A safety hazard intelligent identification and early warning system based on Internet of Things

By deploying hybrid sensing acquisition units and intelligent analysis modules, the system identifies and responds to security vulnerabilities in IoT devices, solving the problem of insufficient monitoring of non-communication physical signal attacks in existing technologies, and achieving full-stack security protection and rapid response for IoT devices.

CN120639469BActive Publication Date: 2026-02-17ZHEJIANG CHUANGGAO SOFTWARE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511000204.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2026-02-17
Estimated Expiration
2045-07-21

AI Technical Summary

Technical Problem

Existing IoT security solutions lack effective monitoring and defense against attacks that are not related to communication physical signals. This results in low detection rates of device key theft, misoperation, and hardware Trojans, insufficient handling of cross-domain causal relationships, and the inability of traditional response mechanisms to proactively counterattack, leading to the collapse of security defenses.

Method used

A hybrid sensor deployment module is adopted, which combines quantum electromagnetic sensors, acoustic arrays, and power consumption sampling circuits to acquire electromagnetic leakage, acoustic anomalies, and energy consumption fluctuation characteristic data of the equipment. The security hazard type analysis module identifies abnormal equipment and implements targeted response strategies. The cross-device threat diffusion prediction module predicts the threat diffusion level, and the security hazard early warning module provides timely warnings.

Benefits of technology

An integrated architecture of "monitoring-diagnosis-prediction-response" has been constructed, which realizes full-stack security protection for IoT devices, reduces the risk of cascading failures, improves attack interception rate and response efficiency, and ensures the safe operation of critical infrastructure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639469B_ABST
    Figure CN120639469B_ABST
Patent Text Reader

Abstract

The application discloses a kind of safety hidden danger intelligent identification and early warning system based on Internet of Things, it is related to Internet of Things security technical field, and is built around Internet of Things equipment security protection, and mixed type sensing acquisition body deployment module is deployed multimodal sensor in the periphery of equipment, and the signal parameters such as electromagnetic, sound wave, power consumption are collected to analyze security posture;Safety hidden danger type analysis module identifies abnormal equipment according to posture evaluation value, determines hidden danger type and matches response strategy;Cross-device threat diffusion prediction module predicts diffusion level and formulates adjacent equipment defense strategy through adjacent equipment risk transmission coefficient;Safety hidden danger early warning module then early warning in time to the equipment and its adjacent equipment that exist hidden danger, form the complete safety protection closed loop of " perception-analysis-prediction-early warning", guarantee Internet of Things equipment safe operation.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet of Things security, and in particular to a security risk intelligent identification and early warning system based on Internet of Things. BACKGROUND

[0002] With the large-scale application of Internet of Things technology in industrial control, smart city, medical health and other fields, Internet of Things devices are facing full-stack security threats from the physical carrier layer to the logical target layer and the system constraint layer, and the traditional security scheme has technical bottlenecks such as fragmented monitoring of multi-modal signals, lack of cross-device threat diffusion prediction, and weak active defense capabilities. In addition, the strict requirements for device security in energy, military and other key fields, it is urgent to build a new security protection system that integrates quantum sensing, multi-modal analysis and intelligent prediction. Therefore, a security risk intelligent identification and early warning system based on Internet of Things emerges as the times require.

[0003] The prior art such as the invention application patent published under the publication number CN115809941A discloses a personalized precision maintenance strategy based on substation equipment operation situation awareness analysis, including establishing an electric power grid operation situation evaluation basic framework, situation understanding stage prediction and situation prediction stage prediction. The present application obtains the main auxiliary equipment monitoring information, combines the regulations and expert experience, establishes the correlation rules between multiple device states and defects based on image recognition, intelligent reasoning and big data intelligent analysis technology, uses the substation equipment state real-time early warning model, equipment defect automatic analysis model and equipment defect processing strategy, etc., and constructs a substation equipment defect active early warning mechanism based on multi-physical quantity perception. The calculation result obtained by the present application using the result of the power flow calculation has a large deviation from the true value, but the data processing and correction using state estimation greatly improves the calculation accuracy and can truly reflect the operation state of the system.

