A method for monitoring the security of a mobile communication device

By dividing mobile communication base stations into high-demand and low-demand areas and combining power supply fluctuation detection with synchronous analysis of communication quality, a differentiated response strategy was implemented. This solved the problem of homogenization of base station service coverage areas and communication failures caused by power supply fluctuations, achieving more efficient network resource management and communication quality assurance.

CN120751413BActive Publication Date: 2025-11-11ANHUI SINGLE POINT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511172071.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-21
Publication Date
2025-11-11
Estimated Expiration
2045-08-21

AI Technical Summary

Technical Problem

In existing technologies, the service coverage area of ​​mobile communication base stations is regarded as a homogeneous whole, lacking differentiation and assessment of the communication demand characteristics of different geographical units. This results in a lack of targeted and adaptive measures to deal with communication quality degradation. Furthermore, the power supply system status and communication quality are not deeply correlated, making it impossible to predict and respond to communication failures caused by power supply fluctuations in a timely manner.

Method used

By extracting communication traffic and service composition characteristics of geographic grids from historical communication logs, high-demand and low-demand areas are divided. Power supply fluctuations and communication quality are detected synchronously during the operation of communication base stations, and differentiated response strategies are implemented, such as user migration and service degradation. Combined with time-series correlation analysis, power supply fluctuations and communication quality are addressed in a coordinated manner.

Benefits of technology

It significantly improved the targeting of countermeasures and the efficiency of network resource utilization, ensuring the stability and continuity of the communication network and minimizing the impact of power supply anomalies on the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120751413B_ABST
    Figure CN120751413B_ABST
Patent Text Reader

Abstract

This invention belongs to the field of mobile communication equipment security monitoring technology, specifically disclosing a mobile communication equipment security monitoring method. This method divides the service coverage area of ​​a mobile communication base station into high-demand and low-demand communication areas based on communication traffic characteristics and service composition characteristics in historical communication logs. During base station operation, power supply fluctuations and communication quality are monitored simultaneously. When only communication quality degradation is detected, differentiated response strategies are implemented based on the affected area, making optimization measures more aligned with actual service load and user needs, significantly improving the targeting of responses and network resource utilization efficiency. When power supply fluctuations are detected, the resulting communication degradation is traced. If a temporal correlation exists between the two, battery power switching is triggered, ensuring the communication network is unaffected by power supply fluctuations. This suppresses fault propagation from the energy source, effectively guaranteeing communication continuity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of mobile communication equipment security monitoring technology, and particularly relates to mobile communication base station operation security monitoring technology, specifically disclosing a mobile communication equipment security monitoring method. Background Technology

[0002] As the core infrastructure of wireless communication networks, mobile communication base stations are primarily responsible for establishing and maintaining wireless connections between mobile terminals and the core network within their service coverage area to support voice calls, SMS services, and the transmission of various data services. To ensure operational security and stability during the continuous provision of communication services by base stations, communication quality monitoring is necessary to promptly identify potential problems, take countermeasures, and guarantee the stable operation of the communication network and the quality of user experience.

[0003] However, existing technologies for monitoring communication quality typically treat the service coverage area of ​​mobile communication base stations as a homogeneous whole, failing to effectively distinguish and assess the communication demand characteristics of different geographical units within the area. This results in response measures triggered when communication quality deteriorates often being pre-set, static, and global, lacking specificity and adaptability.

[0004] More critically, existing monitoring systems typically treat communication quality degradation and power supply system status as independent events, lacking in-depth analysis of the potential causal relationship between the two. Given that power supply is the fundamental energy guarantee for the normal operation of communication base stations, a power supply fluctuation can directly lead to base station equipment restarts, power amplifier performance degradation, or transmission interruptions, thereby triggering a chain reaction of communication quality degradation or even service outages. Without establishing a temporal correlation and root cause analysis mechanism between power supply fluctuations and communication degradation, the system cannot predict or respond promptly to communication failures caused by power supply anomalies. If the power supply problem becomes severe enough to paralyze base station functionality, it will directly cause regional outages of the local communication network. At this point, any optimization and adjustment strategies based on normal communication links will be ineffective, severely impacting network availability and user satisfaction. Summary of the Invention

[0005] Therefore, one objective of this application is to provide a mobile communication device security monitoring method that effectively solves the problems existing in the prior art by focusing on the partitioned response of the service coverage area when the communication quality deteriorates and the coordinated response of communication quality deterioration and power supply fluctuation.

[0006] The purpose of this invention can be achieved through the following technical solution: a mobile communication device security monitoring method, comprising the following steps: (1) extracting the communication traffic characteristics and service composition characteristics of each geographic grid from the historical communication logs of the mobile communication base station, and constructing a communication demand characteristic evaluation dataset.

[0007] (2) Based on the communication demand feature assessment dataset, the service coverage area of ​​the mobile communication base station is divided into gridded areas, and high-demand communication areas and low-demand communication areas are marked.

[0008] (3) Power supply fluctuation detection and communication quality degradation detection are performed simultaneously during the operation of the communication base station.

