An airport business-based service-level link tracking method and system

By using dynamic bytecode enhancement technology and a multi-dimensional tag recognition engine in the airport's multi-vendor environment, an association mapping between business tags and technology call links was established, solving the problem of cross-system fault location, realizing intelligent and rapid airport business-level link tracing, and improving operational efficiency and passenger experience.

CN120880859BActive Publication Date: 2026-03-31QINGDAO CIVIL AVIATION KAIYA SYST INTEGRATION CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-24
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In the heterogeneous environment of airports with multiple vendors, existing technologies cannot effectively establish a global view of cross-system business flows, which makes fault location and responsibility determination difficult, and existing monitoring systems cannot issue timely alarms, affecting operational efficiency and passenger experience.

Method used

A multi-language adaptation probe based on dynamic bytecode enhancement technology is adopted. The collected data is semantically parsed through a multi-dimensional tag recognition engine to establish an association mapping between business tags and technical call links, build a business link monitoring system, and realize cross-system link integration and intelligent positioning.

Benefits of technology

It enables visualized monitoring and intelligent early warning of the entire business chain across technology stacks, quickly locates faults, shortens fault location time, improves operation and maintenance efficiency, and enhances airport operation efficiency and passenger service quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120880859B_ABST
    Figure CN120880859B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of airport business and link tracking, and discloses a business-level link tracking method and system based on airport business. The method uses a business-level multi-language adaptation probe based on dynamic bytecode enhancement technology, performs semantic analysis on collected data through a multi-dimensional label recognition engine, extracts a flight number and an event code business label, establishes an associated mapping between the business label and a technical call link, constructs a business link monitoring system in an airport multi-vendor environment, and realizes business-level fault positioning; based on the business label associated information, cross-system link integration is performed to construct a business-driven full-link tracking view; through multi-dimensional business topology analysis and a dynamic early warning mechanism, intelligent positioning and visual display of business faults are realized. The application can sample as needed, only record key requests and interfaces with long time consumption, and can be integrated with other monitoring systems to quickly respond to and solve problems.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of airport operations and link tracing technology, and particularly relates to a business-level link tracing method and system based on airport operations. Background Technology

[0002] With the rapid development of the aviation industry, large airport systems have become increasingly complex. For example, a certain airport with tens of millions of passengers may have hundreds of low-voltage electrical systems. Some systems have deployed their own distributed tracing systems to track anomalies in their service calls through logs or visualization. However, airports are business-driven, and business systems span multiple systems and service providers. Different vendors using distributed tracing cannot unify business processes. Therefore, when a problem occurs in a business message chain, multiple service providers often need to investigate simultaneously. This is difficult, time-consuming, and wastes significant manpower.

[0003] Taking a major international airport with tens of millions of passengers as an example, its low-voltage electrical system encompasses 23 major categories and 112 subsystems, including baggage sorting, flight scheduling, security verification, and flight display, involving a heterogeneous technical architecture from 38 suppliers. A typical business chain scenario, such as the flight arrival process, requires data interaction across 4 systems (including 3 different service providers) from "air traffic control sending arrival message - ACDM system receiving message - ESB system processing arrival message - flight display system," with a single service call chain length of up to 18 hops.

[0004] Therefore, when business-level anomalies occur, existing technical solutions suffer from three core flaws: First, distributed link tracing cannot establish a global view of cross-system business flows, leading to the need for multi-party manual consultation for fault location; second, differences in data formats and interface specifications among different service providers create silos of tracing information; and third, the lack of a business semantic layer mapping mechanism makes it difficult to effectively link technical call links with business processes. This technical bottleneck not only leads to low efficiency in anomaly handling but also makes it difficult to define responsibilities among service providers, severely hindering the continuous improvement of airport operational efficiency and passenger service quality. Furthermore, when anomalies occur in business systems (e.g., system A has sent an event but system B has not received it, while other systems are operating normally), existing monitoring systems often fail to provide effective alerts, requiring airport users or passengers to discover the anomaly, severely impacting user experience and potentially causing adverse effects. Summary of the Invention

[0005] To overcome the problems existing in related technologies, the present invention discloses a business-level link tracing method and system based on airport operations, specifically involving a business-level link tracing method and system for complex multi-vendor airport operations. The purpose of this invention is to address the complex business connections between multiple vendors and systems at an airport from an operational perspective. When an anomaly occurs in a certain business chain, the system of this invention can provide timely warnings and quickly locate the problem, rather than requiring multiple vendors to jointly troubleshoot and locate the fault, which is difficult and requires obtaining a large amount of evidence during evidence collection.

[0006] The technical solution is as follows: a business-level link tracing method based on airport operations, the method comprising:

[0007] S101 utilizes a business-level multi-language adaptation probe based on dynamic bytecode enhancement technology. Through a multi-dimensional tag recognition engine, it performs semantic parsing on the collected data, extracts flight numbers and event code business tags, establishes an association mapping between business tags and technical call links, builds a business link monitoring system in the airport multi-vendor environment, and realizes business-level fault location.

[0008] S102, based on the generated business tag mapping and technical call chain data association information, performs cross-system link integration to build a business-driven full-link tracing view;

[0009] S103 enables intelligent location and visualization of business faults through multi-dimensional business topology analysis and dynamic early warning mechanisms.

[0010] Another object of the present invention is to provide a business-level link tracing system based on airport operations, the system implementing the business-level link tracing method based on airport operations, the system comprising:

[0011] The business fault location module is used to utilize a business-level multi-language adaptation probe based on dynamic bytecode enhancement technology. Through a multi-dimensional tag recognition engine, it performs semantic parsing on the collected data, extracts flight numbers and event code business tags, establishes an association mapping between business tags and technical call links, builds a business link monitoring system in the airport multi-vendor environment, and realizes business-level fault location.

[0012] The link integration module is used to integrate cross-system links based on business tag association information and build a business-driven full-link tracing view.

[0013] The intelligent analysis module is used to achieve intelligent location and visualization of business faults through multi-dimensional business topology analysis and dynamic early warning mechanisms.

[0014] Combining all the above technical solutions, the beneficial effects of this invention are as follows:

[0015] First, this invention achieves full-link visual monitoring and intelligent early warning across technology stacks through its independently developed distributed link tracing engine, adaptive business tagging system, and intelligent visualization analysis platform. The core innovation of this invention lies in solving the problems of poor technical compatibility, weak business correlation, low fault location efficiency, and inability to promptly alert on broken business chains in the complex multi-vendor heterogeneous environment of airports, which are inherent to traditional APM systems.

[0016] Secondly, this invention, by constructing a dual-dimensional monitoring system for airport operations and technology, has achieved significant results in actual deployments at major hubs such as a certain international airport, realizing four major breakthroughs in the field of airport operations. The specific effects are reflected in:

[0017] (1) Panoramic business link tracing capability; Through self-developed probe and business tag recognition algorithms, the system successfully solves the problem of data silos in multi-vendor systems, realizing full-link tracing of airport systems such as check-in, security check, and baggage sorting. The system adopts a business tag recognition algorithm to identify business tags such as flight number (FlightNo) and event code, and combines it with system technical call link tracing data to effectively map and associate business links with technical call links. It can successfully trace the service status of various vendors such as air traffic control system, airport decision-making system, ground service system, and terminal display, and visualize the link status of complex business.

[0018] (2) Precise Fault Location Mechanism: This invention achieves visualization of business links and focus on business nodes by constructing a full-service link tracing system. When a business anomaly occurs, business link data across multiple vendors and different systems can be quickly retrieved by querying business tags such as time, flight number, and event code. The fault point can be quickly displayed through visualization. By integrating the technical call link, it is possible to deeply track and identify anomalies at the method level of the business system. In the actual test at Jiaodong Airport, under the typical fault scenario of ≥500 flights per day and ≥5 vendor systems, the average location time was shortened from more than 12 hours to 5 minutes. Moreover, by automatically adapting different technology stack log formats through the cross-vendor protocol parsing engine, it completely changes the traditional multi-vendor manual consultation mode and achieves "one-interface precise location and full-link impact visibility".

[0019] (3) Intelligent Early Warning and Response System; This system innovatively constructs a multi-dimensional early warning and assessment system, establishing an intelligent decision-making model based on the business impact level, technical fault depth, anomaly propagation rate, and response time requirements. It automatically adapts to threshold standards for different support scenarios through a dynamic baseline learning algorithm, and combines a time-series prediction engine to predict business traffic trends and resource bottleneck risks. When a potential business anomaly is detected, an alarm is triggered promptly. In actual operation at major transportation hubs, this system has successfully achieved early identification, rapid location, and accurate recovery of business anomalies, significantly improving the business link early warning capabilities of multi-vendor composite systems at airports.

