System and method for automatically distributing competition information of stadium

By introducing a decentralized architecture consisting of a master data distribution center, edge computing nodes, and a security arbitration response module into the sports stadium information distribution system, the single point of failure problem of centralized systems under high-intensity network attacks is solved, and business continuity and data integrity are guaranteed under extreme conditions.

CN120979745AInactive Publication Date: 2025-11-18HANGZHOU CITY BRAIN TECH & SERVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511180267.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2025-11-18
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing centralized information distribution system in sports venues is prone to systemic paralysis when subjected to high-intensity, complex cyberattacks due to its inherent single point of failure (SPOF) bottleneck. This makes it unable to meet the security compliance requirements of critical information infrastructure and unable to guarantee business continuity and data integrity in extreme situations.

Method used

The system adopts a decentralized architecture consisting of a master data distribution center, edge computing nodes, and a security arbitration response module. The master data distribution center is equipped with high-performance hardware and a security-hardened operating system. The edge computing nodes achieve information-theoretic security through quantum key distribution terminals. The security arbitration response module makes decision-making and switching through full traffic monitoring and complex threat analysis, realizing the automatic transformation of the system under high-intensity attacks.

Benefits of technology

Under extreme security threats, the system's survivability increases non-linearly, ensuring the business continuity and data integrity of the sports stadium's information infrastructure, enhancing its resistance to attacks, and reducing the risk of single points of failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979745A_ABST
    Figure CN120979745A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of information processing, discloses a system and a method for automatically distributing stadium competition information, and mainly aims to solve the problem of system paralysis risk caused by single-point failure of an existing stadium centralized information distribution system under high-intensity and compound network attacks. The system comprises a main data distribution center, at least two edge computing nodes and a security arbitration response module, when the security arbitration response module detects a compound network attack, mode switching is executed, a service load is migrated from the main data distribution center to a decentralized network formed by the edge computing nodes, and the decentralized network is connected with the edge computing nodes. And activating an inter-node communication channel based on quantum key distribution. According to the method, the vulnerability of a traditional centralized architecture is overcome, the DDoS attack resistance of the system is remarkably improved, and the service continuity and the data integrity and confidentiality under extreme conditions are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application belongs to the technical field of information processing, and specifically relates to a system and method for automatically distributing information of a sports venue match. BACKGROUND

[0002] In the process of digital transformation of modern sports industry, large sports venues, as the core carriers of event hosting and national fitness, efficient and stable operation of their internal information systems is of vital importance. Traditional sports venue informatization construction is generally faced with the dilemma of data silos, that is, timing and scoring systems, on-site large-screen display systems, television broadcast systems, ticketing systems, and even security monitoring systems are independently constructed and operated, their data formats, communication protocols and interface standards are different, which leads to the fact that key information cannot be interconnected and intercommunicated in real time and automatically between business links.

[0003] To solve this long-standing technical bottleneck, the skilled person in the art has proposed an effective solution, for example, the technical solution disclosed in Chinese patent CN117459556A. The core idea of this solution is to build a centralized on-site information distribution center as a transportation hub for all information flows in the venue. The centralized system actively collects raw data from various heterogeneous information sources by deploying a unified data adapter, performs standardized format conversion and data cleaning in the central server, and then pushes the processed structured information to various information consumer ends according to the pre-set distribution strategy. The emergence of this architecture greatly promotes the automation level of event operation, significantly improves the efficiency and accuracy of information flow by breaking down data barriers, effectively solves the problem of collaborative work under the conventional operation mode, and makes an important contribution to the construction of sports venue informatization.

[0004] However, with the increasingly severe situation of network space security and the continuous improvement of relevant laws and regulations, especially when sports venues host high-level activities with significant international influence or geopolitical sensitivity, their information systems are considered an important part of the national critical information infrastructure, and must meet the high security protection requirements proposed by laws and regulations such as the Cybersecurity Law.

[0005] Under this background, the inherent security vulnerability of the aforementioned centralized information distribution architecture, which is designed to improve the efficiency of conventional operation, has begun to emerge, and has gradually evolved into a core technical contradiction that is difficult to avoid.

[0006] This centralized design philosophy places the stable operation of the entire venue's information system entirely on a single central server or server cluster, thus creating a typical single point of failure (SPOF) bottleneck. This central node, due to its criticality, becomes a highly attractive and valuable target for attacks. Once it encounters an organized, high-intensity, and persistent external cyberattack, such as a large-scale distributed denial-of-service (DDoS) attack or a more covert and destructive advanced persistent threat (APT) attack, the consequences will be catastrophic.

[0007] DDoS attacks can exhaust the computing, storage, and network bandwidth resources of a central server through massive amounts of invalid traffic, rendering it unable to respond to any normal business requests and directly paralyzing the entire venue's information system. APT attacks, on the other hand, can remain dormant for extended periods, stealing system control and tampering with critical match data, causing far-reaching economic losses and social impacts. Under the existing centralized architecture, even with the deployment of firewalls, intrusion detection systems, and other peripheral protection devices, it is impossible to fundamentally eliminate the structural risk that the entire system will collapse once the central node is compromised. This architecture, in its technical principles, cannot provide the absolute business continuity guarantees required for legal compliance under extreme attacks.

[0008] Therefore, how to design a completely new system architecture that can fundamentally overcome the inherent single-point-of-failure vulnerability of traditional centralized solutions, while ensuring information distribution efficiency and data consistency, and effectively resist high-intensity and complex network attacks, so as to ensure that the sports stadium, as a critical information infrastructure, can maintain the continuity of core business and the integrity of data under any extreme circumstances, has become a key technical problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0009] The technical problem to be solved by this invention is to overcome the risk of systemic paralysis caused by the inherent single point of failure (SPOF) bottleneck of existing centralized information distribution systems in sports venues when encountering high-intensity, complex network attacks. Thus, while meeting the security compliance requirements of critical information infrastructure, a new technical solution is provided that can ensure business continuity and data integrity under extreme conditions.