[0004] For the above-mentioned scheme, the present application has found that the above-mentioned technology at least has the following technical problems: 1. The existing technology only focuses on the security monitoring of traditional communication frequency bands, and is completely blind to non-communication physical signal attacks: attackers can steal encryption keys using electromagnetic side channels, while traditional IDS lacks quantum-level sensing and cannot capture weak device electromagnetic fingerprints; at the same time, ultrasonic command injection can silently control voice assistant devices, but traditional acoustic detection is insufficient, resulting in low interception rate of such attacks, leading to a surge in ultrasonic attack events; malicious firmware activated nano-ampere power spurts are ignored due to insufficient sampling accuracy, resulting in low detection rate of hardware Trojan horses.

[0005] 2. Existing solutions lack a physical-digital signal fusion analysis engine, making it impossible to establish cross-domain causal relationships. This leads to the separation of physical environment anomalies and network attacks, resulting in 23.7% of cascading failures in industrial scenarios going unnoticed. Attackers create semantic ambiguity at the protocol translation layer, and because traditional syntax validation cannot understand the instruction context, this causes significant losses of millions of dollars annually due to equipment misoperation. At the same time, resource depletion attacks, due to the lack of modeling the power-security function relationship, cause the system to directly disable intrusion detection when the power level drops below 10%, resulting in the collapse of security defenses.

[0006] 3. Traditional response mechanisms rely on post-incident blocking and cannot achieve proactive countermeasures at the physical layer: In the face of electromagnetic eavesdropping, encryption algorithms can only be passively strengthened, while attackers can still break through the defense by increasing the receiver sensitivity, resulting in a countermeasure efficiency of less than 40%; ultrasonic attacks can only be identified after the device executes malicious commands, with an average response delay of >5 seconds, far exceeding the 200ms security threshold for critical operations such as door lock opening; due to the lack of hardware fingerprint analysis such as power consumption base frequency correlation coefficients, contaminated devices in the hardware supply chain are operating with defects in batches. Summary of the Invention

[0007] To address the aforementioned technical shortcomings, the purpose of this invention is to provide an intelligent identification and early warning system for security risks based on the Internet of Things.

[0008] To solve the above-mentioned technical problems, the present invention adopts the following technical solution: The present invention provides a smart identification and early warning system for security risks based on the Internet of Things, including: a hybrid sensor acquisition module: used to dynamically adapt the hybrid sensor acquisition module to the surrounding area of ​​each device of the target enterprise, thereby acquiring electromagnetic leakage characteristic data, acoustic wave abnormality characteristic data and energy consumption fluctuation characteristic data of each device under the current dynamic triggering state.

[0009] Safety Hazard Type Analysis Module: This module assesses whether each device has a safety hazard based on its dynamic safety risk value. If a device has a safety hazard, it is recorded as an abnormal device. The module then analyzes the subcategories of safety hazards for each abnormal device and performs adaptive response strategy analysis for each abnormal device.

[0010] Cross-device threat propagation prediction module: used to obtain the risk transmission coefficient of adjacent devices corresponding to each abnormal device, thereby predicting the cross-device risk propagation level corresponding to each abnormal device, and then analyzing the neighborhood immunity strategy corresponding to the adjacent devices of each abnormal device.

[0011] Safety Hazard Early Warning Module: This module is used to issue early warnings when a device has a safety hazard, and also to issue early warnings to adjacent devices in each abnormal device.

[0012] The beneficial effects of the present application are: 1. The embodiment of the present application constructs an integrated architecture of "monitoring-diagnosis-prediction-response". The mixed type sensing collection module collects device operation signals in multiple dimensions through quantum electromagnetic sensors, high-precision acoustic arrays and power consumption sampling circuits, and generates dynamic security risk values after data processing; the security hidden danger type analysis module identifies abnormal devices accordingly, divides three types of hidden dangers of physical carrier layer, logical target layer and system constraint layer, and matches targeted response strategies; the cross-device threat diffusion prediction module predicts the threat diffusion level by quantifying the feature similarity between devices and implements hierarchical defense; the security hidden danger early warning module timely warns abnormal devices and surrounding devices, forming a complete security protection closed loop.

[0013] 2. The embodiment of the present application formulates a differentiated response mechanism for different hidden danger types and threat diffusion levels. For physical carrier layer hidden dangers, quantum random phase noise interference and hardware relay cut-off are used to realize efficient electromagnetic / acoustic attack interception; for logical target layer hidden dangers, semantic completion rules and virtual causal firewall are used to greatly reduce the risk of cascading failures; for system constraint layer hidden dangers, resource priority scheduling and ethical constraint injection are used to ensure high survival rate of core business. In cross-device threat defense, according to low, medium and high risk levels, enhanced monitoring, dynamic isolation and emergency blocking strategies are respectively executed to effectively block the threat diffusion path.

