Intelligent alarm linkage processing method for distributed factory

By acquiring multi-source signal fusion and adaptive analysis in distributed factories and building a distributed control network, the problems of untimely response and discontinuous data transmission in the abnormal event processing of distributed factories are solved, and efficient and reliable abnormal event identification and processing are achieved.

CN120808556AActive Publication Date: 2025-10-17FOCUS CLOUD COMPUTING CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511269528.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-08
Publication Date
2025-10-17
Estimated Expiration
2045-09-08

AI Technical Summary

Technical Problem

Distributed factories face problems such as untimely response, low processing efficiency, and insufficient reliability in handling abnormal events. Existing technologies are unable to fully reflect the factory's operating status. Single signal analysis leads to misjudgment, centralized control is prone to paralysis, interference signals are improperly released, data transmission is discontinuous, and monitoring models cannot be adaptively updated.

Method used

By acquiring the operating status data of multiple monitoring sites, establishing a factory monitoring area, using multi-source signal fusion technology to identify abnormal events, calculating the risk index and intrusion index, building a distributed control node network, generating a node data transmission strategy, establishing a backup communication channel, and optimizing the adaptive analysis model.

Benefits of technology

It realizes comprehensive monitoring of distributed factories, reduces false alarms and missed alarms, improves the flexibility and fault resistance of alarm signal distribution, ensures the continuity of data transmission, adapts to changes in factory operating status, and improves the efficiency and reliability of abnormal event handling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120808556A_ABST
    Figure CN120808556A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent monitoring of factories, and discloses an intelligent alarm linkage processing method for distributed factories. The method comprises the following steps: acquiring operation state data of a plurality of monitoring stations of a distributed factory, establishing a factory monitoring area and setting a judgment area; processing the data by adopting a multi-source signal fusion technology; calculating a risk index and an intrusion index of the abnormal event through an adaptive analysis model, and obtaining a threat index through weighted fusion; and judging whether to trigger an alarm linkage response or not based on a comparison result of the threat index and a preset threshold value. After the response is triggered, a distributed control node network is constructed, a node data transmission strategy is generated, and alarm signal distribution and interference signal modulation are executed; monitoring the abnormal event adjustment state, and judging whether to release the interference signal according to the overlapping amount of the abnormal event adjustment state and the judgment area; establishing a standby communication channel to ensure data transmission continuity; new data are collected through an Internet of Things platform, and the self-adaptive analysis model is optimized by updating a training mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of factory intelligent monitoring, in particular to an intelligent alarm linkage processing method for distributed factories. BACKGROUND

[0002] In the process of industrial intelligent transformation, distributed factories have higher requirements for operation state monitoring and abnormal event processing due to the characteristics of expanded production scale and scattered equipment distribution. Traditional factory monitoring relies on single-site data collection, which is difficult to fully reflect the operation situation of the entire factory and is prone to data island phenomenon. In the prior art, the processing of operation state data mainly adopts single signal analysis method, ignoring the correlation between different monitoring site data, which leads to potential abnormal event identification lag or misjudgment. In terms of abnormal event evaluation, traditional methods often make judgments based on single-dimensional indicators, such as triggering alarms only according to the deviation of equipment operation parameters from thresholds, lacking comprehensive consideration of event risk degree and intrusion situation, and being prone to problems of alarm flooding or missing key abnormal events. When it is necessary to start alarm response, the existing linkage mechanism mainly adopts centralized control mode, once the center node fails, the entire alarm system may be paralyzed, and the signal transmission strategy lacks pertinence, which is difficult to adapt to the complex network environment of distributed factories. The release timing control of interference signals is also a weak link in the prior art. Traditional methods often directly release interference signals after alarm triggering, without considering the dynamic changes of abnormal events, which may cause unnecessary interference to normal production processes. At the same time, data transmission excessively relies on a single communication channel, and during alarm linkage response, if the main channel is interrupted, key data cannot be transmitted in time, affecting the processing efficiency of abnormal events. Existing monitoring models are mostly static models, which are difficult to adaptively update with changes in operation state such as factory equipment aging and production process adjustment, and the recognition accuracy will gradually decrease after long-term use, which cannot meet the monitoring needs of continuous operation of distributed factories. These problems together lead to the defects of distributed factories in abnormal event processing, such as un-timely response, low processing efficiency and insufficient reliability, which restricts the improvement of intelligent management level of factories. SUMMARY

[0003] The purpose of the present application is to provide an intelligent alarm linkage processing method for distributed factories to solve the problems raised in the background.

[0004] To achieve the above purpose, the present application provides an intelligent alarm linkage processing method for distributed factories, which comprises: obtaining operation state data of multiple monitoring sites of a distributed factory; establishing a factory monitoring area based on the operation state data, and setting a judgment area; processing the operation state data using a multi-source signal fusion technology to identify a potential abnormal event; calculating a risk index and a break-in index of the abnormal event through an adaptive analysis model, and performing weighted fusion on the risk index and the break-in index to obtain a threat index; based on a comparison result of the threat index and a preset threshold, determining whether to trigger an alarm linkage response; when the alarm linkage response is triggered, a distributed control node network is constructed, and a node data transmission strategy is generated; According to the node data transmission strategy, alarm signal distribution and interference signal modulation are performed; Monitoring the adjustment state of the abnormal event, according to the overlap amount of the adjustment state and the judgment area, determining whether to release the interference signal; Establish a backup communication channel to ensure data transmission continuity during the alarm linkage response; Based on the Internet of Things platform, new operation state data is collected, and the adaptive analysis model is optimized using an update training mechanism.

[0005] Preferably, the operation state data of the plurality of monitoring sites of the distributed factory is obtained, specifically including: Collecting sensor signal streams of the monitoring sites, including temperature signal streams, pressure signal streams and vibration signal streams; Performing noise characteristic analysis on the sensor signal streams to determine a data denoising threshold; According to the data denoising threshold, the sensor signal stream is subjected to filter preprocessing to obtain a standard sensor signal stream; The standard sensor signal stream is input into a multi-source signal fusion unit to extract feature data.

[0006] Preferably, the operation state data is processed using a multi-source signal fusion technology, specifically including: According to the data characteristic information of the feature data, determine the feature extraction method and the position feature type; According to the feature extraction method and the position feature type, the correlation feature extraction is performed on the feature data to obtain a multi-source signal correlation feature set; based on the signal source credibility, the weight dynamic allocation rule is set; The multi-source signal correlation feature set is fused and processed through the weight dynamic allocation rule to determine the estimated position of the abnormal event.

[0007] Preferably, the risk index and the break-in index of the abnormal event are calculated through the adaptive analysis model, specifically including: Obtaining the event type and the device load quantity of the abnormal event; determine whether the event type is a preset high-risk type, and mark the determination result as a type identifier; calculate the risk index based on the type identifier, the number of device loads, and the event change rate; obtain the length of the activity track of the abnormal event in the monitoring area and the length of the activity track in the judgment area; calculate the intrusion index through the length of the activity track.

[0008] Preferably, the risk index and the intrusion index are weighted and fused to obtain a threat index, specifically including: setting a weight factor allocation rule; performing weighted summation on the risk index and the intrusion index through the weight factor allocation rule; normalizing the weighted summation result to obtain the threat index; comparing the threat index with a preset threshold value of the threat index to generate a ruling result.