[0009] (4) Perform differentiated operations based on the test results:

[0010] (41) When only communication quality degradation is detected, focus on the communication degradation area and perform time-domain correlation analysis between communication user increment and communication quality degradation. If the judgment is that there is a correlation and it occurs in the high-demand communication area, trigger the migration of new users to the adjacent area. If the judgment is that there is a correlation and it occurs in the low-demand communication area, trigger the service bearer degradation.

[0011] (42) When power supply fluctuations are detected, track the subsequent changes in communication quality. If communication quality deterioration occurs after power supply fluctuations, switch to battery power supply.

[0012] Combining all the above technical solutions, the positive effects of this invention are as follows: 1. This invention divides the service coverage area of ​​mobile communication base stations into high-demand communication areas and low-demand communication areas based on the communication traffic characteristics and service composition characteristics in historical communication logs. When only communication quality degradation is detected, differentiated response strategies are implemented based on the area where it occurs, making optimization measures more in line with actual service load and user demand characteristics, and significantly improving the pertinence of response and network resource utilization efficiency.

[0013] 2. This invention synchronously monitors power supply fluctuations and communication quality during the operation of communication base stations. After detecting power supply fluctuations, it tracks the communication degradation caused by them. If there is a time correlation between the two, it triggers battery power switching. This realizes the time correlation between power supply fluctuations and communication quality degradation, and can take timely power switching based on this correlation. This ensures that the communication network is not affected by power supply fluctuations, suppresses fault propagation from the energy source, effectively ensures communication continuity, and minimizes the impact of power supply anomalies on network stability. Attached Figure Description

[0014] The present invention will be further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present invention. For those skilled in the art, other drawings can be obtained based on the following drawings without creative effort.

[0015] Figure 1 This is a diagram illustrating the implementation steps of the method of the present invention.

[0016] Figure 2This is a schematic diagram illustrating how the service coverage area of ​​a mobile communication base station is divided into a high-demand communication area and a low-demand communication area in this invention.

[0017] Figure 3 This is a flowchart illustrating the processing steps when only communication quality degradation is detected in this invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] See Figure 1 As shown, the present invention proposes a mobile communication device security monitoring method, which includes the following steps: (1) extracting the communication traffic characteristics and service composition characteristics of each geographic grid from the historical communication logs of the mobile communication base station, and constructing a communication demand characteristic evaluation dataset;

[0020] As a preferred implementation of the above steps, the service coverage area of ​​the mobile communication base station is divided into several regular geographical grids.

[0021] When applying the above scheme, the boundary outline of the service coverage area is first extracted when dividing the geographic grid. Then, the grid granularity is selected. Then, a regular rectangular grid is created within the minimum bounding rectangle of the service coverage area according to the selected grid granularity. Next, each generated grid is traversed to determine whether the center point of the grid is located inside the polygon of the service coverage area. Finally, only the grids located inside the coverage area are retained as the effective service grids of the base station.

[0022] It's important to understand that user communication needs within the service coverage area of ​​a mobile communication base station exhibit significant spatial heterogeneity. User density and service types vary greatly across different geographical locations, such as commercial centers, residential areas, and transportation hubs. Dividing a continuous coverage area into regular geographical grids enables pixel-level fine-grained management of communication needs, avoiding the coarse-grained analysis that treats the entire base station coverage area as a homogeneous region. This allows for the identification of demand hotspots and coldspots within the base station's coverage area.

[0023] Based on the geographic location information in the communication logs, each communication log is mapped to the corresponding geographic raster cell within a set monitoring period.

[0024] It should be noted that communication logs are data files automatically generated by base stations in mobile communication networks when user communication events occur, used to record in detail the user's communication behavior and network interaction process.

[0025] Communication logs typically contain the following key information: geographic location information, the start timestamp of the communication event, and communication traffic. The geographic location is used to determine the spatial location where the communication activity occurred, providing a basis for subsequent mapping to geographic raster cells.

[0026] The communication log records the start and end timestamps of communication events. The duration of the communication session can be obtained by calculating the difference between the two timestamps.

[0027] The communication log records the data traffic generated in this communication session, which is a key indicator for measuring user service consumption and network load.

[0028] It should also be noted that setting a monitoring period for collecting historical communication logs takes into account the dynamic and time-varying nature of communication demand within the base station's service coverage area. The load status of areas currently identified as high-demand may change in the future due to user movement, service fluctuations, or event-driven factors. The introduction of this monitoring period aims to establish a dynamic assessment and update mechanism for demand characteristics, ensuring that the area division results continuously reflect the current true service load distribution and preventing optimization strategies from becoming ineffective due to rigid partitioning. Specifically, the monitoring period can be set on a monthly basis.

[0029] Extract the communication duration and traffic data of a single communication session from the communication logs mapped to each grid, and calculate the communication traffic per unit time for each session.

[0030] For all communication sessions within each geographic raster, the communication duration of each session is used as a weight to perform a weighted average analysis of the communication traffic per unit time, thereby obtaining the communication traffic characteristic value of each geographic raster.

[0031] The above weighted average operation is specifically implemented as follows: for each geographic raster unit, calculate the total duration of all communication sessions within the monitoring period, and then use the proportion of the duration of each session to the total duration as the weight value of that session.