[0010] To achieve the above objectives, the present invention provides the following technical solution: A system for automatically distributing sports venue match information includes: a master data distribution center, at least two edge computing nodes, and a security arbitration response module.

[0011] The main data distribution center, serving as the sole business processing core in the system's normal operating mode, is physically a server cluster. Each server in this cluster is equipped with a multi-core CPU based on the ARMv8 instruction set architecture, with no fewer than 64 physical cores and a clock speed of no less than 2.6GHz. Each server has at least 512 gigabytes of DDR4 error-correcting code RAM (ECCRAM) and a RAID50 storage array consisting of at least eight NVMe solid-state drives with a total capacity of no less than 32 terabytes. At the network interface level, each server is equipped with two 100GbE Ethernet cards supporting remote direct data access technology to achieve high-throughput, low-latency data exchange. Based on this hardware, the main data distribution center runs a security-hardened operating system based on the Linux 5.10 Long Term Support kernel. This operating system enforces SELinux security policies and disables all unnecessary system services and ports.

[0012] The software stack of the master data distribution center, from bottom to top, includes a data adaptation layer, a data processing and distribution engine, and a state synchronization agent. The data adaptation layer is responsible for communicating with existing heterogeneous information sources within the stadium via a dedicated driver. Supported protocols include ModbusTCP, OPCUA, and a custom serial communication protocol. This layer encapsulates the collected raw data into JSON-formatted data objects. The data processing and distribution engine, based on a distribution strategy table stored in a local database and configurable by the administrator, performs standardization, cleaning, aggregation, and format conversion operations on the JSON data objects, and distributes the processed data to designated consumers. The state synchronization agent is a persistent background process whose core responsibility is to periodically generate system state vectors and broadcast them to all edge computing nodes via a dedicated management network.

[0013] Furthermore, the system state vector is a data structure with a specific format, whose total length is strictly limited to 4096 bytes to ensure efficient transmission under low-bandwidth networks. This data structure specifically includes: a 64-bit sequence number, a UTC timestamp accurate to microseconds, an MD5 hash value representing the current distribution policy table content, a binary bitmap containing information on all active data stream sessions, and a 2048-bit RSA digital signature generated using the private key of the master data distribution center. The state synchronization agent generates and broadcasts this state vector at a fixed frequency of twenty times per second. This synchronization mechanism brings an average additional 3% computational load to the central processor of the master data distribution center in normal mode and introduces a fixed latency of approximately 18 milliseconds to the end-to-end data distribution link.

[0014] The edge computing nodes, serving as the system's resilient redundancy units and core of its decentralized operation, are physically deployed in isolated network areas within the stadium, such as connecting to aggregation switches on different floors. The hardware configuration of each edge computing node is identical to that of the main data distribution center's servers. Each edge computing node also integrates a quantum key distribution (QKD) terminal, which connects to the server motherboard via a PCI-Express 4.0 x8 interface. This QKD terminal can generate information-theoretic-secure symmetric keys over a distance of 50 kilometers using the decoy-state BB84 protocol at a rate of at least 20 kilobits per second. The key interface provided by this terminal conforms to the QKD004 standard published by the European Telecommunications Standards Institute (ETSI).

[0015] In normal operation mode, the edge computing node is in a low-power hot standby state. Its operating system and core services are loaded, but the central processing unit is locked in P1 power-saving mode. A standby agent process runs on the node. The sole task of this process is to listen to the dedicated management network, receive and verify the state vector from the main data distribution center. The verification process includes checking the validity of the digital signature, the continuity of the sequence number, and the rationality of the timestamp. After successful verification, the standby agent updates the state vector content to a local in-memory database. The structure of this database is completely consistent with the database structure used by the data processing and distribution engine of the main data distribution center. In this hot standby state, the edge computing node does not process any external business data requests, and its power consumption is only 30% of that in the full-power operation state.

[0016] The security arbitration response module is the core of the decision-making process of this invention. It is physically deployed on a specially hardened 1U rack server that is independent of the main data distribution center and all edge computing nodes. The server is connected to the core network switch through a passive fiber network test access point (TAP) to achieve passive and non-intrusive mirroring of all network traffic entering and leaving the main data distribution center.

[0017] The security arbitration response module integrates three functionally tightly coupled sub-modules: a full-traffic monitoring engine, a composite threat analysis engine, and a decision and execution controller.

[0018] The full-traffic monitoring engine is directly connected to the output port of the fiber optic network TAP. It performs line-speed processing on the mirrored traffic through a dedicated network capture card equipped with a field-programmable gate array (FPGA). The FPGA is responsible for the initial parsing of the data packets, extracting the IP header, TCP / UDP header, and application layer protocol identifier, and writing this metadata along with the precise arrival timestamp of the data packets into a circular shared memory buffer.

[0019] The composite threat analysis engine continuously reads data from the circular shared memory buffer and performs two-layer concurrent analysis. The first layer is traffic statistics analysis, which records and aggregates the number of transaction requests from different source IP addresses in a time-series database, on a second-by-second basis, and calculates a moving average of transactions per second (TPS) based on data from the past five seconds. The second layer is attack signature identification, which uses a built-in attack signature library containing more than 5,000 rules to perform deep packet inspection (DPI) on data packets. This signature library not only covers common network layer and transport layer DDoS attack patterns such as UDP fragmentation attacks, SYN flood attacks, and NTP amplification attacks, but also includes low-speed application layer attack signatures targeting specific services of sports venues (such as ticketing query APIs).

[0020] Furthermore, the engine runs an anomaly detection model based on a Long Short-Term Memory (LSTM) neural network. This model learns normal patterns of 27 network traffic features, including source IP address entropy, packet size distribution, and session establishment frequency, by training offline on several weeks of normal business traffic. In real-time analysis, the model can identify traffic that deviates significantly from the normal pattern and label it as an independent unknown attack vector.