[0014] 3. The embodiment of the present application has significant application value in the fields of industry, medical treatment, energy and the like. In the industrial scene, production accidents caused by PLC instruction tampering are successfully reduced, and economic losses of enterprises are reduced; in the medical environment, rapid response to ultrasonic attacks is realized, and safe operation of medical devices is ensured; in the technical aspect, the technical gap in the field of non-communication physical signal monitoring is filled, and cloud platform elastic expansion and lightweight deployment are supported. The system not only provides full-stack security protection for Internet of Things devices, but also provides an innovative solution for the safe operation of critical infrastructure, promoting the upgrading and development of Internet of Things security protection technology. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description only some embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor on the basis of these drawings.

[0016] Figure 1 The system module connection diagram of the present application. DETAILED DESCRIPTION

[0017] With reference to the accompanying drawings, the technical solutions in the embodiments of the present application will be clearly and completely described below, obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present application.

[0018] The embodiment of the present application comprises Figure 1 As shown in the figure, a safety hazard intelligent identification and early warning system based on Internet of Things comprises a hybrid sensor collection body deployment module, a safety hazard type analysis module, a cross-device threat diffusion prediction module, a safety hazard early warning module and a database.

[0019] The safety hazard type analysis module is connected with the hybrid sensor collection body deployment module and the cross-device threat diffusion prediction module respectively, the safety hazard early warning module is connected with the safety hazard type analysis module and the cross-device threat diffusion prediction module respectively, and the database is connected with the safety hazard type analysis module.

[0020] The hybrid sensor collection body deployment module is used for dynamically adapting the hybrid sensor collection body deployment around each device of the target enterprise, so as to obtain the electromagnetic leakage feature data, the sound wave abnormal feature data and the energy consumption fluctuation feature data of each device under the dynamic triggering state at the current time.

[0021] In a specific embodiment, the dynamically adapting hybrid sensor collection body deployment around each device of the target enterprise has the following specific deployment process: S1, quantum electromagnetic sensor deployment: the type corresponding to each device is obtained, so as to dynamically plan the installation position, if the type corresponding to a certain device is a high-voltage device, the quantum electromagnetic sensor is installed on the signal blind area outside 1.5 meters ± 0.3 meters away from the device through the magnetic attraction type movable support; if the type corresponding to a certain device is a precision device, the sensor is fixed at 0.8 meters away from the device, and the inclination is 30°; all sensors use quantum state regulation technology to convert electromagnetic signals into photon spin state changes, and real-time capture electromagnetic leakage signals in the data transmission frequency band.

[0022] S2, high-precision sound wave array deployment: after the quantum electromagnetic sensor deployment of each device is completed, a 360° ring array is arranged within 0.5 meters radius around each device, 4 MEMS microphones are uniformly distributed, and the beam forming technology is used for directional monitoring of ultrasonic attack signals; for mobile devices, Bluetooth Mesh dynamic networking is used, and the sound wave array keeps a distance of 0.3 meters away from the device to keep synchronous sampling.

[0023] S3, power consumption sampling circuit deployment: after the deployment of the quantum electromagnetic sensor and the high-precision acoustic wave array corresponding to each device is completed, a power consumption sampling circuit is connected to the power supply circuit of each device, and a wireless sampling node using UWB positioning linkage is adopted for the mobile device; all sensor Internet of Things devices are connected.

[0024] In one specific embodiment, the analysis obtains a dynamic security risk value corresponding to each device, and the specific analysis process is as follows: the electromagnetic leakage coefficient, the acoustic anomaly coefficient, and the energy consumption fluctuation coefficient corresponding to each device are analyzed, and the electromagnetic leakage coefficient, the acoustic anomaly coefficient, and the energy consumption fluctuation coefficient corresponding to each device are normalized and substituted into the dynamic security risk value analysis module to obtain the dynamic security risk value corresponding to each device.

[0025] It should be noted that the analysis process of the dynamic security risk value corresponding to each device is as follows: the electromagnetic leakage coefficient, the acoustic anomaly coefficient, and the energy consumption fluctuation coefficient corresponding to each device are respectively denoted as , and , wherein v represents the number of each device, , is a positive integer, and the analysis formula is substituted as follows: to obtain the dynamic security risk value corresponding to each device, wherein , and are the standard electromagnetic leakage coefficient, the standard acoustic anomaly coefficient, and the standard energy consumption fluctuation coefficient corresponding to the device, respectively.

