Network automatic topology method and system for safety control of industrial Internet of Things
By dividing the network topology into critical and edge layers and using a MOSFET power switching circuit to switch the power supply when a security threat is detected, the problem of insufficient security and stability caused by fixed network topology in the Industrial Internet of Things (IIoT) is solved, and dynamic network adjustment and secure and stable data transmission are achieved.
Patent Information
- Application Number
- CN202511470484.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-15
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-10-15
AI Technical Summary
The existing industrial IoT network topology is fixed and lacks dynamic adjustment capabilities, resulting in insufficient network security and stability.
The network topology is divided into critical network topology and edge network topology. A MOSFET power switching circuit is set up to achieve dynamic switching of network topology through security threat detection. When a security threat is detected, the power supply is switched and the transmission path is replanned.
It enables flexible adjustment of network topology, improves the operational security and stability of the Industrial Internet of Things, isolates high-risk paths, and ensures the security and continuity of data transmission.
Smart Images

Figure CN120956609A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure communication technology, and more specifically to an automatic network topology method and system for secure control of the Industrial Internet of Things. Background Technology
[0002] In the Industrial Internet of Things (IIoT), the network topology plays a crucial role in connecting critical equipment and edge nodes, and its security and stability directly impact the continuity and reliability of the entire production process. With the widespread deployment of IIoT devices, the types of data transmitted in the network are diverse, and data transmission paths often span multiple nodes. Due to the complex industrial environment and diverse equipment types, communication links are susceptible to external threats such as network attacks, electromagnetic interference, and malicious intrusions, leading to significant risks to network operation.
[0003] Most existing industrial IoT network topologies are fixed after design, employing a fixed network structure and a single power supply control method, lacking the ability to adaptively switch based on real-time security status. When the network is at high risk or under attack, the topology cannot be adjusted quickly, critical nodes may be affected, causing data transmission interruptions or tampering, thereby threatening the safety and stability of industrial production.
[0004] In summary, existing technologies suffer from technical problems such as insufficient network security and stability due to the fixed topology of industrial IoT networks and the lack of dynamic adjustment capabilities. Summary of the Invention
[0005] The purpose of this application is to provide an automatic network topology method and system for security control of industrial IoT, in order to solve the technical problems in the prior art where the fixed network topology of industrial IoT and the lack of dynamic adjustment capabilities lead to insufficient network operation security and stability.
[0006] In view of the above problems, this application provides a network automatic topology method and system for security control of industrial Internet of Things.
[0007] The first aspect of this application provides an automatic network topology method for security control of the Industrial Internet of Things (IIoT). The method includes: dividing a first network topology into a second network topology, wherein the first network topology includes critical network topology nodes and the second network topology includes edge network topology nodes; setting up a MOSFET power switching circuit connected to an IIoT device, the MOSFET power switching circuit including a first power supply and a second power supply, the first power supply controlling the first network topology and the second power supply controlling the second network topology; detecting security threats during the transmission process of the IIoT to obtain security threat indicators, and when the security threat indicators are greater than or equal to a preset threshold, switching the MOSFET power switching circuit from the first power supply to the second power supply, and performing data transmission based on the second network topology controlled by the second power supply.
[0008] Optionally, real-time network transmission data is acquired, and industrial protocol anomaly detection, equipment behavior baseline anomaly detection, and transmission signal execution anomaly detection are performed on the real-time network transmission data to obtain multi-source anomaly detection results; multiple security threat indicators of the multi-source anomaly detection results are identified, and when any of the multiple security threat indicators is greater than or equal to a preset threshold, the MOS transistor power switching circuit is switched from the first power supply to the second power supply.
[0009] Optionally, the MOS transistor power switching circuit includes an NMOS transistor, a first PMOS transistor, and a second PMOS transistor; when the MOS transistor power switching circuit is powered by the first power supply, the NMOS transistor and the first PMOS transistor are turned on, and the second PMOS transistor is turned off; when the MOS transistor power switching circuit is powered by the second power supply, the NMOS transistor and the first PMOS transistor are turned off, and the second PMOS transistor is turned on.
[0010] Optionally, a set of network topology nodes used for industrial IoT transmission is read; functional attributes of each network topology node in the set are evaluated to obtain a set of key evaluation indicators; network topology nodes in the set of key evaluation indicators that are greater than a first preset key evaluation threshold are identified to establish a first initial network topology; network topology nodes in the set of key evaluation indicators that are less than a second preset key evaluation threshold are identified to establish a second initial network topology; network topology nodes that are greater than or equal to the second preset key evaluation threshold and less than the first preset key evaluation threshold are marked as overlapping areas; the overlapping areas are connected to the first initial network topology and the second initial network topology respectively to obtain a first network topology and a second network topology.
[0011] Optionally, the transmission process is detected based on a first network transmission path controlled by the first power supply; network topology nodes in the overlapping area of the first network topology are identified according to the first network transmission path, and the network topology nodes in the overlapping area are marked as relayable network topology nodes; when the MOS power switching circuit switches from the first power supply to the second power supply, a second network transmission path controlled by the second power supply is replanned based on the relayable network topology nodes, and data is transmitted according to the replanned second network transmission path.
