Cloud internet-of-things security monitoring method and system with fault self-diagnosis function

Through layered edge architecture and cloud distributed storage, combined with IoT gateways, edge computing devices and cloud servers, real-time fault diagnosis and abnormal state perception of monitoring systems are achieved, solving the shortcomings of cloud IoT security monitoring systems in the existing technology, and improving monitoring efficiency and accuracy.

CN120498974AActive Publication Date: 2025-08-15HENAN ZHONGAN ELECTRONIC DETECTION TECH CO LTD

Patent Information

Application Number
CN202510780432.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-08-15
Estimated Expiration
2045-06-12

AI Technical Summary

Technical Problem

The existing cloud IoT security monitoring system has shortcomings in fault diagnosis and abnormal state perception, fails to achieve comprehensive security monitoring, and does not fully utilize cloud computing resources for large-scale data processing and real-time analysis.

Method used

The hierarchical edge architecture is adopted to preprocess and real-time computing the environment data through IoT gateways and edge computing devices, and combined with the distributed storage and abnormal state perception model of cloud servers, real-time security reporting and fault diagnosis of monitoring areas are achieved.

Benefits of technology

It improves the efficiency and accuracy of IoT security monitoring in cloud, realizes efficient processing and real-time response to massive data, can promptly detect and diagnose system failures, and provides refined fault reports.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498974A_ABST
    Figure CN120498974A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent monitoring, and discloses a cloud internet-of-things security monitoring method and system with a fault self-diagnosis function. The method comprises the following steps: an Internet of Things gateway pre-processes environmental data and then generates first processing data, an edge computing device performs real-time computing processing on the first processing data, generates second processing data, performs fusion analysis on all the second processing data, and outputs a first analysis result; the Internet of Things gateway transmits the first processing data, the second processing data and the first analysis result to a cloud server; the cloud server stores the received data, the abnormal state sensing model outputs a second analysis result, the second analysis result is displayed in a map level, and a real-time safety report is generated; the operation state of the monitoring system is monitored in real time, and a real-time fault report is output; and summarizing the real-time safety report and the real-time fault report and then transmitting the summarized report to a terminal. According to the invention, the efficiency and accuracy of cloud Internet of Things security monitoring are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of intelligent monitoring technology, and in particular to a cloud-based Internet of Things security monitoring method and system with fault self-diagnosis function. Background Art

[0002] With the rapid development of the Internet of Things (IoT) and cloud computing, traditional security monitoring systems are gradually transforming towards intelligent and digital technologies. However, existing systems lack the ability to diagnose faults and detect abnormal conditions, making it difficult to achieve comprehensive monitoring and rapid response in complex environments.

[0003] A similar prior art approach is the Chinese patent application with publication number CN105677538A, which discloses an adaptive monitoring method for cloud computing systems based on fault prediction. Principal component analysis is used to calculate the eigenvectors of monitoring data to characterize the system's operating status. The deviation between the eigenvectors of current and historical monitoring data is then used to assess the degree of system anomalies. When the monitored system's anomaly level is high, the monitoring cycle is shortened to closely track its operating status, thereby improving the accuracy and timeliness of error prediction and detection. Conversely, when the monitored system's anomaly level is low, the monitoring cycle is extended to reduce monitoring overhead. There is also a Chinese patent application with publication number CN119720011A, which discloses a big data-based intelligent security monitoring method for IoT devices, involving the field of IoT device security technology, including deploying edge nodes near IoT devices, receiving monitoring data from IoT devices, encrypting and preprocessing the monitoring data, and the edge nodes transmitting the encrypted monitoring data to the big data platform through an encrypted channel; the big data platform uses a decryption key matching the edge node to decrypt the data, and the decrypted data is classified according to different IoT device types and data sources, and stored in a distributed database; the big data platform performs multimodal data fusion on data sources from different devices; the big data platform uses an AI model to analyze the data in the distributed database, identify the normal behavior patterns of the device, and predict the potential abnormal behavior of the device; when the AI model predicts abnormal behavior, it divides the severity of the abnormality and gives a corresponding response strategy.

[0004] The shortcomings of existing technologies are mainly reflected in the fact that they only predict and monitor faults of cloud computing systems, fail to achieve comprehensive security monitoring, and rely solely on edge nodes and big data platforms for data processing and analysis, but do not fully consider the utilization of cloud computing resources. In actual situations, it is necessary to perform status monitoring and fault analysis on a large number of IoT devices, and take advantage of the cloud for large-scale data processing and real-time analysis. Summary of the Invention

[0005] The present application provides a cloud-based Internet of Things security monitoring method and system with fault self-diagnosis function, which is used to improve the efficiency and accuracy of cloud-based Internet of Things security monitoring.

[0006] In a first aspect, the present application provides a cloud-based IoT security monitoring method with a fault self-diagnosis function, the cloud-based IoT security monitoring method with a fault self-diagnosis function comprising: Multiple monitoring devices are set up to collect environmental data of the monitoring area, the Internet of Things gateway pre-processes the environmental data to generate first processed data, an edge computing device is deployed, the edge computing device performs real-time computing and processing on any of the first processed data to generate second processed data, and all the second processed data are integrated and analyzed based on the deployment location of the monitoring device to output a first analysis result; The IoT gateway transmits the first processed data, the second processed data, and the first analysis result to the cloud server; The cloud server stores and processes the received data in a distributed manner, establishes an abnormal state perception model, identifies and analyzes the received data, outputs a second analysis result, displays the second analysis result at a map level based on the deployment location, and generates a real-time safety report corresponding to the monitored area; Performing real-time monitoring of the operating status of the monitoring system, and when an abnormality in the monitoring system is detected, performing fault diagnosis and outputting a real-time fault report, wherein the monitoring system includes the monitoring device, the IoT gateway, and the edge computing device; The cloud server aggregates the real-time safety report and the real-time fault report and transmits the aggregated report to the terminal.

