Mass data cross-security domain transmission high-low priority queue hierarchical scheduling method based on Internet of Things equipment

Through the data packet classification, independent transmission channel design and dynamic weight distribution algorithm of edge computing nodes, combined with blockchain encryption watermark technology, the timeliness, security and flexibility issues in cross-security domain data transmission in the Internet of Things are solved, and efficient and reliable data transmission is achieved.

CN120750876APending Publication Date: 2025-10-03GUANGZHOU KETENG INFORMATION TECH
View PDF 0 Cites 6 Cited by

Patent Information

Application Number
CN202510782182.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

The existing cross-security domain data transmission technology of the Internet of Things has problems in insufficient timeliness guarantee, the trade-off between security and efficiency, and insufficient dynamic scheduling flexibility, which affects the real-time and security of the system.

Method used

It adopts packet classification based on edge computing nodes, independent transmission channel design, dynamic weight allocation algorithm and blockchain encryption watermark technology, combined with preemptive transmission mechanism and bandwidth compensation mechanism, and dynamically adjusts queue scheduling strategy to improve key data transmission efficiency and system adaptability.

Benefits of technology

It improves the efficiency and reliability of data transmission across security domains of IoT devices, enhances the system's adaptability, and is suitable for various application scenarios in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750876A_ABST
    Figure CN120750876A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of Internet of Things data transmission, in particular to a mass data cross-security domain transmission high-low priority queue hierarchical scheduling method based on Internet of Things equipment, which comprises edge computing node classification, independent channel design, a dynamic weight distribution algorithm and a block chain encryption watermark technology. The timeliness is improved through a preemptive and compensation mechanism, and the reliability is enhanced in combination with queue degradation protection and a dynamic adjustment strategy. The method can effectively solve the problems that timeliness is insufficient and safety and efficiency are difficult to balance in a traditional method, the key data transmission efficiency and the system self-adaptive capacity are remarkably improved in a complex network environment, and the method has wide application prospects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of Internet of Things data transmission and network security, and specifically relates to a hierarchical scheduling method for high- and low-priority queues for the cross-security domain transmission of massive data based on Internet of Things devices. Background Art

[0002] In scenarios where IoT devices transmit massive amounts of data across security domains, efficient hierarchical data scheduling and security assurance can be achieved through the collaborative work of edge computing nodes and distributed transmission channels. The performance of hierarchical scheduling relies heavily on the accurate classification of data priority and security level. Traditional methods consume significant computing resources for data transmission prioritization and scheduling strategies, especially in multi-security domain environments, where system performance is significantly affected by factors such as timeliness, load status, and security. Therefore, the existing technology requires a dynamic scheduling method that comprehensively considers multiple factors to improve the efficiency and reliability of cross-security domain data transmission.

[0003] Hierarchical scheduling based on high- and low-priority queues is an emerging solution for IoT data transmission. By prioritizing packets and assigning them independent transmission channels, this approach significantly reduces the transmission latency of high-priority data. Furthermore, by integrating core technologies such as blockchain-based encrypted watermarking and dynamic weight allocation, it achieves a good balance between transmission efficiency and security. This technology enables rapid processing of critical data in complex network environments through preemptive transmission mechanisms and bandwidth compensation, while effectively addressing external environmental impacts such as anomalies in the target security domain.

[0004] Existing IoT cross-security domain data transmission technologies face the following major issues in hierarchical scheduling:

[0005] Insufficient timeliness guarantee: There is a problem of timeliness degradation during data transmission. Especially in high-load environments, low-priority queues may occupy bandwidth resources for a long time, resulting in increased latency for high-priority data, which in turn affects the real-time performance of the entire system.

[0006] The trade-off between security and efficiency: Traditional encryption technologies increase transmission overhead while ensuring data security. However, simplifying the encryption process can increase the risk of data leakage. Finding a balance between security and transmission efficiency is a challenge.

[0007] Insufficient flexibility in dynamic scheduling: The weight allocation algorithms in existing technologies are usually based on fixed parameters, making it difficult to dynamically adjust the scheduling strategy according to real-time load status and data characteristics, thereby limiting the system's adaptability.

