A distributed factory-oriented intelligent alarm linkage processing method
By acquiring multi-source signal fusion and adaptive analysis in a distributed factory, a distributed control network is constructed, which solves the problems of untimely response and discontinuous data transmission in the handling of abnormal events in distributed factories, and realizes accurate alarm linkage and efficient data transmission, adapting to changes in factory status.
Patent Information
- Application Number
- CN202511269528.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2045-09-08
AI Technical Summary
Distributed factories suffer from problems such as untimely response, low processing efficiency, and insufficient reliability in handling abnormal events. Existing technologies are unable to fully reflect the factory's operational status, single signal analysis leads to misjudgments, centralized control is prone to paralysis, interference signals are improperly released, data transmission is discontinuous, and monitoring models cannot be adaptively updated.
By acquiring operational status data from multiple monitoring stations, a factory monitoring area is established. Multi-source signal fusion technology is used to identify abnormal events, calculate risk and intrusion indices, construct a distributed control node network, generate data transmission strategies, execute alarm signal distribution and interference signal modulation, establish backup communication channels, and optimize the adaptive analysis model.
It enables comprehensive monitoring and precise alarm linkage of distributed factories, reduces false alarms and missed alarms, improves the flexibility and fault resistance of alarm signal transmission, ensures the continuity of data transmission, adapts to changes in factory operating status, and improves the efficiency and reliability of abnormal event handling.
Smart Images

Figure CN120808556B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of factory intelligent monitoring, in particular to an intelligent alarm linkage processing method for distributed factories. BACKGROUND
[0002] In the process of industrial intelligent transformation, distributed factories have higher requirements for operation state monitoring and abnormal event processing due to the characteristics of expanded production scale and scattered equipment distribution. Traditional factory monitoring relies on single-site data collection, which is difficult to fully reflect the operation situation of the entire factory and is prone to data island phenomenon. In the prior art, the processing of operation state data mostly adopts a single signal analysis method, ignoring the correlation between different monitoring site data, which leads to potential abnormal event identification lag or misjudgment.
[0003] In terms of abnormal event evaluation, traditional methods often make judgments based on a single dimension index, such as triggering an alarm only according to the deviation of equipment operation parameters from a threshold value, lacking comprehensive consideration of event risk degree and intrusion situation, and being prone to problems such as alarm flooding or missing key abnormal events. When an alarm response needs to be started, the existing linkage mechanism mostly adopts a centralized control mode, and once the center node fails, the entire alarm system may be paralyzed, and the signal transmission strategy lacks pertinence and is difficult to adapt to the complex network environment of distributed factories.
[0004] The release timing control of interference signals is also a weak link in the prior art. Traditional methods often directly release interference signals after alarm triggering, without considering the dynamic changes of abnormal events, which may cause unnecessary interference to normal production processes. At the same time, data transmission relies too much on a single communication channel, and during the alarm linkage response period, if the main channel is interrupted, key data cannot be transmitted in time, affecting the processing efficiency of abnormal events.
[0005] Existing monitoring models are mostly static models, which are difficult to adaptively update with changes in the operation state of factory equipment aging, production process adjustment, etc., and the recognition accuracy will gradually decrease after long-term use, which cannot meet the monitoring needs of the continuous operation of distributed factories. These problems together lead to the problems of distributed factories in abnormal event processing, such as un-timely response, low processing efficiency, and insufficient reliability, which restrict the improvement of the intelligent management level of factories. SUMMARY
[0006] The present application aims to provide an intelligent alarm linkage processing method for distributed factories to solve the problems raised in the background.
[0007] To achieve the above-mentioned purpose, the present application provides an intelligent alarm linkage processing method for distributed factories, which comprises:
[0008] Acquiring running state data of a plurality of monitoring sites of a distributed factory;
[0009] Establishing a factory monitoring area based on the running state data, and setting a judgment area;
[0010] Processing the running state data using a multi-source signal fusion technology to identify a potential abnormal event;
[0011] Calculating a risk index and a break-in index of the abnormal event through an adaptive analysis model, and performing weighted fusion on the risk index and the break-in index to obtain a threat index;
[0012] Based on a comparison result of the threat index and a preset threshold, determining whether to trigger an alarm linkage response;
[0013] When the alarm linkage response is triggered, a distributed control node network is constructed, and a node data transmission strategy is generated;
[0014] According to the node data transmission strategy, alarm signal distribution and interference signal modulation are performed;
[0015] Monitoring an adjustment state of the abnormal event, and determining whether to release the interference signal according to an overlap amount of the adjustment state and the judgment area;
[0016] Establishing a backup communication channel for ensuring data transmission continuity during the alarm linkage response;
[0017] Based on an Internet of Things platform, new running state data is collected, and an update training mechanism is used to optimize the adaptive analysis model.
[0018] Preferably, the acquiring of the running state data of the plurality of monitoring sites of the distributed factory specifically includes:
[0019] Collecting sensor signal streams of the monitoring sites, including temperature signal streams, pressure signal streams, and vibration signal streams;
[0020] Performing noise characteristic analysis on the sensor signal streams to determine a data denoising threshold;
[0021] Performing filter preprocessing on the sensor signal streams according to the data denoising threshold to obtain standard sensor signal streams;
[0022] Inputting the standard sensor signal streams into a multi-source signal fusion unit to extract feature data.
[0023] Preferably, the processing of the running state data using the multi-source signal fusion technology specifically includes:
[0024] According to data characteristic information of the feature data, determining a feature extraction method and a location feature type;
[0025] According to the feature extraction method and location feature type, perform associated feature extraction on the feature data to obtain a multi-source signal associated feature set; set dynamic weight allocation rules based on signal source credibility;
[0026] The multi-source signal correlation feature set is fused using the weighted dynamic allocation rule to determine the estimated location of the abnormal event.
[0027] Preferably, the calculation of the risk index and intrusion index of the abnormal event through the adaptive analysis model specifically includes:
[0028] Obtain the event type and device load of the abnormal event;
[0029] Determine whether the event type is a preset high-risk type, and mark the determination result as a type identifier;
[0030] The risk index is calculated based on the type identifier, the number of devices under load, and the event change rate.
[0031] Obtain the length of the abnormal event's activity trajectory within the monitoring area and the length of its activity trajectory within the judgment area;
[0032] The intrusion index is calculated based on the length of the activity trajectory.
[0033] Preferably, the weighted fusion of the risk index and the intrusion index to obtain the threat index specifically includes:
[0034] Set the weight factor allocation rules;
[0035] The risk index and the intrusion index are weighted and summed according to the weighting factor allocation rule;
[0036] The weighted summation result is normalized to obtain the threat index;
[0037] The threat index is compared with a preset threshold to generate a ruling result.
[0038] Preferably, the construction of the distributed control node network and the generation of node data transmission strategies specifically include:
[0039] Based on the factory area distribution and communication requirements, determine the number of transmission control nodes; perform node deployment analysis based on the number of transmission control nodes to obtain multiple transmission control nodes; configure the communication parameters and network topology of the transmission control nodes; and collect real-time network status and interference signal data of the transmission control nodes.
[0040] The node data transmission strategy is generated through a policy adaptive matching mechanism.
[0041] Preferably, the execution of alarm signal distribution and interference signal modulation specifically includes:
[0042] Based on the estimated location of the abnormal event, a multi-source deception signal is modulated; an alarm signal is distributed through the node data transmission strategy.