[0020] (4) Improved Operation and Maintenance Efficiency: This system reconstructs the core efficiency of the airport operation and maintenance system through the deep integration of architectural innovation and intelligent operation and maintenance technology. It adopts a dynamic protocol adaptation engine to achieve minute-level rapid access to heterogeneous technology frameworks, breaking through the bottleneck of traditional multi-day joint debugging. The built-in resource elastic scheduling algorithm ensures the extremely high availability of critical business links. Through the technologies of anomaly early warning, business node visualization, and in-depth technical call link, the system significantly reduces the fault discovery time and location and recovery time, realizing the intelligent early warning and rapid troubleshooting capabilities of airport operations in complex multi-vendor systems.

[0021] Third, the link tracing of this invention can span multiple services, such as clients, backend services, databases, and caches. By analyzing the time consumption during the process, performance bottlenecks in each step can be identified. Sampling can be performed on demand, recording only critical requests and time-consuming interfaces. It can also be integrated with other monitoring systems for rapid response and problem-solving. In practical applications, it has been found that airports involve complex business environments with multiple vendors and systems. Existing single-system monitoring solutions cannot solve the problem of cross-vendor business fault location, and there is an urgent need for business-level end-to-end monitoring capabilities. Therefore, this invention shifts from single-system technical monitoring to multi-vendor business collaborative monitoring, connecting all vendor data along business dimensions through a business semantic layer. It is the first to propose business-level link tracing in a multi-vendor airport environment, which is fundamentally different from existing technologies in terms of application scenarios. Attached Figure Description

[0022] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure;

[0023] Figure 1 This is a flowchart of a service-level link tracing method based on airport services provided in an embodiment of the present invention;

[0024] Figure 2 This is a schematic diagram of the business-level link tracing method based on airport services provided in an embodiment of the present invention. Detailed Implementation

[0025] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Many specific details are set forth in the following description to provide a thorough understanding of the present invention. However, the present invention can be practiced in many other ways different from those described herein, and those skilled in the art can make similar modifications without departing from the spirit of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0026] The innovation of this invention lies in its innovative business-level link tracing architecture, addressing the technical challenge of rapidly locating business faults in multi-vendor heterogeneous system environments at airports. It utilizes a multi-language adaptation probe based on dynamic bytecode enhancement technology to achieve non-intrusive monitoring and deployment across various container environments such as JBoss, Tomcat, and OSGi. An aviation business semantic extraction mechanism is constructed to automatically identify business tags such as flight numbers and event codes and establish mapping associations with technical call chains. This overcomes the limitations of traditional APM systems that only focus on the technical dimension, achieving deep integration of business logic and technical call chains. Through a distributed tracing engine and a multi-dimensional visual intelligent analysis platform, the system reduces cross-system business fault location time from hours to minutes, providing an innovative technical solution for intelligent operation and maintenance in complex airport business environments and filling the technical gap in business-level full-link monitoring in multi-vendor environments.

[0027] Example 1, as Figure 1 As shown, the service-level link tracing method based on airport services provided in this embodiment of the invention includes:

[0028] S101 utilizes a business-level multi-language adaptation probe based on dynamic bytecode enhancement technology. Through a multi-dimensional tag recognition engine, it performs semantic parsing on the collected data, extracts flight numbers and event code business tags, establishes an association mapping between business tags and technical call links, builds a business link monitoring system in the airport multi-vendor environment, and realizes business-level fault location.

[0029] In step S101, multi-language adaptation probes are deployed in the airport's multi-vendor system using dynamic enhancement technology for containers and frameworks to collect technical call link data from different container environments such as JBoss, Tomcat, and OSGi. Aviation business semantic extraction technology is used to semantically parse the collected technical call data, automatically extracting business tags such as flight numbers and event codes from interface parameters and message content. A business tag injection mechanism is used to inject the extracted business tags into the Span data structure of the technical call in the form of BizTag and BizContext fields, establishing a mapping relationship between business tags and the technical call link based on a spatiotemporal correlation model. Adaptive performance control and dynamic enhancement tuning technology are used to dynamically adjust monitoring strategies according to business importance and time window characteristics, constructing a business link monitoring system to achieve business-level fault location.

[0030] S102, based on the generated business tag mapping and technical call chain data association information, performs cross-system link integration to build a business-driven full-link tracing view;

[0031] S103 enables intelligent location and visualization of business faults through multi-dimensional business topology analysis and dynamic early warning mechanisms.

[0032] For example, in step S101, dynamic bytecode enhancement technology is a built-in technology in the Java JVM; the collected data is semantically parsed through a multi-dimensional tag recognition engine to extract flight numbers and event-coded business tags, establish an association mapping between business tags and technical call links, and build a business link monitoring system in the multi-vendor environment of the airport to achieve business-level fault location. This includes: using dynamic enhancement technology of containers and frameworks (container recognition mechanism), aviation business semantic extraction (business tag extraction and propagation technology), adaptive performance control and dynamic enhancement tuning (performance optimization algorithm) to locate business faults in the business link monitoring system. This invention has been successfully applied in the multi-system business environment of an international airport, solving the problem of business fault location in the multi-vendor heterogeneous environment of traditional monitoring systems.

[0033] For example, the dynamic enhancement technology for containers and frameworks includes: This invention combines bytecode manipulation tools such as ASM and Javassist with an improved ClassFileTransformer mechanism to achieve dynamic enhancement and stable injection of multi-language adaptation probes in various application containers and mainstream framework environments. This multi-dimensional tag recognition engine can automatically extract feature information such as class loading paths, system parameters, service ports, and startup class signatures, accurately identifying typical container environments such as JBoss, Tomcat, and OSGi. It also designs dedicated enhancement templates for different containers through container adapter mechanisms, adapting to their class loading structures and component lifecycles. For instance, in the JBoss container, the multi-language adaptation probe weaves instrumentation logic during component initialization and remote call phases by parsing the JNDI binding path and SessionBean lifecycle interface; in Tomcat, it achieves HTTP call chain request interception and context extraction by injecting Servlet filter chains and Pipeline components; and in the OSGi environment, the multi-language adaptation probe listens to the BundleActivator interface and service registration events, dynamically completing module-level injection and recycling.

[0034] For example, this multidimensional label recognition engine adopts a layered modular architecture in its software structure, mainly including four core layers: feature acquisition layer, intelligent recognition layer, adaptation decision layer, and template management layer. The feature acquisition layer dynamically obtains runtime information such as JVM environment variables, classpath structure, and container startup parameters through reflection mechanisms and system call interfaces. The intelligent recognition layer has a built-in container feature knowledge base and uses a multidimensional feature vector matching algorithm combined with a weighted scoring mechanism to achieve accurate container type identification. The adaptation decision layer selects the corresponding container adapter instance from a pre-set adapter factory based on the recognition results. The template management layer maintains a bytecode enhancement template library for different container environments, supporting dynamic template loading and version management. The entire multidimensional label recognition engine adopts the strategy pattern and factory pattern design patterns to ensure scalability for new container types.

[0035] For example, the improved ClassFileTransformer mechanism adds container context awareness and business tag injection point identification capabilities to the standard interface, enabling automatic identification of key business components during class loading. The integration process dynamically selects bytecode manipulation tools based on the container identification results from the multi-dimensional tag recognition engine: for heavy containers like JBoss, ASM is used for precise bytecode manipulation, inserting monitoring logic into SessionBean lifecycle methods; for lightweight containers like Tomcat, the Javassist high-level API is used, weaving tracing code before and after Servlet methods; for OSGi environments, the BundleWiring mechanism is combined to dynamically inject enhancement logic when the Bundle is activated. A unified enhancement context manager coordinates the operation timing of different bytecode tools, ensuring stable monitoring code injection across multiple vendors.

[0036] For example, the container adapter mechanism employs the abstract factory pattern, encapsulating monitoring injection strategies for different container environments through a unified ContainerAdapter interface. This mechanism maintains an adapter registry, automatically matching the corresponding adapter instance based on container identification results. The JBoss adapter implements SessionBean lifecycle hook listening and code weaving for EJB containers; the Tomcat adapter injects monitoring logic during ServletContext initialization and HttpServletRequest processing; and the OSGi adapter implements monitoring injection and unloading of dynamic modules through BundleActivator and ServiceTracker. Each adapter incorporates a container-specific class loader detection mechanism and enhanced template library, ensuring stable, non-intrusive monitoring deployment across different vendor container environments.

[0037] For example, in the JBoss container, the multi-language adaptation probe weaves instrumentation logic during component initialization and remote call phases by parsing the JNDI binding path and SessionBean lifecycle interfaces; in Tomcat, by injecting Servlet filter chains and Pipeline components, it achieves request interception and context extraction of the HTTP call chain, including:

[0038] In the JBoss container, the multi-language adaptation probe scans the JNDI namespace using reflection to identify EJB components. Monitoring logic is injected into the lifecycle methods of SessionBean, such as `ejbCreate` and `ejbPostConstruct`. By intercepting the `invoke` method of EJBObject, tracing points are inserted before and after remote calls, automatically extracting business information such as flight numbers and event codes from the call parameters. In the Tomcat container, the probe inserts a custom filter into the Servlet filtering chain to achieve unified interception of HTTP requests. Simultaneously, a custom Valve component is injected into the Pipeline processing chain to capture the container's internal processing. By parsing the parameters, headers, and session attributes of HttpServletRequest, it automatically identifies business context information and employs a thread-local storage mechanism to ensure accurate transmission of the tracing context during cross-component calls.