[0026] It should also be noted that the three-level process of "laboratory calibration + scenario calibration + dynamic self-learning" is used to determine: first, in an electromagnetic compatibility laboratory, an acoustic anechoic chamber, or the like, a simulated attack test is carried out on the target device, such as injecting different intensity electromagnetic interference and ultrasonic instructions, recording the maximum electromagnetic threshold value of the electromagnetic spectrum energy density, the ultrasonic power critical value, and the power consumption fluctuation standard deviation when the device malfunctions or data leaks, as the standard electromagnetic leakage coefficient, the standard acoustic anomaly coefficient, and the standard energy consumption fluctuation coefficient corresponding to the device.

[0027] In one specific embodiment, the analysis of the electromagnetic leakage coefficient, the acoustic anomaly coefficient, and the energy consumption fluctuation coefficient corresponding to each device has the following specific analysis process: A1, the electromagnetic leakage feature data, the acoustic anomaly feature data, and the energy consumption fluctuation feature data corresponding to each device at the current time are obtained, the electromagnetic leakage feature data including the spectrum energy density, the spectrum entropy value, and the polarization direction deviation angle; the acoustic anomaly feature data including the ultrasonic energy peak value, the harmonic distortion rate, and the voiceprint MFCC dynamic range; the energy consumption fluctuation feature data including the transient current slope and the wavelet energy entropy.

[0028] It should be noted that the electromagnetic leakage feature data acquisition: with the help of the deployed quantum electromagnetic sensor, the quantum state regulation technology is used to collect the electromagnetic signals radiated by the equipment during operation. The original electromagnetic signal data is obtained by a high-speed data acquisition card at a set sampling frequency, and then a signal processing algorithm is used to perform short-time Fourier transform on the original data. From the time-frequency diagram after transformation, the spectral energy density, spectral entropy value, and polarization direction offset angle are obtained, which are combined with the mathematical model of the signal polarization characteristics to accurately obtain the spectral energy density, spectral entropy value, and polarization direction offset angle parameters related to the electromagnetic signal. The signal processing algorithm and short-time Fourier transform are both prior art.

[0029] Acoustic wave anomaly feature data acquisition: rely on high-precision acoustic wave array, which is composed of multiple MEMS microphones, use beamforming technology to focus on collecting acoustic wave signals in a specific area around the equipment. After the microphone array collects the original acoustic wave data at a certain sampling rate, it is preprocessed by filtering to remove environmental noise. For the ultrasonic energy peak value, the maximum energy value of the acoustic wave signal in the frequency band of 40kHz-00kHz is searched; for the harmonic distortion rate, the harmonic analysis algorithm is used to calculate the energy relationship between the fundamental wave and each harmonic; and the MFCC dynamic range of the acoustic fingerprint is determined by first extracting the Mel frequency cepstral coefficient (MFCC) of the acoustic wave and then analyzing its dynamic change amplitude in the time sequence. The harmonic analysis algorithm is prior art.

[0030] Energy consumption fluctuation feature data acquisition: by connecting a power consumption sampling circuit in the equipment power supply circuit, the circuit has high sampling frequency and high resolution, and collects the instantaneous change data of the power supply current of the equipment during operation. For transient current slope, the differential operation is performed on the continuously collected current data, and the current change rate is calculated based on the time interval; for wavelet energy entropy, the wavelet transform algorithm is used to perform multi-scale decomposition on the power consumption data to obtain wavelet coefficients at different scales, and the wavelet energy entropy is calculated based on the energy distribution of the wavelet coefficients at each scale, so as to obtain the transient current slope and wavelet energy entropy parameters related to the power consumption signal

[0031] A2, normalize the electromagnetic leakage feature data, acoustic wave anomaly feature data, and energy consumption fluctuation feature data corresponding to each device, and input them as input items into the electromagnetic leakage coefficient analysis module, acoustic wave anomaly coefficient analysis model, and energy consumption fluctuation coefficient analysis model, respectively, to output the electromagnetic leakage coefficient, acoustic wave anomaly coefficient, and energy consumption fluctuation coefficient corresponding to each device.