[0043] The multi-source deception signal is used to perform location interference; after the alarm signal is distributed, the changing status of the abnormal event is monitored.
[0044] Preferably, the step of monitoring the adjustment state of the abnormal event and determining whether to release an interference signal based on the overlap between the adjustment state and the judgment area specifically includes:
[0045] Obtain the activity trajectory of the adjusted state; calculate the overlap between the activity trajectory and the judgment area;
[0046] If the overlap is greater than zero, the interference signal is released; if the overlap is zero, the abnormal event is tracked until it escapes the monitoring area.
[0047] Preferably, establishing a backup communication channel specifically includes:
[0048] Configure a quantum encryption channel and frequency band switching mechanism; integrate the quantum encryption channel and frequency band switching mechanism into a backup communication unit; when data transmission is interrupted, activate the backup communication channel and rebuild a new communication link.
[0049] Preferably, the step of collecting new operational status data based on the Internet of Things platform and optimizing the adaptive analysis model using an update training mechanism specifically includes:
[0050] Collect new operational status data points;
[0051] The new running state data points are classified using a clustering algorithm;
[0052] Calculate the distance between the new running state data point and the cluster center;
[0053] Anomaly identification is performed based on the distance;
[0054] The training parameters of the adaptive analysis model are updated based on the anomaly identification results.
[0055] Compared with the prior art, the beneficial effects of the present invention are:
[0056] 1. This intelligent alarm linkage processing method for distributed factories breaks through the limitations of traditional single-site data collection by acquiring operational status data from multiple monitoring stations. It comprehensively captures operational information from all areas of the factory, providing richer foundational data for subsequent anomaly identification. Establishing factory monitoring areas and defining judgment areas provides a clear spatial reference for judging abnormal events, reducing judgment bias caused by ambiguous monitoring scope.
[0057] 2. Multi-source signal fusion technology is employed to process operational status data, fully leveraging the complementarity of different types and sources of signals. This reduces the errors and interference that may exist in single-signal analysis, making the identification of potential anomalies more closely resemble actual operational conditions. An adaptive analysis model calculates risk and intrusion indices, and then performs weighted fusion to obtain a threat index. This comprehensively considers the risk level and intrusion situation of anomalies, making threat assessment more comprehensive and reducing false alarms or missed alarms caused by single-indicator assessments.
[0058] 3. The system determines whether to trigger an alarm linkage response based on a comparison between the threat index and a preset threshold, avoiding unnecessary alarm activation and making the alarm mechanism more targeted. When an alarm linkage response is triggered, a distributed control node network is constructed and a node data transmission strategy is generated, eliminating reliance on centralized control, improving the flexibility and fault tolerance of alarm signal distribution, and ensuring that signals are efficiently transmitted to relevant nodes.
[0059] 4. Alarm signal distribution and interference signal modulation are executed according to the node data transmission strategy, making alarm signal transmission more accurate and interference signals more aligned with actual needs. The adjustment status of abnormal events is monitored, and the release of interference signals is determined based on the overlap with the judgment area, avoiding indiscriminate release of interference signals and reducing unnecessary impact on normal factory operations.
[0060] 5. A backup communication channel was established, providing redundancy for data transmission during alarm and linkage responses. This reduced the risk of data transmission interruption due to primary channel failure and ensured the continuous transmission of critical information. New operational status data was collected based on the IoT platform, and the adaptive analysis model was optimized through an updated training mechanism. This enabled the model to continuously adjust as the factory's operational status changed, maintaining its ability to identify abnormal events and adapting to the dynamic changes in the long-term operation of the distributed factory. Attached Figure Description
[0061] Figure 1 This is a schematic diagram illustrating the working principle of the intelligent alarm linkage processing method for distributed factories described in this invention.
[0062] Figure 2 A sub-flowchart for acquiring runtime status data;
[0063] Figure 3 A sub-flowchart for calculating the abnormal event risk index and the intrusion index;
[0064] Figure 4 A sub-flowchart for generating distributed control node network construction and data transmission strategies. Detailed Implementation
[0065] The technical solution of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0066] Please see Figure 1 This invention provides an intelligent alarm linkage processing method for distributed factories, the method comprising:
[0067] The system acquires operational status data from multiple monitoring stations in a distributed factory; establishes a factory monitoring area based on the operational status data and sets judgment areas; processes the operational status data using multi-source signal fusion technology to identify potential abnormal events; calculates the risk index and intrusion index of the abnormal events using an adaptive analysis model, and weights and fuses the risk index and intrusion index to obtain a threat index; based on the comparison result of the threat index and a preset threshold, it determines whether to trigger an alarm linkage response; when an alarm linkage response is triggered, a distributed control node network is constructed, and a node data transmission strategy is generated. According to the node data transmission strategy, alarm signal distribution and interference signal modulation are executed.
[0068] The system monitors the adjustment status of the abnormal event and determines whether to release an interference signal based on the overlap between the adjustment status and the judgment area; it establishes a backup communication channel to ensure data transmission continuity during alarm linkage response; it collects new operating status data based on the IoT platform and uses an update training mechanism to optimize the adaptive analysis model.
[0069] Example 1: See Figure 2 When acquiring operational status data from multiple monitoring stations in a distributed factory, the specific operation involves collecting signal streams generated by sensors installed at each monitoring station. These sensor signal streams include temperature, pressure, and vibration signal streams. The temperature signal stream reflects changes in the thermal state of the equipment or environment, the pressure signal stream indicates pressure fluctuations within pipes or containers, and the vibration signal stream characterizes the operational stability of mechanical equipment. The acquisition process is completed through a data acquisition terminal deployed throughout the factory, which continuously reads the sensor outputs according to a preset sampling frequency.
[0070] Noise characteristic analysis is performed on the acquired sensor signal stream. The noise characteristic analysis process first performs a spectral transformation on the original signal stream to identify the energy distribution characteristics of different frequency bands. The analysis process calculates the relative ratio of signal energy to noise energy within a specific frequency band, identifying the main noise sources and their frequency distribution characteristics. Based on the spectral analysis results and a preset signal-to-noise ratio target value, combined with the maximum permissible error range specified in the sensor's manufacturer's specifications, a data denoising threshold is comprehensively calculated. This threshold is a dynamically changing value, set separately for different types of signal streams (temperature, pressure, vibration) and different environmental noise levels at different monitoring points.
[0071] Based on the determined data denoising threshold, the original sensor signal stream undergoes filtering preprocessing. The filtering preprocessing employs a wavelet thresholding denoising algorithm. This algorithm decomposes the signal into sub-band signals of different scales and sets differentiated threshold parameters for different frequency sub-bands. High-frequency sub-bands, corresponding to signal details or noise, are suppressed using higher thresholds; low-frequency sub-bands, corresponding to the main signal components, are preserved using lower thresholds. The thresholding method is either a hard threshold or a soft threshold function, selected based on the signal characteristics. After thresholding, the sub-band signals are reconstructed to obtain the denoised standard sensor signal stream. The standard sensor signal stream retains the main characteristics of the original signal while reducing the impact of random noise and impulse interference.
[0072] The processed standard sensor signal stream is input into the multi-source signal fusion unit for feature extraction. The multi-source signal fusion unit receives standard signal streams from different sensor types and different monitoring stations.