[0032] It's important to understand that using a weighted average based on communication duration, rather than a simple arithmetic average, when calculating regional communication traffic characteristics is based on an understanding of the nature of user behavior and network resource consumption. The resulting weighted average more accurately represents the average resource consumption intensity of the region during the monitoring period. If an arithmetic average were used, numerous short-lived, low-traffic sessions would dilute the statistical results, leading to a systematic underestimation of the true network load caused by long-duration sessions. The weighted average effectively corrects for this bias, making the characteristic values ​​more representative and objective, and truly reflecting the actual pressure on the network.

[0033] The communication access objects are extracted from the communication logs mapped to each grid, and it is identified whether the access objects belong to high-bandwidth services. Then, the proportion of communication sessions in each geographic grid whose communication access objects are identified as high-bandwidth services is calculated out of the total communication sessions in that grid as the service composition feature value of the geographic grid. This service feature value represents the high-bandwidth application penetration rate, which indicates the prevalence of high-bandwidth applications in the user service composition of that area.

[0034] It is important to clarify that the communication access object refers to the type of target service or application that a user connects to during communication activities. This object can correspond to high-bandwidth demand services, such as video streaming and high-definition video conferencing, which typically have stringent service quality requirements of high throughput, low latency, and high stability. It can also correspond to low-bandwidth demand services, such as instant messaging, web browsing, and email, which typically have lower data throughput and higher latency tolerance.

[0035] The communication traffic characteristics and service composition characteristics of all geographic rasters are structurally integrated to construct a communication demand characteristic assessment dataset.

[0036] Specifically, the communication demand characteristic assessment dataset uses geographic rasters as the basic record unit, with each row corresponding to one raster. The column fields include: raster identifier, communication traffic characteristic value, and service composition characteristic value.

[0037] It should be noted that after obtaining the communication traffic characteristics of geographic grids based on historical communication logs, further analysis of business composition characteristics is carried out because the assessment of communication needs not only depends on the traffic scale, but also needs to consider the inherent attributes of the business type. Communication traffic characteristics mainly reflect the quantity of resource consumption, while the penetration rate of high-bandwidth applications reflects the quality of business load. This allows for a three-dimensional and multi-faceted characterization of the communication needs of each geographic grid from the two key dimensions of quantity and quality.

[0038] See Figure 2 As shown, (2) the service coverage area of ​​mobile communication base stations is divided into gridded areas based on the communication demand feature assessment dataset, and high-demand communication areas and low-demand communication areas are marked.

[0039] As a specific implementation process of the above steps: Based on the communication demand characteristic assessment dataset, calculate the global arithmetic mean of the communication traffic characteristic value and the service composition characteristic value of all geographical grid cells, and use them as the regional communication traffic benchmark threshold and the regional service benchmark threshold.

[0040] It is important to understand that the aforementioned regional communication traffic benchmark threshold and regional service benchmark threshold are based on the global average level, which can objectively reflect the typical load level and regular service structure characteristics of the overall network. This method relies on actual operating data for dynamic calibration, effectively avoiding the subjective bias and insufficient scenario adaptability caused by manually preset thresholds, and improving the scientific nature, objectivity, and universality of threshold setting.

[0041] For each geographic grid, its own communication traffic characteristic value is compared with the regional communication traffic benchmark threshold, and the service composition characteristic value is compared with the regional service benchmark threshold.

[0042] If a geographic raster meets the following conditions: the communication traffic characteristic value is greater than the regional communication traffic baseline threshold and the service composition characteristic value is greater than the regional service baseline threshold, then the geographic raster is marked as a high communication demand point; otherwise, it is marked as a low communication demand point.

[0043] Based on the spatial adjacency of geographic rasters, connectivity analysis is performed on all rasters marked as high communication demand points. Spatially adjacent high communication demand points are aggregated into a continuous geographic region to form a high-demand communication region. Similarly, spatially adjacent low communication demand points are aggregated into a low-demand communication region.

[0044] It is important to understand that communication needs are usually not isolated, but rather appear in continuous geographical areas. The labeling results of a single grid are discrete, and spatial clustering is needed to integrate them into meaningful continuous areas. This is more in line with the distribution pattern of hotspots in the real world, such as a cluster of office buildings, and avoids fragmenting a continuous hotspot area into multiple isolated high-demand points.

[0045] This invention achieves the transformation from single-point feature analysis to spatial connectivity region division through the above process, effectively identifying hotspot areas with sustained high business demand and good communication quality, as well as areas with relatively low business demand or poor communication stability, providing a spatial decision-making basis for subsequent network resource optimization and dynamic management.

[0046] (3) Power supply fluctuation detection and communication quality degradation detection are performed simultaneously during the operation of the communication base station.

[0047] As an optional implementation of the above scheme, power supply fluctuation detection is performed as follows: during the operation of the mobile communication base station, the real-time effective value of the voltage and the power grid frequency are extracted from the power supply end.

