Priority-based engineering supervision data processing method
By introducing a data value self-declaration and dynamic bandwidth bidding allocation mechanism, the problem of high-value information not being able to be uploaded first in engineering supervision data transmission was solved, achieving fair resource allocation and link stability, and improving the efficiency and security of data transmission.
Patent Information
- Application Number
- CN202510924502.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2045-07-04
AI Technical Summary
In existing engineering supervision data transmission, high-value information cannot be uploaded first, transmission scheduling methods lack proactive value assessment, bandwidth resource allocation is unfair, transmission links are easily affected by sudden fluctuations, malicious terminals preempt bandwidth leading to system congestion, control-data conflicts occur frequently, and terminal rate limiting control is easily bypassed.
It adopts data value self-declaration, dynamic bandwidth bidding allocation, dual-dimensional bidding mechanism and credit downgrade penalty, combined with dynamic link control and circuit breaker compensation mechanism, optimizes resource allocation through value proof certificate and bandwidth auction algorithm, introduces emergency penetration mechanism and credit token compensation, and ensures that high-priority data is transmitted first.
It enables intelligent, precise, and robust scheduling of high-density engineering data, ensuring the priority uploading of high-value information, suppressing bandwidth grabbing by malicious terminals, and improving the stability and scheduling efficiency of transmission links.
Smart Images

Figure CN120583079B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of engineering data processing technology, and in particular to a priority-based method for processing engineering supervision data. Background Technology
[0002] In complex engineering projects such as large-scale infrastructure construction, rail transit, and urban renewal, engineering supervision systems need to collect monitoring images, safety alarms, quality reports, process logs, and other data from multiple sources in real time to assist construction parties and regulatory units in conducting on-site safety early warnings, construction compliance reviews, and closed-loop quality control. With the diversified development of supervision equipment (such as smart cameras, vibration sensors, drones, etc.), supervision data exhibits typical characteristics such as high-frequency generation, multi-source heterogeneity, and uneven value, posing a severe challenge to real-time uploading under limited bandwidth conditions.
[0003] In existing technologies, the transmission scheduling of supervision data mostly relies on fixed priority or first-come-first-served models, lacking a proactive value assessment mechanism based on data service attributes. This results in high-value information not being guaranteed priority uploading. For example, on-site structural deformation alarms and ordinary inspection logs have the same priority in the transmission queue, making them highly susceptible to delays or drops due to bandwidth contention, creating potential risks. Existing methods are mostly based on "static bandwidth pre-allocation" or simple queuing, which cannot cope with sudden fluctuations in the transmission link (such as equipment obstruction, severe weather, etc.) leading to a decrease in speed and a high transmission failure rate. Furthermore, the lack of behavioral governance mechanisms makes it easy for malicious terminals to preempt bandwidth. Some terminals frequently forge high-priority identifiers to preempt bandwidth, causing system congestion and scheduling imbalances, affecting the fairness and stability of overall supervision data transmission.
[0004] In addition, traditional credential control mechanisms often reuse the main channel, and the issuance of instructions is subject to the load of the data channel, which can easily cause control-data conflicts; the terminal's rate limiting control mostly relies on upper-layer software protocols, which are at risk of being bypassed or manipulated. Summary of the Invention
[0005] This invention provides a priority-based engineering supervision data processing method. This method is designed for engineering supervision scenarios and integrates data value self-declaration, priority bandwidth bidding allocation, dynamic link control and circuit breaker compensation mechanisms. It aims to solve the problems of high-priority data not being guaranteed, unfair resource allocation and lack of link recovery mechanisms in existing solutions, and to achieve intelligent, accurate and robust scheduling of high-density engineering data transmission.
[0006] The priority-based engineering supervision data processing method includes the following steps:
[0007] S1, Self-declaration of the value of supervision data: Receive data packets sent by multi-source supervision terminals and parse the value proof certificate embedded in the packet; the value proof certificate is generated by the terminal based on data service attribute indicators;
[0008] S2, Dynamic Bandwidth Competition Allocation: Based on the real-time bandwidth capacity and the value proof credentials of each data packet, an improved bandwidth auction algorithm is run to output bandwidth allocation credentials. The improved bandwidth auction algorithm addresses the resource mismatch problem in engineering supervision data by introducing a two-dimensional bidding mechanism and credit downgrade penalty.