[0039] For example, in the OSGi environment, the multi-language adaptation probe listens for BundleActivator interface and service registration events, dynamically completing module-level injection and recycling, including:

[0040] In the OSGi environment, the multi-language adaptation probe is launched as a system bundle. It registers a BundleListener to listen for bundle lifecycle events, automatically triggering injection logic when changes in the STARTING and ACTIVE states are detected. During injection, the probe first obtains the target bundle's BundleContext, scans class files using the Bundle's getEntry method to identify key classes containing business logic, and then leverages OSGi's class loading isolation mechanism to inject monitoring code into the target class using bytecode enhancement technology without affecting the bundle's original functionality. Simultaneously, the probe registers a ServiceTracker to listen for service registration and deregistration events, automatically weaving tracing logic into the service interface during service publication. The cleanup process is triggered by listening for STOPPING and UNINSTALLED events. The probe automatically cleans up injected monitoring logic, releases related memory resources, deregisters registered service listeners, and removes corresponding records from the internally maintained Bundle monitoring mapping table, ensuring that no memory leaks or resource consumption issues occur after the module is unloaded.

[0041] Furthermore, this invention extends support for automatic identification and adaptation to other mainstream containers such as WebLogic, Jetty, and Spring Boot, and enables rapid integration and template reuse through a registration-based adapter interface. At the framework level, the multi-language adaptation probe supports enhanced integration with commonly used enterprise-level frameworks such as Spring, Spring MVC, Spring Boot, and Hibernate. It can identify core components such as Controller, Service, Repository, Advice, and EntityManager, and accurately weave logic into the IoC container initialization and AOP proxy stages to ensure that the data flow and call relationships of each key node in the business logic chain are completely captured, further solidifying the technical foundation for end-to-end semantic awareness and diagnostic capabilities.

[0042] For example, the semantic extraction of aviation business requests includes: This invention constructs a tag extraction and semantic conversion mechanism for the interface call process, realizing automatic parsing and tagging of parameters carried in aviation business requests. The tag extraction and semantic conversion mechanism includes: after the multi-language adaptation probe intercepts the application layer entry point, the system dynamically parses the input parameters of the interface call based on the method signature and parameter table structure, and combines reflection (a built-in Java software) to restore the attribute fields of the parameter object. Through the built-in configuration parser, the system supports parsing various parameter formats, including basic types, collection structures, custom Java objects and their nested attributes, automatically extracting key fields.

[0043] For example, the dynamic parsing process based on method signatures and parameter table structures, when the link tracing agent intercepts aviation business method calls, first obtains the parameter type information and parameter names of the method through reflection, and then extracts the actual passed parameter values ​​during method execution. After the reflection mechanism restores the parameter object attribute fields, the extracted original field values ​​are passed to the multi-dimensional tag recognition engine for business semantic recognition. The multi-dimensional tag recognition engine adopts a plug-in architecture design, including five core components: rule management module, pattern matching module, semantic verification module, context analysis module, and tag generation module. The rule management module maintains a regular expression library and a business dictionary library, supporting dynamic rule updates; the pattern matching module implements multi-pattern parallel matching based on finite state automata; the semantic verification module performs verification by querying the aviation business knowledge base; the context analysis module uses a sliding window algorithm to analyze the field environment; and the tag generation module integrates the results of each module to generate standardized tag entities. The engine incorporates a regular expression rule library specific to aviation operations, enabling it to automatically identify business tag types based on data format: formats like "MU5137" and "CZ3421" are identified as FlightNo tags, formats like "A12" and "B06" as GateCode tags, and codes like "ARR," "DEP," and "DELAY" as EventCode tags. The parser employs different strategies based on field type: basic types undergo direct pattern matching, collection structures are identified by iterating through each element, and custom objects have their field values ​​recursively extracted and processed uniformly. Through this automated tag extraction mechanism, the system can accurately identify aviation business data in different formats and convert it into standardized business tags.

[0044] After extracting the original fields, the system activates a multi-dimensional label recognition engine. Based on the built-in aviation business semantic rule library and feature dictionary, it performs semantic parsing and label mapping on the field values. The system supports automatic recognition of typical business fields, such as flight number, check-in counter number, gate number, baggage barcode, and flight status code. For each recognition result, a structured label entity is generated, containing metadata information such as label type (e.g., FlightNo, GateCode, EventCode), label value, and extraction path.

[0045] For example, in flight support interface calls, the system can automatically extract the fields "flightNo=MU5137", "gate=C22", and "status=closed" from the parameters and convert them into flight number tags, gate tags, and status tags, respectively. In check-in service calls, it can identify the ID number tag from "passengerInfo.idCard=3708021992****0032" and extract "baggageCode=020CN12345678" from the passenger baggage interface to generate baggage tags, etc. This mechanism ensures the accurate mapping between technical call data and business entity semantics, providing reliable data support for building a business-oriented link semantic graph.

[0046] For example, adaptive performance control and dynamic enhancement tuning include: adaptive performance control includes: utilizing a multilingual adaptive probe performance adaptive management system oriented towards airport requirements to implement differentiated monitoring strategies based on business importance;

[0047] For example, the system establishes a business importance grading system based on the criticality of airport business processes, dividing business interfaces into three levels: core, important, and general. Core-level businesses include critical processes that directly affect flight operations, such as flight takeoff and landing message processing, security checks, and gate allocation, and are subject to 100% full monitoring. Important-level businesses include businesses that affect passenger services, such as check-in, baggage handling, and flight information display, and are subject to medium monitoring intensity of 50%-80%. General-level businesses include auxiliary functions such as statistical queries, log recording, and data synchronization, and are subject to a lightweight monitoring strategy of 1%-10%. The system automatically determines the business type of the interface call through a business tag recognition engine and dynamically allocates corresponding monitoring resources to ensure that critical business links are fully monitored while avoiding performance impact on non-critical businesses.

[0048] Dynamic enhancement and optimization include: an intelligent enhancement mechanism based on business time windows, which automatically adjusts the monitoring intensity during peak flight takeoff and landing periods and downgrades to a lightweight monitoring mode during off-peak periods; combined with hot deployment technology and isolation-like mechanisms, it supports dynamic updates of multi-language adaptation probe logic without downtime, adapting to airport system upgrades and business changes.

[0049] For example, automatically adjusting monitoring intensity during peak flight arrival and departure times includes: a built-in time window detection mechanism that establishes an airport peak business model based on historical data to automatically identify key time windows such as peak flight arrival and departure times and peak passenger flow periods. When a peak business period is detected, the system automatically increases the monitoring sampling rate, raising the core business monitoring intensity from the baseline to the highest level, increasing the frequency of link data collection and anomaly detection sensitivity; simultaneously, it activates the rapid response mode of the early warning mechanism to shorten alarm latency. The adjustment process dynamically calculates the optimal monitoring intensity by monitoring current system load, interface call frequency, error rate, and other indicators in real time, ensuring both monitoring coverage and avoiding system overload, thus achieving intelligent allocation of monitoring resources.

[0050] For example, the lightweight monitoring mode is activated during off-peak business periods or non-critical business processes, minimizing system overhead by reducing data collection granularity, decreasing the types of monitoring metrics, and extending data reporting intervals. This mode retains only core call chain tracing data, suspending resource-intensive operations such as detailed method-level performance analysis and parameter parsing; it employs an asynchronous batch processing mechanism to cache monitoring data in a local buffer and report it in batches periodically, reducing network transmission frequency; simultaneously, it disables some non-critical business tag extraction functions, retaining only basic link connection information. The lightweight monitoring mode can reduce system performance overhead to 10%-20% of the normal mode, ensuring that the monitoring system's impact on business performance is minimized when business load is low.

[0051] For example, hot deployment technology is implemented based on the dynamic characteristics of Java class loaders. The system creates an independent class loader instance for each probe module, and achieves version isolation and dynamic replacement through the parent-child delegation mechanism of class loaders. When the probe logic needs to be updated, the system creates a new class loader instance to load the updated probe class, while the original class loader continues to serve the requests being processed, avoiding interruption of business processes. The class isolation mechanism ensures that there are no conflicts between different versions of probe classes, and prevents class loading conflicts and memory leaks through namespace isolation and resource management. The entire process adopts a double buffering strategy, with the old and new versions of probes running concurrently. The old version is unloaded only after the new version is stable, achieving a smooth version switching process.