[0032] It should be noted that the analysis process of the electromagnetic leakage coefficient corresponding to each device is as follows: the spectral energy density, spectral entropy value, and polarization direction offset angle corresponding to each device are denoted as , and Wherein, the analysis formula is substituted as follows: Wherein, the electromagnetic leakage coefficient corresponding to each device is obtained ; in this way, the sound wave anomaly coefficient corresponding to each device is obtained by further analysis and energy consumption fluctuation coefficient .

[0033] The security risk type analysis module is configured to evaluate whether each device has a security risk according to the dynamic security risk value corresponding to each device, and if a device has a security risk, it is recorded as an abnormal device, and then analyze the security risk subcategory corresponding to each abnormal device and analyze the response strategy for each abnormal device.

[0034] In a specific embodiment, the evaluation of whether each device has a security risk is as follows: compare the dynamic security risk value corresponding to each device with the dynamic security risk value interval corresponding to the standard device, if the dynamic security risk value corresponding to a device is within the dynamic security risk value interval corresponding to the standard device, it is evaluated that the device does not have a security risk, if the dynamic security risk value corresponding to a device is not within the dynamic security risk value interval corresponding to the standard device, it is evaluated that the device has a security risk.

[0035] In a specific embodiment, the analysis of the security risk subcategory corresponding to each abnormal device is as follows: compare the dynamic security risk value corresponding to each abnormal device with the dynamic security risk value interval corresponding to each security risk type in the database, if the dynamic security risk value corresponding to an abnormal device is within the dynamic security risk value interval corresponding to a security risk type in the database, record the security risk type in the database as the security risk type corresponding to the abnormal device.

[0036] The security risk type includes a physical carrier layer risk, a logical target layer risk, and a system constraint layer risk.

[0037] In a specific embodiment, the analysis of the response strategy for each abnormal device is as follows: B1, if the security risk type corresponding to an abnormal device is a physical carrier layer risk, execute quantum barrier and hierarchical hardware fuse defense strategy.

[0038] It should be noted that the quantum barrier and hierarchical hardware fuse defense strategy is: taking "dynamic signal countermeasure + hierarchical hardware isolation" as the core, by monitoring the attack intensity parameters such as electromagnetic leakage power and ultrasonic energy peak value in real time, the defense strength is adaptively adjusted: low intensity attack only starts quantum random phase noise generator to destroy electromagnetic signal coherence, high intensity attack synchronously activates MEMS array to generate opposite phase sound waves to form a cancellation zone, and according to the risk grading of hidden danger diffusion, triggers hardware isolation (low risk fuse external interface power supply, high risk triggers main circuit rapid fuse), while continuously monitoring the attack characteristic parameters, if it does not return to normal within 3 seconds, it will repeat the countermeasure and upgrade the warning, realizing the closed-loop defense of "suppression-isolation-verification".

[0039] B2, if the security risk type corresponding to the abnormal device is a logical target layer risk, a semantic correction and dynamic causal firewall strategy is executed.

[0040] It should be noted that the semantic correction and dynamic causal firewall strategy is: to build an "adaptive repair + traceability fuse" mechanism, relying on incremental learning knowledge graph, quickly matching historical cases to inject complete rules for semantic anomalies (such as incorrect instruction format), and generating temporary repair rules for new attacks through Few-Shot learning; At the same time, based on the ST-GNN attack path graph, Kalman filter is used to correct drifting data at the data layer, and instruction mutual exclusion lock is deployed at the control layer to block the conduction path, trace the attack source and link the firewall for interception, automatically update the path weight parameters every time an attack is processed, and continuously optimize the attack prediction accuracy.

[0041] B3, if the security risk type corresponding to the abnormal device is a system constraint layer risk, an intelligent resilience scheduling and multi-dimensional ethical injection control strategy is executed.

[0042] It should be noted that the intelligent resilience scheduling and multi-dimensional ethical injection control strategy is: through a "core-edge-redundancy" three-level function priority tree to dynamically schedule resources, automatically shut down the edge function when overloaded, switch the core function to a lightweight model and enable redundant devices, while monitoring the core business response delay in real time to balance resource allocation; Fusion of security, energy consumption, privacy constraints, trigger "minimum permission mode" when core function error rate exceeds 5% due to attack, first reduce load and then power off when carbon emission exceeds threshold, automatically desensitize and isolate transmission channel when sensitive data leakage risk occurs, while ensuring business continuity and meeting multi-dimensional compliance requirements.

[0043] Cross-device threat diffusion prediction module: used to obtain the risk conduction coefficient of each adjacent device corresponding to each abnormal device, thereby predicting the cross-device risk diffusion level corresponding to each abnormal device, and then analyzing the neighborhood immunity strategy corresponding to the adjacent device of each abnormal device.