[0021] The core of the decision and execution controller is a deterministic finite state machine (FSM), which includes four states: normal, alert, locked, and switching. The controller checks the output from the composite threat analysis engine 100 times per second and updates the state machine state according to a set of fixed rules. The preset composite conditions for triggering mode switching are: the moving average TPS value exceeds 15,000 times for five consecutive seconds, and during this period, the attack feature identification module identifies three or more types of deterministic attack vectors with different sources and principles.

[0022] Once the aforementioned combined conditions are met, the state machine of the decision and execution controller immediately transitions from the warning state to the locked state and immediately initiates an irreversible system mode switching procedure, which is executed through two parallel channels: First, the controller sends a digitally signed instruction to a network automation orchestration platform through a separate, out-of-band managed serial port. The instruction modifies the routing table of the core router, changing the original routing entry pointing to the virtual IP address (VIP) of the main data distribution center server cluster to an anycast IP address pointing to all edge computing nodes. The completion time of this change operation is strictly controlled within 50 milliseconds.

[0023] Secondly, the controller broadcasts an activation signaling packet to the standby agents of all edge computing nodes through a dedicated management network. The payload of this signaling packet is a JSON object signed with the private key of the security arbitration response module itself, which contains a precise timestamp that triggered the switch and a one-time random number (Nonce) to prevent replay attacks.

[0024] The corresponding method provided by this invention, namely a method for automatically distributing sports venue match information, includes the following steps: Step 1, System Initialization and Normal Operation: When the system starts, the main data distribution center loads all distribution policies and begins processing business data. All edge computing nodes start up and enter hot standby state. The state synchronization agent of the main data distribution center begins to broadcast the system state vector to all edge computing nodes at a frequency of 20 times per second. The security arbitration response module begins to passively monitor network traffic. At this stage, the system appears to the outside world as a centralized service. Its end-to-end distribution latency is stable at a level that is about 22 milliseconds higher than that of the traditional architecture due to the state synchronization overhead.

[0025] Step 2, Attack Occurrence and Identification: When an external, complex DDoS attack is launched against the main data distribution center, the TPS value of the inbound traffic rises sharply, and the attack packets exhibit various characteristics. The complex threat analysis engine of the security arbitration response module detected TPS values ​​exceeding 15,000 times in five consecutive second-level time windows, and cumulatively identified three or more attack vectors, such as SYN flooding, DNS amplification attacks, and HTTPGET-based CC attacks.

[0026] Step 3, System Mode Switching Decision and Execution: The decision and execution controller confirms that the composite triggering conditions are met, the state machine enters the locked state, and immediately issues network routing change instructions and node activation signaling packets in parallel.

[0027] Step 4, Decentralized Mode Activation and Operation: After receiving and verifying the activation signaling packet, the standby agents of all edge computing nodes immediately perform the following actions: switch the central processing unit from P1 power-saving mode to P0 highest performance mode; start the complete data processing and distribution engine, which directly loads the synchronized system state and distribution strategy from the local memory database; trigger the integrated QKD terminal to establish a quantum-safe communication session with all other activated edge computing nodes in the network. Due to the routing change of the core router, the new service data stream is evenly distributed to all edge computing nodes by the anycast mechanism.

[0028] Step 5, Distributed Collaborative Defense and Business Processing: After entering decentralized mode, each edge computing node independently cleans the received traffic, discards malicious data packets, and hands over legitimate business requests to the local data processing and distribution engine. When nodes need to negotiate state or confirm data consistency, their communication is conducted through a channel with information theory security guaranteed by QKD terminals, thereby eliminating the risks of man-in-the-middle attacks and eavesdropping common in distributed systems. Since the business load is distributed across multiple physically isolated nodes, the possibility of a single node's computing or network resources being exhausted is greatly reduced, thus increasing the entire system's DDoS attack tolerance by at least an order of magnitude. In this mode, even if the main data distribution center completely fails due to an attack, the distributed system composed of edge computing node clusters can still maintain no less than 95% of the core business processing capacity, and the integrity and confidentiality of the data are absolutely guaranteed by the quantum encryption channel.

[0029] Step 6, System Recovery: When the security arbitration response module detects that the attack traffic has completely subsided, that is, the TPS value has been below the normal baseline for ten consecutive minutes and no attack characteristics have been identified, it will issue an alarm to the system administrator, prompting that manual recovery can be performed. After the system administrator logs into the security arbitration response module through the secure channel and confirms that the hardware and system status of the main data distribution center are intact, a recovery command can be triggered. This command will guide the system to perform the opposite operation of the switching process, switch the route back to the main data distribution center, and instruct the edge computing nodes to return to hot standby status.

[0030] Compared with the prior art, the present invention has the following advantages: This invention achieves a non-linear leap in system survivability under extreme security threats by proactively accepting a minimal conventional performance cost, fundamentally solving the inherent vulnerability of traditional centralized architectures and providing a deterministic, reliable, and technologically autonomous technical means to ensure the business continuity of critical information infrastructure such as stadiums. Attached Figure Description

[0031] Figure 1 This is a system structure block diagram of the present invention for automatically distributing sports venue competition information; Figure 2 This is a structural block diagram of the secure arbitration response module in this invention; Figure 3 This is a schematic flowchart of a method for automatically distributing sports venue competition information according to the present invention; Figure 4 This is a schematic diagram of the operating structure of the system of the present invention in a decentralized mode.

[0032] In the diagram: 100, Master Data Distribution Center; 110, Data Adaptation Layer; 120, Data Processing and Distribution Engine; 130, State Synchronization Agent; 200, Edge Computing Node; 210, Quantum Key Distribution Terminal; 220, Standby Agent; 300, Security Arbitration Response Module; 310, Full Traffic Monitoring Engine; 320, Composite Threat Analysis Engine; 330, Decision and Execution Controller. Detailed Implementation

[0033] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0034] Reference Figure 1 This invention demonstrates the overall architecture of a system for automatically distributing sports venue match information. This system aims to fundamentally solve the single point of failure bottleneck problem of traditional centralized information systems when facing high-intensity, complex network attacks through a dual-mode redundancy design.