[0009] S3, Certificate-driven transmission execution: The bandwidth allocation certificate is sent to the corresponding terminal, and the terminal performs the upload according to the bandwidth value and time window specified in the certificate.
[0010] Optionally, S1 includes receiving data packets from various supervision terminals through a pre-set multi-source access interface layer. The interface layer supports adaptation to different protocol standards, including UDP, CoAP, and MQTT protocols, stripping the transport layer packet header, and extracting and parsing the encrypted value proof credentials embedded in the data packets.
[0011] Optionally, the value proof certificate is validated through a digital signature verification mechanism. After successful verification, business attribute indicators are parsed out, including data type signature, timeliness coefficient, and associated business chain hash.
[0012] Optionally, the monitoring terminal performs the following during data collection:
[0013] a) Data type signature generation: Call the local rule engine to match the data content with the supervision classification tree, output the signature ciphertext, and generate an encrypted label to identify the type category of the data;
[0014] b) Calculation of timeliness coefficient: retrieve the latest upload time limit of the corresponding data type from the preset regulatory rule base, and calculate the coefficient value in combination with the data generation time;
[0015] c) Construction of related business chain hash: Retrieve the related business data identifiers stored locally, perform hash iteration operation on the identifier sequence, and generate a verifiable lightweight hash chain.
[0016] Optionally, S2 specifically includes:
[0017] S21, Construct a virtual bidding market: Divide the real-time bandwidth capacity into several tradable bandwidth units, each tradable bandwidth unit comes with a basic pricing, and assign virtual token value to the value proof certificate of each supervision terminal data packet;
[0018] S22, execute two-dimensional bidding:
[0019] Dimension 1: Value Priority Bidding;
[0020] Dimension Two: Emergency Penetration Bidding;
[0021] S23, Generate Anti-Monopoly Bandwidth Allocation Certificate: Generate a bandwidth allocation certificate for the supervision data packet that has successfully won the bandwidth bid, including the allocated bandwidth value, time window and token consumption. The time window is the shortest uploadable time period. If the penetration mechanism is triggered, it will be immediately set to a continuous window starting from the current time.
[0022] Optionally, the value of the virtual token is calculated based on a proof-of-value certificate as follows: ;in, Signature weights for data types, For timeliness coefficient, The verification degree of the associated business chain is assigned a value after being verified by the consistency of the server hash chain.
[0023] Optionally, the value priority bidding includes: supervisory data packets are bid in descending order of token value, with those having higher token values having priority to select transaction bandwidth units, until the units are exhausted or the data queue is empty;
[0024] The emergency penetration bidding includes: when the identified data type signature is a security alarm type and the timeliness coefficient is lower than the penetration trigger threshold, the penetration mechanism is triggered and bandwidth is directly allocated.
[0025] Optionally, S23 further includes:
[0026] Failure Compensation Mechanism: Credit token compensation is initiated for supervisory data packets that fail consecutively in bidding: the token value weight is increased for each failure in the next round;
[0027] Malicious Bidding Credit Downgrade: Implement credit downgrade for terminals that engage in malicious high-frequency bidding: reduce their data type signature weight and continue for multiple rounds.
[0028] Optionally, S3 specifically includes:
[0029] S31, Credential Encryption and Targeted Distribution: The server generates a bandwidth allocation credential with a digital watermark signature. The bandwidth allocation credential structure includes a unique identifier for the terminal device, the allocated bandwidth value, the transmission time window, the token consumption value, and a one-time link encryption key. It is then distributed to the designated monitoring terminal through a dedicated narrowband channel for supervision.
[0030] S32, Terminal credential verification and link establishment: The terminal verifies the validity of the digital watermark signature and transmission time window of the credential. If the current time is earlier than the start point of the transmission time window, the credential is cached in the secure storage area.
[0031] When the transmission start time is reached, a bandwidth value-constrained transmission channel is established using the link encryption key, and the channel forcibly limits the upload rate to no more than the allocated bandwidth value;
[0032] S33, Link Quality Monitoring and Circuit Breaker: Real-time monitoring of packet loss rate and latency fluctuations in the transmission channel. When the actual bandwidth value is detected to be significantly lower than the allocated bandwidth value for an extended period of time, a credential invalidation circuit breaker is triggered.
