management unit over a network, typically through a secure VPN tunnel or SSH connection, allowing administrators to remotely access and configure them.

[0207] The secure communication module is responsible for establishing an encrypted connection, while the trusted data transmission protocol implements data integrity verification and authentication on the connection. The two work together to provide end-to-end secure communication protection.

[0208] In this system, smart end devices first establish a secure connection with edge computing nodes via a secure communication module and then send data using a trusted data transmission protocol. Upon receiving the data, the edge computing node can immediately perform local processing, such as data analysis, decision support, or temporary storage. A remote management unit provides system administrators with comprehensive control over the edge computing nodes, including configuration updates, security policy enforcement, and performance monitoring.

[0209] The effect of the above technical solution is: by deploying computing nodes at the edge of the network and integrating large artificial intelligence models, data processing can be localized, which can significantly reduce network latency and improve response speed. The system uses encrypted communication, differential privacy technology, and trusted data transmission protocols to effectively improve the security of data transmission, reduce the risk of data leakage and tampering, and protect the privacy of smart terminal users. At the same time, the introduction of a remote management unit can simplify system maintenance and management, and enhance the system's reliability and flexibility. In addition, the system design can optimize bandwidth utilization, support complex computing tasks, and adapt to network conditions and privacy regulations in different regions, providing strong technical support for the development of smart terminals.

[0210] In general, the edge computing-based smart terminal secure communication method, system and device proposed in the present invention can not only improve the efficiency and security of smart terminal communication, but also reduce operating costs, meet the smart terminal's needs for high-speed and high-reliability communication, and demonstrate broad market application potential and significant socio-economic value.

[0211] The technical features of the above embodiments may be combined in any manner. To simplify the description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification. Although the present invention has been shown and described with reference to specific preferred embodiments, it should not be interpreted as limiting the invention itself. Various changes in form and details may be made without departing from the spirit and scope of the invention as defined in the appended claims.

Claims

1. A secure communication method for intelligent terminals based on edge computing, characterized in that: The steps include: The edge computing node communicates with the smart terminal device through a secure communication module; After establishing a communication connection between the edge computing node and the smart terminal device, encrypting and transmitting data between the edge computing node and the smart terminal device through an encrypted channel; During the data encryption transmission process between the edge computing node and the smart terminal device, the operating status of the edge computing node is monitored in real time, and when there is an abnormality in the operating status of the edge computing node, a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

2. A method for secure communication of intelligent terminals based on edge computing according to claim 1, characterized in that: The edge computing node communicates with the smart terminal device through a secure communication module, specifically including: Performing initial information data configuration for the communication connection between the smart terminal device and the edge computing node; Starting the secure communication module configured within the smart terminal device and the edge computing node, and performing authentication and authorization operations between the secure communication module configured within the smart terminal device and the edge computing node through the authentication method of the zero-trust architecture, thereby completing the authentication and authorization between the secure communication module configured within the smart terminal device and the edge computing node; After the secure communication module is started, the secure communication module is controlled to create an encrypted communication channel and an encrypted communication connection based on TLS and / or SSL between the smart terminal device and the edge computing node.

3. The method for secure communication of an intelligent terminal based on edge computing according to claim 1, characterized in that: After establishing a communication connection between the edge computing node and the smart terminal device, encrypting and transmitting data between the edge computing node and the smart terminal device through an encrypted channel specifically includes: Before the edge computing node transmits data to the smart terminal device, controlling the smart terminal device to process and encrypt the sensitive data, and obtaining an encrypted data packet corresponding to the data to be transmitted; The smart terminal device transmits the encrypted data packet corresponding to the data to be transmitted to the edge computing node through the encrypted channel created by the secure communication module; After receiving the encrypted data packet corresponding to the data to be transmitted, the edge computing node decrypts the data packet to obtain data information corresponding to the data to be transmitted; Performing data integrity verification on the data information corresponding to the data to be transmitted to obtain a data integrity verification result; When the data integrity verification result indicates that the data information corresponding to the data to be transmitted is incomplete, a data incompleteness warning is issued.