[0035] The system mainly consists of a main data distribution center 100, at least two edge computing nodes 200 that are physically and network isolated from each other, and a security arbitration and response module 300 that serves as the system decision-making center. In the normal operation mode, the system presents a centralized architecture with the main data distribution center 100 as the core. However, under the triggering of a preset extreme security event, the system can deterministically switch to a decentralized operation mode composed of all edge computing nodes 200, which has inherent anti-attack capabilities.

[0036] In one specific embodiment, the main data distribution center 100 is deployed in the core data room of the sports stadium, and its physical form is a cluster composed of multiple high-performance servers.

[0037] To ensure high-concurrency data processing capabilities and system stability, each server in the cluster is equipped with a multi-core central processing unit based on the ARMv8 instruction set architecture, specifically a processor with 64 physical cores and a base operating frequency of 2.6GHz.

[0038] In terms of memory, each server is equipped with 512GB of DDR4 error-correcting code memory (ECCRAM), which can automatically detect and correct unit bit errors, thereby ensuring the integrity of critical business data in memory. The storage system uses a RAID50 array consisting of eight 4-terabyte NVMe solid-state drives, with a total usable capacity of over 32 terabytes. This array combines the distributed parity of RAID5 with the striping of RAID0, balancing data redundancy with extremely high read and write throughput.

[0039] At the network connectivity level, each server is equipped with two 100GbE Ethernet cards that support Remote Direct Data Access (RDMA) technology. Through the RoCEv2 protocol, network communication between servers can bypass the operating system kernel and transmit data directly between the application's user space and the network hardware, which greatly reduces communication latency and reduces the load on the central processing unit.

[0040] On the aforementioned hardware platform, the main data distribution center 100 runs a deeply hardened operating system based on the Linux 5.10 Long Term Support (LTS) kernel. This operating system enforces the SELinux security module and is configured with strict access control policies to restrict resource access of each system process according to the principle of least privilege.

[0041] At the same time, all non-essential system services and network ports, such as password authentication for the Remote Login Service (SSH) and the File Transfer Protocol (FTP) service, are permanently shut down or disabled, leaving only the necessary management and business ports open, thereby minimizing the system's attack surface.

[0042] The software stack of the main data distribution center 100, from bottom to top, consists of a data adaptation layer 110, a data processing and distribution engine 120, and a state synchronization agent 130.

[0043] Specifically, the data adaptation layer 110 acts as a bridge between the system and various heterogeneous information sources within the venue. By loading a series of dedicated drivers and protocol stacks, it enables stable communication with devices from different manufacturers and of different types. For example, it can interface with venue environmental monitoring sensors that conform to the Modbus TCP industrial Ethernet protocol, can act as an OPCUA client to interact with modern timing and scoring systems such as the Omega timing system in swimming competitions, and can also communicate with traditional ticketing gate systems that use custom serial communication protocols through an RS-485 to Ethernet gateway.

[0044] The data adaptation layer 110 will parse and standardize the raw data collected from these heterogeneous sources, regardless of their original format, and finally encapsulate them into JSON format data objects using UTF-8 encoding. Each JSON object contains a unique identifier, a source device ID, a timestamp accurate to milliseconds, and a payload field containing specific business data.

[0045] The upper layer immediately above the data adaptation layer 110 is the data processing and distribution engine 120, which is the core of the business logic in the normal mode. The core component of this engine is a high-performance stream processing framework. It processes the JSON data object stream from the data adaptation layer 110 in real time based on a distribution strategy table stored in a local PostgreSQL database. The distribution strategy table is a set of rules that can be dynamically configured by the system administrator through a secure web interface. Each rule defines a set of matching conditions and a corresponding sequence of processing actions.

[0046] The processing steps include data cleaning, data aggregation, format conversion, and data augmentation. Specifically, data cleaning can remove invalid or outliers; data aggregation can calculate the total number of people entering all ticket gates; format conversion can convert JSON data into XML format required by a specific manufacturer's large screen controller; and data augmentation can add athletes' personal information to the competition results data. After processing, the data will be distributed by the engine to designated consumer terminals through different output plugins, such as being pushed to the control console of the LED screen in the venue, provided to the packaging system of the TV station to generate live broadcast graphics, or archived to a historical database.

[0047] The state synchronization agent 130 is one of the key components for implementing the dual-mode redundancy design of this invention. It runs as an independent, high-priority background daemon. Its core responsibility is to periodically capture the current complete running state of the data processing and distribution engine 120 and encapsulate it into a compact system state vector. Then, it is sent to all edge computing nodes 200 via UDP broadcast through a dedicated management network that is physically isolated from the business network. In order to ensure efficient and reliable transmission in low-bandwidth or unstable network environments, the data structure of the system state vector is carefully designed, and its total length is strictly limited to within 4096 bytes.

[0048] Specifically, the data structure includes the following fields: a 64-bit, monotonically increasing sequence number for the receiver to detect packet loss and out-of-order delivery; a 64-bit UTC timestamp representing the generation time, accurate to the microsecond level, for determining state timeliness; a 128-bit MD5 hash value representing a snapshot of the current distribution policy table content, to ensure consistency of policies across all nodes; a dynamically long binary bitmap, where each bit corresponds to a currently active data stream call, for quickly reconstructing the session state; finally, to prevent state information from being tampered with or forged, after the entire state vector is generated, a 2048-bit RSA-PSS digital signature is generated using a private key pre-installed in the hardware security module within the main data distribution center 100 and appended to the end of the vector. The state synchronization agent 130 generates and broadcasts this state vector at a fixed frequency of twenty times per second.