[0048] In the above scheme, voltage and frequency are chosen as the core characterization parameters of power supply status because they are key physical quantities for evaluating the operational stability of the power system: the effective value of voltage mainly reflects the energy supply level and power quality of the power grid, and its fluctuations directly affect the normal operating voltage range of the equipment. Overvoltage or undervoltage may lead to a decrease in the performance of communication equipment or damage; the power grid frequency characterizes the supply and demand balance and dynamic stability of the system's active power, and its deviation will interfere with the clock synchronization mechanism inside the base station, affecting the accuracy of signal processing and transmission.

[0049] The voltage and frequency values ​​at the current moment are calculated by subtracting their corresponding values ​​from those at the previous moment, thus obtaining the voltage and frequency changes at the current moment.

[0050] It is important to understand that fluctuations in a power supply system are essentially rapid changes in voltage or frequency relative to their normal steady-state values. Directly comparing the current value with a fixed nominal value may produce false alarms due to fluctuations within the normal range. However, calculating the difference between adjacent time points can directly quantify the instantaneous rate of change of a physical quantity and is more sensitive to dynamic disturbances.

[0051] If the voltage change and frequency change at the current moment are both greater than the corresponding change limit, a power supply fluctuation is identified. Conversely, if only the voltage change or only the frequency change exceeds the threshold at the current moment, the voltage and frequency changes at multiple adjacent time points are continuously tracked from the current moment. If the corresponding changes at multiple adjacent time points continue to exceed the limit, a power supply fluctuation is identified.

[0052] In the implementation example of the above scheme, the number of consecutive over-limit time points, i.e. the number of adjacent over-limit sampling points required to determine effective power supply fluctuations, can be set according to actual needs.

[0053] The voltage and frequency variation limits mentioned above reflect the maximum allowable dynamic deviation range of the power system under normal operating conditions. They can be determined based on power supply quality standards (such as GB / T12325-2008 "Power Quality - Power Supply Voltage Deviation" and GB / T15945-2008 "Power Quality - Power System Frequency Deviation") to ensure that the detection mechanism complies with the power grid operation specifications and improves the accuracy and standardization of power supply anomaly identification.

[0054] The explanation of the above scheme states that when both voltage and frequency parameters undergo significant abrupt changes simultaneously, it is identified as a power supply fluctuation, which can effectively identify highly hazardous system-level severe disturbances. Such dual-parameter coordinated anomalies typically characterize a rapid deterioration in the power grid's operating state, exhibiting a clear causal relationship and high-risk characteristics. Therefore, they are given higher identification priority, improving the detection accuracy of sudden major events.

[0055] When a single parameter, such as voltage or frequency, momentarily exceeds its limit, a continuous time window tracking mechanism is activated. By monitoring the parameter change trends over multiple adjacent time points, it can effectively filter out transient, non-persistent disturbances caused by measurement noise, instantaneous spikes, or local interference. This mechanism not only significantly reduces the false alarm rate but also identifies chronic power quality degradation that changes relatively gradually but persists. Although such problems are not sudden, their long-term existence leads to decreased power module efficiency, equipment overheating, and accelerated component aging, indirectly causing base station performance instability or communication quality degradation, thus possessing significant early warning value.

[0056] By combining the above-mentioned strategy of instantaneous change detection with continuous change detection, fluctuation events occurring in the power supply system can be effectively identified, providing accurate timestamps and event evidence for subsequent analysis of the impact of power supply status on communication quality.

[0057] As a further optional implementation of the above solution, the communication quality degradation detection is performed as follows:

[0058] During the operation of a mobile communication base station, communication quality indicators are continuously collected from the network-side monitoring interface. Specifically, communication quality indicators can include packet loss rate, latency, jitter, etc.

[0059] The communication quality indicators at the current monitoring time are compared with the high bandwidth service tolerance threshold item by item. If any indicator exceeds the tolerance threshold, it is determined that communication quality has deteriorated at the current time.

[0060] It should be noted that high-bandwidth services have extremely strict quality of service requirements for network performance, and these requirements are usually defined by tolerance thresholds in explicit service level agreements or technical specifications.

[0061] It's important to understand that comparing real-time collected communication quality indicators with high-bandwidth service tolerance thresholds is necessary because high-bandwidth services, compared to non-high-bandwidth services, are more sensitive to network performance in terms of quality of service. This manifests in more stringent requirements for metrics such as latency, jitter, and packet loss rate. When any key indicator exceeds the tolerance threshold for this type of service, it means the network can no longer meet its basic transmission needs, resulting in a significant decline in user experience and potentially causing issues like video stuttering, audio interruptions, and blurry images. Therefore, using high-bandwidth service tolerance as a degradation criterion allows for proactive and highly sensitive identification of communication quality deterioration, providing the most direct and objective basis for assessment.

[0062] If all communication quality indicators do not exceed the tolerance threshold at the current moment, the changes in communication quality indicators are continuously tracked within a time window based on the current moment. If a downward trend is observed within this time window, communication quality degradation is identified.