[0044] In a specific embodiment, the acquiring of the adjacent device risk conduction coefficient corresponding to each abnormal device comprises the following specific process: acquiring the dynamic security risk values corresponding to each abnormal device and each adjacent device in each abnormal device, and denoting them as and wherein h represents the number corresponding to each abnormal device, , is a positive integer, is also the sum of each abnormal device, and k represents the number corresponding to each adjacent device, , is a positive integer, is also the sum of each adjacent device, and substituting into the calculation formula: wherein the adjacent device risk conduction coefficient corresponding to each abnormal device is obtained wherein represents the number of adjacent devices in the abnormal device, , represents the sum of the number of adjacent devices, represents the set device feature similarity radius.

[0045] In a specific embodiment, the predicting of the cross-device risk diffusion level corresponding to each abnormal device comprises the following specific process: comparing the adjacent device risk conduction coefficient corresponding to each abnormal device with the adjacent device risk conduction coefficient interval corresponding to each set cross-device risk diffusion level, if the adjacent device risk conduction coefficient corresponding to a certain abnormal device is located in the adjacent device risk conduction coefficient interval corresponding to a certain set cross-device risk diffusion level, then the set cross-device risk diffusion level is taken as the cross-device risk diffusion level corresponding to the abnormal device.

[0046] The cross-device risk diffusion level comprises low diffusion risk, medium diffusion risk and high diffusion risk.

[0047] In a specific embodiment, the analyzing of the neighborhood immunity strategy corresponding to each abnormal device adjacent device comprises the following specific process: C1, if the cross-device risk diffusion level corresponding to a certain abnormal device is low diffusion risk, then the enhanced monitoring and basic protection strategy is executed on the adjacent device of the abnormal device.

[0048] It should be noted that the enhanced monitoring and basic protection strategy is that the sampling frequency of the multi-modal sensor of the adjacent device is increased by 30%, the electromagnetic, acoustic and power consumption signals are collected in real time, the data is analyzed by the edge computing device at a high frequency, and the potential threat trend can be quickly captured; the network access control list of the adjacent device is updated synchronously, unnecessary communication ports are closed, and non-key data interaction with abnormal devices is limited; at the same time, a lightweight intrusion detection program is started in the adjacent device, and the device running state and data transmission behavior are scanned once an hour, and once an abnormality is found, it is reported to the alarm, and on the premise of maintaining the normal operation of the device, a basic protection barrier is built to prevent the threat from further spreading.

[0049] C2, if the cross-device risk diffusion level of the abnormal device is medium diffusion risk, the dynamic isolation and cooperative defense strategy is executed on the adjacent devices of the abnormal device.

[0050] It should be noted that the dynamic isolation and cooperative defense strategy is to automatically cut off the unnecessary physical communication link between the adjacent device and the abnormal device, and at the same time, a virtual firewall is deployed at the network layer to limit the IP-level data interaction between the two, only necessary state monitoring communication is retained; secondly, the adjacent devices are included in the cooperative defense group, and the security risk characteristic parameters and attack mode information of the abnormal device are shared, and based on the multi-modal signal analysis model, the joint risk assessment is performed on the devices in the group; in addition, the real-time backup mechanism is started for the key business data of the adjacent device, and the data is synchronized to the secure storage node every 10 minutes, and if the threat spreads, the device can quickly recover to normal state, effectively containing the spread of the threat in the region.

[0051] C3, if the cross-device risk diffusion level of the abnormal device is high diffusion risk, the emergency blocking and global reconstruction strategy is executed on the adjacent devices of the abnormal device.

[0052] It should be noted that the emergency blocking and global reconstruction strategy is to cut off the power supply connection and network link between the adjacent device and the abnormal device through a physical relay, implement physical isolation; at the same time, trigger the emergency response program of all devices in the region, migrate the core business to the standby server or cloud disaster recovery system to ensure uninterrupted key functions; reset the adjacent devices at the system level, clear the possibly infected firmware and data, and redeploy the latest security protection program and vulnerability patch; finally, use blockchain technology to store evidence of the security state and data of the device, build a new device trust network, and reconstruct the Internet of Things architecture in the affected area, through deep detection and repair, completely eliminate the high diffusion threat, and restore the safe operation environment of the devices in the region.