[0049] In normal operation, this high-frequency synchronization mechanism brings an average of about 3% additional computing load to the central processing unit of the main data distribution center 100, and introduces a fixed latency of about 18 milliseconds to the end-to-end link from data acquisition to final distribution. Taking into account other processing stages, the total system latency is about 22 milliseconds higher than the traditional architecture without a synchronization mechanism. This slight performance sacrifice is the pre-set price paid to achieve seamless switching and business continuity in extreme cases.

[0050] Next, we will describe the system's elastic redundancy units, namely edge computing nodes 200. These nodes are strategically deployed physically in different areas of the stadium, such as in the low-voltage wells under the four stands (east, west, south, and north), and connected to aggregation switches on different floors. This ensures a high degree of isolation between them in terms of physical location, power supply, and network links, thereby preventing a single physical event from causing all redundant nodes to fail simultaneously. The hardware configuration of each edge computing node 200, including the CPU model, memory capacity, storage array specifications, and network interface capabilities, is completely consistent with the server hardware configuration of the main data distribution center 100. This homogeneous design ensures that after mode switching, the edge computing nodes can seamlessly take over all the business load of the main data distribution center without performance bottlenecks.

[0051] The key difference between edge computing node 200 and main data distribution center 100 lies in the fact that each node additionally integrates a quantum key distribution (QKD) terminal 210. This QKD terminal, installed as a standard PCI-Express 4.0 x8 interface card on the server motherboard, interconnects with QKD terminals on other edge computing nodes via dedicated single-mode fiber optic links, forming a fully connected quantum channel network. Internally, this terminal implements a quantum key negotiation process based on the decoy state BB84 protocol, capable of generating information-theoretically secure symmetric keys at a continuous rate of no less than 20 kilobits per second (kbps) over fiber optic distances up to 50 kilometers.

[0052] This means that even an attacker with unlimited computing power cannot eavesdrop on the channel without being detected. The key materials and management interface provided by the terminal strictly follow the GSQKD004 standard published by the European Telecommunications Standards Institute (ETSI), ensuring its compatibility and standardization with upper-layer cryptographic applications.

[0053] In the normal operating mode of the system, all edge computing nodes 200 are in a low-power hot standby state. Their operating systems and core services are fully loaded into memory, but the operating state of the central processing unit is locked in P1 power saving mode by the operating system power manager. Its core frequency and voltage are reduced. In this state, only a lightweight standby agent 220 process runs on the node. The sole task of this process is to listen for state vector broadcasts from the master data distribution center 100 through a dedicated management network. Whenever a state vector data packet is received, the standby agent 220 first uses the preset master data distribution center public key to verify the digital signature in the vector to ensure the authenticity and integrity of the information source. Subsequently, it checks whether the sequence number is consecutive and whether the timestamp is within a preset reasonable window.

[0054] After all verifications are successful, the standby agent 220 will update the information such as the distribution strategy hash value and active session bitmap contained in the state vector to a local Redis in-memory database. The key-value structure of this database is completely consistent with the database structure used by the main data distribution center 120, thereby maintaining a state replica that is almost completely synchronized with the main center in real time. In this hot standby state, the edge computing node does not process any external business data requests, and its total power consumption is only about 30% of that in the full power operation state, effectively reducing daily operating costs.

[0055] The core of the system's decision-making is the security arbitration response module 300, which is physically deployed on a specially hardened 1U rack server, independent of the main data distribution center 100 and all edge computing nodes 200. In order to achieve non-intrusive monitoring of network traffic, a passive fiber optic network test access point (TAP) is connected in series between the server and the uplink of the stadium's core network switch. The TAP device uses the principle of optical splitting to copy all optical signals on the monitored link to its monitoring port, so that the security arbitration response module 300 can passively, without delay, and without affecting normal network communication, obtain a complete image of all network traffic entering and leaving the main data distribution center 100.

[0056] Reference Figure 2 The software architecture of the security arbitration response module 300 consists of three functionally tightly coupled sub-modules: the full traffic monitoring engine 310, the composite threat analysis engine 320, and the decision and execution controller 330.

[0057] The full-traffic monitoring engine 310 is based on a dedicated network capture card equipped with a Field-Programmable Gate Array (FPGA). Mirrored traffic from the fiber optic TAP is directly input into this card. The FPGA utilizes its parallel processing capabilities to perform preliminary line-speed parsing of data packets without consuming the server's central processing unit resources. It can extract key metadata such as the IP header, TCP / UDP header, and protocol type of each data packet in real time, and add an arrival timestamp with nanosecond resolution generated by a high-precision clock on the card. This metadata, along with the original payload of the data packet, is written to a large-capacity circular shared memory buffer in the server's main memory for consumption by the upper-layer engine.

[0058] The composite threat analysis engine 320, acting as a consumer, continuously reads data at high speed from the circular shared memory buffer and executes a two-layer concurrent deep analysis process. The first layer is macro-level traffic statistics analysis. The engine aggregates the extracted connection information in an embedded database optimized for time-series data. It records and updates metrics such as the number of transaction requests, the number of new connections, and the packet rate from different source IP addresses in real time, using seconds as the basic time unit. It pays particular attention to a key performance indicator: the moving average of transactions per second (TPS) calculated based on data from the past five seconds.

[0059] The second layer is the micro-level attack signature identification. The engine uses a built-in attack signature library containing more than 5,000 precise rules to perform deep packet inspection (DPI) on data packets. This signature library not only covers common network layer and transport layer DDoS attack patterns such as UDP fragmentation attacks, SYN flood attacks, NTP amplification attacks, and DNS reflection attacks, but also specifically includes low-speed application layer attack features targeting specific services of sports venues, such as HTTP GETCC attacks that simulate a large number of slow requests from users targeting the ticket query API.