[0009] Preferably, the distributed control node network is constructed, and a node data transmission strategy is generated, specifically including: determining the number of transmission control nodes according to the factory area distribution area and communication demand, performing node deployment analysis based on the number of transmission control nodes to obtain a plurality of transmission control nodes, configuring the communication parameters and network topology of the transmission control nodes, and collecting real-time network conditions and interference signal data of the transmission control nodes; generating the node data transmission strategy through a strategy self-adaptive matching mechanism.

[0010] Preferably, the alarm signal distribution and interference signal modulation are performed, specifically including: modulating multi-source deception signals based on the estimated position of the abnormal event, and distributing alarm signals through the node data transmission strategy; using the multi-source deception signals to perform position interference, and monitoring the change state of the abnormal event after the alarm signal distribution.

[0011] Preferably, the adjustment state of the abnormal event is monitored, and it is determined whether to release the interference signal according to the overlap amount of the adjustment state and the judgment area, specifically including: obtaining the activity track of the adjustment state, and calculating the overlap amount of the activity track and the judgment area; if the overlap amount is greater than zero, releasing the interference signal; if the overlap amount is zero, tracking the abnormal event until it escapes the monitoring area.

[0012] Preferably, the backup communication channel is established, specifically including: Configure a quantum encryption channel and a frequency band switching mechanism; integrate the quantum encryption channel and the frequency band switching mechanism into a backup communication unit; when data transmission is interrupted, enable the backup communication channel and rebuild a new communication link.

[0013] Preferably, the Internet of Things platform collects new operating state data and optimizes the adaptive analysis model using an update training mechanism, specifically including: Collecting new operating state data points; Performing classification on the new operating state data points through a clustering algorithm; Calculating the distance between the new operating state data points and the cluster centers; Performing abnormal point identification based on the distance; Updating the training parameters of the adaptive analysis model according to the abnormal point identification results.

[0014] Compared with the prior art, the beneficial effects of the present application are: 1. The intelligent alarm linkage processing method for a distributed factory breaks the limitations of traditional single-site data collection by acquiring operating state data from multiple monitoring sites, can fully capture the operating information of each area of the factory, and provides more abundant basic data for subsequent abnormality identification. Establishing a factory monitoring area and setting a judgment area makes the judgment of abnormal events have a clear spatial reference, reducing the judgment deviation caused by ambiguous monitoring range. 2. The operating state data is processed using a multi-source signal fusion technology, which fully utilizes the complementarity of different types and sources of signals, reduces the errors and interference that may exist in single signal analysis, and makes the identification of potential abnormal events closer to the actual operating conditions. The risk index and intrusion index are calculated through the adaptive analysis model, and the threat index is obtained by weighted fusion, which comprehensively considers the risk degree and intrusion situation of the abnormal event, making the threat assessment more comprehensive and reducing the false alarm or missed alarm phenomenon caused by single index evaluation. 3. Whether to trigger an alarm linkage response is determined based on the comparison result of the threat index and the preset threshold, avoiding unnecessary alarm initiation and making the alarm mechanism more targeted. When the alarm linkage response is triggered, a distributed control node network is constructed and a node data transmission strategy is generated, which eliminates the dependence on centralized control, improves the flexibility and fault tolerance of alarm signal distribution, and ensures efficient signal transmission to related nodes. 4. Alarm signal distribution and interference signal modulation are performed according to the node data transmission strategy, making alarm signal transmission more accurate and interference signal action more in line with actual needs. The adjustment state of the monitored abnormal event is monitored, and whether to release interference signals is determined according to the overlap amount with the judgment area, avoiding blind release of interference signals and reducing unnecessary impact on normal operation of the factory. 5. Establish a backup communication channel to provide redundancy for data transmission during alarm linkage response, reduce the risk of data transmission interruption due to main channel failure, and ensure continuous transmission of critical information. Based on the Internet of Things platform, new operating state data is collected, and the adaptive analysis model is optimized by updating the training mechanism, so that the model can continuously adjust with the changes of the factory operating state, maintain the ability to identify abnormal events, and adapt to the dynamic changes in the long-term operation of the distributed factory. BRIEF DESCRIPTION OF DRAWINGS

[0015] Figure 1 The working principle diagram of the intelligent alarm linkage processing method for distributed factory is described. Figure 2 The sub-flowchart for obtaining operating state data is described. Figure 3 The sub-flowchart for calculating abnormal event risk index and intrusion index is described. Figure 4 The sub-flowchart for distributed control node network construction and data transmission strategy generation is described. DETAILED DESCRIPTION

[0016] The technical solutions of the present application will be described in detail below with reference to the drawings of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0017] Please refer to Figure 1 The present application provides an intelligent alarm linkage processing method for distributed factory, which comprises: Obtain operating state data of multiple monitoring sites of the distributed factory; establish a factory monitoring area based on the operating state data, and set a judgment area; use multi-source signal fusion technology to process the operating state data to identify potential abnormal events; calculate the risk index and intrusion index of the abnormal events through an adaptive analysis model, and weight and fuse the risk index and intrusion index to obtain a threat index; based on the comparison result of the threat index and a preset threshold, determine whether to trigger an alarm linkage response; when the alarm linkage response is triggered, construct a distributed control node network and generate a node data transmission strategy. According to the node data transmission strategy, execute alarm signal distribution and interference signal modulation; Monitor the adjustment state of the abnormal event, and determine whether to release the interference signal according to the overlap amount of the adjustment state and the judgment area; establish a backup communication channel to ensure data transmission continuity during alarm linkage response; collect new operating state data based on the Internet of Things platform, and optimize the adaptive analysis model using an updating training mechanism.

[0018] Embodiment 1: refer to Figure 2 When acquiring the running state data of multiple monitoring sites of a distributed factory, the specific operation involves collecting the signal streams generated by the sensors installed at each monitoring site. These sensor signal streams include temperature signal streams, pressure signal streams, and vibration signal streams. The temperature signal streams reflect the thermal state changes of equipment or the environment, the pressure signal streams indicate the pressure fluctuations in pipelines or containers, and the vibration signal streams characterize the running stability of mechanical equipment. The collection process is completed through data collection terminals deployed in the factory, which continuously read the sensor outputs according to the preset sampling frequency.

[0019] Noise characteristic analysis is performed on the collected sensor signal streams. The noise characteristic analysis process first performs frequency spectrum transformation on the original signal streams to identify the energy distribution characteristics of different frequency bands in the signals. The analysis process calculates the relative proportion of signal energy and noise energy in a specific frequency band to identify the main noise source and its frequency distribution characteristics. Based on the frequency spectrum analysis results and the preset signal-to-noise ratio target value, combined with the maximum allowable error range specified in the sensor factory specification, the data denoising threshold value is calculated comprehensively. This threshold value is a dynamically changing value, which is set for different types of signal streams (temperature, pressure, vibration) and different environmental noise levels of different monitoring points.

[0020] According to the determined data denoising threshold, filter preprocessing is performed on the original sensor signal stream. The filter preprocessing uses a wavelet threshold denoising algorithm. This algorithm decomposes the signal into sub-band signals of different scales, and sets different threshold parameters for different frequency sub-bands. High-frequency sub-bands correspond to signal details or noise, and use higher thresholds for suppression; low-frequency sub-bands correspond to the main body of the signal, and use lower thresholds for preservation. The threshold processing method selects a hard threshold or a soft threshold function, which is selected according to the characteristics of the signal. After threshold processing, the sub-band signals are reconstructed to obtain the denoised standard sensor signal stream. The standard sensor signal stream retains the main features of the original signal while reducing the influence of random noise and impulse interference.