[0052] For example, supporting dynamic updates of multi-language adaptation probe logic without system downtime includes: the dynamic update process involves issuing update commands through the configuration management center, and the probe nodes initiating the update process upon receiving the commands. The system first downloads the new probe logic package and verifies digital signatures and version compatibility; then, using reflection mechanisms and bytecode enhancement technology, it dynamically replaces the monitoring logic at runtime, including updating business tag recognition rules, modifying data collection strategies, and adjusting performance control parameters. For Java environments, a custom ClassLoader is used to implement hot-swapping of classes; for .NET environments, the AppDomain isolation mechanism is utilized; and for Python environments, a module re-import mechanism is used. The update process employs a canary release strategy, first testing on a small number of nodes, and then gradually expanding to all nodes after verification.

[0053] For example, a 100% sampling rate is used for key flight support nodes such as takeoff and landing message processing, gate allocation, and baggage sorting instructions. For auxiliary processes such as data synchronization, system self-checks, and business queries, the sampling rate is dynamically adjusted to 1%-10%, balancing comprehensive monitoring with system overhead. An innovative intelligent enhancement mechanism based on business time windows is implemented, automatically adjusting monitoring intensity during peak flight periods and downgrading to a lightweight monitoring mode during off-peak periods. Combining hot deployment technology and a near-isolation mechanism, it supports dynamic updates of multi-language adaptive probe logic without system downtime, adapting to airport system upgrades and business changes.

[0054] For example, step S102, based on business tag association information, integrates cross-system links and constructs a business-driven full-link tracking view, including: constructing a deeply customized distributed tracking engine for full-link monitoring of airport-specific business scenarios; and introducing a business semantic enhancement layer to deeply integrate business logic and technology call links based on the standard Span data structure using multi-dimensional tag recognition algorithms.

[0055] For example, the distributed tracing engine adopts a layered modular architecture, including a data acquisition layer, a data processing layer, a storage management layer, and a query and analysis layer. It is customized for multi-vendor airport environments, with a built-in container adaptation module to handle differences in technology stacks from different vendors, an integrated protocol parsing module to support airport-specific business protocols, and extensible plug-in interfaces for easy integration with new vendor systems.

[0056] For example, by innovatively introducing a business semantic enhancement layer, this distributed tracing engine, based on the standard Span data structure, has developed a multi-dimensional label recognition algorithm and a spatiotemporal correlation model. This breaks through the limitations of traditional APM systems that only focus on the technical dimension, achieving a deep integration of business logic and technical call chains. The business semantic enhancement layer, located between the data acquisition layer and the data processing layer, is responsible for transforming the technical call chain into a business semantic link. The integration mechanism is as follows: when raw Span data is acquired, the business semantic enhancement layer extracts business tags using the multi-dimensional label recognition algorithm and injects them into the standard Span structure in the form of BizTag and BizContext fields; based on the spatiotemporal correlation model, it analyzes the business logic relationships between Spans and establishes a business-level call chain mapping. Through this integration, the technical call chain is transformed into enhanced data that simultaneously contains technical call chains and business semantics, realizing the transformation from "technical call chain tracing" to "business process chain tracing."

[0057] For example, the deep integration of business logic and technical call chains using multi-dimensional tag recognition algorithms includes: the algorithm automatically extracts business tags such as flight number, event code, and operation time from the Span data of the technical call chain, and then re-aggregates and organizes the originally scattered technical call chains based on these business tags. The algorithm associates technical call chains from different vendors' systems based on the same business tag (such as the same flight number), forming a call chain view with the business process as the main thread. Through multi-dimensional combination analysis of business tags, the system can accurately map business processes such as "flight arrival, baggage handling, and passenger service" with underlying technical call chains such as "message reception, data processing, and interface calls."

[0058] For example, this invention constructs a deeply customized distributed tracing engine focused on end-to-end monitoring of specific airport business scenarios. By innovatively introducing a business semantic enhancement layer, this distributed tracing engine develops a multi-dimensional label recognition algorithm and a spatiotemporal correlation model based on the standard Span data structure, breaking through the limitations of traditional APM systems that only focus on the technical dimension, and achieving deep integration of business logic and technical call links.

[0059] Building a deeply customized distributed tracing engine for end-to-end monitoring of specific airport business scenarios specifically includes:

[0060] (1) Semantic Feature Extraction. In flight support services, key semantic information is usually distributed in various media, such as URL paths, request parameters, message loads, and database statements. In order to effectively extract this information, this invention constructs a hierarchical semantic extraction system.

[0061] First, the protocol decoding layer supports parsing mainstream protocols such as HTTP, MQ, gRPC, and JDBC, and combines binary payload deserialization capabilities to obtain structured input. This layer ensures the integrity and accuracy of interface parameters. Next, the lexical and semantic layer accurately extracts entities such as flight identifiers, ground equipment, and job actions through a custom regular expression rule library and a Bi-LSTM-based word segmentation model. The context window layer utilizes an improved Sliding Context Window algorithm, introducing part-of-speech tagging and business context weights to enhance the ability to resolve ambiguous semantics. For example, the lexical and semantic layer accurately extracts entities such as flight identifiers, ground equipment, and job actions through a custom regular expression rule library and a Bi-LSTM-based word segmentation model. This includes: the custom regular expression rule library constructs dedicated pattern matching rules for aviation business characteristics, including flight number patterns, airport code patterns, and equipment number patterns, which can quickly identify structured business entities. For unstructured text data, the system employs a Bi-LSTM word segmentation model for deep semantic analysis. This model learns semantic features in the aviation field through a bidirectional long short-term memory network, enabling it to accurately identify job action words such as "pushback," "taxiing," and "takeoff," as well as ground equipment entities such as "airbridge," "tractor," and "boarding gate." The implementation process first preprocesses and segments the input text, then performs regular expression matching and Bi-LSTM analysis in parallel. The regular expression rule base handles entities with standardized formats, while the Bi-LSTM model handles semantically complex natural language descriptions. Finally, an entity fusion algorithm integrates the recognition results from both methods to generate a complete entity annotation list, ensuring comprehensive and accurate extraction of flight identifiers, ground equipment, and job actions.

[0062] For example, the context window layer utilizes an improved Sliding Context Window algorithm, introducing part-of-speech tagging and business context weights to enhance the ability to resolve ambiguous semantics. This includes: the improved sliding context window algorithm (improved Sliding Context Window algorithm) introduces part-of-speech tagging and business weight mechanisms on top of the standard window, effectively improving the ability to resolve ambiguous semantics. The improved sliding context window algorithm sets a dynamic window size, adaptively adjusting the context range according to the complexity of the current vocabulary. For ambiguous words in aviation business, such as "delay" (which may refer to flight delays or equipment malfunction delays), the system makes a judgment by analyzing the part-of-speech features and business context of adjacent words within the window. The part-of-speech tagging module identifies nouns, verbs, adjectives, and other part-of-speech information. The business context weight mechanism assigns weight scores to different words based on aviation domain knowledge; for example, core business words such as "flight" and "passenger" have higher weights. The improved sliding context window algorithm traverses the text through a sliding window, calculates the weighted semantic similarity of words within the window, and combines it with context consistency checks to select the semantic interpretation that best fits the aviation business context. This effectively solves the semantic ambiguity problem of polysemous words and synonyms in different business scenarios.

[0063] Finally, the semantic standardization layer unifies different expressions into a standard format by customizing a dictionary for the aviation and travel industry, ensuring data consistency across systems and vendors.

[0064] For example, a custom aviation and travel domain dictionary constructs a standardized vocabulary system covering the entire aviation business process, mainly comprising four core components: a flight operation dictionary, an airport facility dictionary, a service process dictionary, and a standardized mapping table. The flight operation dictionary includes professional terms such as flight status, flight phase, and operation codes, along with their standard expressions; the airport facility dictionary covers the standardized names and coding rules for facilities and equipment such as terminals, runways, boarding gates, and baggage systems; and the service process dictionary organizes standard operational terms for business processes such as check-in, security checks, boarding, and baggage handling. The standardized mapping table establishes a mapping relationship between terms from different vendor systems, for example, uniformly mapping different expressions such as "ARR," "ARRIVAL," and "arrival" to the standard "ARRIVAL" format.

[0065] (2) Multidimensional Label Recognition Algorithm. To achieve efficient label extraction, this invention proposes a high-performance algorithm based on state machine driving. By constructing a domain label state graph, it can efficiently identify multiple types of labels such as flight numbers, resource codes, and event codes. In the initial state, the multidimensional label recognition algorithm guides users into feature sub-state groups according to regular expressions, and improves recognition accuracy by combining a domain dictionary, location window, and contextual part-of-speech judgment. This method not only supports label confidence scoring, but also effectively solves the disambiguation problem of conflicting labels, ensuring efficient problem localization in complex business scenarios.