[0073] The process of processing operational status data using multi-source signal fusion technology first determines the subsequent feature extraction method and the types of location features to be extracted based on the data characteristics of the input feature data. Data characteristics include the signal's time-domain statistics, frequency-domain energy distribution, and signal entropy. Time-domain statistics cover parameters such as signal mean, variance, peak factor, and kurtosis; frequency-domain energy distribution is obtained through Fourier transform or wavelet packet transform, calculating the energy proportion of different frequency bands; signal entropy calculates the signal's complexity or uncertainty. Based on these data characteristics, the system automatically selects the feature extraction method: for signals with obvious periodicity, frequency-domain feature extraction is used, mainly analyzing the fundamental frequency and harmonic components; for transient or non-stationary signals, time-domain feature extraction is used, focusing on extracting waveform morphology changes. Simultaneously, the types of location features are determined, including signal source coordinate estimation (based on signal arrival time difference or intensity localization models) and signal intensity distribution maps (reflecting the signal's spatial attenuation characteristics).
[0074] Following the selected feature extraction method and location feature type, correlation feature extraction is performed on the input feature data. The goal of correlation feature extraction is to discover feature combinations from different physical locations and different types of sensors that describe the same potential anomalous event. This process employs algorithms based on mutual information or correlation analysis. The mutual information algorithm calculates the amount of information shared between different signal features, identifying feature pairs with high statistical dependence; the correlation analysis algorithm calculates the linear correlation coefficient between features, identifying synchronously changing feature combinations. The algorithm traverses all input feature data points, calculates the correlation degree between features, and when the correlation degree exceeds a preset correlation degree threshold, these features are combined into a correlation feature group. All identified correlation feature groups are summarized to form a multi-source signal correlation feature set. This feature set contains multiple feature groups, each representing a potential anomalous event and its feature manifestations in multiple dimensions.
[0075] The system uses a dynamic weight allocation rule based on the reliability of the signal source. Signal source reliability is an evaluation metric calculated based on the accuracy and stability scores of the historical data from that signal source (a specific sensor or monitoring station). The accuracy score is calculated by comparing the historical alarm records of the signal source with the finally confirmed actual abnormal event results to determine the consistency rate; the stability score is obtained by calculating the variance or drift of the signal source's output signal over a certain period. A higher reliability score indicates more reliable data from the signal source. The dynamic weight allocation rule assigns different fusion weights to related feature groups or individual features from different signal sources based on this reliability score. Features from signal sources with high reliability are assigned larger weights, while those with low reliability are assigned smaller weights. The weight allocation can be a linear proportional relationship or can use a pre-defined weight segmentation mapping table.
[0076] The multi-source signal correlation feature set is fused using a dynamically assigned weighting rule. The goal of this fusion process is to integrate all relevant feature information to determine the most likely location of the anomaly. The fusion algorithm employs either a weighted average method or an evidence theory approach. The weighted average method directly averages the estimated location coordinates in the correlated feature set according to their weights. Evidence theory methods (such as Dempster-Shafer theory) address the uncertainty and confidence information provided by the feature set regarding location estimation, merging different evidence bodies through combination rules to ultimately output a fused location estimate and its confidence interval. The fusion process integrates all weighted location information to calculate the estimated location of the anomaly. This location information is output in three-dimensional coordinates, typically including longitude, latitude, and altitude, along with a confidence interval or probability value, characterizing the reliability of the location estimate. The output estimated location information of the anomaly serves as a key input for subsequent risk assessment and response decisions.
[0077] Example 2: See Figure 3When calculating the risk index and intrusion index of an abnormal event using an adaptive analysis model, the system first obtains the event type information and the number of affected devices associated with the abnormal event. Event type information is obtained by matching the characteristic description of the abnormal event with a pre-defined event type library. This library contains various predefined abnormal event categories, such as equipment failure, environmental intrusion, and parameter exceeding limits, each with a specific identifier and attribute description. The system then compares the identified event type with a pre-defined list of high-risk types. This list contains specific event categories pre-configured by the system that may cause serious accidents or significant losses, such as critical equipment failure, leakage of toxic or hazardous substances, and intrusion into core control systems. The comparison result is marked as a type identifier. The type identifier is a discrete value or a Boolean value used to indicate whether the abnormal event belongs to a high-risk type; for example, a value of 1 represents a high-risk type, and a value of 0 represents a non-high-risk type, or a specific enumerated value can be used for identification.
[0078] The system retrieves the number of devices affected by the anomaly. The number of devices affected refers to the total number of critical production equipment, control units, or process nodes that are directly in an abnormal state, have limited functionality, or face risks due to the anomaly during factory operation. This number is obtained by querying the factory's equipment topology database, which records the dependencies and impact ranges between devices. Based on the location and type of the anomaly, the system analyzes the list of associated devices and counts the number of devices directly affected.
[0079] The system obtains the rate of change of the anomaly. The rate of change quantifies how quickly the anomaly develops. The system calculates this rate by analyzing the time-series data changes of key parameters associated with the anomaly. The selection of key parameters depends on the event type; for example, for equipment failure events, the system might focus on the rate of temperature rise or the degree of vibration intensification, while for environmental intrusion events, it might focus on changes in movement speed or intrusion depth. The system calculates the derivative or difference value of the selected key parameter within a certain time window, and then obtains a relatively stable rate of change value through sliding window averaging or exponential smoothing.
[0080] Based on the obtained type identifier, equipment load quantity, and event change rate, the system calculates a risk index. The risk index calculation function involves the combined operation of these three input parameters. The type identifier serves as a weighting coefficient factor; a higher coefficient value is assigned to a high-risk type, and a lower coefficient value is assigned otherwise. The equipment load quantity is processed through a linear or nonlinear mapping function. This function is designed based on the factory's risk assessment model and may include logarithmic transformation, piecewise linear transformation, or weighted calculation based on equipment importance to reflect the degree of impact of different equipment quantities on the overall risk. The event change rate serves as a risk amplification factor; the higher the change rate, the more significant its amplification effect. The system performs a weighted combination operation on the mapped equipment load quantity value, the coefficient-adjusted type identifier value, and the event change rate amplification factor. The specific weighting weights can be configured according to the risk preferences of different areas or different event types within the factory. The final output is a value representing the potential harm level of the current abnormal event, i.e., the risk index.
[0081] (1) Definition of “Preset High-Risk Type” and “Type Identifier”
[0082] Preset high-risk types: These refer to abnormal events that may cause major safety accidents, equipment damage, or production interruptions. Specifically, they include: ① Failure of critical production equipment (such as reactor rupture, CNC machine tool spindle jamming, hydraulic system rupture); ② Hazardous substance leakage (such as toxic gas leakage, flammable liquid leakage, corrosive liquid leakage); ③ Intrusion into core control systems (such as unauthorized access to PLC control systems, data tampering). The "Type Identifier (T)" for these events is uniformly set to 0.8 (with a value range of 0-1, the higher the value, the greater the risk base weight).
[0083] Non-preset high-risk types: These refer to abnormal events that have a minor impact on production and pose no direct safety risk. Specifically, they include: ① Abnormal vibration of ordinary equipment (amplitude exceeding the baseline value by 10%-20%, but not reaching the equipment damage threshold); ② Slight deviation of environmental parameters (temperature / humidity exceeding the normal range by ±5℃ / ±10%, without affecting equipment operation); ③ Failure of a single non-core sensor (such as the failure of the temperature sensor in the auxiliary lighting area, which does not affect the main production chain). The "Type Identifier (T)" for this type of event is uniformly set to 0.3.