[0033] Optionally, the triggering of the credential expiration circuit breaker includes:
[0034] a) Immediately terminate the current transmission and release bandwidth resources;
[0035] b) Mark incomplete data packets as pending retransmission;
[0036] c) The terminal automatically generates a compensation request including the hash of the original voucher and submits it to the bandwidth auction system.
[0037] The beneficial effects of this invention are:
[0038] This invention constructs a value proof certificate structure based on data business attributes, integrating multi-dimensional indicators such as data type signature, timeliness coefficient, and associated business chain hash, enabling terminals to autonomously declare data value. This value is then converted into dynamic "token value" through a bandwidth auction algorithm. In particular, the "business chain hash verification degree" is introduced as a weight multiplier, enhancing the quantifiable expressibility of data logical associations. This ensures the priority reporting of high-priority supervision information such as structural security alarms and key node acceptance under resource-constrained conditions, thereby improving the scenario awareness and response efficiency of the overall scheduling strategy.
[0039] This invention employs a dual-dimensional bidding strategy of "value priority + emergency penetration" to overcome the problem of "non-urgent high-value data crowding out transmission resources" in traditional single-price auction mechanisms, ensuring that data such as security alarms can directly obtain transmission channels under any network pressure. Simultaneously, the introduction of "credit token compensation" and "malicious bidding credit downgrade" mechanisms effectively suppresses malicious terminals that forge high-value credentials or frequently seize bandwidth, achieving dynamic bidding weight correction and resource recovery, and improving the system's adaptability to resource abuse and scheduling congestion. It implements end-to-end bandwidth allocation closed-loop control and a circuit breaker retransmission mechanism, significantly improving transmission link stability and scheduling efficiency.
[0040] This invention introduces a closed-loop link control system consisting of an independent credential channel, a bandwidth-constrained channel, and a transmission circuit breaker mechanism. It distributes digitally watermarked encrypted credentials through a narrowband channel, ensuring that scheduling commands are not interrupted by interference from the main channel. Combined with rate limiting at the underlying network interface, it constructs a strongly constrained transmission channel, completely eliminating the risk of over-limit transmission. The system monitors packet loss rate and actual bandwidth usage in real time, quickly triggering a "circuit breaker + compensation" process to avoid resource waste and accurately reallocate unfinished tasks, effectively improving the overall success rate of transmission of multimedia inspection data and image acquisition packets, as well as system load stability. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0042] Figure 1 This is a schematic diagram of the method flow according to an embodiment of the present invention;
[0043] Figure 2 This is a schematic diagram of transaction bandwidth unit segmentation according to an embodiment of the present invention. Detailed Implementation
[0044] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. For some well-known technologies, those skilled in the art may also use other alternative methods to implement the invention. Moreover, the accompanying drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.
[0045] like Figures 1-2 As shown, the priority-based engineering supervision data processing method includes the following steps:
[0046] S1, Self-declaration of the value of supervision data: Receives data packets sent by multiple source supervision terminals and parses the value proof certificate embedded in the packet; the value proof certificate is generated by the terminal based on data business attribute indicators;
[0047] S2, Dynamic Bandwidth Competition Allocation: Based on the real-time bandwidth capacity and the value proof credentials of each data packet, an improved bandwidth auction algorithm is run to output bandwidth allocation credentials. The improved bandwidth auction algorithm addresses the resource mismatch problem in engineering supervision data by introducing a two-dimensional bidding mechanism and credit downgrade penalty.
[0048] S3, Certificate-driven transmission execution: The bandwidth allocation certificate is sent to the corresponding terminal, and the terminal performs the upload according to the bandwidth value and time window specified in the certificate.
[0049] S1 includes receiving data packets from various supervision terminals through a pre-configured multi-source access interface layer. The interface layer supports adaptation to different protocol standards, including UDP, CoAP, and MQTT protocols. It strips the transport layer packet header and extracts and parses the encrypted value proof credentials embedded in the data packets.