[0007] In combination with the first aspect, generating the second processed data includes: Obtaining a timestamp of the first processed data, sorting the first processed data of different monitoring types based on the timestamp to generate first sequence data, and using a sliding window to segment the first sequence data and convert the data into a plurality of first input vectors; Constructing a reservoir computing model, the reservoir computing model comprising an input layer, a reservoir, and an output layer, inputting the first input vector into the input layer, updating the state vector of each neuron in the reservoir based on the connection weight and activation function of the reservoir, and collecting the state vector and target output corresponding to the reservoir based on the time step corresponding to the sliding window; Using the state vector as an input feature and the target output as a label, generating a first data set, training the first data set using a supervised learning algorithm, calculating a weight matrix of the output layer, and deploying the trained reservoir computing model to the edge computing device based on the weight matrix; The trained reservoir calculation model outputs a first prediction result based on the first processed data, and the first prediction result is set as the second processed data.

[0008] In conjunction with the first aspect, outputting the first analysis result includes: Calculating a location distance between any two of the monitoring devices based on the deployment locations, and if the location distance is less than a first preset value, aggregating the second processed data corresponding to any two of the monitoring devices into a first set; Obtaining a correlation between all the second processed data in the first set, and determining whether the first set meets the monitoring phenomenon based on the correlation; if not, eliminating the second processed data with a correlation less than a second preset value, and setting the remaining first set as a first subset; This step is repeated until the second processed data corresponding to all the monitoring devices are analyzed to generate multiple first subsets, and all the first subsets are aggregated based on the location distance to generate the first analysis result.

[0009] In combination with the first aspect, the step of using the IoT gateway to transmit the first processed data, the second processed data, and the first analysis result to the cloud server includes: Setting the first processed data, the second processed data, and the first analysis result as data to be transmitted, and marking the generation time and location of the data to be transmitted; sorting the data to be transmitted based on the generation time and the generation location and storing them in a buffer, setting a transmission ratio, and transmitting the data to be transmitted to the cloud server according to the transmission protocol based on the transmission ratio; If the load of the cloud server is greater than a third preset value, the transmission ratio is reduced.

[0010] In combination with the first aspect, the cloud server stores and processes the received data in a distributed manner, including: The received data includes the first processed data, the second processed data, and the first analysis result, obtaining a data type of the received data, setting a target type based on the data type, and extracting target data from the received data based on the target type; A target threshold is set based on the target type, specific processing is performed on the target data based on the target threshold, and the processed target data is classified and stored based on the target type.

[0011] In combination with the first aspect, outputting the second analysis result includes: Obtain any group of data from the classified and stored received data, set a decision variable, an objective function, and a constraint function based on the target threshold, map the sub-data corresponding to each monitoring device in any of the group of data into a spin variable, and convert the objective function and the constraint function into an energy function of an abnormal state perception model; Dividing all the spin variables into a plurality of sub-arrays, obtaining a correlation between any two sub-data in the group data, and setting an initial value of the spin state based on the correlation; The abnormal state perception model calculates an energy change value of the subarray based on the energy function and the spin state, determines whether the spin state is flipped based on the energy change value, and if so, updates the spin state and converts the updated spin state into the decision variable, and determines whether the monitored area is abnormal based on an output result of the decision variable; This step is repeated until all the received data are judged, and all the groups of data with anomalies are summarized to generate the second analysis result.

[0012] In conjunction with the first aspect, generating a real-time safety report corresponding to the monitored area includes: Dividing the monitoring area into a plurality of grid areas, marking the deployment location on a map based on a geographic information system, generating a plurality of monitoring points, associating the first processed data with the monitoring points, and marking status information of the monitoring points based on preset tags; Obtaining the monitoring point corresponding to the second analysis result, setting it as an abnormal monitoring point, scaling the abnormal monitoring point based on the size of the grid area, and screening out the abnormal area; The status information and the abnormal area are updated in real time based on a timestamp, and description contents are extracted from the updated status information and the abnormal area respectively based on natural language processing to generate the real-time safety report.

[0013] In conjunction with the first aspect, the real-time monitoring of the operating status of the monitoring system includes: Acquiring the operating status and operating status data of the monitoring system, preprocessing the operating status data and inputting it into a deep learning model to extract feature quantities; Performing cluster analysis on the feature values using a clustering algorithm, dividing all the operation status data into a plurality of subcategories, assigning one-to-one correspondence between the subcategories and the operation statuses, and marking category labels for the subcategories; Setting the category labels determined in the cluster analysis as known labels, and establishing a labeling model based on the known labels, wherein the labeling model associates the feature quantity with the category label; Inputting the plurality of operation status data belonging to the same category label into a neural network model for learning and training to generate a plurality of abnormality determination models; In any of the category labels, a difference between the operating state data and the predicted data output by the abnormality determination model is calculated, and a parameter of the difference data is calculated, and the parameter is set as an abnormality detection benchmark based on the parameter; extracting abnormal data from the operating status data based on the size of the difference, marking the abnormal data as faults, and then inputting the fault classification model for training; collecting new operating status data in real time, classifying and labeling the new operating status based on the labeling model, and then inputting the new operating status into the corresponding abnormality determination model; outputting an abnormality degree based on the abnormality detection benchmark; if the abnormality degree is greater than a fourth preset value, determining that the monitoring system is abnormal, and inputting the new operating status data into the fault classification model to output a fault classification result; Based on the device category corresponding to the new operating status data, all the fault classification results are summarized to generate the real-time fault report.