[0012] Optionally, after marking network topology nodes that are greater than or equal to the second preset criticality assessment threshold and less than the first preset criticality assessment threshold as overlapping areas, the overlapping network topology nodes in the overlapping areas are identified; the overlapping network topology nodes are protected by dual power supply based on the first power supply and the second power supply.
[0013] Optionally, the transmission task information of the transmission process is identified; transmission compatibility matching analysis is performed on the relayable network topology nodes according to the transmission task information to obtain a first relayable network topology node; based on the first relayable network topology node and the second network topology, a first candidate network transmission path set is constructed; the transmission quality score of the first candidate network transmission path set is performed according to the transmission task information to obtain a first candidate network transmission path; and the first candidate network transmission path is output as a replanned second network transmission path.
[0014] Optionally, obtain k relayable network topology nodes that meet compatibility requirements; randomly select any one of the k relayable network topology nodes, reconstruct the first candidate network transmission path set and obtain the first candidate network transmission path; based on the first candidate network transmission path, re-perform transmission compatibility matching analysis on the k relayable network topology nodes, and re-obtain the first candidate network transmission path according to the re-selected relayable network topology node, and so on, until the number of consecutive times the re-selected relayable network topology node re-obtains the first candidate network transmission path is the same, and output the second network transmission path.
[0015] Optionally, functional attribute evaluation is performed on each network topology node in the set of network topology nodes, including network real-time performance, network historical failure probability, network security protection mechanism, business criticality, value of stored data, and network connectivity of each topology node.
[0016] A second aspect of this application provides an automatic network topology system for security control of the Industrial Internet of Things (IIoT). The system includes: a network topology partitioning module for partitioning a first network topology and a second network topology, wherein the first network topology includes critical network topology nodes and the second network topology includes edge network topology nodes; a switching circuit setting module for setting a MOSFET power switching circuit connected to the IIoT device, the MOSFET power switching circuit including a first power supply and a second power supply, the first power supply controlling the first network topology and the second power supply controlling the second network topology; and a security detection module for detecting security threats during the transmission process of the IIoT, obtaining security threat indicators, and when the security threat indicators are greater than or equal to a preset threshold, switching the MOSFET power switching circuit from the first power supply to the second power supply, and performing data transmission based on the second network topology controlled by the second power supply.
[0017] One or more technical solutions provided in this application have at least the following technical effects or advantages: The method provided in this application divides the network topology into a first network topology and a second network topology, and sets up a MOSFET power switching circuit. This MOSFET power switching circuit is connected to the industrial IoT device. The MOSFET power switching circuit includes a first power supply and a second power supply. The first power supply controls the first network topology, and the second power supply controls the second network topology. By performing security threat detection on the transmission process of the industrial IoT and obtaining security threat indicators, when the security threat indicators are greater than or equal to a preset threshold, the MOSFET power switching circuit switches from the first power supply to the second power supply. Data transmission is then performed based on the second network topology controlled by the second power supply. This achieves flexible adjustment of the network topology structure, enabling dynamic switching of the network topology under different security states, thereby effectively isolating high-risk paths and improving the operational security and stability of the industrial IoT network.
[0018] The above description is merely an overview of the technical solution of this application. To enable a clearer understanding of the technical means of this application and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of this application more apparent, specific embodiments of this application are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent through the following description. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0020] Figure 1 This is a flowchart illustrating the automatic network topology method for security control of the Industrial Internet of Things provided in this application.
[0021] Figure 2 This is a schematic diagram of the network automatic topology system for security control of the Industrial Internet of Things provided in this application.
[0022] Figure labeling: Network topology partitioning module 11, switching circuit setting module 12, security detection module 13. Detailed Implementation
[0023] This application provides an automatic network topology method and system for security control of the Industrial Internet of Things (IIoT), addressing the technical problem in existing technologies where fixed network topologies and a lack of dynamic adjustment capabilities in IIoT networks lead to insufficient network security and stability. It achieves the technical effect of flexibly adjusting the network topology structure, thereby improving the security and stability of IIoT network operations.
[0024] The technical solutions of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. It should be understood that the present invention is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention. It should also be noted that, for ease of description, only the parts related to the present invention are shown in the accompanying drawings, not all of them.
[0025] Example 1, as Figure 1 As shown, this application provides an automatic network topology method for security control of industrial IoT, the automatic network topology method for security control of industrial IoT includes: A first network topology and a second network topology are defined, wherein the first network topology includes key network topology nodes and the second network topology includes edge network topology nodes.
[0026] Furthermore, the method for dividing the first network topology and the second network topology includes: reading a set of network topology nodes used for industrial IoT transmission; evaluating the functional attributes of each network topology node in the set of network topology nodes to obtain a set of key evaluation indicators; identifying network topology nodes in the set of key evaluation indicators that are greater than a first preset key evaluation threshold, and establishing a first initial network topology; identifying network topology nodes in the set of key evaluation indicators that are less than a second preset key evaluation threshold, and establishing a second initial network topology; marking network topology nodes that are greater than or equal to the second preset key evaluation threshold and less than the first preset key evaluation threshold as overlapping areas; and connecting the overlapping areas to the first initial network topology and the second initial network topology respectively to obtain the first network topology and the second network topology.