[0008] This invention introduces a dynamic weight distribution algorithm and blockchain encryption watermark technology to improve the hierarchical scheduling method and apply it to the cross-security domain data transmission scenario of the Internet of Things, achieving the goal of improving the efficiency of key data transmission under complex network conditions while enhancing the security and adaptability of the system. It is an effective method with broad application prospects. Summary of the Invention

[0009] The technical problem to be solved by the present invention is to overcome the shortcomings of the existing technology and provide a hierarchical scheduling method for high and low priority queues for the transmission of massive data across security domains based on Internet of Things devices.

[0010] In order to solve the above technical problems, the basic concept of the technical solution adopted by the present invention is:

[0011] A hierarchical scheduling method for high- and low-priority queues for cross-security domain transmission of massive data based on Internet of Things devices includes the following steps:

[0012] Step S1: Classify the data packets collected by IoT devices by security level and service priority through edge computing nodes, and generate high priority queues and low priority queues;

[0013] Step S2: Establish independent data transmission channels for different security domains, each channel including a high-priority transmission sub-channel and a low-priority transmission sub-channel;

[0014] Step S3: Calculate the transmission scheduling weight value of each queue using a dynamic weight allocation algorithm. The weight calculation parameters include: data timeliness index, target security domain load status, and data packet security level coefficient.

[0015] Step S4: construct a cross-domain transmission credential based on blockchain technology and embed a verifiable encrypted watermark in the data packet header;

[0016] Step S5: When performing cross-security domain transmission, the high-priority queue adopts a preemptive transmission mechanism, and the low-priority queue adopts a bandwidth idle period compensation transmission mechanism;

[0017] Step S6: Dynamically adjust the queue scheduling strategy through the transmission quality feedback module, and automatically trigger the queue degradation protection mechanism when an abnormality in the target security domain is detected.

[0018] Preferably, the step S1 specifically includes:

[0019] First, we define packet classification criteria, including whether the packet is a real-time control command or security alarm, the credibility of the data source device, and the user privacy level tag associated with the data content. Data packets containing real-time control commands or security alarms are directly assigned to the high-priority queue. For other packets, their priority is further assessed based on their credibility rating and privacy level tag.

[0020] Next, the edge computing node analyzes the packet's timestamp, source device identifier, and data content structure to extract feature information. This information is then fed into a classification model to generate high- and low-priority queues. The classification model is trained using a machine learning algorithm and uses priority labels from historical data to ensure accurate classification results.

[0021] Finally, the generated high-priority queue and low-priority queue are stored in independent queue buffers respectively. The buffer adopts a ring queue structure to support dynamic expansion and fast access.

[0022] Preferably, the step S2 specifically includes:

[0023] First, an independent data transmission channel is designed for each security domain. The channel consists of a physical layer link and a logical layer protocol. The physical layer link uses fiber optic communication technology, and the logical layer protocol is implemented based on the TCP / IP protocol stack extension to ensure the stability and reliability of the channel.

[0024] Secondly, each channel is divided into high-priority and low-priority transmission sub-channels. The high-priority transmission sub-channel uses SRv6 programmable routing technology, with a reserved bandwidth of no less than 30% of the total bandwidth and a maximum transmission delay of no more than 50ms. The low-priority transmission sub-channel uses a dynamic bandwidth allocation mechanism to adjust bandwidth resource allocation based on real-time load status.

[0025] Finally, high-priority sub-channels and low-priority sub-channels are integrated into the same physical link through multiplexing technology, and channel coding technology is used to reduce interference and bit error rate.

[0026] Preferably, the step S3 specifically includes:

[0027] First, the core formula of the dynamic weight allocation algorithm is defined as follows:

[0028] W i =α·T i +β·(1-L d )+γ·S i

[0029] Among them, W i is the weight value of the i-th queue, T i is the time-dependent attenuation factor, L d is the current load rate of the target domain, S i is the safety level coefficient, α, β, γ are dynamic adjustment parameters;

[0030] Secondly, the time-effect attenuation factor T i Calculated by the following formula:

[0031] T i =e -λt

[0032] Where λ is the decay rate constant, and t is the waiting time after the data packet enters the queue;

[0033] Then, the current load rate of the target domain L d It is calculated by monitoring the real-time traffic and resource utilization of the target security zone. The specific formula is as follows:

[0034]

[0035] Among them, C used is the amount of resources used by the target domain, C total is the total resources of the target domain;

[0036] Finally, the security level coefficient Si is assigned according to the security level label of the data packet, and the range is [0,1].