4. The method for secure communication of an intelligent terminal based on edge computing according to claim 1, characterized in that: During the encrypted data transmission between the edge computing node and the smart terminal device, the operating status of the edge computing node is monitored in real time, and when the operating status of the edge computing node is abnormal, a node abnormality warning prompt is sent to the operation and maintenance personnel terminal, specifically including: Control the remote management unit to monitor and collect the operating status parameters of the edge computing node during the communication process in real time under each operating unit time, wherein the operating status parameters include the number of thread locks, thread abnormal exit coefficient, memory utilization, and network signal strength fluctuation amplitude; and the operating unit time has a value range of 1s-10s; The characteristic matrix is obtained by using the operating state parameters of the edge computing node in the communication process under each operating unit time, wherein the structure of the characteristic matrix is as follows: Where F represents the feature matrix; L(t1), L(t2), ..., L(t n ) represent the number of thread deadlocks from the first running unit time to the nth running unit time; E(t1), E(t2), ..., E(t n ) represent the thread abnormal exit coefficients corresponding to the first running unit time to the nth running unit time; M(t1), M(t2), ..., M(t n ) represent the memory utilization corresponding to the first running unit time to the nth running unit time; S(t1), S(t2), ..., S(t n ) represent the fluctuation amplitude of the network signal strength from the first operating unit time to the nth operating unit time; The characteristic matrix is used to obtain the norm corresponding to the characteristic matrix, wherein the norm of the characteristic matrix is obtained by the following formula: Among them, ||F|| f represents the norm corresponding to the feature matrix; n represents the total number of running unit time; F ij represents the parameter data value corresponding to the i-th row and j-th column in the feature matrix F; Obtain the row vector norm corresponding to each row vector for the feature matrix F; wherein the row vector norm is obtained by the following formula: Among them, ||F i || represents the row vector norm corresponding to the row vector of the i-th row in the feature matrix F; L(t i )、E(t i )、M(t i ) and S(t i ) represent the parameter values of the thread deadlock count, thread abnormal exit coefficient, memory utilization and network signal strength fluctuation amplitude contained in the row vector of the i-th row respectively; The comprehensive operation evaluation parameter of the edge computing node is obtained by using the norm corresponding to the characteristic matrix and the row vector modulus corresponding to each row vector; wherein the comprehensive operation evaluation parameter is obtained by the following formula: Among them, Q represents the comprehensive operation evaluation parameter; ||F|| f Represents the norm corresponding to the feature matrix; ||F i || represents the row vector modulus corresponding to the row vector of the i-th row in the feature matrix F; n represents the total number of running unit time; σ(S) represents the standard deviation value corresponding to the fluctuation amplitude of the network signal strength; S p represents the average value of the network signal strength fluctuation amplitude; K represents the network signal fluctuation coefficient, and the network signal fluctuation coefficient is obtained by the following formula: Among them, K represents the network signal fluctuation coefficient; S z Indicates the median value of the network signal strength fluctuation range; S p Indicates the average value of the fluctuation amplitude of network signal strength; The comprehensive operation evaluation parameter is compared with the preset evaluation parameter threshold. When the comprehensive operation evaluation parameter is lower than the preset evaluation parameter threshold, it is determined that there is an abnormality in the operation of the edge computing node, and a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

5. A smart terminal secure communication system based on edge computing, characterized in that: include: The communication connection module is used for the edge computing node to communicate with the intelligent terminal device through the secure communication module; A data encryption transmission module is used to encrypt and transmit data between the edge computing node and the smart terminal device through an encrypted channel after a communication connection is established between the edge computing node and the smart terminal device; The abnormality determination and warning module is used to monitor the operating status of the edge computing node in real time during the data encryption transmission between the edge computing node and the smart terminal device, and send a node abnormality warning prompt to the operation and maintenance personnel terminal when there is an abnormality in the operating status of the edge computing node.

6. A method for secure communication of intelligent terminals based on edge computing according to claim 5, characterized in that: The communication connection module includes: An initial information data configuration module, configured to perform initial information data configuration on the communication connection between the smart terminal device and the edge computing node; A startup operation module is used to start the secure communication module configured internally between the smart terminal device and the edge computing node, and perform authentication and authorization operations between the secure communication module configured internally between the smart terminal device and the edge computing node through the authentication method of the zero-trust architecture, thereby completing the authentication and authorization between the secure communication module configured internally between the smart terminal device and the edge computing node; A communication connection establishment module is used to control the secure communication module to create an encrypted communication channel and encrypted communication connection based on TLS and / or SSL between the smart terminal device and the edge computing node after the secure communication module is started.

7. The method for secure communication of an intelligent terminal based on edge computing according to claim 5, characterized in that: The data encryption transmission module includes: A data packet acquisition module is used to control the smart terminal device to process and encrypt sensitive data before the edge computing node transmits data to the smart terminal device, and obtain an encrypted data packet corresponding to the data to be transmitted; A data transmission execution module, configured for transmitting the encrypted data packet corresponding to the data to be transmitted to the edge computing node via the encrypted channel created by the secure communication module; A decryption module is used for the edge computing node to decrypt the encrypted data packet corresponding to the data to be transmitted after receiving the data packet to obtain data information corresponding to the data to be transmitted; A data integrity verification module is used to perform data integrity verification on the data information corresponding to the data to be transmitted and obtain a data integrity verification result; The data incomplete warning module is used to issue a data incomplete warning when the data integrity verification result indicates that the data information corresponding to the data to be transmitted is in a data incomplete state.