[0066] For example, the process of guiding the system into a feature sub-state group based on regular expressions and improving recognition accuracy by combining a domain dictionary, location window, and contextual part-of-speech tagging includes: The recognition process begins in an initial state. The system first performs basic format pre-judgment on the input field, quickly identifying the basic feature patterns of the field through a preset regular expression trigger. When a specific format pattern is matched, the state machine automatically transitions to the corresponding feature sub-state group. For example, when an alphanumeric combination pattern is identified, the system enters the flight number recognition sub-state; when a three-letter combination is identified, the system enters the airport code recognition sub-state. Within the feature sub-state group, the system initiates a refined recognition process: First, it queries the domain dictionary to verify the business rationality of the field value, such as checking whether "PVG" is a valid airport code; then, it analyzes the location window information, considering the field's position in the data structure, the types of adjacent fields, and other contextual features; next, it performs part-of-speech tagging analysis to determine the field's syntactic attributes and semantic roles; finally, it calculates a confidence score based on multiple judgment dimensions, and confirms the label type when the score exceeds a preset threshold. The entire process employs an early stopping mechanism. Once the confidence level of a certain sub-state group reaches the deterministic threshold, the recognition result is immediately output and other parallel recognition processes are terminated, thereby improving algorithm efficiency. When multiple sub-state groups generate candidate results, the system outputs multiple candidate labels in order of confidence level, providing a wider range of choices for subsequent business association analysis.

[0067] (3) Introduction of a business semantic enhancement layer. As one of the core innovations of the link tracing engine, the business semantic enhancement layer extends the Span structure and adds fields such as BizTag and BizContext to record business semantic metadata. This business semantic enhancement layer deploys three types of enhancement processors.

[0068] First, the format standardization processor performs structural alignment on the tag fields in distributed calls to ensure data consistency. Second, the semantic completion processor, based on tag inheritance logic, propagates the tags of the parent call Span to the child calls, ensuring the integrity of the call chain. Finally, the tag relationship processor builds a call chain semantic graph based on the business logic definitions between tags, laying the foundation for business topology and behavior modeling.

[0069] The tag relationship processor analyzes the associations between different tags based on predefined business logic rules, and establishes a semantic graph of the call chain at the business level. The processor identifies the sequential relationship between different event codes with the same flight number, as well as the dependency relationship between related business entities, transforming the original Span relationship based on technical calls into a semantic relationship graph based on business processes. This enables the system to understand and display the call chain according to business logic rather than the order of technical calls.

[0070] For example, the format standardization processor performs structural alignment of tag fields in distributed calls by unifying business tags from different vendor systems into the same data structure format, ensuring that the BizTag and BizContext fields have consistent field names, data types, and encoding formats across all spans. The processor performs format conversion on tag fields according to predefined standard templates, such as unifying time fields to the ISO standard format and flight numbers to the standard format of uppercase letters and numbers, ensuring format compatibility during cross-system data exchange.

[0071] For example, when constructing the call chain, the semantic completion processor automatically copies key business tags from the parent span to the child span, ensuring the continuity of business context information throughout the call chain. For instance, when the main process of flight processing calls a sub-service, tags such as flight number and event code in the parent span are automatically propagated to all sub-call spans. Even if the sub-service itself does not explicitly process this business information, it can maintain business relevance through the tag inheritance mechanism.

[0072] For example, the tag relationship processor analyzes the associations between different tags according to predefined business logic rules, and establishes a business-level call chain semantic graph. The processor identifies the sequential relationship between different event codes with the same flight number, as well as the dependency relationship between related business entities, transforming the original Span relationship based on technical calls into a semantic relationship graph based on business processes. This enables the system to understand and display the call chain according to business logic rather than the order of technical calls.

[0073] For example, through these mechanisms, the technology call chain has semantic expression capabilities, enabling the rapid identification of specific vendors and system sources when problems arise in the business line, thus achieving efficient problem management and resolution.

[0074] For example, step S103, through multi-dimensional business topology analysis and a dynamic early warning mechanism, achieves intelligent positioning and visualization of business links, including: constructing a visualization analysis system based on a microservice architecture, wherein the core modules include: a business topology reconstruction module, which uses a graph database to store link relationships and supports full-link graph reconstruction based on multiple dimensions such as flight number and event code; a dynamic early warning threshold engine, which adjusts alarm triggering conditions according to business time period characteristics, historical baseline fluctuation range, and the health status of related systems, and performs dynamic threshold calculations for indicators such as link response time and error rate; and an early warning response system, which implements a hierarchical alarm strategy and supports real-time notifications through multiple channels such as SMS, email, and DingTalk.

[0075] For example, the business topology reconstruction module uses a graph database to store and manage link relationships, supporting full-link graph reconstruction based on multiple dimensions such as flight number and event code. In specific implementation, the interface call data of each system is first extracted and formatted into a node and edge structure acceptable to the graph database. Nodes represent system components or services, and edges represent the call relationships between components.

[0076] For example, extracting and formatting interface call data from various systems into a node and edge structure acceptable to a graph database includes: the system abstracts each vendor's service or interface as a "node" in the graph database, and the call relationships between services as "edges" connecting the nodes. Specifically, the process involves extracting service names and interface names from the link tracing data as node information, and extracting the relationship between the caller and the callee as edge information. For instance, "flight scheduling system" and "flight display system" are created as nodes, and the relationship "flight scheduling system calls flight display system to update flight information" is created as an edge connecting the two nodes. Simultaneously, basic storage attributes are stored in the nodes, and detailed information such as call time, parameters, and results is stored in the edges, forming a complete call relationship graph.

[0077] During the graph reconstruction process, the system utilizes key business identifiers such as flight numbers and event codes to aggregate and index the links in multiple dimensions. Leveraging the powerful query capabilities of the graph database, it supports full-link tracing and visualization of specific flights or events. This module not only provides an intuitive representation of complex business scenarios but also lays the foundation for subsequent performance analysis and problem localization.

[0078] For example, leveraging key business identifiers such as flight numbers and event codes, the system performs multi-dimensional aggregation and indexing of call chains. This includes grouping all call chains with the same flight number or event code together to form a business-dimensional chain set. For instance, for flight number "MU5137", the system will find all call chains containing this flight number, regardless of which vendor's system these calls occur in; for event code "ARR" (Arrival), the system will collect all call chains related to flight arrival. By establishing multiple indexes in the graph database, users can quickly query "the complete processing flow of a specific flight" or "the processing status of all flight arrival events", enabling them to view and analyze system call relationships from a business perspective rather than a technical one.

[0079] For example, the dynamic early warning threshold engine includes the following: The dynamic early warning threshold engine is implemented by adjusting the alarm triggering conditions by combining business time period characteristics, historical baseline fluctuation range, and the health status of related systems. Specifically, the system first performs statistical analysis on historical data to establish performance baseline models for each time period. Then, it uses machine learning algorithms to monitor indicators such as current link response time and error rate in real time and compares them with historical baselines.

[0080] Based on the different characteristics of different business periods, such as peak or off-peak hours, the system dynamically adjusts the early warning thresholds to adapt to varying business pressures. Simultaneously, considering the health status of related systems (such as CPU utilization and memory usage), the engine further optimizes threshold settings to ensure timely and accurate alarm triggering when anomalies occur.

[0081] Specifically, the dynamic adjustment of early warning thresholds adjusts the sensitivity of alarms based on the business characteristics of the current period. Thresholds are appropriately relaxed during peak periods and tightened during off-peak periods. System load is also considered; if CPU and memory utilization are already high, the alarm threshold for response time is adjusted accordingly.

[0082] For example, statistical analysis of historical data to establish performance baseline models for each time period includes:

[0083] The system collects interface response time and error rate data over a period of time, and calculates average values ​​by time period. For example, the average response time during the peak flight departure period from 8-10 am is 200ms, and the average response time during the off-peak period in the evening is 50ms. This establishes normal level standards for different time periods as a benchmark for subsequent anomaly judgment.

[0084] For example, using machine learning algorithms to monitor current link response time, error rate, and other metrics in real time includes: the system collects current response time and error rate data in real time, and compares it with historical benchmarks for the corresponding time period using an algorithm. The data for the current time period is compared with the average value for the same historical time period; if it exceeds the normal range, it is judged as abnormal. The machine learning algorithm considers a reasonable range of data fluctuations to avoid false alarms due to small fluctuations.

[0085] For example, the early warning response system includes: The early warning response system implements a tiered alarm strategy, supporting real-time notifications through multiple channels such as SMS, email, and DingTalk. In specific implementation, the tiered alarm strategy classifies events according to their severity and scope of impact. For example, minor anomalies may only require notification to relevant technical personnel via email, while major faults require emergency notifications via instant messaging tools such as SMS and DingTalk.

[0086] For example, a tiered alerting strategy categorizes events based on their severity and scope of impact, including:

[0087] The system sets different levels based on the severity and impact of the anomaly. A slow response from a single interface is classified as low-level, only sending an email; an interruption of the entire flight processing chain is classified as high-level, immediately sending SMS and DingTalk messages; an impact on multiple flights is classified as emergency-level, simultaneously notifying all relevant personnel. The classification criteria include the duration of the anomaly, its business importance, and the number of users affected.