[0063] Specifically, setting a time window based on the current moment and continuously tracking changes in communication quality indicators aims to ensure sufficient time-series data is accumulated within this window to support reliable analysis of performance degradation trends. The length of the time window can be flexibly configured according to the number of data points to be analyzed and the collection frequency of communication quality indicators. For trend analysis within the window, a linear regression method can be used to fit the collected data sequence and calculate its slope. Given that higher values ​​for key indicators such as packet loss rate, latency, and jitter indicate worse communication quality, a significantly positive regression slope or a monotonically increasing data sequence within the window indicates that communication quality is continuously declining.

[0064] It's important to understand that when communication quality indicators haven't yet exceeded the tolerance threshold for high-bandwidth services, continuously tracking their trends within a time window can identify gradual performance degradation in its early stages. This mechanism, based on trend analysis, enables predictive maintenance, providing early warnings when communication quality significantly declines but hasn't reached the hard alarm threshold. Maintenance personnel can then proactively intervene before a failure occurs, effectively preventing the gradual, insidious performance degradation that often occurs when relying solely on static thresholds.

[0065] (4) Perform differentiated operations based on the test results: see Figure 3 As shown, (41) when only communication quality degradation is detected, the focus is on the communication degradation area to perform time domain correlation analysis between communication user increment and quality degradation. If the judgment is that there is a correlation and it occurs in the high demand communication area, the user migration to the adjacent area is triggered. If the judgment is that there is a correlation and it occurs in the low demand communication area, the service bearer degradation operation is triggered.

[0066] As a way to achieve the above scheme, the following operations are performed to perform time-domain correlation analysis between communication user increment and communication quality degradation in the communication degradation area: When communication quality degradation occurs, the communication quality degradation area is focused on and the number of users accessing and communication quality indicators are collected synchronously in the subsequent continuous time window according to the sampling frequency of communication quality monitoring, starting from the timestamp of the communication quality degradation.

[0067] It should be noted that the number of users accessing the system mentioned above reflects the real-time active user load.

[0068] Based on the collected time-series data, with time as the horizontal axis and the number of users accessing the network and communication quality indicators as the vertical axes, corresponding curves for user load change and communication quality change are plotted.

[0069] By analyzing the slope of the user access volume change curve and the communication quality change curve point by point, several points where user access volume increases and several points where communication quality decreases are obtained respectively.

[0070] In the specific implementation of the above scheme, the identification of the user access volume increase point is as follows: the slope of the user access volume change curve at each sampling point is calculated by numerical differentiation, and the time point with a positive slope is marked as the user access volume increase point.

[0071] The specific identification of communication quality degradation points is as follows: calculate the slope of the communication quality change curve at each sampling point, identify the time points with positive slopes, and mark them as points of significant communication quality degradation.

[0072] It's important to explain that communication quality degradation is typically a dynamic process, and its root causes, such as a surge in users, also exhibit dynamic changes. Directly analyzing the absolute values ​​of raw user numbers and quality indicators, or their time series, can be affected by baseline levels, long-term trends, or periodic fluctuations. Analyzing their instantaneous rate of change—that is, focusing on the speed of change—can more directly and sensitively capture the key dynamics driving events.

[0073] All identified points of increased user access volume and decreased communication quality are sorted in ascending order according to their timestamps and assigned a sequence number. Points with the same sequence number are paired with points of decreased access volume to form a series of time-series matching point groups.

[0074] The above method, by identifying points of increased user access and points of decreased communication quality and pairing them chronologically, implicitly assumes that user growth events are precursors to quality degradation events. This pairing method forces the establishment of a temporal framework for event occurrence, making subsequent correlation analysis more consistent with the causal logic of user growth leading to quality degradation.

[0075] For each time-series matching point group, the slope value of the corresponding point on its respective curve is extracted. Then, the slope values ​​of all user access increase points are arranged in time order to form a user access growth intensity sequence, and the slope values ​​of all communication quality decrease points are arranged in time order to form a communication quality degradation intensity sequence.

[0076] The correlation coefficient is calculated between the user access growth intensity sequence and the communication quality degradation intensity sequence.

[0077] An example of applying the above operations is to quantify the dynamic relationship between the user access growth intensity sequence and the communication quality degradation intensity sequence in the time domain by calculating the Pearson correlation coefficient, thereby assessing their temporal correlation. The closer the value is to 1, the higher the temporal dynamic correlation between the rapid growth of user access and the accelerated degradation of communication quality, suggesting that user growth may be the main driving factor leading to quality degradation.

[0078] Furthermore, the correlation coefficient between the increase in communication users and the degradation of communication quality is compared with a critical threshold. If the critical threshold is reached or exceeded, a correlation is judged to exist; otherwise, no correlation exists.

[0079] The critical threshold for the correlation coefficient mentioned above reflects the sensitivity and confidence level required to the relationship between user growth and communication quality degradation. It is used to distinguish whether the correlation is due to random fluctuations or a genuine causal relationship. A higher threshold means that an association is considered to exist only when the correlation is very strong, thereby reducing the false alarm rate. Typically, the corresponding critical value can be determined by referring to the significance level standard in statistics and combining it with the sample size, using a t-distribution table.