[0037] Preferably, the step S4 specifically includes:

[0038] First, a cross-domain transmission credential is constructed based on blockchain technology. The credential contains the data packet’s unique identifier, timestamp, sender and receiver addresses, and an encrypted watermark. The encrypted watermark is generated using a hash function to ensure the integrity and immutability of the data packet.

[0039] Secondly, an encrypted watermark is embedded in the packet header. The watermark is generated using an asymmetric encryption algorithm, with the public key used for encryption and the private key used for decryption. The specific embedding location is a reserved field in the packet header, which is 128 bits long.

[0040] Finally, the validity of cross-domain transmission credentials is verified through smart contracts. Smart contracts are deployed in the blockchain network and support multi-party consensus mechanisms to ensure the credibility of the credentials.

[0041] Preferably, the step S5 specifically includes:

[0042] First, the high-priority queue adopts a preemptive transmission mechanism, which includes the following steps:

[0043] Establish a dual-channel priority arbiter to compare the delay thresholds of high- and low-priority queues in real time;

[0044] When the delay of the high-priority queue exceeds the preset threshold, the transmission of the low-priority queue is automatically suspended;

[0045] After bandwidth resources are released, the backlog data processing of the high-priority queue is resumed first.

[0046] Secondly, the low-priority queue adopts the bandwidth idle period compensation transmission mechanism, which includes the following steps:

[0047] Monitor bandwidth usage of high-priority subchannels and identify idle periods;

[0048] Dynamically allocate bandwidth resources to low-priority queues during idle periods;

[0049] Traffic shaping technology is used to optimize the transmission efficiency of low-priority queues and prevent burst traffic from interfering with high-priority queues.

[0050] Preferably, the step S6 specifically includes:

[0051] First, the real-time status information of the target security domain is collected through the transmission quality feedback module, including indicators such as packet loss rate, delay and throughput.

[0052] Secondly, when an anomaly in the target security zone is detected, the queue degradation protection mechanism is automatically triggered, which includes the following steps:

[0053] Temporarily transfer high-priority queue data to fog computing nodes, which use a distributed storage architecture to support fast read and write operations;

[0054] Activate the data compression engine for lossless compression. The compression algorithm is based on dictionary encoding technology to ensure data integrity.

[0055] Automatically strip non-critical metadata when degraded transfer mode is triggered to reduce transfer overhead.

[0056] Finally, system performance is optimized by dynamically adjusting the threshold parameters in the queue classification policy. This includes the following steps:

[0057] Collect transmission quality indicators of each security domain to form a training data set;

[0058] Update the weight distribution model parameters based on the federated learning algorithm to improve model accuracy while protecting data privacy;

[0059] Dynamically adjust the threshold parameters in the queue classification strategy based on the updated model parameters.

[0060] Therefore, the present invention adopts the above-mentioned high- and low-priority queue scheduling method for the cross-security domain transmission of massive data based on IoT devices. Through edge computing node classification, independent channel design, dynamic weight allocation algorithm, and blockchain encryption watermarking technology, it improves the transmission efficiency of key data and the system's adaptability. At the same time, through preemptive transmission mechanism and bandwidth compensation mechanism, it effectively addresses the timeliness issue in high-load environments. Combined with the queue degradation protection mechanism and dynamic adjustment strategy, it enhances the reliability and security of the system, making it a technical solution with broad application prospects. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] The drawings described below are only some embodiments. A person skilled in the art can derive other drawings based on these drawings without inventive effort. In the drawings:

[0062] Figure 1 This is a flow chart of a method for hierarchical scheduling of high and low priority queues for transmitting massive data across security domains based on IoT devices according to the present invention;

[0063] It should be noted that these drawings and textual descriptions are not intended to limit the conceptual scope of the present invention in any way, but rather to illustrate the concept of the present invention for those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION

[0064] The present invention will now be described in further detail with reference to the accompanying drawings.