[0014] In a second aspect, the present application provides a cloud-based IoT security monitoring system with a fault self-diagnosis function, the cloud-based IoT security monitoring system with a fault self-diagnosis function comprising: a collection module configured to configure multiple monitoring devices to collect environmental data of a monitored area, the IoT gateway to pre-process the environmental data to generate first processed data, deploy edge computing devices, use the edge computing devices to perform real-time computation on any of the first processed data to generate second processed data, perform fusion analysis on all of the second processed data based on the deployment locations of the monitoring devices, and output a first analysis result; A transmission module, configured for the IoT gateway to transmit the first processed data, the second processed data, and the first analysis result to the cloud server; a monitoring module configured to store and process the received data in a distributed manner on the cloud server, establish an abnormal state perception model, identify and analyze the received data, output a second analysis result, display the second analysis result at a map level based on the deployment location, and generate a real-time safety report corresponding to the monitoring area; a self-diagnosis module for real-time monitoring of the operating status of the monitoring system, and performing fault diagnosis and outputting a real-time fault report when an abnormality is detected in the monitoring system, wherein the monitoring system includes the monitoring device, the IoT gateway, and the edge computing device; The feedback module is used for the cloud server to summarize the real-time safety report and the real-time fault report and transmit them to the terminal.

[0015] The technical solution provided in this application firstly adopts a layered edge architecture, deploying multiple information processing systems sequentially from the sensor side to the cloud server. This system can process data from different sensor types, different communication methods, and different transmission paths, improving the accuracy and reliability of the data. Time and location information are associated with sensor data to achieve spatiotemporal correlation analysis of the data, more accurately identifying and locating security incidents. Next, edge computing devices are deployed to perform real-time computations on the data to generate second processed data. The cloud server performs distributed storage and processing on the data from the edge nodes. Through the collaboration of edge computing and cloud computing, efficient processing and real-time response to massive amounts of data are achieved. Edge computing relieves the computing pressure of the cloud server and optimizes system resource utilization. Finally, by real-time monitoring and analysis of the monitoring system's own operating status, the system can promptly detect and diagnose its own faults. The construction of anomaly perception models and fault classification models enables the system to perform refined processing of different types of faults and provide accurate real-time fault reports, thus achieving automated monitoring and fault diagnosis of the monitoring system's operating status, refined processing of different types of faults, and improving the accuracy of fault diagnosis. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0017] Figure 1 This is a schematic diagram of an embodiment of a cloud-based IoT security monitoring method with a fault self-diagnosis function in an embodiment of the present application; Figure 2 A schematic diagram of an embodiment of the process of generating a real-time security report in an embodiment of the present application; Figure 3 This is a schematic diagram of an embodiment of the fault self-diagnosis mechanism process in the embodiment of the present application; Figure 4 This is a schematic diagram of an embodiment of a cloud-based IoT security monitoring system with fault self-diagnosis function in an embodiment of the present application. DETAILED DESCRIPTION

[0018] The embodiments of the present application provide a cloud-based Internet of Things security monitoring method and system with fault self-diagnosis capabilities. The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of this application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "including" or "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or that are inherent to these processes, methods, products or devices.

[0019] For ease of understanding, the specific process of the embodiment of the present application is described below. Figure 1 In one embodiment of the present application, a cloud-based IoT security monitoring method with a fault self-diagnosis function includes: Step S101: Set up multiple monitoring devices to collect environmental data of the monitoring area, the Internet of Things gateway pre-processes the environmental data to generate first processed data, deploy edge computing devices, the edge computing devices perform real-time computing and processing on any first processed data to generate second processed data, and all second processed data are fused and analyzed based on the deployment location of the monitoring device to output the first analysis result.

[0020] It is understandable that the execution subject of this application can be a cloud-based IoT security monitoring device with fault self-diagnosis function, or a terminal or server, which is not limited here. The embodiment of this application is described by taking the server as the execution subject as an example.

[0021] Specifically, monitoring devices refer to various types of flame detectors with IoT communication capabilities, such as image-based flame detectors, fire alarm controllers, infrared flame detectors, and vehicle-mounted laser methane inspection meters. A monitoring area refers to the environmental area that requires monitoring. Environmental data refers to monitoring data collected by monitoring devices, such as ultraviolet image data and smoke gas concentration data. The IoT gateway is responsible for receiving environmental data from monitoring devices and performing preliminary processing, including data format conversion, data cleaning, and data compression. The IoT gateway is a hardware device or software system responsible for data exchange, processing, and management between IoT devices and cloud servers.

[0022] Edge computing devices refer to edge servers or gateway devices with computing capabilities, deployed alongside IoT gateways, and are used to perform real-time analysis, feature extraction, event prediction, and other computational processing on first-processed data. Deployment locations refer to the distribution coordinates of each monitoring device. A first analysis result is a correlation analysis of the monitored phenomena predicted within the monitored area by integrating multiple second-processed results. For example, if there is second-processed data corresponding to fire image data and gas concentration data, and the deployment locations are close, the monitored phenomenon is consistent with "fire." Therefore, the two sets of second-processed data are aggregated to generate a first analysis result, which serves as the data basis for later fire situation assessments.

[0023] Step S102: The IoT gateway transmits the first processed data, the second processed data, and the first analysis result to the cloud server.

[0024] Specifically, when transmitting data, the IoT gateway needs to regulate the data volume in real time to avoid excessive load on the cloud server.

[0025] Step S103: The cloud server stores and processes the received data in a distributed manner, establishes an abnormal state perception model, identifies and analyzes the received data, outputs a second analysis result, displays the second analysis result at a map level based on the deployment location, and generates a real-time safety report corresponding to the monitoring area.

[0026] Specifically, a distributed approach involves sequentially performing specific storage and processing on specific data, allowing for simultaneous processing of data from different monitoring devices. The abnormal state perception model is constructed using an annealing machine to address environmental anomaly perception. The annealing machine is based on a simulated annealing algorithm, a probability-based global optimization algorithm that simulates the physical annealing process. By controlling the "environmental monitoring" parameters, it gradually reduces system energy and ultimately finds a state where energy is minimized, reflecting the correlations and detection characteristics between monitoring devices. The second analysis result refers to data indicating abnormal conditions in the monitored area, such as a "fire status." Map-level display refers to the real-time display of the monitored area's status information, including alarm information, on a map, through integration with a geographic information system (GIS). Real-time safety reports refer to environmental safety reports for the currently monitored area.