[0080] It should be noted that this invention only analyzes and responds to scenarios where there is a significant temporal correlation between the increase in communication users and the degradation of communication quality. Quality degradation events where there is no obvious correlation between the two are not included in the analysis and handling scope of this mechanism.

[0081] As another possible way to implement the above scheme, the user migration to the adjacent area is triggered by the following operation: collecting the communication logs of newly added users within a certain time window from the time the communication quality degradation occurs in the high-demand communication area, and extracting the geographical location from the logs.

[0082] Spatial clustering algorithms are applied to perform cluster analysis on the geographical locations of new users, generating clusters of new users.

[0083] The core function of spatial clustering described above is to identify and extract the distribution patterns of new users in geospatial space. The geographical location data of new users may appear discrete, random, or clustered on a map. Spatial clustering can automatically analyze these discrete point data, identify areas where user locations are significantly dense, and thus transform seemingly chaotic points into meaningful user clusters.

[0084] Understandably, since the communication quality degradation occurred in a high-demand communication area, where existing users are mostly long-term, stable users carrying continuous traffic, and time-domain correlation analysis has shown a significant correlation between the increase in communication users and quality degradation, it is not advisable to implement forced migration or service degradation measures for existing users to avoid affecting their normal communication experience. In this case, behavioral analysis and control for new users is more reasonable. By identifying areas where new users congregate, the main traffic sources or sudden hotspots causing localized congestion can be accurately located, enabling precise intervention at the source of the problem. This strategy avoids indiscriminate optimization of the entire cell, significantly improving the targeting, efficiency, and effectiveness of resource scheduling.

[0085] The distance between the geometric center of the mobile communication base station service coverage area and the geometric center of the identified new user cluster area is calculated and compared with the spatial distribution discrimination limit. If the distance is greater than the spatial distribution discrimination limit, the adjacent base station service coverage area that is geographically close to the new user cluster area and has sufficient capacity is selected as the target area, and a user handover command is sent to the target area. Otherwise, service bearer degradation is triggered in this area.

[0086] It's important to understand that after identifying a new user cluster area, the process doesn't directly perform migration operations on its associated users. Instead, it further analyzes the spatial layout characteristics within the base station's service coverage area. By calculating the Euclidean distance between the geometric center of the base station's coverage area and the centroid of the new user cluster area, and comparing this distance with a preset spatial distribution discrimination threshold, the spatial pattern of user overload can be quantitatively discriminated.

[0087] When this distance exceeds the discrimination threshold, it indicates that the newly added user cluster area is significantly deviated from the coverage center, exhibiting marginalization or local hotspot distribution. At this time, neighboring cells usually have redundant capacity, and the user is at the coverage edge, where signal conditions are relatively switchable. Performing user redirection or handover to a nearby available area can efficiently offload the load, alleviate congestion in the original cell, and potentially improve the signal quality and experience for edge users.

[0088] Conversely, when this distance is less than or equal to the threshold, it indicates that new users are densely distributed around the base station center, forming a centralized global overload. In this case, neighboring cells are likely also under high load, and migration could easily trigger congestion switching. Simultaneously, user signals are strong in the central area, and forced handover will increase unnecessary signaling overhead, and the target cell may not be able to provide better service. Therefore, migration strategies are not suitable in such scenarios; instead, resource optimization measures within the current cell should be prioritized.

[0089] Applying to the above operations, the spatial distribution discrimination limit reflects the distance benchmark when judging the location of the new user gathering area relative to the center of the base station coverage. It is used to distinguish whether the user overload mode is a local hotspot at the edge or a centralized global overload. Specifically, network simulation tools can be used to simulate different user distribution scenarios, evaluate the migration success rate under different limit settings, and thus find the optimal limit.

[0090] When implementing user migration strategies, the aforementioned mechanism can guide users in peripheral areas to neighboring cells with better signal quality and lighter loads. This not only effectively alleviates the network pressure on the original cell but may also simultaneously improve their signal reception quality and service experience. For users in central areas, if their area experiences global overload, a service load degradation strategy is adopted, downgrading only non-critical services and prioritizing resource supply for core services such as voice calls and real-time video, thereby minimizing the degradation of user experience.

[0091] This differentiated strategy avoids implementing a one-size-fits-all approach in unsuitable scenarios, effectively curbing secondary problems such as congestion spread and ping-pong switching, and significantly improving the dynamic scheduling efficiency and overall utilization effectiveness of network resources.

[0092] As another possible way to implement the above scheme, the following operation is performed to trigger service bearer degradation: reduce the scheduling priority of non-high bandwidth multimedia services for new users in the area where service bearer degradation needs to be triggered.

[0093] It should be noted that, since temporal correlation analysis has confirmed a significant correlation between user growth and communication quality degradation, the current network pressure is mainly caused by new users. Therefore, precisely downgrading the scheduling priority of non-high-bandwidth multimedia services only for new users can effectively alleviate network congestion while maximizing the service continuity and experience quality for long-term online users. On the one hand, this avoids indiscriminate impact on users with stable connections, maintaining the satisfaction of the core user group; on the other hand, by applying targeted resource constraints to the incremental sources causing load changes, bandwidth and channel resources can be quickly released, suppressing resource preemption by non-critical services, thereby prioritizing high-priority services.