[0065] See also Figure 1 As shown, in this embodiment, a method for hierarchical scheduling of high and low priority queues for transmitting massive data across security domains based on IoT devices is provided, including the following steps:

[0066] First, the packet classification module is responsible for classifying packets collected by IoT devices and generating high-priority and low-priority queues. The packet classification module is directly connected to the edge computing node and receives data streams from IoT devices. During the classification process, the module first determines whether the packet is a real-time control instruction or security alert based on predefined classification criteria. If so, it is directly assigned to the high-priority queue. Otherwise, the module further analyzes the packet's timestamp, source device identifier, and data content structure, and inputs the extracted features into a classification model. This classification model is trained using a machine learning algorithm and uses priority labels from historical data to ensure accurate classification results. After classification, the high-priority and low-priority queues are stored in separate circular queue buffers, supporting dynamic expansion and fast access. Data is transferred between the packet classification module and the high-priority and low-priority queues via memory mapping, ensuring that classified data is quickly entered into the corresponding queues.

[0067] Secondly, the design of independent transmission channels is an important part of the present invention, which is used to achieve efficient data transmission between different security domains. Each security domain is equipped with an independent physical layer link and logical layer protocol, wherein the physical layer link adopts optical fiber communication technology, and the logical layer protocol is implemented based on the TCP / IP protocol stack extension. The independent transmission channel is further divided into high-priority transmission sub-channels and low-priority transmission sub-channels. The high-priority transmission sub-channel adopts SRv6 programmable routing technology, with a reserved bandwidth of not less than 30% of the total bandwidth and a maximum transmission delay of not more than 50ms; the low-priority transmission sub-channel adopts a dynamic bandwidth allocation mechanism to adjust bandwidth resource allocation according to the real-time load status. Through multiplexing technology, high-priority sub-channels and low-priority sub-channels are integrated into the same physical link, and channel coding technology is used to reduce interference and bit error rate. The independent transmission channel is connected to the data packet classification module through a network interface card to ensure that the classified data can smoothly enter the corresponding transmission sub-channel.

[0068] Next, the dynamic weight allocation module is responsible for calculating the transmission scheduling weight value of each queue to implement a flexible queue scheduling strategy. The core formula of the dynamic weight allocation module is W i =α·T i +β·(1-L d )+γ·S i

[0069] Among them, W i is the weight value of the i-th queue, T i is the time-dependent attenuation factor, L d is the current load rate of the target domain, S i is the safety level coefficient, α, β, γ are dynamic adjustment parameters;

[0070] Secondly, the time-effect attenuation factor T i Calculated by the following formula:

[0071] T i =e -λt

[0072] Where λ is the decay rate constant, and t is the waiting time after the data packet enters the queue;

[0073] Then, the current load rate of the target domain L d It is calculated by monitoring the real-time traffic and resource utilization of the target security zone. The specific formula is as follows:

[0074]

[0075] Among them, C used is the amount of resources used by the target domain, C total is the total resources of the target domain;

[0076] Finally, the security level coefficient Si is assigned a value based on the packet's security level label, ranging from [0 to 1]. The dynamic weight allocation module is connected to the independent transmission channel via a high-speed data bus. It obtains the status information of each queue in real time and outputs the weight value to guide subsequent transmission scheduling.

[0077] The blockchain encrypted watermark module then constructs a cross-domain transmission credential and embeds the encrypted watermark in the data packet header. This module first generates a cross-domain transmission credential containing the data packet's unique identifier, timestamp, sender and receiver addresses, and the encrypted watermark. The encrypted watermark is generated using a hash function to ensure the integrity and immutability of the data packet. Embedding the encrypted watermark in the data packet header utilizes an asymmetric encryption algorithm, using a public key for encryption and a private key for decryption. The watermark is embedded in a reserved 128-bit field in the data packet header. The blockchain encrypted watermark module connects to the smart contract verification module via the blockchain network. The smart contract verification module is deployed within the blockchain network and supports a multi-party consensus mechanism to ensure the credibility of the credential. The blockchain encrypted watermark module is connected to an independent transmission channel via a dedicated interface, ensuring the encrypted watermark is accurately embedded and transmitted along with the data packet.