[0027] Furthermore, functional attributes of each network topology node in the set of network topology nodes are evaluated, including network real-time performance, historical network failure probability, network security protection mechanism, business criticality, value of stored data, and network connectivity for each topology node.
[0028] Specifically, by deploying sensors, monitoring devices, and network management tools in the Industrial Internet of Things (IIoT), and utilizing network scanning tools like Nmap or network discovery protocols such as LLDP and CDP, information on all devices and connection points in the IIoT network transmission is collected. This includes basic information such as device IP address, MAC address, device type, and connection status, as well as topological information such as the device's location and role in the IIoT network transmission. The collected information is integrated to form a network topology node set, which contains all devices and connection points participating in IIoT network data transmission. Each node in the network topology node set is evaluated for its functional attributes using multiple indicators such as network real-time performance, historical network failure probability, network security protection mechanisms, business criticality, value of stored data, and network connectivity. For example, data analysis algorithms and expert experience, combined with historical data, are used to quantify and score each node's indicators through weighted summation, ultimately resulting in a set of key evaluation indicators. Taking a smart factory network in an Industrial Internet of Things (IIoT) as an example, a smart factory contains various types of network topology nodes, such as production control nodes (PLC controllers), equipment monitoring nodes (sensors), data storage nodes (servers), and network communication nodes (switches). Multiple nodes collaborate to ensure the smooth operation of the factory's production process. Based on the actual needs and business characteristics of the IIoT, combined with expert experience and historical data, corresponding weights are assigned to each indicator. Network real-time performance measures the speed at which nodes process and transmit data, with a weight of 0.2. Network historical failure probability assesses node stability, with a weight of 0.15. Network security protection mechanisms evaluate whether nodes possess comprehensive security measures, such as firewalls and encryption algorithms, with a weight of 0.25. Business criticality refers to the importance of the business carried by the node in the overall industrial production, with a weight of 0.2. The value of the stored data is weighted at 0.1. Network connectivity represents the node's ability to connect with other nodes and the quality of communication, with a weight of 0.1. Then, each node is scored. The PLC controller is responsible for real-time control of the production equipment. Historical data analysis shows that its average data transmission latency is within 5ms. Out of 10 points, the PLC controller node's network real-time performance is scored 9 points. Similarly, analyzing the node's fault records over the past year, only one brief fault occurred. According to the preset scoring rules, the network historical fault probability is scored 8 points. The PLC controller node is equipped with firewalls and data encryption functions, which can effectively resist common network attacks. Its security protection level is high, and its network security protection mechanism is scored 9 points.As the core node of production control, the PLC controller directly affects the normal operation of the production line and product quality, making it extremely critical to business operations (10 points). The value of stored data is assigned 7 points, and network connectivity is assigned 8 points. Based on the weighted calculation formula: Criticality Assessment Index = Network Real-time Performance Score × Network Real-time Performance Weight + Network Historical Failure Probability Score × Network Historical Failure Probability Weight + Network Security Protection Mechanism Score × Network Security Protection Mechanism Weight + Business Criticality Score × Business Criticality Weight + Stored Data Value Score × Stored Data Value Weight + Network Connectivity Score × Network Connectivity Weight, the functional attributes of the PLC controller are evaluated, resulting in a score of 9 × 0.2 + 8 × 0.15 + 9 × 0.25 + 10 × 0.2 + 7 × 0.1 + 8 × 0.1 = 8.75. Similarly, the functional attributes of each network topology node in the network topology node set are evaluated to obtain the criticality assessment index set. Based on the actual needs and security standards of the Industrial Internet of Things (IIoT), a first preset criticality assessment threshold is pre-set. Then, each indicator value in the criticality assessment indicator set is compared with the first preset criticality assessment threshold. Network topology nodes with indicators greater than the first preset criticality assessment threshold are identified. Nodes with indicators greater than the first preset criticality assessment threshold possess high real-time performance, low failure probability, strong security protection, high business criticality, high data value, and good connectivity, and are therefore classified as critical network topology nodes. Based on these critical network topology nodes, a first initial network topology is established. For example, if the first preset criticality assessment threshold is set to 7, and the criticality assessment indicator for a PLC controller node is 8.75, which is greater than the first preset criticality assessment threshold, then the PLC controller node is classified as a critical network topology node. Simultaneously, network topology nodes with indicators less than a second preset criticality assessment threshold are identified and classified as second initial network topology nodes. Network topology nodes with indicators less than the second preset criticality assessment threshold exhibit weaker functional attributes and are classified as edge network topology nodes. Network topology nodes with a criticality threshold greater than or equal to the second preset criticality assessment threshold and less than the first preset criticality assessment threshold are marked as overlapping areas. These overlapping areas are located between critical nodes and edge nodes. The overlapping areas are then connected to the first and second initial network topologies to obtain the final first and second network topologies. The first network topology includes critical network topology nodes, and the second network topology includes edge network topology nodes. This overlapping area connection ensures that the first and second network topologies are both independent and interconnected, providing a buffer zone for dynamic adjustments and power switching. When the network faces security threats or requires topology reconfiguration, the transition is smoother, reducing the impact on normal network operation and enhancing the flexibility and adaptability of the industrial IoT network.