[0094] (42) When a power supply fluctuation event is detected, track the subsequent changes in communication quality. If communication quality deterioration occurs after the power supply fluctuation, perform battery power supply switching.

[0095] As a preferred implementation of the above operation, after identifying a power supply fluctuation, the system tracks whether the communication quality has deteriorated. If communication quality deterioration occurs, a timestamp of the communication quality deterioration is recorded.

[0096] The time interval between the timestamp of the power supply fluctuation event and the timestamp of the communication quality degradation is calculated and denoted as the time delay.

[0097] The time delay is compared with the configured maximum allowable time delay threshold. If the time delay is less than the maximum allowable time delay threshold, then communication quality degradation is identified as a consequence of power supply fluctuations.

[0098] The maximum permissible time delay threshold mentioned above reflects the time window assumption of the causal relationship between power supply fluctuations and communication quality degradation. Specifically, it defines the timeframe within which communication quality degradation following a power supply fluctuation can be considered directly caused by that fluctuation. This threshold sets a reasonable time limit within which communication quality degradation is considered strongly correlated with power supply fluctuations.

[0099] Specifically, power supply fluctuations can be simulated in a laboratory environment, and the time difference from the start of the fluctuation to the detection of communication quality degradation can be recorded. The average value after multiple tests can be used as a reference.

[0100] It should be added that, in practical operation, to ensure the reliability and anti-interference capability of decision-making and avoid unnecessary emergency actions triggered by occasional or transient events, the battery power switching mechanism can be set to only be activated after a time-series correlation between power supply fluctuations and communication quality degradation is continuously or repeatedly identified. This strategy can effectively filter out misjudgments caused by transient interference, measurement noise, or non-fatal power fluctuations, improving the robustness of system response. By introducing event persistence verification, critical operations are only performed when the power supply problem is confirmed to have a persistent impact trend, which can significantly reduce the risk of false switching, extend the life of backup power, and ensure sufficient power supply capability when truly needed, thereby achieving precise fault response and optimal resource utilization.

[0101] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, in the form of a computer program product.

[0102] Those skilled in the art will recognize that the algorithmic steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0103] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.

[0104] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0105] Finally, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for security monitoring of mobile communication devices, characterized in that, Includes the following steps: (1) Extract the communication traffic characteristics and service composition characteristics of each geographic grid from the historical communication logs of mobile communication base stations, and construct a communication demand characteristic assessment dataset; (2) Based on the communication demand characteristic assessment dataset, the service coverage area of ​​mobile communication base stations is divided into gridded areas, and high-demand communication areas and low-demand communication areas are marked. (3) Power supply fluctuation detection and communication quality degradation detection are performed simultaneously during the operation of the communication base station; (4) Perform differentiated operations based on the test results: (41) When only communication quality degradation is detected, focus on the communication degradation area and perform time domain correlation analysis between communication user increment and communication quality degradation. If the judgment is that there is a correlation and it occurs in the high demand communication area, trigger the migration of new users to the adjacent area. If the judgment is that there is a correlation and it occurs in the low demand communication area, trigger the service bearer degradation. (42) When a power supply fluctuation is detected, track the subsequent changes in communication quality. If communication quality deterioration occurs after the power supply fluctuation, perform a battery power supply switch. The time-domain correlation analysis of communication user increment and communication quality degradation is performed in the focused communication degradation area as follows: When communication quality degradation occurs, focus on the area of ​​communication quality degradation, take the timestamp of the communication quality degradation as the starting point, and synchronously collect the number of users accessing and communication quality indicators in the subsequent continuous time window according to the sampling frequency of communication quality monitoring. Based on the collected time-series data, with time as the horizontal axis and the number of users accessing the network and communication quality indicators as the vertical axes, corresponding user load change curves and communication quality change curves are plotted. By analyzing the slope of the user access volume change curve and the communication quality change curve, several points where the user access volume increases and several points where the communication quality decreases are obtained respectively. All identified points of increased user access volume and points of decreased communication quality are sorted in ascending order according to their timestamps and assigned a sequence number. Then, points of increased volume and points of decreased communication quality with the same sequence number are paired to form a series of time-series matching point groups. For each time-series matching point group, the slope value of the corresponding point on its respective curve is extracted. Then, the slope values ​​of all user access increase points are arranged in time order to form a user access growth intensity sequence, and the slope values ​​of all communication quality decrease points are arranged in time order to form a communication quality degradation intensity sequence. The correlation coefficient is calculated between the user access growth intensity sequence and the communication quality degradation intensity sequence.

2. The mobile communication device security monitoring method as described in claim 1, characterized in that: Step (1) includes the following: The service coverage area of ​​mobile communication base stations is divided into several regular geographical grids; Based on the geographical location in the communication logs, each historical communication log is mapped to the corresponding geographic raster within the set monitoring period; Extract the communication duration and traffic data of a single communication session from the communication logs mapped to each grid, and calculate the communication traffic per unit time for each session; For all communication sessions within each geographic raster, the communication duration of each session is used as a weight to perform a weighted average analysis of the communication traffic per unit time, thereby obtaining the communication traffic characteristic value of each geographic raster. The communication access objects are extracted from the communication logs mapped to each grid, and it is identified whether the access objects belong to high-bandwidth services. Then, the proportion of communication sessions in each geographic grid whose communication access objects are identified as high-bandwidth services is used as the service composition feature value of the geographic grid. The communication traffic characteristics and service composition characteristics of all geographic rasters are structurally integrated to construct a communication demand characteristic assessment dataset.