[0050] The value proof certificate is validated through a digital signature verification mechanism. Once the verification is successful, business attribute indicators are parsed out, including data type signature, timeliness coefficient, and associated business chain hash.
[0051] The monitoring terminal executes the following during data collection:
[0052] a) Data type signature generation: Call the local rule engine to match the data content with the supervision classification tree, output the signature ciphertext, and generate an encrypted label to identify the type category of the data;
[0053] b) Calculation of timeliness coefficient: retrieve the latest upload time limit of the corresponding data type from the preset regulatory rule base, and calculate the coefficient value in combination with the data generation time;
[0054] c) Construction of related business chain hash: Retrieve the related business data identifiers stored locally, perform hash iteration operation on the identifier sequence, and generate a verifiable lightweight hash chain.
[0055] 1. Data Type Signature: The data type signature is an encrypted tag generated by the supervision terminal based on the local rule engine matching the data content with the supervision classification tree. It is used to identify the type category of the data. Data type categories include security alarms, risk warnings, compliance reports, process records, multimedia sensing data, and automatic monitoring sensor data.
[0056] Step 1: Initialize the local rule engine and supervision classification tree: The local pre-configured classification tree is a directed acyclic graph (DAG), representing the multi-level classification structure of the supervision data, as shown below:
[0057] Each node contains: a unique identifier Type name (Such as security alarms, etc.), matching condition rules Such as field keywords, data type codes, etc.
[0058] Step 2: Data Content Parsing and Matching: Perform semantic or field parsing on the collected data packet content to generate a structured representation. It matches rules in the classification tree node by node. Examples of commonly used matching rules:
[0059] The JSON field contains → Match "Security Alert" category
[0060] Includes the field `concrete_strength` → Matches "Materials Report Class".
[0061] Image file + location information field → Match "Monitoring Image Class".
[0062] Step 3: Generate data type signature ciphertext (encrypted tag): Once a matching node is located... The terminal performs the following operations to generate the signed ciphertext: ; This indicates the regulator's public key or unified system key. This indicates the timestamp used to generate the tag. This indicates a field concatenation operation; the ciphertext... It can be inserted into a value proof certificate as a verifiable data type label.
[0063] 2. Timeliness coefficient: Timeliness coefficient The ratio reflecting the remaining valid data transmission time relative to the standard period is calculated as follows: ;in, This indicates the latest upload timestamp set in the regulatory rule base for the corresponding data type. This indicates the timestamp of the data received by the system. This indicates the standard transmission cycle defined in the rule base for this type of data.
[0064] 3. Related Business Chain Hash: When collecting supervision data, the terminal uses the identifier sequence of the preceding business data in the local cache or storage. For prior business data such as concrete pouring report IDs and task numbers, a verifiable lightweight association chain is constructed using the following iterative hash function: ;
[0065] in, This indicates a concatenation operation between identifiers. This can be represented as a lightweight, irreversible hash function (such as BLAKE2s or a simplified version of SHA-256). The hash value of the final generated associated business chain is used by the host server to quickly verify the causal relationship between the data. The three indicators together constitute the value proof certificate structure and serve as the basis for subsequent bandwidth competition scheduling and priority control.
[0066] A proof of value certificate can be represented by the following structure: ;in, Indicates the data type signature. Indicates the timeliness coefficient. This represents the hash of the associated business chain.
[0067] S2 specifically includes:
[0068] S21, Construct a virtual bidding market: All currently available bandwidth... According to the unit bandwidth requirement Divided into several tradable bandwidth units: ;in, This refers to the number of tradable bandwidth units. This represents the unit bandwidth value (1Mbps), which is dynamically set based on the average data upload volume.
[0069] For each monitoring terminal data packet, a corresponding virtual token value is constructed. Based on the proof of value, the calculation is as follows: ;in, The signature weight for data types is set according to the data type category and the signature weight setting table. For timeliness coefficient, To verify the validity of the associated business chain, a value is assigned after verification using the server's hash chain consistency. Specifically, this is executed based on the server-side consistency verification mechanism. The server maintains a business data graph index library to map the business logic dependency paths between data. The verification logic is as follows:
[0070] Step 1: Locate the business path: Extract relevant fields (such as construction section number and timestamp) from the data packet, retrieve the preceding task chain from the business data graph library, and construct the target verification sequence. .