[0029] Furthermore, after marking network topology nodes that are greater than or equal to the second preset criticality assessment threshold and less than the first preset criticality assessment threshold as overlapping areas, the overlapping network topology nodes in the overlapping areas are identified; the overlapping network topology nodes are protected by dual power supply based on the first power supply and the second power supply.
[0030] Specifically, after completing the criticality assessment of network topology nodes, nodes with a criticality threshold greater than or equal to a second preset criticality assessment threshold and less than a first preset criticality assessment threshold are marked as overlapping areas. Then, network management tools identify all network topology nodes marked as overlapping areas and implement dual power supply protection for these overlapping nodes using both a first and a second power supply. This means that the overlapping network topology nodes are simultaneously connected to both power supplies. The purpose of dual power supply protection is to ensure that overlapping network topology nodes receive a stable power supply under any circumstances, thereby guaranteeing the reliability and stability of network operation. Through dual power supply protection, overlapping network topology nodes can seamlessly switch power supplies during network topology transitions, avoiding interruptions or data loss caused by power switching and ensuring the security and continuity of transmitted data.
[0031] A MOSFET power switching circuit is configured and connected to an industrial IoT device. The MOSFET power switching circuit includes a first power supply and a second power supply. The first power supply is used to control the first network topology, and the second power supply is used to control the second network topology.
[0032] Furthermore, the MOS transistor power switching circuit includes an NMOS transistor, a first PMOS transistor, and a second PMOS transistor; when the MOS transistor power switching circuit is powered by the first power supply, the NMOS transistor and the first PMOS transistor are turned on, and the second PMOS transistor is turned off; when the MOS transistor power switching circuit is powered by the second power supply, the NMOS transistor and the first PMOS transistor are turned off, and the second PMOS transistor is turned on.
[0033] Specifically, based on the power requirements and electrical characteristics of the industrial IoT devices, suitable MOSFET models are selected. For high-power industrial IoT devices, MOSFETs with high withstand voltage and high maximum current are chosen to ensure they can withstand the device's operating voltage and current during power switching, preventing power switching failure or device damage due to MOSFET failure. A MOSFET power switching circuit is then configured based on the selected MOSFETs. This circuit includes three MOSFETs: an NMOS transistor, a first PMOS transistor, and a second PMOS transistor. The first PMOS transistor works in conjunction with the NMOS transistor to control the connection of the first power supply, while the second PMOS transistor controls the connection of the second power supply. The NMOS transistor conducts when its gate is high and disconnects when its gate is low, while the PMOS transistor conducts when its gate is low and disconnects when its gate is high. The MOSFET power switching circuit is connected to the industrial IoT device via a driver circuit. During connection, it is crucial to ensure correct power polarity to prevent damage to the device and MOSFETs due to reverse polarity, ensuring a stable power supply during switching. The MOSFET power switching circuit includes a first power supply and a second power supply. The first power supply controls the first network topology, i.e., critical network topology nodes, while the second power supply controls the second network topology, i.e., edge network topology nodes. When the MOSFET power switching circuit is powered by the first power supply, the gate voltage of the MOSFET controls the NMOS and the first PMOS to turn on, while the second PMOS is turned off. In this state, the first network topology is operational. When the MOSFET power switching circuit is powered by the second power supply, the gate voltage of the MOSFET controls the NMOS and the first PMOS to turn off, while the second PMOS is turned on. In this state, the second network topology is operational. By implementing the MOSFET power switching circuit, when the Industrial Internet of Things (IIoT) detects a security threat, the high-speed switching characteristics of the MOSFETs enable rapid and accurate network topology switching, while simultaneously achieving seamless power switching. This ensures the continuous and stable operation of IIoT devices, improving the security, reliability, and flexibility of the IIoT.
[0034] By detecting security threats during the transmission process of the industrial Internet of Things, security threat indicators are obtained. When the security threat indicators are greater than or equal to a preset threshold, the MOS transistor power switching circuit is switched from the first power supply to the second power supply, and data transmission is performed based on the second network topology controlled by the second power supply.
[0035] Furthermore, by performing security threat detection on the transmission process of the Industrial Internet of Things (IIoT) to obtain security threat indicators, the method includes: acquiring real-time network transmission data; performing industrial protocol anomaly detection, equipment behavior baseline anomaly detection, and transmission signal execution anomaly detection on the real-time network transmission data to obtain multi-source anomaly detection results; identifying multiple security threat indicators from the multi-source anomaly detection results; and when any one of the multiple security threat indicators is greater than or equal to a preset threshold, causing the MOS transistor power switching circuit to switch from the first power supply to the second power supply.