[0021] The processed standard sensor signal stream is input into the multi-source signal fusion unit for feature extraction. The multi-source signal fusion unit receives standard signal streams from different sensor types and different monitoring sites.

[0022] The process of processing the running state data using multi-source signal fusion technology first determines the subsequent feature extraction method and the position feature type to be extracted according to the data characteristic information of the input characteristic data. The data characteristic information includes time domain statistics, frequency domain energy distribution, and signal entropy value. The time domain statistics covers parameters such as signal mean, variance, peak factor, and kurtosis; the frequency domain energy distribution is obtained through Fourier transform or wavelet packet transform to calculate the energy proportion of different frequency bands; and the signal entropy value calculates the complexity or uncertainty of the signal. Based on these data characteristic information, the system automatically selects the feature extraction method: for signals with obvious periodicity, the frequency domain feature extraction method is adopted to mainly analyze the fundamental frequency and harmonic components; and for transient or non-stationary signals, the time domain feature extraction method is adopted to mainly extract the waveform shape change characteristics. At the same time, the position feature type is determined, including signal source coordinate estimation (based on signal time difference or intensity positioning model) and signal intensity distribution map (reflecting the signal attenuation characteristics in space).

[0023] According to the selected feature extraction method and position feature type, the associated feature extraction is performed on the input characteristic data. The target of the associated feature extraction is to find the feature combination from different physical positions and different types of sensors but describing the same potential abnormal event. The process adopts an algorithm based on mutual information or correlation analysis. The mutual information algorithm calculates the information sharing amount between different signal features to identify the feature pairs with high statistical dependence; and the correlation analysis algorithm calculates the linear correlation coefficient between the features to identify the feature combination with synchronous change. The algorithm traverses all the input feature data points to calculate the correlation degree between the features, and when the correlation degree exceeds the preset correlation degree threshold, the features are combined into an associated feature group. All the identified associated feature groups are summarized to form a multi-source signal associated feature set. The feature set includes multiple feature groups, and each feature group represents a potential abnormal event and its feature performance in multiple dimensions.

[0024] The weight dynamic allocation rule is set based on the credibility of the signal source. The signal source credibility is an evaluation index, which is calculated according to the accuracy and stability scores of the historical data of the signal source (specific sensor or monitoring site). The accuracy score is calculated by comparing the historical alarm records of the signal source with the final confirmed real abnormal event results; and the stability score is obtained by calculating the variance or drift degree of the output signal of the signal source within a certain period. The higher the credibility score, the more reliable the data provided by the signal source. The weight dynamic allocation rule allocates different fusion weights to the associated feature groups or single features from different signal sources according to the credibility score. The features of the signal source with high credibility are allocated with larger weights, and the features of the signal source with low credibility are allocated with smaller weights. The weight allocation can be a linear proportional relationship, or a preset weight segmented mapping table can be used.

[0025] The multi-source signal associated feature set is fused by a set of weight dynamic allocation rules. The goal of the fusion process is to integrate all relevant feature information and determine the most likely location of the abnormal event. The fusion algorithm selects either a weighted average method or an evidence theory method. The weighted average method directly averages the estimated location coordinates in the associated feature group according to the weights. The evidence theory method (such as the Dempster-Shafer theory) processes the uncertainty and confidence information provided by the feature group about the location estimate, combines different evidence bodies through combination rules, and finally outputs a fused location estimate and its confidence interval. The fusion process integrates all the weighted location information and calculates the estimated location of the abnormal event. The location information is output in the form of three-dimensional coordinates, usually including longitude, latitude, and height information, and is accompanied by a confidence interval or probability value representing the reliability of the location estimate. The output abnormal event estimated location information is used as a key input for subsequent risk assessment and response decision-making.

[0026] Example 2: see Figure 3 When calculating the risk index and intrusion index of the abnormal event through the adaptive analysis model, the system first obtains the event type information related to the abnormal event and the number of affected device loads. The event type information is obtained by matching the feature description of the abnormal event with the preset event type library. The event type library contains various predefined abnormal event categories such as device failure, environmental intrusion, and parameter overrun, each with specific identifiers and attribute descriptions. The system compares the identified event type with the preset high-risk type list. The preset high-risk type list contains specific event categories that the system has pre-configured and that may cause serious accidents or significant losses, such as critical device failure, toxic and harmful substance leakage, core control system intrusion, etc. The comparison result is marked as a type identifier. The type identifier is a discrete value or a Boolean value indicating whether the abnormal event belongs to a high-risk type, for example, using the value 1 to represent a high-risk type and the value 0 to represent a non-high-risk type, or using specific enumeration values for identification.

[0027] The number of device loads affected by the abnormal event is obtained. The device load number refers to the total number of critical production devices, control units, or process nodes that are directly in an abnormal state, have limited functionality, or are at risk due to the abnormal event during factory operation. This number is obtained by querying the factory device topology relationship database, which records the dependency relationships and influence ranges between devices. The system analyzes the device list associated with the abnormal event based on its location and type, and counts the number of devices within the direct influence range.

[0028] The event change rate of the abnormal event is obtained. The event change rate is used to quantify the degree of rapidity of the development of the abnormal event. The system calculates this rate by analyzing the time series data changes of the key parameters associated with the abnormal event. The selection of key parameters depends on the type of event, for example, a device failure event may focus on the temperature rise speed or the degree of vibration intensification, and an environmental intrusion event may focus on the movement speed or the change in intrusion depth. The system calculates the derivative or difference value of the selected key parameters within a certain time window, and then obtains a relatively stable change rate value through sliding window averaging or exponential smoothing processing.

[0029] Based on the obtained type identification, device load quantity and event change rate, the system calculates the risk index. The calculation function of the risk index involves the combined operation of the three input parameters. The type identification is used as a weight coefficient factor, and if the identification is a high-risk type, a larger coefficient value is given, otherwise a smaller coefficient value is given. The device load quantity is processed through a linear or nonlinear mapping function, which is designed according to the risk assessment model of the factory, and may include logarithmic conversion, piecewise linear conversion or weighted calculation based on the importance of the device, to reflect the influence degree of different device quantities on the overall risk. The event change rate is used as a risk amplification factor, and the larger the change rate, the more significant the amplification effect. The system performs weighted combination operation on the mapped device load quantity value, the type identification value adjusted by the coefficient, and the event change rate amplification factor, and the specific weighted weight can be configured according to the risk preference of different areas or different event types in the factory, and finally outputs a value representing the potential harm degree of the current abnormal event, i.e. the risk index.

[0030] (1) "preset high-risk type" and "type identification" definition Preset high-risk type: refers to abnormal events that may cause major safety accidents, equipment damage or production interruption, including: ① failure of critical production equipment (such as rupture of reaction kettle, jamming of main shaft of numerical control machine tool, explosion of hydraulic system); ② leakage of dangerous substances (such as leakage of toxic gas, leakage of flammable liquid, leakage of corrosive liquid); ③ intrusion of core control system (such as unauthorized access to PLC control system, data tampering); the "type identification (T)" of such events is uniformly set to 0.8 (the value range is 0-1, the higher the value represents the greater the risk basis weight).

[0031] Non-preset high-risk type: refers to abnormal events that have less impact on production and no direct safety risk, including: ① ordinary device vibration anomaly (amplitude exceeds the baseline value by 10%-20%, does not reach the equipment damage threshold); ② small amplitude out-of-tolerance of environmental parameters (temperature / humidity exceeds the normal range by ±5℃ / ±10%, does not affect equipment operation); ③ single non-core sensor failure (such as failure of auxiliary lighting area temperature sensor, does not affect the main production link); the "type identification (T)" of such events is uniformly set to 0.3.