[0078] When performing cross-security domain transmission, the preemptive transmission mechanism and bandwidth compensation mechanism are responsible for transmission scheduling for high-priority queues and low-priority queues, respectively. The preemptive transmission mechanism establishes a dual-channel priority arbiter that compares the latency thresholds of the high- and low-priority queues in real time. When the latency of the high-priority queue exceeds the preset threshold, the transmission of the low-priority queue is automatically suspended, and the processing of the backlog of data in the high-priority queue is prioritized and resumed after bandwidth resources are released. The bandwidth compensation mechanism monitors the bandwidth usage of the high-priority sub-channel, identifies idle periods, and dynamically allocates bandwidth resources to the low-priority queue. Traffic shaping technology is used to optimize the transmission efficiency of the low-priority queue and prevent sudden traffic from interfering with the high-priority queue. The preemptive transmission mechanism and bandwidth compensation mechanism are connected to the independent transmission channels via signal control lines to ensure that scheduling instructions are transmitted and executed in a timely manner.

[0079] Finally, the queue degradation protection module and the transmission quality feedback module jointly ensure the system's reliability and adaptability. The transmission quality feedback module is responsible for collecting real-time status information of the target security domain, including metrics such as packet loss rate, latency, and throughput. When an anomaly in the target security domain is detected, the queue degradation protection module automatically triggers the queue degradation protection mechanism. Specifically, data from high-priority queues is temporarily transferred to fog computing nodes, which utilize a distributed storage architecture to support fast read and write operations. Simultaneously, the data compression engine is activated for lossless compression, using a dictionary encoding algorithm to ensure data integrity. When the degraded transmission mode is triggered, non-critical metadata is automatically stripped to reduce transmission overhead. Furthermore, system performance is optimized by dynamically adjusting the threshold parameters in the queue classification policy. This involves collecting transmission quality metrics from each security domain to form a training dataset, updating the weight allocation model parameters based on a federated learning algorithm to improve model accuracy while protecting data privacy, and dynamically adjusting the threshold parameters in the queue classification policy based on the updated model parameters. The queue degradation protection module and the transmission quality feedback module are connected to the dynamic weight allocation module via an internal communication bus, ensuring timely transmission of feedback information and its use in adjusting the scheduling policy.

[0080] The above describes the specific implementation of the present invention in detail, covering the complete process from data packet classification to cross-domain transmission, and Figure 1 Through the above implementation, the present invention realizes the high efficiency, security and adaptability of the cross-security domain transmission of massive data of IoT devices, and is applicable to various application scenarios in complex network environments.

[0081] In order to better enable relevant personnel in this technical field to fully understand and implement the present invention, the implementation principle of the present invention is supplemented below with reference to specific application scenarios.

[0082] In a practical application of a smart city, assume that IoT devices are deployed in traffic monitoring, environmental monitoring, and public safety warning systems. The data generated by these devices needs to be uploaded to servers in different security domains via edge computing nodes for processing and storage. To ensure efficient and secure cross-domain data transmission, the specific implementation steps of this invention are as follows.

[0083] First, the packet classification module begins operation by receiving data streams from IoT devices and determining whether the packets are real-time control instructions or security alerts based on predefined classification criteria. If a packet is identified as one of these types, it is directly assigned to a high-priority queue. Otherwise, the module further analyzes its timestamp, source device identifier, and data content structure. Packets are prioritized by extracting feature information and inputting it into a classification model trained using a machine learning algorithm. After classification, the high-priority and low-priority queues are stored in separate circular queue buffers, enabling dynamic expansion and fast access. Using memory mapping, the packet classification module quickly transfers the classified data to the corresponding queue, paving the way for subsequent transmission.