8. The method for secure communication of an intelligent terminal based on edge computing according to claim 5, characterized in that: The abnormality determination and early warning module includes: An operating status parameter acquisition module is used to control the remote management unit to monitor and collect the operating status parameters of the edge computing node during the communication process in real time for each operating unit time. The operating status parameters include the number of thread locks, thread abnormal exit coefficient, memory utilization, and network signal strength fluctuation amplitude. The operating unit time has a value range of 1s-10s. The feature matrix acquisition module is used to obtain a feature matrix using the operating state parameters of the edge computing node during the communication process under each operating unit time, wherein the structure of the feature matrix is as follows: Where F represents the feature matrix; L(t1), L(t2), ..., L(t n ) represent the number of thread deadlocks from the first running unit time to the nth running unit time; E(t1), E(t2), ..., E(t n ) represent the thread abnormal exit coefficients corresponding to the first running unit time to the nth running unit time; M(t1), M(t2), ..., M(t n ) represent the memory utilization corresponding to the first running unit time to the nth running unit time; S(t1), S(t2), ..., S(t n ) represent the fluctuation amplitude of the network signal strength from the first operating unit time to the nth operating unit time; A norm acquisition module is used to use the characteristic matrix to obtain the norm corresponding to the characteristic matrix, wherein the norm of the characteristic matrix is obtained by the following formula: Among them, ||F|| f represents the norm corresponding to the feature matrix; n represents the total number of running unit time; F ij represents the parameter data value corresponding to the i-th row and j-th column in the feature matrix F; A row vector modulus acquisition module is used to obtain the row vector modulus corresponding to each row vector of the feature matrix F; wherein the row vector modulus is obtained by the following formula: Among them, ||F i || represents the row vector norm corresponding to the row vector of the i-th row in the feature matrix F; L(t i )、E(t i )、M(t i ) and S(t i ) represent the parameter values of the thread deadlock count, thread abnormal exit coefficient, memory utilization and network signal strength fluctuation amplitude contained in the row vector of the i-th row respectively; A comprehensive operation evaluation parameter acquisition module is used to obtain the comprehensive operation evaluation parameters of the edge computing node using the norm corresponding to the feature matrix and the row vector modulus corresponding to each row vector; wherein the comprehensive operation evaluation parameters are obtained by the following formula: Among them, Q represents the comprehensive operation evaluation parameter; ||F|| f Represents the norm corresponding to the feature matrix; ||F i || represents the row vector modulus corresponding to the row vector of the i-th row in the feature matrix F; n represents the total number of running unit time; σ(S) represents the standard deviation value corresponding to the fluctuation amplitude of the network signal strength; S p represents the average value of the network signal strength fluctuation amplitude; K represents the network signal fluctuation coefficient, and the network signal fluctuation coefficient is obtained by the following formula: Among them, K represents the network signal fluctuation coefficient; S z Indicates the median value of the network signal strength fluctuation range; S p Indicates the average value of the fluctuation amplitude of network signal strength; The abnormal warning execution module is used to compare the comprehensive operation evaluation parameter with the preset evaluation parameter threshold. When the comprehensive operation evaluation parameter is lower than the preset evaluation parameter threshold, it is determined that there is an abnormality in the operation of the edge computing node, and a node abnormality warning prompt is sent to the operation and maintenance personnel terminal.

9. A smart terminal security communication device based on edge computing, characterized in that: The edge computing-based smart terminal security communication device includes an edge computing node, a security communication module and a smart terminal device; wherein, the edge computing node is communicatively connected with the smart terminal device through the security communication module; and the security communication module is respectively arranged in the edge computing node and the smart terminal device.

10. The smart terminal secure communication device based on edge computing according to claim 9, characterized in that: The edge computing-based smart terminal security communication device also includes a remote management unit, which is connected to the edge computing node through a network, wherein the remote management unit and the edge computing node are connected through a homogeneous VPN tunnel or SSH.

Citation Information

Patent Citations

  • Data trusted transmission protection method based on edge computing and communication system

    CN116248410A

  • Monitoring system for edge computing device

    CN118363819A

  • Elevator intelligent management system based on edge computing and computing network integration

    CN119059385A

  • Edge computing scheduling method and system for heterogeneous multi-source sensor

    CN119960950A

  • Edge computing intelligent terminal based on Internet of Things technology

    CN119996416A

Cited By

  • Electronic communication control system based on Internet of Things

    CN121077761A