[0088] The system supports custom alarm rules, allowing users to set different notification strategies and priorities according to business needs. Integration with the user management system ensures that notifications are accurately sent to the personnel responsible for the relevant business, improving response speed and problem-solving efficiency.

[0089] For example, custom alarm rules allow users to set personalized alarm conditions, supporting combined condition settings. Different alarm rules and notification methods can be set according to different business scenarios, responsible persons, and time periods. The system provides a visual configuration interface, allowing users to complete complex alarm rule settings with simple clicks.

[0090] Through the collaborative work of the above modules, this visualization platform not only enables comprehensive monitoring and analysis of complex business environments, but also significantly improves the intelligence level of anomaly detection and response.

[0091] As can be seen from the above embodiments, traditional multi-vendor fault diagnosis requires multiple technicians to work together for several hours. This invention can achieve rapid and accurate fault location, greatly shorten the fault handling time, significantly reduce labor costs, and at the same time, rapid fault location can effectively reduce flight delay losses caused by system failures. Through accurate performance bottleneck identification, it can also optimize system resource allocation and improve equipment utilization.

[0092] From a commercial promotion perspective, numerous airports both domestically and internationally have similar needs. Business-level multi-vendor monitoring technology possesses strong technical barriers and competitive advantages, and its solutions can be extended to other complex multi-system transportation hubs such as ports and high-speed rail stations. This invention fills a significant technological gap in the field of airport business-level link tracing. Currently, mainstream link tracing systems primarily support service call tracing using a single technology stack, making it difficult to handle heterogeneous environments and business semantic mapping issues across multiple vendors. Commercial APM platforms are mainly geared towards internet applications and lack deep adaptation to specific airport business scenarios. Enterprise-level monitoring solutions often require a unified technical architecture, making it difficult to adapt to the existing multi-vendor environment in airports. This invention innovatively establishes an automatic mapping mechanism between aviation business tags and technical call links, solving the problem of unified monitoring across different container environments and providing a new technical path for the development of intelligent airport operations and maintenance technology. This invention effectively solves the long-standing problem of multi-vendor data silos in the airport industry. Traditional technical monitoring cannot be directly mapped to specific business scenarios, requiring operations and maintenance personnel to analyze large amounts of technical logs to locate the root cause of business problems. Furthermore, different vendors use different technology stacks, data formats, and interface standards, making unified real-time monitoring a persistent technical challenge in the industry. This invention overcomes the limitations of traditional intrusive monitoring through dynamic bytecode enhancement technology, enabling non-intrusive monitoring deployment on existing systems. It innovatively achieves automated integration of technology call chains and business processes, resolving the disconnect between monitoring data and business scenarios, and tackling the technical challenge of unified probe deployment across multiple application container environments. This invention overcomes several long-standing limitations in technical understanding. Traditional views hold that link tracing primarily focuses on technical metrics; the industry generally believes that unified monitoring of heterogeneous systems from different vendors is difficult; and there are also limitations related to the high complexity and maintenance costs of business-level monitoring technology. This invention demonstrates the feasibility of deep integration of business semantics and technology call chains through innovative business semantic layer technology; overcomes the technical bottleneck of unified monitoring in multi-vendor environments through container feature recognition and dynamic adaptation technology; and achieves relatively low-maintenance-cost business-level intelligent monitoring through automated business tag recognition and semantic extraction technology. It breaks the limitations of a single technology stack, changes the traditional passive monitoring model, and proves the technical feasibility of achieving business monitoring without relying on deep cooperation from vendors.

[0093] Example 2: This invention provides a business-level link tracing system based on airport operations, the system comprising:

[0094] The business fault location module is used to utilize a business-level multi-language adaptation probe based on dynamic bytecode enhancement technology. Through a multi-dimensional tag recognition engine, it performs semantic parsing on the collected data, extracts flight numbers and event code business tags, establishes an association mapping between business tags and technical call links, builds a business link monitoring system in the airport multi-vendor environment, and realizes business-level fault location.

[0095] The link integration module is used to integrate cross-system links based on business tag association information and build a business-driven full-link tracing view.

[0096] The intelligent analysis module is used to achieve intelligent location and visualization of business faults through multi-dimensional business topology analysis and dynamic early warning mechanisms.

[0097] Example 3, as another embodiment of the present invention, such as Figure 2 As shown, the "Air Traffic Control Message → ACDM Scheduling → Flight Information Display Update" service chain in this system deployed at an international airport is illustrated below. Figure 2 The service-level link tracing method based on airport services provided in this embodiment of the invention specifically includes:

[0098] S1, Data Collection: A non-intrusive multi-language adaptation probe deployment solution based on dynamic bytecode enhancement technology is adopted. Multi-language adaptation probes are automatically embedded during the startup of business nodes such as air traffic control systems, ACDM scheduling systems, flight information display systems, gateway systems, and platform systems, supporting languages ​​such as Java, .NET, and Python. The multi-language adaptation probes capture interface-level communication data through a dynamic proxy mechanism, synchronously collecting 17 types of technical stack characteristic parameters, including HTTP / HTTPS message headers, MQTT message bodies, database SQL statements, and interface parameters.

[0099] S2 is a multi-dimensional tag recognition engine (business tag engine). Based on an asynchronous message bus and dynamic hierarchical routing architecture, it achieves intelligent data distribution from the data acquisition end to the collection end through Kafka partitioning strategies. It can ensure low latency for real-time streaming data, high reliability for abnormal events, and high throughput for batch data, and can dynamically identify system load status to trigger different acquisition modes.

[0100] For example, a Kafka partitioning strategy includes: the system sends different types of data to different Kafka partitions. Real-time data is sent to the fast partition, abnormal events are sent to the reliable partition, and batch data is sent to the high-throughput partition. Partition selection is automatically determined based on the message's business tags. The system monitors the load of each partition and automatically adjusts message distribution when the load is high, ensuring that different data types receive appropriate processing speed and reliability as required.

[0101] S3, based on a multi-dimensional label recognition engine (business label engine), performs regular feature extraction, NLP parsing, and context label inheritance;

[0102] S3.1: For structured data, such as RPC call parameters, message queues, database transactions, and protocol data between systems, business tags are obtained through built-in expression matching, and regular expression templates can be updated online through the rule engine, such as changes or additions to protocols between systems.

[0103] S3.2: For unstructured data, such as printed log content, NLP parsing is used to supplement the tags of regular expressions, and natural language processing technology is used to achieve semantic analysis and structured transformation of the text.

[0104] S3.3: A tagging system enables spatiotemporal correlation of cross-system data, forming a complete view of business technology mapping. Due to the complexity of business chains, distributed tracking tags are used, tag inheritance rules are set, and business dimensions such as flight numbers and event codes are embedded in the Span, supporting cross-technology chain tag fusion. For example, forming a complete view of business technology mapping includes: the system associating technology call chains with business tags; all technical operations of the same flight are linked together through the flight number tag, forming a complete view of the technical execution process from a business perspective. Cross-technology chain tag fusion includes: merging different technology call chains with the same business tag; for example, the processing of the same flight in different systems is merged into a complete business processing chain through the flight number tag.

[0105] S4: Business-driven link integration; constructing a cross-system business relationship topology network based on core business tags such as flight number, event code, and operating terminal. A graph database is used to store node and connection relationship data, with connections defining data flow paths and service call dependencies. For example, constructing a cross-system business relationship topology network includes: storing service nodes and call relationships of each vendor's system in a graph database according to business tags, and establishing a cross-system network relationship graph using flight number, event code, etc., as indexes.

[0106] S5: Intelligent Analysis; The visualization terminal employs dynamic topology rendering technology to establish multi-dimensional visual mapping rules: node sizes dynamically scale with service call frequency, connection line colors change according to latency index gradients, and abnormal nodes are highlighted with pulses. The system provides a topology map layered focusing function, which can quickly collapse non-critical nodes to display core business links, and supports drilling down from the overall airport view to fine-grained topology at the subsystem level.

[0107] For example, the node size can be dynamically scaled according to the frequency of service calls. The node size changes in real time according to the frequency of service calls. The more frequently the service is called, the larger the node is, and the less frequently the service is called, the smaller the node is, which intuitively displays the system usage popularity.

[0108] The color of the connecting lines changes according to the latency index gradient: the connecting line color presents a gradient according to the latency, with green representing fast response, red representing high latency, and yellow and other transitional colors in between. Drilling down from the airport's overall view to the fine-grained topology at the subsystem level includes: when a user clicks on a system node in the overall view, the interface automatically zooms in to display the detailed service call relationships within that system, supporting layer-by-layer in-depth viewing.

[0109] S6: Send the intelligent analysis results to the operation and maintenance management terminal.