[0032] (2) Statistical rules and mapping methods for "equipment load quantity" Statistical scope: Only includes "key production equipment, control units or process nodes directly affected by abnormal events", excludes irrelevant auxiliary equipment (such as workshop lighting, ventilation equipment, non-production computers, etc.); Example: If a numerical control machine tool vibrates abnormally, the statistical scope is "the numerical control machine tool + the adjacent 2 conveying equipment (responsible for the raw material / finished product transfer of the machine tool) + the corresponding PLC control unit", a total of 3 sets of equipment, irrelevant workshop lighting equipment is not counted.

[0033] Value mapping rule: Map the statistical "equipment load quantity (N)" to a standardized value of 0-1 (denoted as N'), the mapping logic is based on "the more equipment, the higher the risk accumulation", specifically: ① 1≤N≤5: N' = 0.02 + (N-1)×0.018 (for example, N = 3, N' = 0.02 + (3-1)×0.018 = 0.056, rounded to two decimal places 0.06); ② 6≤N≤10: N' = 0.1 + (N-6)×0.016 (for example, N = 8, N' = 0.1 + (8-6)×0.016 = 0.132, rounded to two decimal places 0.13); ③ N>10: N' uniformly takes 0.2 (since more than 10 key equipment is affected, it has reached the high risk threshold, there is no need to further accumulate).

[0034] (3) Calculation parameters, formula and sampling rules of "event change rate" Calculation parameter matching: According to the type of abnormal event, determine the core calculation parameter of "event change rate" (that is, "the key indicator representing the speed of event development"), specifically: ① Temperature anomaly: Core parameter = "current temperature value - device normal working temperature threshold" (for example, the device normal threshold is 25℃, the current temperature is 30℃, then the parameter value is 5℃); ② Vibration anomaly: Core parameter = "current vibration amplitude value - device reference vibration amplitude value" (for example, the device reference amplitude is 0.5mm / s², the current amplitude is 1.2mm / s², then the parameter value is 0.7mm / s²); ③ Leakage anomaly: Core parameter = "current leakage concentration value - safety concentration threshold" (for example, the safety concentration threshold is 10ppm, the current concentration is 25ppm, then the parameter value is 15ppm).

[0035] Calculation formula: Event change rate (V) = (current core parameter value - initial core parameter value) / data sampling time interval (Δt).

[0036] Sampling period rule: set Δt according to the "dynamic characteristics" of abnormal events: ① dynamic abnormality (such as leakage diffusion, mobile intrusion): Δt = 1s (high-frequency sampling, capture rapid changes); ② static abnormality (such as slow overheating of equipment, slow vibration aggravation): Δt = 5s (low-frequency sampling, avoid data redundancy).

[0037] Standardization processing: map the calculated V to a standardized value (V') of 0-1, rules: ① when V ≥ V_max (the "dangerous speed threshold" of this type of abnormality, such as V_max = 0.2mm / s³ for vibration): V' = 1.0; ② when V ≤ V_min (the "negligible speed threshold" of this type of abnormality, such as V_min = 0.02mm / s³ for vibration): V' = 0.1; ③ when V_min < V < V_max: V' = 0.1 + (V-V_min) × (0.9 / (V_max-V_min)) (linear interpolation).

[0038] (4) The final calculation formula of risk index: RI = (T × 0.4) + (N' × 0.3) + (V' × 0.3); (Note: 0.4, 0.3, 0.3 are the weights of type identification, device load, and event speed, based on the engineering experience that "type identification has the greatest impact on risk, device load and speed have less impact", which conforms to the core logic of "weighted calculation").

[0039] At the same time, the system calculates the intrusion index of the abnormal event. To calculate the intrusion index, the length of the activity trajectory of the abnormal event in the factory monitoring area and the length of the activity trajectory in the preset judgment area are needed. The activity trajectory refers to the moving path of the abnormal event in the spatial position, which is formed by continuously tracking the position coordinate sequence of the abnormal event. The monitoring area is the geographical range covered by the entire factory safety monitoring system, which is defined by geographical coordinate boundaries at system initialization. The judgment area is one or more core or sensitive sub-areas set in the monitoring area, such as key equipment concentration area, dangerous goods storage area, control center periphery, etc., whose boundaries are also defined by geographical coordinates.

[0040] The system obtains the position coordinate sequence data of the abnormal event. Based on these coordinate points, the system calculates the length of its activity trajectory in the monitoring area. The trajectory length calculation adopts a spatial integration method. The system connects the continuous position coordinate points in time sequence to form trajectory line segments, calculates the Euclidean distance of each segment, and then adds up the distances of all the line segments to obtain the total trajectory length in the monitoring area. Using the same method, the system calculates the length of the activity trajectory of the abnormal event in the judgment area. The trajectory length calculation in the judgment area only adds up the lengths of those line segments that are completely located within the boundary of the judgment area or intersect with the boundary and are located inside. The system determines the positional relationship between each trajectory line segment and the boundary of the judgment area polygon through a spatial geometry algorithm, and accurately calculates the length of the line segment that falls within the judgment area.

[0041] By calculating the two trajectory length values, the system calculates the intrusion index. The intrusion index is defined as the ratio of the activity trajectory length in the judgment area to the activity trajectory length of the abnormal event in the entire monitoring area. The ratio is a value between 0 and 1, which reflects the proportion of the abnormal event's activity in the sensitive judgment area relative to its activity in the entire monitoring area. The higher the ratio, the higher the relative degree of the abnormal event's stay or activity in the sensitive area.

[0042] (1) Collection equipment and sampling rules of "activity trajectory" Collection equipment: Based on the description of the "Internet of Things platform" and "monitoring site", the trajectory collection equipment is: ① dynamic anomaly (such as intrusion, leakage diffusion): UWB positioning module (positioning accuracy ±10cm, supporting real-time coordinate output); ② static anomaly (such as local overheating diffusion of equipment): distributed infrared sensor array (deployed at intervals of 5m, the trajectory is calculated by the order of sensor triggering); Sampling frequency rules: ① dynamic anomaly (such as personnel intrusion, mobile device anomaly): sampling frequency = 1 time / second (high frequency to capture position changes); ② static anomaly (such as leakage diffusion, temperature diffusion): sampling frequency = 1 time / 5 seconds (low frequency to capture range changes, to avoid data redundancy).

[0043] (2) Definition standards of "monitoring area" and "judgment area" Monitoring area definition: Based on the physical coordinates of the factory GIS system, the principle of "covering the entire production area", and the rectangular / polygonal boundary definition, examples: ① The monitoring area of the mechanical processing workshop: the coordinate boundary is a rectangular area with coordinates (X1=100m, Y1=50m), (X2=200m, Y2=50m), (X3=200m, Y3=150m), (X4=100m, Y4=150m) (area 100m x 100m = 10000㎡); ② The monitoring area of the chemical plant storage tank area: the coordinate boundary is a rectangular area with coordinates (X1=120m, Y1=340m), (X2=130m, Y2=340m), (X3=130m, Y3=350m), (X4=120m, Y4=350m) (area 10m x 10m = 100㎡).

[0044] Judgment area definition: "Core sensitive area" within the monitoring area, the principle of "protecting key equipment / hazardous substances", and the circular / rectangular boundary definition, examples: ① The judgment area of the numerical control machine tool: the center point of the equipment (X=150m, Y=100m) as the center, the circular area with a radius of 5m (covering the equipment body and the surrounding operation area); ② The judgment area of the storage tank T-101: the center point of the storage tank (X=125.7m, Y=348.2m) as the center, the circular area with a radius of 10m (covering the storage tank body and the leakage emergency area).