[0027] Step S104: Monitor the operating status of the monitoring system in real time. When an abnormality is detected in the monitoring system, perform fault diagnosis and output a real-time fault report. The monitoring system includes monitoring equipment, an Internet of Things gateway, and an edge computing device.

[0028] Specifically, a monitoring system is a system where a cloud server monitors the operating status of monitoring devices, IoT gateways, and edge computing devices. Real-time fault reporting refers to reports that monitor and analyze the operating status of any device in the monitoring system.

[0029] Step S105: The cloud server aggregates the real-time safety report and the real-time fault report and transmits them to the terminal.

[0030] Specifically, the cloud server will summarize the collected real-time security reports and real-time fault reports based on preset time intervals and send them to the terminal. The terminal user will perform security maintenance and equipment maintenance of the environmental area and monitoring system. The user can remotely control the monitoring system through the terminal device, for example, adjust the parameters of the monitoring equipment, activate emergency plans, etc.

[0031] In a specific embodiment, generating the second processed data includes: (1) Obtaining timestamps of first processed data, sorting the first processed data of different monitoring types based on the timestamps to generate first sequence data, and using a sliding window to segment the first sequence data and convert it into a plurality of first input vectors.

[0032] (2) Construct a reservoir computing model, which includes an input layer, a reservoir, and an output layer. The first input vector is input to the input layer, and the state vector of each neuron in the reservoir is updated based on the connection weight and activation function of the reservoir. Based on the time step corresponding to the sliding window, the state vector and target output corresponding to the reservoir are collected.

[0033] (3) Using the state vector as the input feature and the target output as the label, a first data set is generated, the first data set is trained using a supervised learning algorithm, the weight matrix of the output layer is calculated, and the trained reservoir computing model is deployed to the edge computing device based on the weight matrix.

[0034] (4) The trained reservoir calculation model outputs a first prediction result based on the first processed data, and the first prediction result is set as the second processed data.

[0035] Specifically, the timestamp information can be generated by the monitoring device itself or marked by the IoT gateway based on the data arrival time. The monitoring type refers to the type of different environmental data. The sorting criteria include not only the timestamp but also the monitoring type. For example, first processed data of the same type but in different locations can also be sorted separately, such as gas concentration data in different areas. Using sliding window technology, the first sequence data is divided into multiple fixed-length time windows, and the data in each sliding window is converted into a first input vector. The vectorization method can be to arrange all data points in the time window in sequence into a vector.

[0036] The reservoir computing model, a neural network computing paradigm, offers unique advantages for processing time series data. It can handle time series data of various data types, such as image sets and datasets with temporal relationships. It receives a first input vector as input. The reservoir, composed of a large number of sparsely connected neurons, mimics the dynamic characteristics of biological neural networks. The connection weights and activation functions within the reservoir remain unchanged during training; only the weight matrix of the output layer requires training. The reservoir's role is to map the input vector into a high-dimensional space and extract the time series features from the input data. The connection weights within the reservoir are typically randomly initialized, and the activation function can be a commonly used nonlinear function.

[0037] During reservoir computing model training, the target output is the predicted value of the first sequence of data at the next time step. The reservoir computing model is trained on the first dataset using a supervised learning algorithm (e.g., linear regression, support vector machine, etc.). The training objective is to minimize the error between the output layer's predicted value and the target output. The output layer's weight matrix is the key parameter connecting the reservoir and the output layer, mapping features extracted from the reservoir to the desired output space. Therefore, the reservoir computing model, with the calculated weight matrix, is deployed on edge computing devices.

[0038] The first processed data is updated in real time. After the edge computing device receives the first processed data, the reservoir computing model performs calculations and processing on it, and outputs a first prediction result, which is used to predict the changing trend of the first processed data in the future, that is, the second processed data.

[0039] In a specific embodiment, outputting the first analysis result includes: (1) Calculating the location distance between any two monitoring devices based on the deployment location. If the location distance is less than a first preset value, aggregating the second processed data corresponding to the any two monitoring devices into a first set.

[0040] (2) Obtain the correlation between all the second processed data in the first set, and determine whether the first set meets the monitoring phenomenon based on the correlation. If not, eliminate the second processed data with a correlation less than a second preset value, and set the remaining first set as the first subset.

[0041] (3) Repeat this step until the second processed data corresponding to all monitoring devices are analyzed to generate multiple first subsets, and aggregate all the first subsets based on the location distance to generate a first analysis result.

[0042] Specifically, the location distance refers to the spatial distance between two monitoring devices. When the location distance is less than a first preset value, it indicates that the monitoring ranges of the two monitoring devices share a common area, and the second processed data corresponding to the two monitoring devices can be aggregated into a first set. This step is repeated to aggregate all second processed data to generate multiple first sets, where a first set can contain multiple sets of second processed data. If any second processed data is not aggregated, it is treated as a separate first set.

[0043] Correlation refers to the linear correlation between any two pieces of second-processed data, measured using the Pearson correlation coefficient. Based on this correlation analysis, the data within the first set is judged to determine whether there are any unusual patterns or specific security event characteristics. For example, if the correlation between temperature, smoke gas concentration, and flame sensor data is high, there may be a fire risk, which meets the monitoring requirements. However, if the temperature and smoke gas concentration are low, but the flame sensor data shows infrared flame detection, then the second-processed data corresponding to the flame sensor has an incorrect prediction and does not meet the monitoring requirements. Second-processed data with a correlation less than a second preset value in the first set is removed to generate a first subset.

[0044] By repeatedly executing this step, correlation analysis can be performed on the prediction rationality of all second processed data to generate a first analysis result associated with the location distance.

[0045] In a specific embodiment, the first processed data, the second processed data, and the first analysis result are transmitted to the cloud server using an IoT gateway, including: (1) The first processed data, the second processed data, and the first analysis result are all set as data to be transmitted, and the generation time and generation location of the data to be transmitted are marked.