[0053] Security hazard warning module: used for warning when a device has a security hazard, and warning each adjacent device in each abnormal device.

[0054] The above merely provides the illustration and description of the concept of the present application. Those skilled in the art can make various modifications or supplements to the described specific embodiments or adopt similar ways to replace, as long as they do not deviate from the concept of the present application or exceed the range defined in the specification, which shall belong to the protection scope of the present application.

Claims

1. An Internet of Things-based intelligent identification and early warning system for safety hazards, characterized in that, The application comprises the following: A mixed sensing collection body deployment module is used for dynamically adapting the mixed sensing collection body deployment around each device in the target enterprise, so as to obtain the electromagnetic leakage characteristic data, the sound wave abnormal characteristic data and the energy consumption fluctuation characteristic data of each device corresponding to the dynamic trigger state at the current time; A security risk type analysis module is used for evaluating whether each device has a security risk according to the dynamic security risk value corresponding to each device, and if a certain device has a security risk, the device is recorded as an abnormal device, and then the security risk subcategory corresponding to each abnormal device is analyzed, and the adaptability response strategy of each abnormal device is analyzed; The dynamic security risk value corresponding to each device is obtained through the analysis, and the specific analysis process is as follows: The electromagnetic leakage coefficient, the sound wave abnormal coefficient and the energy consumption fluctuation coefficient corresponding to each device are analyzed, and the electromagnetic leakage coefficient, the sound wave abnormal coefficient and the energy consumption fluctuation coefficient corresponding to each device are normalized and input into the dynamic security risk value analysis module to obtain the dynamic security risk value corresponding to each device; The specific analysis process of the electromagnetic leakage coefficient, the sound wave abnormal coefficient and the energy consumption fluctuation coefficient corresponding to each device is as follows: A1, the electromagnetic leakage characteristic data, the sound wave abnormal characteristic data and the energy consumption fluctuation characteristic data corresponding to each device at the current time are obtained, the electromagnetic leakage characteristic data includes the spectral energy density, the spectral entropy value and the polarization direction offset angle; the sound wave abnormal characteristic data includes the ultrasonic energy peak value, the harmonic distortion rate and the voiceprint MFCC dynamic range; the energy consumption fluctuation characteristic data includes the transient current slope and the wavelet energy entropy; A2, the electromagnetic leakage characteristic data, the sound wave abnormal characteristic data and the energy consumption fluctuation characteristic data corresponding to each device are normalized and input into the electromagnetic leakage coefficient analysis module, the sound wave abnormal coefficient analysis model and the energy consumption fluctuation coefficient analysis model as input items, and the electromagnetic leakage coefficient, the sound wave abnormal coefficient and the energy consumption fluctuation coefficient corresponding to each device are output; A cross-device threat diffusion prediction module is used for obtaining the adjacent device risk conduction coefficient corresponding to each abnormal device, so as to predict the cross-device risk diffusion level corresponding to each abnormal device, and analyze the neighborhood immunity strategy corresponding to the adjacent device of each abnormal device; The specific acquisition process of the adjacent device risk conduction coefficient corresponding to each abnormal device is as follows: The dynamic security risk values corresponding to each abnormal device and each adjacent device in each abnormal device are obtained and respectively recorded as and wherein h represents the number corresponding to each abnormal device, , is a positive integer, is also the sum of each abnormal device, and k represents the number corresponding to each adjacent device, , is a positive integer, is also the sum of each adjacent device, and substituted into the calculation formula: wherein the adjacent device risk conduction coefficient corresponding to each abnormal device is obtained wherein represents the number of adjacent devices in the abnormal device, , represents the sum of the number of adjacent devices, represents the set device feature similarity radius; A security risk early warning module is used for early warning when a certain device has a security risk, and early warning is given to each adjacent device in each abnormal device.