[0036] Specifically, network analysis tools, such as Wireshark, are used to acquire real-time network transmission data for the Industrial Internet of Things (IIoT). This data contains all information about communication between devices in the IIoT, such as data source, destination, transmission protocol, and data content. Multi-dimensional anomaly detection is performed on the acquired real-time network transmission data, including industrial protocol anomaly detection, device behavior baseline anomaly detection, and transmission signal execution anomaly detection. Industrial protocol anomaly detection involves checking each protocol field in the real-time transmission data to determine if there are any non-compliance issues. For example, regular expressions or protocol parsing libraries are used to check whether function codes in the Modbus protocol are within the legal range and whether data addresses are valid. Using normal device operation data, a normal behavior baseline is established for each IIoT device using time-series analysis algorithms. This baseline includes various behavioral characteristics of the device under normal operating conditions, such as data transmission frequency, data volume, and communication time. By comparing the real-time network transmission data with the normal behavior baseline, it is detected whether the device's real-time behavior deviates from the normal range. For example, are the device's connection frequency and data transmission volume abnormal? Transmission signal execution anomaly detection is used to detect the state of the transmitted data during the transmission process, such as signal strength, delay, and jitter. By setting reasonable signal quality thresholds, various signal indicators are monitored in real time. When an indicator exceeds the threshold range, it indicates an abnormality in the transmission signal. Multiple anomaly detection methods are implemented to obtain multi-source anomaly detection results. Several security threat indicators from the multi-source anomaly detection results are identified, such as the number of protocol violations, the frequency of abnormal device behavior, and the signal execution anomaly rate. These multiple security threat indicators reflect the security status of the industrial IoT transmission process from different perspectives. The identified security threat indicators are compared one by one with preset thresholds. The preset thresholds are determined based on the actual security needs of the industrial IoT, the importance of the business, and historical data experience, and are used to determine whether the current network status is secure. If any of the multiple security threat indicators is greater than or equal to the preset threshold, it indicates a security threat in the industrial IoT transmission process. At this time, the MOS transistor power switching circuit is immediately triggered, switching from the first power supply to the second power supply. Data transmission is then performed based on the second network topology controlled by the second power supply. If all security threat indicators are less than the preset threshold, it indicates that the data transmission process is safe and stable, and no changes are made; data transmission continues to be performed through the first network topology controlled by the first power supply.
[0037] Through comprehensive and meticulous security threat detection, potential security threats in the transmission process of industrial IoT can be detected in a timely manner. And through a fast and accurate power switching mechanism, the network topology can be dynamically switched under different security states, thereby effectively reducing the impact of security threats on industrial IoT and ensuring the normal operation of industrial production and the secure and stable transmission of data.
[0038] Furthermore, the method for switching the MOSFET power switching circuit from the first power supply to the second power supply includes: detecting a first network transmission path controlled by the first power supply during the transmission process; identifying network topology nodes in the overlapping area of the first network topology based on the first network transmission path, and marking the network topology nodes in the overlapping area as relayable network topology nodes; when the MOSFET power switching circuit switches from the first power supply to the second power supply, replanning a second network transmission path controlled by the second power supply based on the relayable network topology nodes, and performing data transmission according to the replanned second network transmission path.
[0039] Specifically, monitoring devices deployed in the Industrial Internet of Things (IIoT), such as network analysis tools, are used to monitor and collect network transmission data in real time. This analysis includes the source address, destination address, network nodes traversed, and links of transmitted data packets. A first network transmission path, controlled by a first power supply, is determined, representing the data transmission path of the first network topology under the control of the first power supply. Based on this first network transmission path, and combined with a pre-constructed first and second network topologies, network topology nodes in the overlapping area of the first network topology are identified and marked as relay nodes. These relay nodes act as relays during network switching. When a security threat indicator exceeds a preset threshold, triggering the MOSFET power switching circuit to switch from the first to the second power supply, the relay nodes are used as key nodes. A path planning algorithm, such as Dijkstra's algorithm or A* algorithm, is applied to re-plan the second network transmission path controlled by the second power supply. After planning, data transmission is performed according to the re-planned second network transmission path, achieving seamless data transmission during power switching and ensuring the stable operation of the IIoT.
[0040] By detecting the first network transmission path and identifying network topology nodes in overlapping areas, it is possible to quickly switch to a second power supply when a security threat occurs, and replan the transmission path based on relay nodes. This improves the security and flexibility of industrial IoT data transmission without affecting critical business operations, ensuring the stable operation of the industrial IoT.
[0041] Furthermore, the method for replanning the transmission process based on the relayable network topology node and the second network transmission path controlled by the second power supply includes: identifying the transmission task information of the transmission process; performing transmission compatibility matching analysis on the relayable network topology node according to the transmission task information to obtain a first relayable network topology node; constructing a first candidate network transmission path set based on the first relayable network topology node and the second network topology; performing transmission quality scoring on the first candidate network transmission path set according to the transmission task information to obtain a first candidate network transmission path; and outputting the first candidate network transmission path as the replanned second network transmission path.
[0042] Specifically, the process involves collecting and parsing network transmission data from the Industrial Internet of Things (IIoT) to identify the data type, source address, destination address, bandwidth utilization, packet size, and requirements for transmission latency and packet loss rate, thus forming transmission task information. Based on this information, a transmission compatibility matching analysis is performed on potential relay network topology nodes. This involves checking the current status and performance indicators of these nodes, including available bandwidth, processing latency, data throughput, and stability. A matching algorithm is then used to compare the requirements of the transmission task information with the performance indicators of the potential relay network topology nodes, selecting nodes that meet the requirements and forming the first set of potential relay network topology nodes to prevent data transmission failures due to node incompatibility. Using the second network topology as a graph structure and the first set of potential relay network topology nodes as intermediate nodes, a path planning algorithm, such as Dijkstra's algorithm or A* algorithm, is employed to generate multiple candidate paths from the source node to the destination node, constructing a first set of candidate network transmission paths. Each path in this set contains different combinations of potential relay nodes. Based on various metrics in the transmission task information, such as transmission latency, packet loss rate, and bandwidth utilization, a corresponding weight is assigned to each metric. A weighted average method is used to calculate the transmission quality score for each candidate path. A higher score indicates better transmission quality. The path with the highest score is selected as the first candidate network transmission path. This first candidate network transmission path is then used as the output of the replanned second network transmission path. Data transmission is performed based on this first candidate network transmission path to ensure the stability and continuity of data transmission during power switching.