[0046] (2) The data to be transmitted is sorted based on the generation time and generation location and stored in the buffer, and the transmission ratio is set. Based on the transmission ratio, the data to be transmitted is transmitted to the cloud server according to the transmission protocol.

[0047] (3) If the load of the cloud server is greater than the third preset value, the transmission ratio is reduced.

[0048] Specifically, each piece of data to be transmitted is marked with a precise timestamp and location information upon its generation. For example, the generation time of the first processed data is the timestamp generated by the IoT gateway based on the arrival time of the environmental data. The generation time of the second processed data is the timestamp generated after the edge computing device processes the first processed data. The generation time of the first analysis result is the timestamp of the edge computing device performing the fusion analysis. The generation location refers to the spatial coordinates of the device from which the data to be transmitted originates.

[0049] Data to be transmitted from different locations is sorted based on their generation time. A buffer is a multi-level buffer designed into the IoT gateway to handle sudden data surges. The transmission ratio defines the proportion of the data to be transmitted that is actually transmitted. For example, a transmission ratio of 80% means that 80% of the data in the buffer will be transmitted to the cloud server.

[0050] The cloud server monitors its load in real time, such as memory usage and network bandwidth utilization. A third preset value is set as a load threshold to determine whether the cloud server is under high load. When the cloud server load is detected to be greater than the third preset value, the transmission ratio is reduced. Reducing the transmission ratio can effectively alleviate pressure on the cloud server and prevent server overload.

[0051] In a specific embodiment, the cloud server stores and processes the received data in a distributed manner, including: (1) Receive data including first processed data, second processed data, and a first analysis result, obtain a data type of the received data, set a target type based on the data type, and extract target data from the received data based on the target type.

[0052] (2) Set a target threshold based on the target type, perform specific processing on the target data based on the target threshold, and classify and store the processed target data based on the target type.

[0053] Specifically, the cloud server parses the received data and extracts the data type information for each piece of data, such as the monitoring device data type (smoke gas concentration, infrared image, etc.) and the processing data type (predicted value, feature quantity, etc.). The target type refers to the data type that requires special attention and processing, such as data directly related to security incidents, such as fire alarms. The cloud server extracts data that matches the target type from the received data as the target data. For example, if the target type is set to "fire alarm," all data corresponding to the "fire alarm" type will be extracted.

[0054] For different target types, corresponding target thresholds are set to determine whether the data is abnormal or to trigger specific processing procedures. For example, a smoke gas concentration limit of 100 ppm can be set, exceeding which triggers a fire alarm. Specific processing involves classifying and prioritizing target data based on target type and target threshold. Based on the data classification and priority, the corresponding processing procedures are triggered, and the processed target data is stored and categorized by target type.

[0055] In a specific embodiment, outputting the second analysis result includes: (1) Obtain any set of data from the received data after classification and storage, set the decision variables, objective function and constraint function based on the target threshold, map the sub-data corresponding to each monitoring device in any set of data into spin variables, and convert the objective function and constraint function into the energy function of the abnormal state perception model.

[0056] (2) Divide all spin variables into multiple sub-arrays, obtain the correlation between any two sub-data in the group data, and set the initial value of the spin state based on the correlation.

[0057] (3) The abnormal state perception model calculates the energy change value of the subarray based on the energy function and the spin state, and determines whether the spin state is flipped based on the energy change value. If so, the spin state is updated and the updated spin state is converted into a decision variable. Based on the output result of the decision variable, it is determined whether the monitored area is abnormal.

[0058] (4) Repeat this step until all received data are judged, summarize all abnormal group data, and generate the second analysis result.

[0059] Specifically, group data refers to the data contained in the received data after classification and storage. The target threshold is converted into a decision variable to indicate whether the group data is abnormal. For example, for smoke gas concentration data, a decision variable can be set. The objective function is used to measure the overall degree of abnormality and can be set as a linear combination of decision variables. The constraint function is used to represent the logical relationship or physical constraint between group data. For example, if the temperature and smoke gas concentration exceed the threshold at the same time, a fire is more likely to occur. The sub-data corresponding to each monitoring device is mapped to a spin variable s, which can be +1 or -1, where sub-data refers to the data generated by any monitoring device, +1 indicates that the corresponding data is normal, and -1 indicates that the corresponding data is abnormal. Map the decision variable to the spin variable. For example, when the decision variable is greater than the target threshold, the spin variable is -1. Convert the objective function and the constraint conditions into penalty terms in the energy function, so that the smaller the objective function value, the lower the energy function value. For example, the energy function is expressed as: ,in, is the objective function, is the constraint function, is the energy function, c represents different constraints, is the penalty coefficient, and are all decision variables.

[0060] The number of spin variables is equal to the number of monitoring devices. These can be divided based on their spatial locations, for example, by grouping monitoring devices within the same area into subarrays. The initial values of the spin states are set based on the correlation between the data. For example, if two subarrays have a high correlation, their corresponding spin variables can be initialized to the same value.

[0061] The abnormal state perception model uses an annealing machine to calculate the energy change value of each submatrix based on the energy function and the current spin state. If the energy change value is less than 0, the spin state flip is accepted, which can reduce the total energy of the system. If the energy change value is greater than 0, the spin state flip is accepted according to the preset probability. According to the result of this process, the spin state is updated, and the energy change value calculation and spin state update are repeated until the system reaches a stable state or the preset number of iterations is reached. The updated spin state is converted into a decision variable, and the monitoring area is determined to be abnormal based on the output result of the decision variable. For example, if a decision variable , it means that the corresponding data is abnormal. A threshold can also be set. When the number of abnormal decision variables exceeds the threshold, it is considered that there is an abnormality in the monitoring area.

[0062] Repeat the above steps to judge all received data, generate a second analysis result, and identify the type of abnormal event.

[0063] In a specific embodiment, generating a real-time security report corresponding to a monitored area includes: (1) Divide the monitoring area into multiple grid areas, mark the deployment locations on the map based on the geographic information system, generate multiple monitoring points, associate the first processed data with the monitoring points, and mark the status information of the monitoring points based on preset tags.