[0084] Secondly, in the design of independent transmission channels, each security domain is equipped with independent physical layer links and logical layer protocols. The physical layer links utilize fiber-optic communication technology, and the logical layer protocols are implemented based on an extension of the TCP / IP protocol stack. Independent transmission channels are further divided into high-priority and low-priority transmission subchannels. The high-priority transmission subchannel utilizes SRv6 programmable routing technology, with a reserved bandwidth of no less than 30% of the total bandwidth and a maximum transmission latency of no more than 50ms. The low-priority transmission subchannel uses a dynamic bandwidth allocation mechanism to adjust resource allocation based on real-time load conditions. Multiplexing technology integrates high- and low-priority subchannels onto the same physical link, while channel coding effectively reduces interference and bit error rates. A network interface card connects the packet classification module to the independent transmission channel, ensuring that classified data is smoothly routed to the corresponding transmission subchannel.

[0085] Next, the dynamic weight allocation module starts to calculate the transmission scheduling weight value of each queue. The core formula is W i =α·T i +β·(1-L d )+γ·S i

[0086] Among them, W i is the weight value of the i-th queue, T i is the time-dependent attenuation factor, L d is the current load rate of the target domain, S i is the safety level coefficient, α, β, γ are dynamic adjustment parameters;

[0087] Secondly, the time-effect attenuation factor T i Calculated by the following formula:

[0088] T i =e -λt

[0089] Where λ is the decay rate constant, and t is the waiting time after the data packet enters the queue;

[0090] Then, the current load rate of the target domain L d It is calculated by monitoring the real-time traffic and resource utilization of the target security zone. The specific formula is as follows:

[0091]

[0092] Among them, C used is the amount of resources used by the target domain, C total is the total resources of the target domain;

[0093] Finally, the security level coefficient Si is assigned a value based on the security level label of the data packet, ranging from [0, 1]. The dynamic weight allocation module is connected to the independent transmission channel via a high-speed data bus, obtains the status information of each queue in real time, and outputs the weight value to guide subsequent transmission scheduling.

[0094] The blockchain encrypted watermark module then activates, generating a cross-domain transmission credential containing the data packet's unique identifier, timestamp, sender and receiver addresses, and an encrypted watermark. This encrypted watermark is generated using a hash function to ensure the integrity and immutability of the data packet. The encrypted watermark is embedded using an asymmetric encryption algorithm, with a public key for encryption and a private key for decryption. The watermark is embedded in a reserved 128-bit field in the data packet header. The smart contract verification module, deployed within the blockchain network, supports a multi-party consensus mechanism to ensure the credibility of the credential. A dedicated interface connects the blockchain encrypted watermark module to an independent transmission channel, ensuring the encrypted watermark is accurately embedded and transmitted along with the data packet.

[0095] When performing cross-security domain transmission, the preemptive transmission mechanism and bandwidth compensation mechanism are responsible for transmission scheduling for high-priority queues and low-priority queues, respectively. The preemptive transmission mechanism establishes a dual-channel priority arbiter, comparing the latency thresholds of the high- and low-priority queues in real time. When the latency of the high-priority queue exceeds the preset threshold, the transmission of the low-priority queue is automatically suspended, and the processing of the backlog of data in the high-priority queue is prioritized and resumed after bandwidth resources are released. The bandwidth compensation mechanism monitors the bandwidth usage of the high-priority sub-channel, identifies idle periods, and dynamically allocates bandwidth resources to the low-priority queue. Traffic shaping technology optimizes the transmission efficiency of the low-priority queue and prevents bursts from interfering with the high-priority queue. Signal control lines connect the preemptive transmission mechanism and bandwidth compensation mechanism to independent transmission channels, ensuring that scheduling instructions are delivered and executed in a timely manner.

[0096] Finally, when the transmission quality feedback module detects an anomaly in the target security domain, the queue degradation protection module automatically triggers the queue degradation protection mechanism. Data from high-priority queues is temporarily transferred to fog computing nodes, which utilize a distributed storage architecture to support fast read and write operations. Simultaneously, the data compression engine is activated for lossless compression, using a dictionary encoding algorithm to ensure data integrity. When the degraded transmission mode is triggered, non-critical metadata is automatically stripped to reduce transmission overhead. Furthermore, a training dataset is formed by collecting transmission quality indicators from each security domain. The weight allocation model parameters are updated based on a federated learning algorithm, improving model accuracy while protecting data privacy. The threshold parameters in the queue classification strategy are dynamically adjusted based on the updated model parameters. An internal communication bus connects the queue degradation protection module, the transmission quality feedback module, and the dynamic weight allocation module, ensuring that feedback information is delivered promptly and used to adjust the scheduling strategy.