[0043] By identifying transmission task information, performing transmission compatibility matching analysis, constructing a candidate path set, scoring transmission quality, and selecting the optimal path, the replanning of the second network transmission path based on relay network topology nodes is realized, effectively isolating high-risk paths and improving the continuity of industrial IoT operation and the security of transmitted data.
[0044] Furthermore, after performing transmission compatibility matching analysis on the relayable network topology nodes according to the transmission task information, the method further includes: obtaining k relayable network topology nodes that meet the compatibility requirements; randomly selecting any one of the k relayable network topology nodes, reconstructing the first candidate network transmission path set and obtaining the first candidate network transmission path; performing transmission compatibility matching analysis on the k relayable network topology nodes again based on the first candidate network transmission path, obtaining the first candidate network transmission path again according to the reselected relayable network topology node, and so on, until the number of consecutive times the reselected relayable network topology node obtains the first candidate network transmission path is the same, and outputting the second network transmission path.
[0045] Specifically, after completing the transmission compatibility matching analysis, k nodes that meet the compatibility requirements are selected from all possible relay network topology nodes. Here, k represents the number of nodes that meet the compatibility requirements of the current transmission task, and k is an integer greater than or equal to 2. Then, from these k compatible relay network topology nodes, a random number generation algorithm is used to randomly select one node. Random selection increases the diversity of path planning and avoids getting trapped in locally optimal paths due to a fixed initial selection. Using the randomly selected relay network topology node as a base, combined with the second network topology, a path planning algorithm, such as Dijkstra's algorithm or A* algorithm, is used to reconstruct the first candidate network transmission path set. Similarly, from the reconstructed first candidate network transmission path set, multiple candidate paths are evaluated based on the transmission task information to obtain the first candidate network transmission path. Based on the first candidate network transmission path, a transmission compatibility matching analysis is performed again on the k relayable network topology nodes to obtain relayable network topology nodes that meet the transmission compatibility requirements. The above steps are repeated based on the reselected relayable network topology nodes to obtain the first candidate network transmission path again. This process is repeated iteratively, with each time a relayable node is randomly selected, the candidate path set is reconstructed, and the optimal path is evaluated and selected. This continues until the reselected relayable network topology node obtains the first candidate network transmission path for the same number of consecutive times, with a minimum of 3 consecutive times. At this point, it indicates that the candidate network transmission path is optimal under the current network environment and transmission task conditions. This candidate network transmission path is then output as the second network transmission path, and data transmission is performed according to the replanned second network transmission path.
[0046] By randomly selecting relay nodes and reconstructing the candidate path set, the diversity of transmission paths is increased, reducing potential risks caused by fixed paths. Simultaneously, through repeated optimization processes, the stability and adaptability of the final selected path in dynamic network environments are ensured, improving the security, reliability, and efficiency of industrial IoT data transmission, and guaranteeing the stable operation of the industrial IoT.
[0047] Example 2, based on the same inventive concept as the automatic network topology method for industrial IoT security control in the foregoing examples, such as... Figure 2 As shown, this application provides an automatic network topology system for security control of the Industrial Internet of Things (IIoT), wherein the automatic network topology system for security control of the Industrial Internet of Things includes: The network topology partitioning module 11 is used to partition a first network topology and a second network topology, wherein the first network topology includes critical network topology nodes and the second network topology includes edge network topology nodes; the switching circuit setting module 12 is used to set a MOSFET power switching circuit, which is connected to the industrial IoT device. The MOSFET power switching circuit includes a first power supply and a second power supply, wherein the first power supply is used to control the first network topology and the second power supply is used to control the second network topology; the security detection module 13 is used to perform security threat detection on the transmission process of the industrial IoT, obtain security threat indicators, and when the security threat indicators are greater than or equal to a preset threshold, switch the MOSFET power switching circuit from the first power supply to the second power supply, and perform data transmission based on the second network topology controlled by the second power supply.
[0048] Furthermore, the security detection module 13 in the network automatic topology system for industrial IoT security control is also used to: acquire real-time network transmission data, perform industrial protocol anomaly detection, equipment behavior baseline anomaly detection, and transmission signal execution anomaly detection on the real-time network transmission data, and acquire multi-source anomaly detection results; identify multiple security threat indicators of the multi-source anomaly detection results, and when any of the multiple security threat indicators is greater than or equal to a preset threshold, cause the MOS tube power switching circuit to switch from the first power supply to the second power supply.
[0049] Furthermore, the switching circuit setting module 12 in the network automatic topology system for industrial IoT security control is also configured to: the MOS transistor power switching circuit includes an NMOS transistor, a first PMOS transistor, and a second PMOS transistor; when the MOS transistor power switching circuit is powered by the first power supply, the NMOS transistor and the first PMOS transistor are turned on, and the second PMOS transistor is turned off; when the MOS transistor power switching circuit is powered by the second power supply, the NMOS transistor and the first PMOS transistor are turned off, and the second PMOS transistor is turned on.