[0084] (2) Statistical rules and mapping methods for “equipment load quantity”
[0085] Scope of statistics: Only includes "critical production equipment, control units or process nodes directly affected by abnormal events", excluding irrelevant auxiliary equipment (such as workshop lighting, ventilation equipment, non-production computers, etc.).
[0086] Example: If the CNC machine tool vibrates abnormally, the statistical scope is "the CNC machine tool + 2 adjacent conveying devices (responsible for the transfer of raw materials / finished products of the machine tool) + the corresponding PLC control unit", a total of 3 sets of equipment. Irrelevant workshop lighting equipment is not included.
[0087] Numerical mapping rules: The statistical "number of equipment loads (N)" is mapped to a standardized value of 0-1 (denoted as N'). The mapping logic is based on the principle that "the more equipment there are, the higher the risk." Specifically: ① When 1≤N≤5: N' = 0.02 + (N-1)×0.018 (e.g., when N=3, N'=0.02+(3-1)×0.018=0.056, rounded to two decimal places as 0.06); ② When 6≤N≤10: N'= 0.1 + (N-6)×0.016 (e.g., when N=8, N'=0.1+(8-6)×0.016=0.132, rounded to two decimal places as 0.13); ③ When N>10: N' is uniformly taken as 0.2 (because more than 10 key devices are affected, which has reached the high risk threshold, no further superposition is needed).
[0088] (3) Calculation parameters, formulas and sampling rules for “event change rate”
[0089] Parameter matching: Based on the type of abnormal event, determine the core calculation parameter for the "event change rate" (i.e., the "key indicator characterizing the speed of event development"). Specifically: ① Temperature-related anomalies: Core parameter = "current temperature value - normal operating temperature threshold of the equipment" (e.g., if the normal operating threshold of the equipment is 25℃ and the current temperature is 30℃, then the parameter value is 5℃); ② Vibration-related anomalies: Core parameter = "current vibration amplitude value - equipment reference vibration amplitude value" (e.g., if the equipment reference amplitude is 0.5mm / s² and the current amplitude is 1.2mm / s², then the parameter value is 0.7mm / s²); ③ Leakage-related anomalies: Core parameter = "current leakage concentration value - safe concentration threshold" (e.g., if the safe concentration threshold is 10ppm and the current concentration is 25ppm, then the parameter value is 15ppm).
[0090] Calculation formula: Event change rate (V) = (Current core parameter value - Initial core parameter value) / Data sampling time interval (Δt).
[0091] Sampling period rules: Δt is set according to the "dynamic characteristics" of abnormal events: ① Dynamic anomalies (such as leakage and diffusion, mobile intrusion): Δt=1s (high frequency sampling to capture rapid changes); ② Static anomalies (such as slow overheating of equipment, slow increase in vibration): Δt=5s (low frequency sampling to avoid data redundancy).
[0092] Standardization: The calculated V is mapped to a standardized value (V') of 0-1, with the following rules: ① When V ≥ V_max (the "dangerous rate threshold" for this type of anomaly, such as vibration type V_max = 0.2 mm / s³): V' = 1.0; ② When V ≤ V_min (the "negligible rate threshold" for this type of anomaly, such as vibration type V_min = 0.02 mm / s³): V' = 0.1; ③ When V_min < V < V_max: V' = 0.1 + (V - V_min) × (0.9 / (V_max - V_min)) (linear interpolation).
[0093] (4) The final calculation formula for the risk index: RI = (T×0.4) + (N'×0.3) + (V'×0.3);
[0094] (Note: 0.4, 0.3, and 0.3 are the weights of type identifier, equipment load, and event rate, set based on the engineering experience that "type identifier has the greatest impact on risk, followed by equipment load and rate," which conforms to the core logic of "weighted calculation.")
[0095] Simultaneously, the system calculates the intrusion index of the abnormal event. Calculating the intrusion index requires obtaining the length of the abnormal event's trajectory within the factory's monitoring area and its trajectory length within a preset judgment area. The trajectory refers to the spatial path of the abnormal event, formed by the system continuously tracking the sequence of the abnormal event's location coordinates. The monitoring area is the geographical scope covered by the entire factory safety monitoring system, defined by geographical coordinate boundaries during system initialization. The judgment area is one or more core or sensitive sub-areas set within the monitoring area, such as areas with concentrated critical equipment, hazardous materials storage areas, and the area surrounding the control center; its boundaries are also defined by geographical coordinates.
[0096] The system acquires the sequence of location coordinates for the abnormal event. Based on these coordinates, the system calculates the length of its trajectory within the monitoring area. The trajectory length calculation employs a spatial integration method. The system connects consecutive location coordinates in chronological order to form trajectory segments, calculates the Euclidean distance of each segment, and then sums the distances of all segments to obtain the total trajectory length within the monitoring area. Using the same method, the system calculates the length of the abnormal event's trajectory within the judgment area. The trajectory length calculation within the judgment area only accumulates the lengths of those segments that are completely within the boundary of the judgment area or intersect the boundary and are located inside it. The system uses spatial geometric algorithms to determine the positional relationship between each trajectory segment and the polygonal boundary of the judgment area, accurately calculating the length of the segment within the judgment area.
[0097] The system calculates the intrusion index based on the two calculated trajectory length values. The intrusion index is defined as the ratio of the length of the activity trajectory within the judgment area to the length of the activity trajectory of the abnormal event throughout the entire monitoring area. This ratio is a value between 0 and 1, reflecting the proportion of the abnormal event's activity within the sensitive judgment area relative to its activity throughout the entire monitoring area. A higher ratio indicates a higher relative degree of the abnormal event's stay or activity within the sensitive area.
[0098] (1) Data collection equipment and sampling rules for "activity trajectory"
[0099] Data Acquisition Equipment: Based on the descriptions of "IoT Platform" and "Monitoring Station", the trajectory acquisition equipment is specified as follows: ① Dynamic anomalies (such as intrusion, leakage and spread): UWB positioning module (positioning accuracy ±10cm, supports real-time coordinate output); ② Static anomalies (such as local overheating and spread of equipment): distributed infrared sensor array (deployed at 5m intervals, trajectory is calculated sequentially by sensor triggering).
[0100] Sampling frequency rules: ① Dynamic anomalies (such as personnel intrusion, mobile device malfunction): sampling frequency = 1 time / second (high frequency captures location changes); ② Static anomalies (such as leakage diffusion, temperature diffusion): sampling frequency = 1 time / 5 seconds (low frequency captures range changes to avoid data redundancy).
[0101] (2) Criteria for defining “monitoring area” and “judgment area”
[0102] Monitoring area definition: Based on the physical coordinates of the factory's GIS system, and adhering to the principle of "covering the entire production area," rectangular / polygonal boundaries are used for definition. Examples: ① Monitoring area of the machining workshop: A rectangular area with coordinate boundaries of (X1=100m, Y1=50m), (X2=200m, Y2=50m), (X3=200m, Y3=150m), and (X4=100m, Y4=150m) (area 100m×100m=10000㎡); ② Monitoring area of the chemical plant's tank area: A rectangular area with coordinate boundaries of (X1=120m, Y1=340m), (X2=130m, Y2=340m), (X3=130m, Y3=350m), and (X4=120m, Y4=350m) (area 10m×10m=100㎡).