[0064] (2) Obtain the monitoring point corresponding to the second analysis result, set it as the abnormal monitoring point, scale the abnormal monitoring point based on the size of the grid area, and filter out the abnormal area.

[0065] (3) The status information and abnormal area are updated in real time based on the timestamp, and the description content is extracted from the updated status information and abnormal area based on natural language processing to generate a real-time security report.

[0066] Specifically, Figure 2Flowchart for generating real-time safety reports. The size of the grid area can be set according to the monitoring accuracy and computing resources. After receiving the data from the sensor side, the cloud server extracts the location information of each monitoring device and uses GIS technology to mark the location information of the monitoring device on the digital map. Each grid area corresponds to a monitoring point, which is used to represent the safety status of the area and is associated with the location of the actual monitoring device. For multiple data associated with the same monitoring point, aggregation processing can be performed to set a set of preset states for each monitoring point to describe its safety status, such as preset labels such as "normal" and "fire". According to the first processed data and the preset rules or thresholds, the corresponding preset labels are assigned to each monitoring point.

[0067] The second analysis result is generated after a fusion analysis of the second processed data from multiple monitoring devices. It refers to data with abnormal results. Therefore, the second analysis result is associated with the corresponding monitoring points, and these monitoring points are set as abnormal monitoring points. If the grid area is large, the range of abnormal monitoring points can be appropriately expanded to more accurately reflect the scope of the abnormal area. Interpolation algorithms, such as Kriging interpolation, can be used to estimate the spatial distribution of abnormal areas. Based on the scaled abnormal monitoring points, abnormal areas are screened out.

[0068] Each piece of data includes a timestamp, identifying when the data was generated. The status of each monitoring point is updated in real time based on the latest data received. The location, scope, and status of abnormal areas are updated in real time based on the latest secondary analysis results. Using natural language processing technology, this status information is converted into readable text descriptions, providing a more detailed description of the abnormal areas and generating real-time safety reports.

[0069] In a specific embodiment, real-time monitoring of the operating status of the monitoring system includes: (1) Obtain the operating status and operating status data of the monitoring system, pre-process the operating status data and input it into the deep learning model to extract the feature quantity.

[0070] (2) Use clustering algorithms to perform cluster analysis on feature quantities, divide all operation status data into multiple subcategories, correspond subcategories to operation statuses one by one, and mark category labels for subcategories.

[0071] (3) The category labels determined in the cluster analysis are set as known labels, and a labeling model is established based on the known labels. The labeling model associates the feature quantity with the category label.

[0072] (4) Multiple operation status data belonging to the same category label are input into the neural network model for learning and training to generate multiple abnormality judgment models.

[0073] (5) In any category label, the difference between the operating state data and the predicted data output by the abnormality judgment model is calculated, and the parameters of the difference data are calculated. The parameters are set as the abnormality detection benchmark.

[0074] (6) Based on the size of the difference, abnormal data is extracted from the operating status data, and the abnormal data is marked as fault and input into the fault classification model for training.

[0075] (7) New operating status data is collected in real time, and the new operating status is classified and labeled based on the labeling model and then input into the corresponding abnormality determination model. The abnormality degree is output based on the abnormality detection benchmark. If the abnormality degree is greater than the fourth preset value, the monitoring system is judged to be abnormal, and the new operating status data is input into the fault classification model, and the fault classification result is output.

[0076] (8) Based on the equipment category corresponding to the new operating status data, all fault classification results are summarized and a real-time fault report is generated.

[0077] Specifically, Figure 3 This is a flowchart of the fault self-diagnosis mechanism. Operational status refers to the operating status of the monitoring system. Operational status data comes from various devices in the monitoring system, such as monitoring device operating status data (temperature, voltage, current, signal strength, etc.), IoT gateway operating status data (network connection status, data transmission rate, latency, etc.), and edge computing device operating status data (CPU utilization, memory utilization, storage space utilization, etc.). After preprocessing such as data cleaning and data standardization, the operational status data is input into a trained deep learning model (convolutional neural network). The deep learning model extracts high-dimensional features from the input data, such as image features, time series features, and statistical features.

[0078] The clustering algorithm can group similar operating status data into the same category. The category label corresponding to each cluster center determined in the cluster analysis is set as a known label. For example, different operating status categories can be labeled as "normal," "slightly abnormal," "severely abnormal," etc. Operating status data belonging to the same cluster category can be further divided into multiple subcategories.

[0079] Based on known category labels, a labeling model is built to classify new operational status data into corresponding categories. The labeling model can be constructed through semi-supervised learning, combining labeled and unlabeled data for training.

[0080] Multiple operating status data belonging to the same category label are input into the neural network model for learning and training. The training goal is to minimize the reconstruction error or the difference between the generated samples and the real samples, and generate an anomaly judgment model for each operating status category. These models can detect abnormal data in the corresponding category. Each anomaly judgment model reflects the characteristics of the normal operating status data of the corresponding category label.

[0081] The parameters of the difference data include but are not limited to the maximum value, average value, standard deviation and variance, etc. The calculated parameters are set as the abnormality detection benchmark to determine whether the operation status data is abnormal.

[0082] Based on the labeling model, the new operating status data is classified and labeled, assigned to corresponding categories, and then input into the corresponding anomaly determination model to calculate its abnormality level. The abnormality level can be calculated based on the difference or a parameter of the difference data, for example, the magnitude by which a parameter of the difference data exceeds an anomaly detection benchmark. If the abnormality level is greater than a fourth preset value, the monitoring system corresponding to the operating status data is determined to be abnormal. The fault classification model can categorize different abnormal situations into different fault types, such as monitoring equipment failure, network failure, hardware failure, software failure, etc.