[0045] (3) Specific calculation method of "activity track length" Monitoring area total track length (Lm) calculation: Extract the continuous position coordinate sequence in the sampling period: P1(X1, Y1), P2(X2, Y2), …, Pn(Xn, Yn) (n is the sampling number); Calculate the distance between adjacent two points using the Euclidean distance formula: d_i=√[(X_i - X_{i-1})² + (Y_i - Y_{i-1})²] (i from 2 to n); Total track length Lm=Σd_i (i from 2 to n, accumulate all adjacent point distances).

[0046] Track length in judgment area (Lp) calculation: Use the "ray method" to judge whether each track segment (PiPi-1) falls within the judgment area: draw a ray from any point on the line segment to the positive direction of the X-axis, count the number of intersection points of the ray and the boundary of the judgment area, if it is odd, the line segment is in the area, if it is even, it is outside the area; For "completely in the area line segment", directly count d_i; For "partially in the area line segment", calculate the intersection points of the line segment and the area boundary, take the distance of the "area inside" to count; For "completely outside the area line segment", do not count; Judgment area track length Lp=Σ"area inside line segment distance".

[0047] (4) The final calculation formula of the intrusion index: II = (Lp / Lm) x 100%; (Note: The intrusion index is the proportion of the trajectory length in the judgment area to the total trajectory length. The higher the proportion, the higher the intrusion degree of the abnormal event to the core sensitive area. The value range is 0%-100%. Example: Lm = 3.69m, Lp = 2.95m, then II = (2.95 / 3.69) x 100% ≈ 80%.

[0048] The calculated risk index and intrusion index are weighted and fused to generate the final threat index. The system sets a weight factor allocation rule, which defines the weight proportion of the risk index and the intrusion index in the fusion calculation. The weight factor allocation rule is not fixed, but is dynamically adjusted according to the current safety operation level of the factory. The safety operation level is a comprehensive indicator reflecting the safety state of the factory's overall operation, which may be determined by multiple factors, such as whether there are other high-risk events, production load level, environmental safety assessment results, etc. The rule stipulates that when the safety operation level of the factory is high, the weight of the intrusion index increases accordingly, meaning that in a relatively safe environment, the attention to intrusion behavior in sensitive areas is enhanced; on the contrary, when the safety operation level is low, the weight of the risk index increases, paying more attention to the potential harm degree of the event. The specific weight adjustment mapping relationship is stored in the configuration file.

[0049] According to the real-time weight factor allocation rule, the system performs weighted sum calculation on the risk index and the intrusion index. Multiply the risk index by its corresponding dynamic weight factor, multiply the intrusion index by its corresponding dynamic weight factor, and then add the two products to get a weighted sum value.

[0050] The weighted sum value is normalized. The goal of normalization is to map the calculation result to a standardized numerical range for subsequent comparison with the preset threshold. The system uses the min-max scaling method or other standardization methods for normalization. The min-max scaling method subtracts the historical minimum weighted sum value recorded by the system from the current weighted sum value, and then divides the result by the difference between the historical maximum weighted sum value and the historical minimum weighted sum value. Finally, the result is mapped to the interval of 0 to 1. The historical maximum and minimum values are updated continuously during the system operation according to the actual calculation results. The value obtained after normalization is the threat index.

[0051] (1) The specific basis and numerical value of "weight factor allocation rule" Weight distribution basis: dynamic adjustment based on “factory area risk level” - high-risk areas (such as reaction kettle area, dangerous goods warehouse) prioritize “risk index” (event itself harm), low-risk areas (such as warehouse area, office area) prioritize “intrusion index” (intrusion into sensitive areas), and medium-risk areas (such as processing workshop) balance both.

[0052] Specific weight table (risk index weight W1, intrusion index weight W2, W1+W2=1.0), as shown in Table 1 below: Table 1: Correspondence table of factory area risk level and index weight distribution Factory area risk level Risk index weight (W1) Break-in index weight (W2) Applicable area examples High risk 0.6 0.4 Reaction kettle area, dangerous goods warehouse Medium risk 0.5 0.5 Mechanical processing workshop Low risk 0.4 0.6 Ordinary storage area, office area (Note: The weight value is based on the goal of “solving false positives and false negatives” - high-risk areas focus on risk to avoid missing high-risk events; low-risk areas focus on intrusion to avoid false positives for non-intrusion events).

[0053] (2) Specific formula of “weighted sum” and “normalization processing” Weighted sum formula: Weighted sum value (S) = Risk index (RI) x W1 + Intrusion index (II, converted to 0-1 decimal) x W2; (Note: Intrusion index II needs to be converted from “%” to “decimal”, such as II=80% converted to 0.8).

[0054] Normalization processing formula: Threat index (TI) = (S - Smin) / (Smax - Smin); Where: ① Smin: The minimum weighted sum value of “similar abnormal events” in the past 6 months (extracted from the factory Internet of Things platform operation log, reflecting the “lowest risk level”); ② Smax: The maximum weighted sum value of “similar abnormal events” in the past 6 months (reflecting the “highest risk level”); (Note: After normalization, TI takes value range 0-1, which is convenient for comparison with unified threshold).

[0055] (3) Setting basis and specific value of “preset threshold” Threshold setting basis: based on “threat index of historical abnormal events - actual loss” correlation analysis, ensure that the threshold corresponds to the “acceptable loss boundary” - when TI≥threshold, the event may cause losses beyond the acceptable range, which needs to trigger an alarm; when TI< threshold, the event loss is controllable and does not need to trigger an alarm.

[0056] Specific threshold table (corresponding to area risk level), as shown in Table 2 below: Table 2: Correspondence table of factory area risk level and threat index preset threshold Factory area risk level Threat index preset threshold (TI threshold) Acceptable loss boundary examples High risk 0.5 Single event loss < 20,000 yuan Medium risk 0.6 Single event loss < 50,000 yuan Low risk 0.7 Single event loss < 10,000 yuan Example: Medium risk area, TI = 0.54 < 0.6, ruling “no alarm linkage response triggered”; if TI = 0.62 > 0.6, ruling “alarm linkage response triggered”.

[0057] The generated threat index is compared with preset threat index threshold. The threat index preset threshold is not a single numerical value, but multiple levels according to the risk level of different geographical areas in the factory. High-risk areas (such as chemical plant reactor areas) set a lower trigger threshold, and low-risk areas (such as ordinary storage areas) set a higher trigger threshold. The system selects the corresponding preset threshold for comparison according to the area where the abnormal event is currently located or its main activity area. The comparison result generates a ruling result. The ruling result is a Boolean value indicating whether the current threat index exceeds the preset threshold of the corresponding area. If the threat index is greater than or equal to the preset threshold, the ruling result is true (True), indicating that the alarm linkage response needs to be triggered; if the threat index is less than the preset threshold, the ruling result is false (False), indicating that the threat level of the current abnormal event does not meet the standard for triggering the response. The ruling result directly determines whether to execute the subsequent step S106 and the alarm linkage response process thereafter.