[0060] Furthermore, to address unknown, zero-day attacks, the engine also runs an anomaly detection model based on a Long Short-Term Memory (LSTM) neural network. This model, trained offline on weeks of normal business traffic data, deeply learns normal behavior patterns based on twenty-seven network traffic characteristics, including Shannon entropy of source IP address distribution, statistical distribution of packet size, TCP flag combination patterns, TLS handshake parameters, HTTP request method composition, session establishment frequency, and session duration. During real-time analysis, the model can accurately identify traffic that deviates significantly from the learned normal patterns and label it as an independent, unknown attack vector.

[0061] The decision and execution controller 330 is the brain of the entire system. Its core logic is implemented as a deterministic finite state machine (FSM), which includes four well-defined states: normal, alert, locked, and switching. The controller polls the output of the composite threat analysis engine 320 at a high frequency of 100 times per second and updates the state machine state according to a set of pre-defined, immutable rules in the code. This invention designs a composite condition, rather than a single threshold, to trigger system mode switching, in order to avoid false alarms and ensure that action is only taken when there is a real risk of systemic collapse. The composite condition is defined as follows: the moving average TPS value calculated by the composite threat analysis engine 320 exceeds 15,000 times for five consecutive second-level time windows, and within this period, the cumulative number of deterministic attack vectors identified by the attack feature identification module, with different sources and attack principles, reaches or exceeds three.

[0062] Once the aforementioned composite conditions are precisely met, the state machine of the decision and execution controller 330 immediately and irreversibly transitions from the warning state to the locked state, and immediately initiates the system mode switching procedure. This procedure is executed through two parallel and independent channels to ensure the speed and reliability of the switching action.

[0063] First, the controller sends a command digitally signed with its own private key to a commercial network automation orchestration platform through an out-of-band managed RS-232 serial port that is completely isolated from the main network. The command modifies the routing table of the core router, changing one or more routing entries that originally pointed to the virtual IP address (VIP) of the main data distribution center 100 server cluster to an anycast IP address shared by all edge computing nodes 200. Due to the use of modern network orchestration tools and protocols, the effective time of this routing change operation on the backbone network equipment is strictly controlled within fifty milliseconds.

[0064] Secondly, the controller broadcasts an activation signaling packet to the standby agents 220 of all edge computing nodes 200 via a dedicated management network. The payload of the signaling packet is a JSON object signed with the private key of the security arbitration response module 300, which explicitly contains the precise timestamp that triggered the switch and a random number (Nonce) that can only be used once to prevent any potential replay attacks.

[0065] Based on the above system architecture, referring to Figure 3 The specific execution flow of the method for automatically distributing sports venue competition information disclosed in this invention is as follows: Step 1: System Initialization and Routine Operation: Upon system startup, the main data distribution center 100 loads all distribution strategies, starts its complete internal software stack, and begins receiving, processing, and distributing business data from various information sources within the venue. Simultaneously, all edge computing nodes 200 also start up, and their standby agents 220 begin operation, putting the nodes into a low-power hot standby state. The state synchronization agent 130 of the main data distribution center 100 begins broadcasting the system state vector to all edge computing nodes 200 at a fixed frequency of twenty times per second. The security arbitration response module 300 passively and continuously monitors all network traffic entering and leaving the main data distribution center via fiber optic TAP. During this stage, the entire system appears externally as a traditional, high-performance centralized service. Due to the overhead of state synchronization, its end-to-end data distribution latency remains stable at approximately twenty-two milliseconds higher than that of a traditional architecture without a synchronization mechanism.

[0066] Step 2, Attack Occurrence and Identification: When an external attacker launches a well-planned composite DDoS attack against the main data distribution center 100, such as simultaneously launching a SYN flood attack, a DNS amplification attack, and an HTTP GETCC attack against the business API using a large number of botnet hosts, the TPS value of the inbound traffic will rise sharply, and the characteristics of the data packets will exhibit a variety of different abnormal patterns. The composite threat analysis engine 320 of the security arbitration response module 300 will immediately capture these changes. Its traffic statistics analysis layer will find that the moving average TPS value quickly exceeds 15,000 times, while its attack feature identification layer will simultaneously match the fingerprints of SYN flood and DNS amplification attacks in the feature database, and the LSTM model will also report an abnormal behavior that deviates significantly from the normal HTTP request pattern.

[0067] Step 3, System Mode Switching Decision and Execution: When the composite threat analysis engine 320 confirms that the TPS value is higher than 15,000 times within five consecutive second-level time windows, and the cumulative number of identified attack vector types reaches three, the internal state machine of the decision and execution controller 330 will confirm that the preset composite triggering conditions are met, and the state will immediately transition from warning to lock. Once the lock state is entered, the controller will immediately issue a network routing change command in parallel through the serial port and activate the signaling packet through the management network broadcast node.

[0068] Step 4: Decentralized Mode Activation and Operation: Standby agents 220 on edge computing nodes 200 distributed throughout the venue almost simultaneously receive and verify the validity of the activation signaling packet. Upon successful verification, each node immediately executes a series of pre-set automated actions: First, the central processing unit is instantly switched from P1 power-saving mode to P0 highest performance mode using the ACPI instruction; Secondly, the complete data processing and distribution engine service is launched. This engine loads the latest system state and distribution strategy, which has been prepared by the state synchronization mechanism, directly from the local memory database at startup, thus achieving a hot start. Finally, the integrated QKD terminal 210 is triggered to establish a quantum key-based, point-to-point secure communication session with all other activated edge computing nodes in its peer network. During this period, the routing change of the core router has been completed, and all new external service data streams, due to the change of the target IP address to anycast address, are automatically and evenly distributed to all activated edge computing nodes by the BGP routing protocol according to the network topology distance.

[0069] Step 5, Distributed Collaborative Defense and Business Processing: Refer to Figure 4After the system enters the decentralized mode, the original single centralized processing pressure is effectively distributed. Each edge computing node 220 independently cleans the traffic allocated to it, uses local firewall rules and possible IPS functions to drop obviously malicious data packets, and hands over the identified legitimate business requests to the local data processing and distribution engine 120 for processing.