[0083] Based on the equipment category corresponding to the new operating status data, all fault classification results are summarized to generate a real-time fault report. For example, all faulty equipment and their fault types are listed, and information such as the time, location, and severity of the fault is provided. Suggested maintenance measures or emergency response plans are also provided.

[0084] The above describes the cloud-based IoT security monitoring method with a fault self-diagnosis function in the embodiment of the present application. The following describes the cloud-based IoT security monitoring system with a fault self-diagnosis function in the embodiment of the present application. Figure 4 In one embodiment of the present application, a cloud-based IoT security monitoring system with a fault self-diagnosis function includes: The acquisition module 201 is used to set up multiple monitoring devices to collect environmental data of the monitoring area. The Internet of Things gateway pre-processes the environmental data to generate first processed data, deploys edge computing devices, uses the edge computing devices to perform real-time computing and processing on any first processed data to generate second processed data, and performs a fusion analysis on all second processed data based on the deployment location of the monitoring device to output a first analysis result.

[0085] The transmission module 202 is used for the Internet of Things gateway to transmit the first processed data, the second processed data and the first analysis result to the cloud server.

[0086] The monitoring module 203 is used for the cloud server to store and process the received data in a distributed manner, establish an abnormal state perception model, and the abnormal state perception model identifies and analyzes the received data, outputs a second analysis result, displays the second analysis result at the map level based on the deployment location, and generates a real-time safety report corresponding to the monitoring area.

[0087] The self-diagnosis module 204 is used to monitor the operating status of the monitoring system in real time. When an abnormality is detected in the monitoring system, fault diagnosis is performed and a real-time fault report is output. The monitoring system includes monitoring equipment, an Internet of Things gateway, and an edge computing device.

[0088] The feedback module 205 is used for the cloud server to summarize the real-time safety report and the real-time fault report and transmit them to the terminal.

[0089] Through the collaborative efforts of the aforementioned components, a layered edge architecture is first adopted, with multiple information processing systems deployed sequentially from the sensor side to the cloud server. This system can process data from different sensor types, different communication methods, and different transmission paths, improving data accuracy and reliability. Time and location information are associated with sensor data, enabling spatiotemporal correlation analysis of the data and more accurately identifying and locating security incidents. Next, edge computing devices are deployed to perform real-time computations on the data, generating secondary processed data. Cloud servers perform distributed storage and processing of data from edge nodes. The collaborative efforts of edge computing and cloud computing enable efficient processing and real-time response to massive amounts of data. Edge computing relieves the computing pressure of cloud servers and optimizes system resource utilization. Finally, by real-time monitoring and analysis of the monitoring system's own operating status, the system can promptly detect and diagnose its own faults. The construction of anomaly perception models and fault classification models enables the system to perform refined processing of different fault types and provide accurate real-time fault reports. This enables automated monitoring and fault diagnosis of the monitoring system's operating status, refined processing of different fault types, and improved fault diagnosis accuracy.

[0090] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems, systems and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0091] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.

[0092] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A cloud-based IoT security monitoring method with fault self-diagnosis function, characterized in that: The cloud-based IoT security monitoring method with fault self-diagnosis function includes: Multiple monitoring devices are set up to collect environmental data of the monitoring area, the Internet of Things gateway pre-processes the environmental data to generate first processed data, an edge computing device is deployed, the edge computing device performs real-time computing and processing on any of the first processed data to generate second processed data, and all the second processed data are integrated and analyzed based on the deployment location of the monitoring device to output a first analysis result; The IoT gateway transmits the first processed data, the second processed data, and the first analysis result to the cloud server; The cloud server stores and processes the received data in a distributed manner, establishes an abnormal state perception model, identifies and analyzes the received data, outputs a second analysis result, displays the second analysis result at a map level based on the deployment location, and generates a real-time safety report corresponding to the monitored area; Performing real-time monitoring of the operating status of the monitoring system, and when an abnormality in the monitoring system is detected, performing fault diagnosis and outputting a real-time fault report, wherein the monitoring system includes the monitoring device, the IoT gateway, and the edge computing device; The cloud server aggregates the real-time safety report and the real-time fault report and transmits the aggregated report to the terminal.

2. The cloud-based IoT security monitoring method with fault self-diagnosis function according to claim 1 is characterized in that: The generating of the second processed data comprises: Obtaining a timestamp of the first processed data, sorting the first processed data of different monitoring types based on the timestamp to generate first sequence data, and using a sliding window to segment the first sequence data and convert the data into a plurality of first input vectors; Constructing a reservoir computing model, the reservoir computing model comprising an input layer, a reservoir, and an output layer, inputting the first input vector into the input layer, updating the state vector of each neuron in the reservoir based on the connection weight and activation function of the reservoir, and collecting the state vector and target output corresponding to the reservoir based on the time step corresponding to the sliding window; Using the state vector as an input feature and the target output as a label, generating a first data set, training the first data set using a supervised learning algorithm, calculating a weight matrix of the output layer, and deploying the trained reservoir computing model to the edge computing device based on the weight matrix; The trained reservoir calculation model outputs a first prediction result based on the first processed data, and the first prediction result is set as the second processed data.

3. The cloud-based IoT security monitoring method with fault self-diagnosis function according to claim 1 is characterized in that: The outputting of the first analysis result includes: Calculating a location distance between any two of the monitoring devices based on the deployment locations, and if the location distance is less than a first preset value, aggregating the second processed data corresponding to any two of the monitoring devices into a first set; Obtaining a correlation between all the second processed data in the first set, and determining whether the first set meets the monitoring phenomenon based on the correlation; if not, eliminating the second processed data with a correlation less than a second preset value, and setting the remaining first set as a first subset; This step is repeated until the second processed data corresponding to all the monitoring devices are analyzed to generate multiple first subsets, and all the first subsets are aggregated based on the location distance to generate the first analysis result.