[0103] Delineation of the assessment area: This is defined as the "core sensitive area" within the monitoring area, based on the principle of "protecting critical equipment / hazardous substances." A circular / rectangular boundary is used for definition. Examples: ① CNC machine tool assessment area: A circular area with a radius of 5m centered on the equipment's center point (X=150m, Y=100m) (covering the equipment itself and the surrounding operating area); ② Storage tank T-101 assessment area: A circular area with a radius of 10m centered on the storage tank's center point (X=125.7m, Y=348.2m) (covering the storage tank itself and the leakage emergency zone).
[0104] (3) Specific calculation method for "activity trajectory length"
[0105] Calculation of total trajectory length (Lm) within the monitoring area: Extract the continuous position coordinate sequence within the sampling period: P1(X1,Y1), P2(X2,Y2), ..., Pn(Xn,Yn) (n is the number of samplings); Calculate the distance between two adjacent points using the Euclidean distance formula: d_i=√[(X_i - X_{i-1})² + (Y_i - Y_{i-1})²] (i from 2 to n); Total trajectory length Lm=Σd_i (i from 2 to n, summing the distances of all adjacent points).
[0106] Calculation of trajectory length (Lp) within the judgment area: The "ray method" is used to determine whether each trajectory segment (PiPi-1) falls within the judgment area: Draw a ray from any point of the segment towards the positive X-axis, and count the number of intersections between the ray and the boundary of the judgment area. If the number is odd, the segment is within the area; if the number is even, it is outside the area. For "segments completely within the area", they are directly included in d_i. For "segments partially within the area", the intersections between the segment and the boundary of the area are calculated, and the distance of the "partial part within the area" is included. For "segments completely outside the area", they are not included. The trajectory length within the judgment area Lp = Σ "distance of segments within the area".
[0107] (4) The final formula for calculating the intrusion index: II = (Lp / Lm) × 100%;
[0108] (Note: The intrusion index is the "proportion of the trajectory length in the judgment area to the total trajectory length". The higher the proportion, the higher the degree of intrusion of the abnormal event into the core sensitive area. The value range is 0%-100%.) Example: Lm=3.69m, Lp=2.95m, then II=(2.95 / 3.69)×100%≈80%.
[0109] The calculated risk index and intrusion index are weighted and fused to generate the final threat index. The system sets weighting factor allocation rules, defining the weight ratio of the risk index and intrusion index in the fusion calculation. These weighting factor allocation rules are not fixed but dynamically adjusted based on the factory's current safety operation level. The safety operation level is a comprehensive indicator reflecting the overall safety status of the factory, which may be determined by multiple factors, such as the presence of other high-risk events, production load levels, and environmental safety assessment results. The rules stipulate that when the factory's safety operation level is high, the weight of the intrusion index increases accordingly, meaning that in a relatively safe environment, attention is increased to intrusion behavior in sensitive areas; conversely, when the safety operation level is low, the weight of the risk index increases, focusing more on the potential harm of the event itself. The specific weight adjustment mapping relationship is stored in the configuration file.
[0110] Based on the real-time weighting factor allocation rules, the system performs a weighted summation calculation on the risk index and the intrusion index. The risk index is multiplied by its corresponding dynamic weighting factor, and the intrusion index is multiplied by its corresponding dynamic weighting factor. The two products are then added together to obtain a weighted sum.
[0111] The weighted sum is normalized. The goal of normalization is to map the calculation result to a standardized numerical range for subsequent comparison with a preset threshold. The system uses min-max scaling or other normalization methods for normalization. Min-max scaling subtracts the historical minimum weighted sum from the current weighted sum, then divides by the difference between the historical maximum and minimum weighted sum, ultimately mapping the result to the range of 0 to 1. The historical maximum and minimum values are continuously updated based on actual calculation results during system operation. The normalized value is the threat index.
[0112] (1) The specific basis and values of the "weight factor allocation rule"
[0113] Weighting is based on dynamic adjustment of the "factory area risk level"—high-risk areas (such as reaction kettle areas and hazardous materials warehouses) prioritize the "risk index" (the hazard of the event itself), low-risk areas (such as storage areas and office areas) prioritize the "intrusion index" (intrusion into sensitive areas), and medium-risk areas (such as processing workshops) are balanced between the two.
[0114] The specific weighting table (risk index weight W1, intrusion index weight W2, W1+W2=1.0) is shown in Table 1 below:
[0115] Table 1: Correspondence between Factory Area Risk Level and Index Weight Allocation
[0116] Factory area risk level Risk index weight (W1) Break-in index weight (W2) Applicable area examples High risk 0.6 0.4 Reaction kettle area, dangerous goods warehouse Medium risk 0.5 0.5 Mechanical processing workshop Low risk 0.4 0.6 Ordinary storage area, office area
[0117] (Note: The weight values are based on the goal of "solving false alarms and missed alarms"—high-risk areas focus on risk and avoid missing high-risk events; low-risk areas focus on intrusion and avoid false alarms of non-intrusive events.)
[0118] (2) Specific formulas for "weighted summation" and "normalization".
[0119] Weighted summation formula: Weighted summation (S) = Risk index (RI) × W1 + Intrusion index (II, converted to 0-1 decimal) × W2; (Note: Intrusion index II needs to be converted from "%" to "decimal", such as II = 80% converted to 0.8).
[0120] Normalized formula: Threat Index (TI) = (S - Smin) / (Smax - Smin);
[0121] Wherein: ① Smin: the minimum weighted sum of "similar abnormal events" in the past 6 months (extracted from the factory IoT platform operation logs, reflecting the "lowest risk level"); ② Smax: the maximum weighted sum of "similar abnormal events" in the past 6 months (reflecting the "highest risk level"); (Note: after normalization, TI takes a value range of 0-1, which is convenient for comparison with a unified threshold).
[0122] (3) The basis and specific values for setting the “preset threshold”
[0123] Threshold setting basis: Based on the correlation analysis of "threat index of historical abnormal events - actual loss", ensure that the threshold corresponds to the "acceptable loss boundary" - when TI≥threshold, the event may cause losses beyond the acceptable range, and an alarm needs to be triggered; when TI<threshold, the event loss is controllable and no alarm needs to be triggered.
[0124] The specific threshold table (corresponding to the risk level of the area) is shown in Table 2 below:
[0125] Table 2: Correspondence between Factory Area Risk Level and Preset Threat Index Threat Index Threat Index
[0126] Factory area risk level Threat index preset threshold (TI threshold) Acceptable loss boundary examples High risk 0.5 Single event loss < 20,000 yuan Medium risk 0.6 Single event loss < 50,000 yuan Low risk 0.7 Single event loss < 10,000 yuan
[0127] Example: In the medium-risk area, if TI=0.54<0.6, the decision is "no alarm linkage response to be triggered"; if TI=0.62≥0.6, the decision is "alarm linkage response to be triggered".