[0070] Since each node only handles a portion of the total load, the likelihood of its computing and network resources being exhausted by a single attack is greatly reduced. When business logic requires cross-node state negotiation or data consistency confirmation—for example, when processing a ticket verification operation that requires global atomicity to prevent reuse—communication between nodes will be enforced through an information-theoretic secure channel guaranteed by the QKD terminal 210. This fundamentally eliminates the man-in-the-middle attacks and eavesdropping risks common in traditional distributed systems that target inter-node coordination protocols.

[0071] In this model, even if the main data distribution center 100 is completely ineffective due to continuous attacks, the distributed system composed of edge computing node clusters can still maintain no less than 95% of the core business processing capacity. The integrity and confidentiality of the data are also absolutely guaranteed by the quantum encryption channel. The overall DDoS attack resistance of the entire system is improved by at least one order of magnitude compared to the original centralized model.

[0072] Step 6, System Recovery: When the external attack traffic has completely subsided, and the security arbitration response module 300 detects that the TPS value has been lower than the baseline level of normal business traffic for ten consecutive minutes, and no attack characteristics have been identified, it will automatically send an alarm to the system administrator's monitoring platform, indicating that the attack has ended and the system is ready to recover to normal mode.

[0073] Upon receiving the alarm, the system administrator logs into the security arbitration response module 300 through a secure channel such as out-of-band management and checks the hardware and system status of the main data distribution center 100. After confirming that it is intact, the administrator can trigger a recovery command. This command will guide the decision and execution controller 330 to perform the opposite operation to the switching process. That is, firstly, the network automation platform is instructed to switch the route back to the VIP of the main data distribution center 100, and then the management network broadcasts a command to make all edge computing nodes 200 stop business processing and return to the low-power hot standby state, waiting for the next state synchronization.

[0074] Example 1 To verify the actual effect of the technical solution of the present invention, the following simulation test environment was built. This environment simulates a medium-sized stadium and deploys a system described in the present invention, including a main data distribution center 100, four edge computing nodes 200 deployed in different network areas, and a security arbitration response module 300. The core hardware configuration of the main data distribution center and each edge computing node adopts a 64-core ARMv8 processor, 512GB ECC memory and 32TB NVMe RAID50 storage.

[0075] The network core is 100GbE, and each node has an access rate of 100GbE. The simulated data sources include: 500 simulated ticket gates, which generate 1-5 JSON-formatted entry records per second; 2 simulated central scoreboards, which need to receive real-time updates of the competition results; and 1000 simulated environmental sensors, which report data every 5 seconds.

[0076] Comparative Example 1 In contrast, an information distribution system using a traditional high availability (HA) architecture was built. This system consists of a primary and backup server cluster in an active-passive mode. The hardware configuration is the same as the primary data distribution center in Example 1. The system does not include edge computing nodes and security arbitration response modules. Its DDoS protection relies on traditional firewalls and intrusion prevention systems (IPS) deployed at the network entry point. Its rule base contains common DDoS attack characteristics.

[0077] Test and Data Comparison The same composite DDoS attack, lasting 15 minutes, was applied to both systems. The attack traffic was initiated by a simulated botnet containing 10,000 nodes, with a total traffic of 20Gbps. It consisted of three parts: a SYNFlood attack with a rate of 1 million pps, a UDP fragmentation attack with a bandwidth of 5Gbps, and a low-speed HTTP GETCC attack targeting the ticketing query API with 20,000 concurrent connections. During the test, the key performance indicators of the system were continuously monitored, and the results are recorded in the table below.

[0078] The data comparison in the table above clearly shows that although the system and method proposed in this invention sacrifice a small amount of latency performance (25ms vs 3ms) in the conventional mode, they exhibit an overwhelming advantage when facing high-intensity complex DDoS attacks. They can accurately identify threats within seconds and automatically switch to a decentralized mode, thereby ensuring the continuity of core business (availability > 99%) and acceptable service quality (latency 85ms).

[0079] In contrast, traditional HA architectures, due to their inherent centralized bottlenecks and passive defense mechanisms, quickly fail under attacks of the same intensity, leading to systemic service outages.

[0080] Furthermore, the quantum-secure communication introduced in this invention under a decentralized model provides the highest level of security for collaboration between nodes.

[0081] In summary, this invention, through an innovative design philosophy that proactively sacrifices minor conventional performance in exchange for a leap in survivability under extreme conditions, successfully constructs a system and method for automatically distributing sports venue match information. This solution not only fundamentally solves the inherent vulnerability of traditional centralized architectures but also provides a definite, reliable, and technologically advanced guarantee for the business continuity and data security of critical information infrastructures such as sports venues. Those skilled in the art can understand and implement the technical solution of this invention without obstacles based on the above description.

Claims

1. A system for automatically distributing sports venue competition information, characterized in that, include: A master data distribution center (100) is configured to serve as the sole business processing core in normal operation mode, for real-time processing of business data from the stadium, and periodically generating and broadcasting a system state vector containing its current complete operating status at a preset frequency. At least two edge computing nodes (200) are deployed in mutually isolated network areas. The edge computing nodes (200) are in hot standby mode in the normal operation mode and are configured to continuously receive, verify and store the system state vector broadcast by the main data distribution center (100) to maintain state synchronization with the main data distribution center (100). as well as A security arbitration response module (300) is physically independent of the main data distribution center (100) and the edge computing node (200), and is configured to passively and non-intrusively monitor all network traffic entering and leaving the main data distribution center (100) through network traffic mirroring. The security arbitration response module (300) is further configured to execute an irreversible system mode switching procedure when, during real-time analysis, it is determined that the network traffic meets a set of preset triggering conditions characterizing a complex network attack. The procedure performs the following operations in parallel: (a) Trigger the core network device to change the original service data flow route pointing to the main data distribution center (100) to an anycast route pointing to the at least two edge computing nodes (200); as well as (b) Broadcast an activation signaling to the at least two edge computing nodes (200) to instruct the edge computing nodes (200) to switch from the hot standby state to the fully operational state and take over and process the service data streams distributed by the anycast route using their synchronized system state vectors, thereby forming a decentralized distributed processing cluster.