[0058] Embodiment 3: Refer to Figure 4 When constructing the distributed control node network and generating the node data transmission strategy, the system first determines the number of transmission control nodes according to the actual physical layout of the factory and the communication performance requirements. The factory area distribution area data is derived from the integrated geographic information system database, which stores the accurate boundary coordinates and area information of each area in the factory. The communication demand is quantified by analyzing multiple dimensions of parameters, including the density of the distribution of monitoring points, the data update frequency required by each monitoring point (such as the number of samples per second), and the average size of a single data packet (in bytes). The system calculates the expected value of data flow load per unit area, combines the theoretical bandwidth upper limit of the wireless communication module and the actual environmental attenuation factor, and calculates the minimum node number base value required to meet the communication demand. Considering the communication link redundancy design requirement, a certain proportion of redundant nodes is added to the minimum node number base value to finally determine the total number of transmission control nodes.

[0059] Based on the determined total number of nodes, the system performs node deployment analysis. The goal of node deployment analysis is to determine the optimal physical installation location coordinates for each transmission control node. Key factors considered in this process include: factory area needs to be evenly covered to avoid signal blind spots; communication links need to have redundant paths to maintain communication when a single path is interrupted; the attenuation of wireless signals by obstacles in the physical environment (such as large equipment, metal structures, walls). The analysis process uses optimization algorithms in graph theory. The system discretizes the factory area into grid points, each representing a candidate node location. The communication reachability between any two candidate location points is calculated, which depends on distance, obstacle penetration loss, and antenna gain. Define the coverage quality index Q cov Quantify the performance of the deployment scheme: Q cov = min(1,∑ N i=1 A i / A total ) Where: N is the total number of deployed transmission control nodes; A i is the effective coverage area of the Ith node (the actual coverage range calculated after considering signal strength threshold and obstacle attenuation); A total is the total area of the factory target monitoring area. Q cov The closer the value is to 1, the more comprehensive the area coverage is. At the same time, the redundancy index of the network is calculated, such as the average connectivity of the nodes. The system uses heuristic search algorithms (such as simulated annealing or genetic algorithms) to find the combination of node locations that maximizes network redundancy or minimizes total deployment cost under the premise that Q cov is greater than the preset target value (such as 0.95). Finally, output multiple three-dimensional coordinate deployment schemes for transmission control nodes.

[0060] Configure the communication parameters and network topology of the transmission control nodes. Communication parameters cover physical layer and data link layer settings: wireless communication frequency band is selected from a plurality of pre-set industrial unlicensed frequency bands; modulation mode is selected according to transmission distance and anti-interference requirements, such as QPSK, 16QAM; transmit power is dynamically adjustable according to coverage distance requirements; data packet format defines packet header structure, payload length, and check method. The selection of network topology is based on node deployment location and communication reliability requirements. In areas with small node spacing and high reliability requirements, mesh topology may be used to achieve multi-path redundancy; in areas with widely distributed nodes and central aggregation points, star topology or hierarchical topology may be used. Topology decision algorithm automatically selects after evaluating factors such as average hop count between nodes, end-to-end delay expectation, and fault isolation capability. The selected topology structure determines the logical connection relationship and routing basic rules between nodes.

[0061] The real-time network operating state data and external interference signal data of the transmission control node are collected. The real-time network state data includes: inter-node link quality indication, which reflects the ratio of signal reception strength to background noise level; data packet transmission delay, which records the actual transmission time of data packets from the source node to the target node; and packet loss rate, which calculates the proportion of successfully sent data packets in a specific time window. The external interference signal data is collected by the node's built-in spectrum sensing module, including the signal strength value of non-system transmission sources detected within the system operating frequency band, and the spectral characteristics (such as bandwidth, center frequency, modulation type) of the signal. These data are periodically sampled and aggregated to the network management unit.

[0062] The final node data transmission strategy is generated through a policy adaptive matching mechanism. The core of this mechanism is a policy library containing multiple predefined policy templates, and a decision engine that selects or fine-tunes policies based on real-time data. The decision engine receives the network state and interference signal data reported by the transmission control node in real time. Based on the link quality indication and packet loss rate data, the stability level of each communication path is evaluated. If persistent strong interference signals are detected in a specific frequency band, the decision engine will trigger the frequency hopping strategy, select a pre-set frequency switching sequence from the policy library, and instruct the node to switch to a backup frequency band with less interference. If the end-to-end delay exceeds the application tolerance threshold, the decision engine will evaluate the current topology and may select a backup routing path that bypasses the high-delay node, or activate the data packet fragmentation transmission mechanism to reduce the transmission time. In a severely interfered environment, the redundancy of forward error correction coding may be increased or the transmission power may be temporarily increased. The policy adaptive matching mechanism dynamically integrates the above decision logic to generate specific and operational node data transmission strategies. The strategy defines the data transmission path selection rules (such as which relay nodes should be used for specific target nodes), the communication frequency hopping sequence (such as trigger conditions, switching time points, and target frequency list), data packet fragmentation size and recombination rules, and threshold conditions for transmission power dynamic adjustment. The complete strategy is compiled into a configuration instruction set and distributed to all relevant transmission control nodes in the factory through the management channel for loading and execution. Each node updates its local communication protocol stack parameters and routing table according to the received instruction set, ensuring that the entire network works in accordance with the new strategy.

[0063] Example 4: The system operates based on the estimated location of the identified abnormal event when executing the alarm signal distribution and the jamming signal modulation. Take the toxic gas leakage event in the storage tank area of a chemical plant as an example: the system determines through multi-source signal fusion that the leakage source is located 3 meters northwest of the storage tank T-101 (coordinates X=125.7, Y=348.2), which is the estimated location of the abnormal event. The system modulates multi-source deceptive signals according to this location. Multi-source deceptive signals refer to a group of jamming signal sequences that differ in signal characteristics but work together. For the gas leakage event, the system generates three types of deceptive signals: the first simulates the sound wave signal of a normal pressure relief valve, with a carrier frequency set at 40 kHz, a specific cyclic pseudo-random code sequence loaded, and FSK modulation used; the second simulates the baseline drift signal of an environmental monitoring sensor, with a low-frequency sawtooth wave superimposed on the 4-20 mA current loop; the third generates a fake infrared thermal image data packet, simulating normal temperature distribution on the surface of the storage tank. These signals are emitted directionally by distributed control nodes, covering the area around the leakage source.

[0064] The alarm signal is distributed through the node data transmission strategy. The alarm signal contains a structured data packet: the event type code is set to "HZDQXL" (toxic gas leakage in chemical industry), the location coordinate field is written as (125.7, 348.2), the threat level identifier is set to "A1" (the highest level), and the timestamp marks the start time of the leakage. The distribution process strictly follows the strategy generated in Example 3: since the mesh topology nodes are deployed in this area, the data transmission selects three independent paths to send synchronously. Path 1: leakage point → node N23 → control center; Path 2: leakage point → node N18 → node N12 → control center; Path 3: leakage point → node N27 → control center. Each path enables AES-256 encryption, and the data packet of path 2 is fragmented into 4 128-byte units for transmission. The alarm signal reaches the control center and each emergency response terminal within 800 ms.

[0065] The position jamming is performed using multi-source deceptive signals. Distributed control nodes N15, N19, and N22 cooperatively emit the aforementioned three types of deceptive signals according to the strategy. Node N15 emits a 40 kHz sound wave signal at the top of the storage tank T-101; node N19 injects a 4-20 mA interference current into the nearby process pipeline; and node N22 sends a fake infrared data packet to the inspection robot. The jamming field covers a range of 15 meters centered on the leakage point, aiming to interfere with the sensor readings or mislead the positioning system of potential intruders (such as unauthorized drones).

[0066] After the alarm signal is distributed, the system continuously monitors the changing state of the abnormal event. The monitoring period is set to 5 seconds per time, and the dynamic trajectory of the leakage diffusion is recorded.