[0050] Furthermore, the network topology partitioning module 11 in the automatic network topology system for industrial IoT security control is also used to: read the set of network topology nodes used for industrial IoT transmission; evaluate the functional attributes of each network topology node in the set of network topology nodes to obtain a set of key evaluation indicators; identify network topology nodes in the set of key evaluation indicators that are greater than a first preset key evaluation threshold and establish a first initial network topology structure; identify network topology nodes in the set of key evaluation indicators that are less than a second preset key evaluation threshold and establish a second initial network topology structure; mark network topology nodes that are greater than or equal to the second preset key evaluation threshold and less than the first preset key evaluation threshold as overlapping areas; and connect the overlapping areas to the first initial network topology structure and the second initial network topology structure respectively to obtain a first network topology and a second network topology.
[0051] Furthermore, the security detection module 13 in the network automatic topology system for industrial IoT security control is also used to: detect the first network transmission path controlled by the first power supply during the transmission process; identify network topology nodes in the overlapping area of the first network topology based on the first network transmission path, and mark the network topology nodes in the overlapping area as relayable network topology nodes; when the MOS transistor power switching circuit switches from the first power supply to the second power supply, re-plan the second network transmission path controlled by the second power supply based on the relayable network topology nodes, and perform data transmission according to the re-planned second network transmission path.
[0052] Furthermore, the network topology partitioning module 11 in the automatic network topology system for industrial IoT security control is also used to: mark network topology nodes that are greater than or equal to the second preset criticality assessment threshold and less than the first preset criticality assessment threshold as overlapping areas, and then identify overlapping network topology nodes in the overlapping areas; the overlapping network topology nodes are protected by dual power supply based on the first power supply and the second power supply.
[0053] Furthermore, the switching circuit setting module 12 in the network automatic topology system for industrial IoT security control is also used to: identify the transmission task information of the transmission process; perform transmission compatibility matching analysis on the relayable network topology nodes according to the transmission task information to obtain a first relayable network topology node; construct a first candidate network transmission path set based on the first relayable network topology node and the second network topology; perform transmission quality scoring on the first candidate network transmission path set according to the transmission task information to obtain a first candidate network transmission path; and output the first candidate network transmission path as a replanned second network transmission path.
[0054] Furthermore, the switching circuit setting module 12 in the automatic network topology system for industrial IoT security control is also used to: obtain k relayable network topology nodes that meet compatibility requirements; randomly select any one of the k relayable network topology nodes, reconstruct the first candidate network transmission path set and obtain the first candidate network transmission path; re-perform transmission compatibility matching analysis on the k relayable network topology nodes based on the first candidate network transmission path, and re-obtain the first candidate network transmission path according to the re-selected relayable network topology node, and so on, until the number of consecutive times the re-selected relayable network topology node re-obtains the first candidate network transmission path is the same, and output the second network transmission path.
[0055] Furthermore, the network topology partitioning module 11 in the automatic network topology system for industrial IoT security control is also used to: evaluate the functional attributes of each network topology node in the network topology node set, including the network real-time performance, historical network failure probability, network security protection mechanism, business criticality, value of stored data, and network connectivity of each topology node.
[0056] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Figure 1 The automatic network topology method and specific examples for industrial IoT security control in Example 1 are also applicable to the automatic network topology system for industrial IoT security control in this example. Through the foregoing detailed description of the automatic network topology method for industrial IoT security control, those skilled in the art can clearly understand the automatic network topology system for industrial IoT security control in this example. Therefore, for the sake of brevity, it will not be described in detail here.
[0057] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0058] Obviously, those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of this application.
Claims
1. An automatic network topology method for security control of the Industrial Internet of Things, characterized in that, The method includes: Divide the network into a first network topology and a second network topology, wherein the first network topology includes key network topology nodes and the second network topology includes edge network topology nodes; A MOSFET power switching circuit is configured and connected to an industrial IoT device. The MOSFET power switching circuit includes a first power supply and a second power supply. The first power supply is used to control the first network topology, and the second power supply is used to control the second network topology. By detecting security threats during the transmission process of the industrial Internet of Things, security threat indicators are obtained. When the security threat indicators are greater than or equal to a preset threshold, the MOS transistor power switching circuit is switched from the first power supply to the second power supply, and data transmission is performed based on the second network topology controlled by the second power supply.
2. The automatic network topology method for security control of industrial IoT as described in claim 1, characterized in that, By detecting security threats during the transmission process of the industrial Internet of Things (IoT) and obtaining security threat indicators, the method includes: Acquire real-time network transmission data, and perform industrial protocol anomaly detection, equipment behavior baseline anomaly detection, and transmission signal execution anomaly detection on the real-time network transmission data to obtain multi-source anomaly detection results; The system identifies multiple security threat indicators from the multi-source anomaly detection results. When any one of the multiple security threat indicators is greater than or equal to a preset threshold, the MOS transistor power switching circuit switches from the first power supply to the second power supply.