[0110] S7: Perform the following steps on the maintenance and management terminal:

[0111] S7.1: Business Link Alarm. A multi-indicator collaborative detection mechanism is established for cross-system link failure scenarios. When the message queue backlog continues to increase and the database transaction status is abnormal, the system automatically triggers a tiered alarm. For example, if the message production rate is detected to be higher than the consumption rate for 120 seconds, a location report containing the coordinates of the faulty node, the summary of the associated logs, and the scope of the affected business is immediately generated and pushed to the relevant operations and maintenance personnel.

[0112] For example, establishing a multi-indicator collaborative detection mechanism includes: simultaneously monitoring multiple related indicators, such as message queue backlog, database transaction status, and interface response time, and only triggering an alarm when multiple indicators are abnormal at the same time, thereby reducing false alarms.

[0113] S7.2: Business Link Query provides a multi-condition combined search function, supporting the query of historical links by business dimensions such as flight number, event type, and time window. After entering the query conditions, the system presents the complete business chain in a three-dimensional timeline format. Abnormal nodes are automatically marked with a red warning icon, and in-depth information such as error logs and resource load of the upstream and downstream of the node is displayed, enabling rapid focus on the fault point.

[0114] For example, presenting the complete business chain in the form of a three-dimensional timeline includes:

[0115] With time as the Z-axis, system as the X-axis, and service as the Y-axis, the system provides a three-dimensional view of the time sequence of business processing. Users can rotate the screen to view the call relationships from different angles.

[0116] S7.3: Business link performance optimization analysis. The system constructs an end-to-end time decomposition model to automatically identify performance bottlenecks in each link. Taking the flight display update scenario as an example, the core latency link is located through the time consumption ratio matrix, and targeted suggestions are generated by combining the historical optimization case library. Actual stress test at an international airport shows that the processing time of key links is reduced by 22%, and the overall throughput is increased by 17%, effectively supporting the airport's high-concurrency business needs.

[0117] For example, building an end-to-end time decomposition model includes: breaking down the business process into multiple stages, calculating the time consumption percentage of each stage, automatically identifying which stage is the most time-consuming, and providing a basis for performance optimization.

[0118] To further illustrate the effects of the embodiments of the present invention, the following simulation experiments were conducted: To verify the practical application effect of the present invention in the airport business field, especially the significant improvement in fault location efficiency, the present invention simulated a complex link tracing and fault location task in a multi-vendor system environment based on a typical business scenario of an international airport, and compared it with traditional solutions. The test environment included partial data sampling from the real production environment and high-concurrency simulation in the simulation environment. The test environment and parameter settings are shown in Table 1.

[0119] Table 1. Experimental Environment and Parameter Settings

[0120]

[0121] II. Fault Types and Test Plan Design

[0122] Fault types include, but are not limited to, the following three categories: Category A: Business process anomalies, such as abnormal flight arrival message processing, baggage sorting errors, and check-in data loss; Category B: System performance bottlenecks, such as interface call timeouts, ESB processing delays, and slow flight information display refreshes; Category C: Cross-system collaboration anomalies, such as asynchrony between check-in and baggage systems, and inconsistencies between security check and flight information display statuses.

[0123] The comparative tests deployed the following solutions: Solution 1 (traditional solution): using distributed log analysis + manual troubleshooting process; Solution 2 (method provided by this invention): using adaptive probe component + link integration engine + multi-dimensional intelligent analysis platform to achieve automated full-link tracking and location.

[0124] III. Analysis of Experimental Results.

[0125] 3.1 The average time for fault location is compared in Table 2;

[0126] Table 2 Comparison of Average Fault Location Time

[0127]

[0128] 3.2 Comparison of time consumption for each stage of fault handling (unit: seconds), as shown in Table 3;

[0129] Table 3 Comparison of Time Consumption at Each Stage of Fault Handling

[0130]

[0131] 3.3 Fault location accuracy (by complexity), see Table 4;

[0132] Table 4 Fault Location Accuracy Table

[0133]

[0134] 3.4 Comparison of fault location accuracy of various vendors' systems, as shown in Table 5;

[0135] Table 5 Comparison of Fault Location Accuracy of Systems from Various Vendors

[0136]

[0137] Simulation results show that the system of this invention has significant performance advantages in a multi-vendor heterogeneous environment, especially in the following aspects: high fault node location efficiency: the location time is reduced to 1 / 250 of the original system, and the efficiency is improved by more than 99% in the MTTL stage; superior system stability: after 168 hours of continuous operation, the performance degradation is significantly lower than that of traditional solutions, and it is suitable for long-term high-load scenarios; adaptability to multi-system linkage scenarios: it maintains a high location accuracy in complex faults involving three or more systems; strong applicability for promotion: it can be flexibly adapted to various existing business subsystems of airports and is suitable for actual production environments.

[0138] In summary, the system of this invention has good practicality and innovation, and can effectively support the operation and maintenance data collection and intelligent fault analysis of large airports in complex system environments.

[0139] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications, equivalent substitutions and improvements made by those skilled in the art within the scope of the technology disclosed in the present invention and within the spirit and principles of the present invention should be covered within the scope of protection of the present invention.