[0067] Table 3: State of key time points during monitoring.

[0068] Monitoring timestamp Leak source center coordinates Diffusion radius (m) Main diffusion direction 08:45:00 (125.7,348.2) 3.2 Northwest 08:45:05 (126.1,347.8) 4.5 Northwest by north 08:45:10 (126.9,347.1) 6.0 Due north 08:45:15 (127.5,346.3) 7.8 Northeast Referring to Table 3, the judgment area is predefined as the core protection range of the storage tank area: the rectangular area surrounded by the polygon vertex coordinates (120.0, 350.0), (130.0, 350.0), (130.0, 340.0), and (120.0, 340.0). The system calculates the overlap amount of the active trajectory and the judgment area. The leakage diffusion range is discretized into 200 coordinate points, and the proportion of points falling within the judgment area is calculated. For example, at 08:45:00, 186 of the 200 points are located within the judgment area, and the overlap amount proportion is 93%; by 08:45:15, as the leakage source migrates northeast, only 62 points are located within the area, and the overlap amount drops to 31%.

[0069] The logic of ruling whether to release the interference signal is triggered based on the overlap amount threshold. The system presets that when the overlap amount > 10%, the interference signal is continuously released. In this case: in the three monitoring periods from 08:45:00 to 08:45:10, the overlap amount is all > 75%, and the system maintains the interference signal emission; by the 08:45:15 period, the overlap amount drops to 31% but is still higher than the threshold, and the interference signal continues; but assuming that subsequent monitoring finds that the leakage source completely moves out of the judgment area (e.g., the coordinates migrate to (132.5, 344.1)), the falling rate of discrete points is 0%, and the system immediately terminates the interference signal emission.

[0070] The interference signal release instruction contains detailed parameter configurations. Taking the sound wave interference signal as an example: when it is ruled to be released, the system sends an instruction to node N15 containing the signal type code “S01”, the emission intensity 83 dB, the duration 300 seconds, and the modulation parameter index M12. During the execution of the instruction, the system checks the overlap amount every 30 seconds, and if it is still higher than the threshold, the system automatically renews the period.

[0071] If the overlap amount is zero (e.g., the leakage source completely moves out of the judgment area), the system enters the tracking mode. The coordinate changes of the leakage source are continuously recorded, and the position data is updated every 2 seconds. When the coordinates are detected to be outside the monitoring area boundary (set as the factory fence coordinate range) for three consecutive periods, it is determined that the abnormal event has escaped the monitoring area. At this time, the system saves the complete trajectory log, generates an event termination report, and sets the tracking task state to complete.

[0072] The operation of establishing a backup communication channel starts from the configuration process of the quantum encryption channel. The quantum encryption channel adopts a technical architecture based on a quantum key distribution protocol, and specifically applies the BB84 protocol to realize the secure distribution of keys. The system configures a quantum key generation device, which generates a sequence of photons with random polarization states using a single-photon source. At the transmitting end, a quantum signal transmitting module is integrated, including a polarization modulator and a time synchronization unit; at the receiving end, a quantum signal detection module is deployed, including a single-photon detector and a base vector selector. The initialization of the quantum encryption channel requires the establishment of an identity authentication mechanism between the transmitting and receiving parties, and the verification of the legality of the devices through digital certificate exchange. Subsequently, a quantum key distribution session is performed: the transmitting end randomly selects a base vector (horizontal / vertical or diagonal / anti-diagonal) to modulate the polarization state of the photon, and the receiving end randomly selects a measurement base vector for detection. Both parties compare the base vector selection sequence through a classical channel, and retain the measurement results under the matching base vector as the original key. The original key is processed through information reconciliation and privacy amplification to generate the final secure session key. This key is used to encrypt the alarm instructions and status data transmitted during the alarm linkage response.

[0073] The frequency band switching mechanism configuration involves presetting multiple available communication frequency bands and their corresponding switching logic. The system maintains a list of available frequency bands, including multiple sub-bands in the industrial, scientific, and medical frequency band. Each frequency band records the center frequency, bandwidth, and maximum allowed transmit power parameters. The switching trigger condition is set as a double-threshold mechanism: the signal-to-noise ratio of the main channel is below the set threshold value for more than a time threshold, or continuous interference signal strength is detected in a specific frequency band exceeding the interference tolerance value. The switching controller stores historical performance evaluation data for each frequency band, including average bit error rate and signal stability score. When any of the trigger conditions are met, the system generates a frequency band switching instruction.

[0074] The configured quantum encryption channel and frequency band switching mechanism are integrated into the backup communication unit, which is an independent hardware module containing a quantum signal transceiver, a multi-band radio frequency front-end circuit, and a fast switching control logic unit. The integration process realizes three functional couplings: control bus connection between the quantum key generation device and the main processor; antenna multiplexing interface optimization of the multi-band radio frequency front-end; real-time interrupt response interface between the switching control logic and the network stack. After the module is integrated, end-to-end functional verification is performed: simulate the main channel interruption scenario to test whether the quantum channel establishment delay meets the requirements; inject interference signals to verify the accuracy of the frequency band switching trigger and the switching completion time.

[0075] During the alarm linkage response period, when the main data transmission link is interrupted, the system activates the standby communication channel. The activation process includes three timing operations: interruption detection, quantum channel activation, and link reconstruction. Interruption detection is achieved through a heartbeat packet loss counting mechanism: if three consecutive periodic heartbeat data packets are lost, it is determined that the communication is interrupted. The system immediately sends an activation instruction to the standby communication unit, which includes a set of quantum encryption channel initialization parameters. The standby unit starts the quantum signal emission module power supply, loads the pre-generated quantum session key into the encryption engine. At the same time, the target standby frequency band is initialized, and the optimal available frequency band is selected according to historical performance data, and the radio frequency front-end operating parameters are configured. After the quantum channel is established, the communication link is reconstructed: a link reconstruction request frame is sent through the standby channel, which contains the session context information before the interruption; the receiving end replies with an acknowledgement frame after verifying the quantum encryption signature; both parties negotiate new transmission parameters, including data packet size and retransmission timeout duration; finally, the routing table is updated to redirect subsequent data transmission to the standby channel. The data confidentiality of the encrypted tunnel is maintained throughout the reconstruction process.

[0076] The process of collecting new operating state data based on the Internet of Things platform is continuously executed through the factory-deployed Internet of Things equipment network. The platform subscribes to real-time data streams from each monitoring site through standard interfaces such as MQTT / CoAP. New operating state data points include a timestamp, a unique identifier for the sensor device, and a measurement value. The system establishes a data reception buffer and processes the arriving data points in batches every 500 milliseconds. The collection process implements data integrity verification using the CRC32 verification algorithm to verify data packet integrity and discards data points that fail the verification.

[0077] The operation of optimizing the adaptive analysis model using the update training mechanism starts with the clustering of new operating state data points. The system uses the K-means clustering algorithm to process new data points. In the algorithm initialization stage, the set of cluster center coordinates used by the current model is loaded. The Euclidean distance of each new data point to all cluster centers is calculated, and it is assigned to the nearest cluster. After assignment, the center coordinates of each cluster are recalculated: the arithmetic mean of each feature dimension of all points (including newly assigned points) in the cluster is taken. After iterative calculation, the updated cluster structure is output.