3. The automatic network topology method for security control of the Industrial Internet of Things as described in claim 1, characterized in that, The MOS transistor power switching circuit includes an NMOS transistor, a first PMOS transistor, and a second PMOS transistor; When the MOS transistor power switching circuit is powered by the first power supply, the NMOS transistor and the first PMOS transistor are turned on, and the second PMOS transistor is turned off. When the MOS transistor power switching circuit is powered by the second power supply, the NMOS transistor and the first PMOS transistor are turned off, and the second PMOS transistor is turned on.
4. The automatic network topology method for security control of the Industrial Internet of Things as described in claim 1, characterized in that, Methods for dividing the first network topology into the second network topology include: Read the set of network topology nodes used for industrial IoT transmission; The functional attributes of each network topology node in the set of network topology nodes are evaluated to obtain a set of key evaluation indicators. Identify network topology nodes in the set of key evaluation indicators that are greater than a first preset key evaluation threshold, establish a first initial network topology, and identify network topology nodes in the set of key evaluation indicators that are less than a second preset key evaluation threshold, establish a second initial network topology. Network topology nodes that are greater than or equal to the second preset criticality assessment threshold and less than the first preset criticality assessment threshold are marked as overlapping areas; The overlapping regions are connected to the first initial network topology and the second initial network topology, respectively, to obtain the first network topology and the second network topology.
5. The automatic network topology method for security control of the Industrial Internet of Things as described in claim 4, characterized in that, The method for switching the MOSFET power supply switching circuit from the first power supply to the second power supply includes: The transmission process is detected based on the first network transmission path controlled by the first power supply. Based on the first network transmission path, identify the network topology nodes in the overlapping area of the first network topology, and mark the network topology nodes in the overlapping area as relay network topology nodes; When the MOS transistor power switching circuit switches from the first power supply to the second power supply, the transmission process is replanned based on the relay network topology node, and the second network transmission path controlled by the second power supply is used for data transmission according to the replanned second network transmission path.
6. The automatic network topology method for security control of the Industrial Internet of Things as described in claim 4, characterized in that, After marking network topology nodes that are greater than or equal to the second preset criticality evaluation threshold and less than the first preset criticality evaluation threshold as overlapping areas, the overlapping network topology nodes in the overlapping areas are identified. The overlapping network topology nodes are protected by dual power supply based on the first power supply and the second power supply.
7. The automatic network topology method for security control of the Industrial Internet of Things as described in claim 5, characterized in that, The method for replanning the transmission process based on the relayable network topology nodes and the second network transmission path controlled by the second power supply includes: Identify the transmission task information of the transmission process; Based on the transmission task information, a transmission compatibility matching analysis is performed on the relayable network topology nodes to obtain the first relayable network topology node; Based on the first relayable network topology node and the second network topology, a first candidate network transmission path set is constructed, and the first candidate network transmission path set is scored for transmission quality according to the transmission task information to obtain the first candidate network transmission path. The first candidate network transmission path is output as the replanned second network transmission path.
8. The automatic network topology method for security control of industrial Internet of Things as described in claim 7, characterized in that, After performing transmission compatibility matching analysis on the relayable network topology nodes according to the transmission task information, the method further includes: Obtain k relay network topology nodes that meet compatibility requirements; Randomly select any one of the k relayable network topology nodes, reconstruct the first candidate network transmission path set, and obtain the first candidate network transmission path; Based on the first candidate network transmission path, the k relayable network topology nodes are re-analyzed for transmission compatibility. The first candidate network transmission path is then re-obtained based on the re-selected relayable network topology nodes. This process continues until the number of consecutive times the re-selected relayable network topology nodes obtain the first candidate network transmission path is the same, at which point the second network transmission path is output.
9. The automatic network topology method for security control of the Industrial Internet of Things as described in claim 4, characterized in that, The functional attributes of each network topology node in the set of network topology nodes are evaluated, including the network real-time performance, historical network failure probability, network security protection mechanism, business criticality, value of stored data, and network connectivity of each topology node.
10. A network automatic topology system for security control of the Industrial Internet of Things, characterized in that, The steps for implementing the automatic network topology method for security control of the Industrial Internet of Things according to any one of claims 1 to 9 include: A network topology partitioning module is used to partition a first network topology and a second network topology, wherein the first network topology includes key network topology nodes and the second network topology includes edge network topology nodes. A switching circuit setting module is used to set a MOSFET power switching circuit. The MOSFET power switching circuit is connected to an industrial IoT device. The MOSFET power switching circuit includes a first power supply and a second power supply. The first power supply is used to control the first network topology, and the second power supply is used to control the second network topology. The security detection module is used to detect security threats during the transmission process of the industrial Internet of Things, obtain security threat indicators, and when the security threat indicators are greater than or equal to a preset threshold, cause the MOS transistor power switching circuit to switch from the first power supply to the second power supply, and perform data transmission based on the second network topology controlled by the second power supply.
Citation Information
Patent Citations
Methods and apparatus for selecting multiple paths taking into account shared risk
CA2350449A1
Method for apparatus to join wireless transmission network
CN101287284A
Wireless sensor network-based transmission lines icing on-line monitoring system
CN102818590A
Design method of full vehicle network topology
CN108156021A
CAN bus output driving circuit
CN114978800A