4. The cloud-based IoT security monitoring method with fault self-diagnosis function according to claim 1, characterized in that: The using the IoT gateway to transmit the first processed data, the second processed data, and the first analysis result to the cloud server includes: Setting the first processed data, the second processed data, and the first analysis result as data to be transmitted, and marking the generation time and location of the data to be transmitted; sorting the data to be transmitted based on the generation time and the generation location and storing them in a buffer, setting a transmission ratio, and transmitting the data to be transmitted to the cloud server according to the transmission protocol based on the transmission ratio; If the load of the cloud server is greater than a third preset value, the transmission ratio is reduced.

5. The cloud-based IoT security monitoring method with fault self-diagnosis function according to claim 1 is characterized in that: The cloud server stores and processes the received data in a distributed manner, including: The received data includes the first processed data, the second processed data, and the first analysis result, obtaining a data type of the received data, setting a target type based on the data type, and extracting target data from the received data based on the target type; A target threshold is set based on the target type, specific processing is performed on the target data based on the target threshold, and the processed target data is classified and stored based on the target type.

6. The cloud-based IoT security monitoring method with fault self-diagnosis function according to claim 5, characterized in that: The outputting of the second analysis result includes: Obtain any group of data from the classified and stored received data, set a decision variable, an objective function, and a constraint function based on the target threshold, map the sub-data corresponding to each monitoring device in any of the group of data into a spin variable, and convert the objective function and the constraint function into an energy function of an abnormal state perception model; Dividing all the spin variables into a plurality of sub-arrays, obtaining a correlation between any two sub-data in the group data, and setting an initial value of the spin state based on the correlation; The abnormal state perception model calculates an energy change value of the subarray based on the energy function and the spin state, determines whether the spin state is flipped based on the energy change value, and if so, updates the spin state and converts the updated spin state into the decision variable, and determines whether the monitored area is abnormal based on an output result of the decision variable; This step is repeated until all the received data are judged, and all the groups of data with anomalies are summarized to generate the second analysis result.

7. The cloud-based IoT security monitoring method with fault self-diagnosis function according to claim 1, characterized in that: Generating a real-time safety report corresponding to the monitored area includes: Dividing the monitoring area into a plurality of grid areas, marking the deployment location on a map based on a geographic information system, generating a plurality of monitoring points, associating the first processed data with the monitoring points, and marking status information of the monitoring points based on preset tags; Obtaining the monitoring point corresponding to the second analysis result, setting it as an abnormal monitoring point, scaling the abnormal monitoring point based on the size of the grid area, and screening out the abnormal area; The status information and the abnormal area are updated in real time based on a timestamp, and description contents are extracted from the updated status information and the abnormal area respectively based on natural language processing to generate the real-time safety report.

8. The cloud-based IoT security monitoring method with fault self-diagnosis function according to claim 1, characterized in that: The real-time monitoring of the operating status of the monitoring system includes: Acquiring the operating status and operating status data of the monitoring system, preprocessing the operating status data and inputting it into a deep learning model to extract feature quantities; Performing cluster analysis on the feature values using a clustering algorithm, dividing all the operation status data into a plurality of subcategories, assigning one-to-one correspondence between the subcategories and the operation statuses, and marking category labels for the subcategories; Setting the category labels determined in the cluster analysis as known labels, and establishing a labeling model based on the known labels, wherein the labeling model associates the feature quantity with the category label; Inputting the plurality of operation status data belonging to the same category label into a neural network model for learning and training to generate a plurality of abnormality determination models; In any of the category labels, a difference between the operating state data and the predicted data output by the abnormality determination model is calculated, and a parameter of the difference data is calculated, and the parameter is set as an abnormality detection benchmark based on the parameter; extracting abnormal data from the operating status data based on the size of the difference, marking the abnormal data as faults, and then inputting the fault classification model for training; collecting new operating status data in real time, classifying and labeling the new operating status based on the labeling model, and then inputting the new operating status into the corresponding abnormality determination model; outputting an abnormality degree based on the abnormality detection benchmark; if the abnormality degree is greater than a fourth preset value, determining that the monitoring system is abnormal, and inputting the new operating status data into the fault classification model to output a fault classification result; Based on the device category corresponding to the new operating status data, all the fault classification results are summarized to generate the real-time fault report.

9. A cloud-based IoT security monitoring system with fault self-diagnosis function, characterized in that: The cloud-based IoT security monitoring system with fault self-diagnosis function includes: a collection module configured to configure multiple monitoring devices to collect environmental data of a monitored area, the IoT gateway to pre-process the environmental data to generate first processed data, deploy edge computing devices, use the edge computing devices to perform real-time computation on any of the first processed data to generate second processed data, perform fusion analysis on all of the second processed data based on the deployment locations of the monitoring devices, and output a first analysis result; A transmission module, configured for the IoT gateway to transmit the first processed data, the second processed data, and the first analysis result to the cloud server; a monitoring module configured to store and process the received data in a distributed manner on the cloud server, establish an abnormal state perception model, identify and analyze the received data, output a second analysis result, display the second analysis result at a map level based on the deployment location, and generate a real-time safety report corresponding to the monitoring area; a self-diagnosis module for real-time monitoring of the operating status of the monitoring system, and performing fault diagnosis and outputting a real-time fault report when an abnormality is detected in the monitoring system, wherein the monitoring system includes the monitoring device, the IoT gateway, and the edge computing device; The feedback module is used for the cloud server to summarize the real-time safety report and the real-time fault report and transmit them to the terminal.

Citation Information

Patent Citations

  • Power distribution network box type equipment fault monitoring method and system and computer equipment

    CN115529331A

  • Fire-fighting disaster site internet-of-things sensing system

    CN118250652A

  • Relay protection device data processing method and system based on cloud side-end architecture

    CN118473082A

  • Internet of Things gateway data processing method based on edge computing

    CN119892528A

  • Gateway configurations in industrial internet of things

    US20200014730A1

Cited By

  • Dynamic environment monitoring data real-time processing method and system based on edge computing

    CN120973636A

  • An edge-computing-based real-time processing method and system for dynamic environment monitoring data

    CN120973636B