[0071] Step 2: Reconstruct the theoretical hash chain: Iteratively reconstruct the theoretical hash chain on the server side.
[0072] .
[0073] Step 3: Calculate the hash consistency ratio: Define the hash chain consistency matching degree as: ; The number of hash chain levels for a complete prefix match. The total number of layers in the theoretical chain. The result is limited to the range [0.8, 1.5] by a smoothing factor, which is used to amplify or weaken the token value. Finally, the value is assigned by the final assignment rule table in Table 2.
[0074] Table 1 Data Type Categories and Signature Weight Settings
[0075] Data type categories Encoding Labels Example data content Recommended weight Wb Setting basis instructions Security Alarms ALERT Excessive deformation of foundation pit, tilting of lifting equipment, etc. 1.5 Extremely high priority, must be reported immediately, could lead to a major safety incident. Risk warning RISK_WARN Personnel were not wearing safety helmets, and materials were stacked abnormally. 1.3 Important but non-fatal risk, requiring medium-speed feedback. Compliance Reporting COMPLIANCE Material testing report, concrete strength report 1.2 It requires record-keeping and is subject to regulations, but its timeliness is moderate. Construction process record PROCESS_LOG Construction log, construction schedule 1 Log-type basic data, with the lowest timeliness requirements Multimedia Perception Data Class MEDIA_SENSE Crack images and video inspection clips 1.1 The storage space is large, and its importance needs to be determined in conjunction with the business chain verification. Automatic monitoring of sensor data AUTO_SENSOR Periodic sampling data such as noise, displacement, and vibration 0.9 Periodic and repetitive data collection results in low value for each data point, primarily relying on trend analysis.
[0076] Table 2 Final Assignment Rules Table
[0077] Matching degree ρb explain Value Complete match (perfect match) Completely consistent with historical business chain 1.5 Partial match (≥80%) Missing a small portion of dependent data 1.1~1.3 Exception or forgery chain No valid matching path 0.8
[0078] S22, execute two-dimensional bidding:
[0079] Dimension 1: Value Priority Bidding: All candidate data packages are bid according to token value. Arrange the data in descending order and select bandwidth units sequentially until all units are exhausted or the data queue is empty.
[0080] Dimension Two: Emergency Penetration Mechanism: When the following penetration trigger conditions are met, the regular bidding process is skipped, and bandwidth units are immediately allocated:
[0081] ; Indicates data type label, The penetration trigger threshold (0.2) is expressed as follows:
[0082] If the first Each data packet meets the following two conditions: 1. Its data type is "Security Alert Class" (i.e., Type...). "Safety Alarm Category" indicates that this is high-risk data directly related to engineering safety (such as foundation pit early warning, structural deformation alarm, etc.); 2. Its timeliness coefficient Less than or equal to the penetration threshold This means that the data is very close to its "latest upload time" and is extremely urgent; therefore, the system will immediately allocate bandwidth units directly to the data packet and will no longer participate in the regular bidding process.
[0083] S23, Generate anti-monopoly bandwidth allocation certificate:
[0084] S231, for the successfully awarded terminal data packets, generate a bandwidth allocation certificate with the following structure: ; Indicates the allocated bandwidth value. Indicates the allocation of transmission time windows, This indicates the token consumption value.
[0085] S232, Failure Compensation Mechanism (Credit Token Compensation): For consecutive For data packets that fail in the second round of bidding, their token value will be increased to: ; The original token value, This indicates a series of consecutive failures.
[0086] S233, Malicious Bidding Credit Downgrade: The credit downgrade mechanism is triggered when a terminal meets the following conditions:
[0087] ; This indicates the number of bids made by the terminal. This indicates the average number of bids in the system. Indicates the success rate of the bid. The data type signature weight decreases by 50% during the penalty period, lasting for 3 rounds. The above is represented as:
[0088] If the following two conditions are met: 1. The number of bids for a certain terminal More than 3 times the average number of bids across all terminals in the system (i.e.) This indicates that the terminal participates in bidding very frequently, which is abnormal behavior; 2. The terminal's success rate in bidding. Less than 10% This indicates that its bidding has almost never been successful, raising suspicions of malicious resource hoarding through "high-frequency, low-efficiency" methods; therefore, the system will assign a "data type signature weight" to this terminal. "Perform a downgrade process by multiplying it by 0.5, which means a reduction of 50%."