[0097] Through the above steps, the present invention realizes the high efficiency, security and adaptability of the cross-security domain transmission of massive data of IoT devices. In the smart city scenario, traffic monitoring data, environmental monitoring data and public safety warning data can be classified according to priority and efficiently transmitted to the corresponding security domain server, ensuring the real-time, reliability and security of the system.

[0098] The present invention is not limited to the above-described embodiments. Any structural changes made under the guidance of the present invention, which have the same or similar technical solutions as the present invention, should be understood to fall within the scope of protection of the present invention. The technologies, shapes, and structural parts not described in detail in the present invention are all well-known technologies.

Claims

1. A hierarchical scheduling method for high and low priority queues for massive data transmission across security domains based on IoT devices, characterized in that: The following steps are involved: Step S1: Classify the data packets collected by IoT devices by security level and service priority through edge computing nodes, and generate high priority queues and low priority queues; Step S2: Establish independent data transmission channels for different security domains, each channel including a high-priority transmission sub-channel and a low-priority transmission sub-channel; Step S3: Calculate the transmission scheduling weight value of each queue using a dynamic weight allocation algorithm. The weight calculation parameters include data timeliness index, target security domain load status, and data packet security level coefficient. Step S4: construct a cross-domain transmission credential based on blockchain technology and embed a verifiable encrypted watermark in the data packet header; Step S5: When performing cross-security domain transmission, the high-priority queue adopts a preemptive transmission mechanism, and the low-priority queue adopts a bandwidth idle period compensation transmission mechanism; Step S6: Dynamically adjust the queue scheduling strategy through the transmission quality feedback module, and automatically trigger the queue degradation protection mechanism when an abnormality in the target security domain is detected.

2. According to claim 1, a method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on Internet of Things devices is characterized in that: The step S1 specifically includes: First, data packet classification criteria are defined, including whether the packet type is a real-time control command or security alarm information, the credibility rating of the data source device, and the user privacy level label associated with the data content. Data packets containing real-time control commands or security alarm information are directly classified into a high-priority queue. For other data packets, their priority is further assessed based on their credibility rating and privacy level label. Second, the edge computing node analyzes the data packet's timestamp, source device identifier, and data content structure, extracts feature information, and inputs it into a classification model to generate high-priority and low-priority queues. The classification model is trained using a machine learning algorithm and uses priority labels from historical data as labels. Finally, the generated high-priority queue and low-priority queue are stored in independent ring queue buffers, supporting dynamic expansion and fast access.

3. The method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 1 is characterized in that: The step S2 specifically includes: First, an independent data transmission channel is designed for each security domain. The channel consists of a physical layer link and a logical layer protocol. The physical layer link uses optical fiber communication technology, and the logical layer protocol is implemented based on the TCP / IP protocol stack extension. Secondly, each channel is divided into high-priority transmission sub-channels and low-priority transmission sub-channels. The high-priority transmission sub-channel uses SRv6 programmable routing technology, with a reserved bandwidth of no less than 30% of the total bandwidth and a maximum transmission delay of no more than 50ms. The low-priority transmission sub-channel uses a dynamic bandwidth allocation mechanism to adjust bandwidth resource allocation based on real-time load status. Finally, high-priority sub-channels and low-priority sub-channels are integrated into the same physical link through multiplexing technology, and channel coding technology is used to reduce interference and bit error rate.