[0128] The generated threat index is compared with a preset threat index threshold. The preset threat index threshold is not a single value, but rather multiple levels are set based on the risk levels of different geographical areas within the factory. Lower trigger thresholds are set for high-risk areas (such as the reactor area in a chemical plant), while higher trigger thresholds are set for low-risk areas (such as ordinary storage areas). The system selects the corresponding preset threshold level for comparison based on the current location of the abnormal event or its main activity area. The comparison result generates a ruling. The ruling result is a Boolean value indicating whether the current threat index exceeds the preset threshold for the corresponding area. If the threat index is greater than or equal to the preset threshold, the ruling result is True, indicating that an alarm linkage response needs to be triggered; if the threat index is less than the preset threshold, the ruling result is False, indicating that the threat level of the current abnormal event does not meet the standard for triggering a response. This ruling result directly determines whether to execute subsequent steps S106 and the subsequent alarm linkage response process.
[0129] Example 3: See Figure 4 When constructing a distributed control node network and generating node data transmission strategies, the system first determines the number of transmission control nodes based on the actual physical layout of the factory and its communication performance requirements. The factory area distribution data is obtained from an integrated geographic information system database, which stores the precise boundary coordinates and area information of each area within the factory. Communication requirements are quantified through analysis of multiple parameters, including the density of monitoring point distribution, the required data update frequency for each monitoring point (e.g., sampling times per second), and the average size of a single data packet (in bytes). The system calculates the expected data traffic load per unit area, and, combined with the theoretical bandwidth limit of the wireless communication module and the actual environmental attenuation factor, deduces the minimum number of nodes required to meet communication needs. Considering the redundancy design requirements of the communication link, a certain proportion of redundant nodes are added to the minimum number of nodes, ultimately determining the total number of transmission control nodes.
[0130] Based on a determined total number of nodes, the system performs node deployment analysis. The goal of this analysis is to determine the optimal physical installation coordinates for each transmission control node. Key factors considered in this process include: achieving uniform coverage across the factory area to avoid signal blind spots; ensuring redundant communication paths to maintain communication even if a single path is interrupted; and the attenuation effect of obstacles in the physical environment (such as large equipment, metal structures, and walls) on the wireless signal. The analysis employs optimization algorithms from graph theory. The system discretizes the factory area into a grid of points, each representing a candidate node location. The reachability between any two candidate locations is calculated, depending on distance, obstacle penetration loss, and antenna gain. A coverage quality index Q is defined. cov Quantitative deployment solution performance:
[0131] Q cov =min(1,∑ N i=1 A i / A total )
[0132] Where: N is the total number of deployed transmission control nodes; A i Let A be the area of the effective coverage region of the I-th node (the actual coverage range calculated after considering the signal strength threshold and obstacle attenuation); total Q represents the total area of the factory's target monitoring area. cov The closer the value is to 1, the more comprehensive the area coverage. Simultaneously, network redundancy metrics, such as average node connectivity, are calculated. The system utilizes heuristic search algorithms (such as simulated annealing or genetic algorithms) to find the network that satisfy Q. cov Given a target value greater than 0.95, we search for the combination of node locations that maximizes network redundancy or minimizes total deployment cost, and finally output a three-dimensional coordinate deployment scheme for multiple transmission control nodes.
[0133] Configure the communication parameters and network topology of the transmission control nodes. Communication parameters cover physical layer and data link layer settings: the wireless communication frequency band is selected from several preset industrial unlicensed frequency bands; the modulation method is selected based on transmission distance and anti-interference requirements, such as QPSK or 16QAM; the transmit power is dynamically adjustable according to coverage distance requirements; the data packet format defines the header structure, payload length, and checksum method. The network topology selection is based on node deployment locations and communication reliability requirements. In areas with small node spacing and extremely high reliability requirements, a mesh topology may be used to achieve multi-path redundancy; in areas with widely distributed nodes and a central convergence point, a star topology or hierarchical topology may be used. The topology decision algorithm automatically selects the topology after evaluating factors such as the average hop count between nodes, expected end-to-end delay, and fault isolation capability. The selected topology determines the logical connection relationships between nodes and the basic routing rules.
[0134] The system collects real-time network operation status data and external interference signal data from the transmission control node. Real-time network status data includes: inter-node link quality indication, which reflects the ratio of received signal strength to background noise level; data packet transmission delay, recording the actual transmission time of data packets from the source node to the destination node; and packet loss rate, statistically analyzing the proportion of successfully acknowledged data packets sent within a specific time window. External interference signal data is collected by the node's built-in spectrum sensing module, including the strength values of non-system emission source signals detected within the system's operating frequency band, as well as the spectral characteristics of the signal (such as bandwidth, center frequency, and modulation type). This data is periodically sampled and aggregated to the network management unit.
[0135] The final node data transmission strategy is generated through a policy adaptive matching mechanism. At its core is a policy library containing various predefined policy templates and a decision engine that selects or fine-tunes policies based on real-time data. The decision engine receives real-time network status and interference signal data reported by the transmission control node. Based on link quality indicators and packet loss rate data, it assesses the stability level of each current communication path. If persistent strong interference signals are detected in a specific frequency band, the decision engine triggers a frequency hopping strategy, selecting a preset frequency switching sequence from the policy library to instruct the node to switch to a less interfered backup frequency band. If the end-to-end latency exceeds the application tolerance threshold, the decision engine evaluates the paths in the current topology, potentially choosing an alternative route to bypass the high-latency node or activating a packet fragmentation transmission mechanism to reduce single transmission duration. In environments with severe interference, it may choose to increase the redundancy of forward error correction coding or temporarily increase transmit power. The policy adaptive matching mechanism dynamically integrates the above decision logic to generate specific and operable node data transmission strategies. This strategy defines in detail the data transmission path selection rules (such as which relay nodes should be prioritized for a specific target node), communication frequency hopping sequences (such as trigger conditions, switching time points, and target frequency list), packet fragmentation size and reassembly rules, and threshold conditions for dynamic adjustment of transmission power. The generated complete strategy is compiled into a configuration instruction set and distributed to all relevant transmission control nodes within the factory for loading and execution via the management channel. Each node updates its local communication protocol stack parameters and routing table according to the received instruction set, ensuring that the entire network operates in coordination according to the new strategy.
[0136] Example 4: When performing alarm signal distribution and interference signal modulation, the system operates based on the estimated location of the identified abnormal event. Taking a toxic gas leak in a chemical plant's tank area as an example: the system determines the leak source is located 3 meters northwest of tank T-101 (coordinates X=125.7, Y=348.2) through multi-source signal fusion; this location is the estimated location of the abnormal event. The system modulates a multi-source deception signal based on this location. A multi-source deception signal refers to a sequence of interference signals that differ in signal characteristics but work together. For the gas leak event, the system generates three types of deception signals: the first simulates the acoustic signal of a normal pressure relief valve, with a carrier frequency set at 40kHz, loaded with a specific cyclic pseudo-random code sequence, and modulated using FSK; the second simulates the baseline drift signal of an environmental monitoring sensor, superimposed with a low-frequency sawtooth wave on a 4-20mA current loop; the third generates a fake infrared thermal image data packet, simulating a normal surface temperature distribution of the tank. These signals are directionally transmitted through distributed control nodes, covering the area surrounding the leak source.
[0137] Alarm signals are distributed using a node data transmission strategy. The alarm signal contains a structured data packet: the event type code is set to "HZDQXL" (chemical gas leak), the location coordinates field is written as (125.7, 348.2), the threat level identifier is set to "A1" (highest level), and a timestamp marks the leak start time. The distribution process strictly follows the strategy generated in Example 3: due to the deployment of mesh topology nodes in the area, data transmission is sent synchronously along three independent paths. Path 1: Leak point → Node N23 → Control Center; Path 2: Leak point → Node N18 → Node N12 → Control Center; Path 3: Leak point → Node N27 → Control Center. AES-256 encryption is enabled for each path, and the data packet for Path 2 is fragmented into four 128-byte units for transmission. The alarm signal arrives at the control center and each emergency response terminal within 800ms.