[0089] A credit penalty mechanism is implemented to suppress the following behaviors: forging high-priority credentials for frequent bidding, continuously grabbing data without any actual intention to upload data, and occupying system resources, causing bandwidth congestion.
[0090] By reducing Wd, the terminal will be at a significant disadvantage in subsequent token value calculations, thereby reducing its probability of winning bandwidth bids and achieving the goal of curbing resource abuse and system monopoly behavior.
[0091] S3 specifically includes:
[0092] S31, Encryption and Targeted Distribution of Credentials: After the server completes the bandwidth bidding and allocation, each winning terminal generates an encrypted bandwidth allocation credential structure. It further includes the following fields:
[0093]
[0094] The aforementioned credentials, after being digitally watermarked, signed, and encrypted, are distributed via a dedicated narrowband channel (approximately 200kHz bandwidth) for independent supervision. This channel is physically isolated from the main data upload channel and employs a low-power anti-interference protocol (LoRaWAN) to ensure successful credential delivery even in complex engineering environments. For the start time of transmission, This is the transmission end time.
[0095] S32, Terminal credential verification and link establishment: Terminal receives and caches... Then, execute the following process:
[0096] Perform digital watermark verification on the voucher to confirm its authenticity;
[0097] If the current system time If so, the credentials will be cached in the local secure storage area and wait for the valid transmission window to open;
[0098] arrive At that time, the terminal uses the one-time key in the credential. Establish an encrypted connection with the server and call the network driver interface to limit the upload rate. Construct the following constraints:
[0099] This indicates that the terminal's data upload rate must be less than or equal to the bandwidth allocated by the system. This establishes a bandwidth-constrained transmission channel for the terminal, ensuring that the transmission complies with the range specified in the auction certificate and preventing unauthorized speed increases that could consume bandwidth.
[0100] S33, Dynamic Link Quality Monitoring and Circuit Breaker Mechanism: During data upload, the system monitors two indicators in real time: actual upload rate. Channel packet loss rate A higher packet loss rate in the channel will cause a decrease in the actual upload rate.
[0101] If the following conditions are met within three consecutive seconds: ;
[0102] Within a consecutive 3-second time window Within, if the actual upload speed of the terminal If the bandwidth is consistently below 60% of its allocated bandwidth, the link performance is considered substandard and a circuit breaker mechanism may be triggered.
[0103] This will trigger the credential expiration circuit breaker mechanism, and the following operations will be performed:
[0104] 1. Terminate the current transmission task and release bandwidth resources;
[0105] 2. Set the status of the remaining data packets to "pending retransmission" for subsequent compensation scheduling;
[0106] 3. Automatically construct the compensation request structure, with the following content:
[0107] ;
[0108] The request will be submitted to the bandwidth scheduling system to participate in the next round of compensation bidding.
[0109] This invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of this invention. To provide the public with a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments; however, those skilled in the art will fully understand the invention even without these details. Furthermore, to avoid unnecessary misunderstanding of the essence of this invention, well-known methods, processes, procedures, components, and circuits are not described in detail.