2. The safety hazard intelligent identification and early warning system based on the Internet of Things according to claim 1, characterized in that, The specific deployment process of the mixed sensing collection body deployment around each device in the target enterprise is as follows: S1, quantum electromagnetic sensor deployment: the type corresponding to each device is obtained, so as to dynamically plan the installation position, if the type corresponding to a certain device is a high-voltage device, the quantum electromagnetic sensor is installed on the signal blind area outside 1.5 meters ± 0.3 meters away from the device through a magnetic attraction type movable support; if the type corresponding to a certain device is a precision device, the sensor is fixed at 0.8 meters away from the device with an inclination of 30°; all sensors use quantum state regulation technology to convert electromagnetic signals into photon spin state changes, and real-time capture electromagnetic leakage signals in the data transmission frequency band; S2, high-precision acoustic array deployment: after the deployment of quantum electromagnetic sensors corresponding to each device is completed, 360° ring array is adopted within a radius of 0.5 meters around each device, 4 MEMS microphones are uniformly distributed, and the attack signal of ultrasonic wave is monitored by beamforming technology; Bluetooth Mesh dynamic networking is adopted for mobile devices, and the acoustic array keeps a distance of 0.3 meters from the device to keep sampling synchronously; S3, power sampling circuit deployment: after the deployment of quantum electromagnetic sensors and high-precision acoustic array corresponding to each device is completed, power sampling circuit is connected in the power supply circuit of each device, UWB positioning linkage wireless sampling node is adopted for mobile devices; all sensor Internet of Things devices are connected.

3. The safety hazard intelligent identification and early warning system based on the Internet of Things according to claim 1, characterized in that, The evaluation of whether each device has a security risk is as follows: The dynamic security risk value corresponding to each device is compared with the dynamic security risk value interval corresponding to the standard device, if the dynamic security risk value corresponding to a certain device is within the dynamic security risk value interval corresponding to the standard device, it is evaluated that the device does not have a security risk, if the dynamic security risk value corresponding to a certain device is not within the dynamic security risk value interval corresponding to the standard device, it is evaluated that the device has a security risk.

4. The safety hazard intelligent identification and early warning system based on the Internet of Things according to claim 3, characterized in that, The analysis of the security risk classification corresponding to each abnormal device is as follows: The dynamic security risk value corresponding to each abnormal device is compared with the dynamic security risk value interval corresponding to each security risk type in the database, if the dynamic security risk value corresponding to a certain abnormal device is within the dynamic security risk value interval corresponding to a certain security risk type in the database, the security risk type in the database is recorded as the security risk type corresponding to the abnormal device; The security risk type includes physical carrier layer risk, logical target layer risk and system constraint layer risk.

5. The safety hazard intelligent identification and early warning system based on the Internet of Things according to claim 4, characterized in that, The adaptive response strategy analysis of each abnormal device is as follows: B1, if the security risk type corresponding to a certain abnormal device is a physical carrier layer risk, a quantum barrier and hierarchical hardware fuse defense strategy is executed; B2, if the security risk type corresponding to a certain abnormal device is a logical target layer risk, a semantic rectification and dynamic causal firewall strategy is executed; B3, if the security risk type corresponding to a certain abnormal device is a system constraint layer risk, an intelligent resilience scheduling and multi-dimensional ethical injection control strategy is executed.

6. The safety hazard intelligent identification and early warning system based on the Internet of Things according to claim 1, characterized in that, The prediction of the cross-device risk diffusion level corresponding to each abnormal device is as follows: The adjacent device risk transmission coefficient corresponding to each abnormal device is compared with the adjacent device risk transmission coefficient interval corresponding to each cross-device risk diffusion level set, if the adjacent device risk transmission coefficient corresponding to a certain abnormal device is within the adjacent device risk transmission coefficient interval corresponding to a certain cross-device risk diffusion level set, the cross-device risk diffusion level set is taken as the cross-device risk diffusion level corresponding to the abnormal device; The cross-device risk diffusion level includes low diffusion risk, medium diffusion risk and high diffusion risk.

7. The safety hazard intelligent identification and early warning system based on the Internet of Things according to claim 6, characterized in that, The analysis of the neighborhood immunity strategy corresponding to the adjacent device of each abnormal device is as follows: C1, if the cross-device risk diffusion level corresponding to the abnormal device is low diffusion risk, then the adjacent device of the abnormal device is executed with the reinforcement monitoring and basic protection strategy; C2, if the cross-device risk diffusion level corresponding to the abnormal device is medium diffusion risk, then the adjacent device of the abnormal device is executed with the dynamic isolation and cooperative defense strategy; C3, if the cross-device risk diffusion level corresponding to the abnormal device is high diffusion risk, then the adjacent device of the abnormal device is executed with the emergency blocking and global reconstruction strategy.

Citation Information

Patent Citations

  • Personalized precise maintenance strategy based on substation equipment operation situation perception analysis

    CN115809941A

  • Security protection system for Internet of Things equipment

    CN118921218A

  • Ai-controlled sensor network for threat mapping and characterization and risk adjusted response

    US20250175456A1