[0138] Location interference is performed using multi-source deception signals. Distributed control nodes N15, N19, and N22 coordinately transmit the aforementioned three types of deception signals according to a strategy. Node N15 transmits a 40kHz acoustic signal at the top of tank T-101; node N19 injects a 4-20mA interference current into nearby process pipelines; and node N22 sends false infrared data packets to the inspection robot. The interference field covers an area with a radius of 15 meters centered on the leak point, aiming to interfere with the sensor readings of potential intruders (such as unauthorized drones) or mislead their positioning systems.
[0139] After the alarm signal is distributed, the system continuously monitors the changing status of the abnormal event. The monitoring cycle is set to 5 seconds per instance, recording the dynamic trajectory of the leak's spread.
[0140] Table 3: Status at key time points during monitoring.
[0141] Monitoring timestamp Leak source center coordinates Diffusion radius (m) Main diffusion direction 08:45:00 (125.7,348.2) 3.2 Northwest 08:45:05 (126.1,347.8) 4.5 Northwest by north 08:45:10 (126.9,347.1) 6.0 Due north 08:45:15 (127.5,346.3) 7.8 Northeast
[0142] Referring to Table 3, the judgment area is predefined as the core protection zone of the tank area: a rectangular area enclosed by the polygon vertices (120.0, 350.0), (130.0, 350.0), (130.0, 340.0), and (120.0, 340.0). The system calculates the overlap between the activity trajectory and the judgment area. The leakage diffusion range is discretized into 200 coordinate points, and the proportion of points falling within the judgment area is calculated. For example, at 08:45:00, 186 of the 200 points are located within the judgment area, with an overlap ratio of 93%; by 08:45:15, as the leakage source migrates northeast, only 62 points are located within the area, and the overlap drops to 31%.
[0143] The logic for determining whether to release the interference signal is based on an overlap threshold trigger. The system is pre-set to continuously release the interference signal when the overlap exceeds 10%. In this case: during the three monitoring cycles from 08:45:00 to 08:45:10, the overlap was consistently greater than 75%, and the system maintained interference signal transmission; by the 08:45:15 cycle, the overlap had decreased to 31%, still exceeding the threshold, and the interference signal continued; however, assuming subsequent monitoring reveals that the leak source has completely moved out of the judgment area (e.g., coordinates have shifted to (132.5, 344.1)), and the discrete point inclusion rate is 0%, the system immediately terminates interference signal transmission.
[0144] The interference signal release command includes detailed parameter configurations. Taking acoustic interference signals as an example: when a release is determined, the system sends a command to node N15 containing the signal type code "S01", transmission strength 83dB, duration 300 seconds, and modulation parameter index M12. During command execution, the system checks the overlap every 30 seconds; if it is still higher than the threshold, it automatically extends the release period.
[0145] If the overlap reaches zero (e.g., the leak source completely moves out of the detection area), the system enters tracking mode. It continuously records changes in the leak source coordinates, updating the location data every 2 seconds. When the coordinates exceed the monitoring area boundary (set to the factory perimeter) for three consecutive cycles, the system determines that the abnormal event has escaped the monitoring area. At this point, the system saves a complete trajectory log, generates an event termination report, and sets the tracking task status to complete.
[0146] Example 5: The establishment of a backup communication channel begins with the configuration process of the quantum encrypted channel. The quantum encrypted channel employs a technology architecture based on a quantum key distribution protocol, specifically using the BB84 protocol for secure key distribution. The system is configured with a quantum key generation device, which generates a sequence of photons with random polarization states using a single-photon source. At the transmitter, a quantum signal transmission module is integrated, including a polarization modulator and a time synchronization unit; at the receiver, a quantum signal detection module is deployed, including a single-photon detector and a basis vector selector. Initialization of the quantum encrypted channel requires establishing an authentication mechanism between the sender and receiver, verifying the device's legitimacy through digital certificate exchange. Subsequently, a quantum key distribution session is executed: the transmitter randomly selects a basis vector (horizontal / vertical or diagonal / anti-diagonal) to modulate the photon polarization state, and the receiver randomly selects a measurement basis vector for detection. Both parties publicly compare the basis vector selection sequences through a classical channel, retaining the measurement results under the matching basis vectors as the original key. The original key undergoes information harmonicization and privacy amplification processing to generate the final secure session key. This key is used for transmitting alarm commands and status data during encrypted alarm linkage responses.
[0147] The frequency band switching mechanism configuration involves pre-setting multiple available communication frequency bands and their corresponding switching logic. The system maintains a list of available frequency bands, including multiple sub-bands within the industrial, scientific, and medical frequency bands. Each frequency band records its center frequency, bandwidth, and maximum permissible transmit power parameters. The switching trigger condition is set as a dual-threshold mechanism: the primary channel signal-to-noise ratio is lower than a set threshold for a continuous period exceeding a time threshold, or continuous interference signal strength exceeding the interference tolerance value is detected in a specific frequency band. The switching controller stores historical performance evaluation data for each frequency band, including average bit error rate and signal stability score. When either trigger condition is met, the system generates a frequency band switching command.
[0148] The configured quantum encryption channel and frequency band switching mechanism are integrated into the backup communication unit, which is an independent hardware module containing a quantum signal transceiver, a multi-band RF front-end circuit, and a fast switching control logic unit. The integration process achieves three functional couplings: the control bus connection between the quantum key generation device and the main processor; optimization of the antenna multiplexing interface of the multi-band RF front-end; and the real-time interrupt response interface between the switching control logic and the network stack. After module integration, end-to-end functional verification is performed: simulating a main channel interruption scenario to test whether the quantum channel establishment delay meets the requirements; and injecting interference signals to verify the accuracy of frequency band switching triggering and the switching completion time.
[0149] During alarm linkage response, if the main data transmission link is interrupted, the system activates the backup communication channel. The activation process includes three sequential operations: interruption detection, quantum channel activation, and link reconstruction. Interruption detection is achieved through a heartbeat packet loss counting mechanism: the loss of three consecutive periodic heartbeat data packets is considered a communication interruption. The system immediately sends an activation command to the backup communication unit, which contains the quantum encryption channel initialization parameter set. The backup unit starts the quantum signal transmission module power supply and loads the pre-generated quantum session key into the encryption engine. Simultaneously, it initializes the target backup frequency band, selects the optimal available frequency band based on historical performance data, and configures the RF front-end operating parameters. After the quantum channel is established, communication link reconstruction is performed: a link reconstruction request frame is sent through the backup channel, which contains the session context information before the interruption; the receiving end verifies the quantum encryption signature and replies with an acknowledgment frame; both parties negotiate new transmission parameters, including data packet size and retransmission timeout duration; finally, the routing table is updated to redirect subsequent data transmission to the backup channel. End-to-end data confidentiality protection of the encrypted tunnel is maintained during the reconstruction process.