Claims

1. An airport traffic-based service level link tracing method, characterized by, The method comprises the following steps: S101, using a service level multilingual adaptation probe based on dynamic bytecode enhancement technology, performing semantic analysis on the collected data through a multi-dimensional label recognition engine, extracting a flight number and an event code service label, establishing an association mapping between the service label and the technical call link, constructing a service link monitoring system in an airport multi-vendor environment, and realizing service level fault positioning; S102, based on the generated service label mapping and technical call link data association information, performing cross-system link integration and constructing a business-driven full-link tracking view; S103, through multi-dimensional business topology analysis and dynamic early warning mechanism, realizing intelligent positioning and visual display of business faults; In step S101, through the dynamic enhancement technology of containers and frameworks, the multilingual adaptation probe is deployed in the airport multi-vendor system to realize the collection of technical call link data in different container environments such as JBoss, Tomcat and OSGi; through the aviation business semantic extraction technology, the technical call data collected is subjected to semantic analysis, and the business labels of flight number and event code are automatically extracted from the interface parameters and message content; through the business label injection mechanism, the extracted business labels are injected into the Span data structure of technical call in the form of BizTag and BizContext fields, and the association mapping relationship between the business label and the technical call link is established based on the space-time association model; through adaptive performance control and dynamic enhancement optimization technology, the monitoring strategy is dynamically adjusted according to the business importance and time window characteristics, a business link monitoring system is constructed, and business level fault positioning is realized; The dynamic enhancement technology of containers and frameworks comprises: using a multi-dimensional label recognition engine based on container feature fingerprints, combining ASM and Javassist bytecode operation tools, and integrating an improved ClassFileTransformer mechanism to complete the dynamic enhancement and stable injection of the multilingual adaptation probe in various application containers and mainstream framework environments; the multi-dimensional label recognition engine automatically extracts class loading path, system parameters, service port and startup class signature feature information, identifies typical container environments such as JBoss, Tomcat and OSGi, and designs special enhancement templates for different containers through a container adapter mechanism to adapt the class loading structure and component life cycle; including in the JBoss container, the multilingual adaptation probe parses the JNDI binding path and SessionBean life cycle interface, and weaves the embedding point logic in the component initialization and remote call stage; in Tomcat, the multilingual adaptation probe injects the Servlet filter chain and the Pipeline component to realize request interception and context extraction of the HTTP call chain; in the OSGi environment, the multilingual adaptation probe listens to the BundleActivator interface and service registration events to dynamically complete module level injection and recycling; The multi-dimensional label recognition engine adopts a hierarchical modular architecture, including a feature collection layer, an intelligent recognition layer, an adaptive decision layer, and a template management layer; the feature collection layer dynamically acquires JVM environment variables, class path structures, and container startup parameter runtime information through a reflection mechanism and a system call interface; the intelligent recognition layer has a built-in container feature knowledge base, adopts a multi-dimensional feature vector matching algorithm, and realizes the discrimination of container types in combination with a weight scoring mechanism; the adaptive decision layer selects a corresponding container adapter instance from a preset adapter factory according to the recognition result; the template management layer maintains a bytecode enhancement template library for different container environments, and supports dynamic loading and version management of templates; The improved ClassFileTransformer mechanism adds container context awareness and business label injection point recognition functions on the basis of a standard interface, and automatically recognizes key business components in the class loading process; the fusion process dynamically selects a bytecode operation tool according to the container recognition result of the multi-dimensional label recognition engine: for the JBoss heavy container, ASM is used for accurate bytecode operation, and monitoring logic is inserted in the SessionBean life cycle method; for the Tomcat lightweight container, Javassist advanced API is used to weave link tracking code before and after the Servlet method; for the OSGi environment, the BundleWiring mechanism is combined to dynamically inject enhancement logic when the Bundle is activated; the operation timing of different bytecode tools is coordinated through a unified enhancement context manager, ensuring stable monitoring code injection in a multi-vendor environment; The container adapter mechanism adopts an abstract factory pattern, encapsulates the monitoring injection strategies of different container environments through a unified ContainerAdapter interface, and automatically matches the corresponding adapter instance according to the container recognition result; the JBoss adapter realizes SessionBean life cycle hook listening and code weaving for the EJB container; the Tomcat adapter injects monitoring logic in the ServletContext initialization and HttpServletRequest processing process; the OSGi adapter realizes the monitoring injection and uninstallation of dynamic modules through BundleActivator and ServiceTracker; The aviation business semantic extraction includes: A label extraction and semantic conversion mechanism for interface call processes is constructed to realize automatic analysis and labeling of parameters carried in aviation business requests; The label extraction and semantic conversion mechanism includes: after the multi-language adaptation probe intercepts the application layer entrance, the system dynamically analyzes the parameter content of the interface call based on the method signature and parameter table structure, and restores the attribute fields of the parameter object in combination with the reflection mechanism; through the built-in configuration parser, various parameter formats are parsed, including basic types, collection structures, custom Java objects, and nested attributes, to automatically extract key fields; In step S102, based on the service tag association information, cross-system link integration is performed, and a service-driven full-link tracking view is constructed, including: A deep customized distributed tracking engine is constructed to perform full-link monitoring of airport specific service scenarios; by introducing a service semantic enhancement layer, on the basis of the standard Span data structure, a multi-dimensional tag identification algorithm is used to perform deep fusion of service logic and technical call links; The distributed tracking engine adopts a layered modular architecture, including a data acquisition layer, a data processing layer, a storage management layer, and a query analysis layer; it is customized and designed for the airport multi-vendor environment, with a built-in container adaptation module to handle differences in different vendor technology stacks, an integrated protocol analysis module to integrate airport specific business protocols, and a scalable plug-in interface to access new vendor systems; The service semantic enhancement layer is located between the data acquisition layer and the data processing layer, and is responsible for converting technical call chains into business semantic links; the fusion mechanism is as follows: when the original Span data is collected, the service semantic enhancement layer extracts business tags through a multi-dimensional tag identification algorithm, and injects them into the standard Span structure in the form of BizTag and BizContext fields; based on a space-time association model, the business logic relationship between Spans is analyzed, and a business-level call chain mapping is established; through fusion, the technical call chain is converted into enhanced data containing both technical call links and business semantics, realizing the transition from technical call chain tracking to business process chain tracking; The multi-dimensional tag identification algorithm automatically extracts flight numbers, event codes, and operation time business tags from the Span data of the technical call chain, and then re-aggregates and organizes the originally scattered technical call chains based on these business tags; the multi-dimensional tag identification algorithm associates technical call chains from different vendor systems based on the same business tags to form a call chain view with business processes as the main line; through multi-dimensional combination analysis of business tags, the flight arrival, baggage handling, and passenger service business processes are mapped to the underlying message receiving, data processing, and interface call technical call chains; The construction of the deep customized distributed tracking engine for full-link monitoring of airport specific service scenarios specifically includes: (1) Semantic feature extraction; first, the protocol decoding layer combines the binary payload deserialization capability to obtain structured input; next, the lexical semantic layer extracts flight identification, ground equipment and post action entities through a self-defined regular rule library and a Bi-LSTM-based word segmentation model; the context window layer uses an improved Sliding Context Window algorithm to introduce part-of-speech tagging and business context weight; the context window layer uses an improved Sliding Context Window algorithm to introduce part-of-speech tagging and business context weight, including: the improved sliding context window algorithm sets a dynamic window size, adjusts the context range adaptively according to the complexity of the current vocabulary, and judges by analyzing the part-of-speech features and business context of adjacent words in the window; the part-of-speech tagging module identifies noun, verb and adjective information, and the business context weight mechanism assigns weight scores to different words according to aviation domain knowledge; finally, the semantic standardization layer unifies different expression forms into a standard format through a self-defined aviation field dictionary; (2) Use multi-dimensional label recognition algorithm to construct through domain label state diagram to identify flight number, resource code and event code multi-class labels; in the initial state, according to the regular guide, enter the feature sub-state group, and combine the domain dictionary, position window and context part-of-speech judgment to identify flight number, resource code and event code multi-class labels; (3) Introduce a business semantic enhancement layer; by extending the Span structure, adding BizTag and BizContext fields to record business semantic metadata; first, the format standardization processor aligns the structure of the label field in distributed calls, second, the semantic completion processor propagates the labels of the parent call Span to the child call based on the label inheritance logic, and finally, the label relationship processor establishes a call chain semantic graph according to the business logic definition between labels; wherein, the label relationship processor analyzes the association between different labels according to the predefined business logic rules, and establishes a call chain semantic graph at the business level; the processor identifies the relationship between different event codes with the same flight number, and the dependency relationship between related business entities, and converts the Span relationship based on technical calls into a semantic relationship graph based on business processes; Step S103, through multi-dimensional business topology analysis and dynamic early warning mechanism, realizing intelligent positioning and visual display of business link includes: building a set of visual analysis system based on micro-service architecture, including: business topology reconstruction module, using graph database to store link relationship, supporting multi-dimensional full-link graph reconstruction based on flight number and event code; Dynamic early warning threshold engine, according to the business time period characteristics, historical baseline fluctuation range, correlation system health state, adjusts the alarm trigger condition, calculates the dynamic threshold value of link response time and error rate index; Early warning response system: realize hierarchical alarm strategy, support multi-channel real-time notification of SMS, email, Dingding. 2.The airport traffic based service level link trace method according to claim 1, characterized in that, The aviation business semantic extraction further includes: The dynamic analysis process based on the method signature and the parameter table structure first acquires the parameter type information and the parameter name of the method through a reflection mechanism when the link tracking agent intercepts the aviation business method call, and then extracts the actual passed-in parameter value when the method is executed; the reflection mechanism restores the parameter object attribute field, and then passes the extracted original field value to a multi-dimensional label recognition engine for business semantic recognition; the multi-dimensional label recognition engine adopts a plug-in architecture design, and further includes a rule management module, a pattern matching module, a semantic verification module, a context analysis module, and a label generation module; the rule management module maintains a regular expression library and a business dictionary library, and supports dynamic updating of rules; the pattern matching module implements multi-pattern parallel matching based on a finite state automaton; the semantic verification module verifies by querying an aviation business knowledge base; the context analysis module analyzes the field environment using a sliding window algorithm; the label generation module integrates the results of each module to generate a standardized label entity; the multi-dimensional label recognition engine automatically recognizes business label types according to the data format through the built-in aviation business-specific regular expression rule library; the configuration parser adopts different strategies according to the field type: the basic type directly performs pattern matching, the set structure traverses each element to identify respectively, and the custom object uniformly processes after recursively extracting the field value; through this automatic label extraction mechanism, aviation business data of different formats are recognized and converted into standardized business labels; After extracting the original field, the system starts the multi-dimensional label recognition engine, performs semantic analysis and label mapping on the field value based on the built-in aviation business semantic rule library and feature dictionary; the automatic recognition of typical business fields includes flight number, check-in counter number, boarding gate number, baggage barcode, and flight status code, and a structured label entity is generated for each recognition result, including label type, label value, and extraction path metadata information. 3.The airport traffic based service level link trace method according to claim 1, characterized in that, The adaptive performance control includes: using a multi-language adaptation probe performance adaptive management system oriented to airport needs to perform a differentiated monitoring strategy based on business importance; The dynamic enhancement optimization includes: an intelligent enhancement mechanism based on a business time window to automatically adjust the monitoring intensity during a flight take-off and landing peak period, and to downgrade to a lightweight monitoring mode during a low peak period; in combination with a hot deployment technology and a class isolation mechanism, the multi-language adaptation probe logic is dynamically updated without stopping the machine, to adapt to airport system upgrades and business changes.

4. An airport business based service level link tracing system, characterized by, The system implements the business-level link tracking method based on airport business according to any one of claims 1-3, and the system comprises: A business fault positioning module configured to use a business-level multi-language adaptation probe based on a dynamic bytecode enhancement technology, to perform semantic analysis on collected data through a multi-dimensional label recognition engine, to extract a flight number and an event code business label, to establish an associated mapping between the business label and a technical call link, to construct a business link monitoring system in an airport multi-vendor environment, and to realize business-level fault positioning. A link integration module configured to perform cross-system link integration based on business label associated information, and to construct a business-driven full-link tracking view. Intelligent analysis module is used for intelligent positioning and visual display of business failure through multi-dimensional business topology analysis and dynamic early warning mechanism.

Citation Information

Patent Citations

  • Multi-airport luggage full-process tracking method and system

    CN119918563A

  • Cross-platform authority unified management method and system based on multiple WEB systems

    CN120181813A