[0078] Based on the updated cluster structure, abnormal point identification is performed. The Euclidean distance of each new operating state data point to its corresponding new cluster center is calculated. The system maintains distance distribution statistics for each cluster, including historical average distance and standard deviation. The abnormal point identification rule is defined as follows: if the distance of a data point to its cluster center exceeds three times the standard deviation threshold of the historical average distance of that cluster, it is marked as an abnormal point. The identification process generates an abnormal point marker list, which includes the identifiers of abnormal data points and the quantified values of the deviation.

[0079] According to the abnormal point identification result, the training parameters of the adaptive analysis model are updated. The identified abnormal points are added to the model training data set while retaining their abnormal marker attributes. The system performs an incremental training operation: the original network structure of the model is maintained, and the expanded data set is used as input. The training process uses a back propagation algorithm with sample weights, giving abnormal point samples higher weights to make the model pay more attention to the feature patterns of these samples. The weight value is dynamically calculated based on the deviation degree of the abnormal point, and the greater the deviation degree, the higher the weight. The model parameter update uses a gradient descent optimization algorithm, and the learning rate is set to 50% of the standard value to control the parameter adjustment amplitude. A new model parameter file is generated after each incremental training, and after functional verification, it is deployed to the real-time analysis engine. Non-abnormal new data points are used for periodic complete retraining: the model is retrained using the full data set every week to eliminate the parameter deviation that may be caused by incremental training. After the model update is completed, the new risk index and intrusion index calculation immediately applies the optimized parameter set.

[0080] It should be noted that the relational terms herein such as first and second and the like are used solely to distinguish one entity or action from another, without necessarily requiring or implying any such actual relationship or order between or among such entities or actions. Moreover, the terms "comprises", "comprising", or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include only those elements but can include other elements not expressly listed or inherent to such process, method, article, or apparatus.

[0081] Although embodiments of the present application have been shown and described, it is to be understood that various modifications, substitutions, replacements and variations can be made to these embodiments without departing from the principles and spirit of the present application, and the scope of the present application is defined by the appended claims and their equivalents.

Claims

1. An intelligent alarm linkage processing method for distributed factories, characterized in that: The following steps are involved: Obtain operating status data from multiple monitoring sites in distributed factories; Establishing a factory monitoring area based on the operating status data and setting a judgment area; Processing the operating status data using multi-source signal fusion technology to identify potential abnormal events; Calculating the risk index and intrusion index of the abnormal event through the adaptive analysis model, and performing weighted fusion on the risk index and intrusion index to obtain a threat index; Based on the comparison result of the threat index and the preset threshold, determining whether to trigger an alarm linkage response; When triggering an alarm linkage response, a distributed control node network is constructed and a node data transmission strategy is generated; Execute alarm signal distribution and interference signal modulation according to the node data transmission strategy; monitoring the adjustment state of the abnormal event, and determining whether to release the interference signal according to the overlap between the adjustment state and the judgment area; Establish a backup communication channel to ensure data transmission continuity during the alarm linkage response; New operating status data is collected based on the Internet of Things platform, and the adaptive analysis model is optimized using an update training mechanism.

2. The intelligent alarm linkage processing method for distributed factories according to claim 1 is characterized in that: The obtaining of the operating status data of the plurality of monitoring sites of the distributed factory specifically includes: Collecting sensor signal streams of the monitoring site, including temperature signal streams, pressure signal streams, and vibration signal streams; Performing noise characteristic analysis on the sensor signal stream to determine a data denoising threshold; Performing filtering preprocessing on the sensor signal stream according to the data denoising threshold to obtain a standard sensor signal stream; The standard sensor signal stream is input into a multi-source signal fusion unit to extract feature data.

3. The method for intelligent alarm linkage processing for distributed factories according to claim 2, characterized in that: The processing of the operating status data using a multi-source signal fusion technology specifically includes: Determining a feature extraction method and a position feature type based on data characteristic information of the feature data; According to the feature extraction method and the location feature type, the feature data is subjected to correlation feature extraction to obtain a multi-source signal correlation feature set; and a weight dynamic allocation rule is set based on the credibility of the signal source; The multi-source signal correlation feature set is fused using the dynamic weight allocation rule to determine the estimated location of the abnormal event.

4. The method for intelligent alarm linkage processing for distributed factories according to claim 1, characterized in that: The calculation of the risk index and intrusion index of abnormal events by the adaptive analysis model specifically includes: Obtaining the event type and device load quantity of the abnormal event; Determine whether the event type is a preset high-risk type, and mark the determination result as a type identifier; Calculating the risk index based on the type identifier, the number of device loads, and the event change rate; Obtaining the length of the activity track of the abnormal event in the monitoring area and the length of the activity track in the judgment area; The intrusion index is calculated according to the length of the activity trajectory.

5. The method for intelligent alarm linkage processing for distributed factories according to claim 4 is characterized in that: The weighted fusion of the risk index and the intrusion index to obtain the threat index specifically includes: Set weight factor allocation rules; Performing weighted summation on the risk index and the intrusion index according to the weight factor allocation rule; Normalizing the weighted summation result to obtain the threat index; The threat index is compared with a preset threat index threshold to generate a determination result.

6. The method for intelligent alarm linkage processing for distributed factories according to claim 1, characterized in that: The construction of a distributed control node network and generation of a node data transmission strategy specifically includes: Determine the number of transmission control nodes based on the factory area distribution and communication requirements; perform node deployment analysis based on the number of transmission control nodes to obtain multiple transmission control nodes; configure communication parameters and network topology of the transmission control nodes; and collect real-time network status and interference signal data of the transmission control nodes; The node data transmission strategy is generated through a strategy adaptive matching mechanism.

7. The method for intelligent alarm linkage processing for distributed factories according to claim 1, characterized in that: The execution of alarm signal distribution and interference signal modulation specifically includes: Based on the estimated location of the abnormal event, modulating a multi-source deception signal; distributing the alarm signal through the node data transmission strategy; The multi-source deception signal is used to perform location interference; after the alarm signal is distributed, the change state of the abnormal event is monitored.

8. The method for intelligent alarm linkage processing for distributed factories according to claim 1, characterized in that: The step of monitoring the adjustment state of the abnormal event and determining whether to release the interference signal according to the overlap between the adjustment state and the judgment area specifically includes: Obtaining the activity trajectory of the adjustment state; calculating the overlap amount between the activity trajectory and the judgment area; If the overlap is greater than zero, the interference signal is released; if the overlap is zero, the abnormal event is tracked until it escapes from the monitoring area.

9. The method for intelligent alarm linkage processing for distributed factories according to claim 1, characterized in that: The establishing of the backup communication channel specifically includes: Configure a quantum encryption channel and a frequency band switching mechanism; integrate the quantum encryption channel and the frequency band switching mechanism into a backup communication unit; and enable the backup communication channel and reestablish a new communication link when data transmission is interrupted.

10. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that: The collecting of new operating status data based on the Internet of Things platform and optimizing the adaptive analysis model using an update training mechanism specifically include: Collect new operating status data points; performing classification on the new operating status data points by a clustering algorithm; Calculating the distance between the new running state data point and the cluster center; performing outlier identification based on the distance; The training parameters of the adaptive analysis model are updated according to the outlier identification results.

Citation Information

Patent Citations

  • Chemical industry park hazard situation awareness method and system based on multi-source data fusion

    CN110705842A

  • Intelligent security monitoring alarm system for photovoltaic power station

    CN118230478A

  • Multi-defense-area intelligent linkage alarm method based on AIoT gateway and related equipment

    CN120431699A

  • Event early warning efficient management method and system based on park management

    CN120562887A

  • Method and system for generating electronic fence in dangerous area of chemical plant

    CN120599749A