[0150] The process of collecting new operational status data based on an IoT platform is continuously executed through the network of IoT devices deployed in the factory. The platform subscribes to real-time data streams from each monitoring station via standard interfaces such as MQTT / CoAP. New operational status data points include a timestamp, a unique identifier for the sensor device, and a triplet of the measured value. The system establishes a data receiving buffer and processes arriving data points in batches at 500-millisecond intervals. Data integrity verification is implemented during the acquisition process, using the CRC32 checksum algorithm to verify data packet integrity and discarding data points that fail verification.
[0151] The optimization of the adaptive analysis model using the update training mechanism begins with the clustering of new running state data points. The system employs the K-means clustering algorithm to process new data points. During algorithm initialization, the set of cluster center coordinates used by the current model is loaded. The Euclidean distance from each new data point to all cluster centers is calculated, and the data point is assigned to the nearest cluster. After assignment, the center coordinates of each cluster are recalculated by taking the arithmetic mean of each feature dimension of all points within the cluster (including newly assigned points). After iterative calculation, the updated cluster structure is output.
[0152] Based on the updated clustering structure, outlier identification is performed. The Euclidean distance from each newly generated data point to its new cluster center is calculated. The system maintains distance distribution statistics for each cluster, including historical average distance and standard deviation. The outlier identification rule is defined as follows: if the distance from a data point to its cluster center exceeds three times the standard deviation threshold of the cluster's historical average distance, it is marked as an outlier. The identification process generates an outlier label list, containing outlier data point identifiers and quantified deviation values.
[0153] Based on the anomaly identification results, the training parameters of the adaptive analysis model are updated. Identified anomalies are added to the model's training dataset while retaining their anomaly label attributes. The system performs incremental training: maintaining the original network structure of the model, using the expanded dataset as input. The training process employs a weighted backpropagation algorithm, assigning higher weights to anomaly samples to make the model focus more on the feature patterns of these samples. The weight values are dynamically calculated based on the degree of deviation of the anomalies; the greater the deviation, the higher the weight. Model parameter updates use a gradient descent optimization algorithm, with the learning rate set to 50% of the standard value to control the magnitude of parameter adjustments. After each incremental training iteration, a new model parameter file is generated, functionally validated, and then deployed to the real-time analysis engine. New, non-anomaly data points are used for periodic full retraining: the model is retrained weekly using the full dataset to eliminate parameter shifts that may be introduced by incremental training. After the model update, the new risk index and intrusion index are immediately calculated using the optimized parameter set.
[0154] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0155] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for intelligent alarm linkage processing in distributed factories, characterized in that, Includes the following steps: Obtain operational status data from multiple monitoring stations in the distributed factory; Based on the aforementioned operational status data, a factory monitoring area is established, and a judgment area is defined; The operational status data is processed using multi-source signal fusion technology to identify potential abnormal events; The risk index and intrusion index of abnormal events are calculated by an adaptive analysis model, and the threat index is obtained by weighted fusion of the risk index and intrusion index. Based on the comparison result between the threat index and the preset threshold, a decision is made on whether to trigger an alarm linkage response. When an alarm linkage response is triggered, a distributed control node network is constructed, and a node data transmission strategy is generated. According to the node data transmission strategy, alarm signal distribution and interference signal modulation are performed; Monitor the adjustment status of the abnormal event, and determine whether to release the interference signal based on the amount of overlap between the adjustment status and the judgment area; Establish a backup communication channel to ensure data transmission continuity during alarm linkage response; New operational status data is collected based on an IoT platform, and the adaptive analysis model is optimized using an update training mechanism. The calculation of the risk index and intrusion index of abnormal events through the adaptive analysis model specifically includes: Obtain the event type and device load of the abnormal event; Determine whether the event type is a preset high-risk type, and mark the determination result as a type identifier; The risk index is calculated based on the type identifier, the number of devices under load, and the event change rate. Obtain the length of the abnormal event's activity trajectory within the monitoring area and the length of its activity trajectory within the judgment area; The intrusion index is the ratio of the length of the activity trajectory within the judgment area to the length of the activity trajectory of the abnormal event within the entire monitoring area.
2. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that, The acquisition of operational status data from multiple monitoring stations in the distributed factory specifically includes: The sensor signal streams from the monitoring stations are collected, including temperature signal streams, pressure signal streams, and vibration signal streams; The noise characteristics of the sensor signal stream are analyzed to determine the data denoising threshold; The sensor signal stream is pre-processed by filtering according to the data denoising threshold to obtain a standard sensor signal stream. The standard sensor signal stream is input into the multi-source signal fusion unit to extract feature data.
3. The intelligent alarm linkage processing method for distributed factories according to claim 2, characterized in that, The process of using multi-source signal fusion technology to process the operating status data specifically includes: Based on the data characteristics of the feature data, determine the feature extraction method and the location feature type; According to the feature extraction method and location feature type, perform associated feature extraction on the feature data to obtain a multi-source signal associated feature set; set dynamic weight allocation rules based on signal source credibility; The multi-source signal correlation feature set is fused using the weighted dynamic allocation rule to determine the estimated location of the abnormal event.
4. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that, The threat index is obtained by weighting and fusing the risk index and the intrusion index, specifically including: Set the weight factor allocation rules; The risk index and the intrusion index are weighted and summed according to the weighting factor allocation rule; The weighted summation result is normalized to obtain the threat index; The threat index is compared with a preset threshold to generate a ruling result.
5. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that, The construction of the distributed control node network and the generation of node data transmission strategies specifically include: Based on the factory area distribution and communication requirements, determine the number of transmission control nodes; perform node deployment analysis based on the number of transmission control nodes to obtain multiple transmission control nodes; configure the communication parameters and network topology of the transmission control nodes; and collect real-time network status and interference signal data of the transmission control nodes. The node data transmission strategy is generated through a policy adaptive matching mechanism.
6. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that, The execution of alarm signal distribution and interference signal modulation specifically includes: Based on the estimated location of the abnormal event, a multi-source deception signal is modulated; an alarm signal is distributed through the node data transmission strategy. The multi-source deception signal is used to perform location interference; after the alarm signal is distributed, the changing status of the abnormal event is monitored.
7. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that, The monitoring of the adjustment status of the abnormal event, and the determination of whether to release an interference signal based on the overlap between the adjustment status and the judgment area, specifically includes: Obtain the activity trajectory of the adjusted state; calculate the overlap between the activity trajectory and the judgment area; If the overlap is greater than zero, the interference signal is released; if the overlap is zero, the abnormal event is tracked until it escapes the monitoring area.
8. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that, The establishment of a backup communication channel specifically includes: Configure a quantum encryption channel and frequency band switching mechanism; integrate the quantum encryption channel and frequency band switching mechanism into a backup communication unit; when data transmission is interrupted, activate the backup communication channel and rebuild a new communication link.
9. The intelligent alarm linkage processing method for distributed factories according to claim 1, characterized in that, The process of collecting new operational status data based on an IoT platform and optimizing the adaptive analysis model using an update training mechanism specifically includes: Collect new operational status data points; The new running state data points are classified using a clustering algorithm; Calculate the distance between the new running state data point and the cluster center; Anomaly identification is performed based on the distance; The training parameters of the adaptive analysis model are updated based on the anomaly identification results.
Citation Information
Patent Citations
Chemical industry park hazard situation awareness method and system based on multi-source data fusion
CN110705842A
Multi-defense-area intelligent linkage alarm method based on AIoT gateway and related equipment
CN120431699A