[0110] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A priority-based engineering supervision data processing method, characterized by, The method comprises the following steps: S1, supervising data value self-declaration: receiving data packets sent by multi-source supervision terminals, and analyzing the value proof certificate embedded in the packet; the value proof certificate is generated by the terminal based on data service attribute index; S2, dynamic bandwidth competition and allocation: according to the real-time bandwidth capacity and the value proof certificate of each data packet, an improved bandwidth auction algorithm is run to output a bandwidth allocation certificate, and the improved bandwidth auction algorithm introduces a two-dimensional bidding mechanism and a credit degradation penalty for the resource mismatch problem in engineering supervision data; S3, certificate-driven transmission execution: the bandwidth allocation certificate is sent to the corresponding terminal, and the terminal executes uploading according to the bandwidth value and time window in the certificate; The S2 specifically comprises: S21, constructing a virtual bidding market: the real-time bandwidth capacity is divided into several tradable bandwidth units, each tradable bandwidth unit is attached with a basic price, and the value proof certificate of each supervision terminal data packet is given a virtual token value; S22, executing two-dimensional bidding: Dimension one: value priority bidding; Dimension two: emergency penetration bidding; S23, generating anti-monopoly bandwidth allocation certificate: generating a bandwidth allocation certificate including allocation bandwidth value, time window and token consumption for the supervision data packet that successfully competes for bandwidth, and the time window is the shortest upload time period, and if the penetration mechanism is triggered, it is immediately set to a continuous window starting from the current time; The virtual token value is based on a value proof certificate and is calculated as: ; wherein, is a data type signature weight, is a time coefficient, is a related business chain verification degree, which is assigned after verification by server hash chain consistency; The value priority bidding comprises: the supervision data packet bids in descending order of token value, the high token value is preferentially selected to trade the bandwidth unit, and the unit is exhausted or the data queue is empty; The emergency penetration bidding comprises: when the data type signature is identified as a safety alarm type and the time limit coefficient is lower than the penetration trigger threshold, the penetration mechanism is triggered to directly allocate bandwidth; The S23 further comprises: Failure compensation mechanism: starting credit token compensation for supervision data packets that fail to compete continuously: increasing the token value weight by 1 for each failure in the next round; Malicious bidding credit degradation: performing credit degradation on malicious high-frequency bidding terminals: reducing the data type signature weight and continuing for multiple rounds.
2. The priority-based engineering inspection data processing method of claim 1, wherein, The S1 comprises receiving data packets from each supervision terminal through a pre-set multi-source access interface layer, the interface layer supports adapting to different protocol standards including UDP, CoAP and MQTT protocol, stripping the transmission layer packet header, extracting and analyzing the encrypted value proof certificate embedded in the data packet.
3. The priority-based engineering inspection data processing method of claim 1, wherein, The value proof certificate is verified for validity through a digital signature verification mechanism, and after verification, the business attribute index is parsed, including data type signature, time limit coefficient and associated business chain hash.
4. The priority-based engineering inspection data processing method of claim 1, wherein, The supervision terminal executes the following when collecting data: a) Data type signature generation: calling a local rule engine to match data content and supervision classification tree, outputting signature ciphertext, and generating an encrypted label to identify the type of data; b) Time limit coefficient calculation: calling the latest upload time limit of the corresponding data type in the pre-set supervision rule library to calculate the coefficient value in combination with the data generation time; c) Associated business chain hash construction: retrieving the associated business data identifier stored locally, and performing hash iteration operation on the identifier sequence to generate a verifiable lightweight hash chain.
5. The priority-based engineering inspection data processing method of claim 1, wherein, The S3 specifically comprises: S31, certificate encryption and directional delivery: the server generates a bandwidth allocation certificate with a digital watermark signature, the bandwidth allocation certificate structure includes terminal device unique identifier, allocated bandwidth value, transmission time window, token consumption value and one-time link encryption key, and is delivered to the designated monitoring terminal through the supervisor special narrowband channel; S32, terminal certificate verification and link establishment: the terminal verifies the digital watermark signature and the transmission time window validity of the certificate, if the current time is earlier than the start point of the transmission time window, the certificate is cached to the secure storage area; When the transmission start time is reached, the link encryption key is used to establish a transmission channel with bandwidth value constraint, which forcibly limits the upload rate to be not more than the allocated bandwidth value; S33, link quality monitoring and fusing: the packet loss rate and delay fluctuation of the transmission channel are monitored in real time, when the actual bandwidth value is continuously detected to be lower than the allocated bandwidth value for a long time, the certificate invalidation fusing is triggered.
6. The priority-based engineering inspection data processing method of claim 5, wherein, The trigger certificate invalidation fusing includes: a) immediately terminate the current transmission and release the bandwidth resource; b) mark the unfinished data packet as a retransmission state; c) the terminal automatically generates a compensation request including the original certificate hash and submits it to the bandwidth auction system.
Citation Information
Patent Citations
Data flow priority management method and system of optical communication device
CN118764438A