2. The system for automatically distributing sports venue competition information according to claim 1, characterized in that, The security arbitration response module (300) includes: A full-traffic monitoring engine (310) with a field-programmable gate array (FPGA) network capture card is used to perform line-rate parsing of the network traffic being mirrored, extract packet metadata, and add a high-precision timestamp to each packet before writing the results to a shared memory buffer. A composite threat analysis engine (320) is configured to read data from the shared memory buffer and perform multi-dimensional analysis on the network traffic to identify attack behaviors; and A decision and execution controller (320), internally implemented as a deterministic finite state machine, is configured to determine whether the composite triggering condition is met based on the analysis results of the composite threat analysis engine (320), and to start the system mode switching procedure when the condition is met.

3. The system for automatically distributing sports venue competition information according to claim 2, characterized in that, The two-layer concurrent analysis performed by the composite threat analysis engine (320) includes: The first layer is traffic statistics analysis, which aggregates various indicators of network traffic in a time series database in seconds and calculates a moving average of transactions per second (TPS) based on a specific time window in the past in real time. The second layer is attack signature recognition, which utilizes a built-in attack signature library containing multiple known network attack patterns to perform deep packet inspection (DPI) on data packets to identify known attack vectors. In addition, it also runs an abnormal behavior detection model based on a long short-term memory (LSTM) neural network. This model learns normal patterns of multiple network traffic features, including source IP address entropy and data packet size distribution, through offline training on historical normal business traffic. This model is used to identify abnormal traffic that deviates significantly from the normal patterns and serves as unknown attack vectors in real-time analysis.

4. The system for automatically distributing sports venue competition information according to claim 3, characterized in that, The preset composite trigger condition is defined as follows: the moving average transaction volume per second (TPS) calculated by the composite threat analysis engine (320) continuously exceeds a preset traffic threshold within a continuous preset time period; and within the continuous preset time period, the cumulative number of deterministic attack vector types identified by the attack feature identification, which have different sources or attack principles, reaches or exceeds a preset number of types threshold; wherein, the deterministic attack vector types include known attack vectors matched by the attack feature library and unknown attack vectors identified by the LSTM model.

5. The system for automatically distributing sports venue competition information according to claim 1, characterized in that, The system state vector is a data structure with a limited total length designed to ensure efficient transmission under low bandwidth conditions. It specifically includes the following fields: A 64-bit monotonically increasing sequence number is used by the receiver for packet loss and out-of-order detection; A UTC timestamp accurate to microseconds is used to determine the timeliness of the status; An MD5 hash value representing the contents of the distribution strategy table currently used by the master data distribution center (100); A binary bitmap used to describe the state of all currently active data stream sessions; as well as A 2048-bit RSA digital signature, generated using a private key pre-installed in the master data distribution center (100) and calculated on the contents of all the aforementioned fields, is used to ensure the authenticity of the source and the integrity of the contents of the system state vector.

6. The system for automatically distributing sports venue competition information according to claim 1, characterized in that, The master data distribution center (100) runs a state synchronization agent (130) inside, which is a high-priority background process responsible for generating and broadcasting the system state vector; Furthermore, each of the aforementioned edge computing nodes (200) runs a standby agent (220), which serves as the sole active process in the hot standby state. This agent is responsible for listening to and receiving the system state vector on the dedicated management network, and performing the following verification and storage operations upon receipt: The digital signature in the system state vector is verified using a preset public key; the continuity of the sequence number and the rationality of the timestamp are checked. After verification, the running status information carried in the system status vector is updated to a local memory database, the structure of which is consistent with the business database structure used by the main data distribution center (100).

7. The system for automatically distributing sports venue competition information according to claim 1, characterized in that, Each of the edge computing nodes (200) is additionally integrated with a set of quantum key distribution (QKD) terminals (210); the quantum key distribution (QKD) terminals (210) are configured to, after the edge computing node (200) is activated by the activation signal and enters the decentralized operation mode, negotiate keys with the quantum key distribution (QKD) terminals (210) on other activated edge computing nodes (200) through a dedicated optical fiber link, thereby establishing a symmetric key communication session based on quantum physics principles and with information theory security among all nodes constituting the distributed processing cluster, so as to ensure the confidentiality and integrity of communication between nodes when performing collaborative operations such as state negotiation or data consistency confirmation.

8. The system for automatically distributing sports venue competition information according to claim 1, characterized in that, After receiving the activation signal and verifying its validity, the edge computing node (200) performs an automated sequence of actions to switch from hot standby to full operation, including: instructing its onboard central processing unit to immediately switch from P1 power-saving mode to P0 highest performance mode via the power management interface; starting a complete data processing and distribution engine service, which, upon startup, directly loads the latest system state and distribution strategy, which has been updated in real time by the state synchronization mechanism, from its local memory database to achieve uninterrupted hot start of the service; and triggering its integrated quantum key distribution (QKD) terminal (210) to begin establishing a quantum-secure communication session with other activated peer nodes in the network.

9. A system for automatically distributing sports venue competition information according to claim 1, characterized in that, The software stack of the master data distribution center (100) includes: A data adaptation layer (110) integrates multiple protocol drivers for communicating with existing heterogeneous information sources within the stadium, including those using ModbusTCP, OPCUA, or custom serial communication protocols. It also parses and encapsulates the collected raw data into standardized JSON data objects. A data processing and distribution engine (120) performs a series of processing operations, including data cleaning, aggregation and format conversion, on the JSON format data object stream passed in by the data adaptation layer (110) based on a distribution strategy table stored in a local database that can be dynamically configured by the administrator, and distributes the processed data to one or more specified consumer terminals.

Citation Information

Patent Citations

  • Competitive sports smart venue operation service system

    CN117459556A