3. The mobile communication device security monitoring method as described in claim 2, characterized in that: The specific implementation process of step (2) is as follows: Based on the communication demand characteristic assessment dataset, the global arithmetic mean of the communication traffic characteristic value and service composition characteristic value of all geographic grid cells is calculated as the regional communication traffic benchmark threshold and the regional service benchmark threshold. For each geographic raster, its own communication traffic characteristic value is compared with the regional communication traffic benchmark threshold, and the service composition characteristic value is compared with the regional service benchmark threshold. If a geographic raster meets the following conditions: the communication traffic characteristic value is greater than the regional communication traffic baseline threshold and the service composition characteristic value is greater than the regional service baseline threshold, then the geographic raster is marked as a high communication demand point; otherwise, it is marked as a low communication demand point. Based on the spatial adjacency of geographic rasters, connectivity analysis is performed on all rasters marked as high communication demand points. Spatially adjacent high communication demand points are aggregated into a continuous geographic region to form a high-demand communication region. Similarly, spatially adjacent low communication demand points are aggregated into a low-demand communication region.

4. The mobile communication device security monitoring method as described in claim 1, characterized in that: The power supply fluctuation detection is performed as follows: During the operation of the mobile communication base station, the effective value of voltage and the power grid frequency are collected in real time from the power supply end; The voltage and frequency values ​​at the current moment are calculated by subtracting their corresponding values ​​from the previous moment to obtain the voltage and frequency changes at the current moment. If the voltage change and frequency change at the current moment are both greater than the corresponding change limit, a power supply fluctuation is identified. Conversely, if only the voltage change or only the frequency change exceeds the threshold at the current moment, the voltage and frequency changes at multiple adjacent time points are continuously tracked from the current moment. If the corresponding changes at multiple adjacent time points continue to exceed the limit, a power supply fluctuation is identified.

5. The mobile communication device security monitoring method as described in claim 1, characterized in that: The communication quality degradation detection is performed as follows: During the operation of mobile communication base stations, communication quality indicators are continuously collected from the network-side monitoring interface. The communication quality indicators at the current monitoring time are compared with the high bandwidth service tolerance threshold item by item. If any indicator exceeds the tolerance threshold, it is determined that communication quality degradation has occurred at the current time. If all communication quality indicators do not exceed the tolerance threshold at the current moment, the changes in communication quality indicators are continuously tracked within a time window based on the current moment. If a downward trend is observed within this time window, communication quality degradation is identified.

6. The mobile communication device security monitoring method as described in claim 1, characterized in that: The evaluation is related to the following operations: The correlation coefficient between the increase in communication users and the degradation of communication quality is compared with a critical threshold. If the critical threshold is reached or exceeded, a correlation is judged to exist; otherwise, no correlation exists.

7. The mobile communication device security monitoring method as described in claim 1, characterized in that: The process of triggering the migration of new users to adjacent regions is as follows: In high-demand communication areas where communication quality deterioration occurs, collect communication logs of new users within a certain time window starting from the time the communication quality deterioration occurs, and extract geographical locations from the logs. Spatial clustering algorithms are applied to perform cluster analysis on the geographical locations of new users, generating clusters of new users. The distance between the geometric center of the mobile communication base station service coverage area and the geometric center of the identified new user cluster area is calculated and compared with the spatial distribution discrimination limit. If the distance is greater than the spatial distribution discrimination limit, the adjacent base station service coverage area that is geographically close to the new user cluster area and has sufficient capacity is selected as the target area, and a user handover command is sent to the target area. Otherwise, service bearer degradation is triggered in this area.

8. The mobile communication device security monitoring method as described in claim 7, characterized in that: The triggering of service bearer degradation is as follows: In areas where service capacity degradation needs to be triggered, the scheduling priority of non-high-bandwidth multimedia services for new users should be reduced.

9. The mobile communication device security monitoring method as described in claim 1, characterized in that: The procedure for tracking subsequent communication quality changes when power supply fluctuations are detected is described below: After identifying power supply fluctuations, track whether communication quality deteriorates. When communication quality deterioration occurs, record the timestamp of the communication quality deterioration. The time interval between the timestamp of power supply fluctuation and the timestamp of communication quality degradation is calculated and denoted as time delay; The time delay is compared with the configured maximum allowable time delay threshold. If the time delay is less than the maximum allowable time delay threshold, then communication quality degradation is identified as a consequence of power supply fluctuations.

Citation Information

Patent Citations

  • Electric power communication network emergency disposal method based on artificial intelligence

    CN120151212A

  • Mobile communication load collaborative scheduling system and method based on energy efficiency perception

    CN120499743A