4. The method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 1 is characterized in that: The step S3 specifically includes: First, the core formula of the dynamic weight allocation algorithm is defined as follows: W i =α·T i +β·(1-L d )+γ·S i Among them, W i is the weight value of the i-th queue, T i is the time-dependent attenuation factor, L d is the current load rate of the target domain, S i is the safety level coefficient, α, β, γ are dynamic adjustment parameters; Secondly, the time-effect attenuation factor T i Calculated by the following formula: T i =e -λt Where λ is the decay rate constant, and t is the waiting time after the data packet enters the queue; Then, the current load rate of the target domain L d It is calculated by monitoring the real-time traffic and resource utilization of the target security zone. The specific formula is as follows: Among them, C used is the amount of resources used by the target domain, C total is the total resources of the target domain; Finally, the security level coefficient Si is assigned according to the security level label of the data packet, and the range is [0,1].

5. The method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 1 is characterized in that: The step S4 specifically includes: First, a cross-domain transmission credential is constructed based on blockchain technology. The credential contains the unique identifier of the data packet, timestamp, sender and receiver addresses, and an encrypted watermark. The encrypted watermark is generated through a hash function. Secondly, an encrypted watermark is embedded in the data packet header. The watermark is generated using an asymmetric encryption algorithm. The public key is used for encryption and the private key is used for decryption. The specific embedding position is the reserved field in the data packet header, and the field length is 128 bits. Finally, the validity of cross-domain transmission credentials is verified through smart contracts, which are deployed in the blockchain network and support multi-party consensus mechanism.

6. A hierarchical scheduling method for high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 1, characterized in that: The step S5 specifically includes: First, the high-priority queue adopts a preemptive transmission mechanism, which includes the following steps: A dual-channel priority arbiter is established to compare the latency thresholds of high- and low-priority queues in real time. When the latency of the high-priority queue exceeds the preset threshold, the transmission of the low-priority queue is automatically suspended. After bandwidth resources are released, the backlog data processing of the high-priority queue is resumed first. Secondly, the low-priority queue adopts the bandwidth idle period compensation transmission mechanism, which includes the following steps: Monitor bandwidth usage of high-priority sub-channels and identify idle periods; dynamically allocate bandwidth resources to low-priority queues during idle periods; and optimize the transmission efficiency of low-priority queues through traffic shaping technology.

7. The method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 1 is characterized in that: The step S6 specifically includes: First, the transmission quality feedback module collects real-time status information of the target security domain, including packet loss rate, delay, and throughput; Secondly, when an anomaly in the target security zone is detected, the queue degradation protection mechanism is automatically triggered, which includes the following steps: Temporarily transfer high-priority queue data to fog computing nodes, which use a distributed storage architecture. Activate the data compression engine for lossless compression, using a dictionary encoding algorithm. Automatically strip non-critical metadata when degraded transmission mode is triggered. Finally, system performance is optimized by dynamically adjusting the threshold parameters in the queue classification policy. This includes the following steps: The transmission quality indicators of each security domain are collected to form a training data set; the weight distribution model parameters are updated based on the federated learning algorithm; and the threshold parameters in the queue classification strategy are dynamically adjusted according to the updated model parameters.

8. The method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 2 is characterized in that: The classification model is trained based on the support vector machine algorithm or the random forest algorithm, and the priority annotations in the historical data are used as labels to ensure the accuracy of the classification results.

9. The method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 3 is characterized in that: The maximum transmission delay of the high-priority transmission sub-channel is 50ms, and the dynamic bandwidth allocation mechanism of the low-priority transmission sub-channel adjusts the bandwidth resource allocation ratio according to the real-time load status.

10. The method for hierarchical scheduling of high and low priority queues for mass data transmission across security domains based on IoT devices according to claim 1, characterized in that: The encrypted watermark is generated by the SHA-256 hash function, and the smart contract verification module is deployed in the blockchain network, supporting a multi-party consensus mechanism to ensure the credibility of the certificate.

Citation Information

Cited By

  • Channel scheduling and bandwidth allocation method, system and device for cloud desktop communication

    CN121357122A

  • Internet of Things data transmission method and device, electronic equipment and storage medium

    CN121509475A

  • Iot data transmission method and device, electronic equipment and storage medium

    CN121509475B

  • Distributed secure communication protocol data synchronization method and system

    CN121567454A

  • Data unvarnished transmission method and device of air conditioning system, electronic equipment and storage medium

    CN121644674A